Conversations about generative AI in law firms are full of confident statements, some accurate and some not. Mistaken beliefs matter because they drive decisions: which tools get adopted, what gets pasted into them and which risks go unmanaged. This post tests seven of the most common myths against what is generally known, and against the guidance from the ABA in Formal Opinion 512, issued in July 2024.
Myth 1: "If I do not use AI, my firm has no AI risk."
Reality: AI is arriving inside tools you already use, including email, word processors, practice-management software and conferencing platforms. Staff may also use personal accounts on their own. Even a firm that never buys an AI product has exposure. Start by finding out what is in use and what features have been switched on by default.
Myth 2: "A ban is the safest policy."
Reality: Bans are easy to announce and hard to enforce. When people see real productivity benefits and no approved option, many use tools anyway, out of sight. A sanctioned tool list with clear rules usually produces better visibility and better compliance than a prohibition alone.
Myth 3: "Paid and free versions are basically the same."
Reality: They often differ in data handling, retention, administrative controls and whether content may be used to improve models. Business-tier agreements generally offer stronger commitments than consumer terms. Read the actual terms and get answers in writing.
Myth 4: "If the tool is popular, it must be safe for client data."
Reality: Popularity says nothing about how a product treats confidential information. Opinion 512 discusses a lawyer's duty to understand how a tool uses and stores information, and notes that in some circumstances, informed client consent may be needed before inputting client information. Evaluate each tool on its terms.
Myth 5: "Removing names makes anything safe to paste."
Reality: De-identification is harder than it looks. Facts, dates, locations and unusual circumstances can identify a client or matter even without names. Treat anonymization as a risk reducer, not a guarantee, and set rules about what categories of information never go into outside tools.
Myth 6: "AI output is reliable if it sounds professional."
Reality: These systems can produce fluent, confident, false statements, including invented citations. Courts have responded to filings built on fabricated authorities. Every output used for client work needs verification by a lawyer, particularly citations, quotations and factual claims.
Myth 7: "The ethics rules do not address AI yet."
Reality: The existing rules apply. Opinion 512 discusses how competence, confidentiality, communication, candor, supervision and reasonable fees apply to generative AI. State bars and courts are also issuing their own guidance and rules. Check your jurisdiction's requirements and keep watching, since the landscape is moving.
Turning Myths Into Policy
Use these points to shape a short firm policy:
- Inventory current use, including built-in features and personal accounts.
- Approve specific tools, with business-grade terms and administrative controls.
- Define data rules, including what may never be entered.
- Require verification of all output before reliance.
- Address client communication and billing, consistent with engagement terms and ethics guidance.
- Train people with real examples of good and bad use.
- Review twice a year, as products change quickly.
Questions to Ask Vendors
- Is our content used to train your models?
- How long do you retain prompts and outputs, and can we delete them?
- Who at your company can access our content?
- What security attestations do you hold?
- Can administrators control features and view usage?
What Good Looks Like
A well-run firm knows which AI tools are in use, has approved a short list, has written one page of rules and trains staff on them. It treats AI as a capable assistant that needs supervision, not as an oracle and not as a forbidden object.
A Reminder on Scope
This post is general information, not legal advice. Standards for AI use in legal practice are developing, so confirm requirements with your state bar and any courts where you practice.
How Counsel Cyber Helps
Counsel Cyber helps firms create sanctioned-AI programs, from tool evaluation to policy to technical controls in Microsoft 365. If you would like to sort myth from reality for your firm's setup, we can help.