top of page

Virginia Wrote an AI Rule for Lawyers. It Is About Your Billing.

Writer: cAIberOps (SY-ber-ops) | MSSP
cAIberOps (SY-ber-ops) | MSSP
Aug 19
6 min read

Virginia's Supreme Court approved a legal ethics opinion on artificial intelligence on November 24, 2025. If you practice in the Commonwealth, it is the most current word your regulator has offered on AI.

It is about billing.

Legal Ethics Opinion 1901, "Reasonable Fees and the Use of Generative Artificial Intelligence," answers one question: if AI makes you dramatically faster, are you ethically required to charge less? The opinion says no. It reasons that while AI reduces "the time and labor required," the "skill requisite to perform the legal service properly" may actually increase, because using AI well requires knowing how to prompt it, verify it, and catch its errors. Rule 1.5 is the only rule it applies.

That is a useful opinion. It is also not the one most firms need.

Because there is no Virginia opinion telling you how to protect a client's confidential information once it has been typed into an AI tool. There does not need to be one. And the reason is not that your regulator has not gotten to it yet.

The rule that already covers this was written before AI existed

Rule 1.6 of the Virginia Rules of Professional Conduct is binding on every lawyer in the Commonwealth. It requires that a lawyer "shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information protected under this Rule."

Read that again and notice what is missing. It does not name a technology. It does not distinguish between a fax machine, a cloud drive, and a chat window. It does not care whether the disclosure was deliberate. It attaches to the information, not to the tool, which means it attached to generative AI the moment the first paralegal pasted a client's facts into one.

Rule 5.3 does the same work one level up. A lawyer with managerial or supervisory authority over nonlawyer assistants must make reasonable efforts to ensure their conduct is compatible with the lawyer's own professional obligations, and the rule's comments direct appropriate instruction concerning the duty not to disclose information relating to the representation. Not the associates. The paralegals, the legal assistants, the contract reviewers, the billing staff, and the outside vendors who touch a matter.

Nationally, the American Bar Association reached the same conclusion in Formal Opinion 512, issued July 29, 2024. Worth being precise here, because opposing counsel would be: Opinion 512 is advisory and not binding on anyone. But its analysis is instructive. It recommends that lawyers secure a client's informed consent before putting client confidences into a generative AI tool that learns from what it is given, and it opines that boilerplate consent language buried in an engagement letter will not be adequate. It also puts the duty to establish clear policies on permissible AI use, and to train nonlawyers in it, squarely on partners and supervising lawyers.

None of that is a new obligation. It is the old obligation, pointed at a new tool.

What is actually happening inside law firms right now

The gap between that duty and daily practice is not subtle, and the profession's own numbers describe it.

According to the 8am 2026 Legal Industry Report, 69% of legal professionals personally use generative AI tools for work. A year earlier that figure was 31%. Adoption more than doubled in twelve months.

What are they using it for? Drafting correspondence (58%), general research (58%), brainstorming (54%), and summarizing documents (47%). Every one of those tasks involves the matter. You do not draft a client's correspondence or summarize a client's documents in the abstract.

And 54% of respondents say their firm has provided no training on the responsible use of generative AI and has no current plans to do so.

Set those two numbers beside Rule 5.3 and the problem states itself. More than two thirds of the profession is putting work product into these tools, and more than half of firms have decided not to instruct anyone about it.

The firms are not oblivious. The same report lists their stated concerns: data security (46%), ethical issues (42%), privilege (39%), and lack of trust in results (39%). Roughly four in ten already suspect privilege is exposed. They are not unaware. They are stuck, because they cannot act on a problem they cannot measure.

The part nobody is watching: AI that arrived without being installed

Most firm conversations about AI are about tools someone chose. The harder version is the tools that showed up on their own.

Generative AI now ships inside software the firm already pays for. It appears in productivity suites, in PDF editors, in note takers that join a call and transcribe it, in browser extensions a staff member added in ten seconds without a purchase order, and in meeting assistants that quietly retain a recording of a privileged conversation. Nobody procured these. Nobody signed anything. There was no vendor review, because from the firm's point of view there was no vendor.

Then there is the account question, which is the one that actually decides exposure. The same tool behaves completely differently depending on who is signed in. A firm's enterprise agreement covers the firm's accounts. It does not cover the personal account an associate is logged into on the same machine. Verizon's 2026 Data Breach Investigations Report found that 67% of users accessing AI services on corporate devices were doing so through non-corporate accounts, and that regular AI use on corporate devices rose from 15% to 45% of employees in a single year.

That is the whole problem in one sentence. The tool is the same. The contract is not. And nothing on the screen tells the user which one they are in.

Why this matters more for law firms than for most businesses

Two independent data sets put firms like yours near the front of the line.

The FBI's Internet Crime Complaint Center received more than 1,400 ransomware complaints from businesses outside the sixteen critical infrastructure sectors in its 2025 annual report. Legal services was the single most-reported industry at 18%, ahead of contracting, engineering, and consulting. The report's own examples for that category are law firms and estate planning practices.

Verizon's 2026 report adds the size dimension. Small organizations accounted for 96 percent of ransomware victims, and ransomware appeared in 48 percent of all breaches, the highest share the report has ever recorded. Attackers are not curious. They are shopping.

Meanwhile IBM's 2026 Cost of a Data Breach report found that incidents involving unapproved AI tools rose to 43% from 20% the previous year, cost an average of $5.39 million, and produced a regulatory fine in one out of five cases.

Law firms hold concentrated, high-value, legally protected information about other people's worst moments. That is precisely the inventory this category of attacker wants.

Every one of these duties collapses at the same point

Here is what connects all of it.

You cannot obtain a client's informed consent for a tool you do not know your staff is using. You cannot instruct a paralegal on the responsible use of an application you have never seen. You cannot make "reasonable efforts to prevent unauthorized access" to information you cannot trace. And if a client, a court, or a malpractice carrier asks where a matter's contents went, you cannot answer from memory.

Visibility is not one more control to add after the policy is written. It is the thing every one of these obligations silently assumes you already have.

What a firm actually does about it

This is the part we handle, and it is deliberately narrow.

Our Managed AI Security service starts with AI Discovery, which we run at no charge. It identifies the AI tools, browser extensions, plugins, and agents actually in use across the firm, and, critically, which account each one is signed into. Firm account or personal account. That distinction is usually the difference between a covered use and an uncovered one, and almost no firm can currently see it.

From there, ongoing management does three things.

It gives you an answer. When a client asks whether their matter touched an AI system, or a carrier asks during renewal, or an opposing party asks in discovery, you have a record instead of a guess.

It gives you enforcement. Approved tools on firm accounts stay available. Unapproved tools, and personal accounts handling firm information, get blocked or flagged according to what the firm decides. Your associates keep the productivity. The exposure goes away.

It gives you evidence over time. Continuous monitoring means the answer stays current as staff install things, as vendors add AI features to software you already own, and as people change how they work. A point-in-time snapshot goes stale in about a month. This does not.

To be clear about what we are and are not: we are not your ethics counsel, and we do not write your firm's AI policy. What we provide is the visibility and the control layer that make a policy enforceable instead of aspirational, and that support the reasonable efforts Rule 1.6 already expects of you. The judgment stays with the partners. The evidence comes from us.

Where a firm starts

You do not need to decide your AI strategy first. Most firms have that backwards. The inventory comes first, because until you have it every policy discussion is speculation about your own operation.

Start by finding out what is actually running, on which accounts. That takes days, not months, and it costs nothing to find out.

If you would like to see what is running inside your firm, get in touch. More on how we work with legal practices is on our law firm cybersecurity page, and the service itself is described under Managed AI Security.

Comments


bottom of page