Skip to content

Duties

Five areas that shape every engagement

Our work is organized around frameworks including ABA Formal Opinion 512 and guidance issued by state bars, including the California State Bar. We use them to structure practical governance work, not to provide legal interpretations.

Competence

Competent representation now includes understanding what a generative AI tool does, how it can be wrong, and where its output must be checked. We build that understanding into training rather than leaving it to individual curiosity.

Confidentiality

Before any client information reaches a tool, we establish where that data is stored, whether it is used for training, who at the vendor can access it, and how long it is retained. Workflows are designed so unvetted tools never see client data.

Supervision

Supervisory duties extend to work produced with AI assistance. Every workflow we design names a reviewer and a review standard, so output is never filed, sent, or relied on without a lawyer taking responsibility for it.

Communication

Firms should be able to answer a client's question about how AI is used on their matter. We help you decide what to disclose, when consent is appropriate, and how engagement letters should describe your practice.

Reasonable fees

When work gets faster, billing practices have to keep pace with the duty of reasonableness. We help firms think through billing for AI-assisted work and how any tool costs are presented to clients.

Firms retain responsibility for their own professional judgment. We work alongside your firm's ethics counsel or general counsel where appropriate.

Security

Data security and vendor due diligence

A tool is only as safe as the terms behind it. We assess vendors against a consistent checklist before anything touches a live matter, and we re-run that review when a vendor changes its terms.

  • Data residency, retention, and deletion terms
  • Whether inputs are used to train models
  • Encryption in transit and at rest
  • Authentication, access controls, and audit logging
  • Subprocessors and where they sit
  • Security certifications and incident history
  • Contractual confidentiality and indemnity terms
  • Exit terms and data portability

Governance is a practice, not a document.

Book a Consultation