Your Law Firm's Biggest Risk Might Be Your AI Tools
Law firms are adopting AI fast, but hallucinated citations, data exposure, and weak oversight create serious risks. Here’s how firms can use AI safely.
In 2022, a lawyer inadvertently used an AI tool to aid in researching and drafting a brief for an airline liability case. The citations appeared accurate, but opposing counsel raised suspicions. Upon verification, the lawyer admitted to using AI and revealed he had asked it directly about the cases' authenticity. Six of the cited cases turned out to be entirely fabricated. The judge sanctioned both the attorney and his colleague, imposed a $5,000 fine, and mandated additional legal education on AI usage.
Since then, similar incidents have not only persisted but have increased significantly. The root issue lies not in lawyers' decision to employ AI but rather in a lack of understanding of its implications. In a 2025 case, a California attorney filed an appeal citing 21 cases generated by ChatGPT. He claimed he had authored the appeal himself and utilized AI to refine the language.
However, he failed to realize the AI would also insert citations, including fabricated ones. A three-judge panel subsequently fined him $10,000 for filing a frivolous appeal, violating court rules, and wasting the court's time.
The scale of the problem is becoming increasingly difficult to overlook. Over 300 cases of AI-driven legal errors have been documented in court filings since mid-2023, with the frequency accelerating dramatically - from two cases per week to two or three per day by 2025. Courts across the US, UK, Australia, Canada, and Israel have encountered this issue. Large and reputable firms are not immune; in July 2025, a prominent firm suffered a motion sanction in federal court in Alabama for submitting AI-generated hallucinations.
The most alarming recent case occurred in May 2025, when a plaintiff's law firm was sanctioned $31,100 for submitting fake AI citations in a California federal court. The judge admitted he initially found the citations convincing and nearly included them in his ruling. He stated, "Plaintiff's use of AI affirmatively misled me." The exposure extends beyond fabricated citations; feeding sensitive data into centralized AI platforms poses significant risks.
Law firms possess highly confidential information such as litigation strategies, M&A details, criminal defense materials, and privileged client communications. When this data is input into AI systems, often located on remote servers beyond the firm's control, several serious risks emerge.
These risks include potential malpractice liability if client confidential information is exposed, ethics violations under professional conduct rules concerning confidentiality and competence, and contractual breaches if client engagement letters stipulate data handling provisions. Most lawyers now use AI in their practice, but only ten percent of firms have policies governing its use, creating a substantial governance gap.
Leading firms are beginning to address this by implementing strict access controls, usage policies, and auditability for AI infrastructure, similar to client file systems and case management platforms. Some are even considering private deployment options, such as Aphanarc, which offers atomized deployment and keeps sensitive client data secure with no third-party exposure or risk of input feeding an external model's training data.
Furthermore, verification habits around AI output are essential, ensuring that output is not assumed accurate merely because it appears correct.
Written by urgent.news from HackerNoon's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.