The Small-Firm Sanctions Gap
There's an uncomfortable pattern in the legal-AI data, and it lands hardest on exactly the firms moving fastest. Solo and small firms have adopted AI more aggressively than anyone — and they show up in the sanctions record more than anyone, too. The good news buried in that pattern: the gap between the two is closable, and closing it costs far less than a single sanction.
Adopted fastest
Among solo and small firms, 71–75% report using AI in their work (Clio, 2026 solo/small-firm data via the NC Bar) — outpacing the profession at large. That's the entrepreneurial reflex working exactly as you'd expect: fewer layers, faster decisions, immediate willingness to try the thing that saves time.
But two other numbers complicate the story. Only about a third of those firms report any revenue increase from AI — the efficiency isn't reliably reaching the bottom line (which is a pricing problem worth its own conversation). And firm-level adoption of vetted, legal-specific AI sits far lower than individual use. Read together, the data is precise: the lawyers have adopted AI; the firms mostly haven't. Which means a lot of small-firm AI use is happening on personal ChatGPT accounts and unvetted tools — outside firm policy, outside supervision, often on matters involving client confidences.
Sanctioned most
That ungoverned use has a measurable tail. Stanford's analysis of U.S. attorney AI-hallucination incidents found solo practitioners made up 50.4% of the firms involved, and firms of 2–25 attorneys another 39.5% — together roughly 90%. The incident database those cases come from grew from 87 entries in May 2025 to about 1,700 by July 2026.
It isn't that small-firm lawyers are careless. It's structural. A hallucinated citation is an error any AI tool can produce. In a large firm, a review layer usually catches it before it's filed. In a solo or small practice, there often isn't a second chair — so the same error walks straight into a court filing. Fast adoption plus thin review is the exact formula the record keeps punishing.
The gap is a governance gap, not a talent gap
The instinct, once a managing partner sees these numbers, is to ban the tools. It's the wrong move — a ban pushes usage underground, where you lose the one thing governance buys you: visibility. Your associates will keep using AI; you'll just stop knowing how.
The firms getting this right do three unglamorous things instead:
- Classify the tools. A short, written list — approved, conditional, prohibited — so people know what they're allowed to use before they use it.
- Write the rules down. Where AI may run, where it may not, and what data may never go into a public tool. Roughly half of firms still have no AI policy and no training at all — which, under current supervisory-duty guidance, is itself becoming a problem.
- Make review non-negotiable. One human stands behind every consequential output, under their licence, before it leaves the building. This is the single rule the sanctions record vindicates over and over.
None of that requires a new hire, a big platform, or an IT department. It requires a policy, an approved-tool list, and a habit — the same three things that separate the firms using AI as leverage from the firms in the database.
And it's no longer just prudent — it's a supervisory duty
The reason this has teeth: ABA Formal Opinion 512 places AI tools under Rule 5.3 as "nonlawyer assistance," which means the supervisory duty for what AI produces sits squarely with the deploying attorney and the firm's managers. The same guidance expects firms to have an AI policy and training. Competence under Rule 1.1 now includes understanding the tools you use. In other words, the half of firms operating with no policy and no training aren't just exposed to the occasional bad citation — they're increasingly out of step with the profession's own supervisory expectations.
The trendline is only tightening. Florida's Opinion 24-1 recommends informed client consent before confidential data enters a third-party generative tool; Texas Opinion 705 asks for reasonable precautions; and a California proposal (COPRAC, comment period closed May 2026, not yet adopted) would make verification of AI outputs an enforceable rule rather than guidance. These aren't a single national standard — they differ state to state — but they all point the same direction: away from "use it however" and toward documented, supervised use. A small firm that writes its policy now is getting ahead of a requirement, not reacting to a sanction.
None of these authorities asks a small firm to slow down. They ask it to be able to show its work.
Get the full field guide. The AI Your Firm Never Approved includes the approved-tool classification, the data-handling rules, and an eight-step, 90-day plan a small firm can actually run — sourced, footnoted, and written for managing partners and firm administrators, not IT. Download the free eBook →