Tag: Courts / Litigation Practice

  • California’s AI Employment Bills Reach Enrolled Status With Human Review and Displacement Notice Rules

    California’s AI Employment Bills Reach Enrolled Status With Human Review and Displacement Notice Rules

    California now has two AI employment bills at enrolled status.

    That matters because the pair does not try to regulate workplace AI as one abstract category. It targets two concrete points where automation changes employment power: discipline or termination decisions, and workforce reductions caused by AI or other automated technology.

    SB 947 would bar employers from relying solely on automated decision systems to discipline or fire workers and would require human review when an employer primarily relies on automated decision system output. SB 951 would add AI-driven or automation-driven displacement information to California's mass-layoff notice framework when a covered Cal-WARN notice is already required.

    Both bills are still awaiting executive action. They are not enacted law yet. But the official California records show both measures enrolled on September 4, 2026, after final Senate concurrence votes on August 31. That makes this a live compliance-planning moment, not another introduced-bill story.

    For companies using workforce AI, the direction is clear enough already. California is moving from "should employers use AI carefully?" to "who reviews the automated output, what must the worker be told, and what public records will exist when automation displaces jobs?"

    What Changed This Week

    The official California bill records show SB 947 and SB 951 both reached enrolled status on September 4, 2026.

    SB 947, titled "Employment: automated decision systems," passed after Assembly amendments were concurred in by the Senate on August 31 by a 28-10 vote. The official Legislative Counsel's Digest says the bill would add a new Labor Code part beginning July 1, 2027.

    SB 951, titled "Employment: technological displacement: notice," also reached enrolled status on September 4 after Senate concurrence in Assembly amendments on August 31, by a 29-10 vote.

    Those statuses matter because the legislative question has narrowed. The bills are no longer merely concepts being debated in committee. They are passed measures awaiting executive action.

    That does not make them binding yet. It does make them serious enough that companies should begin mapping whether their workforce systems would fall within the rules if the bills are signed.

    SB 947 Is About AI in Discipline and Termination

    SB 947 is the more direct "robo boss" bill.

    The official digest says the bill would, beginning July 1, 2027, prohibit an employer from using an automated decision system to perform certain functions and limit the purposes for and way in which such a system may be used. It would also create employee rights around the data used by the system when the employer primarily uses an automated decision system to make a disciplinary or termination decision.

    The bill is more than a ban on a fully automated firing button. It is also a documentation and notice bill.

    When an employer primarily uses an automated decision system to make a disciplinary or termination decision, the bill would allow the affected employee to request a description of the employee's own data primarily used by the system. It would also require a written post-use notice when an employer primarily relied on an automated decision system to make the decision.

    The author's office frames the bill more plainly. Senator Jerry McNerney's announcement says SB 947 would bar employers from relying solely on automated decision systems to fire or discipline workers, require human oversight and verification when such systems assist those decisions, and require employers to inform workers if an automated decision system was used.

    The enforcement structure also matters. The official digest says the Labor Commissioner could enforce the bill and a public prosecutor could bring a civil enforcement action. The author's announcement says the bill does not provide a private right of action.

    For employers, that combination points to a regulatory file rather than just a lawsuit file. If the bill is signed, companies will need to show how the human review worked, what notice was given, what data description can be produced, and why the automated system was not treated as the final unreviewed decision maker.

    SB 951 Is About AI-Driven Job Displacement

    SB 951 addresses a different problem: not the individual disciplinary decision, but the larger workforce event.

    The official status page describes SB 951 as a bill on "Employment: technological displacement: notice." The bill text would amend California's mass-layoff notice framework so that, when an employer is already required to issue notice for a mass layoff, relocation, or termination, and that event is caused in whole or in substantial part by an AI system or other automated technology replacing or automating employment positions, the notice must include additional information.

    That information would include:

    • the number, classification or occupation, and work location of layoffs substantially due to replacement or automation by AI or other automated technology;
    • the job functions performed by the replaced workers that will be automated;
    • the specific category or type of AI system or other automating technology that substantially resulted in technological displacement; and
    • a statement at the top of the notice saying, "This notice is for a technology displacement."

    The bill would also require California's Employment Development Department, as part of regular Cal-WARN Act data reporting, to publish a summary of notices received under the new technological-displacement subdivision and post quarterly statewide summaries of reported technology displacements.

    That is a major practical point. SB 951 would add a public reporting trail about AI-related and automation-related displacement.

    For companies, that means the decision to attribute a layoff to AI or automation may become visible outside the company. For policymakers, researchers, unions, journalists, and competitors, the same notices could become a data source about where automation is actually replacing jobs.

    The Two Bills Should Be Read Together

    SB 947 and SB 951 are stronger together than either bill is alone.

    SB 947 focuses on decision quality and worker process when an automated decision system is used in discipline or termination. SB 951 focuses on transparency when technology changes the structure of the workforce.

    One is about the affected worker asking: was an automated system used against me, and what data did it rely on?

    The other is about the affected workforce, government, and public asking: are jobs being eliminated because AI or automation is replacing them, and where is that happening?

    That is the real story. California is moving beyond product-level workplace AI regulation and into the evidence trail around workplace AI.

    Employers will not be able to treat these questions as purely internal design choices if the bills are signed. The practical burden will sit in HR, legal, compliance, procurement, data governance, labor relations, and workforce planning.

    This Fits a Broader State Pattern

    California is not moving in isolation.

    Colorado's 2026 automated decision-making technology law, which replaces the state's earlier high-risk AI framework, also turns on notice, explanations, data correction, and meaningful human review. Illinois already regulates certain employment uses of artificial intelligence through amendments to the Illinois Human Rights Act. New York City has had its automated employment decision tool law in force for several years.

    The California bills would add a different kind of pressure.

    SB 947 would push into discipline and termination, beyond the hiring focus of many employment-AI laws. SB 951 would push into displacement reporting through Cal-WARN notices. Together, they would make employment AI governance a continuing operational requirement rather than a one-time vendor review.

    That matters because many organizations still treat AI employment risk as a hiring-screening issue. The newer pattern is broader. It covers who is evaluated, who is disciplined, who is terminated, who is replaced, and what records prove the company did not let automated systems quietly make the real decision.

    What Companies Should Do Before Signature

    Companies do not need to wait for final enactment to start the useful work.

    The first step is inventory. Employers should identify systems that rank, score, recommend, flag, classify, monitor, or otherwise influence discipline, performance management, termination, layoffs, redeployment, or workforce planning.

    The second step is role mapping. A tool that merely stores employee records is different from a tool that recommends termination, flags productivity concerns, scores performance, identifies positions for elimination, or produces a workforce-reduction plan.

    The third step is human-review design. If a system can affect discipline or termination, the company should be able to say who reviews the output, what information the reviewer sees, what discretion the reviewer has, and how the company records the human judgment.

    The fourth step is notice and data-description readiness. If a worker can ask for a meaningful, objective description of the employee's own data that the system primarily used, the company needs to know whether that description can be produced without exposing unrelated confidential or third-party information.

    The fifth step is displacement classification. If AI or automated technology contributes to layoffs or job eliminations, the company should decide how it will determine whether the technology caused the event "in whole or in substantial part." That phrase is likely to do a lot of work if SB 951 becomes law.

    What Not To Overstate

    There are three cautions.

    First, neither bill is enacted yet. The Governor can still sign, veto, or otherwise affect the final posture. The right status today is enrolled and awaiting executive action.

    Second, SB 947 should not be described as banning all AI use in employment decisions. The official materials point to limits, human oversight, worker notice, and data-description rights around covered uses, especially discipline and termination.

    Third, SB 951 is not a general anti-automation law. It is a notice and reporting bill tied to covered Cal-WARN mass-layoff and related events caused in whole or in substantial part by AI systems or other automated technology.

    Those limits make the bills more useful, not less. They show where the compliance work will actually sit.

    Bottom Line

    California's latest AI employment package is about control and records.

    SB 947 asks whether a human really reviewed the automated decision system output that helped discipline or fire a worker, and whether the worker gets notice and a meaningful description of the employee data primarily used around that use. SB 951 asks whether AI or automation materially contributed to displacement in a covered Cal-WARN event and whether that fact will be reported through the state's layoff-notice system.

    If both bills are signed, California will add another important layer to workplace AI governance: whether the company can show who relied on the tool, who reviewed its output, what the worker was told, and what the public record says when technology replaces jobs.

    That is a much harder problem than updating an AI policy. It is a workflow problem. Companies that use automated systems in employment decisions should treat it that way now.

    Sources and Related Clearon Coverage

  • From a Stricken Filing to an $8,000 Fine: How Courts Calibrate Citation Failures

    From a Stricken Filing to an $8,000 Fine: How Courts Calibrate Citation Failures

    Three late-August federal orders are useful to read together because they show something easy to miss in the current discussion around AI-tainted filings.

    The issue is not just whether bad citations appeared in a filing.

    It is how courts sort out responsibility, procedure, candor, and remedy after that happens.

    The orders in Booker v. The Kroger Co., Adams v. Matrix Providers Inc., and In re Turgeon do not land in the same place. One involves admitted AI consultation and a direct sanctions order. One leaves AI causation unresolved while criticizing counsel's judgment and rule compliance. One involves a pro se debtor, no AI finding, and a stricken filing rather than a separate sanctions ruling. A fourth recent opinion, Snisko v. Cascade Funding Mortgage Trust HB4, adds another variation: a merits affirmance and a same-opinion show-cause order directed at counsel over allegedly fabricated quotations and misrepresentations. Read together, they show that even when AI is part of the background, the consequence still turns on human conduct and procedural posture.

    Booker: The Court Reached A Direct Rule 11 Sanctions Order

    Booker is the clearest of the three.

    In an August 28 Opinion and Order of Sanctions, Judge Steven D. Grimberg sanctioned plaintiff's counsel for using "fake or hallucinated case authorities" and for misrepresenting real authorities. The order also says counsel lied to the court about AI use.

    That candor point mattered.

    The court quoted its own standing order: lawyers may use whatever AI tools they like, but only human beings will be held responsible for the outcome. The order says counsel first denied using AI at the hearing, then later acknowledged that he had "consulted" AI tools. The court found that counsel had repeatedly lied to the court and used an "entirely disingenuous" explanation to minimize responsibility.

    The sanction was concrete and public. The court imposed $1,000 for each of four highlighted fake, false, or misleading authorities, then doubled that amount because of the lies to the court, for a total sanction of $8,000. It also ordered counsel to file documentation verifying the ethics and technology CLE training he said he had completed.

    The practical lesson is that citation failures can become materially more costly after the court concludes that counsel responded with evasion instead of candor, including by falsely denying AI use.

    Adams: The Court Criticized The Briefing, But The Remedy Was Narrower

    The August 27 order in Adams took a different path.

    Judge Charlotte N. Sweeney described serious problems in plaintiff's briefing, including a phantom citation to a nonexistent case, numerous inaccurate descriptions of case holdings, and repeated failures to support assertions with accurate record citations. The court also addressed counsel's explanation that Ricks v. Starbucks was included inadvertently during a family emergency while unnamed outside help and a paralegal assisted with finalizing the briefs.

    But the order stopped short of turning the whole episode into a sweeping AI sanctions opinion.

    The court expressly said it was unclear whether the briefing failures resulted from AI use or from "poor and unexacting legal judgment." Either way, the court found the conduct highly concerning. It also cited the Tenth Circuit's statement in Amarsingh v. Frontier Airlines that there is nothing inherently problematic about using GenAI in legal practice, while careless use can waste judicial resources and damage credibility.

    The court admonished Pearson over the citation failures. Its $1,000 monetary sanction, however, was framed around the courthouse-photography violation and repeated failure to follow local rules and practice standards, although the concluding sanction paragraph also cited Rule 11(c)(1). The order should not be read as assigning a $1,000 sanction specifically to the phantom citation.

    That is a useful distinction. A filing may contain AI-shaped defects without producing the kind of direct hallucination order that Booker delivered. Courts may instead fold the problem into a broader assessment of judgment, local-rule compliance, and lawyer conduct.

    Turgeon: The Court Struck The Filing And Focused On Case Management

    Turgeon is different again.

    The New Hampshire district court affirmed the bankruptcy court's dismissal of the debtor's Chapter 13 case. In recounting the record, the order explains that the bankruptcy judge questioned the debtor about "false, hallucinated case citations" in an objection to the trustee's motion to dismiss, found the citations inaccurate and misleading, and struck the objection.

    The opinion also notes that the debtor was given a chance to cure by filing an amended objection and did not do so.

    What matters here is what the court did not do. This was not a separate Rule 11 sanctions order. The district court did not treat the citation defects as a basis for dismissal. It held that the bankruptcy court could strike the objection under § 105(a), emphasized the two-week opportunity to amend, and rejected the due-process challenge after Turgeon failed to cure. The Chapter 13 dismissal rested on separate plan-filing and delay grounds.

    That makes Turgeon a reminder that citation problems do not always become standalone sanctions opinions. Sometimes they appear as part of a court's effort to manage the docket and police misleading filings without converting the dispute into a separate sanctions proceeding.

    Snisko: The Merits Can End And The Citation Fight Can Still Begin

    Snisko contributes a narrower but useful procedural point.

    In the same August 19 opinion that affirmed the bankruptcy court's abstention ruling, Judge Manish S. Shah separately ordered appellant's counsel to show cause why he should not be sanctioned for fabricated legal citations and other misrepresentations. The opinion said the brief was "replete with false quotations and erroneous statements of law," identified apparent quotations that do not appear in cited cases including In re Aguirre and In re Boughton, and said counsel "doubled down" in the reply after the defects had been flagged.

    The order does not make an express AI finding. That is part of why it matters. It shows that a court does not need to resolve how the errors were produced before opening a sanctions track. It also shows that citation risk can survive the merits, or in this case be embedded in the same opinion that resolves them.

    The Pattern Is Human Accountability, Not Tool Liability

    Taken together, the three orders tell a more useful story than a generic warning not to trust AI.

    They show that courts are still applying familiar legal ideas:

    • responsibility attaches to the signed filing;
    • candor after an error can materially affect sanction severity;
    • procedural posture can shape whether the outcome is a Rule 11 sanction, a local-rule sanction, a stricken filing, a same-opinion show-cause order, or some combination; and
    • the court does not need a grand theory of AI causation before acting.

    That is why the recent AI filing cases should not be read as a separate body of exotic law. They are mostly ordinary supervision, certification, and litigation-conduct rules applied to a new source of error at scale.

    What Law Firms Should Change

    The control problem is not just whether a tool generated a fake case name.

    It is whether the workflow catches:

    • nonexistent authorities;
    • real authorities used for false propositions;
    • quotations that do not appear in the source;
    • inaccurate record references;
    • misleading procedural narratives; and
    • bad post-error responses that make the situation worse.

    The second control point is escalation. Once a court or opposing party flags a possible hallucination or fake authority, the matter should leave ordinary drafting flow and move into a higher-review path led by a supervising lawyer. That follow-up needs independent source verification, a clean explanation of what happened, and absolute candor with the court.

    Booker shows what happens when that second step fails. Snisko shows that simply repeating the challenged position after notice can deepen the problem even before a sanctions amount is set. Booker also shows that a court may reserve whether further sanctions are warranted while requiring proof of the remedial training counsel says he has completed.

    Bottom Line

    The late-August orders do not create a single AI doctrine under Rule 11.

    They do show a stable principle.

    Courts still care most about the human choices around the filing: who signed it, who checked it, how the lawyer responded when the defects surfaced, and whether the court's rules were taken seriously. AI may explain how the error entered the draft. It does not replace the lawyer who owns the result.

    Sources and Related Clearon Coverage

  • Hidden Prompts Are Moving Into Legal Filings and Contract Review

    Hidden Prompts Are Moving Into Legal Filings and Contract Review

    Legal AI's most visible failures have appeared in model outputs: fabricated cases, false quotations, invented research, and confident but wrong summaries.

    Prompt injection creates an earlier problem: the document itself can try to manipulate the AI system reading it.

    That connects a reported Connecticut court-filing incident with a recent LinkedIn post demonstrating prompt injection in contract review. The settings differ, but the tactic is the same: text embedded in a document poses as an instruction to the model.

    The Reported Connecticut Filing

    This example comes from secondary coverage, not our independent review of the court record. A Not the Bee article summarizing Ars Technica's reporting says a self-represented Connecticut plaintiff submitted filings containing hidden text directed at any AI system that might review them. Journalist Jason Koebler described the same reported incident in an X post as a prompt-injection attack intended to make an AI system side with the filer.

    According to the coverage, the text instructed an AI reviewer to agree with the filer's position and support a requested result. Judge Walter Spader Jr. reportedly said the text did not affect the outcome and that the Connecticut Judicial Branch does not use AI to review or decide filings. The court reportedly barred the filer from future electronic filing.

    The attempt reportedly failed. Its significance is that someone allegedly tried to manipulate an AI reviewer in a live court proceeding. Legal workflows can no longer assume every part of a submitted document is merely content.

    The Contract-Review Risk Is More Immediate

    The LinkedIn post brings the threat into an everyday legal workflow. Its contract-review scenario uses instructions concealed in white or tiny text to tell the model not to flag liability, assignment, or IP ownership terms. A mock contract page shows the text becoming visible when formatting marks are revealed.

    Unlike the filing, this is a demonstration, not a reported contract incident. But the control problem is real. A legal team may send an NDA, SaaS agreement, or acquisition draft to an AI review tool. Unless the system reliably separates source material from instructions, hidden text may compete with the reviewer's prompt.

    The result could look polished while omitting the provisions that matter most.

    Why Prompt Injection Is Different From a Hallucinated Citation

    Many legal-AI controls focus on checking the model's answer. Does the case exist? Does the quotation match? Does the summary overstate the holding? Did a lawyer review the filing?

    Prompt injection operates earlier, trying to shape how the model handles the source before it produces an answer.

    The source document is therefore not just evidence or draft language. It is untrusted input that may contain instructions competing with the user's actual request. That makes prompt injection a security problem as well as an accuracy problem.

    Treat External Documents as Untrusted Input

    The risk applies wherever an AI system analyzes text it did not originate, including:

    • court filings submitted by opposing parties or self-represented litigants;
    • contracts received from counterparties;
    • resumes, expert reports, and diligence materials processed by internal AI tools;
    • document sets loaded for summarization, issue spotting, or first-pass redlining; and
    • any workflow in which a model decides what matters inside an external document.

    The operating principle is simple: the document is evidence, not instructions.

    That distinction is obvious to a lawyer. A model needs technical and procedural controls that enforce it.

    What Legal Teams Should Do Now

    The answer is not to stop using AI, but to stop treating documents as trusted input channels.

    Legal teams using AI for review, drafting, or triage should:

    1. Assume incoming documents may contain hidden or manipulative text.
    2. Inspect and, where practical, normalize files before AI review. Check for white or tiny text, comments, footnotes, hidden layers, and embedded metadata.
    3. Require human review of provisions and decisions that can materially change risk, including liability caps, indemnity, IP ownership, assignment, confidentiality, and representations made in a filing.
    4. Treat AI output as a review aid, not a final determination.
    5. Train lawyers and legal operations staff to recognize prompt injection as a document risk, not just a chatbot risk.
    6. Ask vendors how their systems distinguish document content from instructions, detect concealed text, and respond to suspected injection attempts.

    Courts, e-filing platforms, document-management teams, and legal-tech vendors should ask the same question: what happens when a submitted document tries to steer the system reading it?

    Bottom Line

    The Connecticut attempt reportedly failed, and the hidden prompts described in the coverage appear crude. That does not make the tactic harmless.

    The court-filing account and the contract-review demonstration show two versions of the same risk. One targets a court-facing workflow. The other tries to keep an AI reviewer from surfacing consequential terms.

    As legal teams place more AI between a document and a human decision-maker, prompt-injection defenses become basic legal-tech hygiene.

    Sources

  • Delaware Chancery Orders Lawyer and Firm to Explain GenAI Briefing Failures

    Delaware Chancery Orders Lawyer and Firm to Explain GenAI Briefing Failures

    The Delaware Court of Chancery just handed down a useful AI opinion, and the useful part is not a final sanctions award.

    It is the court's decision to force both the signing lawyer and the law firm to explain, in detail, how a GenAI-tainted brief made it onto the docket.

    In Kevin Leiske et al. v. Robert Gregory Kidd et al., Vice Chancellor Lori Will ordered Richard P. Rollo and Richards, Layton & Finger to show cause why they should not be sanctioned under Rule 11 and the court's inherent authority. The July 1 order says the answering brief contained fictitious citations, fabricated quotations, and hallucinated legal propositions. It also says the problems got worse after the errors were flagged.

    That makes this more than another fake-citation story.

    Why This Order Matters

    The Delaware opinion is not just about whether a lawyer used AI badly.

    It is about what a court wants to know after that happens:

    • who used the tool,
    • who entered the prompts,
    • how the output was incorporated,
    • who was supposed to verify it,
    • whether lawyers personally checked the authorities, and
    • what firm safeguards existed at the time.

    That is a more mature court response than a generic warning not to trust AI.

    The court is treating GenAI misuse as a workflow, supervision, and certification problem.

    What The Court Said Happened

    According to the order, the plaintiffs' January 22 answering brief contained false citations, fabricated quotations, and legal propositions that the cited authorities did not support.

    The next day, after the defendants flagged the problems, plaintiffs' counsel acknowledged that a generative AI tool had been used to revise the brief. Counsel admitted the citations were not verified before filing and attributed the lapse to a paralegal's review.

    That did not end the problem.

    The court said the corrected brief removed quotation marks around erroneous statements of law but did not fix the underlying inaccuracies. It also took a dim view of counsel's argument that opposing counsel should have met and conferred before alerting the court. Vice Chancellor Will wrote that there is nothing to negotiate when a filing presents false citations to a tribunal.

    That passage is worth remembering. Courts may expect parties to meet and confer over ordinary disputes. They are not likely to treat false authority in a filed brief as a routine discovery squabble.

    The Firm Is In It Too

    The sharpest part of the order may be the firm-level piece.

    Delaware Chancery Rule 11(c)(1) says that absent exceptional circumstances, a law firm must be held jointly responsible for Rule 11 violations committed by its partners, associates, or employees. Vice Chancellor Will said this incident may implicate the firm's training, supervision, and deployment of GenAI, so the firm must answer alongside the signatory.

    That is what makes the order especially useful for law firm leaders.

    Many AI discussions still drift toward individual blame: which lawyer signed, which associate drafted, which paralegal cite-checked, which tool hallucinated. This order looks past that first layer. It asks what policies, training, and safeguards the firm had in place before the filing was made.

    What The Court Wants Explained

    The show-cause order requires separate affidavits from the signatory lawyer and an authorized firm representative by July 15.

    For the lawyer, the court wants:

    • a timeline showing how and when the GenAI tool was used in drafting the brief;
    • who entered prompts and how the output was added to the filing;
    • a description of the cite-checking process before filing;
    • what instructions were given to paralegals;
    • what verification tools were used;
    • whether attorneys verified the cited text; and
    • why the corrected brief removed quotation marks but kept flawed legal propositions.

    For the firm, the court wants:

    • written GenAI policies, guidelines, and restrictions that were in effect at the time;
    • how those policies were communicated to the lawyers and staff involved;
    • what internal safeguards or training the firm has implemented or plans to implement; and
    • any claimed exceptional circumstances for avoiding joint responsibility.

    That is close to a court-issued AI governance checklist.

    What This Means For Firms Using AI

    The Delaware order does not hold that AI use in drafting is forbidden. In fact, Vice Chancellor Will repeated the now-familiar point that using GenAI in legal work is not inherently problematic if the output is carefully verified.

    The problem is that verification cannot be vague, delegated away, or assumed.

    If a court asks how an AI-assisted brief was produced, a firm should be ready to show more than a policy memo. It should be able to explain the actual workflow:

    • which tools were approved;
    • what legal and factual checks were required before filing;
    • whether the signing lawyer personally reviewed the sources;
    • how staff cite-checking fit into the process; and
    • what happens when an error is found after filing.

    That is where a lot of firms are still thinner than they think.

    Why This Is A Good Follow-On To The Recent Cases

    Clearon has already covered opinions focusing on false quotations, fabricated authorities, and verification failures in appellate and trial-court filings.

    The Delaware order adds a different layer. It is not just asking whether the brief was wrong. It is asking how the law firm's internal AI controls worked, and whether they worked at all.

    That makes it a strong Courts and AI story. It sits at the intersection of court sanctions doctrine, supervisory responsibility, and practical AI governance inside firms.

    Bottom Line

    The Delaware Court of Chancery has not imposed final sanctions in Leiske yet. But the July 1 show-cause order already says a lot.

    It says GenAI mistakes in a filed brief can become a Rule 11 problem. It says deleting quotation marks without fixing the legal proposition is not a real correction. And it says firms should expect courts to ask about policies, training, verification, and supervision when AI-assisted work goes wrong.

    That is the part worth watching.

    Sources

  • AI Privilege Risk Is Becoming a Workflow Problem, Not Just a Confidentiality Warning

    AI Privilege Risk Is Becoming a Workflow Problem, Not Just a Confidentiality Warning

    For a while, the standard legal-AI warning sounded simple:

    Do not put privileged or confidential information into public AI tools.

    That warning is still right. It is also no longer enough.

    Recent federal decisions suggest that AI privilege and work-product issues are turning into workflow questions. Courts are not just asking whether AI was used. They are asking what tool was used, who used it, under whose direction, on what material, with what confidentiality protections, and whether discovery or protective-order obligations changed the analysis.

    That is a much more operational problem than a generic confidentiality lecture.

    The Short Answer

    • AI does not create one uniform privilege or work-product rule.
    • Courts are splitting at least three separate questions: whether confidentiality was lost, whether work-product protection survived, and whether a protective order independently restricted the upload.
    • The practical risk is shifting from abstract “AI waiver” language to concrete questions about tool choice, confidentiality, discovery material, and who approved the use.

    The Cases Are Not Moving In One Direction

    The early federal decisions do not create one simple rule.

    In United States v. Heppner, the Southern District of New York rejected privilege and work-product claims tied to a criminal defendant's use of a consumer AI tool outside counsel's direction.

    In Warner v. Gilbarco Inc., the Eastern District of Michigan treated a pro se civil plaintiff's AI-related materials as protected work product and rejected the idea that AI use automatically destroyed the protection.

    In Morgan v. V2X Inc., the District of Colorado reportedly protected AI-assisted work product but still required disclosure of the AI tool identity and amended the protective order around AI use.

    In Jeffries v. Harcros Chemicals Inc., the District of Kansas approved protective-order restrictions on open AI tools for discovery materials based on retention, training, deletion, privacy, security, and clawback concerns.

    That is the pattern to focus on. The cases are not asking whether AI is good or bad. They are sorting AI use into different legal buckets based on workflow facts.

    That split is the point. A team can lose on confidentiality and privilege, still argue about work product, and separately face protective-order limits on what can be uploaded. It can preserve work-product protection and still be ordered to identify the tool or comply with AI-specific restrictions on discovery material. Treating all of that as one generic waiver question hides the real problem.

    The New Question Is “What Exactly Happened?”

    When AI becomes part of litigation work, the risk analysis turns on details such as:

    • Was the tool public, consumer-facing, or enterprise?
    • Did the platform reserve rights to retain, review, or train on the material?
    • Was the use directed by counsel?
    • Was the material privileged, attorney work product, or discovery produced under a protective order?
    • Did the user expose legal theories or mental impressions?
    • Is the identity of the tool itself discoverable?
    • Did a protective order prohibit or restrict uploads?

    Those are workflow questions. A legal department or law firm cannot answer them well if its internal policy is just “use AI carefully.”

    Privilege, Work Product, And Protective Orders Are Separate Questions

    Another reason the workflow framing matters is that privilege, work product, and protective-order restrictions are not the same issue.

    Attorney-client privilege turns heavily on confidentiality and protected communications made for the purpose of obtaining or providing legal advice. Work product turns on anticipation of litigation, mental impressions, and whether the disclosure was made in a way that substantially increases the likelihood the material will reach an adversary.

    Protective-order restrictions can cut across both. A court may not need to decide that privilege was waived or work product was destroyed before it limits the use of public or open AI tools on produced material.

    That means an AI workflow can create different results across the three lanes. One use pattern may be disastrous for privilege because it undermines confidentiality, while still leaving room for work-product arguments in some civil settings. Another use pattern may preserve internal confidentiality but run straight into a protective-order problem if discovery material was uploaded into a tool that the order does not permit.

    The practical lesson is that “AI waiver” is often the wrong level of abstraction. Teams need to ask which doctrine or restriction is at issue and how the actual workflow maps onto it.

    Protective Orders May Become The Fastest Constraint

    The protective-order cases may be the most immediately important for everyday litigation.

    Even when courts do not say AI use destroys privilege or work product automatically, they may still restrict what can be uploaded into public or open AI tools. That is especially true for discovery material, confidential business information, and materials produced subject to Rule 26(c) orders.

    That makes protective orders one of the fastest ways AI use gets limited in practice.

    Counsel may find that the immediate issue is not abstract doctrine, but whether the governing order:

    • bans public AI tools entirely;
    • bans AI uploads for confidential materials only;
    • permits only closed enterprise tools;
    • requires notice or agreement before AI use;
    • distinguishes between model providers and internal review tools; or
    • treats tool identity as discoverable information in later disputes.

    In many matters, the protective order will be the first real AI policy that matters.

    The Real Failure Mode Is Operational Drift

    Most teams do not deliberately decide to waive privilege.

    The more common failure mode is operational drift.

    Someone uses a familiar public tool to summarize notes. A client pastes in sensitive facts without realizing the downstream implications. A pro se litigant relies on a chatbot to organize case strategy. A discovery team uses AI summarization before anyone asks whether the protective order permits it. Outside counsel and client assume the other side checked the tool terms.

    Each step looks small on its own. Together, they can create a record that is hard to defend later.

    That is why the problem is now better understood as workflow design. If the workflow does not force the right questions early, the doctrine gets tested later under bad facts.

    What A Better AI Litigation Workflow Looks Like

    A usable workflow should answer at least five questions before AI gets used in a matter:

    1. What kind of material is involved? Privileged communications, counsel work product, confidential discovery, trade secrets, personal data, and public material should not all be treated the same way.

    2. What kind of tool is being used? Consumer/public AI, enterprise AI, vendor-hosted tools, internal models, and matter-specific review tools carry different risk profiles.

    3. What do the tool terms say? Retention, training, deletion, human review, security, auditability, and downstream sharing matter.

    4. What do the court orders and client instructions say? Protective orders, outside-counsel guidelines, engagement terms, and client policies may impose stricter limits than the general law.

    5. Who owns the decision? Someone needs to decide whether a particular AI use is allowed, defensible, and documented.

    Without those checkpoints, telling people to "use AI carefully" is not much of a governance system.

    What Firms And Legal Departments Should Do Now

    Legal teams should consider:

    • separating rules for public AI, enterprise AI, and discovery-review tools;
    • prohibiting public-tool use for privileged, confidential, or discovery-protected material unless expressly approved;
    • building matter-opening questions around AI use, tool type, and protective-order restrictions;
    • reviewing outside-counsel guidelines and client instructions for AI-specific terms;
    • preserving enough workflow information to answer later questions about what tool was used and why;
    • training lawyers and staff on the difference between privilege, work product, and protective-order risk; and
    • updating protective-order negotiation positions to address open versus closed AI tools explicitly.

    This is one of those areas where governance that sounds boring is actually what keeps the problem from becoming urgent later.

    Bottom Line

    AI privilege risk is no longer just a warning about confidentiality.

    It is becoming a workflow problem shaped by tool choice, user role, litigation posture, protective-order language, and the facts of how the system was used.

    The early cases do not say “AI always waives protection.” They say something harder and more useful: the legal result depends on what actually happened.

    That means firms and legal departments need workflows that can answer those questions before a court does.

    Sources

  • Sixth Circuit Removes Appointed Counsel After AI-Generated False Quotations

    Sixth Circuit Removes Appointed Counsel After AI-Generated False Quotations

    The Sixth Circuit's decision in United States v. Farris is a narrow appellate sanctions opinion with a broad lesson: a trusted legal AI product is not a substitute for lawyer verification.

    The court did not decide the merits of the defendant's criminal appeal. Instead, it addressed appointed counsel's briefs. Counsel admitted using Westlaw CoCounsel to prepare the briefs and failing to adequately review and verify the AI-generated content before filing.

    The resulting errors were not limited to imaginary cases. The briefs cited real authorities but attributed quotations and legal propositions to them that the authorities did not contain.

    That is the part to underline. A real citation can still be a false authority.

    How The Court Spotted The Problem

    The Sixth Circuit said its initial concern began with the file name of the principal brief: "CoCounsel Skill Results." CoCounsel is Westlaw's AI platform.

    The court then found three problematic citations. The cited authorities existed, but the quoted language did not appear in them. The briefs also misrepresented the holdings of United States v. Washington and United States v. Anthony.

    After issuing a show-cause order, the court required counsel to provide copies of cited authorities and explain who wrote the briefs, whether generative AI was used, how the briefs were cite-checked, and whether AI was used in district court filings.

    Counsel responded that staff uploaded district court documents to Westlaw CoCounsel to create a first draft, that counsel supplemented the draft, and that the same process was used for the reply. Counsel admitted the false quotations were AI-generated, accepted responsibility, and said he had not previously been disciplined.

    What The Court Did

    The Sixth Circuit imposed several consequences.

    It ordered that counsel not be compensated under the Criminal Justice Act for time spent on the appeal. It directed the clerk to forward the opinion to the Chief Judge of the Sixth Circuit for possible disciplinary proceedings. It also directed service on district court and Kentucky Bar authorities.

    By separate order, the court removed counsel from further representation, ordered appointment of replacement counsel, locked the filed briefs, and reset the briefing schedule.

    The delay to the defendant's criminal appeal mattered to the court. So did the fact that the lawyer was serving through a publicly funded appointment.

    The Legal AI Product Point

    The court's opinion is careful not to treat AI as categorically forbidden. It recognizes that new technologies can bring significant promise to legal work.

    But the court also says lawyers must understand how technology can be misused or contribute to inaccuracies. That remains true even when the tool is sponsored by a trusted legal technology provider.

    For law firms and legal departments, that is the operational takeaway: vendor reputation is not a verification protocol.

    What Appellate Teams Should Change

    Appellate teams using AI should build a source-checking process that covers more than whether the case exists.

    At minimum, the process should verify:

    • every cited authority exists;
    • every direct quotation appears in the cited source;
    • every parenthetical and proposition accurately reflects the source;
    • the cited case's outcome is correctly described;
    • the procedural posture is relevant to the argument;
    • the record citations are checked against the record; and
    • the signing lawyer understands how the AI-assisted draft was created.

    The last point matters because counsel in Farris relied on staff to upload materials and generate the first draft. The court treated verification as the attorney's responsibility, not a staff function.

    Bottom Line

    Farris is not just another hallucinated-citation case. It is a false-quotation and mischaracterized-authority case involving a mainstream legal AI product.

    That makes it a more practical warning. The question before filing is not whether the AI invented a case. It is whether a lawyer read the source and confirmed that it says what the brief says it says.

    Sources

  • Michigan Court of Appeals Turns AI-Fabrication Into Published Appellate Sanctions Law

    Michigan Court of Appeals Turns AI-Fabrication Into Published Appellate Sanctions Law

    Michigan now has a published appellate opinion on AI-generated fabricated and unsupported legal authority.

    In Barber v. Morawa, the Michigan Court of Appeals affirmed the denial of a motion for a new trial or evidentiary hearing in a medical-malpractice case. The merits were not the real story. The court separately sanctioned plaintiff's counsel for repeatedly submitting fabricated and unsupported authority that counsel attributed to over-reliance on artificial intelligence.

    The opinion matters because it moves the issue from a general warning to a Michigan-specific appellate holding. Counsel's repeated submission of fabricated and unsupported authority violated MCR 7.216(C)(1) and MCR 1.109(E)(5). The case was remanded for a determination of actual damages and reasonable attorney fees incurred because of the appeal, payable personally by counsel. The court also directed its clerk to forward the opinion to the Attorney Grievance Commission for possible investigation.

    What Went Wrong

    The underlying case involved alleged juror misconduct after a civil medical-malpractice trial. The plaintiff sought a new trial or evidentiary hearing, but the allegations depended on facts outside the record and were not supported by valid affidavits.

    The court resolved that merits issue without much difficulty. The harder issue was counsel's briefing.

    The court said counsel cited fabricated authority in a motion for a protective order, then cited fabricated authority again in a motion for a new trial or evidentiary hearing. Defendant identified the problem and requested sanctions.

    The pattern continued on appeal. Counsel cited a nonexistent Michigan case and repeatedly cited real authorities for propositions they did not support. After defendant identified the defects in the appellee brief, counsel filed a reply without acknowledging the fabricated case or correcting the unsupported assertions.

    Months later, counsel filed a "Notice of Correction." That notice accepted responsibility and attributed the citation errors to over-reliance on AI research tools. But it still did not solve the problem. The court said the notice, also prepared with AI assistance, attributed quotations and legal propositions to cases that did not contain them.

    Why The Published Opinion Matters

    The court did not create an AI-specific exception. It did not create an AI safe harbor either.

    Instead, it applied existing Michigan rules. Under MCR 1.109(E)(5), a lawyer's signature certifies that the lawyer has read the document and that, after reasonable inquiry, it is well grounded in fact and warranted by existing law. The reasonableness standard is objective. Good faith is not enough.

    The court also relied on MCR 7.216(C)(1), which allows sanctions when an appeal or appellate proceeding is vexatious because a brief grossly disregards the requirements of fair presentation, violates court rules, or is grossly lacking in propriety.

    The holding is direct: submitting fabricated and unsupported authority through over-reliance on AI violates the duty of reasonable inquiry.

    That matters for Michigan practitioners because the opinion translates national AI-sanctions principles into Michigan appellate procedure.

    The Correction Filing Lesson

    The most practical part of Barber may be the failed correction filing.

    Once opposing counsel or a court identifies fabricated authority, the next filing should not be treated as ordinary cleanup. It should be treated as a controlled remediation event.

    That means:

    • stop using the same unverified AI workflow that created the problem;
    • identify every disputed citation, quotation, and proposition;
    • review original sources directly;
    • state exactly what was wrong and what is being corrected;
    • avoid substituting new authority unless it has been read and verified; and
    • have a lawyer with responsibility for the filing own the correction.

    In Barber, the correction filing became evidence that the verification problem had not been fixed.

    What Michigan Lawyers Should Do Now

    Michigan litigators should assume that AI-assisted briefing is subject to the same reasonable-inquiry requirement as any other filing.

    Before filing, counsel should verify not only that a case exists, but also that:

    • the quoted language appears in the case;
    • the case actually supports the proposition asserted;
    • the procedural posture is accurately described;
    • the cited rule or statute is current;
    • factual assertions and record references match the record; and
    • criminal cases are not being used to import inapplicable constitutional standards into civil proceedings.

    Law firms should also decide who is responsible for verification. Delegating a first draft to AI, staff, or a junior team member does not delegate the signing lawyer's duty.

    Bottom Line

    Barber v. Morawa is not a ban on AI in Michigan litigation. It is a published reminder that AI does not lower the standard for signed filings.

    For Michigan lawyers, the rule is straightforward: read the authorities, verify the quotations, and do not file a correction until the correction has itself been checked.

    Sources

  • AI Sanctions Are Moving Beyond Fake Cases

    AI Sanctions Are Moving Beyond Fake Cases

    The first wave of AI sanctions cases had an easy headline: fake cases.

    That problem has not gone away. But the next wave is broader and harder to catch. Courts are now calling out false quotations, inaccurate descriptions of real cases, unsupported legal propositions, fabricated record references, and correction filings that repeat the same verification failure they were supposed to fix.

    That shift matters because a fake case name is often easy to spot. A real case with a fake quotation is more dangerous. It can survive a quick citation check, especially if the lawyer confirms that the case exists but never reads what it actually says.

    Recent decisions from the Sixth Circuit and Michigan Court of Appeals, plus a new Oregon Court of Appeals notice, point in the same direction: legal teams need source-level verification, not just citation-level verification.

    Farris: Real Cases, False Quotations

    In United States v. Farris, the Sixth Circuit did not decide the merits of the criminal appeal. It stopped to address the conduct of appointed appellate counsel.

    The court said counsel admitted using Westlaw CoCounsel to draft the briefs and then filing them without properly verifying the legal authorities. The problem was not simply that the briefs cited nonexistent law. The briefs cited genuine authorities but attributed quotations and propositions to them that did not appear in the sources.

    One example involved the Sentencing Guidelines commentary. Other examples involved Sixth Circuit cases that were described as reversing role enhancements when they did not support the propositions asserted. The court said the briefs misrepresented the holdings of United States v. Washington and United States v. Anthony.

    The Sixth Circuit drew a line that every litigation team should build into its review process: citing a real case does not make an AI-assisted brief safe if the quotation is fabricated or the holding is misdescribed.

    The consequences were serious. The court ordered that counsel not be compensated under the Criminal Justice Act for the appeal, forwarded the opinion for possible disciplinary proceedings, served the opinion on district court and Kentucky Bar authorities, and separately removed counsel from further representation. Replacement counsel would be appointed and the briefing schedule reset.

    The court also made an important vendor-neutral point. Lawyers cannot assume that a legal AI product is reliable merely because it comes from an established legal technology provider.

    Barber: The Correction Filing Was Also Wrong

    The Michigan Court of Appeals reached a similar point in Barber v. Morawa, a published medical-malpractice appeal.

    The merits issue was straightforward: the court affirmed denial of a motion for a new trial or evidentiary hearing. The sanctions issue was not. Plaintiff's counsel had cited nonexistent cases in the trial court, relied on criminal authorities in a civil case, and then filed an appellate brief that cited another nonexistent case and used real authorities for propositions they did not support.

    After the defendant identified the defects, counsel eventually filed a "Notice of Correction." But that notice, which counsel acknowledged was also prepared with AI assistance, repeated the problem by attributing quotations and legal propositions to cases that did not contain them.

    The Michigan court held that counsel's repeated submission of fabricated and unsupported authority violated MCR 7.216(C)(1) and MCR 1.109(E)(5). It remanded for a determination of actual damages and reasonable attorney fees incurred because of the appeal, payable personally by counsel, and directed the clerk to forward the opinion to the Attorney Grievance Commission.

    That is the deeper lesson of Barber: a correction cannot be just another AI-assisted filing. Once a court or opposing party flags possible fabricated authority, the next filing should be treated as a high-risk verification event.

    Oregon Turns The Warning Into A Court Notice

    The Oregon Court of Appeals has now posted a notice specifically warning about fabricated authority produced by AI.

    The notice says the court has received an increasing number of filings containing fabricated authorities, including citations that do not exist, quotations that do not appear in the cited authority, propositions of law not reasonably related to the citation, and factual support with no basis in the record.

    The listed consequences include striking the filing, monetary sanctions payable to the court, attorney-fee awards payable to the opposing party, and dismissal of the appeal.

    The notice also gives a practical verification rule. Anyone using generative AI to prepare court-filing content must verify that all cited cases exist, that all quotations actually appear in the cited cases, and that all paraphrased propositions of law are objectively reasonable in light of what the case actually says.

    That is a useful checklist because it is not limited to fake case names. It reaches the subtler errors that are becoming common in appellate sanctions orders.

    The Pattern Is Broader Than One Tool Or One Court

    These developments fit the recent sanctions record.

    In Lnu v. Blanche, the Ninth Circuit sanctioned lawyers for briefs containing nonexistent cases, misattributed quotations, and gross misrepresentations of real authority. The court emphasized that the discipline became more serious because of the lawyers' responses after the errors came to light.

    In Withers v. City of Aberdeen, a Mississippi federal court sanctioned and removed all counsel after filings from both sides contained AI-generated fabricated authority. The order is a sharp warning for local counsel and sponsoring counsel: signing and sponsoring are not administrative formalities.

    In State v. Coleman, an Ohio appellate court sanctioned counsel after a filing contained ChatGPT-generated fabricated transcript quotations prepared by a paralegal. The AI problem there was not fake caselaw. It was a fake record.

    Together, the cases show the sanctions framework maturing. Courts are no longer asking only whether a case exists. They are asking whether the filing honestly represents law and fact.

    What Litigation Teams Should Change

    The review process should be built around propositions, not just citations.

    Before filing AI-assisted work, litigation teams should verify:

    • every cited case, statute, rule, and record reference exists;
    • every direct quotation appears in the cited source;
    • every parenthetical accurately describes the source;
    • every paraphrased proposition is fairly supported by the authority;
    • every record quotation or factual assertion matches the underlying record;
    • the lawyer signing the filing has personally satisfied the required level of review; and
    • any correction filing receives independent source review before submission.

    It is not enough to ask whether the tool hallucinated a case. A real case can be turned into a false authority if the quotation, holding, or procedural posture is wrong.

    Bottom Line

    The AI sanctions story is moving from fake cases to false authority.

    That is a harder problem and a more practical one. Lawyers have always had to verify the law and the record before filing. AI makes that duty more visible, not less binding.

    The practical rule is simple: if a filing relies on a source, someone must read the source.

    Sources

  • AI Court Rules Are Becoming Verification Rules

    AI Court Rules Are Becoming Verification Rules

    The next phase of legal AI regulation looks less like a blanket ban and more like a verification record.

    Florida now requires filers to stand behind the existence and accuracy of cited legal authorities. New York now allows AI-assisted court papers without a statewide disclosure requirement, but requires independent verification. The Ninth Circuit just sanctioned lawyers for AI hallucinations and lack of candor. A Mississippi federal judge just removed all four lawyers from a case after both sides filed AI-tainted briefs.

    Different courts. Same message: the tool is not the issue. The filing is.

    The New Rule: Verify First

    Florida's amended Rule 2.515(d)(2), effective June 15, 2026, says that by filing a document, the signer represents that "the legal authorities identified exist and are accurately cited." If that representation is false, sanctions can include reprimand, contempt, striking the filing, dismissal, costs, attorneys' fees, or other relief.

    That is deliberately broader than AI. A lawyer cannot escape the rule by saying a fake case came from a chatbot, a legal research product, an associate, local counsel, a vendor, or a recycled brief.

    New York's Part 161, effective June 1, takes a different route but lands in the same place. It permits AI use in court submissions and does not impose a statewide disclosure mandate. But users must understand the technology's limits and independently ensure that filings do not contain fabricated or fictitious cases, statutes, or other material.

    So the emerging split is not "AI allowed" versus "AI banned." It is disclosure versus no disclosure, with verification underneath both.

    The Sanctions Cases Are Getting Less Patient

    In Lnu v. Blanche, the Ninth Circuit sanctioned two lawyers after filings contained nonexistent cases, misattributed quotations, and serious misreadings of real cases. The court stressed that it was not punishing AI use by itself. It was punishing false filings and the lawyers' later lack of candor.

    That distinction matters. A bad citation is a serious problem. A bad explanation can become the larger one.

    The Mississippi sanctions order in Withers v. City of Aberdeen is even more vivid. The case started as a fee dispute brought by Louisiana lawyer Tom Withers III against Aberdeen, Mississippi. After transfer to the Northern District of Mississippi, the court found hallucinated authorities in filings from both sides.

    The plaintiff side included Louisiana pro hac vice counsel Kathleen M. Wilson and Mississippi local counsel Shauncey Hunter Ridgeway. The defense side included Texas pro hac vice counsel Kathryn Y. Williams and Mississippi local counsel Mark C. McClinton. The court removed all four lawyers from the case, revoked both pro hac vice admissions, barred the two out-of-state lawyers from appearing in the district for two years, imposed monetary sanctions, and referred the order to disciplinary authorities.

    The local-counsel lesson is hard to miss: signing is not clerical. Sponsoring is not ceremonial. If your name is on the filing, the verification problem is yours too.

    California May Be Next

    California is also moving from guidance toward rules. The State Bar has opened public comment on proposed amendments to the Rules of Professional Conduct related to AI, after the California Supreme Court asked it to consider incorporating generative-AI guidance and addressing agentic AI tools.

    That is not a court-filing rule like Florida's or New York's. But it shows the same maturation curve. Soft guidance is starting to harden.

    What To Do Before The Next Filing

    Litigation teams should assume courts will ask a simple question: who checked this?

    • Check the courtwide rule, local rule, judge's standing order, and part rules before filing.
    • Identify whether AI touched research, drafting, editing, factual summaries, record citations, or proposed orders.
    • Verify every cited authority in an authoritative source.
    • Read the authority, not just the citation.
    • Confirm quotations, parentheticals, holdings, procedural posture, and subsequent history.
    • Trace facts and record cites back to the record.
    • Make signing, local, and sponsoring counsel confirm the verification process.
    • If an error is found, correct it quickly and candidly.

    The hardest AI errors are not always fake case names. Sometimes they are real cases used for propositions they do not support. A citation check is not enough; the proposition has to survive too.

    Bottom Line

    Courts are not focused on whether AI helped with the first draft. They want to know whether a lawyer verified the final filing.

    The practical rule is now simple: use the tool if the forum, client, confidentiality obligations, and governing orders allow it. But before anything is filed, someone qualified must verify the authorities, quotations, facts, and record references. And someone with a signature block must be ready to say so.

    For a broader inventory of court rules, sanctions orders, privilege decisions, protective-order restrictions, and tribunal guidance, see Clearon's AI Litigation Practice Tracker.

    Sources

    Sources

  • AI-Assisted Legal Filing Verification Checklist

    AI-Assisted Legal Filing Verification Checklist

    Generative AI can accelerate legal work, but it does not change who is responsible for a court filing. Use this checklist before filing any paper that may contain AI-assisted research, drafting, revision, or analysis.

    It is a practical starting point, not a substitute for the requirements applicable to a particular matter.

    Quick Rule

    Do not file an AI-assisted document until a qualified human has independently verified every legal authority, quotation, factual assertion, record citation, and representation about the proceeding against an authoritative source.

    If any item cannot be checked, stop and resolve it before filing.

    1. Confirm Permitted Use

    • [ ] Identify the AI tools used and the portions of the filing they may have affected.
    • [ ] Confirm the use complies with client instructions, protective orders, confidentiality duties, firm policy, and applicable law.
    • [ ] Check local rules, standing orders, judge-specific practices, and filing instructions for AI restrictions or disclosure requirements.
    • [ ] Confirm no protected information was entered into an unapproved system.

    2. Verify Authorities and Quotations

    • [ ] Open and read every cited authority in an authoritative source.
    • [ ] Confirm each citation identifies the correct authority and current version.
    • [ ] Confirm that each authority supports the precise proposition for which it is cited.
    • [ ] Check precedential status, subsequent history, negative treatment, and applicable citation limits.
    • [ ] Compare every quotation and pinpoint citation against the original source and surrounding context.
    • [ ] Confirm parentheticals, paraphrases, and descriptions accurately characterize the source.

    3. Verify Facts and the Record

    • [ ] Trace every material factual assertion to the record or another permissible source.
    • [ ] Open and verify every record citation, exhibit reference, transcript page, docket entry, and date.
    • [ ] Check names, entities, amounts, calculations, timelines, tables, and summaries.
    • [ ] Distinguish allegations, evidence, findings, holdings, inferences, and argument.

    4. Review and Approve the Final Filing

    • [ ] Have a qualified human independently review the final version.
    • [ ] Check the requested relief, legal standard, jurisdiction, deadlines, service representations, and procedural history.
    • [ ] Check for placeholders, invented citations, inconsistent names, unsupported cross-references, and omitted controlling authority.
    • [ ] Verify appendices, exhibits, certificates, signature blocks, and proposed orders.
    • [ ] Complete any required AI-use disclosures or certifications.
    • [ ] Obtain informed approval from the signing lawyer and responsible supervising, local, or sponsoring counsel.

    Ready to File

    • [ ] Every authority, quotation, fact, and record citation has been independently verified.
    • [ ] The final version has not changed since verification.
    • [ ] Applicable AI rules, client restrictions, and disclosure duties have been satisfied.
    • [ ] The signing lawyer can accurately explain how the filing was prepared and checked.
    • [ ] The team preserved a concise record of who reviewed what and when.

    If an Error Is Discovered After Filing

    • [ ] Stop using the affected material and notify responsible lawyers immediately.
    • [ ] Independently determine the error's full scope and preserve relevant records.
    • [ ] Assess duties to the client, court, opposing counsel, insurer, firm, and disciplinary authorities.
    • [ ] Correct material errors promptly and candidly using the required procedure.
    • [ ] Review other filings or matters that may have used the same workflow.

    Candor after discovery can materially affect the court's response. Recent sanctions orders show that concealment, blame shifting, and repeated inaccuracies can be more damaging than the original mistake.

    Bottom Line

    AI assistance does not reduce the duty of inquiry attached to a court filing. Independent verification, meaningful supervision, signer approval, and prompt candor are still the core requirements.

    For examples of how courts are applying those principles, see Oregon Supreme Court's First AI Hallucination Sanctions Show What Courts Punish Most and Clearon's AI Litigation Practice Tracker.

    Sources

    Sources