Parity in Practice: The Defender's Duty to Ethically Use AI

AI ETHICS and compliance, responding to incidents or concerns, and coordinating with IT and security functions where applicable. Clear assignment of these responsibilities prevents gaps where issues fall through organizational cracks.

3.

Permissible vs. Prohibited Uses

The policy should clearly distinguish between uses that are permitted, uses that require supervisory approval, and uses that are prohibited entirely.

Permissible uses might include drafting routine administrative documents, researching general legal principles, generating templates and checklists, and other low-risk applications as discussed above. The policy should specify which approved tools may be used for these purposes.

Uses requiring supervisory approval might include drafting case-specific documents like motions or briefs, analyzing client-provided information, processing discovery materials, and other medium-risk applications. The approval requirement ensures oversight without prohibiting beneficial uses.

Prohibited uses should include any use of non-approved AI tools for client matters, entering confidential information into open systems, relying on AI outputs without verification, and any application that would violate ethical rules or court orders. Moreover, firms and offices should prohibit the use of any personal AI tools for professional work and the commingling of any personal use with professional use. The policy should state these prohibitions clearly and unambiguously.

4.

Confidentiality and Data Security Requirements

The policy must address confidentiality with specificity. Requirements should include restricting AI use to approved enterprise systems for any work involving confidential client information, prohibiting entry of privileged communications into AI systems unless specifically authorized, establishing protocols for handling discovery materials subject to protective orders, requiring review of AI vendor security practices before approval, and specifying data handling requirements for any in-house AI development. The policy should also address what happens when things go wrong. If confidential information is inadvertently entered into an unapproved system, staff should have clear guidance on how to report and mitigate client damage. The mitigation system should promote immediate disclosure. This section may look similar to Business Continuity Plan documents or Data Breach Notification / Security Incident Response Plans. Prompt reporting, assessment of harm, client notification where appropriate, and remediation measures should all be addressed.

42

Parity in Practice: The Defender’s Duty to Ethically Use AI

Made with FlippingBook Online document maker