AI Ethics for Texas Lawyers: A TDRPC Compliance Guide for Solo and Small Firms

Practical guide to AI ethics under the Texas Disciplinary Rules: Rule 1.01 competence, Rule 1.05 confidentiality, Rule 5.03 supervision, Rule 1.04 fees, and TRAIGA's impact on Texas law practices.

Abstract fresco: a teal mass, half precisely faceted and half rough and organic, held inside a slender copper hexagonal armature on a dark navy plaster ground.
Loading AudioNative Player...

If you are a solo practitioner or small-firm lawyer in Texas, you have probably already experimented with generative AI tools — ChatGPT for drafting, Claude for document review, or one of the specialized legal AI platforms for research. The technology is moving fast, and the pressure to adopt it is real. But here is the problem: the Texas State Bar has not yet issued formal, AI-specific ethics guidance, and the existing ABA guidance does not map directly to the Texas Disciplinary Rules of Professional Conduct (TDRPC).

That gap leaves many Texas attorneys improvising — adopting AI tools without a compliance framework, sending confidential client data to third-party platforms, and hoping nothing goes wrong. In this guide, we map the TDRPC rules that matter most when you use AI in your practice, build an audit-ready workflow checklist, and address how TRAIGA — Texas's own AI governance law — intersects with your professional obligations.

Why This Matters Now

The Texas Responsible Artificial Intelligence Governance Act (TRAIGA), signed into law as House Bill 149, creates a regulatory framework for AI developers and deployers operating in Texas. While TRAIGA primarily targets commercial AI systems rather than lawyers' professional conduct, its disclosure requirements, consumer-protection provisions, and risk-management expectations create a backdrop that every Texas attorney should understand. When your practice involves advising clients on AI compliance — or when your own use of AI tools touches consumer data — TRAIGA becomes directly relevant.

At the same time, the ABA Resolution 604, adopted at the ABA's 2023 Midyear Meeting, urges organizations that design, develop, deploy, and use AI to ensure human oversight, accountability for harms, and transparency and traceability in AI systems. The resolution, submitted by the ABA Cybersecurity Legal Task Force, calls on federal and state entities to incorporate these principles into laws and standards. For Texas lawyers, this means the ABA's framework is a signal of where regulation is heading — and a practical guide for building your own AI workflows before the State Bar catches up.

Rule 1.01: Competence Means Understanding AI's Benefits and Risks

TDRPC Rule 1.01 requires lawyers to provide competent and diligent representation. The rule's Comment 8 is explicit: "each lawyer should strive to become and remain proficient and competent in the practice of law, including the benefits and risks associated with relevant technology."

That language — which mirrors the ABA Model Rule 1.1 Comment 8 technology competence requirement — means that if you use AI tools in your practice, you must understand enough about how they work to use them competently. You do not need to build a neural network, but you need to know:

  • What the tool does with your data. Does the AI platform retain your inputs for model training? Does it store conversation history on its servers? Does it share data with subprocessors?
  • What the tool's error profile looks like. Generative AI models can produce confident-sounding but entirely fabricated case citations — the well-documented "hallucination" problem. If you cite a case that does not exist, that is your competence failure, not the tool's.
  • What the tool's limitations are. AI research tools trained on older caselaw may miss recent developments. Tools that summarize documents may miss nuances that change the legal analysis.

If you cannot answer these questions about the AI tools you use, you are not meeting the competence standard that Rule 1.01 requires. The fix is not to stop using AI — it is to invest in AI literacy before you deploy AI in client work.

Practical Competence Steps

  • Read the AI vendor's terms of service and data processing agreement. Identify whether your inputs are used for training, retained after your session, or accessible to the vendor's staff.
  • Test the tool on matters you already know well before using it on new client work. This builds your understanding of where the tool is reliable and where it breaks down.
  • Establish a verification protocol: every AI-generated citation, legal proposition, or factual claim must be independently confirmed against a primary source before it enters a client deliverable.

Rule 1.05: Confidentiality in the Age of Third-Party AI

TDRPC Rule 1.05 is Texas's confidentiality rule — the Texas analogue to ABA Model Rule 1.6. (Rule 1.06, by contrast, governs conflicts of interest.)

Rule 1.05 defines confidential information broadly to include "all information relating to a client or furnished by the client, other than privileged information, acquired by the lawyer during the course of or by reason of the representation of the client." The rule prohibits lawyers from knowingly revealing confidential information to anyone other than the client, the client's representatives, or members of the lawyer's firm — unless an exception applies.

This creates a direct problem with consumer-grade AI tools. When you paste a client's facts into ChatGPT's web interface, you are transmitting confidential information to a third-party company (OpenAI) that is not a member of your firm, not the client, and not the client's representative. The information may be stored, logged, or used to improve the model. That is a knowing disclosure of confidential information to an unauthorized recipient.

How to Use AI Without Breaking Confidentiality

  • Use enterprise or API tiers that exclude training on your data. Many AI vendors offer enterprise plans with contractual commitments that your inputs will not be used for model training. If you cannot get that commitment, do not send client data.
  • Anonymize before you input. If you are using a consumer AI tool for general research, strip all identifying details — names, dates, amounts, locations — before you type anything into the prompt. If the anonymized query still gives you useful legal analysis, you have protected your client. If it does not, you need a different tool.
  • Obtain informed consent. If you want to use a client's data with an AI tool and the disclosure falls outside what the client reasonably expects, get the client's express authorization after explaining the risks. Document that conversation.
  • Vet the vendor's security posture. Before deploying any AI tool that touches client data, review the vendor's SOC 2 reports, data residency commitments, and breach-notification terms. This is not paranoia — it is the diligence that Rule 1.05 requires when you hand client information to a third party.

For a deeper dive on vendor evaluation, our guide to evaluating AI legal research tools walks through the specific contract terms and security questions you should ask before signing up.

Rule 5.03: Supervision of Nonlawyer Assistants — Applied to AI

TDRPC Rule 5.03 governs a lawyer's responsibilities regarding nonlawyer assistants — paralegals, secretaries, investigators, and other staff. The rule requires lawyers with direct supervisory authority to "make reasonable efforts to ensure that the person's conduct is compatible with the professional obligations of the lawyer." A lawyer is subject to discipline for a nonlawyer's conduct if the lawyer ordered or permitted it, or if the lawyer knew of the misconduct and failed to take reasonable remedial action.

AI tools are not human assistants, but the supervisory principle maps directly. When you deploy an AI tool to draft, research, or summarize, you are delegating work to a nonlawyer agent. You must supervise its output the same way you would supervise a paralegal's work — with the added complexity that AI cannot be trained in professional ethics the way a paralegal can.

The practical implications are significant:

  • Review every AI-generated work product before it reaches the client or the court. No AI output should go out the door without lawyer review. This is your supervision obligation.
  • Set use-case boundaries. Decide which tasks AI may handle (first-draft generation, document summarization, initial research) and which it may not (final citations, court filings, client communications) — and document those decisions.
  • Train everyone in the firm. If your paralegal uses an AI tool on a client matter, you are responsible for that use. Make sure every person in your firm who touches AI understands the confidentiality and competence rules that apply.

Rule 1.04: Fee Disclosure and AI-Efficiency Gains

TDRPC Rule 1.04 governs legal fees. While the rule does not mention AI specifically, its principles apply directly when AI tools change the economics of your practice. If you use AI to generate a first draft of a motion in 20 minutes — work that used to take three hours — the fee you charge should reflect the value of the service, not the time you spent before you had the tool.

The ethical tension is real. On one hand, if you bill hourly and AI dramatically reduces your time, your client benefits from a lower bill. On the other hand, if you charge a flat fee and AI lets you deliver the same product faster, you capture the efficiency gain — and that is generally permissible as long as the fee remains reasonable under Rule 1.04's standards.

The key compliance points:

  • Disclose AI-related cost structures to clients when relevant. If your engagement letter says you bill for "research time" and you now use an AI tool that compresses that time, be transparent about how fees are calculated.
  • Do not bill for time you did not spend. If AI generates a draft and you spend 30 minutes reviewing it, you cannot bill three hours for drafting.
  • Consider fee arrangements that align incentives. Flat fees, capped fees, or phased fees can let you capture AI efficiency gains without the ethical risk of overbilling hourly.

ABA Resolution 604: The Accountability Framework

While the TDRPC provides the binding ethics rules for Texas lawyers, ABA Resolution 604 offers a governance framework that is useful for building internal AI policies. The resolution establishes three core principles for organizations that use AI:

  1. Human authority, oversight, and control. AI systems should be subject to human oversight — the lawyer must remain in the loop and retain decision-making authority.
  2. Accountability for consequences. Organizations should be accountable for harms caused by their AI use unless they took reasonable steps to prevent them. For a law firm, this means building verification and review processes that catch AI errors before they cause client harm.
  3. Transparency and traceability. AI systems should document key decisions about data, procedures, and outcomes. In a law firm, this translates to logging which AI tools were used, what inputs were provided, and what review was conducted — so you can reconstruct your workflow if a malpractice claim or disciplinary complaint arises.

These principles are not binding law in Texas, but they represent the direction of travel. The Texas State Bar's ethics committee is actively studying AI issues, and when formal guidance arrives, it is likely to track these ABA principles closely. Building your AI workflows around Resolution 604 now puts you ahead of the curve.

TRAIGA (HB 149) creates a comprehensive AI governance framework for Texas. The law applies to persons who develop or deploy AI systems in Texas, and it imposes duties including consumer disclosure when AI interacts with individuals, prohibitions on manipulative AI systems, and restrictions on government use of social-scoring AI.

For Texas lawyers, TRAIGA intersects with practice in two ways:

First, if you advise clients on AI compliance. Your clients who develop or deploy AI systems may need guidance on TRAIGA's disclosure requirements, its definitions of "developer" and "deployer," and its safe-harbor provisions tied to the NIST AI Risk Management Framework. You need to understand TRAIGA well enough to counsel them competently — which, under Rule 1.01, is itself a technology-competence obligation.

Second, if your own firm deploys AI systems that interact with consumers. If your firm uses an AI chatbot for client intake — one that "interacts with consumers" — TRAIGA Section 552.051 requires disclosure that the consumer is interacting with an AI system. The disclosure must be clear, conspicuous, in plain language, and may not use dark patterns. A lawyer who deploys an AI intake bot without this disclosure may be violating TRAIGA in addition to any ethics concerns.

Building an Audit-Ready AI Workflow Checklist

Based on the rules above, here is a practical checklist that maps each TDRPC rule to concrete AI workflow controls:

Before You Adopt an AI Tool

  • [ ] Competence (Rule 1.01): Document your understanding of the tool's capabilities, limitations, and error profile. Test it on known matters first.
  • [ ] Confidentiality (Rule 1.05): Review the vendor's data processing terms. Confirm whether inputs are used for training. If yes, either switch to an enterprise plan or establish an anonymization protocol.
  • [ ] Supervision (Rule 5.03): Write a one-page AI use policy for your firm that specifies which tasks AI may and may not perform, who reviews AI output, and what verification steps are required.
  • [ ] Fees (Rule 1.04): Review your fee arrangements. If AI changes your cost structure, update engagement letters to reflect how fees are calculated.

During Client Work

  • [ ] Verify every AI-generated citation against a primary source before using it in any deliverable.
  • [ ] Review and revise all AI-drafted text before it reaches a client or court — no exceptions.
  • [ ] Log which AI tools were used, on which matters, and what review was performed. This is your traceability record under ABA Resolution 604.
  • [ ] If using an AI chatbot for client intake, ensure TRAIGA-required disclosures are in place.

After AI-Assisted Work Is Delivered

  • [ ] Retain AI workflow records in the client file so you can reconstruct your process if challenged.
  • [ ] Periodically re-evaluate your AI tools — vendors update their models, terms of service change, and new risks emerge.
  • [ ] If a client asks whether you used AI, be transparent. Honesty about AI use builds trust and avoids future disputes.

Actionable Next Steps

AI adoption in legal practice is not a question of whether — it is a question of how. The Texas Disciplinary Rules give you the framework; the gap is in implementation. Here is what we recommend:

  1. Conduct an AI audit of your current practice. Identify every AI tool you and your staff already use — including informal use of consumer chatbots. Assess each against the checklist above.
  2. Adopt a written AI use policy. Even a solo practitioner needs a one-page document that sets the rules for how AI tools may be used, what data may be input, and what review is required. This policy is your evidence of compliance if your AI use is ever questioned.
  3. Invest in AI literacy. Spend two hours learning the fundamentals of how generative AI works — what training data is, what hallucination means, what data retention looks like. This is your Rule 1.01 competence obligation in action.
  4. Review your vendor agreements. Pull the terms of service for every AI tool in your practice. If any of them allow training on your inputs, either upgrade to an enterprise tier or stop sending client data.
  5. Watch for Texas State Bar guidance. The Bar is actively studying AI ethics. When formal guidance issues, you will need to update your policies — but do not wait for it. The TDRPC rules already apply, and they already require what we have outlined above.

At Promise Legal, we help Texas law firms adopt AI tools ethically and compliantly — from drafting AI use policies to reviewing vendor contracts to building audit-ready workflows. If you are navigating these questions, we can help you build a framework that satisfies the TDRPC and positions your firm for what comes next.

Need help building an AI compliance framework for your Texas law practice? We can help you draft policies, review vendor agreements, and build audit-ready workflows that satisfy the TDRPC.

Book a consultation