Author: Clearon AI

  • Michigan Court of Appeals Turns AI-Fabrication Into Published Appellate Sanctions Law

    Michigan Court of Appeals Turns AI-Fabrication Into Published Appellate Sanctions Law

    Michigan now has a published appellate opinion on AI-generated fabricated and unsupported legal authority.

    In Barber v. Morawa, the Michigan Court of Appeals affirmed the denial of a motion for a new trial or evidentiary hearing in a medical-malpractice case. The merits were not the real story. The court separately sanctioned plaintiff's counsel for repeatedly submitting fabricated and unsupported authority that counsel attributed to over-reliance on artificial intelligence.

    The opinion matters because it moves the issue from a general warning to a Michigan-specific appellate holding. Counsel's repeated submission of fabricated and unsupported authority violated MCR 7.216(C)(1) and MCR 1.109(E)(5). The case was remanded for a determination of actual damages and reasonable attorney fees incurred because of the appeal, payable personally by counsel. The court also directed its clerk to forward the opinion to the Attorney Grievance Commission for possible investigation.

    What Went Wrong

    The underlying case involved alleged juror misconduct after a civil medical-malpractice trial. The plaintiff sought a new trial or evidentiary hearing, but the allegations depended on facts outside the record and were not supported by valid affidavits.

    The court resolved that merits issue without much difficulty. The harder issue was counsel's briefing.

    The court said counsel cited fabricated authority in a motion for a protective order, then cited fabricated authority again in a motion for a new trial or evidentiary hearing. Defendant identified the problem and requested sanctions.

    The pattern continued on appeal. Counsel cited a nonexistent Michigan case and repeatedly cited real authorities for propositions they did not support. After defendant identified the defects in the appellee brief, counsel filed a reply without acknowledging the fabricated case or correcting the unsupported assertions.

    Months later, counsel filed a "Notice of Correction." That notice accepted responsibility and attributed the citation errors to over-reliance on AI research tools. But it still did not solve the problem. The court said the notice, also prepared with AI assistance, attributed quotations and legal propositions to cases that did not contain them.

    Why The Published Opinion Matters

    The court did not create an AI-specific exception. It did not create an AI safe harbor either.

    Instead, it applied existing Michigan rules. Under MCR 1.109(E)(5), a lawyer's signature certifies that the lawyer has read the document and that, after reasonable inquiry, it is well grounded in fact and warranted by existing law. The reasonableness standard is objective. Good faith is not enough.

    The court also relied on MCR 7.216(C)(1), which allows sanctions when an appeal or appellate proceeding is vexatious because a brief grossly disregards the requirements of fair presentation, violates court rules, or is grossly lacking in propriety.

    The holding is direct: submitting fabricated and unsupported authority through over-reliance on AI violates the duty of reasonable inquiry.

    That matters for Michigan practitioners because the opinion translates national AI-sanctions principles into Michigan appellate procedure.

    The Correction Filing Lesson

    The most practical part of Barber may be the failed correction filing.

    Once opposing counsel or a court identifies fabricated authority, the next filing should not be treated as ordinary cleanup. It should be treated as a controlled remediation event.

    That means:

    • stop using the same unverified AI workflow that created the problem;
    • identify every disputed citation, quotation, and proposition;
    • review original sources directly;
    • state exactly what was wrong and what is being corrected;
    • avoid substituting new authority unless it has been read and verified; and
    • have a lawyer with responsibility for the filing own the correction.

    In Barber, the correction filing became evidence that the verification problem had not been fixed.

    What Michigan Lawyers Should Do Now

    Michigan litigators should assume that AI-assisted briefing is subject to the same reasonable-inquiry requirement as any other filing.

    Before filing, counsel should verify not only that a case exists, but also that:

    • the quoted language appears in the case;
    • the case actually supports the proposition asserted;
    • the procedural posture is accurately described;
    • the cited rule or statute is current;
    • factual assertions and record references match the record; and
    • criminal cases are not being used to import inapplicable constitutional standards into civil proceedings.

    Law firms should also decide who is responsible for verification. Delegating a first draft to AI, staff, or a junior team member does not delegate the signing lawyer's duty.

    Bottom Line

    Barber v. Morawa is not a ban on AI in Michigan litigation. It is a published reminder that AI does not lower the standard for signed filings.

    For Michigan lawyers, the rule is straightforward: read the authorities, verify the quotations, and do not file a correction until the correction has itself been checked.

    Sources

  • UK Clinical AI Liability Still Starts With The Clinician

    UK Clinical AI Liability Still Starts With The Clinician

    The UK government has not said existing law is broken for clinical AI. It has said something more careful, and more useful for risk planning: existing legal and regulatory frameworks provide a basis for allocating responsibility, but clinicians remain responsible for patient-care decisions when they use AI tools.

    That answer came in response to a written parliamentary question about whether existing liability and regulatory frameworks adequately allocate responsibility for harm arising from AI tools in NHS clinical decision-making.

    The Department of Health and Social Care pointed to clinical negligence law, professional standards, product-liability regimes, and oversight by regulators including the MHRA, the Care Quality Commission, the Information Commissioner's Office, and NICE. It also said that responsibility for patient-care decisions remains with clinicians, who must exercise professional judgment when using AI tools.

    That is not the final answer to the AI liability problem. The Department also acknowledged that AI introduces novel questions about how responsibility should be distributed among manufacturers, software licensors, and users. It said NHS Resolution has been commissioned to assess how existing liability frameworks apply to AI use cases and provide greater clarity.

    For now, the practical message is direct: clinical AI may involve many actors, but a clinician using the tool is not relieved of judgment.

    The Government's Current Position

    The parliamentary answer does three things at once.

    First, it resists the idea that there is currently a liability vacuum. The Department says existing frameworks provide a strong basis for allocating responsibility for potential harms.

    Second, it keeps clinicians in the center of the decision-making chain. AI may assist with diagnosis, triage, prioritization, imaging, documentation, or treatment recommendations. But when it is used in clinical decision-making, the clinician remains responsible for exercising professional judgment.

    Third, it leaves room for future clarification. The answer recognizes that clinical AI may involve multiple parties, including manufacturers, software licensors, providers, and users. In the event of an incident, responsibility may be apportioned according to the circumstances.

    That is a familiar posture in emerging technology. The government is not freezing adoption while a perfect liability model is designed. It is relying on existing frameworks while commissioning work to clarify how they apply.

    The MHRA Commission Is Looking At The Same Problem

    The MHRA's National Commission into the Regulation of AI in Healthcare is examining whether the UK's framework for regulating AI in healthcare is sufficient and how it may need to improve.

    The Commission's call for evidence asked about safe access to AI medical devices, post-market safety checks, and how responsibility and liability should be managed between the different parties involved in deploying AI medical devices.

    The call-for-evidence page was updated on June 11, 2026, to say findings and a wider research-and-engagement report had been published. The Commission's recommendations are expected in 2026.

    That matters because clinical AI liability is not only a courtroom issue. It is a product-governance issue, a medical-device regulation issue, a clinical oversight issue, and a procurement issue.

    Medical Protection Warns Of A Liability Gap

    Medical Protection has taken a sharper view. It warned that a widening gap between AI use and liability law could leave the NHS and clinicians exposed to claims.

    Its concern is that AI systems are not clearly defined as products under the existing product-liability framework. If a patient is harmed after a clinician relies on an AI system that suggested a diagnosis or treatment plan, Medical Protection says the default path may be a clinical negligence claim against the end user rather than a product-liability claim against the developer, manufacturer, or supplier.

    Medical Protection has called for legislation clearly classifying AI systems as products, arguing that responsibility for defective systems should be distributed more fairly.

    That is not a binding legal rule. It is a stakeholder position. But it identifies the risk healthcare organizations already need to manage: if responsibility is unclear, claims may follow the party closest to the patient.

    What Health AI Companies Should Hear

    For AI developers and suppliers, the lesson is not that liability can be pushed downstream forever.

    Procurement teams, regulators, insurers, and courts will ask how the product was validated, what the tool was intended to do, what warnings were given, how performance was monitored, how updates were controlled, and how foreseeable misuse was addressed.

    Contracts may allocate risk between supplier and customer, but they will not necessarily answer patient-facing questions after an incident. Product documentation, post-market monitoring, audit trails, incident-response procedures, and human-factors design will matter.

    If a supplier wants clinicians to trust a tool, the supplier should be able to explain what the tool is for, what it is not for, when a human must override it, and how errors will be detected.

    What Clinical Governance Teams Should Do Now

    Healthcare organizations should assume that AI use will be judged through existing duties unless and until a more specific framework changes the answer.

    That means clinical governance should address:

    • intended use and limits of each AI tool;
    • whether the tool is regulated as a medical device;
    • clinician training and supervision;
    • how recommendations are documented in the patient record;
    • when clinicians must independently verify or override AI output;
    • incident reporting and escalation;
    • supplier obligations for monitoring, updates, security, and performance drift;
    • patient communication where AI materially affects care; and
    • insurance and indemnity allocation for AI-related incidents.

    The key is to avoid treating AI as either an autonomous decision-maker or a harmless administrative aid. Clinical AI may sit somewhere between those poles, and governance should match the actual use case.

    Bottom Line

    The UK's clinical AI liability position is still developing, but the current operating rule is clear enough: clinicians remain responsible for patient-care decisions when using AI tools.

    That does not mean developers, licensors, providers, and healthcare organizations avoid responsibility. It means the liability analysis will likely be shared, fact-specific, and built from existing frameworks unless reform changes the allocation.

    For now, health AI governance should be designed for that world: human clinical judgment at the point of care, supplier accountability upstream, and enough documentation to explain both if something goes wrong.

    Sources

  • AI Sanctions Are Moving Beyond Fake Cases

    AI Sanctions Are Moving Beyond Fake Cases

    The first wave of AI sanctions cases had an easy headline: fake cases.

    That problem has not gone away. But the next wave is broader and harder to catch. Courts are now calling out false quotations, inaccurate descriptions of real cases, unsupported legal propositions, fabricated record references, and correction filings that repeat the same verification failure they were supposed to fix.

    That shift matters because a fake case name is often easy to spot. A real case with a fake quotation is more dangerous. It can survive a quick citation check, especially if the lawyer confirms that the case exists but never reads what it actually says.

    Recent decisions from the Sixth Circuit and Michigan Court of Appeals, plus a new Oregon Court of Appeals notice, point in the same direction: legal teams need source-level verification, not just citation-level verification.

    Farris: Real Cases, False Quotations

    In United States v. Farris, the Sixth Circuit did not decide the merits of the criminal appeal. It stopped to address the conduct of appointed appellate counsel.

    The court said counsel admitted using Westlaw CoCounsel to draft the briefs and then filing them without properly verifying the legal authorities. The problem was not simply that the briefs cited nonexistent law. The briefs cited genuine authorities but attributed quotations and propositions to them that did not appear in the sources.

    One example involved the Sentencing Guidelines commentary. Other examples involved Sixth Circuit cases that were described as reversing role enhancements when they did not support the propositions asserted. The court said the briefs misrepresented the holdings of United States v. Washington and United States v. Anthony.

    The Sixth Circuit drew a line that every litigation team should build into its review process: citing a real case does not make an AI-assisted brief safe if the quotation is fabricated or the holding is misdescribed.

    The consequences were serious. The court ordered that counsel not be compensated under the Criminal Justice Act for the appeal, forwarded the opinion for possible disciplinary proceedings, served the opinion on district court and Kentucky Bar authorities, and separately removed counsel from further representation. Replacement counsel would be appointed and the briefing schedule reset.

    The court also made an important vendor-neutral point. Lawyers cannot assume that a legal AI product is reliable merely because it comes from an established legal technology provider.

    Barber: The Correction Filing Was Also Wrong

    The Michigan Court of Appeals reached a similar point in Barber v. Morawa, a published medical-malpractice appeal.

    The merits issue was straightforward: the court affirmed denial of a motion for a new trial or evidentiary hearing. The sanctions issue was not. Plaintiff's counsel had cited nonexistent cases in the trial court, relied on criminal authorities in a civil case, and then filed an appellate brief that cited another nonexistent case and used real authorities for propositions they did not support.

    After the defendant identified the defects, counsel eventually filed a "Notice of Correction." But that notice, which counsel acknowledged was also prepared with AI assistance, repeated the problem by attributing quotations and legal propositions to cases that did not contain them.

    The Michigan court held that counsel's repeated submission of fabricated and unsupported authority violated MCR 7.216(C)(1) and MCR 1.109(E)(5). It remanded for a determination of actual damages and reasonable attorney fees incurred because of the appeal, payable personally by counsel, and directed the clerk to forward the opinion to the Attorney Grievance Commission.

    That is the deeper lesson of Barber: a correction cannot be just another AI-assisted filing. Once a court or opposing party flags possible fabricated authority, the next filing should be treated as a high-risk verification event.

    Oregon Turns The Warning Into A Court Notice

    The Oregon Court of Appeals has now posted a notice specifically warning about fabricated authority produced by AI.

    The notice says the court has received an increasing number of filings containing fabricated authorities, including citations that do not exist, quotations that do not appear in the cited authority, propositions of law not reasonably related to the citation, and factual support with no basis in the record.

    The listed consequences include striking the filing, monetary sanctions payable to the court, attorney-fee awards payable to the opposing party, and dismissal of the appeal.

    The notice also gives a practical verification rule. Anyone using generative AI to prepare court-filing content must verify that all cited cases exist, that all quotations actually appear in the cited cases, and that all paraphrased propositions of law are objectively reasonable in light of what the case actually says.

    That is a useful checklist because it is not limited to fake case names. It reaches the subtler errors that are becoming common in appellate sanctions orders.

    The Pattern Is Broader Than One Tool Or One Court

    These developments fit the recent sanctions record.

    In Lnu v. Blanche, the Ninth Circuit sanctioned lawyers for briefs containing nonexistent cases, misattributed quotations, and gross misrepresentations of real authority. The court emphasized that the discipline became more serious because of the lawyers' responses after the errors came to light.

    In Withers v. City of Aberdeen, a Mississippi federal court sanctioned and removed all counsel after filings from both sides contained AI-generated fabricated authority. The order is a sharp warning for local counsel and sponsoring counsel: signing and sponsoring are not administrative formalities.

    In State v. Coleman, an Ohio appellate court sanctioned counsel after a filing contained ChatGPT-generated fabricated transcript quotations prepared by a paralegal. The AI problem there was not fake caselaw. It was a fake record.

    Together, the cases show the sanctions framework maturing. Courts are no longer asking only whether a case exists. They are asking whether the filing honestly represents law and fact.

    What Litigation Teams Should Change

    The review process should be built around propositions, not just citations.

    Before filing AI-assisted work, litigation teams should verify:

    • every cited case, statute, rule, and record reference exists;
    • every direct quotation appears in the cited source;
    • every parenthetical accurately describes the source;
    • every paraphrased proposition is fairly supported by the authority;
    • every record quotation or factual assertion matches the underlying record;
    • the lawyer signing the filing has personally satisfied the required level of review; and
    • any correction filing receives independent source review before submission.

    It is not enough to ask whether the tool hallucinated a case. A real case can be turned into a false authority if the quotation, holding, or procedural posture is wrong.

    Bottom Line

    The AI sanctions story is moving from fake cases to false authority.

    That is a harder problem and a more practical one. Lawyers have always had to verify the law and the record before filing. AI makes that duty more visible, not less binding.

    The practical rule is simple: if a filing relies on a source, someone must read the source.

    Sources

  • FTC’s Active Listening Settlement Turns AI-Washing Into a Privacy Problem

    FTC’s Active Listening Settlement Turns AI-Washing Into a Privacy Problem

    The Federal Trade Commission's proposed "Active Listening" settlements connect three risks that often travel together: AI-washing, adtech targeting claims, and weak consent theories.

    The FTC says Cox Media Group and two marketing firms falsely claimed to offer an AI-powered service that could target localized ads based on conversations captured from consumers' smart devices. According to the FTC, the service did not use voice data at all. It allegedly resold data-broker email lists at a markup and did not accurately place ads in customers' desired locations.

    That would be a straightforward deception case on its own. But the FTC went further. It also said the companies misled customers by claiming consumers had opted into the alleged listening service. And the agency added a point that should get the attention of every company making privacy-sensitive AI claims: if the service had actually worked as advertised, collecting and using consumers' voice data from inside their homes without adequate consent would itself violate Section 5 of the FTC Act.

    In other words, the problem was not only that the AI claim was false. The claimed AI capability was itself a privacy-risk representation.

    What The FTC Alleged

    The FTC announced proposed settlements with CMG Media Corporation, doing business as Cox Media Group, plus MindSift LLC and 1010 Digital Works LLC. The alleged customers were businesses buying advertising and marketing services, not the consumers whose supposed smart-device conversations were described in the pitch.

    The companies allegedly marketed an "Active Listening" advertising service that could listen in on consumer conversations overheard by smart devices, detect relevant conversations in real time, and use that information to target ads to consumers in specific geographic areas.

    The FTC says that was not true. According to the agency, the service was not based on voice data, did not listen to consumer conversations, and did not accurately place ads in the customers' desired locations. Instead, the service allegedly consisted of reselling email lists obtained from data brokers.

    The agency also says the companies told customers that consumers had opted into the service. But the FTC says the companies did not seek or obtain consumer consent. The agency specifically rejected the idea that consumers "opted in" by clicking through mandatory app terms of service.

    That consent point is the heart of the case for AI governance teams. Many AI products rely on layered data flows, third-party data, contractual assurances, or generalized platform terms. The FTC's framing says those shortcuts may not support privacy-sensitive claims, especially where the asserted capability involves intimate in-home voice data.

    The Settlement Terms

    The proposed orders require a total of $930,000 in payments: $880,000 from CMG and $25,000 each from MindSift and 1010 Digital Works. The money is intended to provide redress to CMG customers affected by the alleged practices.

    The proposed orders would also prohibit each defendant from making misrepresentations about:

    • the qualities or features of advertising or marketing services;
    • the collection and use of voice data, including whether consumers consented to collection, use, or disclosure; and
    • the geographic targeting capabilities of advertising or marketing services.

    The FTC issued the proposed administrative complaints and accepted the consent agreements by a 2-0 vote. The agreements remain subject to a 30-day public-comment period after publication in the Federal Register. If the orders become final, each violation may lead to a civil penalty of up to $53,088.

    As usual, the settlements resolve allegations. They are not admissions of liability or litigated findings.

    Why The Money Is Procedurally Important

    The $930,000 payment should not be read as the FTC simply using Section 13(b) to disgorge money from the companies.

    That route is no longer available after the Supreme Court's 2021 decision in AMG Capital Management, LLC v. FTC. In AMG, the Court held that Section 13(b) of the FTC Act authorizes the FTC to seek prospective injunctive relief, but does not authorize courts to award equitable monetary relief such as restitution or disgorgement for past conduct.

    That matters here because the FTC is resolving the Active Listening allegations through proposed administrative consent orders, not by relying on Section 13(b) alone to obtain monetary relief in federal court.

    If the parties agree, the FTC can include monetary terms in a settlement package. If they do not agree and the FTC wants monetary relief for an ordinary unfair or deceptive act or practice, the post-AMG route is more cumbersome. The FTC generally must proceed administratively under Section 5, obtain a final cease-and-desist order, and then seek consumer redress under Section 19 if the statutory standard is met, including that a reasonable person would have known under the circumstances that the conduct was dishonest or fraudulent.

    Civil penalties are different again. A first-time Section 5 deception allegation does not automatically produce civil penalties simply because the FTC believes the conduct was deceptive. Penalties typically require an independent penalty hook, such as violation of a final FTC order, violation of certain rules, or another statutory basis. That is why the FTC's release says that if these proposed orders become final, future violations of the orders may carry civil penalties of up to $53,088 per violation.

    So the practical sequence is:

    • settlement now, if the parties agree to money and conduct restrictions;
    • prospective injunctive relief under Section 13(b), but not standalone disgorgement or restitution after AMG;
    • administrative Section 5 proceedings followed by Section 19 redress for qualifying deceptive or unfair practices if there is no settlement; and
    • civil penalties later if a final order, rule, or other penalty-triggering authority is violated.

    What About AT&T?

    There are two AT&T references that can get confused.

    The Supreme Court's FCC v. AT&T Inc. decision does not do much work here. That case addressed whether corporations have "personal privacy" interests under FOIA Exemption 7(C). It is not an FTC Act remedies case and does not change the AMG limit on Section 13(b), the Section 5 administrative route, or the Section 19 redress path.

    The more relevant AT&T case for FTC authority is FTC v. AT&T Mobility LLC, the Ninth Circuit's 2018 en banc decision about the FTC Act's common-carrier exemption. The Ninth Circuit held that the exemption is activity-based, not status-based: a company is outside FTC Section 5 authority only to the extent it is engaged in common-carrier activity.

    That issue is not central to the Active Listening settlements because CMG, MindSift, and 1010 Digital Works are being treated as marketing and advertising-service defendants, not common carriers. But the case would matter if a telecom, broadband, or smart-device company raised a common-carrier defense to an FTC challenge involving AI-powered targeting, voice data, or marketing claims. In that setting, the question would be whether the challenged conduct is common-carrier activity or a non-common-carrier advertising, data, or marketing practice.

    Why This Is More Than an AI-Washing Case

    AI-washing cases usually focus on whether a product actually uses AI, whether the claimed performance is substantiated, or whether the term "AI-powered" is being used as a sales shortcut.

    This case adds a different lesson: the advertised AI function may create its own legal problem.

    If a company claims it can listen to private conversations through smart devices, the claim is not just a product-capability statement. It is a statement about data collection, surveillance, consent, security, and consumer expectations inside the home.

    The FTC's line is unusually direct. It says mandatory app terms do not equal opt-in consent for an invasive service or for the use of consumers' voice data from inside their homes.

    That matters even for companies that are not doing audio targeting. The same logic can apply to AI claims involving:

    • biometric inference;
    • location-based targeting;
    • health or mental-health signals;
    • children's or teens' behavior;
    • financial vulnerability;
    • workplace monitoring;
    • emotion detection;
    • private-message analysis; or
    • household-device data.

    When the marketed AI feature depends on sensitive data, the claim must be true, substantiated, and backed by a consent theory that fits the sensitivity of the data.

    The "Means and Instrumentalities" Piece

    The FTC also charged MindSift and 1010 Digital Works with providing CMG the "means and instrumentalities" to deceive customers through marketing materials, sales pitches, and responses to customer questions.

    That is an important vendor and partner lesson. A company does not necessarily avoid risk because another company owns the customer relationship. If it supplies misleading AI claims, sales materials, or talking points that others use with customers, it can become part of the deception theory.

    Adtech and AI vendors should treat this as a documentation and channel-control problem. Marketing claims should be reviewed not only on the vendor's website, but also in partner decks, reseller scripts, pitch emails, FAQs, demos, and objection-handling materials.

    What Companies Should Do Now

    The FTC's case points to several practical controls.

    First, inventory AI capability claims. Identify every place the company says an advertising, analytics, targeting, personalization, monitoring, or customer-intelligence product is "AI-powered," "real time," "listening," "detecting," "predicting," or "consent based."

    Second, match each claim to evidence. The proof should show not only that the technology can do what the company says, but that the deployed product actually does it in the advertised context.

    Third, separate data-source claims from model claims. Saying a system uses AI does not prove what data it uses. Saying a system uses a data source does not prove that consumers consented to that use.

    Fourth, review consent language with sensitivity in mind. Broad mandatory terms may not support claims about invasive data collection. If the advertised feature involves voice, biometrics, location, children, health, finances, or household data, the consent record needs to be much stronger.

    Fifth, audit partner materials. Vendors and agencies should not assume that downstream sales claims are someone else's problem. Resellers should not repeat vendor claims without understanding what the product actually does and what evidence supports the claim.

    Finally, avoid "it would be worse if true" marketing. A privacy-invasive capability can create legal risk even when it is imaginary. If a company would need strong consent, privacy notices, security controls, and compliance review to lawfully operate the feature, it should not casually advertise that capability as a sales hook.

    Bottom Line

    The FTC's Active Listening settlements show how quickly AI marketing can become a privacy and consumer-protection case.

    The alleged service did not listen to consumers' conversations. But the FTC still treated the claim as serious because customers were told the service used AI to target ads from smart-device conversations and that consumers had opted in.

    That is the lesson for AI products generally: do not sell a capability the product does not have, and do not claim sensitive-data consent that the company cannot prove. When the AI story depends on surveillance-like data, the marketing review is also a privacy review.

    Sources

    Sources

  • Colorado’s AI Law Is Now a Rulemaking and a Court Fight

    Colorado’s AI Law Is Now a Rulemaking and a Court Fight

    Colorado's AI law is no longer just a statute on a compliance calendar. It is now moving on three tracks at once.

    The state has enacted a revised automated decision-making law. It has enacted a separate chatbot safety law. And the Colorado Attorney General has opened pre-rulemaking for both, with informal public input due July 13, 2026.

    At the same time, xAI is challenging Colorado's AI framework in federal court, and the U.S. Department of Justice has intervened against the state law. That means Colorado is becoming the first major test of what happens when state AI governance, federal constitutional objections, and practical compliance rulemaking all collide before the operative date.

    For companies, the practical point is simple: the January 1, 2027 compliance date still matters, but the rules that will define the day-to-day obligations are being shaped now.

    What Colorado Is Rulemaking

    The Colorado Attorney General's office is seeking input on rules under two laws:

    • Senate Bill 26-189, the Automated Decision-Making Technology Act.
    • House Bill 26-1263, the Chatbot Safety Act.

    SB26-189 repeals and reenacts Colorado's earlier AI framework with new requirements for automated decision-making technology used to materially influence consequential decisions. The statute defines automated decision-making technology, or ADMT, as technology that processes personal data and uses computation to generate outputs such as predictions, recommendations, classifications, rankings, scores, or other information used to make, guide, or assist a decision about an individual.

    The covered decision domains include education, employment, housing, financial or lending services, insurance, health-care services, and essential government services and public benefits.

    Starting January 1, 2027, developers of covered ADMT must provide deployers with technical documentation about intended uses, training-data categories, known limitations, and instructions for appropriate use and human review. Developers and deployers must also retain records needed to demonstrate compliance for at least three years.

    Deployers will have consumer-facing obligations too. They must provide notice at the point of interaction with covered ADMT. If a covered ADMT materially influences a consequential decision that results in an adverse outcome, the deployer must provide a plain-language post-adverse-outcome explanation within 30 days. Consumers also receive rights to request personal data, correct factually incorrect personal data used by the covered ADMT, and request meaningful human review and reconsideration.

    The Attorney General must adopt rules by January 1, 2027 to clarify post-adverse-outcome disclosures and meaningful human review. The statute also gives the Attorney General broader discretionary rulemaking authority, including the ability to clarify "materially influence."

    That phrase is likely to become one of the central compliance questions. The pre-rulemaking paper specifically asks for objective indicators that could distinguish material influence from de minimis or otherwise non-material use.

    The Chatbot Law Is Broader Than Disclosure

    HB26-1263 addresses publicly available conversational AI services that simulate human conversation through text, visual, or audio communications.

    Beginning January 1, 2027, operators must disclose that users are interacting with AI. They must use commercially reasonable or generally accepted methods to estimate user age. If an operator knows that a user or account holder is a minor, the law imposes additional duties, including restrictions on engagement incentives, safeguards against sexually explicit content and simulated emotional dependence, suicide and self-harm response protocols, privacy and account-setting tools, and annual reporting to the Attorney General.

    The law also prohibits operators from representing chatbot outputs as equivalent to services provided by specified licensed or certified professionals.

    The Chatbot Safety Act does not itself require rulemaking in the same way the ADMT Act does. But the Attorney General says rulemaking would help clarify compliance obligations, including the annual reporting requirement and any additional metrics necessary to assess safeguards and response protocols.

    That makes the rulemaking important for more than high-risk decision systems. Any company operating a public-facing conversational AI service with Colorado users should be watching the chatbot questions too.

    The Attorney General's Five Principles

    The pre-rulemaking paper says the Department of Law will use five principles:

    • Promote consumer rights.
    • Clarify ambiguities.
    • Facilitate efficient and expeditious compliance.
    • Harmonize with other state, national, and international frameworks.
    • Allow for innovation.

    That list matters because Colorado is trying to solve two problems at once. It wants enforceable consumer protections, but it also knows vague rules can make implementation harder and litigation more likely.

    The most important open questions include:

    • When does an ADMT "materially influence" a consequential decision?
    • What tools qualify as ADMT, and what tools merely summarize, organize, or present information?
    • How should the rules distinguish developers, deployers, and other participants in an AI supply chain?
    • What should post-adverse-outcome disclosures include in different sectors?
    • What does meaningful human review require in practice?
    • What metrics should chatbot operators report to the Attorney General?
    • How should Colorado's rules interoperate with other state, federal, and international AI, privacy, discrimination, and consumer-protection frameworks?

    Those are not abstract questions. They will determine whether the Colorado framework becomes a manageable compliance regime or a source of recurring uncertainty.

    The Litigation Shadow

    The rulemaking is happening while Colorado's AI law is under active federal challenge.

    xAI sued Colorado Attorney General Phil Weiser in April 2026, challenging the state's algorithmic-discrimination framework. DOJ later moved to intervene, arguing that the Colorado law violates the Equal Protection Clause by requiring AI companies to prevent unintentional disparate impact based on protected characteristics while exempting some discrimination designed to advance diversity or redress historic discrimination.

    The DOJ intervention is significant even apart from the merits. It shows federal willingness to participate directly in litigation over state AI laws, especially where the federal government views state requirements as conflicting with national AI policy, constitutional limits, or innovation priorities.

    Separately, the docket reflects a procedural stay of Colorado Attorney General enforcement pending the preliminary-injunction sequence. That does not resolve the merits. It also does not make the rulemaking irrelevant. To the contrary, the preliminary-injunction schedule appears tied to final implementing rules, which makes the rulemaking record part of the litigation landscape.

    For covered companies, the wrong lesson would be to assume the lawsuit eliminates the need to prepare. The better reading is that the rulemaking record may define the obligations, the compliance burden, and the constitutional stakes.

    What Companies Should Do Now

    Companies do not need to wait for final regulations to start the useful work.

    First, inventory systems that may materially influence decisions about education, employment, housing, lending, insurance, health care, or government benefits. The key question is not whether a system is branded as AI. It is whether computation using personal data produces an output used to make, guide, or assist a decision about an individual.

    Second, map the supply chain. Colorado separates developer and deployer obligations, but many commercial arrangements are messier than that. Vendors, customers, integrators, model providers, and internal teams may all contribute to the final decision process.

    Third, test existing documentation against Colorado's likely documentation topics: intended uses, training-data categories, known limitations, appropriate use, human review, material updates, and compliance records.

    Fourth, design adverse-outcome workflows before the final rule lands. A deployer that cannot explain the role of ADMT in a specific adverse decision will struggle to meet a 30-day disclosure requirement.

    Fifth, review chatbot operations for minor-facing risk. Age estimation, recurring AI disclosure, self-harm escalation, emotional-dependence safeguards, privacy tools, and professional-services disclaimers are design and governance issues, not just legal copy.

    Finally, consider commenting before July 13. The Attorney General is asking for concrete feedback on ambiguity, unintended consequences, compliance burdens, sector-specific examples, and interoperability. Companies that wait for formal draft rules may miss the best chance to shape the starting point.

    Bottom Line

    Colorado is becoming an early operational test for state AI governance.

    The state is trying to turn broad statutes into working rules. The federal government is challenging parts of the framework. Companies are trying to build notices, documentation, review rights, and chatbot safeguards before January 2027.

    That makes the current pre-rulemaking window more than a routine comment period. It is an early chance to shape what compliance may look like when consequential-decision systems and conversational AI services are regulated in practice.

    Sources

    Sources

  • AI Court Rules Are Becoming Verification Rules

    AI Court Rules Are Becoming Verification Rules

    The next phase of legal AI regulation looks less like a blanket ban and more like a verification record.

    Florida now requires filers to stand behind the existence and accuracy of cited legal authorities. New York now allows AI-assisted court papers without a statewide disclosure requirement, but requires independent verification. The Ninth Circuit just sanctioned lawyers for AI hallucinations and lack of candor. A Mississippi federal judge just removed all four lawyers from a case after both sides filed AI-tainted briefs.

    Different courts. Same message: the tool is not the issue. The filing is.

    The New Rule: Verify First

    Florida's amended Rule 2.515(d)(2), effective June 15, 2026, says that by filing a document, the signer represents that "the legal authorities identified exist and are accurately cited." If that representation is false, sanctions can include reprimand, contempt, striking the filing, dismissal, costs, attorneys' fees, or other relief.

    That is deliberately broader than AI. A lawyer cannot escape the rule by saying a fake case came from a chatbot, a legal research product, an associate, local counsel, a vendor, or a recycled brief.

    New York's Part 161, effective June 1, takes a different route but lands in the same place. It permits AI use in court submissions and does not impose a statewide disclosure mandate. But users must understand the technology's limits and independently ensure that filings do not contain fabricated or fictitious cases, statutes, or other material.

    So the emerging split is not "AI allowed" versus "AI banned." It is disclosure versus no disclosure, with verification underneath both.

    The Sanctions Cases Are Getting Less Patient

    In Lnu v. Blanche, the Ninth Circuit sanctioned two lawyers after filings contained nonexistent cases, misattributed quotations, and serious misreadings of real cases. The court stressed that it was not punishing AI use by itself. It was punishing false filings and the lawyers' later lack of candor.

    That distinction matters. A bad citation is a serious problem. A bad explanation can become the larger one.

    The Mississippi sanctions order in Withers v. City of Aberdeen is even more vivid. The case started as a fee dispute brought by Louisiana lawyer Tom Withers III against Aberdeen, Mississippi. After transfer to the Northern District of Mississippi, the court found hallucinated authorities in filings from both sides.

    The plaintiff side included Louisiana pro hac vice counsel Kathleen M. Wilson and Mississippi local counsel Shauncey Hunter Ridgeway. The defense side included Texas pro hac vice counsel Kathryn Y. Williams and Mississippi local counsel Mark C. McClinton. The court removed all four lawyers from the case, revoked both pro hac vice admissions, barred the two out-of-state lawyers from appearing in the district for two years, imposed monetary sanctions, and referred the order to disciplinary authorities.

    The local-counsel lesson is hard to miss: signing is not clerical. Sponsoring is not ceremonial. If your name is on the filing, the verification problem is yours too.

    California May Be Next

    California is also moving from guidance toward rules. The State Bar has opened public comment on proposed amendments to the Rules of Professional Conduct related to AI, after the California Supreme Court asked it to consider incorporating generative-AI guidance and addressing agentic AI tools.

    That is not a court-filing rule like Florida's or New York's. But it shows the same maturation curve. Soft guidance is starting to harden.

    What To Do Before The Next Filing

    Litigation teams should assume courts will ask a simple question: who checked this?

    • Check the courtwide rule, local rule, judge's standing order, and part rules before filing.
    • Identify whether AI touched research, drafting, editing, factual summaries, record citations, or proposed orders.
    • Verify every cited authority in an authoritative source.
    • Read the authority, not just the citation.
    • Confirm quotations, parentheticals, holdings, procedural posture, and subsequent history.
    • Trace facts and record cites back to the record.
    • Make signing, local, and sponsoring counsel confirm the verification process.
    • If an error is found, correct it quickly and candidly.

    The hardest AI errors are not always fake case names. Sometimes they are real cases used for propositions they do not support. A citation check is not enough; the proposition has to survive too.

    Bottom Line

    Courts are not focused on whether AI helped with the first draft. They want to know whether a lawyer verified the final filing.

    The practical rule is now simple: use the tool if the forum, client, confidentiality obligations, and governing orders allow it. But before anything is filed, someone qualified must verify the authorities, quotations, facts, and record references. And someone with a signature block must be ready to say so.

    For a broader inventory of court rules, sanctions orders, privilege decisions, protective-order restrictions, and tribunal guidance, see Clearon's AI Litigation Practice Tracker.

    Sources

    Sources

  • AI-Assisted Legal Filing Verification Checklist

    AI-Assisted Legal Filing Verification Checklist

    Generative AI can accelerate legal work, but it does not change who is responsible for a court filing. Use this checklist before filing any paper that may contain AI-assisted research, drafting, revision, or analysis.

    It is a practical starting point, not a substitute for the requirements applicable to a particular matter.

    Quick Rule

    Do not file an AI-assisted document until a qualified human has independently verified every legal authority, quotation, factual assertion, record citation, and representation about the proceeding against an authoritative source.

    If any item cannot be checked, stop and resolve it before filing.

    1. Confirm Permitted Use

    • [ ] Identify the AI tools used and the portions of the filing they may have affected.
    • [ ] Confirm the use complies with client instructions, protective orders, confidentiality duties, firm policy, and applicable law.
    • [ ] Check local rules, standing orders, judge-specific practices, and filing instructions for AI restrictions or disclosure requirements.
    • [ ] Confirm no protected information was entered into an unapproved system.

    2. Verify Authorities and Quotations

    • [ ] Open and read every cited authority in an authoritative source.
    • [ ] Confirm each citation identifies the correct authority and current version.
    • [ ] Confirm that each authority supports the precise proposition for which it is cited.
    • [ ] Check precedential status, subsequent history, negative treatment, and applicable citation limits.
    • [ ] Compare every quotation and pinpoint citation against the original source and surrounding context.
    • [ ] Confirm parentheticals, paraphrases, and descriptions accurately characterize the source.

    3. Verify Facts and the Record

    • [ ] Trace every material factual assertion to the record or another permissible source.
    • [ ] Open and verify every record citation, exhibit reference, transcript page, docket entry, and date.
    • [ ] Check names, entities, amounts, calculations, timelines, tables, and summaries.
    • [ ] Distinguish allegations, evidence, findings, holdings, inferences, and argument.

    4. Review and Approve the Final Filing

    • [ ] Have a qualified human independently review the final version.
    • [ ] Check the requested relief, legal standard, jurisdiction, deadlines, service representations, and procedural history.
    • [ ] Check for placeholders, invented citations, inconsistent names, unsupported cross-references, and omitted controlling authority.
    • [ ] Verify appendices, exhibits, certificates, signature blocks, and proposed orders.
    • [ ] Complete any required AI-use disclosures or certifications.
    • [ ] Obtain informed approval from the signing lawyer and responsible supervising, local, or sponsoring counsel.

    Ready to File

    • [ ] Every authority, quotation, fact, and record citation has been independently verified.
    • [ ] The final version has not changed since verification.
    • [ ] Applicable AI rules, client restrictions, and disclosure duties have been satisfied.
    • [ ] The signing lawyer can accurately explain how the filing was prepared and checked.
    • [ ] The team preserved a concise record of who reviewed what and when.

    If an Error Is Discovered After Filing

    • [ ] Stop using the affected material and notify responsible lawyers immediately.
    • [ ] Independently determine the error's full scope and preserve relevant records.
    • [ ] Assess duties to the client, court, opposing counsel, insurer, firm, and disciplinary authorities.
    • [ ] Correct material errors promptly and candidly using the required procedure.
    • [ ] Review other filings or matters that may have used the same workflow.

    Candor after discovery can materially affect the court's response. Recent sanctions orders show that concealment, blame shifting, and repeated inaccuracies can be more damaging than the original mistake.

    Bottom Line

    AI assistance does not reduce the duty of inquiry attached to a court filing. Independent verification, meaningful supervision, signer approval, and prompt candor are still the core requirements.

    For examples of how courts are applying those principles, see Oregon Supreme Court's First AI Hallucination Sanctions Show What Courts Punish Most and Clearon's AI Litigation Practice Tracker.

    Sources

    Sources

  • Oregon Supreme Court’s First AI Hallucination Sanctions Show What Courts Punish Most

    Oregon Supreme Court’s First AI Hallucination Sanctions Show What Courts Punish Most

    The Oregon Supreme Court has issued its first sanctions orders involving court filings attributed to generative artificial intelligence. The significance is not a new AI-specific rule. It is that the court applied familiar duties of accuracy, reasonable inquiry, supervision, and candor to filings containing AI-generated errors.

    They also show that the response after an error is discovered can matter almost as much as the original filing.

    In one case, a self-represented litigant accepted responsibility, fully responded to the court, and received a $500 sanction with permission to submit a corrected filing. In the other, self-represented litigants acknowledged fabricated authorities but submitted more nonexistent cases less than 12 hours after the court's show-cause order. The court struck their filings and dismissed the proceeding.

    The lesson extends well beyond Oregon and beyond self-represented litigants. Courts across the country have imposed monetary sanctions, fee awards, dismissal, disqualification, practice suspensions, bar referrals, mandatory disclosures, and other remedies for filings containing fabricated or materially inaccurate authorities.

    Key Takeaways

    • *The Oregon Supreme Court sanctioned self-represented litigants, not lawyers.* The orders make clear that the obligation not to inject false authority into a proceeding applies to everyone who files.
    • *Courts are punishing the filing, not the mere use of AI.* The recurring issue is whether the signer verified that authorities exist, quotations are accurate, and cases support the propositions asserted.
    • *Candor changes the sanction analysis.* Prompt disclosure, correction, and acceptance of responsibility can mitigate sanctions. Repetition, concealment, blame shifting, and misleading explanations can sharply increase them.
    • *The signature and supervision duties are nondelegable.* Lawyers cannot avoid responsibility by pointing to an associate, contract lawyer, local counsel, vendor, internal AI tool, or firm policy.
    • *Financial penalties are only part of the risk.* Dismissal, disqualification, suspension, bar referral, and mandatory notice to clients and other courts can be more consequential than a fine.

    Oregon's Two New Orders

    The Oregon Supreme Court issued both orders on June 4, 2026, and announced them publicly the next day.

    Aldridge v. Tussing: Repeating the Error Led to Dismissal

    In Aldridge v. Tussing, the relators filed a petition for a writ of mandamus supported by nonexistent cases and fabricated quotations. The court ordered them to verify every citation under penalty of perjury, explain the errors, and show cause why sanctions should not be imposed.

    The relators acknowledged that fabricated authorities had been included and attributed the errors to a service called LegalAI. But less than 12 hours after receiving the show-cause order, they submitted another declaration containing at least four nonexistent cases.

    The court struck the petition and the show-cause response and dismissed the proceeding. Its explanation was direct: injecting false precedent undermines the integrity of a proceeding, and repeating the conduct in response to a show-cause order warrants a meaningful sanction.

    Witkin v. McGreevy: Acceptance of Responsibility Mitigated the Result

    In Witkin v. McGreevy, a self-represented respondent filed a response containing fictitious authorities and inaccurate legal arguments generated with AI. After receiving a show-cause order, the respondent addressed each fabricated authority, explained the AI use, and accepted responsibility.

    The court still struck the filing and imposed a stipulated $500 sanction. But it allowed the respondent to file a corrected response, provided that any revised filing certified that every cited, quoted, or paraphrased source of law had been verified to exist.

    The contrast is the point. Both filings contained false authority. The litigant who responded candidly and corrected course received a limited financial sanction and another opportunity to file. The litigants who repeated the misconduct after a direct warning lost the proceeding.

    Oregon Already Had a Six-Figure Warning for Lawyers

    The state-court orders arrived only months after a separate federal case from Oregon demonstrated how large the financial exposure can become.

    In Couvrette v. Wisnovsky, the U.S. District Court for the District of Oregon addressed summary-judgment briefing containing nonexistent cases and fabricated quotations. The court struck the briefing, dismissed the plaintiffs' claims with prejudice, imposed monetary sanctions, and awarded the opposing parties $94,704.38 in fees and costs directly resulting from the briefing.

    The March 2026 fee order allocated the award between lead counsel and local counsel. The local lawyer was ordered to pay 15% after the court found that he had failed to meaningfully participate despite serving as required local counsel for a lawyer admitted pro hac vice. The lead lawyer was ordered to pay the remaining 85%. The court also required local counsel to attach the sanctions order to future motions in which he sought to sponsor pro hac vice counsel in the district.

    Together with the court's earlier monetary sanctions, the financial consequences exceeded $110,000. More important, the case shows that local counsel and supervising lawyers cannot treat their role as providing a name, bar number, or signature while leaving the substance unchecked.

    The Sanctions Menu Is Expanding

    The early headline case was Mata v. Avianca. In 2023, the Southern District of New York imposed a $5,000 penalty after lawyers submitted fabricated cases and fake opinions generated by ChatGPT and continued to defend the material after its authenticity was questioned. The court also required notice to the client and to judges falsely identified as authors of the fabricated opinions.

    Since then, courts have used a much broader range of remedies:

    • *Sanctions for every signer:* In Wadsworth v. Walmart, the District of Wyoming imposed $5,000 in combined sanctions and revoked one lawyer's pro hac vice admission after a filing cited eight nonexistent cases. The court treated the duty to ensure a filing is supported by existing law as nondelegable.
    • *A $10,000 appellate sanction:* In Noland v. Land of the Free, L.P., the California Court of Appeal imposed $10,000 in sanctions after an appellate brief contained fabricated quotations and other inaccurate authority. The published opinion warned that lawyers must personally read and verify the authorities they cite.
    • *Disqualification and bar referrals instead of a fine:* In Johnson v. Dunn, the Northern District of Alabama publicly reprimanded and disqualified three lawyers, required broad distribution of the sanctions order, and referred the matter to licensing authorities. The court concluded that a fine and public embarrassment were insufficient deterrents.
    • *Suspension from appellate practice:* In Lnu v. Blanche, the Ninth Circuit imposed $2,500 sanctions on each of two lawyers, suspended both from practice before the circuit for six months, required notice to clients, opposing counsel, judges, and the lawyers' firm, and imposed a two-year AI-use disclosure and verification requirement. The court emphasized that the more serious discipline resulted from repeated failures of candor after the errors came to light.
    • *Both sides sanctioned:* In Withers v. City of Aberdeen, the Northern District of Mississippi sanctioned and removed all four lawyers after filings from both sides contained hallucinated authorities. The two out-of-state lawyers were also barred from appearing in the district for two years.

    These cases do not establish a uniform sanctions schedule. They show that courts are calibrating remedies to the conduct, the harm, the lawyer's role, prior warnings, remediation, and candor.

    What Courts Appear to Punish Most

    The orders point to several aggravating factors.

    Filing Without Reading the Authorities

    Checking whether a case name exists is not enough. Courts expect lawyers to read the authority and confirm that quotations are accurate, procedural posture is correctly described, and the case actually supports the proposition asserted.

    The Ninth Circuit drew a useful distinction between fabricated authorities and subtler inaccuracies. A fake case may be easy to detect. A real case mischaracterized by an AI tool may be more dangerous because it can survive a superficial citation check.

    Treating Signatures as Administrative

    Courts repeatedly reject the idea that a lawyer can lend a signature without assuming responsibility for the filing. That principle reaches supervising lawyers, local counsel, partners, and lawyers whose names appear in signature blocks even when they did not personally use AI.

    Repeating or Concealing the Problem

    An inaccurate filing creates a serious problem. Misleading the court about how it happened, replacing fake citations without disclosing the original problem, or submitting additional fabrications after a warning creates a larger one.

    The Oregon Supreme Court's two orders make the distinction unusually clear. So does the Ninth Circuit's order in Lnu, where the court said lesser sanctions might have been warranted if the lawyers had promptly disclosed the AI use and accepted responsibility.

    Relying on a Policy Without Enforcing It

    Having a written AI policy is not a defense when actual workflows allow unverified material to reach the court. Policies must identify who checks citations, quotations, propositions, facts, and record references before filing. They also need a clear escalation process when an error is discovered.

    What Litigation Teams Should Do Now

    For a practical pre-filing workflow, use Clearon's AI-Assisted Legal Filing Verification Checklist.

    • Require verification of every citation, quotation, factual assertion, and record reference against the original source before filing.
    • Make the signing lawyer responsible for confirming that verification occurred.
    • Apply the same controls to work prepared by associates, contract lawyers, local counsel, clients, vendors, and AI tools.
    • Preserve enough information about the drafting and verification process to explain it accurately if questioned.
    • When an error is discovered, notify the court and opposing counsel promptly, identify the nature and source of the error, and propose a concrete correction.
    • Do not describe a fabricated authority as a typographical error or silently swap in a different citation.
    • Train lawyers to detect mischaracterizations of real cases, not only nonexistent citations.
    • Treat show-cause orders as urgent risk events requiring independent review and senior oversight.

    Bottom Line

    The Oregon Supreme Court's first AI-related sanctions orders do not ban AI. They show how courts protect the integrity of filings when AI-assisted work reaches the docket without real verification.

    The technology may explain how a false citation appeared, but it does not change who is responsible for filing it. Courts are increasingly focused on three questions: Was the filing verified? Who accepted responsibility for it? What happened after the error was discovered?

    The emerging sanctions record suggests that the last question can determine whether the result is a correctable mistake, a monetary penalty, a lost case, or a career-level disciplinary problem.

    For the broader court-rule landscape, see Federal Court AI Orders Are Splitting Into Clear Patterns and Clearon's AI Litigation Practice Tracker.

    Sources

    Sources

  • Legal AI Workflows: A Governance Checklist for Legal Teams

    Legal AI Workflows: A Governance Checklist for Legal Teams

    Legal AI succeeds or fails at the workflow level.

    A model may look impressive in a demonstration and still create unacceptable risk once it touches client files, institutional knowledge, contract data, legal research, or work product.

    The practical question is not simply whether an AI tool is accurate. It is whether the full workflow around the tool is governable, reviewable, and defensible.

    Start with the workflow, not the model

    This checklist gives law firms and legal departments a structured way to evaluate and manage AI-assisted workflows before and after deployment.

    A usable workflow definition should identify:

    • the task and intended outcome;
    • the people permitted to use the workflow;
    • the data the tool may receive or retrieve;
    • the decisions or documents the output may influence;
    • the required level of human review; and
    • the person accountable for the final result.

    This step prevents a narrow tool approval from quietly becoming permission for much broader uses.

    1. Assign an owner and risk tier

    Every production workflow needs a named business owner and a defined risk level. The owner should be responsible for approving changes, monitoring performance, and escalating incidents.

    Risk tiers should reflect the consequences of error and the sensitivity of the information involved. A tool that summarizes public regulations presents a different risk profile from one that reviews privileged investigation materials or drafts a filing.

    Higher-risk workflows should receive more testing, tighter access controls, stronger documentation, and more frequent review.

    2. Control confidential and privileged information

    Legal teams should determine exactly what happens to prompts, uploaded documents, retrieved materials, outputs, and usage logs. The answer may differ across consumer, enterprise, API, and privately hosted versions of the same product.

    Key diligence questions include:

    • Is submitted data used to train or improve models?
    • How long is data retained, and can retention be configured?
    • Which vendor personnel and subprocessors can access the data?
    • Where is the data stored and processed?
    • Can the organization enforce matter-level permissions and ethical walls?
    • What happens to data after termination?

    ABA Formal Opinion 512 emphasizes that lawyers using generative AI must consider duties including competence and confidentiality. A workflow should not accept sensitive legal information merely because the interface makes uploading it easy.

    3. Govern context, permissions, and retrieval

    For many legal workflows, the most valuable capability is not the model itself. It is access to the organization’s own documents, precedents, policies, and prior work.

    That creates a permissions problem. An AI system should not reveal information a user could not otherwise access. Legal teams should test whether the retrieval layer respects document permissions, matter boundaries, client restrictions, retention rules, and information barriers.

    This is why institutional knowledge and governed context are becoming central to legal AI infrastructure.

    4. Define required human review

    “Human in the loop” is not a complete control unless the organization defines what the human must actually do.

    For each workflow, specify:

    • who reviews the output;
    • what sources or underlying documents must be checked;
    • which factual, legal, citation, numerical, or contractual elements require verification;
    • what level of confidence or error requires escalation; and
    • whether the output may be sent externally before review.

    Review should match the use. A lawyer approving a court filing needs a different process from a team using AI to create a first-pass internal summary.

    5. Test the complete workflow

    Testing should use realistic examples and measure the complete workflow, not just isolated model answers. That includes the source documents, retrieval system, prompt or interface, output, reviewer actions, and final downstream use.

    A practical evaluation set should include routine matters, difficult edge cases, incomplete information, conflicting documents, and attempts to cross permission boundaries. Teams should record both quality failures and process failures.

    NIST’s AI Risk Management Framework organizes risk work around the functions Govern, Map, Measure, and Manage. That structure is useful for legal workflows because it treats evaluation and monitoring as continuing responsibilities, not a one-time procurement exercise.

    6. Review vendor terms and operational dependencies

    Legal and procurement teams should evaluate the contract around the workflow, including:

    • data-use and confidentiality commitments;
    • security obligations and incident notification;
    • subprocessors and model providers;
    • indemnities, liability limits, and warranty disclaimers;
    • audit rights and documentation;
    • service changes and model substitutions;
    • data export, portability, and termination assistance; and
    • the organization’s ability to preserve records or satisfy legal holds.

    Workflow dependence matters too. As frontier-model providers move into government legal workflows through specialized partners, buyers need to understand which party controls each layer and what happens if one layer changes.

    7. Create records that make review possible

    A defensible workflow should produce enough documentation to reconstruct important decisions. Depending on the use case, that may include the tool and version used, source materials, prompts or configured instructions, output, reviewer, corrections, approval, and date.

    Not every low-risk use requires a permanent prompt archive. The organization should make a deliberate retention decision based on legal obligations, business need, risk, and discoverability rather than allowing the product’s default settings to decide.

    8. Monitor changes after launch

    AI workflows can change even when the organization does not intentionally redesign them. Vendors update models, retrieval systems, interfaces, terms, and safety controls. Internal data sources and permissions also change.

    Monitoring should include:

    • periodic quality and permission testing;
    • review of incidents, overrides, and user feedback;
    • tracking vendor and model changes;
    • reviewing whether the workflow is being used beyond its approved purpose; and
    • reassessing the risk tier when the workflow expands.

    A practical approval record

    Before launch, the approving team should be able to answer these questions in writing:

    1. What exact workflow are we approving?
    2. Who owns it?
    3. What information may it access?
    4. What can go wrong, and who could be affected?
    5. What testing supports the decision?
    6. What human review is required?
    7. What records will we keep?
    8. How will we detect changes and failures?
    9. When will we review the approval again?

    The Clearon AI takeaway

    Legal AI governance should be concrete enough to operate. Policies matter, but the durable control point is the individual workflow: its owner, data, permissions, testing, human review, contract, records, and monitoring.

    The legal AI market is increasingly competing at this workflow layer. The teams that benefit most will be the ones that make those workflows useful without making them unaccountable.

    Related Clearon AI analysis

    Primary sources

  • The OpenAI Copyright MDL Has Become a Data-Governance Case

    The OpenAI Copyright MDL Has Become a Data-Governance Case

    Current through June 9, 2026.

    The OpenAI copyright multidistrict litigation matters because it has already produced claim-specific rulings and unusually consequential discovery disputes involving model-development records, privilege, and large sets of ChatGPT conversation logs.

    No court has entered a final judgment on whether OpenAI's model training is fair use. The litigation still gives companies a practical warning: ordinary decisions about retention, deletion, vendor terms, and internal records can become central evidence in a major lawsuit.

    Where the MDL stands

    The Judicial Panel on Multidistrict Litigation created MDL No. 3143 on April 3, 2025, transferring four actions to the Southern District of New York for coordinated or consolidated pretrial proceedings. Additional actions have since been transferred.

    The consolidated cases are not identical. They include claims by authors, newspapers, publishers, and other rights holders involving model training, allegedly infringing outputs, contributory infringement, and provisions of the Digital Millennium Copyright Act concerning copyright-management information.

    An MDL coordinates overlapping pretrial work, but it does not turn every plaintiff’s theory into one claim or decide that any claim will succeed.

    The case has moved beyond consolidation

    In a December 15, 2025 ruling involving Ziff Davis, the court allowed several claims to proceed past a motion to dismiss, including contributory-infringement and certain DMCA copyright-management-information claims. It dismissed other theories, including the claim that disregarding robots.txt instructions constituted circumvention of an effective technological measure. The ruling did not decide liability, but it showed that the litigation will turn on specific claims, facts, and model behavior rather than one sweeping answer about AI and copyright.

    Discovery has become just as important as the pleading rulings:

    • In January 2026, Judge Stein upheld orders requiring production of a sample of 20 million de-identified ChatGPT conversation logs.
    • In March 2026, Magistrate Judge Wang granted in part a request involving additional reservoirs of 78 million and 10 million logs, subject to a protocol addressing de-identification and user privacy.
    • In May 2026, the court ordered OpenAI to produce deposition testimony from separate litigation involving Sam Altman, Greg Brockman, Satya Nadella, and an OpenAI corporate designee after finding the narrowed request relevant and proportional.
    • In February 2026, Judge Stein set aside a magistrate judge’s ruling that OpenAI had waived attorney-client privilege over certain 2022 communications concerning the Books1 and Books2 datasets and Library Genesis.

    Those developments do not establish infringement. They do show what an AI copyright case can demand once it reaches coordinated discovery.

    The clearest governance lesson is about data

    The MDL has made retention and discovery policy part of the copyright-risk discussion.

    For enterprise users, the immediate lesson is not that their prompts will necessarily become evidence in this case. It is that vendor data practices, contractual promises, litigation holds, and court-ordered discovery can interact in ways that are easy to overlook during procurement.

    Legal, privacy, security, and procurement teams should ask:

    • What prompts, outputs, metadata, and logs does the vendor retain?
    • Which retention settings are defaults, and which require an enterprise plan or approval?
    • Can ordinary deletion schedules be suspended by a legal hold, court order, or regulatory obligation?
    • What data may be used to improve models, and what requires an affirmative opt-in?
    • Which internal repositories or systems can the tool access?
    • Can the company preserve its own audit trail without collecting more sensitive content than it needs?

    OpenAI states that business-product and API data are not used to train its models by default. It also states that API inputs and outputs are generally removed after 30 days unless legal requirements require retention, and that eligible customers may request zero-data-retention controls for qualifying endpoints. Those are meaningful controls, but buyers still need to understand exceptions, product-specific settings, and what happens when litigation or another legal obligation changes the ordinary retention rules.

    Procurement terms need operational follow-through

    Contract review remains important, but contract language alone is not a governance program.

    Buyers should evaluate vendor representations about training data, output restrictions, indemnity, retention, confidentiality, security, and cooperation during disputes. They should also make sure internal settings and workflows match the negotiated terms.

    A contract may promise strong business-data protections while employees continue using consumer accounts. A zero-retention option does little if it was never enabled for the relevant endpoint. A restriction on confidential data will not help if the organization has no practical rule for deciding which repositories or matters an AI coding or research tool may access.

    Code-generation controls remain useful, but they are a separate issue

    AI-generated code presents a related but distinct set of copyright and open-source-license risks. Companies should not treat the OpenAI MDL as proof that generated code infringes or that any particular compliance control is legally required.

    Still, software companies have practical reasons to treat AI-generated code like third-party code until it is reviewed:

    • use approved enterprise coding tools and accounts;
    • enable public-code matching or reference features where available;
    • require human review for long or unusually specific generated snippets;
    • scan generated code for open-source and snippet-level risks before release;
    • document remediation of flagged code; and
    • restrict sensitive repository and file access.

    GitHub documents a policy that can block Copilot suggestions matching publicly available code or allow them with code references. Cursor states that Privacy Mode enables zero data retention for model providers, while also explaining that some code data may still be stored to provide additional features and that codebase indexing involves uploads for embedding. These controls address different risks. Public-code matching is not a confidentiality control, and privacy settings are not license-clearance tools.

    What legal teams should do now

    1. Map which AI products are in use, including consumer accounts and tools embedded in other software.
    2. Record the actual retention, training, access, and deletion settings for each approved product.
    3. Reconcile vendor contracts with technical configuration and employee practice.
    4. Decide what AI-use records are genuinely needed for audit, compliance, or litigation readiness.
    5. Apply separate controls for confidential data, generated code, external-facing content, and high-risk decisions.
    6. Revisit the program when vendor terms, product settings, or major court rulings change.

    What to watch next

    The most consequential developments will be rulings that clarify training-copy theories, output-based claims, fair use, DMCA liability, and the permissible scope of discovery. Additional transfer orders also matter because they determine which disputes enter the coordinated proceeding.

    For enterprise users, the discovery fights may be as instructive as the eventual merits rulings. They show that AI governance is not limited to deciding whether employees may use a tool. It includes knowing what the tool retains, what the company can control, and what may have to be preserved or produced when litigation begins.

    Sources