Legal technology governance

California's 2026 AI Guidance: A Firm Checklist

California's updated AI guidance addresses agentic systems and gives law firms a practical governance checklist for supervision, confidentiality, and review.

Four legal professionals reviewing an agentic AI workflow map with a highlighted human approval checkpoint in a modern law office.
Editorial illustration for this article.

Published 2026-08-17 · Updated 2026-08-17 · By The Hammer Lex Editorial Team

Quick answer

The State Bar of California approved updated practical guidance on May 14, 2026, replacing its 2023 guidance and adding specific discussion of agentic artificial intelligence. The update matters beyond California because it shows how professional-responsibility duties are being translated into operational expectations for tools that can plan, act, and iterate with limited prompting.

For a law firm, the useful response is a workflow-level control system: inventory the tools already in use, classify the data and authority each tool can access, set a named human approver, preserve an audit trail, and define when an agent must stop. California's guidance is not a universal rule for every lawyer, but it is a useful benchmark for designing a responsible AI program.

This article is informational and not legal advice. Professional-responsibility, confidentiality, billing, data-protection, and court-filing requirements vary by jurisdiction, client, and matter. Consult qualified counsel and the applicable bar or court authority before changing your firm's practices.

What California changed in 2026

The State Bar's updated Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law replaces the November 2023 version. The State Bar says the revision reflects newer developments, including agentic AI, and clarifies how existing professional duties apply when lawyers use these technologies.

The underlying shift is important. A conventional drafting assistant usually waits for a person to ask for an output. An agentic system may be configured to break a goal into steps, call other tools, retrieve information, update a record, or continue iterating. The label matters less than the capability: the system can create a chain of actions that is harder to review as one isolated response.

The State Bar's supporting materials describe agentic AI as automated programs that can plan and execute tasks and work toward a defined goal with minimal or no human intervention. The guidance still operates through familiar duties—competence, confidentiality, communication, candor, supervision, and professional judgment—but the operational question becomes sharper: who approved the chain of actions, what could it access, and what evidence shows that the final work was reviewed?

California's move follows an August 2025 directive from the Supreme Court of California asking the State Bar to consider AI-related rule comments, including the use of agentic tools. The State Bar also published proposed amendments addressing competence, communication, confidentiality, candor toward the tribunal, managerial responsibilities, and supervision of nonlawyer assistants. Those proposals and the practical guidance are related, but they are not the same thing; firms should track their status separately.

Why agentic AI changes the governance problem

The governance challenge is not simply that an agent may produce an incorrect sentence. It is that a tool may make several individually plausible decisions whose combined result creates a professional or business risk.

Consider an intake workflow that reads a web form, classifies the matter, searches a conflicts database, drafts a response, and creates a task for a lawyer. Each step may look administrative. Together, the workflow can affect who receives a response, what information is stored, whether a potential conflict is escalated, and what the firm implicitly promises to a prospective client.

Or consider a litigation assistant that retrieves authorities, summarizes a record, proposes citations, and inserts language into a draft. The final document may appear polished while the system has silently used the wrong jurisdiction, missed a qualifying fact, or relied on a source that a lawyer has not checked. A review step at the end is necessary, but it may be insufficient if nobody can reconstruct the inputs and intermediate actions.

The practical distinction is between output review and process control:

  • Output review asks whether the final text, classification, or task is accurate and appropriate.
  • Process control asks what the system was allowed to do, what information it touched, what it changed, and where a person had to approve the next step.

Small firms do not need an enterprise AI laboratory to implement both. They need a short, maintained record for each meaningful AI-assisted workflow.

A five-part checklist for law-firm leaders

1. Inventory capabilities, not product names

Start with the work people are actually doing. Ask attorneys, paralegals, intake staff, and administrators which tools can summarize, draft, search, classify, transcribe, send, update, or trigger another system. Include AI features embedded in practice-management, research, document, email, and meeting tools.

Record at least:

  • the workflow and business owner;
  • the tool, model, or feature involved;
  • whether the system only suggests or can take an action;
  • the information it receives and the systems it can reach;
  • the person responsible for approving the result; and
  • the date for the next vendor or workflow review.

An inventory built around product names becomes stale quickly. An inventory built around capabilities remains useful when a vendor adds a new agent mode or changes a default.

2. Define the boundary before enabling autonomy

Every agent should have a written boundary. The boundary should answer what the agent may read, what it may create, what it may change, and what it may never do without approval.

For example, an intake agent might be allowed to normalize public web-form data and prepare a draft acknowledgment. It might not be allowed to decide that the firm has accepted representation, provide legal conclusions, search unrestricted client folders, or send a message that creates a deadline or commitment without human approval.

Use simple permission levels:

  1. Suggest: the system produces a draft or recommendation only.
  2. Prepare: the system may organize information or create a queued task, but a person approves the action.
  3. Execute with guardrails: the system may complete a narrow, reversible action within a defined scope.
  4. Prohibited: the system may not perform the action, even if a user asks informally.

The point is not to make every workflow slow. It is to make autonomy deliberate and reviewable.

3. Put a human checkpoint where judgment is required

“A lawyer reviews the output” is too vague to operate as a control. Identify the actual decision that requires professional judgment and assign it to a named role.

For legal research, the checkpoint may require verifying each authority against a primary source and confirming that the cited proposition is supported. For client communications, it may require checking scope, tone, facts, confidentiality, and whether the message could be understood as advice or an engagement decision. For intake, it may require a lawyer or trained supervisor to review conflicts and urgency before the matter is advanced.

The checkpoint should be visible in the system: a status, approval field, task, or stored review note. If the only evidence is a person's memory that they looked at a screen, the control will be difficult to test, train, or defend.

4. Preserve enough evidence to reconstruct the work

The firm does not necessarily need to preserve every prompt forever. It does need to decide what evidence is appropriate for the risk and the matter. A useful record might include the tool version, date, user, source files, output, reviewer, corrections, and approval status.

Retention should match the firm's obligations and client agreements. Do not create a new repository of sensitive prompts without considering access controls, retention, export, and deletion. The record is valuable only if it is protected and can be found when a matter owner needs it.

This is where an AI policy and the practice-management system should meet. If the review record lives in a separate spreadsheet no one checks, the policy describes an aspiration rather than the firm's real control.

5. Test failure modes before expanding the workflow

Agentic workflows should be tested with ordinary matters and deliberate edge cases. Test missing information, conflicting instructions, unusual names, duplicate records, stale authorities, permission failures, vendor outages, and a user attempting to bypass the approval step.

For each test, record the expected stop condition. The agent should stop when it reaches an action outside its authority, cannot verify a source, detects an ambiguity that could affect the matter, or cannot protect the required information. A clear stop condition is more useful than a general warning to “use caution.”

What this means for a small firm

The State Bar guidance does not require every small firm to deploy agents or to buy a governance platform. It does suggest a disciplined order of operations:

First, find the unofficial use

Ask what staff already use, including consumer tools and features hidden inside approved software. A firm cannot assess confidentiality or supervision risk for tools it does not know exist. The conversation should be framed as discovery, not punishment, or people will conceal the most useful information.

Second, select one bounded workflow

Choose a workflow with a clear input, output, owner, and review step. A first pilot might be internal matter-status summarization or a draft task list from a meeting transcript. Avoid beginning with an autonomous client communication, court filing, conflicts decision, or fee calculation.

Third, connect the approval to the matter record

Store the result, reviewer, and decision where the firm already manages the matter. This reduces the gap between the written policy and actual operations. It also makes it easier to answer a client or internal reviewer who asks how a result was produced.

Fourth, measure both speed and reliability

Track turnaround time, correction rate, review completion, escalation frequency, and the time required to recover from errors. If the workflow is client-facing, add client response time and rework. Faster output is not a success if it shifts the burden to a lawyer who must silently repair it.

Fifth, set a review date

Agentic tools change through vendor updates, new permissions, integrations, and model behavior. Revisit the workflow after a material product change and on a regular calendar. Treat the review date as part of the workflow, not as a one-time implementation task.

How to explain the change to clients

Clients may ask whether the firm uses AI, whether their information is used to train a model, who reviews the output, and whether the use changes fees or the quality-control process. The firm should be able to answer those questions accurately for its actual configuration.

The answer should be plain language, specific to the service, and consistent with the engagement agreement and applicable professional duties. Do not promise that AI is never used if embedded features operate in the firm's systems. Do not describe a human review step that is not reliably performed. Trust is damaged more by a vague or inaccurate assurance than by a candid explanation of a bounded tool.

The ABA's Formal Opinion 512 remains a useful national reference point for questions involving competence, confidentiality, communication, candor, and fees. California's 2026 guidance adds a current example of how those duties are being considered as systems become more autonomous. Neither source replaces the rules that apply in the jurisdiction and matter at hand.

The management takeaway

Agentic AI turns software governance into service governance. The firm is no longer evaluating only whether a tool writes a good paragraph. It is deciding how much authority to delegate, what the system may know, which actions require approval, how the firm proves review occurred, and how it responds when the technology changes.

That is a manageable problem when it is attached to a real workflow. Start with one process, one owner, one boundary, and one visible human checkpoint. The result will be more useful than a broad promise to “use AI responsibly,” and it will give the firm a foundation for evaluating future tools with less guesswork.

For related operational context, see Post-AI Lawyering: What Firms Should Change Now and Legal Technology's Expanding Fault Lines.

Frequently asked questions

Does California's 2026 guidance apply to every law firm?

No. It is guidance from the State Bar of California and should not be treated as a single nationwide rule. Firms should use it as a useful benchmark while checking the rules, opinions, court requirements, client obligations, and technology contracts that apply to their own work.

What makes an AI tool agentic?

An agentic tool can do more than return one response to one prompt. It may plan a sequence, use connected tools, retrieve or change information, and continue toward a goal with limited human prompting. The exact marketing label is less important than the system's real permissions and ability to take action.

What is the best first agentic AI use case for a small firm?

Start with a bounded internal workflow that has low-risk inputs, a reversible output, a named owner, and a visible review step. Internal status summaries or draft task lists are usually easier to control than autonomous client messages, conflicts determinations, court filings, or fee decisions.

Does a human review at the end solve the risk?

Not by itself. The reviewer also needs to know what the system accessed, what it changed, and what claims or decisions require verification. A final review should be paired with permission limits, stop conditions, and enough evidence to reconstruct the process.

Should a firm update its AI policy now?

It should review the policy if the firm uses tools that can act beyond a single draft or if the current policy does not describe actual usage. Focus the update on capabilities, data boundaries, human approval, records, vendor changes, and escalation. Have qualified counsel assess the final policy against the firm's jurisdictional and client-specific obligations.

Source and context: This article is informational and is not legal advice. Verify current details with the linked source and qualified counsel where appropriate.

Sources

Make responsible automation visible

Connect people, matters, documents, deadlines, billing, and review steps so your firm can scale useful automation with accountability.

Book a demo

More industry articles · Free law-firm tools