AI Agents for Lawyers: Research, Drafting and Duty of Care
AI agents for lawyers are useful for first drafts, summaries, research leads and matter task lists, and every one of those stays the lawyer’s work product. What each job looks like, what ABA Formal Opinion 512 asks on competence, confidentiality, communication and fees, what fabricated citations have cost lawyers in court, and how to keep client information safe with connected tools.
7 min read
AI agents for lawyers are most useful on four jobs: first drafts from the firm’s own precedents, summaries of long documents, research leads that a lawyer then verifies, and matter task lists. In each, the agent prepares and the lawyer decides, and the output stays the lawyer’s responsibility as fully as if a junior had written it. ABA Formal Opinion 512, issued July 29, 2024, applies the existing Model Rules to generative AI: competence, confidentiality, communication with clients, and reasonable fees. Courts have already sanctioned lawyers for filing citations an AI tool invented. The rule that follows is simple: every citation is pulled and read by a person before anything is filed or sent.
This page is about a US law practice. The general method for checking an agent’s output, from evidence to sampling, is in verifying AI-generated work; a contract review example sits among the human-in-the-loop AI examples.
Four jobs worth handing over
1. First drafts
Engagement letters, routine motions, discovery requests, standard clauses. The agent starts from the firm’s own templates and precedents, not from a blank page, and marks every place it departed from them or had to assume a fact. The lawyer edits and signs. A draft built from your precedents is easier to check than one built from the model’s general idea of what such a document says.
2. Summaries
Deposition transcripts, document productions, contracts, a long chain of correspondence. Ask for a summary that cites the page and line, or the document and paragraph, for every point, so the lawyer can check any sentence in seconds. A summary without pin cites is a summary nobody can rely on.
3. Research with verified citations
Treat an agent’s research as leads, not authority. It can suggest lines of argument, search terms and cases worth reading. Every case, statute and quotation is then pulled from a trusted source and read by a person, who confirms that it exists, says what the draft claims, and is still good law. NIST’s Generative AI Profile, NIST AI 600-1 (opens in a new tab), names the risk “confabulation” and warns that outputs may include “confabulated logic or citations that purport to justify or explain the system’s answer.” A fluent paragraph with a wrong citation reads exactly like a right one.
4. Matter task lists
After an intake call or a hearing, the agent turns the notes into a list of next steps for the matter: documents to request, research to run, drafts to prepare, questions for the client. The lawyer confirms the list. Court deadlines and limitation dates stay in your docketing and calendar system, where they are checked by the people responsible for them.
ABA Formal Opinion 512 in plain words
This is a plain-language summary, not legal advice. Opinion 512 interprets the ABA Model Rules; the rules that bind you are your own jurisdiction’s rules of professional conduct and its bar’s opinions, so read those too.
- Competence (Model Rule 1.1): understand the capabilities and limitations of the tools you use, and keep that understanding up to date. Review the output with the care the matter needs.
- Confidentiality (Model Rule 1.6): know how the tool uses the information you give it, and have safeguards so it is not disclosed to others. The opinion says informed client consent is required before information relating to a representation goes into a self-learning tool, and that boilerplate consent in an engagement letter is not enough.
- Communication (Model Rule 1.4): even where Rule 1.6 does not require consent, consider whether the client should be told how AI is being used on their matter.
- Fees (Model Rule 1.5): fees must be reasonable. Hourly billing covers the time actually spent, and a lawyer generally may not bill clients for time spent learning a tool they will use across matters, unless the client asked for that particular tool.
The opinion also covers meritorious claims and candor toward the tribunal: before submitting anything, review the AI output, including its analysis and citations, and correct errors. And it covers supervision: lawyers with managerial duties should set clear policies on permitted use and make sure lawyers, staff and outside providers are trained. An agent is closest to a very fast nonlawyer assistant: its work is yours once you use it.
What fabricated citations have cost
The best-known case is Mata v. Avianca in the Southern District of New York. In its opinion and order on sanctions of June 22, 2023 (opens in a new tab), the court found that the lawyers “submitted non-existent judicial opinions with fake quotes and citations created by the artificial intelligence tool ChatGPT”, then stood by them after the court questioned their existence. It imposed sanctions on the individual lawyers under Rule 11 and, because Rule 11 holds a firm jointly responsible for its lawyers absent exceptional circumstances, on the firm as well.
The court was careful about what it was not saying: “there is nothing inherently improper about using a reliable artificial intelligence tool for assistance. But existing rules impose a gatekeeping role on attorneys to ensure the accuracy of their filings.” Rule 11 of the Federal Rules of Civil Procedure (opens in a new tab) makes the signature on a filing a certification that its legal contentions are warranted by existing law. The tool does not sign; you do.
Client confidentiality with connected tools
A chat window only sees what you paste into it. An agent connected to your document management system, email or practice management software over MCP can read whatever that connection allows, and can be steered by text inside the documents it reads. The MCP specification (opens in a new tab) says hosts must obtain explicit user consent before exposing user data to servers, and states that MCP itself cannot enforce these security principles at the protocol level. The safeguards are yours to set:
- Connect per matter, not per firm. An agent working on one matter should not be able to read another client’s files.
- Prefer read-only connections. An agent that drafts does not need to send email or file anything.
- Treat opposing parties’ documents as untrusted input. Text inside a production can carry instructions aimed at the agent; indirect prompt injection explains the risk.
- Check the vendor’s terms for whether inputs are stored or used for training, and get the client’s informed consent where the opinion says you need it.
What a lawyer must approve
- Everything filed with a court, sent to a client, or sent to the other side.
- Every citation and quotation, checked against the source by a person.
- Every piece of legal advice, and every statement of what the law is.
- What client information any tool can read, and the client’s consent where it is needed.
- Time entries and bills for work the agent helped with.
- Which connectors and tools are switched on, and for which matters.
A board for matter tasks
The agent’s task lists need somewhere to live that the team can see. On fenbs, each next step is a task with a priority from 1 to 10 and a plan, moved by a person through To Do, Next Up, In Progress and Completed. Every task has a Your reference box for your own numbering, which is where the matter number goes. Keep client names and privileged content off the board: the note says what to do and links to the document in your own system. The firm’s standing rules, such as “no citation leaves the firm until a person has read the source”, go on the Decisions and rules page, which every connected AI assistant reads first, and History records who changed each task. fenbs is not a docketing system: it has no due dates, so court deadlines stay where they are tracked today.
Related
Checking an agent’s output: verifying AI-generated work. Text that steers an agent: indirect prompt injection. Who may do what: roles and permissions for humans and AI agents. Scopes for an assistant’s token: assistant tokens and scopes.