Parity in Practice: The Defender's Duty to Ethically Use AI

A report for the NACDL Task Force on Artificial Intelligence

Parity in Practice: THE DEFENDER’S DUTY TO ETHICALLY USE AI

A white paper on ethical and practical use of generative AI by criminal defense lawyers Mason R. Clark

Copyright © 2026 National Association of Criminal Defense Lawyers

This work is licensed under the Creative Commons Attribution-NonCommercial- NoDerivatives 4.0 International License. To view a copy of this license, visit https://creativecommons.org/licenses/by-nc-nd/4.0/ . It may be reproduced, provided that no charge is imposed, and the National Association of Criminal Defense Lawyers (NACDL) is acknowledged as the original publishers and the copyright holders. For any other form of reproduction, please contact NACDL for permission.

For more information contact: National Association of Criminal Defense Lawyers ® 1660 L Street NW, 12th Floor, Washington, DC 20036 Phone 202-872-8600 NACDL.org This publication is available online at NACDL.org/ParityInPractice

A version of this article is forthcoming in the inaugural edition of The Journal of Advocacy and Litigation (Vol. 1, 2026).

Parity in Practice: THE DEFENDER’S DUTY TO ETHICALLY USE AI

Andrew S. Birrell President, NACDL Minneapolis, MN Lisa M. Wayne Executive Director, NACDL & NFCJ Washington, DC Kyle O’Dowd Deputy Director, NACDL Washington, DC REPORT AUTHOR Mason R. Clark Assistant Professor of Law St. Mary’s University School of Law San Antonio, TX

Table of Contents About NACDL .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 5 Acknowledgements .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 6 Executive Summary .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 7 Introduction .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 9 A. Purpose and Scope.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 9 B. Why This Matters Now .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 9 C. Timeline for Implementation.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 11 Part I: AI Overview .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 12 A. What Is Generative AI?.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 12 B. Use of AI in Defense .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 16 C. The Defense Lawyer’s Duty to Use AI.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 20 Part II: AI Ethics and the Model Rules of Professional Conduct .�.�.�.�.�.�.�.�.�.�. 23 A. Helpful Resources to Guide AI Use.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 23 B. Balancing Duties of Competence, Confidentiality, and Candor .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 25 Part III: Practical Guidance For Defense Lawyers .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 33 A. Practical Guidance for Defense Lawyers.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 33 B. AI Use Policies .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 41 C. Additional Policy Recommendations.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 45 Conclusion .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 47 Endnotes .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 49 Appendix A .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 56 Model AI Use Policy .�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�.�. 56

AI ETHICS

About NACDL

The National Association of Criminal Defense Lawyers (NACDL) envisions a society where all individuals receive fair, rational, and humane treatment within the criminal legal system. NACDL’s mission is to serve as a leader, alongside diverse coalitions, in identifying and reforming flaws and inequities in the criminal legal system, and redressing systemic racism, and ensuring that its members and others in the criminal defense bar are fully equipped to serve all accused persons at the highest level. NACDL is committed to enhancing the capacity of the criminal defense bar to safeguard fundamental constitutional rights. NACDL harnesses the unique perspectives of NACDL members to advocate for policy and practice improvements in the criminal legal system. NACDL also actively engages with emerging technologies through its Fourth Amendment Center and related programming and task forces, educating defense attorneys on issues like probabilistic genotyping, forensic genetic genealogy, and the impacts of AI on policing, sentencing, and privacy rights. Additionally, NACDL has launched a Task Force on Artificial Intelligence to establish policy and the ethics of artificial intelligence and to monitor the impact that AI will have on criminal defense lawyers and their clients. NACDL also believes “Justice is Green,” and is committed to being a bar organization that leads in criminal legal reform as well as various going green initiatives. This commitment prioritizes NACDL’s respect for the planet alongside its vision for a more just and fairer criminal legal system. NACDL believes we all need to modify our behavior to ensure the wellbeing of our planet and its inhabitants; for NACDL, this commitment will be reflected in its conduct as well as its messaging to other bar associations around the country. Finally, NACDL has established the NACDL Foundation for Criminal Justice (NFCJ), a 501(c)(3) registered charity. The mission of the NFCJ is to preserve and promote the core values of the criminal legal system guaranteed by the Constitution — among them due process, fair sentencing, and effective assistance of counsel — by educating the public and the legal profession to the role of these rights and values in a free society.

5

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS

Acknowledgements

The author would like to thank Jonathan Brayman (Breen & Pugh, Chicago), Melanie Foote (Kentucky Department of Public Advocacy), Katherine Tang Newberger (Office of the Federal Public Defender, Maryland), Giselle Pomerleau (Office of the Federal Public Defender, New Jersey), and the National Association of Criminal Defense Lawyers for spearheading this project and providing thoughtful review and suggestions. Additional thanks to the following NACDL staff for their contributions to this report: Lisa Wayne (Executive Director), Kyle O’Dowd (Deputy Director), Jumana Musa (Director, Fourth Amendment Center), Jonathan Hutson (Communications Director), and Cathy Zlomek (Art Director). As nearly two dozen jurisdictions now require attorneys to provide disclosure and/or verification statements for documents prepared with assistance from or containing information generated by generative artificial intelligence, it seems fitting to include a specific and conspicuous disclosure and verification statement here: This white paper was prepared with the assistance of generative artificial intelligence. The author used various large language models to organize some parts and subsections; to rephrase some content for brevity; to format citations; to summarize lengthy reports or articles; and to compile research material into accessible folders. The author certifies that all citations have been manually verified to ensure their existence and confirm their propositions as accurate representations.

6

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS

Executive Summary

Generative artificial intelligence (AI) presents both opportunities and risks for criminal defense lawyers. 1 With practical, strategic guidance and dedicated organizational governance, these tools can improve efficiency, support legal research, and help defense lawyers manage overwhelming caseloads and provide effective counsel. However, generative AI raises serious concerns about confidentiality, accuracy, fairness, and ethical compliance, and these concerns impact all participants in the American criminal legal system — from prosecution and defense to judges and juries. Some prosecutors’ offices are increasingly experimenting with enterprise-level AI tools, though resource disparities may hinder comparable adoption among some defender organizations. Moreover, AI has already impacted workflows and organizational structures at firms and defenders’ offices, and its ubiquity encourages skill flattening. 2 What is clear, though, is that defenders have an ethical obligation to use AI in their practice and in the courtroom, and a failure to do so could produce incompetent representation of and negative outcomes for criminal defendants. This white paper provides a framework for ethical and practical AI use across all types of criminal defense practice, grounded in the ABA Model Rules of Professional Conduct and best practices as described by practitioners, academics, and other experts. While AI tools can meaningfully improve efficiency and expand analytical capacity, those benefits are highly contingent on tool selection, implementation, and oversight. The white paper also recognizes that cost, access to training, and institutional resources remain significant barriers — particularly for solo practitioners, small firms, and under-resourced public defense offices — and discusses AI throughout as a set of tools whose value depends on informed, responsible, and ethical use. It explains what generative AI is, identifies its risks and limitations (including emerging issues like deepfakes and climate impacts), surveys its current use by prosecutors and its reception in courts, and provides practical guidance for defenders on important day-to-day decision-making, such as which tools to use and how to use them ethically and efficiently. It uses job-specific examples (e.g., sentencing memos and character statements) to explain where and how AI could be used and highlight potential ethical concerns in its use. Most importantly, it sets out a roadmap for drafting AI policies, including considerations for data privacy and security, verification, training, and compliance with judicial standing orders.

7

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS Finally, this white paper acknowledges the realities of technology and the law: The technology is rapidly evolving, and the guidance will likely change, too. With that in mind, this white paper recommends that defenders adopt formal, written AI policies, secure feasible AI tools, implement staff training protocols, and establish flexible yet clear guidelines for permissible and prohibited uses. Flexible guidelines are essential because the goal of any model AI Use Policy is to provide a consistent analytical framework to evaluate and guide use of tools in a dynamic environment. A model AI Use Policy is provided in Appendix A. It is meant to serve as a model only, and practitioners and firms are expected to tailor its provisions in ways that best reflect the workload and culture of each individual attorney or office. The paper also highlights the environmental footprint of AI and recommends strategies for minimizing energy consumption when selecting and deploying AI tools. Defenders must ultimately balance innovation with responsibility, ensuring that generative AI enhances zealous advocacy and competent representation without sacrificing ethical obligations.

8

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS

Introduction

A. Purpose and Scope

This white paper provides guidance on the ethical, responsible, and practical use of generative AI by criminal defense lawyers, from solo practitioners to firm members to public defenders (collectively, “defenders”). The guidance draws directly from the ABA Model Rules of Professional Conduct and reflects the realities of day-to-day representation and practice. Defenders at every level will find practical frameworks for integrating AI tools into their work while maintaining their professional and ethical obligations. This white paper also serves as a call to action. Prosecutors across the country have already begun experimenting with enterprise-level AI tools to manage evidence, streamline discovery, and automate review of wrongful convictions and resentencing. 3 As the Vanderbilt Project on Prosecution Policy has documented, prosecutors use AI even when it is “often unclear how accurately and fairly these tools complete the task at hand.” 4 Defenders cannot afford to remain on the sidelines. The adversarial nature of the criminal legal system demands that defenders achieve parity or risk providing representation that falls short of constitutional and ethical standards. B. Why This Matters Now Generative AI has entered legal practice at a remarkable pace. When OpenAI released ChatGPT in late 2022, it reached approximately 100 million monthly active users within two months, making it one of the fastest-growing consumer applications in history. 5 The technology’s ability to predict, analyze, and produce writing strikes at the core of much legal work. As one commentator observed, AI now targets the “bread and butter” of what lawyers do. 6 Yet adoption remains uneven between prosecutors and defenders, and “[r]ecent years have seen an increase in the use of AI tools to support crime prevention, prosecution, sentencing, and other facets of the criminal [legal] system.” 7 Judges have largely permitted police and prosecutors to use “black box AI,” which refers to the types of AI tools and systems whose internal decision-making processes are hard to understand or explain, leading to transparency concerns. 8 Meanwhile, many public defender

9

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS offices and solo practitioners lack not only access to enterprise-level AI systems, but also the resources and expertise to challenge software outputs (including AI-generated outputs) as unreliable in court. 9 This disparity raises urgent questions about competence and fairness, but also requires defenders to proactively engage with the AI tools that are available as a potential equalizer. The proliferation of generative AI among the legal profession, generally, has been controversial and landed many lawyers in trouble with the court. There are countless recent examples of prosecutors and defenders misusing AI in briefing and in the courtroom, but two recent examples highlight the ethical concerns at the heart of this white paper. The New York Times recently published a story about a District Attorney in California who allegedly used AI in an 11-page brief asking the court to deny bail to the accused and keep him in jail, a brief allegedly “rife with errors that bear the hallmarks of generative artificial intelligence” and including “wholesale misrepresentations of the law, as well as quotations that do not actually appear in the cited texts.” 10 And on the other side of the bench, a defender included several misrepresentations of law in a brief before the Illinois Supreme Court, something that was a source of tense questioning during the defender’s oral argument. 11 When one of the justices challenged the defender regarding the inaccurate case propositions, the defender said, “I can only tell you that we rely on the Lexis, the flags and so forth, and my associate was assisting me, so I will have to have a long chat.” 12 Just minutes before, the defender admitted to using X’s chatbot Grok to learn more about certain expert testimony requirements, one of the key issues to be reviewed by the Illinois Supreme Court on appeal. 13 These two examples underscore two serious concerns with overreliance on AI to be discussed in this white paper. First, AI often “hallucinates,” or invents, fabricates, exaggerates, or misstates cases, rulings, and even facts. 14 According to researcher Damien Charlotin, there are at least 500 cases in the United States, identified as of January 6, 2026, where generative AI produced hallucinated content through fabricated, falsely quoted, or misrepresented case law, and a court or tribunal specifically levied warnings or other punishments. 15 Second, in the Smith case mentioned above and in countless other cases, lawyers who have been caught using hallucinated case law often blame the mistake on a lack of supervision of younger or more junior associates. As discussed later in the white paper, both prosecutors and defenders are on notice that AI hallucinates, courts can and will sanction the misuse of AI in briefings and in the courtroom, and blaming a junior associate will not relieve an attorney of their ethical obligations or any punishment for violating them. Beyond the misuse of AI in the courtroom, there are access-to-justice concerns about AI, too. As Professor Drew Simshaw has explained, although legal AI has “the potential to increase the efficiency and cost effectiveness of work done by lawyers” and “help people solve their own legal problems or connect them with licensed legal professionals who can,” overreliance on and legitimization of technology-driven legal services, “will lead to one or more inequitable two-tiered systems.” 16 AI will either be superior, cost more, and only be available to large firms and wealthy clients, or the inverse

10

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS will be true. 17 Either way, the benefits of AI depend on who can access and effectively use the technology. Without deliberate efforts to ensure equitable access, “the realization of any combination of these two-tiered systems” risks widening rather than narrowing the justice gap. 18 These concerns matter to NACDL, which has long engaged with emerging technologies through its Fourth Amendment Center and related programming, but has a strong commitment to increasing access to justice. Finally, NACDL believes “Justice is Green” and remains committed to environmental sustainability. AI systems — particularly large language models — consume substantial electricity and water, with research suggesting that “by 2030, the current rate of AI growth would annually put 24 to 44 million metric tons of carbon dioxide into the atmosphere, the emissions equivalent of adding 5 to 10 million cars to U.S. roadways” and “equal to the annual household water usage of 6 to 10 million Americans.” 19 Defenders should consider these environmental costs when selecting and deploying AI tools, consistent with NACDL’s commitment to reducing its carbon footprint while pursuing a more just criminal legal system. The tools and platforms discussed in this whitepaper are cited as illustrative examples only. Their inclusion does not constitute an endorsement of any particular product, vendor, or service provider, nor does it imply that the tools described are superior to alternatives not discussed. C. Timeline for Implementation

Defense lawyers should aim to implement formal AI use policies within one year. However, the rapid pace of technological change may require interim safeguards sooner. To meet the goal of developing and implementing AI policies within a year, defenders must start the process now by:

1. Understanding the basic capabilities and limitations of both generative and non-generative AI tools, and identifying tools that may enhance client representation within their practice.

2. Inventorying current AI usage (if any) in their offices and how AI is being used.

3. Drafting an enterprise-level AI use policy.

4. Training all necessary staff on internal policies related to the use of AI tools.

5. Reviewing any standing orders or local rules in their jurisdictions that govern AI use, and learning how prosecutors in a given jurisdiction are currently using AI tools in practice.

The model AI Use Policy provided in Appendix A offers a starting framework that practitioners can adapt to their specific circumstances.

11

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS PART I: AI Overview

Part I provides an overview of generative artificial intelligence and its emerging role in criminal defense practice. It begins by explaining, at a high level, what generative AI is, how certain systems (e.g., LLMs) work, and why their design and limitations matter in practice. The discussion then turns to the ways defenders are already using generative AI tools in practice, including legal research, drafting, case organization, discovery review, and client communication, while also noting the risks of inaccuracy, bias, confidentiality breaches, and overreliance. Finally, Part I affirms that defenders have an ethical duty to understand and use AI. Together, these sections establish the technological, practical, and ethical foundation necessary to assess how AI should be responsibly integrated into criminal defense practice. A. What Is Generative AI?

1.

Definition and Core Functionality

Artificial intelligence encompasses a rather large umbrella of technologies that in some way mimic human intelligence. The National Institute of Standards and Technology defines AI as systems that can “make predictions, recommendations or decisions influencing real or virtual environments” for a given set of human-defined objectives. 20 These systems work with machine learning 21 and data analytics 22 to form conclusions using real-time data. However, to make intelligent decisions, computer programmers must first build intelligent algorithms. 23 Generative AI refers to a specific subset of artificial intelligence. These systems use machine learning models trained on vast datasets to create new content (e.g., text, images, code) based on patterns identified in that training data. Large language models (LLMs), such as those powering ChatGPT, Claude, and similar tools, analyze enormous amounts of text and generate responses to user prompts based on the patterns they have learned. As OpenAI CEO Sam Altman explained to Congress in 2023, these models “generate responses by predicting the next likely word in response to the user’s request, and then continuing to predict each subsequent word after that.” 24 The capabilities of these LLMs have

12

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS advanced rapidly. When OpenAI released GPT-4 in March 2023, testing showed it scored in the top ten percent of July 2022 Uniform Bar Exam test takers. 25 This performance demonstrates why generative AI poses both opportunities and challenges for legal practice: The technology can now produce work product that, at least superficially, resembles the output of trained lawyers. But generative AI is not limited to just LLMs and text generation for legal writing. Beyond large language models, lawyers are beginning to explore other forms of generative AI. Some of these generative AI tools include research and case analysis tools to summarize and compare cases, statutes, and regulations; image generators to create demonstrative exhibits and other visual aids; document review tools to classify documents and flag relevance or privilege; and video generators to “synthesize background sound effects and dialogue based on prompts.” 26 Perhaps more significantly, courts are grappling with deepfakes and manipulated audio and video evidence appearing in litigation, prompting the Advisory Committee on Evidence Rules to consider proposed Rule 901(c) governing potentially fabricated electronic evidence. 27

2.

Open or Closed Systems

a.

Open/Closed Source v. Open/Closed System

Defenders must understand the critical distinction between the meanings of “open” and “closed” in AI discourse. The terms “open” and “closed” carry two related but distinct meanings in AI discourse. One meaning concerns the AI model’s development and distribution. The Open Source Initiative defines “open-source” AI as any system, model, weights, and/or parameters that grant users the freedom to (1) use the system for any purpose without asking for permission; (2) study how the system works and inspect its components; (3) modify the system for any purpose, including to change its output; and (4) share the system for others to use with or without modifications, for any purpose. Open- source models make their underlying code and models publicly available, allowing anyone to inspect, modify, or deploy them. “Closed-source” or proprietary models — such as ChatGPT or Claude — keep their architecture and training data confidential, offering access only through controlled interfaces or application programming interfaces (API). Proponents of open-source models argue they “level[] the playing field by making technology accessible to all” and enable transparency into how the model was trained and what it was trained on, both key metrics for evaluating an AI tool. They can also be run on local hardware with significantly fewer environmental effects. Proponents of the closed-source models, however, contend they allow developers to maintain centralized control over deployment and rapidly patch vulnerabilities, reducing the risk that malicious actors will bypass safety guardrails or deploy models without use restrictions. 28

13

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS The second meaning concerns the environment in which users use the AI. This is perhaps more relevant to defenders reading this white paper and using or preparing to use AI. A closed environment (sometimes called an “enterprise” or “private” deployment) keeps user inputs (mostly) confidential and segregated, either on-premises (i.e., on a localized server on the firm’s premises) or in a cloud-based instance (i.e., the platform stores the data in the cloud). An open environment, by contrast, may incorporate user interactions into future training data or make them accessible to the provider, law enforcement, or other unintended third parties. This distinction matters particularly for attorneys handling confidential client information. Bar ethics opinions have emphasized that lawyers must understand how their AI tools operate with respect to preserving confidentiality under Model Rule 1.6. 29

b.

What are the risks of open and closed systems?

Open AI systems use publicly available models, transparent training datasets, and are often freely accessible to consumers. 30 When users enter information into open systems, that data may become part of the broader training dataset or otherwise leave the user’s control. Open systems offer certain advantages — including broader training data and greater resources for innovation — but this openness and transparency comes at a cost for confidentiality. Searches performed and content generated through open systems may effectively enter the public domain. Moreover, stored data is likely used to train the system and otherwise shared with third parties. Closed AI systems, by contrast, operate within self-contained and controlled environments. These enterprise-level deployments house data on private servers or secure cloud instances, limiting access to authorized users within an organization. Closed systems restrict training data to information the organization provides or approves, and they better maintain confidentiality (albeit not entirely) by preventing data from leaving the secure environment. However, closed systems typically require significant financial investment and technical infrastructure that many solo practitioners and under- resourced public defender offices cannot easily afford. Finally, defenders may learn about “on-prem” (i.e., on premises) AI environments. These are often a subset of closed AI environments in which the data actually stays within the firm’s or office’s own infrastructure and is managed by its own internal information technology and security teams. On-prem AI systems can be beneficial for defenders (and lawyers, generally) because they are more customizable and directly managed by those using the system every day. However, on-prem AI requires upfront spending on the actual hardware and physical infrastructure (e.g., servers, space, and other physical infrastructure, like cooling) that many solo practitioners or under-resourced firms may not be able to afford. 31

14

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS

c.

Why does this matter?

For defense lawyers, this distinction matters enormously. Entering privileged client information, case facts, discovery, or any other materials subject to protective orders into either system risks breaching confidentiality obligations under Model Rule 1.6, but closed systems remain a safer option for defenders who disclose this type of information in an AI tool. State bar opinions have likewise required lawyers to understand how different AI tools handle data. 32 Even if the risk of a specific query resurfacing in another user’s results seems remote, the possibility is not zero and defenders must weigh that risk against the potential benefits.

3.

Examples in Practice

Several AI tools have emerged as relevant to legal practice. General-purpose tools include ChatGPT (developed by OpenAI), Claude (developed by Anthropic), and Gemini (developed by Google). These LLMs allow users to generate text (e.g., drafting an email to the client or preparing a section of a brief or motion), summarize documents, and receive answers to questions across virtually any subject matter. Legal-specific AI tools have also proliferated. Thomson Reuters has integrated AI capabilities into Westlaw through its CoCounsel product, which was the first legal AI assistant powered by OpenAI’s GPT-4 technology and now provides agentic functionality using Anthropic’s Claude SDK (software development kit). LexisNexis offers Lexis+ AI for legal research and document analysis. Harvey, a startup backed by Sequoia and OpenAI, has partnered with major law firms to develop AI tools tailored specifically for legal work. But legal-specific AI tools share the same problems as other AI tools and LLMs. Legal tech startups often promote “retrieval-augmented generation” (RAG), which act as LLMs but instead of drawing from the entire internet, RAG models “get their information only from a closed set of data, such as Westlaw, Bloomberg, or the lawyer’s own collection of documents, allowing RAG systems to provide accurate citations when answering user prompts.” 33 Although legal AI tools may reduce errors compared to the general-use LLMs, RAGs still hallucinate “at an alarming rate.” 34 Researchers at the Stanford RegLab and Institute for Human- Centered Artificial Intelligence (HAI) found “the Lexis+ AI and Ask Practical Law AI systems produced incorrect information more than 17% of the time, while Westlaw’s AI-Assisted Research hallucinated more than 34% of the time.” 35 Defenders evaluating these tools should consider several factors, including but not limited to: (1) whether the system operates as open or closed (both source and environment); (2) what data security guarantees the vendor provides, such as data retention and deletion controls, encryption standards, role-based access controls, and breach notification procedures; (3) how the system was trained and on what data; and (4) what verification mechanisms exist to catch errors or hallucinations in the output.

15

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS B. Use of AI in Defense

Defenders can use AI for defender-specific work, from internal office operations to evidence review to courtroom advocacy. Understanding these use cases helps defenders identify where AI might improve efficiency without compromising ethical obligations. Although this section discusses multiple forms of artificial intelligence (i.e., GenAI tools v. traditional, non-generative tools), the analysis is intentionally broad to provide guidance for using different types of tools. The ethical concerns that arise from AI use often turn less on the specific model or system than on how, where, and why the model or system is deployed. Accordingly, the discussion that follows treats AI as a general category of support and automation tools and emphasizes recurring risks and safeguards that cut across different tools and use cases.

1.

Operations

AI can streamline many administrative and preparatory tasks within a defense practice. Chatbots and virtual assistants can handle initial client intake, gathering basic information before an attorney becomes involved. AI-powered transcription services can convert audio recordings — including client interviews, witness statements, jail recordings, and court proceedings — into searchable text. Document automation tools can generate routine correspondence, fee agreements, and standard motions from templates. Legal aid organizations across the country are adopting AI-powered case management software and other tools at almost twice the rate reported across the wider legal profession, and these tools can now conduct initial client interviews, gathering basic information about legal problems, applying eligibility criteria, and producing structured summaries for staff review. 36 These systems operate around the clock, meaning a client served with an eviction notice or facing charges can begin the intake process at midnight rather than waiting days for a callback during business hours. For offices serving large geographic areas, this also extends reach to rural clients who may be unable to travel for in-person interviews. 37 For example, in 2023 the Los Angeles County Public Defender’s Office partnered with Amazon Web Services to develop a custom pipeline that is to reduce manual data entry from documents by up to 85%. 38 The new system makes all documents searchable and proactively alerts defenders to filings from law enforcement, courts and the district attorney’s office. It ingests scanned PDFs, classifies useful pages, extracts agency-specific information, and allows staff to verify results through a user interface. The office’s Chief Information Officer described: “When we did the first presentation to a group of attorneys, you should have seen their faces. It identified the summary sheet, got the relevant charges

16

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS and maximum sentences. It went and found witness information and created witness records. Everyone was leaning forward to the computer with their mouth open looking at this.” 39 In another example, the Maryland Office of the Public Defender implemented eDefender, a cloud- based case management system from Journal Technologies, Inc., that centralizes all case files into searchable folders accessible securely to defenders and paralegals working on the same case. The tool integrates with other third-party “justice partner systems,” APIs, and platforms (like Evidence. com) and centralizes critical tasks, reports, and communications. 40 Journal Technologies has similar platforms for prosecutors (eProsecutor) and courts (eCourts), and if all three are adopted in a given jurisdiction, this may facilitate equal access among all players in the jurisdiction. NACDL spoke with a representative from the New Jersey Office of the Public Defender (OPD) for this white paper, and the conversation offered an instructive example of how a statewide public defender office can approach AI adoption incrementally using (1) internally developed and customized tools, (2) emerging tools with existing vendors like Westlaw, and (3) experimental tools with institutions researching AI use in certain industries. For example, the New Jersey OPD first started using an internal AI tool developed by New Jersey’s Office of Information Technology (NJOIT) specifically for state employees. This tool allows users to choose from models such as Claude and other large language models, that enable attorneys, investigators, or staff to quickly generate first drafts of informational memos, letters and policies, yet it is not used for legal briefs or any substantive legal research or work product. More recently, the office secured a six-to-nine-month trial of Westlaw’s CoCounsel product at no additional cost over their existing Westlaw subscription, which includes several AI features. Finally, the office is also partnering with Princeton University, NJOIT, and the New Jersey Innovation Authority to develop a “Brief Bank,” which would house all New Jersey public defender briefs on secured state infrastructure (through the state’s Office of Information Technology and with help from Amazon Web Services) and allow attorneys to generate first drafts informed by that institutional knowledge base. Critically, each of the tools used is structured so that client queries do not train the underlying models, and have validated security controls to ensure client information remains inaccessible to anyone but the public defenders. The New Jersey OPD’s posture overall might be described as “curious and responsible”: Public Defender Jennifer Sellitti recognizes that meaningful AI adoption requires understanding not just what tools exist and the limitations of those tools, but also a willingness to engage with public and private stakeholders who are interested in developing new tools and testing them with public interest focused organizations. This posture is worth examining for public defense offices navigating similar questions about efficiency and ethics, and procurement and resource constraints.

17

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS

2.

Evidence and Case Review; Legal Research and Writing

Defenders are deploying AI to address the crushing workload that has long defined public defense, including everything from intake to evidence analysis to trial preparation. For example, the Kentucky Department of Public Advocacy uses JusticeText to “handle the surge of bodycam footage in cases,” and defenders reported that it “reduced time spent reviewing evidence by hours per case, allowing them to find key contradictions in police statements more efficiently.” 41 The Colorado State Public Defender’s office has used Reduct, which allows defenders to highlight key clips, generate captions, and create court exhibits from bodycam footage and police interrogations. 42 AI transcription and analysis tools have thus fundamentally changed how defenders manage overwhelming swaths of data and evidence. Defenders upload audio and video files, and AI generates searchable transcripts within minutes. What once required teams of staff listening to recordings in real time now happens automatically. Attorneys can search across hours of footage using keywords, jumping directly to moments where specific topics, names, or phrases appear. One Wisconsin defender used JusticeText to more efficiently reveal evidence of police misconduct that would have required substantial manual review, including instances where detectives destroyed evidence intentionally. 43 AI also performs substantive analysis of discovery materials. When police reports and witness statements are uploaded, AI generates organized summaries that highlight key facts such as who was involved, what evidence was collected, and where inconsistencies appear. It can identify which witnesses may be changing their stories and flags contradictions between different accounts of the same events. In another example, the California Innocence Project relied on CoCounsel to narrowly focus on issues commonly seen in wrongful conviction cases, such as witness misidentification. It also helped comb through documents in databases to identify inconsistencies in witness statements or testimony. The managing attorney, Michael Semanchik, said: “Maybe we get to the point where it’s able to just take a look at an entire case, flag some of the wrongful conviction causes that we normally see and send it over for attorney review so we’re not spinning our wheels trying to find the good cases; the good cases come to us through AI.” 44

3.

Sentencing Advocacy

AI also supports sentencing advocacy. Some platforms analyze federal sentencing data to generate statistical reports on likely sentencing outcomes based on historical trends. 45 By analyzing trends in judicial decisions, defenders can present data-backed arguments demonstrating disparities or inconsistencies in sentencing patterns for similarly situated defendants. 46

18

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS AI is increasingly present in the courtroom itself, and defenders should cautiously embrace using AI tools for things like sentencing memos and character statements. AI drafting tools can generate initial versions of sentencing memoranda by synthesizing case facts, identifying mitigating circumstances, and locating precedent, each requiring work that might otherwise consume hours of defender time. Some platforms — generally categorized as predictive analytics or legal analytics tools — analyze millions of federal sentencing outcomes to produce statistical reports showing how similarly-situated defendants have been sentenced, giving defenders empirical support for variance arguments. Although the specific products used are changing much like other general-use products, an example product is the Sentence Intelligence Report or Federal Sentence Predictor tools from SentencingStats.com. For character letters, AI can help family members and supporters structure their narratives effectively and address the elements judges find most persuasive while avoiding common pitfalls like disputing guilt or criticizing the prosecution. Yet defenders should understand the risks of using AI for these uses, specifically. Hallucinations, the same error that led to sanctions against attorneys in widely publicized cases, and other errors in sentencing memos could devastate a client facing years of incarceration. Character letters present different dangers. When clients or their families use AI to draft support letters without defender review, the results often read as generic and formulaic, lacking the specific stories and concrete details that judges find persuasive. Worse, AI-generated letters from multiple supporters may share suspiciously similar phrasing, signaling to the court that the letters are manufactured rather than genuine expressions of support. Judges are increasingly adept at recognizing AI-generated content, and the perception that a defendant’s mitigation package is inauthentic can undermine the entire sentencing presentation. Some judges have approved using AI for sentencing and/or character statements in much more dramatic ways. In 2025, the family of a slain road-rage victim used AI to generate a video of the victim speaking to the court. It was considered the “first time the technology has been used in the U.S. to create an impact statement read by an AI rendering of the deceased victim.” 47 Nonetheless, a defender’s obligation to scrutinize and object to outrageous uses of AI — such as the creation of wholly fabricated evidence and not simply its use for exhibit creation, generally — extends to all materials submitted to the court, as discussed further in Part II.

19

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS C. The Defense Lawyer’s Duty to Use AI

1.

Adversarial Reality

The criminal legal system operates on adversarial principles. Prosecutors and defense lawyers each advocate zealously for their respective positions, and the truth-seeking function depends on both sides presenting their strongest cases. When one side gains significant technological advantages, this balance shifts. The Vanderbilt Project on Prosecution Policy documents current prosecutorial uses including probabilistic genotyping for DNA analysis, extraction and analysis of data from personal electronic devices, enhancement of digital evidence, evidence management and organization, automated transcription and translation, AI-assisted redactions, and pattern identification across cases. 48 Defense lawyers who are unable — due to a lack of resources or support or use restrictions from their firm or office — or unwilling to engage with AI risk falling behind. If prosecutors can delegate workloads more efficiently through AI-assisted platforms, they may better manage staff and deadlines. If prosecutors can process a cell phone extraction containing thousands of text messages in hours while defenders take weeks to review the same material manually, critical evidence may go unnoticed. And if prosecutors use AI to identify connections between cases and defendants while defenders lack similar capabilities, the informational asymmetry compounds existing resource disparities. This does not mean defenders should develop or invest in a new AI solution without critically reviewing its capabilities and security. But it does mean defenders have an obligation — rooted in their duty of competence under Model Rule 1.1 and their duty of diligence under Model Rule 1.3 — to understand what AI tools exist, how prosecutors use them, when to object, and whether comparable tools might benefit their own clients. The ABA’s comment to Model Rule 1.3 specifically states that lawyers must act with zeal in advocacy upon the client’s behalf (emphasis added). Of course, the ability to mount a zealous defense is contingent upon having access to the same or similar tools that prosecutors access.

2.

Ethical Use and Evidence

In 2023, the Advisory Committee on Evidence Rules, for example, amended Federal Rule of Evidence 702 to require that “expert testimony may not be admitted unless the proponent demonstrates to the court that it is more likely than not that the proffered testimony meets the admissibility requirements set forth in the rule.” 49 Likewise, the Advisory Committee has proposed a new Federal Rule of Evidence 707 to regulate the admissibility of machine-generated evidence introduced without expert testimony. 50

20

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS The proposed rule seeks to address issues raised by AI use in courts and has generated extensive discussion and comments from judges, lawyers, and other stakeholders. The NACDL submitted comments to the Advisory Committee on February 16, 2026. 51 Defense lawyers must recognize that AI creates new risks of fabricated or manipulated evidence generated by clients, witnesses, and prosecutors, and it also presents a temptation for defense lawyers to follow suit. Defense lawyers should prepare to scrutinize and confront fabricated evidence generated by any and all parties in a case. AI image generators can create photographs of events that never occurred. The use of deepfakes in the courtroom has prompted responses from scholars, practitioners, bar associations, and courts alike. Professor Rebecca Delfino argued in 2023 that “no evidentiary procedure explicitly governs the presentation of deepfake evidence in court,” and was the first to propose a new Rule 901(c) in the Federal Rules of Evidence “reflecting a novel reallocation of fact-determining responsibilities from the jury to the judge, treating the question of deepfake authenticity as one for the court to decide as an expanded gatekeeping function under the Rules.” 52 Others have more recently suggested a new Rule 901(b)(11) requiring courts to go beyond a witness statement to enable the accused party to request a hearing to require the proponent to provide corroborating sources, 53 and a new Rule 901(c) that holds if the challenging party successfully presents evidence that challenges the authenticity of evidence as more likely than not to be a deepfake, the proponent must show that its probative value outweighs its prejudicial effect on the party challenging the evidence. 54 The risks of manipulated evidence run in multiple directions. Prosecutors might intentionally use or unknowingly rely on AI-manipulated evidence. Witnesses might submit AI-generated materials. Defenders themselves might inadvertently present fabricated content if they fail to verify AI outputs. Defenders should approach evidence with heightened skepticism in the AI era and consider the feasibility of bringing in forensic experts to inspect both the prosecutor’s materials and audit their own materials.

3.

Standard Setting

Defenders have an opportunity — and perhaps an obligation — to lead in establishing ethical standards for AI use in the criminal legal system. By developing and adhering to rigorous ethical frameworks, defenders can model responsible AI practices and create standards against which prosecutorial AI use can be measured. Moreover, knowledgeable and trained defenders can become advocates for parity in ethical use of AI among prosecutors. Once defenders better understand how practical uses of AI clash with ethical obligations, defenders can better articulate that conflict to key stakeholders in the public and private sector.

21

Parity in Practice: The Defender’s Duty to Ethically Use AI

AI ETHICS This standard-setting function serves multiple purposes. Internally, clear ethical guidelines protect defenders from inadvertent misconduct and help offices maintain consistent practices. Externally, documented defense standards provide a basis for challenging prosecutorial AI use that fails to meet comparable ethical benchmarks. Defenders who understand AI well can more effectively litigate against improper prosecutorial uses. Challenging the reliability of probabilistic genotyping software, for instance, requires understanding how such algorithms function and where they might fail. Contesting facial recognition identifications demands knowledge of how those systems operate, their error rates, and their documented racial disparities. Defenders who remain ignorant of AI technology cannot effectively advocate for their clients when that technology affects the prosecution’s case. The NACDL’s Task Force on Artificial Intelligence represents one effort to develop collective defense standards. Individual offices and bar associations can contribute by sharing policies, training materials, and litigation strategies. Through coordinated effort, the defense bar can ensure that AI advances ethical justice rather than undermines it.

22

Parity in Practice: The Defender’s Duty to Ethically Use AI

Page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 13 Page 14 Page 15 Page 16 Page 17 Page 18 Page 19 Page 20 Page 21 Page 22 Page 23 Page 24 Page 25 Page 26 Page 27 Page 28 Page 29 Page 30 Page 31 Page 32 Page 33 Page 34 Page 35 Page 36 Page 37 Page 38 Page 39 Page 40 Page 41 Page 42 Page 43 Page 44 Page 45 Page 46 Page 47 Page 48 Page 49 Page 50 Page 51 Page 52 Page 53 Page 54 Page 55 Page 56 Page 57 Page 58 Page 59 Page 60 Page 61 Page 62 Page 63 Page 64 Page 65 Page 66 Page 67 Page 68 Page 69 Page 70

www.nacdl.org

Made with FlippingBook Online document maker