AI Answer Summary
In Johnson v. Dunn, a federal court sanctioned three lawyers at a firm of more than 350 attorneys for filing citations fabricated by ChatGPT, and released the firm itself. The court found the firm had acted reasonably to prevent the misconduct, pointing to a written policy, a warning from its general counsel, and an AI committee.
That release came under the court's inherent authority, which requires bad faith. Rule 11 did not apply because the filings were discovery motions. Under Rule 11, a firm is held jointly responsible for its lawyers' violations absent exceptional circumstances.
So a law firm AI policy is how a firm separates its own liability from an individual lawyer's. The same opinion also documents five gaps in that firm's policy, each one visible in the lawyers' own sworn declarations.
What a Law Firm AI Policy Is For
A law firm AI policy is not a compliance document. It is how the firm separates its own liability from an individual lawyer's, and one federal court has now shown that working in both directions at once.
The case is Johnson v. Dunn, 792 F. Supp. 3d 1241, decided in the Northern District of Alabama in July 2025 by Judge Anna Manasco. Butler Snow was representing a former Alabama corrections commissioner in prison litigation. A partner, revising two discovery motions, asked ChatGPT for supporting authority and dropped the results in without checking them. Five citations were fabricated. The lawyer who drafted the motions incorporated the edits and filed them. The practice group leader's name sat in the signature block.
Here is the part that matters for anyone writing a policy. The court cited the firm's warnings and controls as the reason the firm acted reasonably. It also cited the same warnings and controls as the reason a fine was not enough for the three individuals. In the court's words, they benefitted from repeated warnings, internal controls, and firm policies about the dangers of AI misuse. And yet here we are.
A policy moves exposure from the institution onto the person. Whoever drafts one should know that before they start.
The Five Gaps a Federal Court Found in One Firm's AI Policy
Butler Snow had a policy and it did not prevent this. The opinion records why, in the lawyers' own declarations and hearing testimony, which makes it the closest thing the profession has to a published audit of a real firm's AI governance. Every gap below is one you can check against your own firm this week.
Nobody Owned the Signature Block
The firm's general counsel told the court the firm had no specific policy on who appears in a signature block. It was left to the individual lawyer's discretion. Three names appeared on motions that none of them had verified, and the court held all three responsible.
The court also noted a case where attorneys were sanctioned despite never seeing the filing, because they had let others use their signatures. The duty to make sure a filing is supported by existing law does not transfer.
What to write instead: the policy names who may appear in a signature block, and states that appearing there is a personal commitment to having verified the document.
Practice Group Leaders Were Exempt From Their Own Rule
The firm's 2023 policy required written permission from a practice group leader before anyone used generative AI as a secondary research tool. At the hearing, counsel for the firm confirmed that practice group leaders themselves did not have to ask anyone.
The lawyer who used ChatGPT was an assistant practice group leader. The control applied to everyone below the level of the person who broke it.
What to write instead: no seniority exemption, and the approval route never runs through the person being approved.
Juniors Did Not Check a Senior's Citations
The lawyer who signed and filed both motions told the court that in his normal practice he does not typically check citations added by his supervisors. The practice group leader testified that he would not have expected him to, since the lawyer adding authority was understood to be responsible for it.
Neither of them described this as a lapse. They described it as how the group worked, and a policy that says "verify everything" does nothing against a workflow built on the opposite assumption.
What to write instead: the signing lawyer verifies every authority in the document, whatever its source and whoever inserted it.
Recycled Text Was Treated as Already Verified
The practice group leader explained that because the group's cases share facts and law, the team routinely pulled authority from earlier filings and dropped it into new ones. The court observed that this appeared to happen without re-verification, and that checking the research for each case was not something he required of his team.
Nobody used AI to do that. It is the same failure with a different source.
What to write instead: material reused from an earlier filing counts as unverified, because authority moves and the earlier filing may have been wrong too.
No Prefiling Verification Step Existed
After the sanctions order, the firm committed to a prefiling protocol requiring review of all legal authority in any document filed with a court, confirming the existence, accuracy and relevance of each citation. That protocol is the single control most likely to have caught all five fabrications. It arrived after the fact.
What to write instead: the protocol exists before anything is filed, and someone signs that it ran.
Look at the five together. Every one is a workflow assumption rather than a technology decision, and not one would have been fixed by choosing a different AI tool.
Why the Firm Escaped Sanction, and What Would Have Changed It
The firm's release turned partly on which rule applied, and the rule that applied was an accident of the filings involved.
What the court found about the firm. Judge Manasco concluded that Butler Snow acted reasonably in its efforts to prevent the misconduct and doubled down on its precautionary measures once it surfaced. She listed what persuaded her: a June 2023 email from the firm's general counsel warning that model output could appear perfectly researched and logical while being wholly inaccurate, the permission policy, the AI committee, lawyers at the firm publishing articles on the risks, and an escalated response after the show cause order. On that record there was no basis to find the firm acted in bad faith.
Why bad faith was the test. Rule 11 does not reach motions brought under Rules 26 through 37, and both filings were discovery motions. The court called this an unintended anomaly, noted that the discovery rules themselves gave it no basis to act, and fell back on its inherent authority. Inherent authority requires bad faith or something close to it, which is a high bar for a firm to clear.
What Rule 11 would have meant. Under Rule 11, a law firm must be held jointly responsible for a violation by its partner, associate or employee, absent exceptional circumstances. The court said plainly that but for the discovery-motion exception, the filing lawyer's conduct would have been a textbook Rule 11 violation.
Our reading, and we are labelling it as such: the policy was credited, and it was credited under the more forgiving of two possible standards. A firm treating its AI policy as a liability shield should plan on the harder one.
Who Else Is Writing Rules for Your Firm
Four parties are setting rules for your firm's AI use, and only one of them is your bar association.
The client row needs care, because the headline number is easy to misread.
Fulkerson Advisors searched 1,054 outside counsel guidelines written since ChatGPT's release and found that 2% mention AI at all. The method is published and so is the underlying data, which is rare in this field. But the researchers are clear about the sample's limits: companies mostly deliver guidelines through private portals and never publish them, so 86% of the documents came from public bodies and universities, and only 24 came from companies.
Among those 24 companies, three had AI terms: Microsoft, Zscaler and A&K Travel. Banks and insurers in the sample had them at similar rates, including UBS and The Hartford. So the accurate reading is that published guidelines are overwhelmingly silent, and the sophisticated private clients whose guidelines stay private are the ones most likely to have written something.
What they ask for is concrete. Of the 20 guidelines that mention AI, 12 require the firm to disclose when it was used, 9 keep client information out of public tools, 8 require a lawyer to review the output, and 3 require the firm to have its own AI policy on file. Zscaler's guidelines ask timekeepers to note generative AI use in the time entry itself. The trend is small and rising: 2 of the 220 guidelines dated 2024 mention AI, 8 of 365 dated 2025, and 10 of 261 dated 2026.
The court row is best shown with one state. Illinois has a Supreme Court policy stating that disclosure of AI use should not be required in filings, and individual courts there have issued standing orders requiring it anyway. A firm operating entirely inside one state can still have matters where disclosure is mandatory. No firm-wide policy can answer that question in advance. It can only make sure someone checks.
The Eight Decisions Your AI Policy Has to Settle
Eight decisions, and the drafting is the easy part.
Two of these get written badly more often than the rest.
Verification is where policies write an aspiration instead of a process. "All AI output must be verified" is a sentence nobody can follow or audit. "The lawyer who signs opens every cited authority in Westlaw or Lexis before filing" is a sentence someone can be held to, and it covers recycled text and a senior colleague's insertions without needing to mention either.
Billing belongs in the policy because it is a conduct rule rather than a finance preference. On hourly work, ABA Formal Opinion 512 requires billing the time spent, so a tool that compresses the work compresses the invoice. Our guide to legal billing automation covers what that does to realisation.
What the eight have in common is that each one names a person rather than a principle. The five gaps in the previous section were all places where a principle existed and no person was responsible for it.
Where to Get Drafting Language Without Paying for It
A disciplinary regulator has published templates for free, and they are better sourced than anything you will be sold.
The Illinois Attorney Registration and Disciplinary Commission issued the Illinois Attorney's Guide to Implementing AI in October 2025, aligned with the Illinois Supreme Court's AI policy. It includes a sample policy covering supervision, review and error management, a sample notice of AI practices for telling clients how the firm uses AI, and a checklist for reviewing an AI provider's terms of use, covering data security, privacy, update protocols and liability.
The State Bar of Texas AI Toolkit serves a similar purpose alongside that state's ethics opinion.
Our advice is to take the drafting language from a regulator and spend your own time on the eight decisions above. Those are the ones nobody outside your firm can make for you, and the Butler Snow record shows they are also the ones that fail.
How to Show the Policy Was Followed
The policy that matters is the one you can evidence on a specific matter, months after the fact.
Consider what Butler Snow had to do once the show cause order arrived. The firm reviewed 52 Alabama federal dockets, 40 of which contained citations to check. Then, at its own expense, it hired another firm, which put 28 attorneys on verifying more than 2,400 citations across 330 filings. The review found nothing further. It also cost a great deal, and the court said as much.
That is what proving a negative costs when the record does not already exist. A firm that logs verification as part of the filing workflow can answer the same question in an afternoon.
Four things worth recording:
- Which AI tool was used on which matter, and for what
- Who verified the authorities before filing, and when
- Who approved any AI-assisted output that left the firm
- When the policy was last reviewed, and when it was last communicated to every lawyer
A policy on a shared drive proves intent. A record proves compliance, and the record is what a court, a client or an insurer will ask for.
How Codebridge Builds Workflows Around a Firm's Policy
We do not write AI policies and we are not your counsel. What we build is the layer underneath one: the workflows a policy assumes exist, with the record it assumes someone is keeping.
The approval checkpoint is designed in during the first conversation, and the log of who approved what, on which matter, is part of the build rather than something reconstructed under a show cause order. One workflow goes live in three weeks, wired into the systems the firm already runs. Your firm owns the repository, the prompts and the configuration from day one.
The closest reference we can offer, labelled for what it is: Knowledge Cloud, built for a Big Four tax and legal practice, runs an expert review queue with an immutable audit log, so a senior practitioner approves each output before the firm acts on it. A research platform rather than a law firm system. What it demonstrates is the audit pattern.
Our founding team spent more than a decade at KPMG.
If you want to find out which workflow your policy currently has no record for, book a 20-minute call.

Heading 1
Heading 2
Heading 3
Heading 4
Heading 5
Heading 6
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
Block quote
Ordered list
- Item 1
- Item 2
- Item 3
Unordered list
- Item A
- Item B
- Item C
Bold text
Emphasis
Superscript
Subscript



























