DEV Community

CourtGPT
CourtGPT

Posted on

ABA Model Rule 5.3: AI Vendor Supervision Patterns

ABA Model Rule 5.3: AI Vendor Supervision Patterns

ABA Model Rule 5.3 governs supervision of non-lawyer assistants. AI vendors and AI tools fall under this rule's application. This article catalogs implementation patterns.

The rule

Model Rule 5.3 (Responsibilities Regarding Nonlawyer Assistants):

"With respect to a nonlawyer employed or retained by or associated with a lawyer... a partner in a law firm shall make reasonable efforts to ensure that the firm has in effect measures giving reasonable assurance that the nonlawyer's conduct is compatible with the lawyer's professional obligations..."

Source: ABA Model Rules.

AI as a "non-lawyer assistant"

Per ABA Opinion 512 (2024) and Opinion 533 (2024):

AI tools function as non-lawyer assistants subject to Rule 5.3 supervision.

Implementation patterns

Vendor vetting

For AI vendors:

  1. Verify BAA availability (HIPAA-covered if applicable)
  2. Verify SOC 2 Type II compliance
  3. Review data retention policies
  4. Review training data use opt-out
  5. Verify subprocessor compliance
  6. Audit log access for the firm
  7. Breach history review

Ongoing supervision

Working patterns:

  1. Periodic vendor compliance review (annual)
  2. Audit log review per matter
  3. Eval framework against published benchmarks
  4. Security audit annually
  5. Update vendor credentials on personnel changes

Override controls

Working patterns:

  1. Lawyer review mandatory for any AI-assisted filing
  2. AI cannot directly interact with court filing systems
  3. AI suggestions tracked and lawyer reviews each
  4. Override audit log entries

Evidence retention

Working patterns:

  1. AI query logs retained 7+ years
  2. AI response logs retained 7+ years
  3. Audit log hashes (tamper-evident)
  4. Vendor configuration snapshots

Conflict of interest considerations

Rule 5.3 requires avoiding conflicts of interest:

  1. AI vendor's other clients
  2. AI vendor's training data sources
  3. Cross-jurisdictional compliance

For an AI vendor with multiple law firm clients:

  1. Conflict check: vendor doesn't have conflict with matter's client
  2. Confidentiality: vendor's BAA covers the matter's jurisdiction
  3. Audit trail: vendor provides audit logs

Liability allocation

When AI makes an error:

  1. Vendor's contractual liability (rarely direct)
  2. Law firm's professional liability (presumed)
  3. Insurance coverage varies

Working pattern:

  • Vendor contract should include indemnification for AI errors (where vendor is at fault)
  • Law firm maintains professional liability coverage
  • Cyber insurance covers AI vendor breach (typically)

Acknowledgments

This article summarizes public sources as of early 2026.

Dillon Deutsch has worked with ABA Rule 5.3 compliance for AI vendors. https://courtgpt.ai

Top comments (0)