Courts and disciplinary authorities are moving past the question whether lawyers and litigants will use generative AI. The immediate questions are operational: What client or matter information may be submitted to an AI system? Who verifies the output? What does a signer certify? And what duties arise when an AI-assisted error reaches the court?
The most consequential recent authorities do not create a uniform AI-specific code. They apply familiar rules governing privilege, competence, candor, supervision, and signed filings to a new workflow. Together, they point to two control points. Confidentiality must be protected before information enters an AI system. Accuracy and candor must be protected before—and sometimes after—a paper is filed.

Heppner makes client-side AI use a privilege issue
In United States v. Heppner, a federal criminal defendant used the publicly available version of Claude on his own initiative after retaining counsel. He created roughly thirty-one documents about his legal position, later shared the material with his lawyers, and asserted attorney-client privilege and work-product protection after the documents were seized. On February 17, 2026, Judge Jed Rakoff held that neither protection applied.
The court’s reasoning was narrower—and more useful—than the shorthand that “AI waives privilege.” Claude was neither counsel nor counsel’s agent. The communications were not confidential under the privacy policy the court examined. The defendant had not used the tool at counsel’s direction, and the documents did not reflect counsel’s strategy when created.
It is black-letter law that non-privileged communications are not somehow alchemically changed into privileged ones upon being shared with counsel.
— United States v. Heppner (S.D.N.Y. 2026)
Heppner is a district-court decision. It does not hold that all AI-assisted material is unprivileged, much less necessarily discoverable. The court also left open whether counsel-directed use might function like a professional agent necessary to facilitate legal advice—a Kovel-type theory. That possibility is not a safe harbor. Tool terms, data retention, the purpose of the communication, counsel’s direction, and the governing jurisdiction still matter. The practical lesson is that a client’s use of a consumer chatbot about an active dispute should be treated as a potential confidentiality, waiver, and discovery issue, not as a private extension of the lawyer’s office.
That unresolved point raises an immediate practice question: should firms revise engagement letters? A clause can help create the record; it cannot create the privilege. Heppner ↗ ABA Formal Opinion 512 ↗ An engagement letter or incorporated client-AI protocol can instruct clients not to submit matter information to consumer AI tools absent counsel’s specific written direction and can explain that any approved workflow will identify the tool, purpose, and confidentiality controls. That documentation may help show counsel’s direction and the legal purpose of the work. It cannot cure disclosure under a provider’s terms. And ABA Formal Opinion 512 cautions that boilerplate engagement-letter language is not a substitute for the matter-specific dialogue and informed consent a particular tool and proposed use may require.
Lnu v. Blanche puts the responsibility at signing and filing
The Ninth Circuit’s published June 3, 2026 discipline order in Lnu v. Blanche draws a different line. The court said the violation did not occur merely because generative AI may have been used for research or drafting. It occurred when lawyers signed and filed briefs containing nonexistent cases, false quotations, and serious mischaracterizations of real authority.
The rules are not violated at the point of research and drafting, but at the point of signing and filing.
— Lnu v. Blanche (9th Cir. 2026)
The lawyers’ conduct after the court identified the errors aggravated the violation. They described fabricated authorities as typographical or copy-and-paste errors and repeatedly denied that AI might be the source. The court imposed $2,500 sanctions on each lawyer, suspended both from practice before the Ninth Circuit for six months, ordered broad notice to clients, courts, opposing counsel, and the firm, and required a firm-wide AI disclosure and verification statement in filings for two years.
The durable lesson is not “ban AI.” It is that a policy against AI does not substitute for supervision. Citation validation limited to confirming that an authority exists is incomplete; the filing lawyer must read the authority, determine whether it supports the proposition for which it is cited, and act with immediate transparency if an error is found. A correction that obscures the nature or source of the mistake can become a separate candor problem.
Daghra shows institutional filers receive no verification safe harbor
On July 16, 2026, Chief Judge Hala Jarbou addressed an apparent hallucination in Daghra v. Hinkley, an immigration detention case. A Justice Department filing cited Taylor v. Hott at a reporter page occupied by a different commercial-arbitration opinion. The court could not locate the quoted case or language and said the citation was likely produced by generative AI. It declined to impose sanctions at that time but warned the government that future filings could not include nonexistent law.
It should be obvious that any attorney who uses AI must scrupulously review its work product to ensure that the cited cases exist ...
— Daghra v. Hinkley (W.D. Mich. 2026)
The order is important precisely because the filer was the government. Workload, institutional stature, vendor branding, and professional formatting do not satisfy counsel’s verification obligation. Investigating fabricated citations consumes judicial resources and imposes costs on opposing parties and clients.
Pro se litigants may receive context, but not an exemption
For self-represented litigants, the recent cases show both restraint and a firm floor. In Jones v. Kankakee County Sheriff’s Department, the Seventh Circuit suspected AI use after a pro se brief attributed nonexistent quotations to real cases. The court declined sanctions because it had not previously supplied guidance, found no reason to infer knowing misconduct, and recognized AI’s promise for access to justice. It nevertheless emphasized that represented and unrepresented filers alike must read their papers and take reasonable care to avoid factual and legal misrepresentations.
Accuracy and honesty matter. ... all litigants—represented and unrepresented—must read their filings and take reasonable care to avoid misrepresentations, factual and legal.
— Jones v. Kankakee County Sheriff’s Department (7th Cir. 2026)
Moore v. City of Del City demonstrates that sanctions may include dismissal. The Tenth Circuit affirmed on the merits and, alternatively, dismissed the pro se appeal as a sanction after the appellant used eleven nonexistent cases and misrepresented real ones. Future filings were required to state under penalty of perjury whether generative AI was used and to verify that every citation referred to a real case. The court warned that dismissal without reaching the merits, fees, or other sanctions may be appropriate for unscrutinized AI use.
The principal misuse here is Moore’s failure to verify that the eleven case citations in her appellate brief ... refer to cases that actually exist.
— Moore v. City of Del City (10th Cir. 2025)
The Oregon Supreme Court added state-level consequences in June 2026. In Aldridge v. Tussing, it dismissed a pro se mandamus proceeding after fabricated material appeared again in a response to a show-cause order. In Witkin v. McGreevy, it struck a filing and accepted a $500 sanction after the filer accepted responsibility and obtained leave to file a corrected response. The distinction is practical: courts may consider notice, intent, repetition, and corrective conduct when determining sanctions; repeated fabrication or evasion materially increases sanction exposure.
The injection of false precedent undermines the integrity of the proceedings. Doing it repeatedly ... warrants imposition of a meaningful sanction.
— Aldridge v. Tussing (Or. 2026)
Reliance on legal citations and arguments produced by generative AI without any effort to verify those citations is unreasonable.
— Witkin v. McGreevy (Or. 2026)
Court rules are hardening, but they are not uniform
New York’s Part 161, effective June 1, 2026, adopts a permissive statewide policy: courts should not prohibit AI-assisted preparation when existing duties are followed, and AI use ordinarily should not trigger a disclosure requirement. Individual courts may adopt a model rule under which signing certifies that the filer carefully reviewed the paper and independently ensured it contains no fabricated cases, statutes, or other material.
Florida instead adopted a uniform statewide certification rule. Effective June 15, 2026, amended Rule 2.515(d)(2) requires the signer of a filing to represent that cited legal authorities exist and are accurately cited, with sanctions available after notice and an opportunity to be heard. The Florida Supreme Court simultaneously displaced circuit-level AI disclosure and certification rules. A Miami-Dade disclosure order issued earlier in 2026 therefore should not be treated as the current statewide answer.
There is still no special nationwide amendment to Federal Rule of Civil Procedure 11 requiring an AI certification. A proposal to amend Rule 11(a) remains listed by the federal judiciary as pending consideration. Existing Rule 11 obligations already apply to attorneys and unrepresented parties, while appellate rules, local rules, standing orders, and judge-specific practices can add requirements. Applicable certification and disclosure duties are therefore jurisdiction-, court-, judge-, and date-specific.
What law-firm leadership should change now
First, distinguish unilateral client use from firm-authorized or counsel-directed use. Engagement guidance should tell clients not to submit matter facts, privileged communications, witness accounts, strategy, or documents to consumer AI tools without discussing it with counsel. An approved enterprise tool may reduce data-handling risk, but it does not automatically establish privilege.
Second, design verification around propositions, not documents. For every citation, the responsible lawyer or a qualified reviewer should open the authoritative source, confirm the court and date, locate the quoted language, and decide whether the case actually supports the sentence. A plausible citation checked only through another chatbot is not independent verification.
Third, document supervision and review responsibility. The lawyer who signs should know who drafted each section, which tools were used, how authorities were checked, and whether client information entered any external system. Policies must cover lawyers, law graduates, paralegals, vendors, and client-facing intake—not just the people licensed to sign.
Fourth, create an error-response protocol. Cease relying on or disseminating the questionable material, preserve enough information to determine what occurred, notify the responsible lawyer, audit related filings, and assess prompt correction to the court and opposing counsel. The Ninth Circuit’s decision in Lnu v. Blanche makes clear that candor after an error is identified can materially affect the sanction. Read the order ↗
A safer path for self-represented litigants
AI can still help a pro se litigant translate court instructions into plain language, organize a chronology, identify questions to research, or produce a checklist. It should not be treated as the source of legal authority. Obtain each cited opinion, statute, and rule from the court, a government website, or another dependable legal source; read the material itself; confirm the quotation and page; and make sure the authority applies in the relevant court.
Do not enter private communications with a lawyer, sensitive evidence, personal identifiers, or strategy into a public chatbot on the assumption that the conversation is privileged. Check the rules of the specific court and judge before filing, including any AI disclosure or certification language. If a filed citation is wrong, correct it promptly and accurately rather than silently substituting a new case.
This briefing provides general information, not legal advice. A court’s self-help center, law library, legal-aid organization, or licensed lawyer can help a self-represented person identify the governing local requirements. The access-to-justice promise of AI is real, but it depends on a workflow that lets the user see and verify the source instead of merely trusting a polished answer.
Privilege before the prompt; signer responsibility at filing; candor after error
Heppner and the filing cases address different moments. Before the prompt, the risks are confidentiality and waiver: information may fall outside the protected relationship or lose an available protection through disclosure. At filing, the signer adopts the paper’s factual and legal representations. After an error is discovered, the governing concern becomes correction and candor.
The cases point to a straightforward operating principle: protect confidentiality before the prompt, and verify accuracy before the signature. An approved-tools list cannot do either by itself. Firms need controls for client communication, data boundaries, research provenance, substantive review, local-rule compliance, supervision, and prompt correction when something goes wrong. Courts do not need a uniform body of AI-specific law to demand those safeguards. The technology may be new. The duties of confidentiality, candor, and supervision are not.
Full source record
Every authority used in this briefing, collected in one place.
- United States v. Heppner, Memorandum, No. 25 Cr. 503 (JSR)U.S. District Court for the Southern District of New York
- United States v. Kovel, 296 F.2d 918 (2d Cir. 1961)U.S. Court of Appeals for the Second Circuit
- Lnu v. Blanche, Attorney Discipline / Use of Artificial Intelligence, No. 24-4790U.S. Court of Appeals for the Ninth Circuit
- Jones v. Kankakee County Sheriff's Department, No. 25-1251U.S. Court of Appeals for the Seventh Circuit
- Moore v. City of Del City, No. 25-6002U.S. Court of Appeals for the Tenth Circuit
- Daghra v. Hinkley, Order, No. 1:26-cv-1429U.S. District Court for the Western District of Michigan
- Oregon Supreme Court issues its first orders related to AIOregon Judicial Department
- Aldridge v. Tussing, Order, No. S072780Oregon Supreme Court
- Witkin v. McGreevy, Order, No. S072692Oregon Supreme Court
- Administrative Order 75/2026: Part 161, Use of Artificial Intelligence TechnologyNew York State Unified Court System
- Administrative Order AOSC26-12: Representations by Signers of FilingsSupreme Court of Florida
- Rules Suggestion 25-CV-S: Proposed Amendment to Federal Rule of Civil Procedure 11(a)Administrative Office of the U.S. Courts
- Formal Opinion 512: Generative Artificial Intelligence ToolsAmerican Bar Association Standing Committee on Ethics and Professional Responsibility
What decision is your firm trying to make?
Continue the conversation