ABA guidance addresses lawyers’ use of generative AI under existing professional-responsibility duties.
ABA Standing Committee on Ethics and Professional Responsibility · verified 2026-09-22Industry / Legal
AI security assessment for Legal
Protect client information and govern AI across research, drafting, discovery, knowledge, and firm operations.
01 / CONTEXT
AI security in legal practice starts with confidentiality, supervision, and control of the toolchain.
Generative AI can touch confidential client information, legal research, drafting, discovery, and other workflows where professional duties remain with the lawyer. ABA Formal Opinion 512 states that lawyers using generative AI must consider duties including competence, confidentiality, communication, supervision, candor, and reasonable fees.
That makes AI governance in a legal environment more than a generic technology-policy exercise. Firms need to understand which tools are used, what client or matter information reaches them, how outputs are verified, what contractual and technical protections apply, and where human review remains mandatory.
Ayliea’s legal assessment focuses on those security and governance boundaries. It does not provide legal advice or determine professional-responsibility compliance; it documents the technical controls, data flows, vendor dependencies, and evidence that counsel can evaluate in the context of the firm’s obligations.
02 / Current signals
What shapes the review.
Primary-source requirements and guidance establish the context. The engagement still follows the actual system, data, and use case in scope.
Competence remains relevant when lawyers select, understand, and use generative AI tools.
ABA Formal Opinion 512 · verified 2026-09-22Protection of information relating to client representation remains a central consideration in AI use.
ABA Formal Opinion 512 · verified 2026-09-2203 / Requirements & frameworks
Map evidence to the environment around the AI.
Frameworks are not treated as interchangeable certifications. Ayliea uses the requirements and guidance that actually belong in the engagement scope.
ABA Formal Opinion 512
ABA ethics guidance identifies competence, confidentiality, communication, supervision, candor, and reasonable fees among the professional duties lawyers should consider when using generative AI.
ABA Model Rules
Existing professional-responsibility duties continue to apply when lawyers use AI. Exact obligations and interpretations depend on jurisdiction and circumstances.
Client & matter requirements
Engagement terms, protective orders, client security requirements, confidentiality commitments, and matter-specific restrictions can shape acceptable AI use.
Security frameworks
Technical assessment can map controls to cross-sector security and AI-risk frameworks while leaving legal and ethics conclusions to qualified counsel.
04 / Assessment surface
What we examine in Legal.
The exact procedures are scoped to the organization. These are common areas that shape evidence requests and assessor judgment.
Client Confidentiality in AI Workflows
Map where information relating to client representations enters generative AI, research, drafting, discovery, summarization, or other AI-enabled tools and evaluate the technical and contractual safeguards around that data.
AI Vendor Due Diligence
Review provider terms, retention and training behavior, tenant isolation, access controls, subprocessors, security evidence, and enterprise configuration so the firm can make an informed decision about approved tools and data types.
Matter & Access Boundaries
Assess whether AI-enabled systems preserve appropriate matter, client, workspace, and role boundaries and whether integrations or agents can reach repositories beyond what a user or workflow actually needs.
Output Verification & Human Oversight
Document how AI-generated research, citations, drafting, summaries, and recommendations are checked before reliance, filing, client delivery, or other consequential use.
AI Use Policy & Supervision
Evaluate whether approved tools, prohibited data, review expectations, training, exception handling, and supervision responsibilities are documented and operational rather than left to individual judgment.
Incident & Disclosure Readiness
Review the firm’s ability to investigate accidental disclosure, compromised AI accounts, unsafe integrations, or vendor incidents and to route legal, client, insurance, and professional-responsibility questions to the appropriate decision-makers.
05 / Common review needs
Start with the problem you are actually trying to solve.
These focused pages go deeper on common security and diligence questions in this industry.
06 / OUTPUT
Evidence a reviewer can interrogate.
Ayliea documents the systems reviewed, evidence examined, findings, limitations, framework mappings, remediation priorities, and accountable human review. The report is designed to support diligence and internal risk decisions—not to substitute for legal advice or a regulator’s determination.
AI system inventory
Data-flow & boundary review
Evidence references
Findings & limitations
Industry-relevant mappings
Remediation priorities
Accountable sign-off
07 / SCOPE THE WORK
Start with the AI system and the evidence you already have.
We will determine whether an independent assessment fits the review, customer, compliance, or security question you need to answer.