Guide · Updated August 2026
Using AI for discovery responses under California's ethics guidance
This guide is educational information for attorneys, not legal advice, and it is not a substitute for reading the State Bar's guidance itself. It is published by Data Lab Inc., the company behind Propound — we state that up front so you can weigh what follows accordingly. Wherever possible we link the primary sources.
What the State Bar has actually said
The State Bar of California's Standing Committee on Professional Responsibility and Conduct (COPRAC) issued its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law in November 2023, and replaced it with a revised 2026 version — updated at the request of the California Supreme Court to address newer technology, including agentic AI. The through-line of both versions: your existing ethical duties apply to AI the way they apply to any technology. There is no AI exemption from the Rules of Professional Conduct, and no AI prohibition either.
Separately, the State Bar has proposed amendments to the Rules of Professional Conduct that would move several of these principles from guidance into binding rules — including an express duty to independently review and verify AI output (Rule 1.1), treating exposure of confidential information to AI systems as a form of revealing it where it creates material risk (Rule 1.6), and verifying that cited authorities are real and accurately characterized (Rule 3.3). The public comment period closed in May 2026; the proposals await further action and Supreme Court approval. Even unadopted, they show clearly where California is heading: use is permitted, verification is mandatory, and confidentiality is the line that cannot move.
What this means for discovery practice specifically
Discovery responses are where these duties collide with the most tempting use case. Responding to a full set of interrogatories is high-volume, deadline-driven, and formulaic in structure — exactly what generative AI is good at. It is also saturated with confidential client information: names, addresses, medical facts, finances, vehicle identifiers, the client's own words. Four duties do most of the work here.
1. Confidentiality (Rule 1.6, Bus. & Prof. Code § 6068(e))
The guidance is blunt on this point: a lawyer must not put confidential client information into an AI product that will use those inputs to train its models or to answer other users, and should understand a tool's security, retention, and data-use practices before using it — consulting IT or security professionals where needed. For discovery work, that means the question to ask about any tool is not "is it accurate?" but "where does my client's information go when I press generate, who stores it, for how long, and what else is it used for?" If the vendor cannot answer those questions in writing, the analysis ends there.
2. Competence and verification (Rule 1.1)
Every draft an AI produces is a draft for your judgment. In discovery practice the failure modes are concrete: an objection that doesn't fit the request, a response that concedes a fact the file doesn't support, a fabricated or misdescribed citation. The duty of competence — and the proposed rule amendment, expressly — requires independent review of every output before it goes out under your signature. A tool that makes review easy (showing you what it drew from, flagging what it could not verify) supports that duty; a tool that invites one-click bulk sending undermines it.
3. Candor (Rule 3.3) and the signature you put on the response
Discovery responses are verified under penalty of perjury and served under your name. Case law sanctioning attorneys for AI-fabricated citations is no longer novel; the proposed Rule 3.3 amendment would make checking AI-cited authority an express obligation. Treat every citation and every factual assertion in an AI draft the way you would treat a first-year associate's — as unverified until you have checked it.
4. Communication and supervision (Rules 1.4, 5.1, 5.3)
The guidance asks lawyers to consider disclosing AI use to clients where it is significant to the representation, and the proposed amendments would require disclosure where AI use presents significant risk or materially affects the matter. Firms should also decide — deliberately, in writing — which tools staff may use and how. A one-page internal AI policy costs an afternoon and answers a question every malpractice carrier is starting to ask.
A vendor-neutral checklist for evaluating any AI tool
Whether you're evaluating Propound or any competitor, these are the questions the guidance effectively requires you to be able to answer:
- Where does matter content live? On your machine, or on the vendor's servers? If the vendor's, under what retention policy?
- Is your data used for training? Get it in writing — not from a sales call, from the terms.
- What actually leaves your computer when you use the AI features? The full file? A redacted excerpt? Ask for specifics.
- Can client identifiers be masked before anything is transmitted? Automatically, or does it depend on you remembering?
- Does the workflow force review? Can you see and edit every response before it is exported and served?
- What does the vendor log? Usage metadata is normal; the substance of your requests should not be.
- Can you answer a client's or a court's question about all of the above? If the vendor's documentation doesn't let you, that is itself the answer.
How Propound is built against this standard
We built Propound for California discovery practice with this guidance as a design constraint, not a compliance afterthought. Concretely: your cases, documents, drafts, and chat history live in a local database on your Mac — our servers store your account, subscription, and usage counts, not your matter content. Before any AI request leaves the app, detected client identifiers (names, addresses, VINs, case numbers, phone numbers, emails, and identifiers you add yourself) are replaced with placeholders by default and restored only on your screen. Every generated response lands in an editor for your review — flagged where the AI could not verify something — before anything is exported for service. And a pre-service check looks for surviving placeholders and unverified flags before you export. The Privacy Policy and Terms say all of this in binding words rather than marketing ones.
None of that removes your obligation to review what you sign — nothing can, and the State Bar's direction of travel makes that plain. The design goal is narrower: that when you ask the checklist questions above about Propound, the answers are short, verifiable, and boring.
Sources