ABA Formal Opinion 512 and Your Practice Management Tools
ABA Formal Opinion 512 addresses lawyers' ethical obligations when using generative artificial intelligence in their practice. The opinion itself is specific to AI tools, but the core ethical duties it discusses — competence (Rule 1.1), confidentiality (Rule 1.6), and communication (Rule 1.4) — are general Model Rule obligations that apply to all technology an attorney uses, including practice management software.
Scope of Formal Opinion 512: Updated to clarify that ABA Formal Opinion 512 (July 2024) specifically addresses lawyers' ethical obligations when using generative artificial intelligence tools. The opinion does not directly address non-AI practice management software. The core ethical duties discussed — competence (Rule 1.1), confidentiality (Rule 1.6), and communication (Rule 1.4) — are general Model Rule obligations that apply to all technology use, independently of Opinion 512.
In July 2024, the American Bar Association's Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512, addressing lawyers' ethical obligations when using generative artificial intelligence tools. The opinion generated significant attention for its specific guidance on AI-generated content, hallucination risks, and the duty to supervise AI outputs. The core ethical duties that inform the opinion — competence (Rule 1.1), confidentiality (Rule 1.6), and communication (Rule 1.4) — are general Model Rule obligations that apply to all technology an attorney uses, including practice management software, but Opinion 512 itself is specific to generative AI.
This post examines these core ethical duties — which also informed Formal Opinion 512's analysis of AI — and what they mean for attorneys evaluating case management tools, including both cloud-based and on-device platforms.
The Core Ethical Duties That Apply to All Technology
Three fundamental ethical duties, drawn from the Model Rules of Professional Conduct, apply to all technology use, not just AI. Formal Opinion 512 discusses these duties in the context of generative AI, but they originate in the Model Rules and apply independently to any tool an attorney uses. Understanding these duties helps an attorney evaluate any practice management tool:
Duty of Competence (Rule 1.1): As earlier opinions (Formal Opinions 477R and 483) established, the duty of technological competence requires attorneys to understand the benefits and risks of the technology they use. Comment [8] to Rule 1.1 specifically states that to maintain competence, lawyers should "keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology." When choosing a case management tool, this means understanding how the tool stores, processes, and transmits client data — not merely accepting a vendor's security claims at face value.
Duty of Confidentiality (Rule 1.6): As discussed extensively in our earlier post on attorney-client privilege, Rule 1.6 requires attorneys to make "reasonable efforts" to prevent unauthorized disclosure of client information. This is the central ethical constraint on technology use, reaffirmed in Formal Opinion 512 for AI tools but independently applicable to all technology. The "reasonable efforts" standard requires the attorney to consider the sensitivity of the information, the security measures available, and the cost of additional protections. For case management tools, the core question is whether the tool's architecture and the attorney's use of it satisfy this standard.
Duty to Communicate (Rule 1.4): Attorneys must communicate with clients about their use of technology when that use could materially affect the representation. If a case management tool transmits data to a third-party server — even for legitimate purposes like backup or syncing — the attorney may need to disclose this to the client and obtain informed consent. With on-device tools that transmit no data, this disclosure burden is eliminated.
Competence (Rule 1.1): Does the attorney understand how their case management tool stores and protects client data? For cloud tools, this requires evaluating the vendor's security practices, data processing agreements, and data retention policies. For on-device tools, this requires evaluating the app, device security, backups, exports, and any enabled operating-system services.
Confidentiality (Rule 1.6): Does the tool's architecture prevent unauthorized disclosure? Cloud tools introduce third-party access that must be evaluated under the Kovel doctrine and state bar ethics opinions. On-device tools eliminate third-party access entirely.
Communication (Rule 1.4): Has the attorney disclosed relevant technology use to the client? When a case management tool transmits data to third parties, disclosure may be required. When no data is transmitted, the scope of disclosure is narrower.
Formal Opinion 512's AI-Specific Guidance — and the Broader Technology Principles
Formal Opinion 512 addresses several AI-specific risks: hallucination (the tendency of AI models to generate false information), bias (the risk of discriminatory outputs), and client consent requirements specific to AI use. These are distinct to generative AI and do not directly apply to practice management tools. However, the same Model Rule obligations that informed Opinion 512 — competence, confidentiality, and communication — apply independently to any software that processes client data.
Vendor due diligence (Rule 1.1): The Model Rules require attorneys to understand the technology they use, as established in Formal Opinion 477R and Comment [8] to Rule 1.1. For case management tools, this means understanding how the platform handles data — including sub-processing relationships (does the platform vendor use AWS, Azure, or another infrastructure provider?), data residency (are the servers in the United States or abroad?), and data retention (what happens to data when the subscription ends?).
Ongoing supervision and data governance (Rule 1.6): Rule 1.6's "reasonable efforts" standard requires attorneys to verify that a tool is configured correctly, that data access controls are appropriate, and that data portability is available if the attorney needs to migrate to another system.
How On-Device Architecture Supports the Core Ethical Duties
On-device case management aligns naturally with the ethical framework of competence, confidentiality, and communication that the Model Rules establish. Because the tool stores all data locally on the attorney's device, several of the due diligence obligations that apply to cloud services are either simplified or eliminated:
- Vendor due diligence: With no app-operated cloud component, the attorney can focus the analysis on the app, device, exports, backups, and any operating-system services that are enabled.
- Data confidentiality: A local primary store removes an application-server access path but does not eliminate risks from device access, lawful process, exports, backups, or other enabled services.
- Client communication: The communication analysis may be simpler when the app does not transmit data, but the attorney still must evaluate the actual configuration and representation-specific circumstances.
1. Do you understand how your case management tool stores, processes, and transmits client data? (Rule 1.1)
2. Have you evaluated whether the tool's data protection measures are reasonable given the sensitivity of your case data? (Rule 1.6)
3. If the tool transmits any data to third parties, have you analyzed whether disclosure to clients is required? (Rule 1.4)
4. Can you export your data if you need to change tools? Do you know the format and process? (Rule 1.1 — competence requires planning for transitions.)
5. How often do you review your tool's security practices and terms of service for changes that could affect your ethical obligations? (Rule 1.6 — reasonable efforts are ongoing.)
The Broader Trend: Technology Competence as an Ongoing Duty
These opinions are part of a broader trend in legal ethics that treats technology competence as an ongoing, affirmative duty — not a one-time evaluation. Formal Opinion 477R (2017) established the "reasonable efforts" framework for securing client data. Formal Opinion 483 (2018) addressed lawyers' obligations after a data breach. Formal Opinion 498 (2021) addressed virtual practice. Formal Opinion 512 (2024) addresses generative AI. Each opinion builds on the previous ones, and together they create a clear expectation: attorneys must understand their technology, evaluate its risks, and take reasonable steps to protect client data throughout the attorney-client relationship.
For solo practitioners and small firms, the cumulative weight of these obligations can be daunting. On-device case management can remove an app-operated server from the primary data path and simplify part of the analysis, but architecture alone is not compliance. Attorneys still must evaluate the app's actual behavior, device and backup configuration, exports, lawful-access risks, and the circumstances of each representation.
This content is legal information, not legal advice. It does not create an attorney-client relationship and cannot substitute for consultation with a licensed attorney about your specific circumstances.