ABA Opinion 512 and the Law Firm AI Policy
Formal Opinion 512 does not ban generative AI for lawyers. It requires informed consent before client information goes into a self-learning tool, which turns a firm AI policy into a question about what leaves the machine. Here is what the opinion asks and how a policy answers it.
In short
Boilerplate consent in an engagement letter does not satisfy Rule 1.6: the lawyer must explain the specific risk, what information would be disclosed, and how disclosure could work against the client's interests. Stripping identifying material before the paste is the mitigation the opinion points at, because the obligation attaches to inputting information that identifies a client. Opinion 512 also reaches competence and independent verification under Rule 1.1, client communication under Rule 1.4, and firm supervision of lawyers and nonlawyers under Rules 5.1 and 5.3.
The American Bar Association published Formal Opinion 512 on 29 July 2024, its first comprehensive ethics guidance on lawyers using generative AI. It is worth reading in full because it is more useful than its reputation suggests. It does not ban anything. It maps existing Model Rules onto a new tool and, in doing so, converts a vague worry about AI into a specific and answerable question: what happens to the text after you paste it.
What Rule 1.6 requires before a paste
The confidentiality analysis is the part that changes how a firm operates. Rule 1.6 obliges a lawyer to keep confidential all information relating to the representation, not merely information a client marked confidential. Opinion 512 reasons that because many current generative AI tools are self-learning, meaning inputs can feed back into the model and surface in output to other users, sending client information into such a tool risks disclosure. Its conclusion is that a client's informed consent is required before information relating to the representation goes into a self-learning tool.
Informed consent is a higher bar than it sounds. The opinion is explicit that a boilerplate clause in an engagement letter does not carry it. Consent has to be informed, which means the lawyer explains the specific risk, what information would be disclosed, how that disclosure could work against the client's interests, and what the benefit of using the tool actually is. A firm that reads this and concludes it needs a new paragraph in its retainer template has misread it.
The way out the opinion leaves open
That framing is what makes the opinion practically useful rather than merely cautionary, because it points at a way out. The obligation attaches to inputting information relating to the representation. Opinion 512 tells lawyers to consider the sensitivity of the information and the likelihood of disclosure before entering anything, and commentary on the opinion consistently lands on the same mitigation: strip the identifying material before it goes in. If what reaches the tool contains nothing relating to an identifiable client, the disclosure the consent requirement is guarding against has not occurred. The prompt still gets the legal question. The tool never gets the client.
There is a second route the opinion leaves open, and firms with the appetite for it should take it seriously: the analysis turns on the tool being self-learning and on inputs being retained or reviewed. A tool that runs entirely on the lawyer's own hardware, retains nothing, and sends nothing anywhere presents a different question, because there is no third party for the information to be disclosed to. Evaluating that is a competence question under Rule 1.1 and its comment on technological competence, which asks a lawyer to understand the benefits and risks of the technology they use, and to keep that understanding current. Reading a vendor's terms of use, privacy policy and retention terms is not optional diligence here. It is the diligence.
The other rules in play
Confidentiality is not the only rule the opinion touches, and the others are easy to underrate. Competence under Rule 1.1 requires independent verification of output, which is the answer to a now well-documented category of sanction where fabricated citations reached a court. Rule 1.4 governs when and how a lawyer must tell a client that AI was used. Rules 5.1 and 5.3 put supervisory duties on the firm for both lawyers and nonlawyers, which is why an AI policy has to be a policy and not a partner's personal practice. And Rules 1.5 and the fee guidance address the awkward question of billing for time a tool saved.
Three questions a firm AI policy has to answer
So what does this actually mean for a firm AI policy. In practice the opinion collapses into three questions a policy has to answer in writing, and the third is the one most drafts skip.
First, which tools are approved, and on what basis. Not a list of names, but the criteria: whether inputs train the model, whether they are retained, whether humans review them, whether the vendor's terms actually say so, and who at the firm checked. That record is what turns a choice into diligence.
Second, what may be entered into each approved tool. This is where a policy either works or becomes decoration. A rule saying "do not enter confidential information" is not a control, because it asks a person on a deadline to make a judgement call correctly every single time, and the failure is invisible when they do not. A rule saying which categories must be stripped before any paste, backed by something that performs the stripping, is a control.
Third, what happens at the moment of the paste. This is the gap. Approved-tool lists govern the tool. Consent language governs the client relationship. Neither reaches the instant when someone highlights four lines of a client file, copies, switches to a browser tab the firm does not manage, and pastes. No file moved, so file-centric monitoring sees nothing. A policy that stops one step short of that moment is governing everything except the event it exists to prevent.
Where the paste itself gets governed
That gap is the reason Omit Protect exists and the reason it is free for everyone, permanently, with no licence. It watches the clipboard, detects personal information in what is about to be pasted, and replaces it with numbered placeholders before it leaves the machine. The lawyer keeps the drafting help. The client's name, matter details and identifiers do not travel. It runs entirely offline, so the guard itself is not a new disclosure risk, which would otherwise be a fairly obvious problem with a tool built to solve this one.
For the document side, Omit Redact handles filings, exhibits and discovery material on the same engine, including the four Rule 5.2 identifier categories with the partial treatments that rule actually requires. That workload is covered separately in our post on redacting a court filing under Rule 5.2, and the terminology underneath all of it, since Opinion 512 uses "anonymize" loosely and the distinction matters, is in redaction versus anonymization versus pseudonymization.
What software cannot do
One caveat we would rather state than have you infer. Nothing here is legal advice, and a tool cannot deliver compliance with a rule that assigns the duty to a lawyer. Opinion 512 is guidance, state bars have issued their own with meaningful variations, and the informed consent question in particular turns on facts about your matter and your jurisdiction. What software can do is make the safe path the default one, so that the policy you wrote describes what people actually do rather than what you asked them to remember.