Many managing partners and solo practitioners look for a straight answer to a simple question: do I need my client to sign off before I use AI on their case? If you run a modern firm, you are likely using artificial intelligence to speed up your work. But deciding when and how to tell your clients about these tools is a difficult compliance challenge. The answer to whether you need consent is not uniform. It depends entirely on which state bar governs your practice, how your specific tools handle data, and what tasks those tools perform.
Regulators across the country have split into three distinct camps. Some states expect strict, informed consent before any client data touches an AI model. Other states only suggest that you consider disclosure. A few jurisdictions have explicitly declined to impose any client-facing disclosure rules at all.
This guide walks through this state-by-state split so you can determine your exact obligations. This analysis is strictly about client-facing disclosure and consent. We do not cover court-facing certification requirements here, which you can read about in Courts are writing their own AI rules, and they don't agree. We also do not restate the broad ethical frameworks of confidentiality and competence, which we cover in What the bar actually requires when you use AI. Instead, we focus on what you must put in front of your clients and how to write those terms.
The trigger: client data in, not just AI in the workflow
Before looking at state rules, you must understand what triggers the disclosure obligation. The trigger is almost never the mere use of AI. Instead, the trigger is the input of client confidential information.
If you use AI purely on public information, your disclosure obligations are low. For example, you might use AI to summarize a published judicial opinion. You might use it to polish your own internal templates where no client facts are present. In these scenarios, you are not exposing client data to a third party.
The compliance posture changes entirely when you input confidential client information into an AI tool. This includes case facts, client documents, trade secrets, or personally identifiable information. When you feed this data into a third-party model, you risk exposing it to outside parties.
This risk depends heavily on your vendor's data policies. To understand how different vendors handle your inputs, you can read Does Your Legal AI Tool Train on Client Data? What the Policies Actually Say. You should also check What legal AI vendors actually do with your client data to verify their security protocols. If a tool retains data or uses it for model training, inputting client information without consent is a major confidentiality risk. This specific data-sharing act is what triggers the strict rules in the states below.
Where bars require or expect consent
The first group of jurisdictions has a clear expectation: you must obtain informed consent from your client before putting their confidential information into an AI tool. These authorities also agree that vague, generic disclosures are not enough.
The ABA Position
The American Bar Association set the national baseline in ABA Formal Opinion 512, issued on July 29, 2024. The opinion states that lawyers should secure a client's informed consent before inputting confidential information into a generative AI tool.
According to the American Bar Association, boilerplate language in a standard engagement letter does not satisfy this duty. The ABA explains that consent must be specific. Your client must understand exactly which tool you are using and how that tool handles their data before they can give valid informed consent.
California
California has established a strong disclosure expectation. The State Bar of California updated its Generative AI Practical Guidance in September 2025. This document builds on the state's initial November 2023 guidelines.
According to the California State Bar Guidance, attorneys must inform clients when generative AI is involved in their matter, especially if the AI use significantly affects the representation. The guidance states that a lawyer must not input confidential client information into an AI tool without first obtaining informed consent regarding the risks.
California has also developed a proposed Committee on Professional Responsibility and Conduct opinion, known as Proposed Formal Opinion 2024-1, which outlines when disclosing AI use to clients is highly advisable.
Florida
The Florida Bar has some of the most explicit rules in the country. On January 19, 2024, the bar approved Ethics Opinion 24-1. This opinion requires Florida attorneys to get informed consent before using any third-party AI tool that would expose confidential client information.
Florida's rules go beyond confidentiality. Opinion 24-1 also requires lawyers to disclose AI use if it affects client billing or case costs. Finally, if a Florida firm uses a client-facing AI chatbot on its website, the chatbot must clearly identify itself as artificial intelligence so clients do not mistake it for a human lawyer.
Where bars recommend but don't require it
The second group of jurisdictions acknowledges the rise of legal AI but uses softer, non-mandatory language. These state bars suggest that you consider disclosure, but they stop short of a flat requirement.
Texas
The Professional Ethics Committee for the State Bar of Texas addressed this topic in Opinion No. 705, issued in February 2025. This was the first Texas-specific ethics opinion focusing on generative AI.
The Texas Opinion 705 PDF states that a lawyer "should consider" informing clients and getting their consent when confidential information is involved. The opinion advises that if a lawyer is not entirely satisfied that an AI tool will protect client confidentiality, the lawyer should not input that information without consulting the client and getting consent. However, Texas frames this as a strong recommendation rather than a blanket mandate.
New York City
The New York City Bar Association took a similar approach in Formal Opinion 2024-5, issued on August 7, 2024. This opinion frames client disclosure as a case-by-case decision.
The opinion suggests that lawyers should weigh whether a client would reasonably expect to know that AI produced their work product. The NYC Bar also distinguishes between different types of tools. It treats routine, embedded tools (such as basic spell-check or standard research platform features) differently from substantive drafting tools. You do not need to disclose routine tools, but you should consider disclosure for substantive drafting.
Where there's no client-disclosure mandate at all
The third group of jurisdictions has declined to create any client-facing AI disclosure requirements. Where rules exist, they target court filings rather than client relationships.
New York State
New York's statewide court rule, known as 22 NYCRR Part 161, went into effect on June 1, 2026. This rule governs how lawyers use AI in court filings. However, the rule does not impose any system-wide requirement to disclose AI use to your clients.
Illinois
The Illinois Supreme Court issued its Policy on Artificial Intelligence on January 1, 2025. This policy recommends that judges do not require attorneys to disclose their use of AI when drafting pleadings. This court-facing policy shows that regulators do not always view automatic disclosure as a necessity. It keeps the focus on the final legal product rather than the tools used to create it.
What to put in an engagement letter
Because state rules vary, you cannot rely on a single, bar-approved template. No state bar has published an official, mandatory AI disclosure clause. Instead, you must design your own engagement-letter terms.
Practitioner-published drafting guidance from law-firm-practice-management sources, including Zusman Partners and the Polygraf AI clause library, shows what a well-built AI clause must contain. If you are drafting a clause for your firm, make sure it covers these five elements:
- An affirmative statement of AI use: Create a standalone section in your engagement letter. Do not bury this language in generic boilerplate about "using modern technology." State clearly that the firm may use AI-assisted tools for research, document review, and drafting.
- An explicit attorney-review guarantee: State that all AI-generated work is reviewed, verified, and edited by a licensed attorney before it is used or filed. This assures the client that a human is always in control. To understand why this matters, you can read How accurate is legal AI, really? What the benchmarks show in 2026.
- A plain-language description of data handling: Explain how your chosen AI tools process client data. Specify whether the vendor trains its models on your inputs or shares the data with third parties. This helps meet the informed consent standards set by California and Florida.
- An opt-out mechanism for the client: Give the client a clear way to limit or reject the use of AI on their matter. Under Model Rule 1.2, a client has the authority to limit the means of representation. If they instruct you not to use AI, that instruction is binding on your firm.
- Specific, rather than blanket, consent: Make sure your consent process is tool-specific. A client who consents to AI-assisted legal research has not consented to having their sensitive trade secrets or medical records uploaded to a public drafting tool.
Because states like Texas use softer "should consider" language while California and Florida expect strict consent, you should verify these elements against your own state's latest guidelines.
What this means for firms practicing in more than one state
If your firm represents clients in multiple states, or if you plan to expand, you face a patchwork of conflicting rules. A Texas-based lawyer might feel safe relying on Opinion 705's soft recommendation. However, if that lawyer represents a client in Florida or California, they must meet those states' stricter standards.
The safest compliance strategy is to default to the most protective posture. You should obtain specific, documented consent whenever client confidential information is input into an AI tool, regardless of your home state.
Defaulting to a high-disclosure standard protects your firm in several ways:
- It prevents confidentiality claims: A Texas firm can still face a disciplinary action or malpractice claim for a confidentiality breach under Rule 1.6, even though Opinion 705 only "recommends" consent.
- It satisfies malpractice insurers: Insurers are increasingly looking at how firms document their technology use. To see what carriers are looking for, read What legal malpractice insurers are actually asking about AI.
- It builds client trust: Clients appreciate transparency. Explaining your AI use upfront prevents difficult conversations later if a client discovers AI-generated text in their billing statements.
Remember that client consent is a floor, not a substitute for your own diligence. Getting a signature does not relieve you of your duty to verify the accuracy of your tools and vet your vendors' data policies.
FAQ
Do I legally have to tell my client I'm using AI on their case?
There is no single national rule. It depends on your state and whether you are inputting confidential client data into the tool. California and Florida guidance points toward a yes when confidential information or billing is affected, while Texas's Opinion 705 only recommends disclosure, and Illinois court policy declines to require it.
Is boilerplate engagement-letter language about "may use technology" enough consent?
No. ABA Formal Opinion 512 explicitly states that general boilerplate language in an engagement letter is not adequate to secure informed consent. Your disclosure must be specific to the particular tool you are using and explain how that tool handles client data.
Can a client refuse to let their lawyer use AI on their matter?
Yes. Under Model Rule 1.2, a client has the authority to limit the objectives and means of the representation. If a client explicitly requests that you do not use AI tools on their case, that instruction is ethically binding on your firm.
Does using AI just for internal drafting, without inputting client data, require consent?
Generally no. The disclosure and consent triggers in state bar opinions (such as those from the ABA, California, and Florida) are tied to the exposure of confidential client information. If you use AI for abstract drafting or editing without entering client-specific facts, you are not triggering these strict consent requirements.
Is there a standard, bar-approved AI consent clause every firm can copy?
No. No state bar has published an official, mandatory AI consent clause. The recommended clause elements come from law-firm practice-management sources, and you must tailor your language to match the specific rules of your jurisdiction.
The bottom line
The rules governing client consent and AI are not uniform. If you operate a growing firm, you cannot treat client disclosure as an afterthought. Waiting for your state bar to issue a flat mandate is a risky approach.
The best practice for modern firms, including those detailed in our Legal AI for Solo & Small Law Firms: A Buyer's Guide, is to establish a clear, tool-specific consent process now. Treat this as a client-relationship and documentation task rather than a simple regulatory chore. By writing clear AI clauses into your engagement letters and securing specific consent before uploading client data, you protect your firm's reputation and satisfy your ethical duties.