ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Technology Competence Under Model Rule 1.1 Comment 8, Explained

What ABA Model Rule 1.1 Comment 8 says about technology competence, how states have responded, and practical steps firms can take to show reasonable effort.

3 min readBy Counsel Cyber Team

In 2012, the ABA amended the comments to Model Rule 1.1 on competence. Comment 8 now says that, to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. That short phrase has become one of the most cited anchors for technology obligations in the legal profession.

This post explains what the comment says, what it does not say, and what practical steps firms can take. It is not legal advice, and the rules in your jurisdiction may differ, so confirm requirements with your state bar.

What the comment actually says

The text is brief. It does not mandate particular software, certifications, or security standards. It ties technology awareness to the existing duty of competence. In other words, a lawyer who uses email, cloud storage, e-discovery tools or, increasingly, generative AI should understand enough about the benefits and risks to use them appropriately or to get help from someone who does.

Many states have adopted the comment or similar language, though details vary. Some have gone further with their own opinions or CLE requirements on technology. Because state rules control, the first practical step is to check what your own state has adopted.

Competence is not the same as expertise

A common misunderstanding is that Comment 8 requires every lawyer to become an IT professional. It does not. The ABA's own guidance in related areas, such as Formal Opinion 477R on securing communications, recognizes that lawyers may rely on qualified experts and vendors, with appropriate supervision. The point is not to know everything. The point is to know enough to ask the right questions and to avoid blind trust.

How this connects to other rules

Confidentiality, Rule 1.6(c)

Rule 1.6(c) asks lawyers to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or access to, client information. Technology competence is how you evaluate whether your efforts are reasonable.

Supervision, Rules 5.1 and 5.3

Partners and supervising lawyers are expected to have reasonable measures in place so that lawyers and nonlawyer assistants conduct themselves compatibly with professional obligations. When IT vendors and staff handle client data, the supervision question applies.

Communication, Rule 1.4

If a breach affects client information, communication duties may come into play. ABA Formal Opinion 483 discusses lawyers' obligations after a data breach or cyberattack.

What reasonable looks like in practice

Because the comment is principle-based, "reasonable" depends on the firm's size, the sensitivity of the data, and the cost and availability of safeguards. Still, patterns emerge that most firms can follow.

  1. Know your systems. Keep an inventory of where client data lives: email, practice management, document storage, personal devices, and third-party tools.
  2. Know your risks. Perform a periodic risk assessment, even a simple one, and record what you decided.
  3. Use basic safeguards. MFA, encryption, patching, backups, and email filtering are widely recognized as baseline measures.
  4. Vet vendors. Ask about security practices, data location, and breach notification before storing client information with a provider.
  5. Train people. A short annual session is a minimum. Short, frequent reminders work better.
  6. Document your decisions. If you decide not to adopt a control, write down why.

Staying current without drowning

Technology changes constantly, and no partner has time to read every advisory. A manageable approach looks like this:

  • Assign one partner or administrator to own technology risk and report quarterly.
  • Subscribe to a small number of reliable sources, such as your state bar's technology publications and government alerts from CISA.
  • Ask your IT provider for a short written summary each quarter: what changed, what was patched, what threats are active.
  • Attend at least one technology-focused CLE each year, particularly if your state offers technology credit.

Common mistakes

  • Assuming the IT provider is responsible for competence. Delegation helps, but supervision remains with the lawyers.
  • Treating new tools as exempt from review. Generative AI, e-signature tools, and cloud collaboration platforms all raise Comment 8 questions.
  • Waiting for an incident to learn what is in the environment.
  • Keeping no records of training, assessments or vendor reviews.

Putting it to work

You do not need a large program to demonstrate good-faith effort. A one-page technology risk summary, a vendor list, a training log, and a quarterly review meeting give you a credible record. Counsel Cyber helps law firms assemble exactly this kind of documentation and can serve as the technical partner your attorneys consult. If it would help to have a structured review, we can begin with a short conversation.