AI Ethics for Texas Law Firms: A Practical Compliance Playbook for Generative AI

Texas attorneys deploying AI must satisfy TDRPC Rules 1.01, 1.05, 1.04, and 5.03. This practical compliance playbook covers vendor vetting, engagement letter disclosures, supervision policies, and citation verification for solo and small-firm Texas law firms.

Abstract digital fresco: teal crystalline burst with branching tendrils blooming from the center, bounded by a copper geometric lattice with cream light points, on grained deep navy
Loading AudioNative Player...

If your Texas law firm is using generative AI tools for legal research, contract drafting, or discovery review, you are already operating within the reach of the Texas Disciplinary Rules of Professional Conduct (TDRPC). The question is not whether AI ethics rules for law firms in Texas apply to you — they do. The question is whether your firm has built the compliance infrastructure to deploy AI tools without violating your ethical obligations.

In February 2025, the Professional Ethics Committee for the State Bar of Texas issued Opinion 705, the first Texas-specific ethics opinion addressing generative AI use by attorneys. The opinion identifies four core obligations: competence (Rule 1.01), confidentiality (Rule 1.05), independent verification of AI outputs, and fair billing practices. The State Bar followed up with its AI Toolkit, which includes vendor evaluation checklists, sample client disclosure forms, and practical guidance for Texas legal professionals.

This is significant because Texas had been operating without AI-specific ethics guidance while adoption of generative AI tools in legal practice exploded. The ABA issued its Formal Opinion 512 in July 2024, providing the national framework. But Texas attorneys practice under the TDRPC, not the ABA Model Rules — and the differences matter. This article maps the TDRPC requirements to the practical decisions your firm must make before deploying AI tools: vendor vetting, data processing terms, engagement letter disclosures, and supervision policies.

For a broader look at how Texas AI law affects organizations deploying AI systems, see our guide on TRAIGA compliance for Texas companies. For the compliance infrastructure that supports AI governance more broadly, our NIST AI RMF implementation guide provides the structural backbone.

The TDRPC Framework: Four Rules That Govern AI Use

Opinion 705 did not create new ethical obligations for AI use — it applied existing TDRPC rules to the specific context of generative AI. Four rules do the heavy lifting. Understanding each one in practical terms is the foundation of a defensible AI deployment strategy.

Rule 1.01: Competence — Understanding What AI Does and Where It Fails

TDRPC Rule 1.01 requires a lawyer to provide competent representation, which includes the legal knowledge, skill, thoroughness, and preparation reasonably necessary for the representation. Opinion 705 makes clear that competence in the AI era requires attorneys to understand how generative AI functions — not at a technical level, but well enough to identify its limitations and verify its outputs.

Generative AI tools can produce convincing but fabricated legal citations — a phenomenon known as "hallucination." In June 2023, a New York federal court sanctioned attorneys who submitted a brief containing six nonexistent cases generated by ChatGPT, a scenario that has played out in multiple jurisdictions since. The lesson for Texas attorneys is direct: if you cannot identify when AI has fabricated a citation, a factual assertion, or a legal conclusion, you lack the competence required by Rule 1.01 to use that tool in client representation.

Practically, competence under Rule 1.01 means your firm should:

  • Understand the tool's training data and update cycle. Does the AI tool have access to current Texas statutes and case law, or is its knowledge cutoff months or years old? Many consumer AI tools have significant temporal gaps in their training data.
  • Recognize hallucination risk. Generative AI models produce fluent, confident text regardless of whether the underlying content is accurate. Attorneys must treat every AI output as unverified until independently checked.
  • Know the tool's scope. An AI tool trained on general internet data is not a substitute for Texas-specific legal research. Using a general-purpose chatbot for Texas-specific legal analysis without verification is a competence failure.
  • Train your team. Opinion 705 specifically recommends training staff on AI tools to ensure compliance. Competence is not just about the supervising attorney — it extends to every person in the firm who interacts with AI-generated content.

Rule 1.05: Confidentiality — Protecting Client Data in AI Pipelines

TDRPC Rule 1.05 prohibits a lawyer from revealing information relating to the representation of a client, including both privileged information and unprivileged client information. This is where AI deployment creates the most acute ethical risk. When you input client facts, deposition excerpts, contract terms, or case strategy into a generative AI tool, you are potentially transmitting confidential client information to a third-party vendor.

Opinion 705 warns that attorneys "must be cautious not to disclose confidential client information inadvertently" and specifically notes the risk that AI systems "may inadvertently share information with third parties." The opinion recommends "thorough vetting of generative AI tools for confidentiality safeguards."

The core problem is this: many consumer-grade AI tools — including free versions of ChatGPT, Claude, and Gemini — use user inputs to train their models. If you paste a client's deposition transcript into a consumer AI tool, that information may become part of the model's training data and could theoretically be reproduced in response to another user's query. That is a Rule 1.05 violation.

Practically, confidentiality under Rule 1.05 requires your firm to:

  • Use enterprise or API versions of AI tools that do not train on user inputs. Most major AI providers offer enterprise tiers with contractual commitments that user data will not be used for model training. These tiers typically include data retention controls, encryption in transit and at rest, and administrative controls over data access.
  • Anonymize inputs before processing. If you must use a tool whose data practices are uncertain, strip client-identifying information before input. Replace names, dates, locations, and other identifying details with generic placeholders.
  • Verify the vendor's data processing terms. Does the vendor's terms of service explicitly prohibit training on user inputs? Does it specify retention periods and deletion protocols? Does it provide breach notification? If the terms are silent, do not use the tool with client data.
  • Train staff on the distinction between consumer and enterprise AI tools. A paralegal using a personal ChatGPT account to summarize a client's medical records is creating a confidentiality breach, even if the output is never shared outside the firm.

Rule 1.04: Communication — Telling Clients About AI Use

TDRPC Rule 1.04(a) requires a lawyer to keep a client reasonably informed about the status of a matter and to comply with reasonable requests for information. While Rule 1.04 does not explicitly require disclosure of AI tool use, the ABA's Formal Opinion 512 recommends that lawyers consider informing clients about their use of generative AI, particularly when AI is used to produce substantive work product.

The State Bar of Texas AI Toolkit includes sample client disclosure forms, signaling that the Bar views client communication about AI use as a best practice — and potentially an ethical expectation under Rule 1.04's "reasonably informed" standard. The question is not whether to disclose, but how much detail to provide and where to document it.

Practically, communication under Rule 1.04 means your firm should:

  • Add AI disclosure language to engagement letters. A clear, concise statement that the firm uses AI tools to assist with certain aspects of legal work — research, document review, drafting — and that all AI outputs are reviewed and verified by an attorney before use. This puts the client on notice and creates a documented record of informed consent.
  • Describe the scope of AI use. Not every AI tool use requires disclosure. Using AI to proofread a brief is different from using AI to generate the legal analysis in that brief. Disclose the uses that could materially affect the client's interests or that involve processing confidential client information.
  • Address billing transparency. Opinion 705 addresses billing directly: efficiencies gained through AI "must benefit the client financially when using hourly billing methods." Attorneys cannot bill for hours not worked, but reasonable AI tool subscription costs may be passed through with prior client agreement. Your engagement letter should specify how AI-related costs are handled.
  • Document client consent. If a client objects to AI use after disclosure, document that objection and adjust the firm's approach for that client. If the client consents, keep a record in the engagement file.

Rule 5.03: Supervision of Nonlawyer AI Vendors

TDRPC Rule 5.03 makes a lawyer responsible for the conduct of a nonlawyer the lawyer employs or retains, to the extent that the lawyer orders or knowingly ratifies the conduct. When you deploy a generative AI tool provided by a technology vendor, you are effectively delegating certain tasks to a nonlawyer — the AI system itself, and the vendor that operates it. The supervising lawyer remains responsible for the quality and ethical compliance of the work product that AI produces.

ABA Formal Opinion 512 explicitly addresses this dynamic, noting that lawyers must make reasonable efforts to ensure that nonlawyer assistance is compatible with the lawyer's professional obligations. Applied to AI vendors, Rule 5.03 supervision requires the firm to:

  • Vet vendors before deployment. Understand what the AI tool does, how it processes data, whether it trains on user inputs, what security certifications it holds, and what its data retention and deletion policies are. The State Bar of Texas AI Toolkit provides a vendor evaluation checklist that firms can use as a starting point.
  • Establish supervision protocols for AI-assisted work product. Every AI-generated output that goes into client work — a research memo, a contract draft, a discovery review summary — must be reviewed and verified by a supervising attorney. The attorney must have sufficient understanding of the subject matter to identify errors, fabrications, and missing analysis.
  • Document the review process. If your firm is later questioned about AI use in a matter, the ability to show that AI outputs went through attorney review — with documented sign-off — is your primary defense. Build this documentation into your workflow, not as an afterthought.
  • Limit access to AI tools based on role. Not every staff member needs access to every AI tool. Control who can input client data into AI systems and under what circumstances. This is particularly important for tools that may not have enterprise-grade data protections.

Vendor Vetting Checklist: What to Demand Before You Deploy

Before your firm deploys any generative AI tool that will process client information, you should complete a vendor vetting process that documents the tool's data practices, security posture, and suitability for legal work. This is not a one-time exercise — vendors update their terms of service, and you need a process for monitoring material changes.

Here is a practical vendor vetting checklist organized around the TDRPC obligations above:

Data, Training, and Retention

  • Training on inputs: Does the vendor's terms of service explicitly prohibit using user inputs to train its models? If the terms are ambiguous or silent, assume your data may be used for training and do not input confidential client information.
  • Data retention period: How long does the vendor retain user inputs and outputs? Is there a documented deletion process? The shorter the retention period, the lower your confidentiality risk under Rule 1.05.
  • Data location: Where are user data stored and processed? If data is processed in jurisdictions with different privacy standards, your client data may be subject to foreign legal processes you cannot control.
  • Opt-out from training: Even if the vendor's default terms allow training on inputs, many enterprise tiers offer an opt-out. Verify that the opt-out is documented in the contract, not just available in a settings menu.

Security and Encryption

  • Encryption in transit and at rest: Does the vendor use TLS encryption for data in transit and AES-256 (or equivalent) for data at rest? These are baseline security standards. A vendor that cannot confirm both is not suitable for processing client information.
  • SOC 2 Type II certification: Has the vendor completed a SOC 2 Type II audit? This is the baseline security certification for cloud vendors handling sensitive data. Request the current SOC 2 report during vetting.
  • Access controls: Who at the vendor can access your firm's data? Is access limited to authorized personnel with a documented need? Does the vendor provide audit logs of data access?
  • Breach notification: Does the vendor's contract include a breach notification obligation? How quickly will the vendor notify your firm if client data is compromised? The standard is 72 hours or less.
  • Texas-specific legal content: If the AI tool is used for legal research, does it have access to current Texas statutes, Texas case law, and Texas administrative regulations? A tool trained on general federal law without Texas-specific content may produce misleading analysis for Texas practitioners.
  • Citation verification: Does the tool include features for verifying that cited cases and statutes actually exist? Some legal AI tools now include built-in citation checking. If the tool does not, your firm must verify every citation manually.
  • Customization and scope limitation: Can the tool be configured to limit its outputs to specific practice areas or jurisdictions? The ability to scope AI tools reduces the risk of the tool producing analysis outside the attorney's area of competence.

Engagement Letter AI Disclosure Language

One of the most practical steps your firm can take is adding AI disclosure language to your engagement letters. This serves three purposes: it satisfies the Rule 1.04 communication obligation, it documents client consent, and it sets expectations about how AI efficiencies will affect billing. The State Bar of Texas AI Toolkit includes sample disclosure forms, but the specific language should be tailored to your firm's actual AI use.

Here is a framework for engagement letter AI disclosure language, which you should adapt to your firm's specific practices:

Sample AI Disclosure Clause:

"Our firm uses generative artificial intelligence (AI) tools to assist with certain aspects of legal work, including legal research, document review, contract drafting, and discovery analysis. All AI-generated content is reviewed and verified by a licensed attorney before it is incorporated into client work product. We do not input confidential client information into AI tools that use such information for model training. AI tool subscription costs may be passed through as a reimbursable expense as agreed in the fee arrangement below. If you have questions about our use of AI tools or wish to discuss limitations on AI use in your matter, please contact [attorney name]."

This language is intentionally broad — it discloses AI use without over-promising specifics that may change as tools evolve. But it addresses the key ethical concerns: attorney review of outputs, data protection, billing transparency, and an invitation for client dialogue.

What to Include and What to Avoid

  • Do specify that an attorney reviews all AI outputs. This directly addresses the supervision obligation under Rule 5.03 and the competence obligation under Rule 1.01.
  • Do address billing. Opinion 705's billing guidance means you should disclose how AI-related costs are handled — whether AI tool costs are passed through, and whether AI-driven efficiencies will reduce billed hours.
  • Do not overstate the role of AI. Avoid language suggesting that AI performs legal analysis independently. The attorney remains responsible for all legal work.
  • Do not use the word "free." Any consultation or AI-related service should not be described as free. If you are absorbing AI tool costs, describe them as included in the fee arrangement, not as free.
  • Do not promise specific AI tool brands. Your tool stack will change. Disclosure language should describe categories of AI use, not specific products.

Supervision Policies for AI-Assisted Work Product

Having a vendor vetting process and engagement letter language is necessary but not sufficient. The day-to-day supervision of how your firm uses AI tools is where ethical compliance is actually tested. A firm that has vetted its tools and disclosed AI use to clients but lets associates paste unredacted client documents into consumer AI tools is still violating Rule 1.05.

A written AI supervision policy is the operational tool that translates ethical obligations into firm-wide practice. The policy should address:

1. Approved Tools and Access Controls

Maintain a list of approved AI tools that the firm has vetted according to the checklist above. No attorney or staff member should use an unvetted AI tool for any purpose that involves client information. Access to approved tools should be controlled through enterprise accounts with centralized administration — not through individual consumer accounts.

2. Input Protocols

Establish clear rules for what may be input into AI tools. At minimum:

  • Client-identifying information should be anonymized before input unless the tool is enterprise-grade with contractual no-training guarantees.
  • Privileged communications should not be input into any AI tool without explicit attorney approval and documented confirmation that the tool does not use inputs for training.
  • Sensitive negotiation strategies, settlement positions, and litigation tactics should be treated with the same confidentiality protections as any other client information.

3. Review and Verification Requirements

Every AI-generated output that will be incorporated into client work product must pass through attorney review before it reaches the client. The review should include:

  • Citation verification: Every legal citation generated by AI must be independently verified against an authoritative source (Westlaw, Lexis, Texas case law databases). Fabricated citations are the most common and most dangerous AI error.
  • Factual verification: Any factual assertion generated by AI must be independently confirmed. AI tools can confidently state incorrect facts, including wrong dates, wrong party names, and wrong procedural histories.
  • Legal analysis review: AI-generated legal analysis must be reviewed by an attorney with sufficient knowledge to identify errors, incomplete reasoning, or misapplication of Texas law. An attorney who does not understand the legal issue well enough to evaluate the AI's analysis is not competent to supervise that AI use under Rule 1.01.
  • Documentation: The reviewing attorney should document that review occurred — whether through a workflow tool, an email confirmation, or a notation in the matter file. This documentation is your defense if AI-related errors are later questioned.

4. Training Requirements

Opinion 705 recommends training staff on AI tools. Your supervision policy should require training before any attorney or staff member uses an AI tool for client work. Training should cover: how the specific tool works, its known limitations, the firm's input protocols, the review and verification requirements, and the confidentiality obligations that apply to AI use.

5. Billing and Timekeeping Integration

Opinion 705's billing guidance requires that AI-driven efficiencies benefit the client. Your policy should address: how time saved through AI tools is recorded, whether AI tool subscription costs are passed through to clients (and under what authority), and how the firm ensures that hourly billing reflects actual attorney work — not padded to compensate for AI-driven efficiency. The key principle: if AI saves two hours of research, the client should see that savings in reduced hours, not in a billing entry for work that the AI performed.

The Firm Size Question: Solo and Small-Firm Deployment

For solo and small-firm Texas attorneys, the compliance challenge is resource allocation. You may not have a dedicated IT team, a compliance officer, or a vendor procurement process. But the ethical obligations are the same regardless of firm size. Rule 1.01's competence requirement does not scale down for solo practitioners — and neither does Rule 1.05's confidentiality obligation.

The good news is that right-sized compliance is achievable. For a solo or small firm, the essential elements are:

  1. A one-page AI use policy that identifies approved tools, input protocols, and review requirements. This does not need to be a 50-page document — it needs to be clear, accessible, and followed.
  2. Enterprise-tier AI tool subscriptions for any tool that will process client information. The cost differential between consumer and enterprise tiers is modest compared to the ethical exposure of using consumer tools with client data.
  3. Engagement letter disclosure language using the framework above, tailored to the firm's actual AI practices.
  4. A citation verification habit. Every AI-generated citation is checked before it goes into any document that reaches a client or a court. This is the single most important practice for preventing the most visible AI ethics violation.
  5. Documentation of the review process. Even a simple notation in the matter file — "AI-assisted research reviewed by [attorney]" — creates a defensible record.

For firms handling practice transitions or succession planning, AI tool compliance should be part of the transition package — documented policies, approved vendor lists, and engagement letter templates should transfer with the practice. See our guide on selling a law practice in Texas for the broader succession planning framework.

Actionable Next Steps

Here is what your Texas law firm should do — this month — to build a defensible AI ethics compliance framework:

  1. Read Opinion 705 and the State Bar AI Toolkit. Opinion 705 is short, practical, and directly applicable to your daily practice. The AI Toolkit includes vendor checklists and sample disclosure forms. Start there.
  2. Inventory your firm's current AI tool usage. List every AI tool that any attorney or staff member is using for client work. For each, document whether it has been vetted, whether it is an enterprise or consumer tier, and whether its terms of service prohibit training on user inputs. If any tool is unvetted, stop using it with client information immediately.
  3. Upgrade to enterprise tiers for any tool processing client data. If your firm is using a consumer AI account for any client-related task, the confidentiality risk under Rule 1.05 is immediate. Enterprise subscriptions from major providers typically include no-training guarantees, data retention controls, and SOC 2 certification.
  4. Draft and implement an AI supervision policy. Use the framework above. Keep it to one or two pages. The policy should identify approved tools, input protocols, review and verification requirements, training requirements, and billing integration.
  5. Add AI disclosure language to your engagement letters. Use the sample clause above as a starting point and tailor it to your firm's actual AI practices. For existing clients, consider sending a notice describing your AI use and offering to discuss any concerns.
  6. Train every person who touches AI tools. This includes attorneys, paralegals, legal assistants, and administrative staff. Training should cover the firm's approved tools, input protocols, review requirements, and confidentiality obligations. Document that training occurred.
  7. Build citation verification into your workflow. Whether through automated tools or manual checking, every AI-generated citation must be verified before it appears in any document that reaches a client or court. This single practice prevents the most common and most damaging AI ethics violation.
  8. Engage ethics counsel for a compliance review. The cost of a proactive AI ethics compliance assessment is a fraction of the cost of a grievance — and a fraction of the reputational damage from a public AI-related ethics violation. We help Texas law firms build practical, right-sized AI compliance programs that satisfy TDRPC obligations without overburdening the practice.

AI tools are not going away. The firms that deploy them thoughtfully — with vetted vendors, written policies, attorney supervision, and client communication — will capture the efficiency gains while maintaining their ethical obligations. The firms that deploy them carelessly will discover that the Texas Disciplinary Rules of Professional Conduct do not make exceptions for technological convenience. Opinion 705 is the roadmap. Build your compliance framework now, before an AI-related error forces the question.

Deploying generative AI tools in your Texas law practice? We help law firms build practical AI ethics compliance programs — vendor vetting, engagement letter language, supervision policies, and TDRPC-compliant workflows that protect both your clients and your license.

Get in touch