Generative AI in the Law Office: Managing the Risks
9.21.2026

Prepared by Aaron M. Barham of the New York City-based law firm of Furman Kornfeld & Brennan LLP on behalf of the NYSBA Insurance Program
Generative artificial intelligence (AI) tools have moved rapidly in recent years from novelty to a regular feature of legal practice. Lawyers may encounter AI whether or not they choose to use it themselves—through general-purpose chatbots, legal-research platforms, document-management systems, and everyday workplace software, as well as in work product and communications from clients, opposing counsel, experts, and others. These tools can assist with tasks ranging from drafting motions and contract clauses to reviewing and summarizing dense documents. Their speed and apparent sophistication make them particularly attractive to busy practitioners, especially in high-volume practice areas.
However, lawyers must proceed carefully. The risks of using AI tools include technical errors, ethical violations, reputational harm, and malpractice exposure. This article identifies the safeguards lawyers and law firms should implement before using AI in client work. It does not endorse any particular AI tool or use case.
Why Lawyers Are Using AI
Generative AI tools can instantly produce drafts, summaries, research leads, and other work product that appear competent at first glance. For attorneys facing tight deadlines or heavy workloads, these tools may offer meaningful assistance with routine and time-consuming tasks. But appearances can be deceiving. AI can generate remarkably fluent work, but it does not exercise professional judgment or accept responsibility for its conclusions. Its outputs are probabilistic and may be incomplete, outdated, biased, jurisdictionally incorrect, or simply fabricated. Lawyers who mistake fluency for reliability risk flawed analysis, client harm, reputational damage, and malpractice exposure.
The Risks: Beyond Hallucinated Cases
High-profile incidents of attorneys being sanctioned for submitting AI-generated briefs with non-existent cases have been widely publicized. While these cases highlight the embarrassing and severe consequences of relying uncritically on AI, they represent only the most visible risks.
The deeper and potentially more damaging risks include:
- Propagation of Errors: An AI-generated mistake, such as a misinterpreted statute or flawed legal analysis, can serve as the foundation for further drafting, embedding itself into additional sections of a document or future client work. Once accepted, these errors can quietly spread, compounding over time and undermining the integrity of legal advice or filings.
- Loss of Legal Judgment: Overreliance on AI, particularly among junior attorneys and law students, can erode critical legal skills such as issue-spotting, factual analysis, strategic thinking, and contextual interpretation of the law.
- Confidentiality Breaches: Entering client information into an AI system without understanding its terms, settings, access controls, retention practices, training practices, and security protections may violate a lawyer’s confidentiality obligations. The risks can differ materially between public consumer tools and enterprise or legal-industry systems with appropriate contractual and technical safeguards.
- Transactional Mistakes: Lawyers outside litigation, such as estate planners, transactional attorneys, or compliance specialists, may inadvertently introduce outdated, jurisdictionally incorrect, or otherwise flawed terms into client documents due to AI-generated content.
- Billing and Client-Communication Issues: Lawyers who use AI must ensure that their fees remain reasonable and, when billing hourly, that their bills accurately reflect the time actually spent. They must also consider whether a particular use of AI should be disclosed to the client or requires the client’s informed consent.
These risks expose lawyers to malpractice, client harm, and reputational damage—often before the underlying errors are even detected.
Essential Risk Management Considerations
For law firms that are using or evaluating AI, several fundamental risk-management steps must be considered:
- Independent Verification: AI-assisted work must receive human review commensurate with the task and the risks involved. Every legal authority, quotation, and material factual assertion should be checked against reliable sources, and every final court submission should be carefully reviewed. The lawyer must confirm that each authority exists, is current, applies in the relevant jurisdiction, and actually supports the proposition asserted.
- Confidentiality and Privacy: Before entering client information, firms must understand how the particular tool stores, processes, retains, and uses that information; who may access prompts and outputs; and whether the information may be used to train a model. Confidential information should not be entered unless the firm has determined that the tool and the proposed use provide appropriate protection.
- Maintain Human Judgment: AI should never replace legal judgment. These tools do not possess human reasoning, ethical insight, or understanding of client nuances. The lawyer remains responsible for the strategy, advice, analysis, and final work product, regardless of how much assistance an AI tool provided.
- Supervision and Policy Controls: Firms choosing to use AI must have robust internal policies outlining who can use such tools, under what circumstances, and with what oversight. Policies should identify approved tools and permissible uses; address confidential information; require appropriate review; and provide for training and supervision of attorneys and nonlawyers. If a firm lacks the technical knowledge or resources to enforce adequate controls, it should restrict or prohibit AI use until those controls are in place.
- Current Ethical and Court Requirements: Although the New York Rules of Professional Conduct do not specifically regulate AI, existing duties of competence, confidentiality, communication, supervision, candor, and reasonable fees apply fully to AI-assisted work. The NYSBA Task Force on Artificial Intelligence’s April 2024 Report and Recommendations and New York City Bar Formal Opinion 2024-5 each address these duties in the context of generative AI. In New York, 22 N.Y.C.R.R. Part 161, effective June 1, 2026, establishes a statewide policy providing that attorneys and parties should not be prohibited from using AI to prepare court papers, provided they comply with their existing duties and responsibilities. Part 161 does not impose a general disclosure requirement, but its Appendix A contains a model rule that individual courts and judges may adopt. Under that model rule, an attorney or party who uses AI to prepare a paper certifies, by signing the paper, that it was carefully reviewed and contains no fabricated or fictitious cases, statutes, or other material. A court that finds otherwise may impose sanctions or other remedial action. Litigators should therefore review both the statewide rule and the assigned judge’s current Part rules.
- A Strong Malpractice Insurance Policy: In addition to the steps above, check with your insurance provider to learn what your malpractice policy covers. It may be less than you think.
Conclusion: Exercise Informed Caution
AI tools present substantial risks, but they are no longer novel or confined to early adopters. For firms that permit AI, sound risk management requires controlled and informed use: selecting an appropriate tool for a defined task, protecting client information, verifying material output, maintaining human judgment, and supervising everyone who uses the technology. A firm that lacks the knowledge or resources to implement those safeguards should restrict AI use to clearly defined, low-risk tasks—or prohibit its use until adequate controls are established.
Even with safeguards, human nature tends toward convenience. Under time pressure or heavy workloads, lawyers may skip critical checks or lean too heavily on AI-generated output—choosing the path of least resistance rather than the harder work of thoughtful, detailed analysis. Over time, this not only increases the risk of unchecked errors but also erodes the judgment and reasoning skills that are essential to sound legal practice.
The practice of law remains a fundamentally human endeavor built upon judgment, care, and ethical responsibility. These qualities should not be outsourced to artificial intelligence. While AI may assist the lawyer, it cannot assume the lawyer’s professional obligations.
This article was prepared by Aaron M. Barham of the New York City-based law firm of Furman Kornfeld & Brennan LLP. Aaron is part of a team of over 40 lawyers and paralegals devoted to the defense of attorneys and other professionals in malpractice and disciplinary matters, as well as the defense of construction and personal-injury accidents. For more information about the above topic or the author, please visit www.fkblaw.com.
We trust that the above article was useful and thought-provoking; however, please note that it is intended as a general guide and opinion only, not a complete analysis of the issues addressed, and readers should always seek specific legal guidance on particular matters.
About the NYSBA Insurance Program and USI Affinity
The NYSBA Insurance Program was designed to meet the risk management needs of NYSBA members for both professional and personal coverage. The program is administered by USI Affinity, a national leader in designing malpractice insurance solutions for over 22,000 law firms nationwide. While you specialize in a specific area of practice, USI Affinity specializes in insurance. The NYSBA Insurance Program from USI Affinity offers a proprietary, comprehensive Lawyers Professional Liability program specifically designed to mitigate risk and close gaps in coverage for NY attorneys.
For more information, visit nysbainsurance.com.

