AI Data Protection for Law Firms Now Turns on Agent Access Scope
The State Bar of California issued a 2026 revision of its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law, replacing the 2023 version and addressing agentic AI at the request of the California Supreme Court. It warns that agentic systems with access to email, document management and client files raise acute confidentiality concerns, and that a lawyer must not permit autonomous external transmission of client information without safeguards and human review.

The State Bar of California's Committee on Professional Responsibility and Conduct issued a 2026 revision of its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law. It replaces the November 2023 version and, at the request of the California Supreme Court, addresses agentic AI. The guidance states that "the degree of lawyer diligence and supervision must correspond to the level of system access and autonomy." That sentence turns AI data protection law firms work into an access-scope exercise rather than a tool-approval exercise.
The distinction matters because the approval question and the access question have different answers. A firm can approve a vendor and still create an unbounded confidentiality exposure by connecting that vendor to the document management system without restriction.
TL;DR
- California's 2026 guidance ties required diligence to how much system access and autonomy the AI has, replacing a single tool-level judgment.
- Agentic systems connected to email, document management, client files or calendaring raise acute confidentiality concerns under rule 1.6 and section 6068(e)(1).
- A lawyer must not deploy an agent that autonomously transmits client information externally without appropriate safeguards and human review.
- Reasonable efforts require more than reliance on generalized marketing assurances, so read the terms and record what you found.
Access scope is the new confidentiality perimeter
The State Bar of California's practical guidance describes the exposure in concrete terms. Agentic systems "may be configured to access internal firm systems, such as email, messaging platforms, document management systems, knowledge bases, client files, or calendaring systems," and unlike isolated prompt-based tools they "may have persistent or automated access to large volumes of confidential client information."
The guidance then sets the duty: "Lawyers must carefully evaluate and limit the scope of such access," because "unrestricted or poorly configured agentic systems may unintentionally disclose confidential information (including across different matters) and even expose privileged material."
A firm's ethical wall lives in the document management permissions. An agent that inherits a broad service identity rather than a scoped one reads straight through that wall, and the guidance names disclosure across different matters as a specific risk of poorly configured agentic systems.
Autonomous transmission needs a human in the path
The guidance includes a direct prohibition. A lawyer "must not deploy an agentic AI system in a manner that permits autonomous external transmission of client information, including automated communications, filings, or data transfers, without appropriate safeguards and human review."
That sentence should be read as a configuration requirement. It means the firm needs to know, for each deployed agent, whether external transmission is possible at all, which destinations are reachable and what review step stands between a draft and a send.
Evidencing it requires three records per transmission: the client information the agent read, the content it produced and the identified person who released it. A firm that cannot produce the third record has no answer when a client asks who authorized a disclosure.
Reasonable efforts means reading the terms
On confidentiality, the guidance is explicit that a lawyer "should take reasonable steps to understand how a generative AI product collects, uses, stores, and discloses information provided by the user," and that "reasonable efforts require more than reliance on generalized marketing assurances." It names reviewing terms of use, privacy policies or vendor documentation, and notes that in some cases a user agrees to the terms simply by using the product.
The practical implication for a firm is a dated diligence record per tool, naming who reviewed which version of which document and what the finding was. The guidance also contemplates consulting qualified IT or cybersecurity professionals where circumstances warrant.
A tool approved in 2024 on terms that changed in 2026 is an unassessed tool. AI governance for law firms covers the committee and policy structure this record sits inside.
Informed consent has a trigger condition
The guidance frames consent around material risk: a lawyer should not input client confidential information into a generative AI solution that may present material risks to confidentiality or security absent informed client consent as to the underlying risks.
Two operational questions follow. Which of the firm's deployed tools are judged to present material risk, with the reasoning recorded. And for those, how consent is obtained and stored so that it can be produced for a specific matter years later.
Engagement letter language helps and does not finish the job, because the consent has to match the risk actually presented by the specific configuration in use. Legal AI privilege protection covers the privilege side of the same analysis.
Monitoring and access controls are named obligations
The guidance states that a lawyer "remains responsible for ensuring that any agentic AI system is configured in a manner consistent with their duty of confidentiality and that appropriate monitoring and access controls are implemented."
Monitoring here means seeing the traffic. For an agent that reaches firm systems and model endpoints over HTTP, that is achievable: record the identity the agent presented, the matter scope it touched, the destination it reached and the decision that permitted it. The NIST AI Risk Management Framework places the same expectation under MEASURE, which asks for dated evidence that a control operated rather than a statement that it exists. For an agent executing locally through a desktop integration, the HTTP path does not exist and endpoint controls carry the monitoring duty instead.
AI policy enforcement at the HTTP layer describes the managed path. Shadow AI in law firms covers the unmanaged path, which is where most firms actually lose client confidences.
Supervision extends to the configuration
Rules 5.1 through 5.3 obligations are addressed directly. Managerial and supervisory lawyers "should establish clear policies regarding the uses of generative AI, including more autonomous or agentic AI tools," provide training on tools "that perform tasks with limited or no real-time human direction," and review and update firm policies, controls and training as the technology changes.
Treat the agent configuration as a supervised work product. Someone named signs off on the access scope, the review step and the destination list, and that sign-off is dated and revisited when the vendor ships a new capability.
DeepInspect
DeepInspect is a stateless proxy for authenticated HTTP traffic between firm users or agents and LLM endpoints. It evaluates application-supplied identity, request classification, approved destination and policy before forwarding, and every permit, redaction, reroute or block produces a signed per-decision record outside the calling application's write path.
For a firm, that supports the monitoring and access-control obligations the guidance names, and it gives a destination list that an agent cannot transmit outside. DeepInspect does not make the privilege call, obtain client consent, review generated output or supervise a local desktop integration, all of which stay with the firm. Book a demo today.
Frequently asked questions
- Does the California guidance apply outside California?
The guidance binds California licensees, and its reasoning tracks duties that exist in substantially similar form in other jurisdictions, including confidentiality, competence and supervision. Firms with multi-state practices should check each applicable bar's current position, then configure to the strictest adopted standard rather than maintaining several configurations.
- What changed in the 2026 revision?
The 2026 Practical Guidance replaces the November 2023 version and addresses agentic AI at the request of the California Supreme Court, including the confidentiality implications of systems with persistent or automated access to firm systems and the limits on autonomous external transmission of client information.
- How do we limit an agent's access scope in practice?
Give the agent an identity of its own rather than a shared service account, scope that identity to specific matters or document libraries, and test the boundary. Place a marker document outside the intended scope and confirm the agent cannot retrieve it, then keep the dated test result as the evidence.
- What records answer a client question about AI use on their matter?
Per-request records covering the matter period that name the user or agent identity, the documents or data classes read, the destination model, the policy decision and the timestamp, plus the human review record for any content that left the firm. Those need to be retained for at least as long as the client file itself.