Most attorneys I talk to have made peace with AI as a research assistant. You run a query through Lexis+ AI or CoCounsel, you review the output, you exercise your judgment. That part feels familiar. The lawyer is still in the loop.
What a lot of firms have not thought through is what happens when AI stops being a research assistant and starts being an agent. Not a tool you query. A process that acts on your behalf, without waiting to be asked.
What’s actually running in your firm right now
AI agents are different from the AI tools attorneys have been cautiously experimenting with. An agent doesn’t just respond to a prompt. It takes action: it can draft and send emails, update matter records in Clio, pull documents, route tasks, and trigger workflows across systems — all without a person approving each step.
The problem is that a lot of these agents are showing up in law firms the same way shadow IT always does: one tool at a time, often adopted by an associate or administrator who found something useful, with no formal approval and no IT visibility into what it is accessing.
Microsoft’s Cyber Pulse report, published in March 2026, found that 84% of business leaders across industries acknowledged that unauthorized or poorly governed AI agents are a serious security concern. The same report found that 62% of organizations had already deployed AI agents in some capacity — a 22% increase year over year. The adoption is outpacing the governance by a wide margin.
For a law firm, that gap is not just a security risk. It is an ethics exposure.
The duty of competence includes knowing what is running
The duty of confidentiality requires reasonable efforts to prevent unauthorized access to client information. That obligation runs through ABA Model Rule 1.6(c) for attorneys in most U.S. jurisdictions, and through Business and Professions Code section 6068(e), California Rule 1.1, and California State Bar Formal Opinion 2010-179 for California practitioners. The specific rule structure differs, but the underlying obligation does not: you are responsible for the safeguards around client data.
An AI agent operating without defined permissions, logging, or oversight is a gap in those safeguards. If the agent is pulling data from your matters to draft communications, you need to know which matters, what data, and where it is going. If you cannot answer those questions, you cannot satisfy yourself that the firm’s confidentiality obligations are being met.
There is also a competence question. ABA Formal Opinion 512, issued in July 2024, confirmed that generative AI use by attorneys is subject to the duty of competence. A lawyer who deploys or permits AI tools without understanding what they do and what they can access is not using the technology competently. The California State Bar’s November 2023 guidance on generative AI made the same point. The lawyer remains responsible for the work product, and the lawyer remains responsible for the systems producing it.
The question you need to be able to answer
If opposing counsel asks why a certain communication was sent, or a client asks who had access to their matter, or a regulator asks what systems touched that data, can you answer?
An AI agent operating without an audit trail is a black box. When something goes wrong inside a black box, the answer to “why did that happen” is “I don’t know.” That is not a defensible answer in a malpractice claim. It is not a defensible answer in a bar complaint. And it is not an answer that satisfies a client whose confidential information ended up somewhere unexpected.
What governance actually looks like for a law firm
This does not require pulling out every AI tool your team is using. It requires knowing they are there.
Start with an inventory: what AI tools are running in your environment, what credentials have they been granted, and what firm data can they access. That includes the AI features built into tools the firm already uses — Microsoft Copilot has AI agent functionality baked into Microsoft 365, and if your firm is on Microsoft 365, it may already be available to your attorneys and staff whether anyone turned it on deliberately or not.
From there, treat AI agents the way you’d treat any other identity with access to firm systems. Define what each one is permitted to access. Limit it to what is actually necessary. Make sure there is a log of what it does, so that when a question comes up — from a client, an insurer, or opposing counsel — you can answer it.
None of this is novel governance work. It is the same principle as requiring two signatures on a trust account withdrawal: not because you distrust the person, but because the obligation requires a record.
If your firm has not done this kind of inventory yet, our managed IT services for law firms includes this. Xentric can walk through your environment, map where AI is operating, and help you put the controls in place before someone is asking the questions in a context where “we weren’t sure” is the wrong answer. Reach out to schedule a call.