California is now the first state to specifically regulate attorneys’ use of generative AI by statute. On September 30, 2026, Governor Newsom signed SB 574, which adds a new Section 6068.1 to the Business and Professions Code, amends Code of Civil Procedure Section 128.7 (California’s counterpart to Federal Rule 11), and adds new rules for arbitrators. Because the bill has no urgency clause, it should take effect January 1, 2027.
Much of SB 574 codifies what courts and the State Bar have been saying for the past two years, e.g., attorneys have always been required to verify citations. Some of it goes further. Most significantly, attorneys must disclose their use of generative AI to the court in every document they submit. Given how widely these tools are now used, that will touch most filings in California courts.
Consequently, any firm with attorneys practicing in California should update its AI policy before January 1, 2027, and provide mandatory training on the new law.
No Delegating the Practice of Law to AI
New Section 6068.1(a)(2) states that “[a]n attorney shall not delegate the practice of law to generative artificial intelligence.” The statute does not define what counts as delegation, and that is a broad standard to leave undefined.
A solid reading is that AI can assist, but a licensed attorney has to make the legal judgments and own the work product. The statute reinforces this by stating that nothing in Section 6068.1 abrogates an attorney’s existing duty of competence and diligence. Using AI to draft a first pass of a brief that an attorney then reviews, revises and stands behind should be fine. Sending AI-generated advice to a client or filing AI-generated work without meaningful attorney review is where it gets more dangerous. Expect this line to get worked out through State Bar guidance and discipline cases over time.
Confidential Information and Tool Selection
Section 6068.1(a)(3)(A) is new and goes beyond the typical hallucination-related sanctions we’ve all seen handed down. It bars attorneys from entering confidential, personal identifying or other nonpublic information into a generative AI system unless access to those inputs is restricted to the attorney and people the attorney has authorized and are under obligations to protect the information.
Some early coverage has described this as a flat ban on putting confidential information into AI. The statute is narrower than that. The test is who can access what you input. An enterprise tool with strong confidentiality terms, limited data retention (Fable?) and no vendor access to inputs should satisfy it. A consumer tool whose terms let the provider retain, review or train on user inputs likely will not.
Turning off model training is a good start, but it may not be enough on its own. If the vendor keeps inputs for abuse monitoring or allows human review, people outside the attorney’s control may still have access. Firms need to read the actual data retention and review terms for each tool they approve.
The statute also defines “personal identifying information” broadly. It includes driver’s license and Social Security numbers; dates of birth; addresses and phone numbers of parties; victims; witnesses; court personnel; medical and psychiatric information; financial information; account numbers; and anything sealed or deemed confidential by court rule or statute.
Verifying and Correcting AI Output
Section 6068.1(a)(3)(B) requires attorneys to take reasonable steps to verify the accuracy of AI outputs, “including, but not limited to, the accuracy of all case and statutory citations,” and to correct any erroneous or hallucinated output in any material the attorney uses.
First, the duty covers all AI output, not only citations. Factual summaries, deposition digests, contract analysis and research memos all fall within it. Second, it applies to “any material used by the attorney,” which reaches client advice and internal work product, as well as court filings. A hallucinated case in a client memo is now a statutory problem in California, even if it never reaches a judge – that’s a big deal.
Disclosing AI Use to the Court
Section 6068.1(a)(3)(C) requires attorneys to “[d]isclose the use of generative artificial intelligence to the court for all documents submitted to the court.” It also requires attorneys to consider whether to disclose AI use in content provided to the public.
This is the provision that will change day-to-day practice the most. Courts around the country have adopted standing orders requiring AI disclosure, but those are judge-specific. SB 574 makes disclosure a statewide statutory obligation for every document submitted to a California court.
At this point, generative AI is built into legal research platforms, word processors and document review tools. Many attorneys use it on nearly every filing, sometimes without thinking of it as “using AI.” The statute does not say how detailed the disclosure needs to be or whether incidental uses count. Until courts or the state provide guidance, the safer course is to assume any meaningful use of generative AI in preparing a document triggers disclosure.
I expect most firms will handle this with a standard disclosure paragraph at the end of each filing, similar to a word-count certification. Firms should draft that language now, decide who in the matter team is responsible for confirming whether AI was used and build the step into their filing checklists.
Sanctions Under CCP Section 128.7
SB 574 gives these requirements teeth by amending Section 128.7. New subdivision (b)(2) provides that a brief, pleading, motion or other paper filed in any court “shall not contain any citations that an attorney responsible for submitting the pleading has not personally verified, including any citation provided by generative artificial intelligence.”
Courts could already sanction attorneys for fake citations under Section 128.7’s existing certification requirements. The amendment adds a specific, personal verification duty that is easier to apply. “Personally verified” suggests that relying on a paralegal, junior associate or citation-checking tool, without the responsible attorney confirming the citations, may not be enough.
A few procedural points are of relevance here:
- The existing 21-day safe harbor (just like FRCP 11) still applies. An attorney who withdraws or corrects the challenged paper within 21 days of service of a sanctions motion or order to show cause can avoid sanctions.
- Monetary sanctions for a citation violation under (b)(2) cannot be imposed on a represented party. The financial exposure falls on the attorneys and their firm.
- Absent exceptional circumstances, a law firm is jointly responsible for violations committed by its partners, associates and employees. A single attorney’s failing becomes the entire firm’s problem.
What Firms Should Do Before January 1
Most firm AI policies were written around ethics opinions and general best practices. SB 574 turns several of those best practices into statutory duties with sanctions attached and adds a prohibition on the entry of confidential information and a disclosure requirement most policies do not address. Firms with attorneys licensed in, or appearing before, courts in California, including attorneys admitted pro hac vice, should update their AI policies now, or, if they don’t have a policy, get one.
The statute does not expressly say whether Section 6068.1 reaches pro hac vice counsel, so that point is not entirely settled. It very likely does, since attorneys admitted pro hac vice are subject to the State Bar’s disciplinary jurisdiction, and the Section 128.7 amendments apply to filings in California courts regardless of where the signing attorney is licensed.
At a minimum, the updated AI policies should cover the following:
- Approved tools. Review the data retention, human review and training terms for every AI tool in use. Approve only tools that restrict access to inputs as Section 6068.1(a)(3)(A) requires and prohibit consumer tools for any client or case information.
- What can go in. Give attorneys and staff a clear rule on what information may be entered into which tools, using the statute’s definition of personal identifying information as the floor.
- Attorney review. State that AI output is a draft, and that an attorney must review and take responsibility for any AI-assisted work before it goes to a client, a court or opposing counsel.
- Verification. Require the responsible attorney to personally verify every citation in every court filing and document that step in the filing checklist.
- Court disclosure. Adopt standard disclosure language for California filings, decide who confirms whether AI was used on a given document and make the disclosure part of the pre-filing review.
Firms practicing in multiple states should consider applying these rules firm-wide. Much like CCPA in the data privacy context, other states are likely to follow California’s lead with regard to SB 574, and running one set of AI rules for California matters and another for everywhere else invites mistakes.
Our Artificial Intelligence Industry Team tracks AI court decisions and regulations throughout the country. If you have questions or concerns about AI-related matters, please reach out to attorney Brendan M. Palfreyman at (315) 214-2161 and bpalfreyman@harrisbeachmurtha.com, or the Harris Beach Murtha attorney with whom you most frequently work.
This alert is not a substitute for advice of counsel on specific legal issues.
Harris Beach Murtha’s lawyers and consultants practice from offices throughout Connecticut in Bantam, Hartford, New Haven and Stamford; New York State in Albany, Binghamton, Buffalo, Ithaca, New York City, Niagara Falls, Rochester, Saratoga Springs, Syracuse, Long Island and White Plains; as well as in Boston, Massachusetts; Providence, Rhode Island; and Newark, New Jersey.