Skip to content
ServicesSpeaking & CLEInsightsAbout Book a call

Iowa Never Wrote an AI Rule for Lawyers. It Still Reprimanded One.

A cave diver deep inside a flooded cavern, one gloved hand on a thin guideline running off into the dark while a flashlight beam pushes into the passage ahead. The line and the light are what make the dark navigable.

TL;DR: 69% of legal professionals now use general-purpose AI for work, more than double a year ago, while over 1,300 US court decisions already involve AI-fabricated material and malpractice insurers are seeing the first wave of AI-related claims. I spent the past week coding every state’s official AI guidance, and I came away with one conviction. Bar guidance isn’t bureaucratic noise. It’s the only thing standing between a duty you already have and a sanctions order with your name on it.

Four summary statistics. States with official guidance: 40 of 50, with 10 having nothing and 4 of the 40 governing only the court system. Explicit duty to verify AI output: 34 states, the closest thing to a national consensus. States departing from ABA Opinion 512: 0, with 14 adopting or citing it and the rest simply not engaging. Require telling the client: 2, Georgia and Pennsylvania, with 26 more saying it depends and 9 states expressly rejecting court disclosure.

There’s a lawyer I keep picturing. She’s good at her job, busy, and somewhere around last spring she started pasting things into ChatGPT. A demand letter here, a research question there. She’s careful about it. She’s also never told a soul at her firm, because she has no idea whether she’s allowed to be doing this.

If that’s you, or half your firm, you’re in the majority. 8am’s 2026 Legal Industry Report, which surveyed more than 1,300 legal professionals last fall, found 69% now use general-purpose AI tools for work, up from 31% a year earlier. Adoption more than doubled in twelve months. I can’t think of another tool in law practice that spread that fast. Email didn’t. E-filing certainly didn’t.

And most of it is happening exactly like my imaginary lawyer: quietly, without rules, in the dark. The same survey found fewer than half of firms train their people on responsible use.

The question nobody can answer alone

I just finished a research project I’d wanted to do for months: I pulled the official AI guidance from all 50 states, every ethics opinion, court rule, and adopted policy I could verify against primary sources, and coded each state on the three questions lawyers actually ask. Can client information go into the tool? Do I have to tell anyone? What do I have to check before I file?

Here’s the thing that struck me while reading opinion after opinion. Your professional rules already answer these questions. Competence, confidentiality, candor. Those duties attached to AI the moment you opened a browser tab. What they don’t do is tell you where the lines sit. Rule 1.6 was written for a world of file cabinets and fax machines. Whether “reasonable efforts” lets you use a consumer chatbot on a client matter is a judgment call, and the person who makes it, if your bar hasn’t, is a disciplinary board reading your file after something went wrong.

That’s what bar guidance is. Not permission. Notice. It tells you which judgment calls your regulator has already made, before you bet your license on guessing.

What happens where guidance is missing

The states that stayed silent didn’t stay safe. They just moved the rulemaking into the enforcement phase.

Iowa is my favorite example because it’s so clean. Iowa has never issued a word of AI guidance for attorneys. In May 2026, Iowa’s disciplinary board publicly reprimanded a lawyer anyway, for filing AI-fabricated citations. Utah has no ethics opinion on AI either; its court of appeals sanctioned lawyers last year and made clear that the duty to review and verify a filing stays with the attorney who signs it. The rules got made in both states. They were just announced through individual lawyers’ disciplinary records instead of through guidance everyone could read first.

And the volume behind those anecdotes is bigger than most attorneys realize. The standard tracker of these incidents, a database maintained by researcher Damien Charlotin, counts more than 1,900 court decisions worldwide involving AI-fabricated material, over 1,300 of them in US courts, as of August 19, 2026. When I checked, the newest entry was a day old. The penalties are climbing. The famous 2023 case that started all this ended in a $5,000 fine. By 2026 courts were handing out $15,000 per attorney and, in a few cases, suspensions.

One detail from that database stuck with me. Most hallucination cases involve people representing themselves, and courts are pretty forgiving with them. The lawyer cases are fewer, and those are the ones that end in fines, referrals, and suspensions. Judges tend to extend grace to laypeople. They extend far less to the licensed professional who certified the filing.

Your insurer got here before you did

One development I’d flag for any managing partner. In EPIC’s annual survey of lawyers’ professional liability insurers, seven of thirteen carriers reported an increase in AI-related claims this year. Underwriters have been asking firms AI questions for several years now; what changed in 2026 is that the claims finally showed up. And what carriers want, in the words of the broker who runs that survey, is evidence that firms understand the risks and are taking meaningful steps.

Think about what the cheapest credible evidence of “meaningful steps” looks like for a five-lawyer firm. It’s not a custom AI governance program. It’s a one-page policy that says: we follow our state bar’s guidance, here’s how. The bar opinion you haven’t read is sitting there waiting to become your insurance documentation.

There’s an upside case too, and I don’t want to bury it. Clio’s 2025 Legal Trends Report found firms with wide AI adoption were nearly three times more likely to report revenue growth. More than half of consumers have now used or would consider AI for a legal question, and among those who did, 28% got told by the chatbot to go hire a lawyer. Your clients are arriving pre-loaded with AI expectations. Guidance is what lets you meet them without flinching.

What the guidance says, in one breath

Forty states have now adopted something official, counting only real instruments: ethics opinions, court rules and orders, and guidance a bar or court actually adopted, not staff articles in bar magazines or unadopted committee drafts. Only 36 of the forty speak to attorneys directly.

A grid map of the 50 states titled Who regulates, and how firmly, shaded by the form each state's AI guidance takes. No guidance found: 10 states, being Maine, Idaho, Montana, Wisconsin, Nevada, Wyoming, South Dakota, Nebraska, Kansas and Tennessee. Task force or interim guidance: 9. Formal ethics opinion: 10. Court rule or order: 11. Multiple forms: 10. Iowa, Utah, Delaware and South Carolina are starred as having instruments that govern only the court system rather than attorneys.

Read them all and a playbook emerges that you could teach in an afternoon. Verify everything AI produces before you rely on it; 34 states say so explicitly and none says otherwise.

A grid map of the 50 states titled The verification duty, state by state, answering whether a lawyer must independently verify AI output before relying on it or filing it. Explicit duty to verify: 34 states. Implied duty: 4, being Iowa, Colorado, Arkansas and South Carolina. Guidance silent on the question: 2, Utah and Delaware. No guidance at all: 10.

Vet the tool before client data goes in, and in a handful of states (Georgia, Missouri, New Hampshire) get informed client consent first.

A grid map of the 50 states titled The confidentiality fault line, showing what each state requires before confidential client information touches an AI tool. Informed consent required: 3, being New Hampshire, Missouri and Georgia. Consent sometimes required: 16. Reasonable safeguards: 11. Guidance silent on the question: 10. No guidance at all: 10.

And the part that surprised me most? You mostly don’t have to confess. Nine states have expressly rejected mandatory disclosure of AI use to courts, New York loudest among them. The regulators mostly landed on treating AI like any other tool. You own the output. The tool itself is beside the point in most states.

Four stacked bar charts titled Where 50 states land on each question, with darker shading meaning stricter. Q1, confidentiality, what must happen before client data goes in: 3 states require consent, 16 sometimes require it, 11 require reasonable safeguards, 10 are silent, 10 have no guidance. Q2a, must the lawyer tell the client: 2 required, 26 situational, 12 silent, 10 no guidance. Q2b, must the lawyer tell the court: 14 situational, 9 expressly not required, 17 silent, 10 no guidance. Q3, duty to verify AI output: 34 explicit, 4 implied, 2 silent, 10 no guidance.

The catch is which playbook applies to you depends on your state, and the differences are real. The same associate doing the same work is compliant in Richmond and exposed in Atlanta. Which is exactly why the generic advice circulating on LinkedIn isn’t enough. You need your state’s answer.

The honest caveats

Most of this guidance is advisory, not binding law, and a skeptic could wave it off on those grounds. I’d push back: advisory guidance is precisely what your disciplinary board will cite when a complaint lands, and what a plaintiff’s expert will cite in a malpractice case. Ignoring it because it isn’t a statute is a bet I wouldn’t make with my license.

The other caveat is speed. Fifteen states’ current guidance was issued or revised in the first eight months of 2026 alone. Whatever you read on this topic, including this piece, check the date on it.

What to do Monday morning

  1. Find your state’s guidance and read the document itself, not a summary. Many run just a few pages. If your state is one of the ten with nothing, read ABA Formal Opinion 512; it’s the national baseline the state opinions themselves build on.

  2. Write the one-page firm policy: which tools are approved, what never goes into them, who verifies output before filing. Anchor every line to your bar’s guidance so it doubles as your answer when the insurance renewal asks.

  3. Tell your clients how you use AI, in the engagement letter. Two states require it, half the country says it depends, and every client relationship survives transparency better than surprise.

The lawyer I described at the top isn’t reckless. She’s just working without notice of the rules, in a profession that punishes exactly that. In 40 states, the bar or the court has done something quietly valuable. It wrote the rules down before the sanctions hearing. The flashlight exists.

Pick it up.


Note to the reader: a ton of research went into this and I’m sure I made a mistake or two (or more!). Any mistakes are mine. I did use AI to try and cross-check all of the data but at the end - it’s my output and I “own” it ;)

I hope you found this useful. If you did, please share it with others!

Share Intelligence by Intent

Last, here’s a shot of Magnus hanging out in the shade next to me while I enjoy a nice soak in the jacuzzi.

Magnus lying on a shaded flagstone patio beside a tall hedge, front paws hanging over the edge of the step and tongue out in the heat.

All insights Subscribe on Substack

Let's talk

Ready to apply this at your firm?

A 20-minute call. I'll identify which workflows are worth prioritizing and the right way in.

20-minute call. I'll show you where firms like yours typically start.

Please don't include confidential client information. I use these details only to respond to you.