Solicitors and firms adopting generative AI carry duties that do not bend to the tool. The paramount duty to the court, competence, confidentiality and client legal privilege all sit above any efficiency gain, and hallucinated citations have already drawn referrals for professional misconduct. Layered on top are the Privacy Act, the automated-decision transparency duty commencing 10 December 2026, and court practice notes governing AI in filed material. This matrix maps the verified obligations for Australian legal practices.
9 obligations across the legal regulators. Map every AI system you run against each.
The paramount duty to the court and the administration of justice prevails over every other duty, including any efficiency gained from AI. A solicitor must not deceive or knowingly or recklessly mislead the court. Filing AI-generated fake or unverified citations breaches this rule. In Valu (No 2) the Federal Circuit and Family Court referred the practitioner for professional conduct investigation over non-existent AI-generated authorities.
Source: ASCR 2015 rule 3 (NSW legislation, Uniform Law)A solicitor must deliver legal services competently, diligently and be honest in all dealings. Regulators confirm these duties apply to AI use as to any other work. Relying on a generative tool without understanding its limits, or delegating legal judgement to it, can fall short of competent and diligent service. Practitioners must verify output and remain responsible for the advice given to the client.
Source: ASCR 2015 rule 4 (NSW legislation, Uniform Law)A solicitor must keep client information confidential. Regulators warn that entering confidential material into a public generative AI tool can place it in the public domain, breach confidentiality and cause the client to lose legal professional privilege. Practices must vet whether a cloud AI service trains on inputs, retains data offshore, or exposes prompts, before any client matter is processed through it.
Source: ASCR 2015 rule 9 (NSW legislation, Uniform Law)A principal must exercise reasonable supervision over solicitors and staff providing legal services. Where junior lawyers or paralegals use AI to draft, research or summarise, the supervising solicitor remains accountable for the accuracy and quality of that work. Firms need a documented, risk-based AI policy so supervision is real rather than assumed, and so unverified AI output never reaches a client or the court unchecked.
Source: ASCR 2015 rule 37 (NSW legislation, Uniform Law)Practice Note SC Gen 23 (NSW), commencing 3 February 2025, restricts generative AI and prohibits its use to generate the content of affidavits, witness statements and other evidence, and requires verification of any AI-assisted material. The Supreme Court of Victoria has parallel guidelines and Practice Note SC Gen 25. Practitioners must know the protocol in each court and disclose AI use where required.
Source: Supreme Court of NSW generative AI Practice Note SC Gen 23Law firms handle sensitive personal information and must comply with the 13 Australian Privacy Principles governing collection, use, disclosure, security and access. AI tools that ingest client files must be assessed against APP 6 (use and disclosure), APP 8 (cross-border disclosure) and APP 11 (security). A breach of an APP is an interference with privacy and can lead to regulatory action and penalties.
Source: OAIC Australian Privacy Principles overviewFrom 10 December 2026, under the Privacy and Other Legislation Amendment Act 2024, an APP entity must disclose in its privacy policy where a computer program uses personal information to make a decision that could reasonably be expected to significantly affect an individual. Legal practices deploying AI triage, eligibility or matter-assessment tools that touch personal information must update privacy policies before that date.
Source: Privacy and Other Legislation Amendment Act 2024 (Cth)Under the Notifiable Data Breaches scheme, if a breach of personal information held by the firm is likely to result in serious harm, the practice must assess it and notify the OAIC and affected individuals. AI vendors, prompt logs and third-party integrations widen the attack surface, so firms need breach-response plans that account for data exposed through AI tools and their supply chain.
Source: OAIC Notifiable Data Breaches schemeThe Guidance for AI Adoption, published 21 October 2025, sets out six essential practices for safe and responsible AI governance, evolving the earlier Voluntary AI Safety Standard and aligning with the AI Ethics Principles. Though voluntary, it is the reference benchmark Australian regulators expect legal practices to meet: governance, risk management, testing, transparency, human oversight and record-keeping across the AI lifecycle.
Source: Guidance for AI Adoption (National AI Centre)Each obligation links to its primary or official source. Verified against OAIC, Supreme Court NSW, Law Society NSW, DISR and the relevant Australian legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the obligations that apply in this sector.
Adopt a written, risk-based AI use policy that names permitted tools and bars client-confidential inputs into public generative AI.
Mandate human verification of every AI-assisted citation, quote and authority before it is filed or sent, in line with duty to the court.
Map each litigation court practice note (SC Gen 23 in NSW, the Victorian guidelines and SC Gen 25) and follow its restrictions on AI in affidavits and evidence.
Vet AI vendors for data training, retention, offshore hosting and privilege exposure before any matter passes through them.
Update privacy policies before 10 December 2026 to disclose any AI-assisted decisions that use personal information.
Train solicitors and staff on confidentiality, privilege and hallucination risk, and log who is authorised to use which tools.
Extend the firm data-breach response plan to cover AI tools, prompt logs and third-party integrations under the Notifiable Data Breaches scheme.
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check