California State Bar Issues 2026 Ethics Guidance on AI Use in Legal Practice
Artificial intelligence is no longer a peripheral tool in law practice; it is embedded in the research platforms, document review systems, and practice management software many lawyers use every day, whether or not those products are marketed as “AI.”1 Against that backdrop, the State Bar of California’s Standing Committee on Professional Responsibility and Conduct (COPRAC) has issued a substantially updated Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, approved by the Board of Trustees in May 2026.23 The 2026 update replaces COPRAC’s original November 2023 guidance and, at the request of the Supreme Court of California, extends the analysis to “agentic” AI systems capable of planning and executing multistep legal tasks with little or no ongoing human direction.4 For lawyers well outside California’s borders, the update is worth close attention. The duties it addresses — competence, confidentiality, supervision, candor, communication, and billing — track the core obligations found in the rules of professional conduct in nearly every state, and California’s guidance is among the most detailed treatment any state bar has produced on how those duties apply to generative and agentic AI.5
From Advisory Guidance to a Broader Regulatory Push
It is worth being precise about what changed and what remains pending. The document COPRAC revised and the Board of Trustees approved in May 2026 is, like its 2023 predecessor, guidance rather than a binding rule — it interprets existing obligations under the California Rules of Professional Conduct and the State Bar Act rather than creating independently enforceable requirements.6 At the same time, California is moving on a second, related track. Acting on an August 22, 2025 directive from the Supreme Court of California, COPRAC separately approved proposed amendments to six rules of professional conduct in March 2026 that would embed AI-specific obligations directly into rule commentary covering competence, client communication, confidentiality, candor, and supervision of lawyers and nonlawyer staff.7 Unlike the practical guidance, those amendments would carry disciplinary weight if adopted, and they were out for public comment as of this spring.8 Lawyers who track only the practical guidance should keep an eye on that parallel rulemaking process, since it is the more consequential development for discipline exposure going forward.
Generative AI, Agentic AI, and the Persistence of Hallucinations
The 2026 guidance carefully separates two categories of technology. Generative AI creates new content — text, images, analysis, or code — in response to a prompt, based on patterns learned from data rather than fixed rules, and it can produce plausible but inaccurate information, including citations to legal authority that does not exist.9 Agentic AI goes further: it can plan, select tools, and execute multistep workflows — revising pleadings across iterations, preparing discovery responses, coordinating document review, or handling client intake — without continuous human prompting.10 COPRAC’s central point is that autonomy does not satisfy a lawyer’s duty of independent judgment, and it may make matters worse: because agentic systems can initiate tasks and interact with external tools on their own, they increase the risk that a lawyer will rely on an automated process without contemporaneous review unless supervisory controls are built into the workflow itself.11
The reliability concerns behind this caution are not theoretical. A Stanford study that tested leading AI-assisted legal research tools — including products from LexisNexis and Thomson Reuters, alongside a general-purpose model — found that even purpose-built legal research tools hallucinated on a substantial share of queries, notwithstanding vendor marketing claims of accuracy.12 Separately, a database tracking reported instances of AI-generated fabrications in court filings had documented nearly 1,300 such episodes in U.S. courts alone (more than 1,870 worldwide) as of August 2026, with sanctions — and in some cases disqualification of counsel — following as courts lose patience with the pattern.1314
Competence: Technological Fluency Without Delegating Judgment
The guidance frames competence as two related duties. First, a lawyer must attain baseline technological competence — a reasonable understanding of a given AI system’s capabilities, data sources, limitations, and material risks — before deploying it in connection with legal services. Second, and more fundamentally, a lawyer must exercise independent professional judgment by reviewing, verifying, and correcting AI-generated output, a responsibility that cannot be delegated to the technology no matter how capable it becomes.15 The guidance is explicit that competence requires more than catching and removing hallucinations after the fact; at its core, it requires that the lawyer, not the AI system, retain control over strategic decision-making.16 It also builds in a moving target: because AI systems evolve through updates and model changes, the duty of competence includes periodically reassessing a system’s capabilities and risks, including whenever it is deployed for a new type of task.17
Confidentiality, Vendor Diligence, and Agentic Access to Firm Systems
Confidentiality raises a distinct set of concerns. Data entered into a generative AI system may be used to train or refine the underlying model or may be shared with third parties, and a breach can occur through prompt content, uploaded documents, or inadequate security — not just deliberate misuse.18 The guidance states that a lawyer must not input a client’s confidential information into a generative AI product that presents a material risk to confidentiality or security absent informed client consent to the underlying risk, and that “reasonable efforts” to protect confidentiality require more than reliance on a vendor’s general marketing assurances. Lawyers must actually review the applicable terms of use, privacy policy, and vendor documentation, and in appropriate cases consult IT or cybersecurity professionals to confirm that a system adheres to adequate security, confidentiality, and data-retention protocols.19
Agentic AI heightens this analysis considerably. Because agentic systems may be configured with persistent or automated access to firm email, document management systems, client files, or calendaring platforms, an unrestricted or poorly configured deployment can unintentionally disclose confidential information — including across unrelated matters — or expose privileged material.20 The guidance places responsibility for configuring and monitoring that access squarely on the lawyer, and it states plainly that a lawyer must not deploy an agentic system in a manner that permits autonomous external transmission of client information, including automated communications, filings, or data transfers, without appropriate safeguards and human review.21
Supervision, Client Communication, and Compliance with Law
Managerial and supervisory lawyers are expected to adopt clear policies governing the use of generative and agentic AI, provide training on the practical pitfalls of tools that operate with limited real-time human direction, and revisit those policies as the technology and its integration into firm workflows evolve.22 Subordinate lawyers, for their part, retain an independent obligation not to use AI tools at a supervisor’s direction in a way that violates their own professional responsibilities.23
On client communication, the guidance ties disclosure obligations to the facts of the representation: a lawyer should consider telling a client that AI will be used, how, and with what risks and benefits, particularly where AI materially affects decision-making in the matter, and must honor any client instructions that restrict or limit AI use.24 Lawyers must also comply with the substantive law implicated by their AI use — privacy law, cross-border data transfer restrictions, intellectual property law, and cybersecurity requirements among them — a reminder that AI adoption is a legal-risk and compliance question, not merely a technology decision.25
Billing for AI-Assisted Work
The guidance takes a pragmatic but firm position on fees. A lawyer may use generative AI to produce work product more efficiently and may bill for time actually spent — crafting or refining prompts, or reviewing and editing AI output — but must not bill a client for time the technology saved.26 Subscription costs for general-purpose AI tools typically constitute firm overhead, similar to library or general computer-system costs, and should not be passed through to clients separately. Costs incurred specifically for a client’s matter, such as per-use fees for specialized tools, may be billed if the fee agreement discloses that practice, the charge reflects actual cost, and no markup is added without the client’s informed written consent.27
Candor to the Tribunal: The Nondelegable Duty
Perhaps the guidance’s most pointed language concerns candor. A lawyer’s duty of candor to the tribunal cannot be delegated to AI, regardless of whether an output was generated with or without real-time human direction, and a lawyer must independently verify and correct any errors or misleading statements before submission to a court.28 For agentic tools used in connection with court filings, the guidance is categorical: no document may be transmitted to a court without lawyer review and approval, and a lawyer must not permit an AI system to autonomously file documents, communicate with a court, or make representations on the lawyer’s behalf.29 That principle is not new in substance — courts have sanctioned lawyers for submitting fabricated AI-generated citations since at least the widely publicized Mata v. Avianca matter in 202330 — but the 2026 guidance makes explicit what many lawyers still treat as optional: personally reading and verifying every citation before it goes into a filing.
Practical Implications for Law Firms
For firms translating this guidance into practice, several steps follow directly from its structure. First, firms should inventory the AI tools already in use across research, drafting, document review, billing, and intake, including AI features embedded in existing platforms that were never formally “adopted,” because the duty of competence attaches regardless of whether a tool was deliberately selected. Second, firms should develop a short, plain-language AI use policy that distinguishes between low-risk uses, such as general legal research with human verification, and higher-risk uses, such as agentic tools with access to client data or the ability to communicate externally, and calibrate supervision and verification requirements accordingly. Third, before adopting any tool that will process confidential client information, firms should build in actual review of the vendor’s terms of use, privacy policy, and data-retention practices, rather than relying on a sales team’s assurances, and should document that review. Fourth, firms should build citation verification into the workflow for any AI-assisted filing as a nonnegotiable step rather than a discretionary one, given how easily fabricated authority can survive a cursory read. Fifth, firms should revisit engagement letters and outside counsel guidelines to address whether and how AI use will be disclosed to clients, particularly institutional clients that increasingly impose their own AI restrictions on outside counsel. Sixth, managing partners and general counsel should treat AI governance as a living policy area requiring periodic reassessment rather than a one-time adoption decision, given how quickly both the underlying tools and the regulatory guidance addressing them continue to change.
Multi-Jurisdictional Practice Considerations
Lawyers licensed in multiple states face an added layer of complexity, since AI-specific guidance is developing unevenly across jurisdictions. The American Bar Association addressed generative AI at the national level in Formal Opinion 512, issued in July 2024, which covers competence, confidentiality, communication, candor, supervision, and fees under the ABA Model Rules and has informed much of the state-level guidance issued since.31 Arizona, where I am licensed, has issued its own guidance addressing generative AI under the Arizona Rules of Professional Conduct, with an emphasis similar to California’s on competence and confidentiality.32 Mississippi, where I have practiced for more than two decades, has not yet issued comparable formal guidance specific to generative or agentic AI, leaving Mississippi lawyers to apply the existing rules of professional conduct without state-specific interpretive guidance — a reminder that a technology-neutral rule of professional conduct still applies in full even in the absence of a technology-specific opinion.
Because the underlying ethical duties are substantially uniform across jurisdictions even where formal AI guidance is not, the more detailed guidance issued by states like California and Arizona is useful persuasive authority for lawyers practicing under rules that have not yet been supplemented with AI-specific commentary. Firms and in-house AI governance functions — particularly those working across the insurance sector, where AI-driven underwriting, claims handling, and litigation-support tools raise parallel confidentiality, bias, and vendor-diligence questions — should treat the California guidance as a practical benchmark even where it does not directly govern, since regulators and courts elsewhere are likely to look to it as AI-related disputes and disciplinary matters increase.
Conclusion
California’s 2026 Practical Guidance does not create new ethical obligations so much as it maps existing ones — competence, confidentiality, supervision, communication, billing, and candor — onto a technology that is evolving faster than the rules meant to govern it. The parallel effort to embed AI-specific obligations into binding rules of professional conduct suggests California, and likely other states, will move from advisory guidance toward enforceable requirements over time.33 For lawyers integrating AI into practice management or client work, regardless of where they are licensed, the practical message is the same: the technology can assist, but it cannot absorb the lawyer’s judgment, verification responsibilities, or accountability for the final product.