The most important development in legal technology this year is not that autonomous AI agents can now run inside a law firm. It is that they can, the risk of doing so carelessly is documented in detail, and the professional responsibility framework that governs the consequences has hardened into rules, sanctions, and privilege losses.
The excessive agency problem
Start with why the governance layer exists at all. The OWASP GenAI Security Project catalogs the core danger as LLM06:2025 Excessive Agency, which it defines as the vulnerability that enables damaging actions to be performed in response to unexpected, ambiguous, or manipulated outputs from an LLM, regardless of what is causing the model to malfunction. OWASP breaks this into excessive functionality, excessive permissions, and excessive autonomy, and its primary mitigation is blunt: implement authorization in downstream systems rather than trusting the model. An agent that can read a mailbox, call an API, move a file, or spend money is only as safe as the boundary around it.
The OpenClaw record shows what happens when that boundary is thin. OpenClaw is an open source agent created by Austrian developer Peter Steinberger, launched in November 2025 and later renamed from "Clawdbot." It is not an NVIDIA product and not an Anthropic product, a distinction worth stating plainly because the opposite has circulated. Its security history is not theoretical. Researcher Henrique Branquinho of Ethiack chained a one-click account takeover into remote code execution in roughly one hour and forty minutes. A related one-click remote code execution flaw was assigned CVE-2026-25253 with a CVSS score of 8.8 and patched in late January 2026. The related Moltbook social network exposed a backend database including secret API keys. CertiK's "OpenClaw Security Report" found weak Gateway control plane authentication, fragile identity binding across messaging platforms, inconsistent enforcement between policy and execution, and insecure filesystem boundaries. Government bodies issued restrictions, including a CNCERT warning about extremely weak default configuration. For a firm, the lesson is not "avoid this one project." It is that agent autonomy plus weak controls produces exactly the failure OWASP describes.
What the reference architectures actually do
This is the context for the reference architectures now emerging. NVIDIA's NemoClaw is an open source reference stack that packages the OpenClaw agent, NVIDIA OpenShell, and Nemotron local inference into a one-command deployment, launched at GTC 2026. OpenShell is an Apache 2.0 runtime that runs autonomous agents as a K3s cluster inside a Docker container and enforces filesystem, network egress, and process constraints through declarative YAML policy, with default-deny outbound networking. Its four named components are the Gateway, the Sandbox, the Policy Engine, and the Privacy Router.
The Privacy Router deserves a precise description because a looser one has spread. Per NVIDIA's developer blog it keeps sensitive context on-device with local open models and routes to frontier models only when policy allows, and the router makes decisions based on the operator's cost and privacy policy rather than the agent's. That is operator-defined, policy-based routing. It is not the agent autonomously classifying sensitivity in real time. Some commentators have called OpenShell "SELinux for agent governance," which is a useful analogy but not an official product name.
Local inference matters here for a reason that is legal, not just architectural. Nemotron is NVIDIA's open model family, with Nemotron 3 announced December 15, 2025 and the Ultra model released June 4, 2026, under a permissive license permitting commercial use and genuine local inference on supported hardware. Keeping client data on hardware the firm controls changes the confidentiality and privilege analysis directly. None of this removes the need for the sandboxing and governance controls that already exist, including gVisor, Firecracker, Kata Containers, seccomp, AppArmor, SELinux, the Kubernetes SIG agent-sandbox project, and enterprise governance layers such as Microsoft Entra Agent ID unified under Agent 365, AWS Bedrock Agents guardrails, and Google Vertex AI Agent Builder.
The legal layer is national
The ABA Model Rules already govern this conduct. Model Rule 1.1 requires competent representation, and Comment 8 requires a lawyer to keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. Model Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation. Model Rule 5.3 extends supervisory duties to nonlawyer assistance, and its comments now reach services outside the firm, requiring the lawyer to make reasonable efforts to ensure the service is compatible with the lawyer's professional obligations. Model Rule 5.1 covers supervision of lawyers, Model Rule 2.1 preserves independent professional judgment, Model Rule 1.5 governs fees, and Model Rule 3.3 requires candor toward the tribunal, including the duty to correct a false statement of fact or law previously made. An autonomous agent is, for these purposes, a nonlawyer assistant that a lawyer directs and must supervise.
ABA Formal Opinion 512, issued July 29, 2024 by the Standing Committee on Ethics and Professional Responsibility, applied these rules to generative AI. It holds that lawyers using such tools must fully consider their applicable ethical obligations, including the duties to provide competent representation, protect client information, communicate with clients, supervise employees and agents, advance only meritorious claims and contentions, ensure candor toward the tribunal, and charge reasonable fees. The ABA has not issued a formal opinion aimed specifically at agentic AI as distinct from generative AI. Its most recent word is the Task Force on Law and Artificial Intelligence "Year 2 Report," released in December 2025, which observed that platforms begin to chain together tasks, whether called robotic process automation or agentic AI, and noted the challenges this creates.
The state landscape is broad and converging. As of June 2026, one national tracker counts fifteen U.S. jurisdictions with numbered formal ethics opinions on generative AI plus the ABA, and thirty-eight jurisdictions with something official once guidance, task force reports, and court rules are counted (single source: the legalaicompliance.help 50-state tracker; corroborated in general terms by multiple bar compilations, though other counts vary with definition). The significant opinions include Florida Bar Opinion 24-1, the Pennsylvania and Philadelphia joint Formal Opinion 2024-200, North Carolina 2024 Formal Ethics Opinion 1, Texas Opinion 705, DC Bar Opinion 388, New York City Bar Formal Opinion 2024-5, and the California State Bar's Practical Guidance. They converge on three points: lawyers may use AI, the lawyer remains responsible for every output, and competence plus confidentiality plus verification are mandatory. They diverge mainly on client disclosure. Some jurisdictions push toward disclosure for substantive use, while others, including the New York City Bar, treat embedded tools like Westlaw and Microsoft Word as requiring none.
Two 2026 developments matter most for agents specifically. Oregon State Bar Formal Opinion No. 2026-208, "Chatbots and AI Agent Communications," is the first U.S. state bar opinion to analyze autonomous AI agents as a distinct category, warning that chatbots making use of AI agents possess a greater level of autonomy and therefore create potentially greater risk from a legal ethics perspective, and advising that it would be prudent to subject autonomous learning or actions by a chatbot to lawyer approval. The State Bar of California's 2026 update to its Practical Guidance, requested by the California Supreme Court, addresses agentic AI directly, stating that its autonomy does not satisfy a lawyer's duty to exercise independent judgment, nor does it alter a lawyer's existing ethical obligations, and that the greater the degree of autonomy afforded to an AI system, the more important it is for a lawyer to implement supervisory controls.
The sanctions trend is the sharpest signal
It began with Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), where the court imposed a $5,000 Rule 11 sanction for six fabricated ChatGPT citations. The Second Circuit followed in Park v. Kim, 91 F.4th 610 (2d Cir. 2024), referring an attorney to its grievance panel for citing a nonexistent case. In Wadsworth v. Walmart Inc., 348 F.R.D. 489 (D. Wyo. 2025), the court fined the drafting attorney $3,000 and revoked his pro hac vice admission, with $1,000 fines for two others. In Coomer v. Lindell, No. 1:22-cv-01129-NYW-SBP (D. Colo. July 7, 2025), counsel for MyPillow's chief executive were fined $3,000 each for a brief with nearly thirty defective citations, and the court imposed a further $5,000 sanction in May 2026 for a repeat mis-citation. In Kohls v. Ellison, No. 24-cv-3754 (D. Minn. Jan. 10, 2025), the court struck an expert declaration whose fabricated citations, generated with ChatGPT, destroyed the expert's credibility with the court.
The severity is now rising, and courts are saying so explicitly. In Whiting v. City of Athens, 2026 WL 710568 (6th Cir. Mar. 13, 2026), the Sixth Circuit ordered two attorneys to pay $15,000 each, reasoning that smaller fines have plainly been inadequate, plus opposing appellate fees and double costs, though the court did not expressly attribute the fabricated citations to AI and grounded the sanction in the duty to read and verify every cite regardless of how it was generated. The largest aggregate to date came in Couvrette v. Wisnovsky, No. 1:21-cv-00157-CL, 2025 WL 4109655 (D. Or. Dec. 12, 2025), which the court called a notorious outlier in both degree and volume. Magistrate Judge Mark D. Clarke assessed a total of $110,204.38, applying a tariff of $500 per nonexistent case and $1,000 per fabricated quotation for a $15,500 sanction, then apportioning roughly $96,000 against pro hac vice counsel and roughly $14,000 against local counsel for failure to supervise (the precise per-lawyer apportionment and cents-level total rest mainly on legal-tech trackers; the rounded aggregate and the $15,500 court sanction are multi-source).
The volume is the story behind the headline cases. Damien Charlotin, a research fellow at HEC Paris's Smart Law Hub, maintains the public database of AI hallucination decisions; secondary auditing reports its count rising from roughly 200 cases in mid-2025 to 719 by January 2026, 1,227 by early April 2026, and 1,598 by June 9, 2026. That curve, not any single fine, is what firm leadership should read as the risk trajectory.
Courts are also legislating by standing order. Per trackers maintained by Ropes & Gray and Bloomberg Law, more than 300 federal judges have adopted some form of AI disclosure or certification requirement since Judge Brantley Starr of the Northern District of Texas issued one of the earliest orders in May 2023. Bloomberg Law analyst Emily Preston's April 16, 2025 analysis found that 39 federal judges had issued standing orders in the roughly two years since AI hallucinations first made headlines, a subset that has since grown. The orders require disclosure, certification, human verification, or some combination, and they vary enormously, from generative AI only to any AI tool. On January 28, 2026, the District of Kansas issued Standing Order 26-01, the first district-wide, court-wide AI rule covering every judge in the district.
Privilege is the quietest but most consequential risk
In United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 17, 2026), Judge Rakoff held that a defendant's exchanges with a consumer version of Claude were protected by neither attorney-client privilege nor the work product doctrine, because the tool is not an attorney, because the provider's privacy policy defeated any expectation of confidentiality, and because the materials were not created at counsel's direction. Two district courts have drawn a narrower line for work product. In Warner v. Gilbarco, Inc. (E.D. Mich. Feb. 2026) and Morgan v. V2X, Inc., 2026 U.S. Dist. LEXIS 67939 (D. Colo. Mar. 30, 2026), the courts treated AI as a tool rather than a third person for work product purposes, which is waived only by disclosure to an adversary. The practical takeaway is consistent across these decisions and the analyses of them by White & Case, K&L Gates, and Paul, Weiss: sending privileged material to a public, third-party AI provider under terms that permit training and disclosure risks waiver. Local inference on firm-controlled infrastructure changes that analysis because there is no transmission to an external third party at all. Notably, Judge Rakoff left the door open in dicta, suggesting that had counsel directed the client to use the tool, it might have functioned as a protected agent, which is precisely the distinction between an unsupervised consumer chatbot and a governed, firm-controlled deployment.
Client and institutional pressure is closing from the other direction
Outside counsel guidelines are being rewritten to specify which AI tools may touch client data, where that data is processed, and how AI use is disclosed. ACC sample guidelines show the direction of travel, and ABA Formal Opinion 512 requires informed client consent before confidential information is fed to a self-learning tool. Cyber insurers are moving fastest. Carriers introduced AI disclosure questionnaires at renewal in 2025, the Insurance Services Office introduced generative AI exclusion endorsements effective January 1, 2026, and some carriers now require proof of red teaming and documented risk assessments before extending coverage. Underwriters analyzing agentic deployments focus on three things: whether agents operate under least-privilege access, whether controls gate high-impact actions like data deletion or system changes, and whether the organization can monitor and detect abnormal agent behavior. Firms that can demonstrate governance certifications, including SOC 2, ISO/IEC 27001, and the newer ISO/IEC 42001 AI management system standard, are better positioned as underwriting tightens.
A staged framework a firm can act on
Stage one — inventory and classify
Identify every place an agent could act, and map each proposed use to the specific Model Rule it implicates and the applicable court and client requirements. Adopt the NIST AI Risk Management Framework's Govern, Map, Measure, Manage structure, and its Generative AI Profile, as the organizing spine.
Stage two — contain
Require that any agent run inside a sandbox with default-deny egress, least-privilege permissions, and downstream authorization, consistent with the OWASP LLM06 mitigation. Treat “the agent decided” as never an acceptable answer for an action the firm cannot reverse.
Stage three — keep sensitive matter data local
For privileged and highly confidential work, favor local inference on firm-controlled hardware, or enterprise instances with contractual bars on training and disclosure, precisely to avoid the Heppner problem.
Stage four — supervise and document
Assign a named partner responsible for AI oversight, require human verification of every citation and every outbound communication before it leaves the firm, and preserve an audit trail. This is Rule 5.1, Rule 5.3, and Rule 3.3 operationalized.
Stage five — disclose and insure
Update engagement letters and outside counsel responses, obtain client consent where confidential data will be processed, and align the firm's controls with cyber insurance questionnaires and a recognized standard such as ISO 42001.
The benchmark that should change any of these steps is simple. If a court in your jurisdiction adopts a district-wide disclosure rule, if your carrier attaches an AI exclusion, or if your client's outside counsel guidelines require local processing, the staged posture moves from advisable to mandatory. The governance layer does not make an agent safe to deploy. It makes deployment defensible. That is the standard the Model Rules, the sanctions docket, and the insurance market now demand.
Editorial notes
Claims resting on a single source (flagged in the body)
- The count of 15 formal opinions and 38 official instruments across jurisdictions as of June 2026 rests primarily on the legalaicompliance.help 50-state tracker. Other compilations give different numbers depending on whether task force reports and court rules are counted; some cite "more than 25 states." The convergence points (use permitted, lawyer responsible, verification required) are multi-source.
- The 1,598 hallucination-case figure originates with Damien Charlotin's database (HEC Paris), reported through a secondary auditor; the intermediate monthly counts are from that auditor and should be treated as approximate.
- The "more than 300 federal judges" figure comes from legal-tech trackers (Ropes & Gray, Bloomberg Law); the discrete count of 39 standing orders is from Bloomberg Law's April 2025 analysis. These measure different things and should not be conflated.
- The exact Couvrette aggregate of $110,204.38 and the per-lawyer apportionment rest mainly on legal-tech trackers; the rounded aggregate and the $15,500 court sanction are corroborated across multiple reputable outlets.
Corrections made to the original source draft
- OpenClaw is attributed to Austrian developer Peter Steinberger, not to NVIDIA or Anthropic.
- The OpenShell Privacy Router is described as operator-defined, policy-based routing, not as the agent autonomously classifying sensitivity in real time.
- "SELinux for agent governance" is labeled a commentator analogy, not an official NVIDIA product name.
To verify before further reliance
- The official F.4th reporter citation for Whiting v. City of Athens once assigned (currently available only as 2026 WL 710568).
- The Couvrette dollar figures and apportionment against the primary docket orders (2025 WL 4109655; fee order at Doc. 225).
- The exact amount and docket entry of the second Coomer v. Lindell sanction (reported as an additional $5,000 in May 2026).
- The final adoption status of any State Bar of California rule amendments on agentic AI (the 2026 Practical Guidance update is confirmed; related Board of Trustees rule proposals were in process as of the sources).
- Confirmation of the Warner v. Gilbarco pinpoint citation and docket number (reported as E.D. Mich., Feb. 2026, No. 2:24-cv-12333).
Source ledger
OWASP, NIST, and technical standards
ABA Model Rules and Formal Opinion 512
ABA Task Force and state guidance
Sanctions and standing orders
- AI hallucination cases sanctions tracker (HAQQ)
- AI hallucination sanctions tracker (Vaquill)
- Legal AI Governance case tracker
- Park v. Kim analysis (FDLI)
- Coomer v. Lindell sanction coverage (Reason/Volokh)
- Kohls v. Ellison opinion (PDF, UC Berkeley Law)
- Federal judge AI orders tracker (Law360)
- District of Kansas AI disclosure coverage
Privilege and work product
Outside counsel guidelines and insurance
Related LegalTek.ai reading
Matthew A. Mishak, Esq. is the Managing Attorney of Mishak Law LLC and the Founder and CEO of LegalTek.ai (SilverTung), an AI powered legal practice management and governance platform. He brings twenty years of Ohio legal practice across domestic relations, criminal defense, and municipal law, and is the architect of the COUNSEL framework operationalizing ABA Formal Opinion 512.
Disclaimer: This article is for general informational purposes only and does not constitute legal advice. Attorney review required before reliance. LegalTek.ai is a technology company, not a law firm.









