AI, lawyers and law firms: a case for greater emphasis on law firms’ responsibilities

Friday 7 August 2026

Anurag Bana

IBA Legal Policy & Research Unit, London

anurag.bana@int-bar.org

Emma Mandou-Berranger

Former IBA Legal Intern, Legal Policy & Research Unit, London

emmamb@orange.fr

When lawyers submit AI-generated hallucinations to courts, it results in reputational harm to law firms, which may then have to issue apologies and self-report to regulatory authorities.[1] This shows that law firms cannot be exempt from addressing their lawyers’ use of AI. Bar associations and law societies across jurisdictions have issued best practice guidelines concerning professional duties that may be put at risk through the use of AI, including confidentiality, professional secrecy, data protection, competence, reasonable fee setting, diligence, independence and transparency. While these duties must be individually observed by lawyers, the implementation of AI in law firms may increase risks of violation. It raises the questions: to what extent can law firms facilitate the compliance of lawyers with their professional duties, and what role do managerial lawyers have? AI-driven law firms have a responsibility to support their lawyers in complying with their professional duties in the use of AI, and to play an active role in regulating AI-related issues within their scope of action, such as training, billing systems, oversight and professional indemnity insurance. The question is no longer whether law firms should adopt AI policies, but what these policies should comprise. Indeed, integrating AI into law firms involves more than purchasing licences; it requires law firms to evaluate their needs and establish governance frameworks.[2] These should be defined in accordance with lawyers’ professional duties.[3]

Confidentiality and data protection

The duty of confidentiality and professional secrecy requires lawyers to maintain the confidentiality of information received from, and advice provided to, current and former clients. Lawyers should also process clients’ personal data in compliance with data protection regulation. To comply with these duties while using AI, lawyers should assess whether AI systems provide sufficient safeguards, pseudonymise or anonymise data, and limit contextual information when entering data into external AI systems. However, there can be significant variation in how lawyers apply these recommendations, depending on their jurisdiction, area of practice, law firm and individual skills. Furthermore, risks still exist with in-house AI systems, such as indirect identification through data cross-referencing. Making confidential client information accessible to other lawyers within the law firm who do not adequately protect the information from improper disclosure due to a lack of knowledge regarding its source is another issue.[4] The use of client data to train internal AI systems also gives rise to risks which can only be effectively addressed at the law firm level. Therefore, implementing an AI system for the firm does not suffice to prevent unwanted disclosure. AI-driven law firms still have responsibilities with respect to confidentiality, data protection and cybersecurity risks. For these reasons, law firms should address confidentiality issues at the firm level to ensure compliance by lawyers. Law firms could include in their policies a list of approved AI platforms, precise guidance on prompts to harmonise the level of precision of the information lawyers enter into AI systems, and clarification on which documents may be uploaded.[5]

Technological competence through firm-led training

The duty of competence requires lawyers to carry out their work in a competent manner and to only take on work they can conduct in such manner. With the implementation of AI in law firms and its use by individual lawyers, practitioners should have a sound understanding of AI systems and develop AI-specific skills. This expectation is increasingly reflected in professional guidance. For example, the International Bar Association (IBA) Council, in May 2024, approved an update to the Explanatory Note for Principle 9 on Competence in the IBA International Principles on Conduct for the Legal Profession, recognising that lawyers should maintain an understanding of the benefits and risks associated with relevant technologies (including AI) and develop the technological competence necessary for their practice.[6] External training is available, but it is voluntary and may not be sufficiently tailored to the specific AI systems and operational needs of individual law firms, particularly where proprietary or in-house AI systems are used. Relying on bar associations’ guidance and resources, law firms could take the lead on training their lawyers and make training mandatory. This would ensure that all lawyers within the law firm have equal knowledge and apply the same safeguards, therefore reducing risks of missteps.[7] It would allow technical training targeted at AI systems used in the law firm. In-house training could also enable firms to stay on top of skills gaps and adjust their training. Law firms could analyse staff attitudes to using AI and adapt training to land more effectively. By having a clear understanding of their lawyers’ exact level of competence,[8] law firms may be better able to anticipate and identify negligence risks arising from the use of AI for professional indemnity insurance and also assess whether purchase of additional insurance coverage is required.[9]

Rethinking billing models and fee structures

Lawyers are entitled to a reasonable fee for their work but should not charge unreasonable fees nor generate unnecessary work. This requires law firms’ billing systems to be in line with lawyers’ use of AI, as well as with clients’ expectations. It is questionable whether clients would accept the same fees as they used to for tasks performed with AI. Therefore, integrating AI in legal practice could prompt law firms to reevaluate their business models. Law firms in Australia have started rethinking the billable-hour model and setting pricing value for productivity and quality of output, and the value generated by lawyers’ skills.[10] This, in turn, justifies law firms training their lawyers to prevent inequality in terms of productivity and output evaluation, to ensure lawyers can still apply their craft while resorting to AI, and that AI-adapted legal skills can be charged for. Law firms should draft firm-wide fee-setting criteria that take into consideration legal skills in relation to AI, the time saved by using AI, and the time needed to review AI-generated content. Moreover, the time and manner dedicated to reviewing AI-produced content should also be determined at the firm level to prevent unnecessary work if left to individual appreciation.

Diligence, independence and oversight

The duty of diligence requires lawyers to exercise due diligence in their undertakings and to retain full control over their ability to fulfil those undertakings. The duty of independence requires lawyers to remain independent and unbiased in advising and representing clients. Concerns related to the use of AI include bias and erosion of legal reasoning and professional judgement. For lawyers with supervisory responsibilities, it implies ensuring that lawyers and staff under their direction are equipped with appropriate training.[11] This could be made easier by law firms implementing mandatory in-house training, explicitly listing tasks which require human control, and setting criteria for human review of AI-generated content.[12] Given that the use of AI is included in lawyers’ technical independence as part of their autonomy to choose the methods to fulfil their undertakings, the balance between supervision and independence should be addressed in a policy to prevent uncertainty and abuse of power. Challenges to diligence and independence will be even more exacerbated by the introduction of agentic AI in law firms, which is designed to become autonomous and take over tasks traditionally performed by office administrators, assistants and paralegals.[13] The functioning of AI affects the whole firm’s ecosystem and consequently falls into the law firm’s sphere of control; individual lawyers cannot supervise what an agentic AI system does in the place of office administrators, yet their duty of diligence still applies. Law firms should therefore establish a firm-wide supervisory framework to ensure compliance, shifting oversight from individual to system-level assurance, audit mechanisms and risk thresholds.[14]

Transparency and client disclosure obligations

It remains uncertain whether, and to what extent, lawyers should be transparent about their use of AI in light of their autonomy in choosing the methods they use to provide legal services. The use of AI could be considered comparable to the use of legal databases, for which it is not necessary to inform clients. However, lawyers must disclose their use of AI if a client specifically enquires about it or when the client’s consent is required, but practices subject to prior consent can be difficult to determine. Moreover, transparency is guided by the relationship of trust with the client and the context of the undertaking, leaving to lawyers the decision to disclose their use of AI. This creates uncertainty and could lead to disparity, with lawyers automatically disclosing their use of AI and other lawyers being less transparent within the same law firm. Therefore, law firms should clarify this issue with clear guidelines on transparency in the use of AI.

Conclusion

As AI reshapes legal practice, law firms will play an increasingly important role in ensuring that innovation is accompanied by responsibility. AI governance should therefore be viewed not merely as a technology issue, but as an integral aspect of law firm leadership, risk management and professional responsibility. This approach is consistent with the broader direction of international AI governance. The recently released preliminary report of the UN Independent International Scientific Panel on AI emphasises that the responsible development and deployment of AI requires robust governance frameworks, effective accountability mechanisms and coordinated oversight.[15] Looking ahead, the emergence of increasingly autonomous AI systems is likely to shift responsibility further from individual lawyers towards firm-wide governance, oversight and accountability. Law firms that proactively develop clear AI policies, invest in training, strengthen supervisory mechanisms and continually review their business models will be better positioned to realise the benefits of AI while managing its legal, ethical and commercial risks. In doing so, they will not only support their lawyers but also reinforce public confidence in the legal profession during this period of rapid technological change.

Notes


[1] Reena SenGupta, ‘Australian law firms are taking a lead on navigating best use of AI’, FT, 15 May 2026 www.ft.com/content/63e1f03f-9b98-4c02-a268-08e6713bd561?syn-25a6b1a6=1 accessed 4 July 2026.

[2] Marshall C Watson Jr, ‘How AI Is Reshaping the Practice of Law’, ABA, 30 September 2025.

[3] IBA, ‘IBA International Principles on Conduct for the Legal Profession’ (2018 version, updated 2024), www.ibanet.org/document?id=-International-Principles-on-Conduct-for-the-Legal-Profession-2018 accessed 4 July 2026.

[4] Matthew J Bester, Victoria Lageyre, ‘Ethics and Generative Artificial Intelligence in Your Practice’, ABA, 21 May 2026.

[5] Ashley Hallene, Jeffrey M Allen, ‘How to Avoid Accidental Disclosure When Using AI’, ABA, 10 May 2026.

[6] See Explanatory Note 9.2 on Competence in IBA, ‘IBA International Principles on Conduct for the Legal Profession’ (2018 version, updated 2024), www.ibanet.org/document?id=-International-Principles-on-Conduct-for-the-Legal-Profession-2018 accessed 4 July 2026.

[7] See n 1, above.

[8] Ibid.

[9] Anurag Bana, ‘Artificial Intelligence, Legal Professional Negligence and the Rise of AI-Covered Indemnity’, SSRN Electronic Journal, 1 July 2025, https://ssrn.com/abstract=6443021 accessed 4 July 2026.

[10] See n 1, above.

[11] See n 4, above.

[12] See n 5, above.

[14] Ibid.

[15] UN, ‘Independent International Scientific Panel on Artificial Intelligence’, Preliminary Report, 1 July 2026, www.un.org/independent-international-scientific-panel-ai/en/preliminary-report accessed 4 July 2026.