Small business team reviewing company policies together.
Policy Management
Governance
August 20, 2026
15 Minute Read

Law Firm AI Use Policies: What Is Actually Required, and What’s Coming

Imogen Eden
CEO

Summary:

  • ABA Formal Opinion 512 requires managerial lawyers to establish clear policies on the firm’s permissible use of generative AI. Supervisory lawyers must also make reasonable efforts to ensure that the firm’s lawyers and non-lawyers comply with their professional obligations when using generative AI (GAI) tools.
  • New York’s Part 161 puts that duty into practice at the court level: it permits AI use in preparing court papers and expressly does not require disclosure of that use of AI. Verification and certification are optional, left to individual courts to adopt on a court-by-court basis, not imposed state-wide.
  • Malpractice underwriting has not caught up with widespread AI use yet. Some carriers now ask about AI use as part of underwriting, but this is confirmed at only a handful of carriers, not an industry-wide requirement.
  • Underwriting requirements on AI use are likely to tighten over time. Cyber insurance underwriting moved from taking firms at their word that security controls were in place to requiring proof of those controls. Some expect legal malpractice underwriting to move in a similar direction, with a documented AI policy along with supporting evidence like proof of policy acknowledgement, training records, usage logs, and verification protocols becoming similar proof points. But, this is a prediction, not yet a reality.

What does ABA Formal Opinion 512 require?

Formal Opinion 512, issued by the ABA Standing Committee on Ethics and Professional Responsibility on 29 July 2024, requires managerial lawyers to establish clear policies regarding the firm’s permissible use of generative AI, and supervisory lawyers to make reasonable efforts to ensure lawyers and nonlawyers comply. It creates no new rules. It reads the existing Model Rules onto a new tool (GAI): competence (1.1), communication (1.4), fees (1.5),confidentiality (1.6), candour to the tribunal (3.3) and supervision (5.1 and 5.3).

The important qualification here is that the opinion is advisory. It doesn’t bind any lawyer until the underlying rules are adopted in a jurisdiction, and no state has yet formally adopted Opinion 512 itself. More than 20 jurisdictions have issued their own AI guidance instead, generally building on Opinion 512’s framework. They differ mainly on the subject of client disclosure: Florida and North Carolina lean toward requiring or recommending it, while Texas and the New York City Bar leave it to lawyer judgment, with the NYC Bar going as far as confirming that routine embedded tools like Westlaw and Lexis need no disclosure at all. Regardless of jurisdiction, the lawyer remains answerable for the output from generative AI tools.

What does New York’s Part 161 require?

Less than its reputation suggests.

22 NYCRR Part 161 took effect 1 June 2026, applying to all Unified Court System courts. It permits AI use in preparing court papers and does not require attorneys to disclose their use of AI.

The real substance sits in Appendix A, an optional model rule under which an attorney certifies, by signature, that they’ve reviewed a paper and found no fabricated cases or authority. Courts adopt it at their own discretion, so practitioners will need to check their judge. But, this isn’t a new duty: the same verification obligation already existed under 22 NYCRR130-1.1 and Rule 3.3. Part 161 just makes it explicit.

The pressure driving courts toward Appendix A adoption is real. Damien Charlotin's public database, which only counts cases where a judge actually caught and wrote up an AI hallucination, tracks such rulings by the thousand and grows weekly. Eugene Volokh, using that data, found 17 US decisions flagging suspected hallucinations on a single day: 31 March 2026. The database itself traces back to Mata v. Avianca, Inc. (S.D.N.Y. 2023), the first widely reported case of its kind, where Judge Castel sanctioned two attorneys and their firm $5,000 for citing AI-fabricated cases.

Are malpractice carriers asking about AI?

Some are. AmTrust’s lawyers professional liability form asks firms to confirm whether they allow AI software to draft documents and, if so, to attach a description. Per a primary-source review by Legal AI Governance, that was the only verifiable AI question located on a US LPL application form as of April 2026.

However, in Insurance Journal's Independent Agent (IA) Magazine on 9 March 2026, Sean Burke of the wholesale specialist Jencap said agents should prepare their law firm clients for underwriters asking how they use AI, though he suggested this scrutiny is still fairly light-touch for now. Stan Sterna of Aon, who administers the AICPA Member Insurance Program and leads risk control for accounting and law firm professional liability forecasted, from his vantage point close to the underwriting process, that he expects carriers will start asking client firms more questions about AI at renewal as scrutiny increases. Namely, whether they have an AI policy, communicate the policy, train people on it, and have oversight of AI usage.

Does malpractice insurance cover AI mistakes?

Usually the policy does not say. At least at this stage.

Most LPL policies are silent on AI. Even though these policies renew annually, most carriers haven't added AI-specific language yet, so the same general wording just keeps carrying over. If a claim involving AI arises, the outcome depends on how a court interprets that pre-existing language, since nothing in it explicitly addresses AI one way or the other.

As of May 2026 no major US LPL writer had publicly filed an explicit AI exclusion on its named LPL form. The filed exclusions sit on adjacent lines: W.R. Berkley's absolute AI exclusion (form PC 51380) on management liability, Hamilton Select on professional liability paper, and ISO's general liability endorsements effective 1 January 2026. None of these attach to the LPL policies law firms actually carry.

That silence may not last. WTW's Insurance Marketplace Realities 2026 report, an industry research publication rather than trade-press commentary, describes the period from January 2025 to January 2026 as a "structural break" in the professional liability market. It's a description of a shift already underway rather than a firm prediction of when LPL-specific AI language will land, but it's a signal from a credible source that the current silence in LPL forms is unlikely to hold indefinitely.

A small market for affirmative AI coverage, insurance that explicitly agrees to cover AI-related claims, has started to emerge. For law firms specifically, Armilla AI (underwritten through Lloyd's syndicate Chaucer and Axis Capital) offers this as a separate product sold alongside a firm's existing LPL policy, not a replacement for it – noting that it covers things like hallucinations and model drift, rather than being purpose-built for law firm malpractice risk specifically.  Insurers offering AI insurance typically require firms to complete a documented AI risk assessment and show governance practices are in place before they'll bind the policy. In practice this means that firms need a written AI policy, training records, and usage logs to qualify for coverage: aspects of which can be achieved with policy management tooling, such as Dayspring Software.

Are law firms actually required to have an AI policy?

Not as a matter of binding law, in any US jurisdiction.

But three separate pressures are pushing law firms towards having a documented AI policy anyway:

  1. ABA Formal Opinion 512 requires it directly: managerial lawyers must establish clear policies and supervise compliance across lawyers and nonlawyers alike.
  2. New York’s Part 161 doesn’t require a policy outright, but it does require individual attorneys to personally verify and certify their filings. That’s far easier to do consistently if the firm has a documented policy and process behind it.
  3. Insurers’ underwriting questions add the third push, as carriers increasingly ask what AI governance a firm has in place before binding a policy.

Professional obligations of this kind rarely arrive first as a legislative requirement. They arrive faster through contract terms and underwriting conditions, which can take effect in months rather than years. Client outside counsel guidelines are likely to move first, since they already ask about a firm’s policies and security practices. Insurance is likely to follow.  

The insurance path also has a recent parallel. Over the last five years, cyber underwriting moved from firms simply stating that they were secure to needing verified evidence of their security practices to get coverage, once losses started to accumulate. Loss data is now accumulating in AI, too. EPIC’s 16th Annual LPL Claims Survey found that 7 of 13 insurers reported year-on-year increases in AI-related claims, and the count of court decisions catching fabricated citations keeps climbing. But, several factors could stall AI-related changes to underwriting. Cyber insurance requirements hardened in response to catastrophic, aggregated losses that legal malpractice hasn't experienced.AI-related malpractice, so far, largely looks like ordinary lawyer error in new clothing, something existing cover already contemplates. And as things stand, no carrier has filed an AI exclusion on an LPL form.

Should law firms create and adopt an AI policy?

Yes. Strip away the speculation and a modest but solid conclusion remains: firms already have a supervision duty that contemplates policies and training, courts increasingly ask whether a human verified the output, and carriers are likely to ask more AI governance questions at renewal. Taken together, these signals point the same way. Law firms should put a firm-wide AI policy in place now, rather than wait for legislation or a regulator to make it mandatory.

A documented policy is only as useful as the records behind it. Firms need to show who owns the policy, when it was last reviewed, and that it's actually been communicated to staff, not just written and filed away. That's the difference between a policy that protects a firm and one that just exists in SharePoint or Google Drive.

Policy management tooling, like Dayspring Software, can help firms keep these records organized and demonstrably up to date, making that proof easy to produce when a client, underwriter, or court asks for it.

FAQs:

Does a law firm need a written AI policy?

No US jurisdiction legally mandates one yet. But three pressures point the same way: ABA Formal Opinion 512 requires managerial lawyers to establish clear AI policies and supervise compliance, New York's Part 161 requires attorneys to verify and certify filings (which is easier to prove consistently with a documented policy behind it), and malpractice insurers are increasingly asking about AI governance at renewal. In practice, a written policy, with clear ownership, review dates, and proof it's been communicated to staff, is the standard way firms meet all three at once.

Is ABA Formal Opinion 512 binding?

No. It is advisory, issued 29 July 2024, and no US jurisdiction has adopted it as binding law. It carries persuasive authority and is widely cited by state bars, but it binds no lawyer unless and until a jurisdiction adopts it.

Does New York require disclosure of AI use in filings?

No.22 NYCRR Part 161, effective 1 June 2026, expressly states that attorneys are not required to disclose when they've used AI to prepare a court paper. What individual courts can require instead is different: Part 161's Appendix A offers an optional model rule that courts may adopt, under which an attorney's signature certifies the paper contains no fabricated cases, statutes, or other material. That's a certification of accuracy, not a disclosure of AI use, and it only applies in courts that have chosen to adopt it.

Do malpractice insurers ask about AI at renewal?

Some do, but it's not yet standard practice. AmTrust's lawyers professional liability application is the only US LPL form with a confirmed, verbatim AI question, asking firms to confirm whether they allow AI to draft documents. Beyond that, brokers report underwriters are increasingly asking informally how firms use AI and whether they have governance in place, though this varies by carrier and isn't yet a fixed part of most renewal applications. As of May 2026, no major LPL carrier has filed an AI-specific exclusion on its policy form, so coverage for AI-related claims still depends on existing policy language rather than new AI-specific terms.

Does malpractice insurance cover AI-related claims?

Usually, but the policy doesn't say so directly. Most lawyers’ professional liability(LPL) policies are silent on AI, so coverage for an AI-related claim depends on how a court interprets pre-existing policy language, not on any AI-specific term. As of May 2026, no major US LPL carrier had filed an explicit AI exclusion on its policy form, so silence currently favors coverage rather than working against it. That said, AI exclusions already exist on adjacent policy types(management liability and general liability), which signals where the market may be heading. A small affirmative AI insurance market has also emerged, sold as an add-on to a firm's existing LPL policy, though insurers offering it typically require a documented AI risk assessment and governance practices before they'll bind the policy.