AI.

Israel’s Bar Association sets strict rules for lawyers using AI agents

Lawyers must supervise autonomous systems closely, protect confidential client information and verify AI-generated legal work before relying on it. 

While artificial intelligence offers tempting shortcuts, the National Ethics Committee of the Israel Bar Association has established a clear rule: autonomous systems and AI agents must not be permitted to make substantive legal decisions, provide independent legal advice, draft legal pleadings, or advance legal proceedings without close human supervision and approval.
In an updated position paper published on Thursday and signed by Adv. Menachem Moskowitz, Chair of the National Ethics Committee of the Bar Association, the committee clarifies that AI may serve as a supervised technical aid, but full legal and professional responsibility remains with the human lawyer. There is no substitute for human judgment. There are currently approximately 100,000 lawyers in Israel.
1 View gallery
צוות של סוכני AI עם אנליסטים אנושיים ליכולות מתקדמות
צוות של סוכני AI עם אנליסטים אנושיים ליכולות מתקדמות
AI.
(Photo: Canva)
Artificial intelligence systems are no longer limited to tools that generate a specific output in response to a user prompt. They can also include components or systems capable of operating with a higher degree of autonomy. These systems are sometimes referred to as “AI agents.” As a result, the committee says lawyers must recognize that as a system’s level of autonomy increases, so do the ethical, professional and procedural risks associated with its use.
An AI agent is essentially an artificial intelligence system capable of operating with a certain degree of autonomy when performing tasks, planning workflows, selecting tools and interacting with external systems or environments, without continuous human intervention.
The position paper states that “the rule is that autonomous systems or AI agents must not be used in a manner that allows them to make decisions in place of the lawyer,” including in matters concerning representation, independent legal advice, acts of representation vis-à-vis a client, court or third party, the filing of pleadings, service of binding documents or the advancement of legal proceedings without sufficient human oversight and approval.
However, the committee determined that there is no impediment to using such systems for technical, circumscribed, documented and reversible actions carried out pursuant to a prior human decision and subject to clear parameters, appropriate controls and human oversight.
The Bar clarifies that “the mere inclusion of an autonomous component or ‘AI agent’ in the system does not necessarily prohibit its use; however, it requires the lawyer to exercise heightened scrutiny regarding the suitability of the use for the purpose of representation, the nature of the actions the system is authorized to perform, and the actual level of human oversight applied.”
The bottom line is clear: “The lawyer bears personal and direct responsibility for every professional action, decision, piece of advice, argument, or output performed by them or on their behalf through the use of artificial intelligence systems.”
“A lawyer must protect client information, including privileged, confidential, and personal data, when using artificial intelligence systems, and must refrain from any use that could lead to unauthorized disclosure, a breach of privacy, or a violation of confidentiality and privilege obligations,” the statement reads.
Client privacy
The document also states that lawyers must refrain from entering “restricted information”, any non-public information provided to a lawyer that is subject to a legal, professional or ethical obligation to prevent its disclosure to third parties, into open, unsecured artificial intelligence systems, such as public versions of chatbots.
“Lawyers must avoid inputting restricted information into open AI platforms or any other usage environment where there is insufficient certainty that the information will remain protected at a level consistent with their professional obligations,” the paper states. “This rule applies not only to full documents or case files but also to partial information, case descriptions, email drafts, commercial data, medical information, unique factual details, and more.”
The Bar Association warns that simple “anonymization,” such as removing a client’s name or another identifying detail, does not necessarily provide sufficient protection, as sophisticated data cross-referencing could reveal the individual’s identity.
The National Ethics Committee further notes that even a “closed platform” does not exempt lawyers from their duty of care.
“The lawyer must examine the residual risks, including data storage methods, access permissions, logs, encryption, the system’s level of automation, and its interfaces with other systems.”
The paper defines a closed platform as an AI system subject to organizational obligations on the part of the provider regarding appropriate technical and organizational measures for information security, confidentiality and privacy concerning the data entered into it, as well as contractual commitments ensuring that the data remains in a controlled environment and is not used for public purposes or for training or improving the model.
What are clients entitled to know?
Must a lawyer disclose to a client that AI has been used? The document states that the mere use of a technological tool does not necessarily require disclosure in every instance, particularly when it involves routine, technical or ancillary use that does not involve exposing restricted information on an open AI platform.
However, transparency with the client will generally be required when the use of an AI system materially affects how the objectives of the representation are achieved; when the lawyer intends to enter restricted information or information related to the representation into an open AI platform; when the system is expected to materially influence the lawyer’s professional decision-making; when the client has requested information about the matter; when the client has issued guidelines, restrictions or procedures regarding AI use that have been brought to the lawyer’s attention; or when the use of the system is relevant to the basis of legal fees or expenses charged to the client.
The Bar emphasizes that “when a lawyer seeks to use restricted client information on an open AI platform, including instances where anonymization has been performed or is being considered, prior, explicit, and informed consent from the client is required if, under the circumstances, the anonymization does not sufficiently rule out the possibility of direct identification, indirect identification, re-identification, or linking the information to the client’s matter.”
Furthermore, as a general rule, a vague, generic or sweeping provision in engagement documents, a fee agreement or a power of attorney stating that the lawyer “is permitted to use artificial intelligence” does not constitute sufficient informed consent for such use.
Within the firm as well
Confidentiality and privilege obligations bind lawyers not only when information is transferred outside the firm, but also, in some circumstances, when information is shared within the firm itself.
Accordingly, the position paper states that “when an AI system is used, and even more so with a closed or integrated system, steps must be taken to ensure the system does not grant access to information to individuals who should not be exposed to it, even within the firm; this includes other firm employees, teams not handling the specific case, or lawyers separated by a technological ‘Chinese wall.’”
When an external provider is involved, the paper says firms must also secure clear and effective contractual obligations ensuring that information entered into the system, as well as the results of its training, outputs, metadata and usage patterns associated with it, is not made available to other clients of the provider or included in an external database outside the firm’s control.
Furthermore, when an AI system is provided by an external vendor, the firm and the lawyer using it must verify, to a reasonable extent and in light of the circumstances, that the provider is contractually, operationally and technologically committed to protecting client information.
This includes examining whether the provider commits to not sharing information with third parties; not using the information to train or improve the model without appropriate consent; not including the information or the results of its processing in external databases outside the firm’s control; and maintaining reasonable standards for information security, access control, data deletion and data retention.
Beware of “hallucinations”
Beyond its restrictions on the use of autonomous systems without human oversight, the Bar Association warns against “hallucinations”, situations in which AI systems fabricate court rulings, citations or legal sources that appear credible but are entirely erroneous.
The committee notes that lawyers have already submitted documents containing fabricated rulings to courts and warns that blind reliance on computer-generated outputs can lead to sanctions, reputational damage and disciplinary measures.
“A lawyer must be aware of the inherent risk associated with these systems, which are not necessarily designed to provide factually correct or legally accurate information; rather, they often generate a ‘statistically probable’ or superficially satisfying response that appears plausible and convincing, even if it is erroneous, incomplete, outdated, biased, or based on flawed premises,” the document states.
The Bar Association further notes that “AI outputs may provide a lawyer with insights, recommendations, lines of reasoning, drafting assistance, or an initial basis for work. However, they cannot substitute for the human professional action or judgment required in any legal matter, judgment based on a factual and professional examination of all relevant aspects.”
“A lawyer’s personal and direct responsibility for their actions, advice, drafted legal documents, opinions, and filed pleadings remains absolute; they may not hide behind AI outputs that appear to be professional work products, nor may they place ‘blind reliance’ upon them.”
Finally, the committee determines that “failure to comply with the provisions of this position paper may constitute prima facie evidence, albeit rebuttable, that the lawyer has not met their ethical obligations regarding the use of such tools.”
Conversely, compliance with the provisions of the position paper will serve as a significant indication that the lawyer acted ethically and reasonably. However, such compliance will not, in itself, absolve the lawyer of the duty to act in accordance with applicable law and to exercise case-specific judgment in each instance.