Agentic AI — systems that execute multi-step workflows rather than answer prompts: gathering sources, drafting, sending, filing, updating systems of record — moves legal technology across the line the ethics rules have always policed. Model Rule 5.3 makes a lawyer responsible for the conduct of a nonlawyer assistant the lawyer directs, and a workflow agent is nonlawyer assistance in the rule's functional sense: the duties of competence, confidentiality, and supervision attach to what the agent does, not to whether the actor has a heartbeat. ABA Formal Opinion 512 (July 2024) mapped generative tools onto those duties for drafting; the agentic turn asks the harder question of who supervised the action.
3G Times publishes information, not legal advice; professional-responsibility questions are jurisdiction-specific and belong with counsel and the applicable bar's guidance.
Why does agency change the ethics analysis?
A drafting tool presents output for review; the failure mode is bad text that a careful lawyer catches. An agent executes: it may email opposing parties, file with a court, calendar deadlines, or modify matter records — failure modes that act on the world at machine speed, including the unauthorized ones. The rule structure reaches both, but the supervisory burden differs in kind. With tools, supervision is largely intake discipline — verify the output. With agents, supervision must be designed into the workflow: scope limits on what the agent may do without approval, hard gates on external-facing actions, human sign-off points at the judgment-bearing steps, and logs that let the supervising lawyer reconstruct what happened. The competence duty (Rule 1.1) also reads differently: competent use of an agent includes understanding its action space, not just its accuracy.
What should the supervision architecture contain?
Four elements are becoming the practice pattern. Scoping: each agent's authority written down — data it may read, systems it may touch, actions it may take alone versus with approval — the corporate analogue of a paralegal's task list, versioned like any control document. Gates: external effects (filings, service, client communications, payment instructions) behind explicit human approval, with the approval captured as an artifact. Observability: action logs retained to matter files, so the record of what the agent did is discoverable-by-design rather than reconstructed from platform telemetry. Containment: kill-switch mechanics, spending caps on tool calls, and rate limits that bound the damage of a misconceived run. Each element has a supervision-rule analogue; together they are what "reasonable efforts to ensure the assistant's conduct is compatible" looks like when the assistant runs continuously.
| Control | Rule 5.3 analogue | Agentic implementation |
|---|---|---|
| Authority scope | Task assignment within competence | Written action whitelist per agent |
| Approval gates | Review of nonlawyer work | Human sign-off before external effects |
| Action logs | Supervisory knowledge | Matter-file telemetry, retained |
| Containment | Directions to halt and correct | Kill switch, caps, rate limits |
A note on cross-matter contamination, the quietest of the surfaces: agents operating across a firm's matters need isolation that privilege recognizes — context segregated by client, memory scoped and expunged per matter lifecycle, and no learning across the boundary without consent analysis. The collaboration-intelligence features that make agents efficient are exactly the features that make them privilege hazards when the boundaries are soft.
Where are the specific risk surfaces?
Communication rules first: an agent that emails a represented party directly implicates the no-contact rule (4.2), and one that drafts communications with unverified facts implicates candor and the care owed clients. Filing surfaces next: an agent completing court forms or e-filings presses against certification requirements — the submitting lawyer vouches for the filing, machine-drafted citations and all. Confidentiality throughout: agents operating across matters need isolation boundaries that privilege discipline recognizes, and tool vendors' data paths need the Opinion 512 treatment — consent gating, no-training terms, and jurisdiction routing for cross-border flows. Deadlines deserve their own line: calendaring agents are the agentic future's most seductive and most dangerous delegation, because a missed-limitation machine error is a malpractice claim with a log file.
How should firms write the delegation decision?
The bar's centuries-old delegation logic transfers: delegate the task, retain the judgment. Firms adopting agentic workflows usefully maintain a delegation register — which workflows run under which supervision level, approved by whom, reviewed when — and a training component that treats the agent as staff: what it may do, what must be checked, where the gate clicks. Malpractice carriers are already asking the questions the register answers, and OCG language is beginning to require client notice before agent-executed actions touch the client's matters, the same notice logic departments applied to AI drafting. The firms that wrote the register before the carrier asked describe the conversation as routine; the others describe it as a coverage discussion.
What does this mean in practice?
- Write the authority whitelist first. The agent's action space is a control document; expanding it is a governance event, not a configuration change.
- Gate every external effect. Filings, sends, payments: human approval with an artifact — the supervision evidence and the malpractice defense are the same file.
- Log to the matter, not the platform. Agent telemetry belongs where discovery and audits look first.
- Rehearse failure. A misconceived run's blast radius is the containment design; test the kill switch before the day it matters.
Rule 5.3 was written for clerks and investigators; its logic — you direct it, you own it — is technology-proof. The agentic era's contribution is making supervision architectural: written authority, hard gates, retained logs. The lawyers who build that will delegate freely; the ones who don't will discover that an unsupervised agent is staff whose errors compound at machine speed.
The register also disciplines vendor selection: an agent's supervision level constrains what data it may touch, so the procurement checklist inherits from the register rather than the reverse. Teams that buy first and scope later end up governing a tool whose action space was defined by its sales deck — the single most common origin story for agentic incidents.
What belongs in the delegation register's first version?
Three columns and honesty: the workflow, its supervision level (unsupervised internal, gated external, human-in-loop judgment), and the approver. Everything else — kill-switch owners, tool-call caps, vendor contact paths — attaches later as appendices the register refers to. The document's purpose is the answer to "who let the agent do that"; it fails only when ambition inflates the unsupervised column before the gates exist.
Frequently asked questions
Can an agent ever file or serve without human approval?
That is a governance decision firms are writing now, and the conservative default is no: the submitting lawyer's certification and the communication rules make external effects the natural gate. Routine, low-risk notices are the boundary cases where written, reviewed procedures occasionally carry the delegation.
Does using agents require client disclosure?
Not categorically under current guidance, but the direction of travel in engagement terms is notice-before-agent-action on the client's matters, mirroring the AI-drafting disclosure pattern. Confidentiality-implicating data paths require consent analysis regardless.
Who is responsible when the agent errs — firm, vendor, or lawyer?
Ethically, the directing lawyer through the supervision rules, always; commercially, the vendor contract allocates what it can. Neither answer protects the client, which is why the gates exist — the architecture is the risk allocation that matters.
For more context, read Billing for AI-Assisted Drafting: How Outside-Counsel Guidelines Are Catching Up to Rule 1.5.
For more context, read legal research verification ai.
For more context, read judicial standing orders generative ai.

