What ABA Opinion 512 Requires for Agentforce in Law Firms
- Authority
- ABA Standing Committee on Ethics and Professional Responsibility
- Rule type
- ethics opinion
- Jurisdiction scope
- US national
- Effective date
- Jul 29, 2024
- Source text
- Read primary rule text ↗
Firms must configure Agentforce so competence, confidentiality, candor, and supervision duties are enforced through permissions, human approval gates, and audit trails.
The procurement answer starts with the ethics record
The first answer to “Can we ethically deploy Salesforce Agentforce AI for law firms?” is not a product answer. It is an obligation record: Agentforce does not change the lawyer’s duties of competence, confidentiality, candor, and supervision. ABA Formal Opinion 512, issued July 29, 2024, organizes lawyers’ use of generative AI under existing Model Rules, including Rules 1.1, 1.6, 3.3, 8.4(c), 5.1, and 5.3.[1]
That framing matters because Agentforce is not merely a drafting box. It is built around agents that can retrieve information, route work, trigger workflows, and place proposed actions in front of humans. Those features may give a firm better compliance handles than an ungoverned chatbot: permissions can be mapped, approval steps can be required, logs can be reviewed. But a configurable control is not the same thing as ethical compliance. The question is whether the firm configured the control, tested it, required it, retained the record, and supervised the people relying on the agent’s output.

For benchmark methodology, hallucination testing, and a product-level reliability discussion, see the site’s Salesforce Agentforce legal reliability evaluation. This article is narrower. It asks what a law firm must be able to defend when an autonomous or semi-autonomous agent touches client information, legal work product, filings, advice, or client-impacting workflows.
The sanction record makes this more than a procurement issue
The recent sanctions record is the part of the AI ethics discussion that partner meetings should not skip. Courts have not treated fabricated citations as a software accident that floats outside ordinary professional responsibility. They have looked for the lawyer, the reviewer, the firm process, and the failure point.
Mata v. Avianca became the early warning in 2023, with a $5,000 sanction after lawyers submitted non-existent cases generated through AI-assisted research.[2] By 2025 and 2026, the pattern had broadened. HAQQ’s AI legal hallucination audit, re-verified June 9, 2026, tracked 1,598 cases and estimated roughly eight new cases per day.[2] The point is not that every AI use produces sanctions. The point is that courts have repeatedly treated verification, candor, and supervision as enforceable duties even when the immediate source of the false material was an AI tool or AI-enabled workflow.
Wadsworth v. Walmart is the closest warning for firm-controlled systems because the problem was tied to the firm’s own in-house platform, MX2.law, not a consumer chatbot. The reported consequences included pro hac vice revocation and fines of $3,000 and $1,000.[2] That is the scenario a law firm evaluating Agentforce should keep in view: when the tool sits inside the firm’s own environment, the “AI did it” explanation becomes less persuasive, not more.
The later matters show escalation rather than novelty. HAQQ’s audit reports $3,000 per lawyer in Coomer v. Lindell, an approximately $109,700 record penalty in Couvrette v. Wisnovsky, $15,000 per attorney plus fees and double costs in Whiting v. City of Athens, and, in Withers v. City of Aberdeen, a canceled trial and two-year suspensions.[2] The Singapore decision in Tan Hai Peng is not a U.S. ethics authority, but it is useful as a supervision warning because personal costs were imposed on both the junior lawyer and the supervising partner.[2]
That is the enforcement backdrop for Agentforce. A platform with role controls, approval paths, and auditability may be easier to supervise than a loose collection of unsanctioned AI accounts. But once a firm chooses the platform, the firm also owns the configuration choices and the review process around the outputs.
What ABA Formal Opinion 512 requires before Agentforce features matter
Formal Opinion 512 is sometimes discussed as if it created a new AI rule. That overstates it. Its practical value is that it gathers older duties into a usable AI record. The rules matter before the product demo begins.
| Duty | What the duty requires in an Agentforce deployment | Control evidence the firm should expect to produce |
|---|---|---|
| Rule 1.1 competence | Lawyers must understand enough about the technology’s capabilities and limits to use it responsibly, including when human verification is required.[1] | A documented use policy, training record, matter-type restrictions, and a verification requirement for legal outputs. |
| Rule 1.6 confidentiality | The firm must protect client information and cannot treat generic consent language as adequate for exposing confidences to generative AI tools.[1] | Permission mapping, field-level access testing, vendor-data settings, prompt restrictions, and documented client-consent analysis where needed. |
| Rules 3.3 and 8.4(c) candor | The firm cannot submit or rely on false legal authority, fabricated facts, or misleading AI-generated content.[1] | Mandatory human review before filings, citation checking, source retrieval, and an escalation path when the agent cannot substantiate an answer. |
| Rules 5.1 and 5.3 supervision | Partners and supervising lawyers must make reasonable efforts to ensure compliance by lawyers and nonlawyer assistants involved in the work.[1] | Named owners for agent configuration, approval gates, log review, exception reports, and periodic testing. |
The confidentiality point deserves special attention because it is where vendor language often becomes too soothing. Formal Opinion 512 treats client confidences as a professional-duty problem, not merely a data-processing problem, and the ABA discussion flags that boilerplate engagement-letter consent is inadequate for client confidences in generative AI tools.[1] A firm cannot cure weak information governance by pointing to a general AI clause that no one used to make a matter-specific disclosure judgment.
Why agentic AI fits most naturally under supervision
Agentforce raises a harder governance question than an ordinary chatbot because the system can be placed inside workflows. It may draft a response, retrieve client data, summarize a file, route an approval, create a task, or trigger the next step in a business process. That behavior looks less like passive software and more like delegated work.
That is an application of Formal Opinion 512, not a quotation from it. The opinion does not name Agentforce or use “agentic AI” as a category. But its supervision analysis under Rules 5.1 and 5.3 is the most useful place to put autonomous agents because the operational risk resembles delegated staff work: someone receives instructions, uses information, produces work product, and sends something forward for another person to rely on.
Once the agent is treated as a supervised delegate, the control questions become familiar. Who was allowed to instruct it? What information could it access? Which outputs required review? Who approved them? What happened when the agent could not verify a source? Who reviewed exceptions? If the answer is “the platform has controls,” the supervision record is not finished. The firm must be able to show how those controls operated in the relevant matter.

Mapping Agentforce controls to the ethics duties
Confidentiality: permissions have to be mapped, not admired
Salesforce says Agentforce agents “respect existing role-based access controls, field-level security settings, and sharing rules,” and that if a user lacks permission to see a field, “the agent cannot see or use it.”[3] That is a meaningful vendor assertion for Rule 1.6 analysis because it gives the firm a mechanism to align agent access with human access.
It is not, by itself, a confidentiality answer. Someone still has to decide whether the firm’s Salesforce roles reflect legal confidentiality obligations rather than ordinary business convenience. A lateral partner’s matters, an internal investigation, a sealed filing project, a joint-defense file, and a client pitch database may all sit awkwardly inside commercial CRM categories. The ethical question is not whether Agentforce can inherit permissions; it is whether the inherited permissions were fit for legal work.
A defensible configuration record should therefore show who mapped roles, who tested field-level access, what sample matters were used for testing, how exceptions were handled, and whether the agent was prevented from using sensitive fields in prompts, summaries, or downstream workflow steps. If the firm cannot answer those questions, the sentence “the agent cannot see what the user cannot see” has not yet become a Rule 1.6 control.
Zero Data Retention helps only inside a broader confidentiality analysis
Salesforce also describes Zero Data Retention with third-party LLM providers as part of the Agentforce trust model.[3] For a law firm, that assertion is relevant because model-provider retention and training risk are central concerns when client information enters an AI workflow.
But Zero Data Retention is not a complete Rule 1.6 analysis. It does not decide which client information may be used, whether the client must be consulted, whether the agent should touch privileged material, or whether the firm’s own logs retain sensitive content. It also does not replace vendor diligence on subprocessors, contractual commitments, incident response, or cross-border data handling. The useful legal-risk formulation is narrower: Zero Data Retention may reduce one class of vendor-retention risk if the representation is accurate and contractually supported; it does not authorize indiscriminate use of client confidences.
Candor: legally consequential outputs need human approval gates
The sanction cases make the candor rule operational. If an agent drafts a filing section, recommends authorities, summarizes a deposition, or prepares a client-facing legal conclusion, the firm needs a human approval gate before that output leaves the internal workflow. The gate should be mandatory for filings, legal advice, client-impacting correspondence, settlement positions, regulatory submissions, and anything that purports to state law or evidence.
A useful approval gate is not a rubber-stamp button at the end of an automated path. It should force the reviewer to see the sources, inspect the underlying record, and verify the citations or factual statements that matter. For tribunal-facing work, the reviewing lawyer should be able to reconstruct what the agent generated, what sources it relied on, what the lawyer changed, and why the final version was approved.
This is where firms should be careful with internal language. Calling an output “AI-assisted” does not make it tentative once it is filed or sent. By the time the material reaches a court, regulator, opposing counsel, or client, it is the firm’s work product. The approval record has to match that reality.
Supervision: audit trails must be reviewable by lawyers, not just stored somewhere
Audit trails are valuable because they turn agentic activity into something a supervising lawyer can inspect. In a dispute or sanctions inquiry, the firm will want more than a general statement that the workflow was logged. It will want a record of user prompts, agent actions, data sources accessed, approvals requested, approvals granted or denied, edits made after AI generation, and the final output delivered externally.
Retention matters. A log that expires before anyone reviews it is weak evidence of supervision. A log that exists but is readable only by technical administrators is not much better. The supervising lawyer, risk team, or designated KM reviewer needs a practical way to review agent activity at matter level, not merely at platform level.
This is also where responsibility should be assigned before launch. If no partner, practice leader, KM lawyer, or risk function is named as the reviewer of exception reports and approval patterns, the audit trail may become a museum of failures rather than a supervision tool.
The deployment record a firm should be able to defend
For risk review, the cleanest approach is to turn the ethics duties into artifacts. The firm should not need to reconstruct its Agentforce governance for the first time after a bad filing or client complaint.
- A use-case inventory identifying which Agentforce workflows may touch client information, legal analysis, filings, advice, or client-impacting actions.
- A role and field-access map showing how legal confidentiality obligations were translated into Salesforce permissions, field-level security, and sharing rules.
- A client-confidentiality analysis covering when client consent is needed, why generic consent language is insufficient, and what data is excluded from agent use.
- Mandatory approval gates for legally consequential outputs, with named reviewer roles and clear criteria for approval, rejection, and escalation.
- A verification protocol for citations, quoted authorities, factual summaries, deposition references, and record citations.
- An audit-log retention and review plan that lawyers and risk staff can actually use.
- Training for lawyers, paralegals, assistants, and business professionals who may instruct or rely on agents.
- A periodic testing process that checks whether permissions, approval paths, and logs still work after system changes, new data integrations, or practice-group customization.
The distinction between “available” and “operated” should be explicit in that record. Role-based access is only a confidentiality control if the roles are correct. Human approval is only a candor control if the reviewer verifies the work. Auditability is only a supervision control if someone reviews the audit trail. Zero Data Retention is only one part of the vendor-risk analysis, not a license to place client confidences wherever the workflow is convenient.
The risk judgment
Agentforce can be part of an ethically defensible law-firm deployment. Its agentic architecture may even be preferable to unsupervised AI use when permissions, approval gates, and logs are configured in a way lawyers can inspect. But the defensible position is conditional.
The firm must treat agents as supervised delegates, document configuration choices, keep humans in approval positions for legally consequential outputs, protect client confidences at the permission and vendor-contract levels, and verify work product before it reaches clients, courts, regulators, or opposing parties. Agentic autonomy changes where the firm intervenes. It does not convert professional judgment into a platform feature.
Do not confuse agentic autonomy with ethical delegation without supervision.
References
- ABA Ethics Opinion on Generative AI Offers Useful Framework, ABA Business Law Today, October 2024
- AI Legal Hallucination Audit, HAQQ, June 9, 2026
- Agentforce Metrics, Salesforce
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →