MTC: When AI Lawyers’ Assistants Start Acting as an Agent: Why Autonomous Agents Cannot Be Given the Keys to Your Law Practice ⚖️

AI Agents in Law Firms Need Boundaries Before They Receive Access to Client Data. ⚖️🔐

Artificial intelligence is moving beyond the chat window. The next generation of tools does not merely draft an email, summarize a document, or answer a question. It can browse the web, search connected systems, open files, follow links, use software tools, upload information, submit forms, and take multi-step action toward an assigned objective.

For lawyers, that development deserves more than curiosity. It demands caution.

In my earlier post, “MTC: Claude Can Answer Your Emails. Why Lawyers Should Not Let AI Just Send Them Unreviewed,” I addressed the danger of allowing AI to send a substantive email without a lawyer’s review. That remains a serious concern. An AI-generated message can contain a factual error, disclose client information, make an unintended concession, or create a record that harms the client.

But email is only the beginning.

The larger issue is what happens when an AI system becomes an agent—a system authorized to use tools, access accounts, navigate websites, retrieve information, and act through the lawyer’s digital environment. These systems are often marketed as “agentic,” “autonomous,” “proactive,” or “hands-free.” Those labels may sound like productivity features. In a law practice, they should also sound like professional-responsibility warnings. 🚨

The legal question is no longer only, “Did the AI draft something accurate?”

It is, “What can this AI do in my name, with my credentials, using my clients’ information—and who is responsible if it does the wrong thing?”

The answer is not the vendor. It is not the algorithm. It is the lawyer and, where applicable, the law firm that authorized the system, connected the accounts, granted the permissions, and failed to impose adequate safeguards.

From AI Assistant to AI Agent

It helps to distinguish between ordinary generative AI and an AI agent.

A conventional generative-AI tool generally waits for a user prompt. It produces text, analysis, a summary, or a draft. The lawyer then decides what to do with that output. The tool may be imperfect, but it is usually operating within a relatively contained workflow.

An AI agent is different. It may be able to plan and perform a sequence of tasks. It can interact with browsers, software applications, application programming interfaces, email, shared drives, calendars, cloud services, and other connected tools. It may take the next step without waiting for a fresh instruction at each point.

That distinction matters because an AI agent can inherit the power of the person or organization that deploys it.

If an agent is connected to a lawyer’s email, document-management system, cloud storage, password manager, practice-management platform, legal research account, calendar, client portal, or browser session, it may have access to far more than the task requires. It may also have the capacity to do far more than the lawyer intended.

The agent does not need malicious intent to create damage. It may misunderstand an instruction. It may draw the wrong inference. It may rely on inaccurate information. It may follow a link it should not follow. It may act on content supplied by an adversary. Or it may perform an otherwise lawful task in a way that reveals confidential information, exceeds the scope of authority, or causes a legally consequential result.

This is why a law firm should never evaluate an agentic AI tool as if it were merely a faster chatbot.

When AI Leaves the Sandbox

Every responsible firm should think in terms of two sandboxes.

When an AI Agent Exceeds Its Authority, Lawyers Must Be Ready to Stop It Immediately. 🛑⚖️

The first is a technical sandbox: a restricted environment that limits what software can access, change, or transmit. The second is a professional sandbox: a controlled setting in which lawyers can test AI without exposing live client data, actual accounts, privileged documents, or external systems to avoidable risk.

Problems begin when the AI leaves either one. 🔒

Consider a few plausible instructions:

  • “Review the client’s online accounts and gather the relevant documents.”

  • “Find everything public about this company and organize it by issue.”

  • “Check the opposing party’s portal for new activity.”

  • “Handle this vendor issue and get us back on track.”

  • “Research whether this online filing system will accept our documents.”

  • “Use the web to find contact information and send the necessary requests.”

Each prompt appears practical. Each could become dangerous if the agent’s tools, permissions, and boundaries are unclear.

A lawyer may intend a public-web search. The agent may encounter a login screen, use stored browser credentials, and access a restricted account. A lawyer may intend for the agent to collect public information. The agent may scrape, copy, or retain material in a manner that violates terms of use, triggers security controls, or creates legal exposure. A lawyer may intend for the agent to summarize a webpage. The agent may follow embedded directions, interact with a third-party system, or use information from a connected firm repository that was unnecessary to the assignment.

Lawyers must be especially careful not to authorize, encourage, or negligently permit activity that crosses legal or ethical boundaries. AI does not create an exception to laws governing unauthorized access, fraud, privacy, intellectual property, data protection, or deceptive conduct.

The better framing is not that AI will “infiltrate” a company. The concern is more precise and more likely: an unsupervised agent may access, probe, interact with, retrieve from, or transmit information through third-party systems in ways that exceed the lawyer’s authority, violate applicable rules or agreements, compromise security, or harm a client. Just as you are responsible for your paralegal when they take unethical or illegal steps in their work, you are also responsible for AI Agents when they go awry.

Also, machine speed does not reduce lawyer responsibility. It can increase the scale of the harm.

The Prompt-Injection Problem

One of the most important risks is indirect prompt injection.

A prompt injection occurs when instructions are designed to manipulate an AI system away from its intended task. Indirect prompt injection is particularly troubling for AI agents because the hostile instruction may be embedded in material the agent reads rather than placed directly in the lawyer’s request.

The source could be a webpage, email, PDF, calendar entry, legal document, attachment, database entry, shared file, online form, API response, or other external content. Security guidance for AI agents stresses that external content should be treated as untrusted, because an agent may encounter instructions intended to redirect its actions or misuse its connected tools.

Here is a simplified illustration:

A lawyer instructs an AI agent to review public webpages for information about a business dispute. One webpage contains hidden text directing the agent to locate “supporting documents” in the lawyer’s connected cloud drive and upload them to an external location.

The lawyer never gave that instruction. The webpage did.

A well-designed system should reject it. But responsible lawyers should not assume that an AI will reliably distinguish between a lawyer’s authorized objective and hostile instructions hidden inside content the agent encounters. The core danger is that agentic systems combine three things that do not safely belong together without controls:

  1. Untrusted content.

  2. Broad access to sensitive information.

  3. Authority to take action.

That is not a theoretical concern. Open Worldwide Application Security Project (OWASP)'s agent-security guidance identifies prompt injection, excessive agency, insecure tool use, identity and authorization failures, and unbounded autonomy as material risks for systems that can act through tools and connected accounts. Its recommended controls include treating external data as untrusted, applying least-privilege permissions, requiring human involvement for high-risk actions, logging activity, separating decision-making from irreversible execution, and testing agents against adversarial inputs before deployment.

Editor’s Note: My earlier article, “MTC: Judges Will Be Hunting These AI Tricks After Brazil’s Scandal,” addressed hidden prompts in court filings—concealed text or instructions intended to influence an AI-enabled system’s treatment of a case. Lawyers should never engage in that practice. Nor should they allow an AI agent to follow hostile instructions embedded in webpages, emails, attachments, or other external content. That conduct threatens candor toward the tribunal and may implicate ABA Model Rules 3.3 and 8.4. The lesson is symmetrical: do not manipulate an AI system, and do not give an AI system unchecked authority to be manipulated by someone else. ⚖️

For lawyers, the practical rule is straightforward:

An AI agent may read untrusted content, but it must never be allowed to treat that content as authorized instruction.

Confidentiality Is Not a Setting

lawyers must monitor Prompt Injection as it Can Turn a Helpful AI Agent Into a Law-Firm Security Risk. 🚨🔒

ABA Model Rule 1.6 should be at the center of every law firm’s AI-agent policy.

Rule 1.6(a) generally prohibits a lawyer from revealing information relating to the representation of a client without informed consent, implied authorization to carry out the representation, or another applicable exception. Rule 1.6(c) also requires a lawyer to make reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to representation.

An AI agent connected to a law firm’s systems can create both dangers.

First, there is overcollection. The agent may access client information beyond what is reasonably necessary to perform the requested task.

Second, there is overaction. The agent may use, combine, disclose, upload, summarize, transmit, or act upon information beyond the lawyer’s instruction or authority.

This is why the relevant question is not merely whether the AI vendor uses encryption or advertises a secure platform. Those facts matter. They are not enough.

Lawyers must also ask:

  • What systems can the agent access?

  • What client data might it encounter?

  • Can it retrieve information from more than one matter?

  • Can it read attachments, shared drives, calendars, contact lists, or historical email?

  • Can it use stored sessions or credentials?

  • Can it upload, download, send, submit, or share material?

  • Can it contact third parties?

  • Can it alter records, schedule events, approve transactions, or make commitments?

  • Is the agent’s activity logged in a way the firm can review after an incident?

  • Can the firm immediately revoke its access?

ABA Formal Opinion 512 explains that lawyers using generative AI must fully consider existing professional obligations, including competence, confidentiality, client communication, supervision, candor, and reasonable fees. The opinion does not create an AI exception to the Rules of Professional Conduct. It applies familiar duties to newer technology.

That principle becomes even more important when the AI is not simply producing words but is acting through connected systems.

Do not give an AI agent your whole digital office merely because it promises to organize the desk.

Competence Means Understanding Authority

ABA Model Rule 1.1 requires competent representation. Comment 8 provides that lawyers should keep abreast of the benefits and risks associated with relevant technology.

That duty does not require every solo practitioner or small-firm lawyer to become an AI security engineer. It does require more than clicking “enable” on a product feature.

For agentic AI, competence means understanding the system’s practical authority:

  • Whether it can browse the open web.

  • Whether it can access authenticated websites through saved sessions.

  • Whether it can use a firm’s email or cloud storage accounts.

  • Whether it can invoke software tools or APIs.

  • Whether it can create, modify, upload, delete, send, or submit information.

  • Whether it can act repeatedly without asking for approval.

  • Whether permissions can be limited by task, user, matter, data source, and destination.

  • Whether the firm can reconstruct the agent’s actions after a security or ethics incident.

The National Institute of Standards and Technology (NIST)’s AI Agent Standards Initiative recognizes that secure agent use requires work on identity and authentication infrastructure for interactions in which agents act on behalf of users. That is an important reminder for law firms: an agent should not simply be treated as an invisible extension of a lawyer’s identity. Its access, authority, and activity need governance.[nist]

Marketing language matters here. When a vendor describes an AI system as autonomous, proactive, browser-enabled, hands-free, or able to “get things done,” the lawyer should translate those claims into risk questions:

  • What can it do?

  • What can it access?

  • What can it send?

  • What can it change?

  • What happens when it encounters conflicting instructions?

  • What happens when it is wrong?

Those are competence questions, not technology-department questions.

Supervision Does Not Disappear

everyone in the law firm, lawyers, paralegal, secretaries, staff, etc., must learn that Responsible Legal AI Starts With Least-Privilege Access and Human-Led Governance. ✅⚖️

AI is not a lawyer. It is not a paralegal. It is not a law clerk. It is not an independent source of professional judgment.

But if it performs work in connection with client representation, it must be subject to appropriate oversight.

ABA Model Rules 5.1 and 5.3 require lawyers with managerial and supervisory responsibilities to make reasonable efforts to ensure that lawyers and nonlawyer assistance operate consistently with the firm’s professional obligations. The exact categorization of an AI system may be unsettled in some contexts. The governing principle should not be: a lawyer cannot escape responsibility by assigning professional work to a software product.

A disciplinary authority will not be satisfied with this explanation:

“The system accessed the account, found the information, contacted the third party, or took the action on its own.”

The next question will be obvious:

“Why did the lawyer give the system the power to do that?”

That question should be answered before the tool is used—not after an incident.

Lack of oversight is not a defense to a bar complaint. It may be the central allegation.

The same is true in a malpractice dispute. If an agent missed a material deadline, sent privileged information to the wrong recipient, accepted an unfavorable term, followed malicious instructions, accessed a restricted system, or failed to alert the lawyer to a critical issue, the firm will need to explain its safeguards. A vague assertion that “the AI made the decision” does not reduce the lawyer’s duty to the client.

Where AI Agents May Help

None of this means lawyers should reject AI agents categorically. They may offer real value when narrowly deployed, properly tested, and meaningfully supervised.

Appropriate uses may include:

  • Sorting inbound messages by matter, urgency, sender, and subject.

  • Identifying potential deadlines or tasks for lawyer review.

  • Preparing internal summaries of selected correspondence.

  • Locating documents within a defined, matter-specific repository.

  • Creating preliminary chronologies from reviewed materials.

  • Comparing a draft against a firm-approved checklist.

  • Preparing an internal first draft of a non-substantive task list.

  • Flagging missing attachments, inconsistent dates, or unanswered questions.

  • Gathering information from a specified set of approved public sources.

The critical limits are clear:

  • The agent should have only the access it needs.

  • It should operate only within a defined task and approved data set.

  • It should not use unrestricted browser sessions or broad credentials.

  • It should not make substantive legal judgments.

  • It should not communicate externally without lawyer review.

  • It should not upload, submit, delete, purchase, disclose, or alter information without affirmative human approval.

The fact that a tool is capable of acting does not mean the law firm should let it act.

A Practical Law-Firm Policy

For solo and small-to-medium firms, a useful starting policy is this:

No AI agent may access live client-data systems, authenticated third-party accounts, or firm-wide repositories unless the firm has documented the business purpose, evaluated the risks, restricted access, and established human approval for consequential actions.

That policy should include the following controls:

  • Use least-privilege access. Give an agent only the minimum permissions needed for a defined task.

  • Do not provide master credentials, password-manager access, unrestricted administrative rights, or blanket cloud-drive access.

  • Create separate accounts for testing and limited workflows when possible.

  • Prohibit autonomous external communications, uploads, form submissions, record changes, financial activity, and data transfers without affirmative human approval.

  • Limit agent access by client matter, practice group, data category, source, and destination.

  • Treat webpages, emails, attachments, documents, and external tool results as untrusted input.

  • Disable or restrict browsing when browsing is unnecessary to the approved task.

  • Require logging of actions, tools used, information accessed, approvals obtained, and external destinations.

  • Establish a “kill switch” that permits the firm to revoke permissions, disconnect integrations, and terminate active sessions promptly.

  • Test the system against prompt injection, harmful tool calls, excessive permissions, and anomalous behavior before using it in live client work.

  • Review vendor terms for confidentiality, retention, training, access, subprocessors, security, auditability, and breach notification.

  • Train lawyers and staff to recognize that an AI summary is not a substitute for reviewing the underlying record. 🧠

These are not bureaucratic obstacles to innovation. They are the governance mechanisms that make responsible innovation possible.

The Lawyer Still Owns the Result

Lawyers Must Act as the First, Last, and Continuous Line of Defense for AI Agents. ⚖️🔒

The central lesson is simple.

An AI agent can be a useful assistant. It may help a law firm reduce repetitive work, organize information, identify issues, and prepare preliminary work product. Those benefits are real.

But an AI agent is not a colleague with legal judgment. It is not a licensed professional. It cannot hold client confidences in the ethical sense. It cannot explain its actions to disciplinary counsel. It cannot defend a malpractice claim. It cannot be sanctioned in the way a lawyer or law firm can.

It is a tool acting with the authority its human users give it.

When a lawyer authorizes an AI to operate beyond the sandbox—to browse, access accounts, use connected software, retrieve information, or take action—the lawyer has not delegated accountability. The lawyer has expanded the range of conduct for which accountability may be demanded.

Let AI assist. Let it organize. Let it draft. Let it identify questions for review.

But before granting it access to your firm’s digital office, your client information, or the internet under your identity, ask the question that will matter most if something goes wrong:

What exactly can this system do in my name? ⚖️

MTC: Claude Can Answer Your Emails. Why Lawyers Should Not Let AI Just Send Them Unreviewed. 🤖⚖️

One Click, Big Risk: AI Email Ethics for Lawyers!

David Nield’s recent Lifehacker experiment, “I Let Claude Answer My Emails for Me, and Here’s How It Went,” is worth every lawyer’s attention. Not because it reveals a spectacular AI failure. It does something more useful: it shows how competent-looking AI email automation can create professional risk precisely because it often appears to work.

Claude can now connect to Gmail, search an inbox, summarize messages, draft replies, and send emails from the connected account. The feature’s default settings are cautious: automatic sending is off unless the user changes permissions. But users can authorize individual actions—such as searching, sending, or editing labels—to “Never allow,” “Always allow,” or “Always ask for permission.”

For ordinary personal email, that may be a reasonable productivity choice. For lawyers, it demands a much more careful analysis. A law-firm email is not simply a unit of inbox administration. It may be a communication to a client, opposing counsel, a tribunal, an agency, an expert, a witness, or an insurer. It may convey legal advice, create reliance, disclose strategy, make a representation, accept a deadline, or become an exhibit.

That is why the distinction between AI-assisted drafting and AI-authorized sending matters so much. The first can be useful. The second can amount to unsupervised legal communication.

The Most Important Detail

Nield gave Claude permission to send messages automatically, but he did not test the feature with his actual editors. He decided that a hallucinated misunderstanding was not worth risking and instead conducted the experiment through an exchange with a secondary email account. That was a sensible safeguard. It is also the heart of the legal-tech lesson. 🔍

If a technology writer worries that an AI-generated email might create confusion with an editor, lawyers should recognize the dramatically higher stakes of their own communications.

Consider a few routine examples:

  • An AI responds to opposing counsel: “We agree to the requested extension.”

  • An AI tells a client: “You should withdraw the appeal and refile later.”

  • An AI replies to an agency representative: “We have no additional responsive documents.”

  • An AI responds to a settlement inquiry: “My client is prepared to accept that proposal.”

  • An AI tells a witness: “You do not need to preserve those messages.”

Each could be inaccurate, incomplete, premature, unauthorized, or inconsistent with the client’s objectives. Each could create avoidable procedural, strategic, ethical, or malpractice exposure.

The danger is not only an obvious hallucination. It is a plausible sentence sent at the wrong time, to the wrong recipient, with an unintended implication.

Competence Requires More Than Turning It On

AI Email Assistants Transform Legal Workflows With Human Oversight!

ABA Model Rule 1.1 requires competent representation. Comment 8 specifically directs lawyers to keep abreast of the benefits and risks associated with relevant technology.

That obligation does not mean a lawyer must master the underlying architecture of a large language model. It does mean a lawyer must understand what the tool can access, what it can do, what it may get wrong, and what controls exist before adopting it in a client-facing workflow.

Claude’s Gmail integration illustrates why that inquiry matters. The system can understand labels, dates, contacts, subject lines, themes, and context. It can identify a recent message, carry information through a thread, and compose a reply based on instructions. It can also use connected Google Drive data to prepare a work summary and fold that material into an outgoing email.

Those are real capabilities. They are also real risk surfaces. A connected inbox and Drive account may contain privileged communications, work product, medical records, personnel documents, settlement analyses, client financial information, litigation strategy, and confidential drafts.

Before connecting an AI platform to firm email or cloud storage, lawyers should ask:

  • What email and document data can the system retrieve?

  • What information is retained, logged, or used to improve the service?

  • Does the vendor contractually prohibit training on the firm’s data?

  • Who may access data at the provider, and where is it stored?

  • Can the firm restrict access by user, matter, mailbox, sender, or document type?

  • Can the firm produce an audit trail showing what the AI accessed, drafted, and sent?

  • What happens to the firm’s data when the subscription ends?

Those questions are not technology trivia. They are part of competent vendor assessment.

The “Cheers” Problem Is Not Trivial

Balancing AI Innovation With Human Judgment in Legal Practice

In Nield’s test, Claude composed a generally acceptable message. Yet it signed the email with “cheers,” a phrase the author said he would not ordinarily use. That small mismatch is revealing. Claude had not merely organized information. It had made a communicative choice in someone else’s name.

For a lawyer, voice is not just branding. Tone can convey firmness, concession, uncertainty, urgency, skepticism, hostility, openness to settlement, or a willingness to cooperate. A message that is “a little generic,” as Nield described Claude’s output, may be harmless when discussing weather and a meeting with oneself. It may be harmful in a dispute where each word will be parsed for meaning. ✉️

An email that begins, “We are happy to work with you,” may convey a strategic position that the lawyer did not intend. A reply that omits one key qualification can alter the practical meaning of a settlement discussion. A bot that tries to be helpful may include a fact from a prior thread that should not be repeated, or it may summarize a client’s situation so broadly that it creates a misleading record.

Lawyers should not equate grammatically fluent text with sound legal judgment.

Rules 1.2, 1.4, and 1.6

ABA Model Rule 1.2 requires lawyers to abide by a client’s decisions concerning the objectives of representation and to consult with the client about the means of pursuing those objectives. An AI system cannot determine whether accepting an extension, offering a document, softening a demand, or answering a client’s question advances those objectives.

Rule 1.4 requires appropriate client communication. An AI-generated reply can appear reassuring while omitting necessary advice, misunderstanding the issue, or providing a client with an answer that no lawyer has evaluated. A client should not receive what appears to be legal counsel when it is actually unreviewed probabilistic text.

Rule 1.6 is equally central. Lawyers must not reveal information relating to representation without authorization, subject to limited exceptions. Giving an AI provider access to email and Drive is not automatically unethical, but it requires reasonable diligence and safeguards. The more expansive the permission, the more careful the analysis must be. 🔒

A lawyer who enables automatic sending compounds the issue. Now the system is not only reading protected information; it may also select, summarize, and transmit it externally.

When AI Bots Email Each Other

Nield also raises a concern that lawyers should not dismiss: the prospect of AI systems emailing other AI systems “into infinity.”

That is more than a philosophical concern in legal practice. Imagine two firms each authorizing AI assistants to respond automatically. One system writes, “We can accommodate a brief extension.” The other interprets that as agreement, sends a confirmation, and then proposes a revised deadline. The first system responds with language suggesting continued assent.

Neither lawyer may have reviewed the exchange until a dispute arises. Yet both sides may face a written record that appears to memorialize an agreement.

The proper response is not to ban AI from legal email. It is to preserve human responsibility at the point of external communication.

The Right Workflow

Legal Technology Works Best when lawyers balance Ethics, Trust, and Accountability!

AI can help lawyers manage an overloaded inbox. It can identify urgent messages, group correspondence by matter, summarize long threads, retrieve relevant prior communications, and prepare a first draft. Those uses can reduce administrative burden and create time for legal analysis. ✅

But law firms should adopt a bright-line rule: No AI system may automatically send a substantive external communication without human review and approval.

A practical protocol should require the reviewing lawyer or trained staff member to:

  • Read the full thread and relevant attachments.

  • Confirm the recipient and email address.

  • Verify every factual assertion and deadline.

  • Check for client commitments, concessions, and settlement implications.

  • Remove unnecessary confidential information.

  • Confirm that the message reflects the lawyer’s actual voice, judgment, and strategy.

  • Send the communication only after that review is complete.

Claude’s Gmail feature is impressive. It can make email easier. But as Nield’s own decision to test it only with himself demonstrates, capability is not the same as reliability, and reliability is not the same as professional responsibility.

For lawyers, the governing principle should be simple: let AI prepare the draft; let a responsible human decide whether it should ever leave the outbox. ⚖️

MTC

MTC: When Your Phone's "Self-Destruct" Button Becomes a Federal Crime: Duress Passwords, Spoliation & the Duty to Preserve ⚖️📱

lawyers should know the interplay among Duress Passcodes, Border Searches, and Smartphone Evidence Destruction

The Justice Department just indicted an Atlanta man for handing border agents a "duress passcode" that wiped his phone during a secondary inspection. It's believed to be the first prosecution of its kind — and it should put every lawyer (and every client with a smartphone) on notice. 🔔

"Duress passwords" — sometimes called "panic codes" or "coercion PINs" — are a real feature in iOS, Android, and third-party privacy apps. Enter one code and the device unlocks normally. Enter the duress code and the phone quietly obliterates its encryption keys, rendering the data unrecoverable. For journalists, activists, and anyone crossing borders with sensitive material, they're a shield. For prosecutors, they look like a loaded gun pointed at the evidence locker. 🔫💾

Here's where the professional-responsibility rubber meets the road. ABA Model Rule 3.4(a) makes it professional misconduct to "unlawfully obstruct another party's access to evidence or unlawfully alter, destroy or conceal a document or other material having potential evidentiary value." Comment 2 to Rule 3.4 clarifies that the duty attaches when a lawyer knows or reasonably should know that litigation is pending or reasonably foreseeable. A border inspection of a device you know contains responsive data? That's reasonably foreseeable. 📋

lawyers need to know the ABA Ethics Rules for Lawyers Protecting Digital Client Data!

But Rule 1.15 (Safekeeping Property) and Rule 1.6 (Confidentiality) also impose affirmative duties to protect client data. A lawyer who carries privileged communications across a border has a genuine tension: the duty to preserve vs. the duty to safeguard. The duress password sits exactly on that fault line. If you trigger it before a preservation obligation attaches — say, because your phone is stolen — it's property protection. If you trigger it after a subpoena, a litigation hold, or a border detention you knew was coming, it's spoliation. 🧨

The line isn't always bright. Good-faith accident — dropping your phone in coffee, a toddler factory-resetting your iPad — is not a crime. But intent is inferred from circumstances: Did you enable the duress feature after learning of the investigation? Did you select the code specifically for the border crossing? Did you fail to issue a litigation hold to yourself? Courts draw adverse inferences from all three. 📉

Practical takeaways for your practice:

1.      Audit your own devices now. If you use a duress feature, document why and when you enabled it — before any matter makes it suspect. 📝

2.     Issue written preservation notices to yourself the moment litigation is reasonably foreseeable.

3.     Advise clients in writing about duress features before they travel. A client who wipes a phone at the border because you never mentioned the risk creates a Rule 1.1 (Competence) and Rule 1.4 (Communication) problem for you. ✉️

4.     Use encrypted cloud backups with immutable retention (“WORM” [Write Once, Read Many] storage) so a local wipe doesn't equal total loss. That's preservation and property protection. ☁️🔒

what are the four takeaways lawyers should know when it comes to protecting client data at the boarder!

The Atlanta case will test whether providing a duress code to law enforcement is "destruction" under 18 U.S.C. § 1519 or the Federal Rules' spoliation doctrine. But you don't need the verdict to know your ethical north star: preservation obligations attach when you know — or should know — the data matters. The duress code doesn't suspend that duty; it just makes the violation faster and harder to detect. ⚡

Stay tech-savvy. Stay ethical. And maybe keep a spare phone in the carry-on or use a different phone specifically for travel. 🧳📱

MTC*

* Please remember this is an editorial not legal advice nor create an attorney-client relationship. You should contact an attorney for legal advice about your situation should the need arise.

🚨 BOLO: Apple's Emergency Mac Patch Closes a Screen Sharing Backdoor — Lawyers Update Now!

your apple computer may need an update right now!

Here's a security bug that has nothing to do with your caseload and everything to do with your law license. On August 6, 2026, Apple pushed an unusual, single-purpose emergency patch after security researchers discovered that Screen Sharing on the Mac could be tricked into granting full desktop access without a valid password. If you use a Mac to store client files, draft privileged communications, or manage your practice, this is a “Be On the Look Out” moment, and I mean that literally.

What Actually Happened

update your mac and windows os today and keep an eye out for new updates - they are more frequent than you think!!!

Apple's advisory describes the flaw in characteristically understated terms: "An attacker on the network may be able to authenticate to Screen Sharing without valid credentials". Translated out of engineer-speak, a bug in how macOS tracked login attempts meant the system could be fooled into treating an unauthenticated session as verified. Security firm Huntress went further, explaining that the bug exploited the Screen Sharing service's implementation of Secure Remote Password, which "ultimately allows pre-authenticated remote code execution on all supported macOS versions". In plain English: someone on your network, whether that's your building's shared Wi-Fi, a co-working space router, or a compromised office LAN, could potentially run code on your Mac without ever knowing your password. That's not a nuisance bug. That's the kind of hole that keeps ethics counsel up at night.

The flaw has an official tracking number, CVE-2026-65400, which is just a standardized ID security researchers use to reference a specific vulnerability across advisories and news coverage — think of it like a case citation for bugs 📋. It reaches across three generations of macOS: Tahoe, Sequoia, and Sonoma. Apple fixed it with macOS Tahoe 26.6.1macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 all released the same day, an unusual move that signals Apple treated this as serious enough to skip its normal beta-testing cycle.

Why This Matters for Your Practice

your ethical duty of technological competence doesn't pause because a vulnerability sounds technical!

I've said it before on here and on the podcast, and I'll say it again: your ethical duty of technological competence doesn't pause because a vulnerability sounds technical. ABA Model Rule 1.1, Comment 8, requires lawyers to "keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology" 📚. A screen-sharing bypass that hands an attacker the same control as someone physically at your keyboard is exactly the kind of risk that comment contemplates.

Model Rule 1.6 compounds the stakes. If Screen Sharing was enabled on a Mac holding client files, an attacker exploiting this flaw before the patch could have accessed privileged communications, case strategy, or financial data without leaving an obvious trace 🔐. That's a confidentiality problem regardless of whether you can prove exploitation occurred. And if you're a firm supervising associates or staff under Rule 5.1 or 5.3, this is also a moment to confirm every managed device across your practice, not just your own laptop, has been patched.

The silver lining: Apple has stated there's no evidence this bug was exploited in the wild before the fix shipped, and Screen Sharing is off by default on most Macs. But "off by default" isn't the same as "off on your machine," especially if you or an IT vendor ever turned it on for remote support.

How to Check and Patch Your Mac

This is a five-minute task, and it should not wait until end of day. ⏱️

  1. Click the Apple menuSystem Settings

  2. Select GeneralSoftware Update

  3. Install whichever applies: macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9

If your firm manages devices through IT and you can't update immediately, disable the feature entirely: Apple menuSystem SettingsGeneralSharing, then toggle Screen Sharing off. Note that Huntress specifically warns this is a pre-authentication bug, so the usual hardening tricks (removing user accounts, disabling legacy VNC passwords) won't protect you; only the patch or fully disabling the feature will.

The Bigger Pattern Worth Watching

A good rule of thumb is to keep your software os and programs up to date!

This isn't the first time Apple has issued an emergency patch outside its normal cadence, and it won't be the last. Solo and small firms need a patching routine, not just reactive fixes.

The takeaway is simple, even if the underlying vulnerability wasn’t: Almost always, keep your software up to date!  Update your Mac today, verify Screen Sharing's status even if you don't think you use it, and treat this as a reminder that competence under Rule 1.1 is an ongoing obligation, not a box you check once. 🛡️

Follow The Tech-Savvy Lawyer.Page for updates and alerts!

MTC: Washington’s Bar Exam Meltdown: What It Says About Cyber Risk, Competence, and the Future of Legal Tech ⚖️💻

Washington Bar Exam Cybersecurity Crisis Exposes Legal Technology Risks!

Washington’s last‑minute cancellation of this summer’s bar exam is not just a licensing story; it is a technology and ethics story that should make every practicing lawyer sit up straight. For solo and small‑firm practitioners, this is a case study in how fragile our exam, court, and law‑practice infrastructure has become in the face of sophisticated cyber threats—and how quickly that fragility can collide with our professional duties under the ABA Model Rules.

What Happened in Washington—and Why It Matters

The Washington bar abruptly pulled the plug on its planned exam administration, citing serious concerns about system integrity and the security of the underlying technology. Although details are still emerging, the through‑line is clear: the systems that deliver and proctor high‑stakes exams are now attractive targets for attackers and highly sensitive to infrastructure failures.

Think about the impact on examinees. Months of preparation, financial investment, travel, and childcare planning vanished with a late‑stage cancellation notice. But this is not only about logistics. This is about trust: Trust in the profession’s gatekeeping machinery and in the digital rails we have built for critical legal functions. When that trust erodes, the ripple hits everything from admissions to public confidence in our systems.

For working lawyers, this is a preview of what can happen when core legal processes—hearings, filings, exams, CLEs—depend on infrastructure that may be compromised or simply not resilient enough to withstand modern threats.

From Hotel Wi‑Fi to Bar Exams: The Captive Portal Threat 🚨

If the Washington story feels abstract, pair it with Microsoft’s recent warning about hotel and hospitality Wi‑Fi. Microsoft has identified a campaign, dubbed “CaptiveCrunch,” attributed to Russian‑linked threat actors (Storm‑2945), that hijacks captive portals—the login or “click to accept” pages we all use in hotels and conference centers—to steal credentials and deliver malware.

These attacks work by compromising the network infrastructure that sits between the user and the open internet. When a lawyer or bar examinee connects to the hotel Wi‑Fi and sees what looks like a routine sign‑in or software update prompt, that page may in fact be controlled by a threat actor. Microsoft reports that the attackers can:

  • Redirect users to fake Microsoft 365 sign‑in pages and harvest credentials without sending a phishing email.

  • Abuse device‑code authentication flows, so even multi‑factor authentication can be sidestepped if the victim enters a code and approves the request.

  • Deliver a Windows remote access trojan (“CornFlake”) that can log keystrokes, grab files, record audio and video, and maintain persistent access.

Now layer this onto the bar exam setting. You have hundreds of exam takers in hotels and rented housing, many running locked‑down exam software on laptops that still need network access for downloads, updates, or cloud syncing before or after the exam. If the exam provider’s systems or the candidates’ devices ride on compromised networks, you have a recipe for:

  • Actual or suspected compromise of exam content

  • Loss or alteration of answer files

  • Exposure of highly sensitive personal and biometric data

The bar’s decision to cancel may well reflect a recognition that once you have a credible cyber risk in the mix, it is better to protect exam integrity—even at enormous logistical and human cost—than to run an exam whose validity may later be attacked.  My heart goes out to the affected examinees, who have been left adrift in a difficult professional limbo—unable to move to the next stage of their careers and required to devote still more time, money, and emotional energy to preparing for another exam, with the hope that it will not be disrupted by malicious actors.

Ethics Meets Cyber Reality: ABA Model Rules in Play 📜

CaptiveCrunch Hotel Wi-Fi Attacks Threaten Lawyers’ Digital Security

This is where your daily practice intersects directly with the bar’s meltdown.

Model Rule 1.1 (Competence) explicitly includes a duty to understand “the benefits and risks associated with relevant technology.” Cyber threats like CaptiveCrunch are now squarely within “relevant technology.” If you travel for hearings, depositions, client meetings, or bar events and routinely connect to hotel Wi‑Fi without safeguards, you are not just taking a personal risk; you may be jeopardizing client confidences, privileged communications, and case strategy.

Model Rule 1.6 (Confidentiality of Information) requires reasonable efforts to prevent unauthorized access to client information. Using untrusted hotel or conference Wi‑Fi without protections—especially when we now have concrete warnings from Microsoft—raises tough questions about whether your security posture is still “reasonable.”

Model Rule 5.3 (Responsibilities Regarding Nonlawyer Assistance) and Rule 5.1 (Supervisory Lawyers) also surface here. When your cloud vendors, exam providers, or outsourced IT teams operate systems on which your work depends, your duty is not satisfied by “we assumed they had it handled.” You must perform due diligence, ask questions about security practices, and be prepared to adjust your workflows when a vendor’s risk profile changes.

The Bar Exam as a Canary in the Cyber Coal Mine 🐤

The Washington bar exam cancellation looks like a one‑off crisis, but it is better seen as a canary in the coal mine for the entire legal ecosystem.

We increasingly rely on:

  • Online proctoring systems for bar exams, law school tests, and certifications

  • Remote hearing platforms and e‑filing systems for courts

  • Cloud‑based case management, timekeeping, and trust accounting tools

Each of these systems sits on infrastructure that can be compromised at the network, platform, or endpoint level. The CaptiveCrunch campaign shows that attackers are willing to invest in compromising hospitality networks globally, in part because those networks handle high‑value corporate and professional traffic.

If attackers can hijack captive portals to intercept Microsoft 365 logins and deliver Remote Access Trojans (RATs) like CornFlake, they can also target:

  • Judicial staff connecting from hotels during conferences

  • Law firm partners working on the road

  • In‑house counsel traveling to negotiation sessions

Once a single endpoint is compromised, attackers can move laterally into cloud resources, email archives, document management systems, and case data.

In other words, the Washington bar’s crisis is the profession’s crisis—just seen in extreme close‑up.

Practical Security Takeaways for Solo and Small‑Firm Lawyers 🛡️

So what do you do differently now?

Microsoft’s recommendations for travelers are a good starting point: assume guest networks are untrusted, favor mobile hotspots or secured private connections, and avoid performing updates or entering credentials through captive portals. Let’s translate that into concrete steps for law practice:

Travel Playbook

  • Prefer your phone’s hotspot or a dedicated travel router with a trusted VPN when accessing email, case management, or client files on the road.

  • If you have no choice but to use hotel or other public Wi‑Fi, connect only through a reputable VPN and treat the captive portal as a necessary but dangerous doorway.

  • Complete only the minimum captive‑portal steps needed to get online, and then avoid entering passwords, approving authentication prompts, or installing updates until your VPN is active and you are past the captive‑portal page.

Authentication Hygiene

  • Move to phishing‑resistant authentication where possible (hardware security keys, platform authenticators) and restrict device‑code flows unless truly needed

  • Train your team to treat unexpected device‑code prompts or update pages during hotel logins as red flags, not background noise.

Vendor and Exam Provider Scrutiny

  • Ask pointed questions about incident response, logging, and how they handle suspected network compromise.

  • Build contingency plans—if an exam, hearing, or critical system fails or is compromised, what is your fallback?  (Perhaps a cheap backup laptop? Apple has a pretty good return policy - check provider details for timeliness and other requirements.)

Final Thoughts: Looking Ahead - Resilience, Not Just Compliance ✅

Cybersecurity Competence Is Now Essential for Modern Legal Practice!

The Washington bar’s decision to cancel its exam sends a hard message: compliance checklists and bare‑minimum security are no longer enough. We need resilience—systems and workflows designed to fail gracefully, with clear fallback paths that do not compromise integrity or fairness.

For bar authorities and courts, that means:

  • Building redundancy into exam and hearing platforms

  • Running adversarial security testing and tabletop exercises

  • Communicating transparently with stakeholders about how cyber risk is identified and mitigated

For practicing lawyers, it means re‑framing technology as part of our core competence, not a bolt‑on afterthought. Model Rule 1.1’s commentary on technology is not aspirational; it is a reflection of the reality that our ethical duties now live at the intersection of law and information security.

The bar exam meltdown in Washington is a wake‑up call. Pair it with Microsoft’s warning on hotel Wi‑Fi, and the message is unmistakable: our digital rails are under live fire. The question is whether we treat this as yet another “unprecedented” event—or as the moment we upgrade our tools, our habits, and our ethics posture to meet the threat.

MTC

MTC: Judges Will Be Hunting These AI Tricks After Brazil’s Scandal

it is hard to believe that judges will be happy if lawyer insert “code” into their online filings!

Recently, Brazilian court officials uncovered something that should make every tech‑savvy lawyer sit up straight. In a labor court, staff discovered a filing that looked ordinary to the human eye—until they examined it more closely. Hidden in the document was text written in white font on a white background, invisible to anyone casually reading the PDF but fully legible to the court’s AI system.

That invisible text was not a typo. It was an instruction—what technologists call a “prompt injection”—telling the court’s AI software to review the case only superficially and not to challenge the evidence submitted. In other words, the filing was designed to trick the judiciary’s own AI tools into rubber‑stamping a favorable outcome by smuggling in commands that humans would never see.

Fortunately, court staff caught the scheme before it affected the proceedings. But Brazilian authorities immediately recognized the incident as a new species of digital fraud and began discussing safeguards: automatic detection of invisible text, formatting checks before AI processing, and stronger human oversight at every stage. They also raised the prospect of stricter ethics rules and sanctions for lawyers who try to manipulate court AI systems.

For our purposes, the Brazil case does three important things:

  1. It confirms that AI now sits inside judicial workflows—not just law firm workflows.

  2. It shows that some lawyers will try to game those systems if they think they can get away with it.

  3. It gives us a concrete example of what not to do and what to watch for as courts in the U.S. and elsewhere adopt similar tools.

From an ABA perspective, a “white‑text prompt injection” is not clever lawyering—it’s a direct collision with Model Rule 3.3 (candor toward the tribunal) and Model Rule 8.4(c)’s prohibition on conduct involving dishonesty, fraud, deceit, or misrepresentation. And because the Brazil incident exploits the very AI tools that the judiciary is using, it also implicates Model Rule 1.1 and Comment 8: the duty of technology competence now includes understanding how these systems can be abused.

So let’s unpack what we should learn from Brazil—starting with what not to do.

What Not To Do: Hidden Instructions and “Clever” Hacks

The Brazil case is a textbook on the wrong way to think about AI in litigation.

  • Do not embed hidden commands in filings (through white‑on‑white text, metadata, or other tricks) with the intent to influence how a court’s AI tools process your case.

  • Do not treat court‑side AI as just another system to be “SEO‑optimized” or hacked. Unlike a marketing algorithm, this is part of the machinery of justice; trying to tilt it in your favor crosses a bright ethical line.

  • Do not assume that “if the judge doesn’t see it, it doesn’t count.” Malicious prompts aimed at judicial AI are still part of your submission to the tribunal, and they reflect directly on your candor and honesty under Model Rules 3.3 and 8.4.

In short: if you would never say it to the judge in plain black‑and‑white text, you should not whisper it to the court’s AI in invisible text.

What To Watch For: How to Recognize This Behavior

lawyers need to be prepared to vet opposing counsel’s filings for ai injection!

The harder question is how you, as a solo or small‑firm lawyer, can spot similar tactics when others use them—especially when you don’t control the court’s systems.

Here are practical signals and questions:

  • Suspicious formatting in PDFs or Word files. Odd spacing, unexpected blank pages, or inconsistent fonts can sometimes signal hidden layers of text. While you won’t always spot white‑on‑white content, unusual formatting should prompt closer inspection.

  • Metadata anomalies. If you routinely examine document properties, look for multiple authors, unusual editing histories, or automation tags that do not match the face of the document. These can indicate heavy automated processing or embedded instructions.

  • Patterns in AI‑mediated decisions. If certain filings—often from the same party—seem to sail through automated queues or receive unusually favorable, boilerplate orders, you may be seeing the downstream effect of prompt manipulation or aggressive “AI‑targeted” drafting.

Because you usually won’t have direct access to the court’s internal AI, you may need to raise these concerns procedurally: requesting clarification on how filings are screened, asking whether AI systems were involved in certain steps, or moving for relief if you believe your client’s matter was prejudiced by automated processing.

How To Protect Yourself and Your Clients:

Brazil’s experience is a warning shot—not just about bad actors, but about what a healthy response should look like.

Here’s how to translate that into a practical “do this, not that” playbook for your own practice:

1. Assume courts will adopt AI—and plan for it:

Brazil’s judiciary uses AI to prioritize cases, draft reports, and propose decisions in response to massive backlogs. U.S. courts are already experimenting with similar tools, even if not as publicly. Competence under Model Rule 1.1 now includes staying informed about these trends and understanding their implications.

2.     Build “AI integrity” into your litigation strategy.

  • Treat any automated system that touches your filings—court e‑filing portals, online forms, AI‑assisted triage tools—as part of the tribunal.

  • Resolve that you will never include hidden instructions, misleading metadata, or manipulative formatting in documents submitted to those systems.

3.     Advocate for transparent safeguards.

  • In Brazil, authorities responded by exploring automatic detection of invisible text and stronger human oversight.

  • When U.S. courts announce AI pilots or tools, comment on proposed rules, advocate for clear notice when AI is used, and request mechanisms for lawyers to challenge AI‑influenced outcomes.

4.     Document your own good‑faith use of AI.

it may be deemed a “fruad upon the court” if a lawyer injects ai into their electronic filings.

  • If you rely on AI to format or generate parts of your filings, keep internal records of prompts, outputs, and human review.

  • This documentation will help if a court or disciplinary body later asks how you ensured candor and accuracy, especially in a world where Brazil‑style abuses are making judges more skeptical.

Final Thoughts

AI isn’t just something we use; it’s now part of the institutional environment—just like e‑filing, CM/ECF, or digital signatures. The line between legitimate technology use and unethical manipulation is not about whether you use AI, but how you use it and whether you’re honest about it.

MTC

MTC: ChatGPT, Work Product, and Waiver: New Lessons from Tate Group Automotive ⚖️🤖

Tech‑savvy lawyerS need to be able to defend ChatGPT work product before Texas Business Court.

On June 3, 2026, the Business Court of Texas issued a minute entry in Tate Group Automotive, LLC v. Legacy Automotive Capital, LLC that every tech‑curious lawyer should know about. As of today, this is one of the first reported decisions to tackle whether a non‑lawyer’s ChatGPT conversations are protected attorney work product and, if so, whether using a public AI tool waives that protection.

The court’s answer is nuanced but important: generative AI does not automatically destroy work‑product protection, at least where the disclosure is not made to an adversary under Texas Rule of Civil Procedure 192.5(a)(1). For solos and small firms experimenting with AI tools, this is both reassuring and sobering.

What Happened in Tate Group Automotive?

The case arises from a dispute in the Texas Business Court’s Eleventh Division, in which Tate Group Automotive sued Legacy Automotive Capital, The Reynolds and Reynolds Company, and individual defendants. During discovery, the plaintiff withheld “Kris Tate–ChatGPT conversations” on the basis of attorney work‑product protection and submitted them to the court for in camera review.

Defendants challenged that claim. They argued that attorney work‑product protection does not extend to a non‑lawyer’s chats with an AI tool, or alternatively, that any protection was waived when Kris Tate used ChatGPT. They also asked the court to order the plaintiff to identify all discovery materials Mr. Tate or Tate Group had shared with ChatGPT.

Judge Grant Dorfman acknowledged that the issue was “novel,” noting that all case law cited by the parties dated from 2026 and that at least one opinion called the question “a first impression nationwide.” Against that backdrop, he evaluated the ChatGPT conversations under Texas Rule of Civil Procedure 192.5(a)(1), which defines work product and addresses waiver.

The key takeaway from the minute entry—based on the Minerva summary—is that the court concluded a non‑lawyer’s chats with ChatGPT did not automatically waive work‑product protection because the disclosure was not made to an adversary. That is a narrow holding, but it marks a significant moment in the emerging law of AI and privilege.

Why This Ruling Matters for Lawyers Using AI

At first glance, Tate Group may look like a niche discovery dispute. In reality, it answers a question many lawyers have quietly asked: “If my client uses ChatGPT, have we blown work product?”

The court’s answer is “not necessarily.” By focusing on whether the disclosure was made to an adversary, Judge Dorfman signaled that the waiver analysis for AI platforms should track the familiar contours of work‑product doctrine, at least in Texas. That gives practitioners a framework instead of a panic button.

At the same time, this is a minute entry in a specific context—not a blanket blessing for all AI use. The court still treated the issue as novel, still conducted in camera review, and still scrutinized how the AI tool was used. For lawyers, that means AI usage is now part of the discovery and privilege landscape, and courts will expect thoughtful, documented positions—not hand‑waving about “just using a tool.”

From an ABA perspective, this aligns with Model Rule 1.1 and Comment 8: competence now includes understanding the “benefits and risks associated with relevant technology,” including how generative AI intersects with privilege and work product. Model Rule 1.6 (confidentiality) and Rules 5.1/5.3 (supervision of lawyers and non‑lawyers) also come into play when clients or staff use tools like ChatGPT in ways that touch litigation strategy.

Lesson 1: Treat Client AI Use as Discoverable Reality, Not a Side Note

One of the most striking aspects of Tate Group is procedural: the court required in camera review of the ChatGPT conversations and entertained requests that plaintiff identify all discovery materials shared with ChatGPT. That tells us courts are prepared to treat AI interactions as real, reviewable artifacts in discovery.

If your clients or internal teams use AI to draft, summarize, or analyze case materials, those interactions can become part of the discovery conversation, just as drafts, notes, and emails have always been. Under Model Rules 1.1 and 1.6, you cannot stay competent or protect confidentiality if you do not know whether and how AI is being used on your matters.

Practically, that means:

  • Ask clients early whether they have used tools like ChatGPT or other AI services to “get help” on their case.

  • Document the scope and purpose of any AI use, especially if it involves draft pleadings, strategy, or privileged communications.

  • Be prepared to defend or adjust your privilege and work‑product positions in light of those uses, as plaintiff did in Tate Group by asserting work‑product and submitting chats for in camera review.

Lesson 2: Public AI Platforms Are Not Automatic Waiver Machines

Solo attorneys need to protect their privileged work product from risky AI tools.

Defendants in Tate Group argued that a non‑lawyer’s chats with an AI tool either are not work product at all or, at minimum, effect a waiver. The court rejected the idea that simply using ChatGPT automatically destroys protection under Texas Rule 192.5(a)(1) when there is no disclosure to an adversary.

That matters, because there has been a real fear—sometimes stoked by vendors—that “if anyone touches ChatGPT, all privilege is gone.” This ruling shows courts can adopt a more nuanced view, at least under a work‑product framework.

For ABA‑Model‑Rules lawyers, this should not be read as a free pass. Model Rule 1.6 still requires reasonable efforts to prevent unauthorized disclosure of client information, and using a public AI platform can create confidentiality risk even if work product is technically preserved. But Tate Group suggests that waiver analysis will still look to core principles like whether disclosure reached an adversary.

In practice:

  • You should not assume that any AI use destroys work product, but you should be ready to explain why your use did not involve disclosure to an adversary or the public.

  • Engagement letters and internal policies should clarify whether and how you will use AI tools and what safeguards you apply, consistent with Model Rules 1.1, 1.4, and 1.6.

Lesson 3: In Camera Review Will Become Common for AI Disputes

The court’s process—ordering in camera review of the ChatGPT conversations before ruling—signals a likely pattern for AI‑related privilege disputes. Judges will want to see how AI was used, not just hear generalities, before deciding whether protection applies or has been waived.

That has three implications for practicing lawyers:

  • You should assume that AI‑related materials can be reviewed by courts under appropriate safeguards.

  • You need internal workflows to collect and present those materials when necessary without scrambling through chat histories.

  • You should approach AI use with the expectation that a judge, someday, may read the raw prompts and outputs and ask whether your supervision met the standards of Model Rules 5.1 and 5.3.

This is a shift from treating AI as a “black box” helper to treating it as a discoverable component of your litigation process.

Lesson 4: Non‑Lawyers and AI Need Clear Supervision

In Tate Group, the conversations at issue were between Kris Tate—a non‑lawyer—and ChatGPT, yet they were withheld under an attorney work‑product theory. The court’s willingness to consider work‑product protection in that context underscores a point many of us have made: non‑lawyers can participate in the creation of protected material if they are acting at the direction of counsel.

But it also heightens the importance of supervision. Model Rule 5.3 requires lawyers to ensure that non‑lawyer assistants’ conduct is compatible with the lawyer’s professional obligations. When non‑lawyers use AI tools on client matters, they are effectively acting as an extension of the legal team.

Practical steps include:

  • Training non‑lawyers on what they may and may not share with AI platforms.

  • Setting clear rules about which tools are approved, for what purposes, and under whose supervision.

  • Reviewing AI outputs and underlying prompts when they feed into litigation strategy, to ensure accuracy and compliance with Model Rules 3.3 and 4.1.

As we have discussed in episodes of The Tech‑Savvy Lawyer podcast, AI is not just a “lawyer tool”; it is often a staff and client tool. Your ethical obligations follow it wherever it goes. 💼🤖

Lesson 5: This Is Only the Beginning—But You Can Prepare

Texas judges along with others will be weighing ChatGPT privilege and waiver in generative AI era.

Judge Dorfman noted that all the case law cited by the parties dated from 2026 and that one authority called its ruling a “question of first impression nationwide.” That means we are at the very start of AI‑and‑privilege jurisprudence, not the end.

Every new decision—whether from Texas Business Courts or elsewhere—will refine the analysis. Some may take a stricter view of waiver for public AI tools; others may distinguish between work product and attorney‑client privilege. Regardless, Model Rule 1.1’s technology‑competence requirement demands that we follow these developments and integrate them into our practice.

You do not need to become an AI engineer, but you do need a plan:

  • Inventory where AI is used in your matters (by you, your staff, your clients).

  • Align that usage with your duties of competence, confidentiality, and supervision.

  • Be prepared for in camera review of AI‑related materials, as in Tate Group.

  • Update your engagement letters and internal policies to reflect reality, not wishful thinking.

If you approach AI as you approached email, e‑filing, and cloud storage when they were “new,” you will be ahead of many peers—and aligned with the spirit of both the ABA Model Rules and emerging case law.

MTC

MTC: Law School, Laptops, and AI: Why Banning Computers Misses the Point!

Law schools are throwing out the baby with the bathwater by banning laptops from the classroom as an effort to combat improper ai use.

On July 10, 2026, the conversation around artificial intelligence in legal education reached a new level. Reports of universities banning both AI tools and laptops in classrooms reflect a growing anxiety: how do we preserve critical thinking in an age of automation? ⚖️

It is a fair question. It is also the wrong solution.

Let me be clear at the outset. A first-year ban on AI tools makes sense. A blanket ban on laptops does not.

The Case for Limiting AI—At First

Legal education has always been about building judgment. That means learning how to analyze facts, synthesize doctrine, and construct arguments from scratch. AI short-circuits that process if used too early.

Under ABA Model Rule 1.1 (Competence), lawyers must provide knowledgeable and skilled representation. That competence begins in law school. If students rely on AI before they understand the law themselves, they risk becoming operators instead of thinkers.

As I have noted in prior discussions on legal technology, AI should augment—not replace—legal reasoning.

So yes, a structured limitation on AI during the first year is defensible. It creates a foundation. It forces students to wrestle with ambiguity. It builds intellectual muscle. 💡

But Banning Laptops? That Is an Overreach

This is where the policy breaks down.

When I entered law school then graduated in 2002, laptops were just beginning to appear in classrooms. They were not universal. They were not always welcome.

For me, the laptop was not a distraction. It was essential.

My handwriting was and sadly still is poor. My ability to type, organize notes, and revise quickly made the difference between struggling and succeeding. My laptop was not a shortcut. It was an accessibility tool before we used that term widely.

Fast forward to today. Students are typing far more than they write. Many have never learned cursive. Their academic workflows are digital from the start.

To remove laptops is not to level the playing field. It is to shift it—often unfairly.

The Practical Reality of Modern Learning

Legal education does not exist in a vacuum. Law practice is digital.

Law students who learned on laptops will be disadvantaged if classrooms suddenly ban them.

Under ABA Model Rule 1.1, Comment 8, lawyers must understand the benefits and risks of technology. That obligation does not begin after graduation. It begins in law school.

Students today must learn:

  • How to organize digital research

  • How to draft and revise efficiently

  • How to manage documents and workflows

  • How to integrate technology into legal reasoning

You cannot teach modern legal competence while removing the primary tools of modern legal work. 🖥️

A laptop is not the problem. Misuse is.

The Enforcement Problem No One Is Talking About

There is also a practical issue. Banning AI is difficult to enforce. Banning laptops is easy.

That does not make it the right policy.

If anything, banning laptops is a workaround for the harder problem of AI enforcement. It is a policy by convenience.

And it raises a deeper concern under ABA Model Rule 5.3 (Responsibilities Regarding Nonlawyer Assistance), which increasingly applies to AI tools. Lawyers—and future lawyers—must learn to supervise and evaluate AI outputs.

You cannot teach supervision by eliminating exposure.

A Better Approach: Controlled Access, Not Prohibition

Law schools should be experimenting with smarter controls instead of blunt bans.

Some possibilities include:

  • Disabling Wi-Fi and cellular signals in certain classrooms 📶

  • Using locked-down exam or classroom software environments

  • Creating AI-permitted and AI-prohibited assignments with clear boundaries

  • Requiring disclosure of AI use in coursework

  • Teaching prompt engineering and AI verification as part of the curriculum

This approach aligns with ABA Model Rule 1.6 (Confidentiality) as well. Students must learn what data can and cannot be shared with AI systems.

Exposure with guardrails is more effective than prohibition. That principle applies directly to how law schools should approach AI.

Critical Thinking and Technology Are Not Opposites

There is a persistent myth underlying these bans: that technology erodes thinking.

That is not inherently true.

Technology can weaken thinking if it replaces effort. It can strengthen thinking if it supports it.

A student who uses a laptop to organize case law, annotate notes, and refine arguments is not thinking less. They are thinking differently—and often more effectively.

The same will eventually be true of AI.

The goal is not to create lawyers who avoid technology or who think less by using AI. It is to create lawyers who use it wisely. ⚖️

What Law Schools Should Be Teaching Instead

If I were designing a first-year curriculum today, I would include:

THE MODERN LAWYER NEEDS TO KNOW HOW TO BALANCE JUDGMENT WITH AI USE IN THEIR WORK!

  • A temporary restriction on AI-generated work

  • Mandatory instruction on how AI tools function

  • Exercises in verifying AI outputs against primary sources

  • Training on ethical risks, including hallucinations and confidentiality

  • Continued use of laptops as standard tools

This approach respects both sides of the equation: foundational thinking and technological competence.

Final Thought: Do Not Solve the Wrong Problem

Law schools are right to be concerned. AI is reshaping the profession at a rapid pace.

But banning laptops is not a solution. It is a signal of discomfort.

The better path is harder. It requires nuance. It requires experimentation. It requires trust in students, guided by structure.

Most importantly, it requires recognizing that the future lawyer will not choose between thinking and technology.

They will need both.

And law school is exactly where they should learn how to do that. 🚀

MTC: When Your CEO Asks ChatGPT How to Take Over: Lessons for Lawyers on Public AI, Ethics, and Confidentiality 🧠⚖️

Lawyers need to evaluate public AI chatbot against ABA confidentiality and privilege rules

In March 2026, the Delaware Court of Chancery in Fortis Advisors, LLC v. Krafton, Inc. handed lawyers one of the clearest cautionary tales yet about public AI chatbots, corporate governance, and the limits of “move fast and break things.” A South Korean gaming conglomerate, Krafton Inc., used an artificial intelligence chatbot to help devise an internal “Project X” takeover plan against its own studio, Unknown Worlds Entertainment, and then tried to defend the fallout in court. The result: a detailed opinion reinstating the studio’s CEO, extending a $250 million earnout period, and spotlighting how AI misuse can become Exhibit A when things go wrong.

If you’re a solo, a small-firm lawyer, or an AI‑curious practitioner dabbling with ChatGPT or similar tools, this case is your wake‑up call. The message is not “don’t use AI.” The message is: treat public chatbots the same way you treat email, cloud storage, or texting — through the lens of ABA ethics, client confidentiality, and privilege. 😬

In this editorial, I’ll unpack what happened, how the court framed the misuse of a chatbot, and what you should do in your own practice to stay on the right side of the rules.

The Case in a Nutshell: AI as a Takeover Co‑Pilot

Krafton bought Unknown Worlds — the studio behind Subnautica — for $500 million upfront plus up to $250 million in contingent earnout payments, with a contractually guaranteed structure: the founders and CEO (the “Key Employees”) retained operational control and could only be fired for defined “Cause.”  As Subnautica 2 approached early‑access launch, internal projections showed the game would easily trigger a massive earnout.

The CEO of Krafton grew concerned he looked like a “pushover” under the deal and turned to a public AI chatbot for advice on how to avoid paying the earnout and seize control of the studio. The chatbot’s “response strategy” included:

  • Locking down publishing rights and code access.

  • Crafting messaging to “secure public support” and undermine the “large corporation vs. indie” narrative.

  • Preparing a “takeover” path that blended hardball legal tactics with PR framing. 

Krafton’s internal team implemented much of that plan — cutting off the studio’s access to its Steam publishing console, posting unilateral public statements, and ultimately terminating the founders and CEO on a pretext of “premature release” risk.  When sued, Krafton tried to pivot to new justifications, including the executives’ role changes and their defensive downloads of company data. 

The court was having none of it. Vice Chancellor Will held that:

  • The terminations were not “for Cause” under the negotiated contract.

  • The “Project X” takeover guided by the chatbot was a pretext to avoid the earnout.

  • The studio’s CEO, Ted Gill, must be reinstated with full operational control, and the earnout period equitably extended by the length of his ouster. 

In other words, the AI‑assisted takeover strategy became part of the factual narrative of bad faith and breach — not a clever workaround.

Public Chatbots and ABA Model Rules: Three Pressure Points ⚖️

Attorneys must consider ethical AI chatbot use for confidential client case analysis

Even though this is a corporate earnout case, the opinion gives lawyers a concrete frame for thinking about public AI tools under the ABA Model Rules.

1. Confidentiality — Model Rule 1.6

Rule 1.6 requires lawyers to keep “information relating to the representation of a client” confidential, absent informed consent or a specific exception. Public chatbots are not your firm’s Document Management System (DMS) — they’re third‑party services that typically ingest prompts for training, quality, and logging. When Krafton’s CEO ran “Project X” through a chatbot, he was effectively outsourcing high‑stakes strategy to a non‑privileged third‑party system that could store and learn from those prompts. 

For lawyers, the parallels are obvious:

  • Dropping fact patterns, names, or deal structures into a public chatbot can mean you’ve disclosed client information to a non‑controlled vendor.

  • Even “sanitized” prompts can be re‑identified when combined with other data.

Under 1.6, that’s a potential confidentiality breach unless you’ve vetted the tool, negotiated appropriate terms (including data handling and retention), and obtained informed client consent for that mode of assistance. Emojis and “it’s just drafting help” don’t change that. 😉

2. Privilege — Model Rules 1.1 and 1.4 (Competence and Communication)

Privilege isn’t framed in the Model Rules, but Rule 1.1 (competence) and 1.4 (communication) require you to understand how your technology choices affect the protection of client communications. When you route strategy discussions through a public chatbot:

  • You may jeopardize attorney–client privilege by involving a third‑party with no need‑to‑know and no formal role in the representation.

  • You may create discoverable records that live outside your control, just as Krafton’s CEO created chat logs he then tried to delete. 

The court noted that relevant chatbot logs were deleted, which did not play well in evaluating Krafton’s narrative.  Privilege analysis is already complex with cloud tools; adding public AI as a “secret co‑counsel” without protections only compounds that risk. 

Competent use of technology now includes understanding whether your AI stack is preserving or eroding privilege and communicating those risks to clients when you propose AI‑assisted workflows.

3. Candor and Misrepresentation — Model Rule 4.1 and 8.4(c) 🚨

Although this case turns on contractual “Cause” and good faith, the court’s language about “pretextual” justifications and manufactured defenses should resonate with litigators. Model Rule 4.1 prohibits knowingly making false statements of material fact to third parties; Rule 8.4(c) bars conduct involving dishonesty, fraud, deceit, or misrepresentation. 

When you:

  • Use a chatbot to generate strategic messaging designed to mislead stakeholders.

  • Craft public statements or demand letters that you know are pretextual, but you’ve optimized with AI for tone and impact.

… you’re still responsible for the truthfulness of that content. The court saw through Krafton’s attempt to re‑frame events after the fact, and its internal AI‑assisted playbooks did not help. 

For lawyers, the lesson is simple: AI‑generated output is yours once you sign or speak it. If it’s misleading, you own the ethics problem — not “the algorithm.”

Practical Takeaways for Solo and Small‑Firm Lawyers 🧩

So what do you do if you’re a tech‑savvy lawyer who likes AI, but doesn’t want your prompts quoted in an opinion like this?

Here are grounded, practice‑ready steps.

1. Establish an AI Use Policy

Even if you’re a solo, write down what you will and won’t do with public chatbots.

lawyers need to build practical, ethical AI policies for practice.

  • No client names, exact fact patterns, or identifiable deal terms in public tools.

  • Use AI for structure and language, not for strategy or confidential analysis.

  • Prefer client‑specific, non‑logging enterprise tools when handling sensitive material.

Treat this like you treat your cloud storage or remote‑work policy — it’s part of your competence under Model Rule 1.1 and your supervisory obligations under 5.1/5.3 if you have staff.

2. Separate “Public Prompting” from “Privileged Thinking” 🧠

Use public chatbots for:

  • Headline and meta description drafting.

  • Blog outlines, post ideas, or simple explainer language for non‑client scenarios.

  • Rough templates for standard documents that you will heavily edit.

Avoid using them for:

  • Fact‑specific case assessments.

  • Litigation strategy, negotiation plans, or internal “playbooks” like Krafton’s “Project X.” 

  • Anything that feels like the kind of conversation you’d normally have only with a colleague behind closed doors.

This separation keeps your privileged work product inside tools and workflows you control.

3. Vet Vendors Like You Vet e‑Discovery Platforms

If you move beyond public chatbots to paid AI tools, evaluate them as you would any major legaltech vendor:

  • Where is data stored?

  • Is training on your material disabled by default?

  • Can you get a Business Associate Agreement or Data Processing Agreement / Data Protection Impact Assessment that aligns with your jurisdiction’s expectations?

The ABA’s Formal Opinion 477R on secure communications and cloud ethics opinions from state bars all provide analogies: reasonable steps, not perfection, are required — but “type client memo into random website” is not reasonable. 😄

4. Document Client Consent When AI Is Material to the Representation

If you expect to use AI in a way that materially affects how you deliver legal services, communicate that to clients under Rule 1.4:

  • Explain benefits (efficiency, faster drafting).

  • Explain risks (data handling, reliability, hallucinations).

  • Offer an AI‑free option.

Written engagement terms that address AI use can save hard conversations later if something goes sideways.

5. Revisit Your “Bad Facts” Mindset

Reading this Delaware opinion, you see how internal strategy — including AI‑assisted plotting — can become a litigation exhibit.  For lawyers, that’s an invitation to ask: 

“If this prompt or chatbot conversation showed up in an opinion, would I be comfortable defending it under the Model Rules?”

If the answer is no, don’t send it. That simple heuristic scales across tools and platforms.

What This Case Signals for the Next Wave of Legal Tech 🌊

There can be significant legal consequences for AI chatbot misuse in legal disputes.

The opinion in Fortis Advisors v. Krafton is not an ethics decision aimed at lawyers, but it shows courts will:

  • Scrutinize AI‑assisted strategies as part of broader narratives about good faith, bad faith, and pretext.

  • Expect parties — and by extension, counsel — to maintain and produce AI‑related records where relevant.

  • Be unimpressed by attempts to retroactively justify decisions made for economic reasons with thin “quality” or “readiness” arguments. 

As public models get more powerful and more embedded in practice, ABA Model Rules on competence, confidentiality, supervision, and candor apply just as they did when lawyers moved to email, smartphones, and the cloud. AI is just the next tool — but it’s a tool that makes it very easy to generate sophisticated bad ideas quickly.

Your job is to keep your ethical compass steady, even when the chatbot is very persuasive. 🧭

MTC