Course Description
This session explores the ethical and cybersecurity challenges lawyers face as generative and agentic AI reshape the legal landscape. We will examine recent cases where AI misuse led to sanctions and review major developments such as ABA Formal Opinion 512 (published in July 2024 by the American Bar Association’s Standing Committee on Ethics and Professional Responsibility), Executive Order 14110 (on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence), and the EU AI Act. Participants will gain practical strategies to verify AI outputs, safeguard client confidentiality, and prepare for new compliance requirements.
Principles
- Verify AI Outputs Before Relying on Them
- Lawyers remain responsible for the accuracy and integrity of AI-assisted work product.
- Counsel should establish verification workflows to detect hallucinations, fabricated authorities, and other errors, while documenting appropriate AI use and disclosures.
- Protect Client Confidentiality and Data
- Generative and agentic AI introduce new risks involving privileged information, sensitive client data, and third-party platforms.
- Lawyers should understand data-handling practices, vendor risks, security controls, and appropriate safeguards before entering client information into AI systems.
- Recognize AI-Enabled Cybersecurity and Fraud Threats
- Deepfakes, impersonation, automated phishing, and other AI-enabled attacks can compromise client funds, confidential communications, and law-firm systems.
- Firms should implement verification procedures for financial transactions, identity-sensitive communications, and high-risk requests.
- Build an AI Governance and Compliance Framework
- Lawyers need to understand the ethical and regulatory landscape, including ABA Formal Opinion 512, Executive Order 14110, and the EU AI Act.
- A practical governance framework should address approved AI tools, human oversight, documentation, disclosures, vendor management, and cross-jurisdictional compliance.
- Prepare for the Agentic Era
- Agentic AI creates risks beyond traditional generative AI because systems may take actions on a user’s behalf.
- Counsel should update engagement letters, vendor agreements, cybersecurity policies, and incident-response plans to address autonomous decision-making, delegated authority, liability, and accountability.
Syllabus
- Context
- Generative and agentic AI are rapidly becoming everyday tools in the legal profession
- With their adoption come new ethical, cybersecurity, and compliance risks
- Key Themes (from the last two years)
- Hallucinations & Trust: AI-generated legal briefs have led to sanctions and new verification/disclosure rules
- Data Stewardship & Breaches: Law firms increasingly targeted in breaches (e.g., MOVEit-related, Kirkland, Kelley Drye)
- Deepfakes & Social Engineering: AI-enabled impersonations threaten client funds, privilege, and trust (e.g., $25M Hong Kong deepfake heist)
- Regulation & Governance: ABA Formal Opinion 512 (2023), U.S. Executive Order 14110 (2023), and the EU AI Act (phased rollout, GPAI duties starting 2025)
- Practical Takeaways for Lawyers
- Build verification workflows and document disclosures for AI use
- Protect client confidentiality when working with AI platforms
- Strengthen breach readiness tailored to law-firm threat profiles
- Implement deep-fake/impersonation controls for financial transactions and case communications
- Adopt a cross-jurisdictional compliance checklist (ABA, EO 14110, EU AI Act timelines)
- Update engagement letters, vendor contracts, and incident response plans to address risks of autonomous/agentic systems
- Why It Matters
- The legal world is entering the “agentic era,” where AI systems can act on user’s behalf
- Lawyers must anticipate liability, ethical, and cybersecurity implications to uphold professional standards and client trust