Illinois Attorneys: AI Ethics Guidance You Need to Know (2026 Update)
Quick Answer: Illinois attorneys using AI tools must comply with ARDC Rule 1.6(e) ("reasonable efforts" to prevent unauthorized disclosure) and Rule 1.1 Comment 8 (technology competence). ISBA Advisory Opinion 24-01 (2024) adds that lawyers must understand the capabilities and limits of generative AI tools, evaluate how a tool stores, processes, and shares client data before using it, bill reasonably for AI-assisted work, and consider disclosing AI use to clients. The Illinois Supreme Court's Policy on Artificial Intelligence, effective January 1, 2025, confirms that AI use is permitted when it complies with existing legal and ethical standards.
Introduction
If you're an Illinois attorney using AI tools—or considering them—here's what you need to know about your ethics obligations in 2025.
This guide synthesizes ARDC rules, ISBA ethics opinions, and ABA guidance to give you a practical compliance framework.
The Governing Rules
Illinois Rule 1.6: Confidentiality
The foundation of AI ethics compliance is Rule 1.6(a):
"A lawyer shall not reveal information relating to the representation of a client unless the client gives informed consent..."
And Rule 1.6(e):
"A lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."
Key point: "Reasonable efforts" is the standard. What's reasonable evolves with technology.
Illinois Rule 1.1: Competence
Comment 8 to the ABA Model Rules (adopted by Illinois) requires:
"...keeping abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology..."
Key point: You can't claim ignorance about how your AI tools handle client data. You have an affirmative duty to understand.
ISBA Ethics Opinions on Technology
ISBA Opinion 16-06: Cloud Computing
This opinion addressed cloud services and established that Illinois attorneys may use cloud providers if they:
- Conduct reasonable due diligence on the provider
- Ensure the provider has adequate security measures
- Consider whether client data will be accessible to third parties
- Review and understand the provider's terms of service
Application to AI: Cloud-based AI billing tools are cloud services. The same due diligence requirements apply.
ISBA Advisory Opinion 24-01: Generative AI
In August 2024 the ISBA issued Advisory Opinion 24-01, its first opinion directed specifically at generative AI. It works through the existing rules rather than creating new ones, and its practical requirements are:
- Competence. Understand what the tool can and cannot do, including the risk of fabricated citations and factual errors, before relying on it.
- Confidentiality. Evaluate how the tool stores, processes, and shares client information before client data goes into it. That evaluation is the lawyer's job, not the vendor's.
- Billing. Bill reasonably and transparently for AI-assisted work. Time the tool saved is not time the client pays for.
- Disclosure. Consider telling clients when AI is used in their matter, particularly where confidential information is involved.
Advisory opinions are guidance rather than binding rules, but they reflect how the bar reads the Rules of Professional Conduct and would be cited in any disciplinary proceeding.
The Illinois Supreme Court Policy on Artificial Intelligence
Effective January 1, 2025, the Illinois Supreme Court adopted a policy on AI in the state courts. It states that AI use by attorneys and litigants "may be expected, should not be discouraged, and is authorized provided it complies with legal and ethical standards," that disclosure of AI use should not be required in a pleading, and that the Rules of Professional Conduct apply fully to the use of AI technologies. The ARDC followed in October 2025 with an Illinois Attorney's Guide to Implementing AI. None of this loosens the confidentiality analysis; it confirms that the analysis is yours to do.
ABA Opinion 512: The National Framework
While not binding in Illinois, ABA Formal Opinion 512 (2024) provides persuasive guidance that Illinois attorneys should consider:
"All lawyers should read and understand the Terms of Use, privacy policy, and related contractual terms and policies of any GAI tool they use."
The opinion emphasizes:
- Due diligence on AI vendors is mandatory
- Confidentiality assessment must consider where data goes
- Informed consent may be required for certain uses
- Supervision of AI outputs is the attorney's responsibility
Practical Compliance Checklist
Based on Illinois rules and ISBA/ABA guidance, here's what Illinois attorneys should do:
Before Adopting an AI Tool
[ ] Read the Terms of Service
Not the marketing page—the actual ToS. Understand data retention, third-party sharing, and processing locations.
[ ] Review the Privacy Policy
Where is data stored? Who can access it? Is it used for model training?
[ ] Request a Data Processing Agreement
For enterprise tools, this should specify data handling, security measures, and liability allocation.
[ ] Map the Data Flow
Where does client data go? Which third parties (OpenAI, Azure, etc.) touch the data?
[ ] Assess Third-Party Providers
If the vendor uses sub-processors, understand who they are and what access they have.
Before Using AI on Client Matters
[ ] Evaluate Matter Sensitivity
High-stakes litigation, family law, criminal defense—these may require heightened protections.
[ ] Consider Client Disclosure
For cloud-based AI, disclosure in engagement letters is prudent. For sensitive matters, explicit consent may be appropriate.
[ ] Document Your Assessment
If challenged, you'll need to show you made reasonable efforts. Keep records.
Ongoing Compliance
[ ] Monitor ToS Changes
Vendors update terms. Set calendar reminders to review quarterly.
[ ] Supervise AI Output
Don't submit AI-generated content without attorney review.
[ ] Update Engagement Letters
As your tech stack changes, update disclosures.
Client Disclosure Language
For Illinois attorneys using cloud-based AI tools, consider adding this to engagement letters:
Technology Disclosure
Our firm uses artificial intelligence software to assist with [time tracking and billing / legal research / document review]. This software may process information related to your representation on third-party cloud servers.
We have evaluated our technology providers and believe their security practices meet professional standards. However, we want to ensure you understand that information may be processed outside our direct infrastructure.
If you have concerns about this technology use or would prefer alternative methods, please notify us.
For local/on-premise AI:
Technology Disclosure
Our firm uses AI-assisted tools for [time tracking and billing]. The AI analysis runs locally on our firm's own computers. Your email and documents remain in the systems our firm already uses, and they are not transmitted to any third-party AI provider.
The Privilege Question
Illinois follows traditional privilege doctrine. The key question for AI tools:
Does transmitting client communications to a third-party AI provider constitute disclosure that could waive privilege?
The answer isn't settled, but the risk exists. Under the third-party disclosure doctrine, voluntary transmission to an outside party may waive privilege even if the recipient promises confidentiality.
Risk factors that increase privilege exposure:
- Data processed on third-party cloud servers
- Multiple sub-processors in the chain (vendor → OpenAI → Azure)
- Processing in foreign jurisdictions
- Opposing counsel actively seeking privilege waiver arguments
Factors that reduce exposure:
- Local AI processing (no third-party transmission)
- Documented client consent
- Kovel-type "necessary agent" arguments (though these have limits)
ARDC Disciplinary Considerations
The ARDC hasn't yet disciplined an attorney specifically for AI-related confidentiality breaches. But the framework exists:
Rule 1.6 violations could arise from:
- Using AI tools without understanding data flows
- Failing to make reasonable security assessments
- Disclosing confidential information without consent
Rule 1.1 violations could arise from:
- Technology incompetence (not understanding how AI works)
- Failing to supervise AI output
- Submitting hallucinated content to courts
Rule 5.3 violations could arise from:
- Failing to supervise AI as a "nonlawyer assistant"
- Not establishing policies for AI use in the firm
The ARDC is likely watching for a test case. Don't be it.
The Safe Harbor: Local AI
For Illinois attorneys who want to eliminate cloud AI risk entirely:
Local AI processing means the AI runs on your device or your firm's server. Client data never leaves your infrastructure.
This approach:
- Eliminates third-party disclosure
- Removes subpoena exposure to vendors
- Satisfies "reasonable efforts" without ongoing vendor monitoring
- Simplifies disclosure requirements
IntelliBill, built by an Illinois attorney, takes this approach. It runs as a Mac app that reads the Microsoft 365 email you authorize and performs classification, matter matching, and narrative drafting on the Mac with no cloud model fallback. Every proposed entry still requires human review before export.
Key Takeaways for Illinois Attorneys
-
You have a duty to understand your AI tools. "I didn't know" isn't a defense.
-
Cloud AI requires due diligence. Read ToS, map data flows, assess privilege risk.
-
Disclosure is prudent. Update engagement letters to cover AI use.
-
Sensitive matters need extra care. Family law, criminal defense, high-stakes litigation may require explicit consent or local processing.
-
Local AI eliminates third-party risk. If you want to avoid the cloud AI analysis entirely, tools exist.
This article is for informational purposes only and does not constitute legal advice. For jurisdiction-specific guidance, contact the ISBA Ethics Hotline or ARDC.
ATTORNEY ADVERTISING
Comments
No comments yet. Be the first to comment!
Check whether IntelliBill fits your billing workflow.
The planned Mac pilot covers email-to-draft review and a reviewed CSV handoff. Access is by request; activation depends on a supported mailbox connector and completed release testing. Read the current availability and setup guide before arranging working-data access.
Request pilot accessThe hosted Product Tour uses fictional browser-local data and creates no working-data workspace.