California AI Practice Guidance: 2024 State Bar Opinion
The State Bar of California issued guidance on AI use in legal practice in 2024, building on ABA Formal Opinions 512/533 and applying California-specific rules.
Background
The California State Bar Standing Committee on Professional Responsibility and Conduct has issued guidance on AI use in legal practice, supplementing ABA Opinions 512 and 533.
Key California-specific provisions
Confidentiality
AI use must:
- Maintain client confidentiality under California Rule 1.6
- Pass Business Associate Agreement (BAA) review for HIPAA-covered matters
- Ensure vendor security meets California requirements
- Comply with CCPA for any personal information processing
Supervision
California Rule 5.3 supervision applies to AI tools:
- Reasonable supervision of AI outputs
- Vendor vetting and ongoing review
- Audit log retention
- Quarterly compliance review
Fees
California Rule 4-210 requires:
- Fees not unconscionable
- AI cost savings may reduce fees for clients
- Disclosure of AI use on billing if relevant
- Trust account rules apply to retainers
Competence
California Rule 1.1 (Competence) requires:
- Keep abreast of changes in law and practice
- AI tools fall under competence requirements
- Training and continuing education on AI use
California-specific implementation patterns
Engagement letter language
Working California engagement letter language:
"We may use AI-assisted tools including [tool name] in providing legal services to you. These tools process client information under our confidentiality and security policies, including California State Bar requirements under Rule 1.6 and applicable CCPA provisions. All AI-generated outputs are reviewed by a licensed California attorney before being relied upon. AI cost savings may reduce fees for certain tasks; we will discuss this with you if relevant."
AI use log
Per California requirements:
- Per-matter AI query and response log
- Vendor name and version
- Citation verification status
- Attorney review timestamp
Vendor vetting
Working vendor checklist for California practices:
- CCPA compliance (privacy policy review)
- BAA available
- SOC 2 Type II
- Data residency (US-only preferred for sensitive matters)
- Audit log access
- Breach history review
Acknowledgments
This article summarizes public sources including the California State Bar guidance, ABA Formal Opinions 512/533.
Dillon Deutsch has worked with California-licensed lawyers on AI compliance. https://courtgpt.ai
Top comments (0)