California’s New AI Regulation on Attorneys, and What this Means for Other Jurisdictions.
On September 30, 2026, the State of California approved Senate Bill No. 574 which is arguably the nation’s first Artificial Intelligence (“AI”) regulation on attorneys. This bill directly amends the California Business and Professions code to require that attorneys agree to not delegate the practice of law to generative artificial intelligence, refrain from entering confidential information into the system, and take reasonable steps to ensure the accuracy of all outputs by the artificial intelligence, among other provisions. This bill will take effect on January 1, 2027 and will apply to all attorneys in the State of California. While this only governs California attorney conduct, this is an important development in the practice of law which warrants a closer look at, and determining what this means for other practitioners in other jurisdictions now that the “lens” is on attorneys using AI.
What does CA Senate Bill No. 574 entail?
California Senate Bill No. 574 was approved by the Governor and filed with the Secretary of State on September 30, 2026 with an effective date of January 1, 2027. The Legislative Counsel’s Digest highlights the following key information from the bill and how it applies to attorneys:
- The bill prohibits an attorney from delegating the practice of law AI, to refrain from entering “confidential, personal identifying, and other nonpublic information” into a generative artificial intelligence system.
- The attorney must take reasonable steps to verify the accuracy of AI outputs and to correct any “erroneous or hallucinated output” in any material used by the attorney.
- Reaffirms the doctrine that every pleading or similar document which is signed by the attorney warrants to the best of their knowledge, information, and belief, that it’s not being presented for an improper purpose and that the claims, defenses, and legal and factual contentions are warranted.
- Requires verification of all cases and citations in the brief to be “personally verified” by the attorney.
- Prohibits arbitrators from delegating decision-making to AI.
- Requires the Judicial Council to specify “standards of judicial administration to incorporate any necessary changes reflecting the further development of generative artificial intelligence.”
- Requires the State Bar to adopt procedures to determine if there is an AI violation, and if further disciplinary actions are warranted.
This raises a larger question regarding how AI is used in the practice of law. Practitioners generally are to exercise due caution when using these tools because AI collects information in perpetuity to train its models and develop better answers based on the inputs. AI in practice is not bound by the duty of confidentiality, but the attorney is, and without assurance that there is a “zero data retention” policy with the AI tool, it can be hard to satisfy this duty of confidence owed to the client.
What is “zero data retention”?
A “zero data retention” (“ZDR”) policy is a policy by a company which states that the prompts, completions, metadata, and documentation uploaded to the AI model will not be stored, logged, or used for any purpose such as model training, abuse monitoring, or product improvement. ZDR policies are of common interest to professions such as the legal profession and medical profession, where rules of professional conduct or federal statutes such as HIPAA control the “portability” or “disclosure” of these types of information. If you are an attorney, paralegal, doctor, nurse, or other professional governed by an applicable rule of professional conduct or federal statute, you must be aware of how the usage of AI in your practice can affect your obligations.
Not all AI platforms are created the same. As a practitioner bound by a duty of confidence, the safest “default” is to assume that any and all information submitted to an AI platform is presumed to be retained and used to “train” future models which can potentially destroy confidentiality. As of the date of this article, our team launched a quick survey of common AI platforms and what their current ZDR policies are.
- ChatGPT by OpenAI. By default, ChatGPT does not have a zero data retention policy for public accounts. ZDR agreements may be available for “frontier models”, but it does not appear that it is implemented by default. Source: https://openai.com/index/offering-zero-data-retention-for-frontier-models/
- Claude by Anthropic. Zero data retention is not turned on by default for Claude accounts, and ZDR policies are only available for qualified accounts on Claude for Enterprise. The same applies to HIPAA regulations within the Claude atmosphere. Source: https://code.claude.com/docs/en/zero-data-retention
- Microsoft Copilot. At this time, Microsoft Copilot does not have a zero data retention model for its services within the Microsoft 365 atmosphere, nor do any provisions appear in its API model. Source: https://learn.microsoft.com/en-au/answers/questions/6024225/microsoft-365-copilot-apis-does-enterprise-data-pr
- Google Gemini. When utilizing a paid service, Google Gemini does not use the prompts, associated system instructions, cached content, or files or responses to improve their products. However, to achieve true zero data retention, Google requires the user to take additional steps. Source: https://ai.google.dev/gemini-api/docs/zdr
- Grammarly. Grammarly retains personal data and does not have a zero data retention policy. Source: https://www.grammarly.com/privacy-policy-november-2024
- Westlaw CoCounsel. Westlaw CoCounsel utilizes SOC 2 Type II, ISO 27001, and zero-retention API architectures which helps ensure that confidential information is not being used to train AI models. Source: https://legal.thomsonreuters.com/blog/responsible-ai-in-courts-the-answer-is-cocounsel-legal/
As you can see, only one platform has a sufficient ZDR policy which could be used with client confidential data. Out of the other platforms, the consensus is clear: it’s safer to assume that any input will be used to train the AI model and the confidentiality of such data will be lost to the ether.
What this means for other jurisdictions and practitioners.
While this new legislation only affects California practitioners, other state bar associations have issued advisory opinions on how attorneys can responsibly utilize AI solutions with their law practice. This is not an admonishment of the downfalls of AI, but this serves more as a “wake-up call” to the legal profession that AI is here to stay, and it must be utilized responsibly. Instead of waiting for your local bar association or legislature to issue formal guidance on AI usage, here are some steps that you can take to ensure you are complying with the duty of confidence:
- Review the current AI products you use within your practice. You may be surprised what is included in the terms and conditions or privacy policies of this platforms, or better yet, what is not included. If it is not readily apparent that the AI platform you use has a ZDR policy in place, immediately reach out to the AI provider to see if any confidential client data is at risk when utilizing the platform.
- Review your current data storage practices. Online storage services such as Google Drive, Microsoft OneDrive, and Dropbox may have AI-based plugins or solutions which help speed productivity or recommend documents based on your current workflow. Ensure that these options are not tracking sensitive client data and take the appropriate steps to secure confidential information.
- Formalize and implement a firm AI policy. A law firm without an AI policy in place that is using AI tools is at risk for violating the rules of professional conduct. Therefore, it would be a good idea to have firm administration or managing partners seriously consider how AI usage works in their practice, and to implement appropriate policies to help ensure that all members of the firm are operating within established procedures.
- Limit the use of AI, even on seemingly harmless platforms. When in doubt, if the AI platform does not explicitly say that they have a Zero Data Retention policy or something similar, try not to use it. Complying with the rules of professional conduct and using established secure methods of data protection outweighs the costs of breaching the duty of confidentiality and potential disciplinary sanctions.
- Keep up-to-date surrounding the discussions and case law regarding AI usage. Get in touch with your local state bar association’s technology committee, or keep abreast of changes at the legislative level to see if and when your local jurisdiction will enact formal guidance or laws regarding the usage of AI.
Attorneys can utilize AI in responsible ways to accomplish their objectives while preserving the confidential nature of their client’s information. Starting off with a simple audit of current procedures and determining what solutions work and don’t work is just the beginning – maintaining current with regulations surrounding AI use and ensuring that procedures are in-place all point to an attorney’s duty of confidentiality and competence. While California is the first state to promulgate a formal regulation on attorneys regarding the usage of AI, it definitely will not be the last to do so.