AI is becoming part of the plaintiff-firm intake operation.
Chatbots can respond to prospective clients after hours. Voice agents can collect preliminary information. Other automated systems can summarize conversations, identify possible case categories, schedule consultations, prioritize leads, and route inquiries to the appropriate team.
Used carefully, these tools can help firms respond faster and reduce the administrative burden on intake staff. Used without adequate controls, however, automation can repeat the same mistake across hundreds or thousands of prospective-client interactions.
The central question is not simply whether a firm uses AI. It is whether the firm remains in control of what the system collects, communicates, recommends, and retains.
ABA Formal Opinion 512 explains how existing professional duties, including competence, confidentiality, communication, supervision, accuracy, and reasonable fees, apply when lawyers use generative AI. The opinion does not replace jurisdiction-specific analysis. Firms should evaluate the professional-conduct rules, privacy requirements, recording laws, accessibility obligations, and other laws applicable to their practices.
For plaintiff firms, these issues can arise before a representation agreement is signed. Intake systems frequently interact with people who may disclose medical histories, employment details, financial losses, potential defendants, accident facts, and other sensitive information.
The following seven controls are recommended risk-management measures. Not every control is expressly required in every jurisdiction or for every technology. Firms should adapt them to the system’s capabilities, the sensitivity of the information involved, and the rules governing the firm.
1. Define What the AI May and May Not Collect
An AI intake system should not collect every fact a prospective client is willing to share.
The firm should identify the minimum information reasonably needed at each stage of intake. Initial screening may require a person’s contact information, incident type, incident date, location, names needed for a conflict check, and a short description.
Detailed medical records, Social Security numbers, financial documents, photographs, and lengthy narratives may not be necessary until the firm has completed preliminary screening and appropriate conflict checks.
This issue matters because communications with prospective clients may trigger confidentiality and conflict obligations even when the firm ultimately declines the matter.
ABA Model Rule 1.18 provides that information learned during a qualifying consultation with a prospective client generally may not be used or revealed merely because no attorney-client relationship was formed. Comment [2] explains that written, oral, and electronic communications may constitute a consultation depending on the circumstances. A consultation is more likely when a firm invites people to submit information about a potential representation without clear and reasonably understandable warnings limiting the firm’s obligations.
Warnings should be carefully drafted. A disclaimer does not automatically eliminate every duty, and its effect may depend on its wording, presentation, the information requested, and applicable jurisdictional rules.
Create a written data map that answers:
- What information does the system collect?
- At what stage is each category collected?
- Why is the information necessary?
- Where is it stored?
- Which employees, contractors, and vendors can access it?
- How long is it retained?
- When and how is it deleted?
- Is it used to train or improve any model?
- Can it be retrieved, corrected, exported, and removed?
The safest workflow is generally staged. Collect only enough information to determine the next appropriate step, then request additional details through a controlled process.
2. Clearly Explain the System’s Role
An intake chatbot or voice agent should not imply that it is an attorney, a paralegal, or a human intake specialist.
As a transparency and risk-management measure, prospective clients should receive a clear notice when they are interacting with an automated system. The notice should accurately describe the system’s limited role and should tell users not to treat the interaction as legal advice or confirmation that the firm has accepted the matter.
The case for prominent disclosure becomes stronger when a system does more than schedule an appointment. A tool that summarizes facts, scores or prioritizes leads, recommends a disposition, or generates substantive responses is influencing the intake process in a meaningful way.
Formal Opinion 512 explains that a lawyer’s duty to communicate with a client may require disclosure of AI use depending on the circumstances, including the importance of the tool’s role and the client’s reasonable expectations. That client-communication analysis should not be treated as a universal rule governing every initial contact from a prospective client. Even so, advance notice during intake is a prudent control, particularly when sensitive information will be processed.
Place the notice before the system requests sensitive information, not only in a lengthy privacy policy.
Distinguish among at least three separate messages:
- The person is interacting with an automated system.
- Submitting information does not, by itself, create an attorney-client relationship or mean the firm has accepted the matter.
- The person’s information may be processed, stored, reviewed, or shared with specified service providers as described in the firm’s notice.
Each message serves a different purpose. Combining them into vague boilerplate may leave prospective clients uncertain about what is happening.
3. Perform Meaningful Vendor Due Diligence
A vendor’s general statement that its platform is “secure” is not enough.
Before permitting a provider to process intake information, the firm should understand the provider’s actual practices. Relevant questions include:
- Is customer information used to train, tune, evaluate, or improve models?
- Is information shared with subprocessors?
- Where is the information stored and processed?
- How long is it retained?
- Can the vendor or its personnel view prompts, recordings, transcripts, or outputs?
- What happens to the information when the contract ends?
- Can information be permanently deleted?
- How does the provider separate one customer’s information from another’s?
The firm should also evaluate authentication controls, encryption, access logging, breach-notification procedures, data-export capabilities, deletion processes, business-continuity arrangements, and the vendor’s response to security incidents.
ABA Model Rule 5.3 requires lawyers with managerial or supervisory authority to make reasonable efforts to ensure that nonlawyer assistance is provided consistently with the lawyer’s professional obligations. Comment [3] specifically identifies document-management companies and internet-based information-storage services as examples requiring consideration of confidentiality, contractual protections, provider reputation and experience, the nature of the services, and the environments in which the work is performed.
Based on the tool’s risk profile, the sensitivity of the information involved, and the firm’s bargaining position, the agreement should address issues such as:
- Ownership of firm and prospective-client information
- Restrictions on model training and secondary uses
- Confidentiality requirements
- Approved subprocessors
- Security standards
- Breach-notification procedures and timing
- Data-return and deletion procedures
- Audit or assurance rights
- Indemnification and liability allocation
- Data-residency requirements
- Procedures for immediately terminating access
- Obligations following acquisition, insolvency, or contract termination
Vendor diligence should not end when the contract is signed. Material product changes, new AI features, acquisitions, security incidents, revised terms, and new subprocessors may warrant renewed review.
4. Keep a Human in Every Consequential Decision
AI may assist with intake decisions, but it should not silently become the final decision-maker.
A system might incorrectly conclude that a claim is outside the statute of limitations. It may misunderstand a caller, miss an unusual liability theory, confuse jurisdictions, or downgrade a potentially valuable matter because its facts do not match the examples on which the system was configured.
Human review should be required before:
- Rejecting a matter based on a potentially dispositive legal conclusion
- Communicating substantive legal advice
- Determining that a filing deadline has expired
- Identifying a particular defendant or legal theory as definitive
- Assigning or communicating a case value
- Advising someone to stop seeking legal representation
- Making a representation about likely liability, recovery, or eligibility
- Sending a communication that could reasonably be understood as individualized legal advice
The reviewer should be able to identify which portions of the intake record came directly from the prospective client and which were generated, inferred, transcribed, scored, or summarized by an automated system.
Without that distinction, an inaccurate summary can be mistaken for the prospective client’s own statement.
Formal Opinion 512 explains that lawyers using generative AI need a reasonable understanding of the tool’s capabilities and limitations and remain responsible for appropriately reviewing its output. The opinion also connects AI use to lawyers’ supervisory obligations over employees and agents.
Human oversight should therefore be designed into the workflow. It should not depend on an employee happening to notice that something looks wrong.
5. Build Conflict and Confidentiality Safeguards Into Intake
AI-assisted intake can create a conflict problem before anyone at the firm recognizes that a conflict exists.
A prospective client may identify an adverse party, describe confidential litigation strategy, or provide information that could be significantly harmful in a related matter. If the system requests an unrestricted narrative before conducting a conflict check, the firm may receive far more information than it needed to determine whether it could consider the representation.
Subject to its informed-consent and screening provisions, Model Rule 1.18 may restrict a lawyer, and in some circumstances the lawyer’s firm, from undertaking a materially adverse representation in the same or a substantially related matter when the lawyer received significantly harmful information from a prospective client.
The rule’s commentary therefore recommends limiting an initial consultation to information reasonably necessary to determine whether to undertake the representation.
A controlled workflow should:
- Request party names early enough to support conflict screening.
- Run an appropriate conflict check before soliciting an extensive narrative when feasible.
- Warn users not to submit unnecessary confidential or sensitive information.
- Limit unrestricted free-text fields during preliminary screening.
- Separate rejected-lead information from active-client systems when appropriate.
- Restrict internal access according to role and need.
- Create a process for immediately escalating potential conflicts.
- Document any screening or consent measures used under applicable rules.
Firms should also test whether automated summaries preserve the meaning and uncertainty of a prospective client’s statements.
A summary that changes dates, removes qualifiers, selects one interpretation of an ambiguous statement, or turns an allegation into a confirmed fact can distort both conflict review and later case evaluation.
6. Test for Unequal Treatment and Accessibility Failures
An intake system can appear neutral while producing uneven results.
Language patterns, speech differences, disabilities, incomplete records, limited digital literacy, and unusual ways of describing an injury may affect how an automated system transcribes, scores, or routes an inquiry.
A voice system may perform differently when callers have accents, speech impairments, poor connections, background noise, or significant emotional distress.
Firms should test the system across the communication methods and user populations reasonably expected to use it. The objective is not merely to confirm that the tool operates. The firm should determine whether similarly situated prospective clients receive materially different treatment because of irrelevant characteristics or avoidable system limitations.
Depending on the firm’s users and intake channels, testing may examine:
- Whether certain accents or speech patterns produce elevated transcription errors
- Whether non-native English speakers receive systematically different scores or routing
- Whether users with disabilities can complete the process
- Whether notices and consent language are usable on mobile devices
- Whether emotionally distressed callers are incorrectly classified
- Whether location variables improperly influence prioritization
- Whether particular case descriptions are repeatedly misunderstood
- Whether a manual review changes automated rejection decisions at unusual rates
- Whether performance changes after a model or workflow update
NIST’s voluntary AI Risk Management Framework organizes AI-risk management around four continuing functions: Govern, Map, Measure, and Manage. It emphasizes documented, lifecycle-based risk management, including testing, evaluation, verification, validation, monitoring, and improvement.
NIST’s framework and Playbook are not jurisdiction-specific legal requirements or mandatory checklists. They are useful governance resources that firms can adapt to their circumstances.
Firms should generally preserve a practical route to a person, particularly for prospective clients who cannot effectively use the automated process, do not wish to use it, or require an accommodation. The design of that alternative should be reviewed under applicable accessibility and nondiscrimination requirements.
7. Maintain Logs, Escalation Rules, and an Incident Plan
A firm cannot meaningfully supervise an AI intake system it cannot evaluate.
The firm should preserve enough information to determine what occurred during a disputed, inaccurate, or defective interaction. Depending on the technology and applicable law, that record may include:
- The prospective client’s original submission or recording
- A transcript and any corrections
- The system’s output
- The model, prompt, or workflow version
- The date and time of the interaction
- Any automated score or classification
- The identity of the employee who reviewed it
- Changes made during human review
- The final intake disposition
Logging must be balanced against data-minimization, privacy, confidentiality, security, and retention obligations. The answer is not to preserve everything indefinitely. The firm should retain the information reasonably necessary for quality control, conflict management, security, complaint resolution, and defensibility under a documented schedule.
The firm should define events requiring immediate escalation. Depending on the firm’s practice and applicable law, examples may include:
- A credible indication of imminent self-harm or harm to another person
- A rapidly approaching filing deadline
- A potential data breach or unauthorized disclosure
- An automated promise, guarantee, or unsupported prediction
- A substantive legal conclusion sent without required approval
- An unexplained systemwide increase in rejection or abandonment rates
- Evidence of biased or materially inconsistent outcomes
- Information from one matter appearing in another
- A vendor making an unapproved change to its data practices
- A material decline in transcription or classification accuracy
Emergency and safety-related escalation procedures should be developed with qualified ethics, privacy, employment, and other appropriate legal review. Employees should be trained on both the limits of their roles and the circumstances requiring escalation.
On May 14, 2026, the State Bar of California Board of Trustees approved revisions to its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law. The updated guidance addresses emerging developments, including agentic AI, and is intended to remain a living document as technologies and use cases change.
Assign ownership before an incident occurs. Intake leadership, operations, information security, firm management, privacy personnel, and ethics counsel should understand:
- Who can pause the system
- Who preserves relevant records
- Who evaluates legal and ethical obligations
- Who contacts the vendor
- Who communicates with affected individuals
- Who approves restoration of the system
AI Intake Should Accelerate Judgment, Not Replace It
The strongest AI intake systems do not operate as autonomous digital lawyers. They perform limited, defined tasks inside a supervised process.
Firm leaders should be able to answer:
- What is the system permitted to do?
- What is it prohibited from doing?
- What information can it access?
- What information does it retain?
- Where is it most likely to make mistakes?
- Which outputs require human review?
- How will the firm detect a problem?
- Who has authority to intervene?
- How will changes to the system be evaluated?
AI-assisted intake can improve responsiveness and help firms serve prospective clients more consistently. But speed without governance merely permits errors to spread faster.
Before expanding an AI intake program, pressure-test the workflow against these seven controls. The goal is not to eliminate every possible risk. It is to create a system in which risks are visible, responsibilities are assigned, and human professional judgment remains firmly in charge.
Build a Stronger Legal Growth System
AI intake is only one part of a successful client acquisition strategy.
SmashOrbit Legal helps law firms strengthen marketing, lead generation, intake, technology, and operational workflows so they can attract better opportunities, respond more effectively, and build sustainable growth.
Contact SmashOrbit Legal to discuss how your firm can improve its client acquisition and growth strategy.

