This Monday (August 31, 2026), the California legislature passed SB 574, a bill containing thirteen words that could shape the future of legal AI.
The most familiar problem behind SB 574 is hallucinated legal citations: lawyers filing authorities that do not exist or attributing invented words to real cases. The bill would put into statute a version of what the Court of Appeal said in Noland v. Land of the Free last year: verify what you cite. It also goes further than existing guidance in ways that matter, with a mandatory duty to disclose covered AI use in documents submitted to a court and a confidentiality rule written around who can access what you type into a system. Those are real obligations and they deserve their own posts.
But there is one sentence in the bill that the materials I have reviewed do not explain, and it is the sentence that will decide whether California lawyers get to use this technology the way I think they should. It is thirteen words long. It says that an attorney may not “delegate the practice of law” to generative artificial intelligence.
Neither of the operative terms is defined. The sentence was added in the Assembly in July, after the Senate had already voted on a version without it, and the published analyses reviewed for this post state it without construing it. The bill passed both houses on August 31 without an opposing vote and is awaiting the Governor. Once it is presented, he has until September 30 to act, and if he does nothing it becomes law. If enacted, the thirteen words take effect on January 1, 2027, and if nobody with authority has said what they mean by then, the first constructions may come from disciplinary charging decisions and trial-court rulings before the profession has a clear, worked explanation of the design question. (Bill text and history.)
I want to make an argument that may surprise some of my friends in legal tech. The sentence is not crazy. It is, at bottom, a demand for an authority boundary, and I have written about why authority boundaries matter for legal AI. The agent prepares the path; the lawyer chooses the road. A statute that says a lawyer may not hand the road-choosing to a machine is saying something I believe.
The problem is that the sentence does not say that. It says the practice of law, and in California that phrase has a century of case law behind it and reaches far beyond appearances in court. If the sentence means that a machine may not perform any task that falls within the practice of law, then it prohibits methods a federal court in California has already allowed in eDiscovery (more on that below), and soon enough it will reach every practice area as the tools mature. If it means that a lawyer may not let the machine exercise the lawyer’s judgment in the lawyer’s place, then it is a sensible boundary that leaves enormous room for the technology. Same 13 words. Opposite worlds.
This post goes deep on which reading is better, what it means for eDiscovery today and for everything tomorrow, and what the Governor, the State Bar and law firms could do in the next few weeks. It is long because the stakes call for it. The research behind it was done with AI assistance, two systems checking each other against a shared legal-research service (Descrybe); what follows is my reading of it, with the sources linked so you can check me.
I. What the bill says
Pro-tip: Work from the August 21 text, not from summaries. Several official summaries describe earlier versions, and the version history matters. The delegation sentence, the access-restriction confidentiality test and the mandatory court-disclosure duty appear in the July 2 print. The explicit reference to reading was removed from the citation-verification standard on August 13, along with an anti-discrimination duty that early coverage still describes. (Version selector on leginfo.)
The attorney provisions, in a new Business and Professions Code section 6068.1, establish several distinct obligations. A savings clause preserves the ordinary duty of competence and diligence. The thirteen words follow. Then, for any lawyer who uses generative AI to assist in practice: keep confidential, personal identifying and nonpublic information out of a system unless access to what you enter is limited to you and to people you have authorized who are bound to keep it confidential; take reasonable steps to verify outputs, including every citation, and to correct erroneous or hallucinated output in material you use; and disclose your use of generative AI to the court for documents you submit to a court. A separate amendment to Code of Civil Procedure section 128.7 bars filed papers from containing citations the responsible attorney has not personally verified, expressly including citations an AI supplied. Arbitrators get their own, broader rule, a bar on delegating any part of their decisionmaking process to a generative tool.
One piece of history matters for everything below. The Senate Judiciary Committee’s January analysis says the bill was modeled on the Judicial Council’s Standard 10.80 for judges and on Noland, both of which permit AI use with verification. That history predates the July sentence, so it does not settle the sentence’s meaning. It supplies relevant background for understanding the earlier proposal. (Senate Judiciary analysis; Noland.)
II. Why the sentence is not crazy
I run a lot of agents. I have written about what happens when you audit the system prompt and about the cognitive floor below which our systems are incapable of carrying the intelligence load we are coming to expect of them. The most useful idea I have found for law practice is that there is a line between the work an agent does and the judgment a lawyer owns, and that the line can be written down and enforced in code. A restricted service identity can prevent a consequential action, provided other tools and access paths do not reopen it.
Ryan McDonough’s Human Accountable for the Loop, in its September 2026 release, gives the general version. An approval means something only when the person has four things: information, time, authority and effect. His line is that if you remove any one of them, the approval “begins to resemble evidence gathered for the organisation rather than power granted to the individual.” A prompt that says never file without approval is guidance; a service identity that cannot file is a control. He also describes Cork v. Smith, an English High Court decision from May: a firm with an AI policy submitted fabricated statutory wording despite review by two supervising solicitors and repeated warnings from the tool to verify the source. Its subsequent letter compounded the problem with an explanation of the error that the judge found untrue. Human presence is not verification.
So when the Legislature says a lawyer may not delegate the practice of law to a machine, my first reaction is not outrage. It is agreement with what I take to be the purpose: the lawyer’s judgment, authority and name on the work must be real. The State Bar’s updated guidance from May, prepared at the Supreme Court’s request to address agentic systems, says the same thing in its own words: attorneys must retain professional judgment and provide oversight suited to the system’s autonomy. Read the thirteen words as that principle and the whole bill coheres. (Practical Guidance, May 2026.)
III. What legal practice means, and who the cases were about
California’s general definition of legal practice is developed in the cases, alongside statutes governing licensing and particular roles. People v. Merchants’ Protective Corp. in 1922 and Baron v. City of Los Angeles in 1970 place it in court appearances and, more broadly, in giving legal advice and preparing the instruments by which legal rights are secured; Baron, a case about a lobbyist-registration ordinance, adds that the test is whether the work requires applying legal knowledge and technique. People v. Landlords Professional Services drew the line between typing what a customer supplies and selecting the form and explaining the law. And the Ninth Circuit in In re Reynoso, applying California law to bankruptcy software that chose the exemptions and gave personalized guidance, held the operator was practicing law without a license, while expressly leaving open whether software alone would be. (Baron; Landlords; Reynoso.)
Notice what those cases decide and what they do not. They help identify legal work and, in their different settings, examine the actor’s authority to perform it. Reynoso’s software was doing legal work; its operator’s lack of a license made that unauthorized. None of the cases asked what happens when the operator is a licensed lawyer using the tool inside a representation the lawyer is responsible for. That distinction, between the tool’s activity and the lawyer’s role, does not make the statute disappear. The Legislature aimed the sentence at licensed attorneys and it means something. But it does reframe the question the statute forces: not whether the tool practices law, but whether the lawyer has kept the judgment, the authority and the responsibility over what the tool does. The Legislature could clarify that boundary in the statute, and the State Bar could provide reasoned guidance on how lawyers should apply it. Rather than wait for a binding judicial interpretation, either (or both) of these steps could reduce uncertainty and the risk of restrictive readings that unnecessarily impair modern legal practice.
IV. What “delegate” has meant, in California’s own words
Here is the part that should reassure people. California already has a body of law about delegation by lawyers, and it does not say what the anxious reading of SB 574 says.
The paralegal statute, Business and Professions Code section 6450, defines a paralegal as someone who performs substantial legal work that the attorney has specifically delegated, under the attorney’s direction and supervision. The statute’s own list of delegable work includes legal research, drafting and analyzing legal documents, and making an independent recommendation to the supervising attorney. What a paralegal may not do is give legal advice, appear in court, or select or recommend a legal document for anyone other than the supervising attorney. That last line is the sharpest in the whole body of law: substantial recommendations can be prepared for the directing lawyer, while the statute restricts the paralegal’s independent advice and document recommendations to clients. (Section 6450.)
The State Bar’s own ethics committee, in Formal Opinion 1982–68, adopted the ABA’s old formulation: delegation is proper where the lawyer keeps a direct relationship with the client, supervises the work and takes complete professional responsibility for it. The opinion let a creditor-client’s employees prepare collection letters on the lawyer’s stationery over the lawyer’s signature under supervision, identified lending one’s signature without an active role as the vice, and required the lawyer’s own authorization for any letter threatening legal action in the particular case. Formal Opinion 1988–97 let a nonlawyer sign trust-account checks as a ministerial act at the lawyer’s direction, with no discretion. Formal Opinion 2015–193, on eDiscovery, told lawyers to keep overall responsibility, get competent help and test the process. (1982–68; 1988–97; 2015–193.)
The Supreme Court’s cases run the same way. Crawford v. State Bar describes preparatory work becoming the lawyer’s own through the lawyer’s personal examination and approval or further effort; the misconduct there was a disbarred person independently running matters behind a licensed name. County of Santa Clara v. Superior Court told public lawyers what real supervision of outside counsel contains: reserved decisions, a veto and a personally involved lawyer, not boilerplate. And the discipline cases punish the absent lawyer: Townsend in 1930, who signed complaints that insurance adjusters prepared and took little interest in; Moore in 1964, who by his own admission never checked whether his staff had done what he relied on them to do; and Del Biaggio v. Bansen this July, where the court said a plan to have a paralegal alone check AI-added citations would have been inappropriate even had it worked. (Crawford; Santa Clara; Del Biaggio.)
Taken together, these authorities show that substantial assistance can be lawful under defined conditions. They also show why a licensed name and retained liability are insufficient when someone else effectively conducts the practice. Their human-role permissions do not automatically extend to an AI-specific prohibition. In consulting, I have said “a system may generate; the lawyer must decide”. That is not a claim that the system does no legal reasoning. It plainly does. The question is whether the lawyer’s direction, evaluation and control over what it does are professionally sufficient for the service being provided.
V. Three readings, and which one I would defend
There are three serious ways to read the thirteen words.
The strict reading is a task ban: generative AI may not perform any activity within the Merchants definition, only assist around it, so a lawyer who lets a system draft the complaint or classify the responsive documents has delegated the practice of law even if the lawyer reviews the result. This reading has some textual support and I will not pretend otherwise. The Legislature knew how to write specifically delegated and under the direction and supervision in section 6450 and wrote neither here. The practice of law is broader than professional judgment. The strongest version of the argument points at Reynoso: if selecting the form is practicing law, then a lawyer who has a model select the form has delegated practice, and later review does not undo an act already done.
The intermediate reading permits substantive preparation but requires that each substantive output be individually adopted by a lawyer before it is used. Research, drafts and analyses are fine; a classification, an answer or a document that has effect must receive a lawyer’s attention and judgment one at a time. This is plausible for advice, filings and irreversible acts. Applied to every intermediate classification in a large review, it can conflict with appropriate process-level reliance. That consequence needs examination rather than a label.
The reading I would defend permits process-level judgment: the lawyer defines the criteria, validates the system on the population it will work on, samples the results, handles the exceptions and takes the decisions that reach a client, a court or a counterparty, and the system may make the individual calls in between. The lawyer may not place the system in the lawyer’s position so that its judgment is the operative one.
Four things support this. The same section regulates lawyers who use AI to assist in practice and contemplates AI outputs, AI-supplied citations and hallucinated output in material the lawyer uses, so the bill plainly expects substantial use. The disclosure duty is further evidence that at least some AI participation in court filings is contemplated, which is hard to square with a ban on AI performing the work that goes into those filings. The arbitrator provision, in the same bill, forbids delegating any part of the decisionmaking process, so the Legislature had component-level language available and used it only for arbitrators. And the bill’s own modeling history points at permission-plus-verification rules.
Two honest caveats: The structure supports the broad reading; it does not prove it. A reader can say the assistance provisions govern only narrower forms of assistance, and the words are what they are. And the history predates the July sentence. So there is ambiguity. That is exactly why someone with authority should say what the words mean before January, when this legislation goes into effect if it is not vetoed.
VI. eDiscovery: the workflow that already exists
The conservative reading of this prohibition against delegating the practice of law to generative AI would cause significant harm now. This is not a hypothetical about the AI-native firm of 2030.
Large document reviews have run on technology-assisted review for more than a decade. Since Da Silva Moore in 2012, courts have accepted computer-assisted review, and in Dynamo Holdings in 2016 the Tax Court said in terms that the standard for a discovery response is a reasonable inquiry, not perfection, and upheld a predictive-coding response. Rule 26(g) requires a certification based on reasonable inquiry. An appropriate process may use sampling; it does not generally require counsel personally to read a million documents. Even the Da Silva Moore protocol kept human eyes on the documents the system predicted relevant; what has changed since is how much of the calling the machine does. Federal Rule of Evidence 502 exists because pre-production privilege review had become prohibitively expensive; and clawback orders are common because it is accepted that sometimes mistakes may happen so we have a process to rectify them. California’s Electronic Discovery Act added a clawback procedure in 2009. Da Silva Moore, opinion and protocol; Dynamo, July 13, 2016 order, pp. 7–9. (FRE 502; Code Civ. Proc. § 2031.285.) We have these rules because the modern world, with the exponential increase in data and records, requires eDiscovery technology for litigation to operate.
What changed in the last two years is that the process is increasingly a large language model. For example, Relativity’s documentation describes a develop, validate, apply sequence in which counsel writes prompt criteria, the model applies them to each document independently and returns a call with a rationale and citations, and the team validates against human-coded samples and measures recall, precision and elusion. Everlaw’s published workflow is similar: lawyer-written coding criteria, iterative testing, application at scale, sampling to validate. Other vendors describe comparable products. These systems generate derived text, so they are generative AI under the bill’s definition, which turns on what the system can generate, not on whether a particular prompt asks only for a label. A generated rationale is a useful thing to inspect; it is not proof that the call was right. (Relativity aiR; Everlaw workflow.)
And a federal court in California has already allowed it. In Schulte v. LinkedIn Corp., in a discovery order filed July 1, 2026, the court recorded LinkedIn’s disclosure that a generative review tool was being used to make the final responsiveness calls on a review set of about 204,000 documents, with human review of samples from each responsiveness category. Plaintiffs asked the court to bar keyword pre-culling, to require the tool to run across all custodial files and to compel validation metrics. Magistrate Judge Laurel Beeler denied those three requests, treated the workflow as a form of technology-assisted review under the existing ESI order, and sent the parties to meet and confer on the search strings. The court allowed the disclosed GenAI responsiveness-review workflow to continue while resolving specific discovery disputes. It did not decide the future meaning of SB 574. That makes the case especially useful here: substantive machine classification is already part of an actual litigation workflow that the court allowed, and California should explain how its new prohibition would apply to it. This use of generative AI is simply reasonable today but I observe it is becoming the common, expected, and default mode. (Schulte, ECF 203.)
Now, however, put the thirteen words next to that court order. Deciding whether a document is responsive to a request applies legal knowledge to a client’s matter; under Baron that is the practice of law. In Schulte the model made that call on documents no lawyer read. Under the process-level reading, a workflow in which the lawyers wrote the criteria, validated the tool, sampled the results, handled the exceptions and signed the certification is the paradigm of non-delegation.
I should be clear that the order records the final calls and the sampling; the fuller set of controls is how I would build the workflow, not a finding the court made. Under the strict reading, disciplinary counsel could argue that each of those unreviewed calls was a delegated act of law practice by the California lawyer who signed the certification. I do not think that argument reflects the reasonable interpretation of the law or that it should win.
Let me be careful about what I am and am not claiming, because the sloppy version of this argument will be used against the careful one. I am not saying courts mandate generative AI; they require reasonable, proportional eDiscovery, and the cases I have seen declined to compel even predictive coding (Hyles v. New York City and In re Viagra, both 2016). I am not saying eDiscovery would stop; non-generative classifiers and larger review teams remain available, at a monetary cost that clients would pay and a time cost that would further slow the wheels of justice. I am not saying Schulte settles privilege; privilege decisions carry different consequences and need their own validation and escalation, and the discovery workflows I have seen described keep lawyers in the decision to withhold. The argument I would put forward is a bit more precise: an interpretation of SB 574 that prohibits generative AI from making substantive document classifications within an attorney-directed, validated review process would exclude a method already allowed in federal litigation in California, and depending on the matter, replacing it could materially increase cost, delay or error and make existing eDiscovery plans impracticable. The statute should not leave that consequence to an undefined distinction between assistance and delegation.
A technical oddity worth naming: two systems can perform the same substantive classification yet fall on different sides of this prohibition because one is generative AI and the other is not. The bill’s definition turns on the system’s capacity to generate synthetic content, not on whether a particular response displays an explanation or only a score. Asking a generative model to return a bare label does not necessarily take it outside the definition. The policy question is why comparable legal work should receive different treatment because of the technology performing it, rather than the lawyer’s control and the reliability of the process. A rule that regulates specific technology and architecture rather than by technology-neutral function will keep producing bizarre and incongruous results like that.
And a separate, substantial issue for litigators: the confidentiality clause. Discovery corpora are dense with exactly the personal identifying information the bill enumerates. You may enter it only into a system where access is limited to you and to people you have authorized who are bound to keep it confidential. An enterprise label is not enough; what matters is who can actually reach the data and under what obligations. Every vendor and sub-processor chain now needs to be documented against those words. I’ll have a lot more to say, and some potential solutions to offer, on this and other provisions of SB 574 in good time, but for now, let’s finish this thought.
VII. Then everything else
Discovery is first only because the doctrine there is most mature. The same structure, a lawyer’s judgment encoded in criteria that a system applies at scale and a lawyer validates, is how contract review already works against a negotiation playbook, how regulatory mapping and large investigations work, and how research agents that decompose a question, run the searches, draft the memo and check the authorities are starting to work.
The hard question inside all of that, put well in a practitioner digest this August, is: what if you encode your judgment? People can learn a lawyer’s methods, and a configured system can embody parts of them. Neither fact establishes that the lawyer has already decided every new question the method encounters. My answer is that executing criteria that actually determine the outcome can be the lawyer’s judgment, in the way Schecter v. County of Los Angeles allowed an official’s subordinates to investigate, recommend and draft while the decision finally exercised had to be the official’s own. That is an analogy, not a holding about software, and it has a limit that is doing real work: the system is reasoning, not just executing, and the more discretion it exercises that the criteria do not determine, the more the lawyer’s validation and exception handling have to carry. Our older opinions did not license criteria-only decisions in every matter; 1982–68 still required the lawyer’s authorization for the threatening letter in the particular case. The design question is which decisions those are, and how are they made. Schecter, 258 Cal.App.2d 391, 397–398.
VIII. The competitive question, stated carefully
My friends in legal tech may want me to say that California lawyers will be crushed by lawyers in Texas and New York who can use the full generative AI toolkit. I will say something a bit narrower, because the narrower thing is what I can support … at least for today.
In the regimes I have looked at, the ABA’s Formal Opinion 512 and the state bar guidance it has influenced, regulation of lawyers’ AI use runs through duties of competence, supervision and verification, not through a statutory ban on delegation. The ABA opinion even contains an example that reads like a permission slip for process-level judgment: a lawyer who has tested a tool on a sample of contract summaries need not review the entire set by hand. Someone should do a 50 state survey to surface more such examples, I’m sure there are many. (ABA Formal Opinion 512.)
The concern is that a strict reading could give California lawyers a method and tool restriction that opposing counsel does not face in an otherwise comparable engagement. Where the applicable rules differ, why should a California lawyer be barred from using a validated discovery method that another lawyer may lawfully use? California Rule 8.5. But where that disparity exists, the competitive consequences for California lawyer vis-a-vis lawyers of any other state could be substantial. My prediction is that, if the strict reading takes hold, an early practical impact will appear in the cost and speed of handling large matters through California firms. Literally, one side of litigation could be burdened with inferior, more costly, and slower tools and results than the out of state counter-party. The disadvantage could extend to negotiations, large transactions and other work as these systems become more capable and more widely used. California should examine that possibility now, before an uncertain prohibition becomes a practical barrier to methods that lawyers elsewhere may competently and lawfully employ.
IX. What could happen now
The Governor. Sign or veto is his call, and the veto case is real: an undefined prohibition, added late, construed by no published analysis I have found, capable of reaching a method a court has allowed, passed while the profession’s own regulator was still developing the rule amendments the California Supreme Court requested. The bill also carries a citation-verification rule and a confidentiality standard that are worth having, and it passed without a no vote. If he signs, a signing message cannot amend the text or bind the courts and carries little weight as legislative history, but it can state his understanding and invite the State Bar and the Judicial Council to clarify within their own authority. The understanding I would want stated is one sentence: that the prohibition on delegating the practice of law is read consistently with the State Bar’s guidance, as a bar on handing the lawyer’s professional judgment to a machine, not on using these systems to perform legal work under the lawyer’s direction, evaluation and control.
The State Bar. The Bar has already written the principle. Its May guidance calls for retained attorney judgment over AI use. Its pending comment to Rule 1.1, now in a second draft, says competence requires professional judgment over all aspects of a lawyer’s use of technology, inputs and outputs included. One clarifying sentence in that comment, saying that the nature and extent of the judgment depend on the task and the consequences of error and that, where appropriate, it may be exercised over a validated process rather than by separately reviewing every output, would tell lawyers and courts how the Bar reads its own rule before the statute takes effect. A comment is a proposal until the Supreme Court approves it, and it cannot rewrite a statute; but it can say how the profession’s regulator understands the duty, which is what courts will look for, I think. I should disclose that I have helped the State Bar working group drafting those comments as an invited expert. The views here are mine alone, not the committee’s, and I offer them as an interpretation to be tested. That group understands California professional ethics and law far better than I do, and I expect they will make wise decisions on what, if any, comments or other clarifications may be appropriate. (June 2026 proposed comments.)
The Legislature. Courts can interpret the statute; the Legislature can expressly amend it, including by adding a disclosure threshold or clarifying the personal-verification standard. Deleting the explicit reading requirement (in earlier drafts it required reading and verifying, now it only requires verifying) does not by itself tell us whether the Legislature intended a substantive relaxation or a removal of redundancy. I would favor clear legislative language explaining how tools can support a lawyer’s genuinely personal judgment, and functionally where the line is to be drawn.A cleanup bill could specify periodic review of the Judicial Council’s standard, if that is the intended policy; correct the cross-reference in section 128.7; and revisit the mediation-confidentiality provisions that drew opposition to SB 574 from the ADR community. For comparison, the Judicial Council’s own rule for courts requires disclosure at a minimum when a public work is entirely generated, and permits stricter policies; the attorney statute sets no threshold at all. (Rule 10.430.)
Firms. Build the authority and judgment boundary now, whatever the Governor or state bar does. Reserve the professional acts to lawyers in policy, practice, and program: advice, strategy, legal conclusions, negotiation beyond preset parameters, signatures, filings, etc. Let agents do substantial legal work, including research, analysis, drafting and classification, when it flows to a lawyer who decides and makes legal judgments. Enforce authority outside the model: eg no filing credential, no send credential, no settlement authority reachable by an AI identity. Validate on your own matters, sample by consequence, escalate the novel. Keep a record that lets a stranger reconstruct, months later, what the system did and what the lawyer decided. Verify cited authorities yourself; a checker is a first filter. And document your vendors against the confidentiality clause’s actual words. None of that is a safe harbor. It is evidence that you kept the judgment and practice SB 574 (and good sense) say is yours.
X. The bigger point
Regulate by function, not by technology. A generative system and a non-generative classifier may perform comparable substantive work, yet an AI-specific prohibition can treat them differently. A standard focused on the lawyer’s judgment, authority, responsibility and basis for reliance would remain useful as the tools evolve. On the evidence so far, I expect these systems to become more capable and more deeply integrated into legal practice. Accountability is what the law asks of us. Evidence of meaningful control is how we show we provided it. Neither creates permission the statute withholds, which is why the words matter, and the interpretation of those words matters even more.
The line between machine work and human judgment can be drawn, written down and checked. California has written it down without saying where it runs. We have until January to say.

