State lawmakers and regulators are continuing to fill the AI-policy vacuum, and the latest moves in Illinois and California could have immediate consequences for how lawyers, law departments, and neutrals use generative AI in practice.
Illinois recently enacted a broad AI framework, adding to the growing patchwork of state-level rules that can affect businesses well beyond state borders. At the same time, California is advancing measures aimed more directly at the legal industry, including proposals focused on attorneys’ use of AI and arbitrators’ reliance on generative AI in decision-making. Together, those developments signal that AI governance is no longer just a privacy or consumer-protection issue; it is becoming a legal-operations and professional-responsibility issue as well.
For legal professionals, the significance is practical as much as theoretical. Rules aimed at lawyers’ AI use could touch core duties of competence, supervision, confidentiality, and candor. If adopted, they may require attorneys to evaluate when AI assistance must be disclosed, how outputs should be verified, and what guardrails must be in place before client information is entered into third-party tools. For arbitrators and arbitration counsel, proposed limits on generative AI use raise separate concerns about neutrality, transparency, and the integrity of awards.
Litigators should pay particular attention to how these state initiatives may shape discovery disputes, motion practice, and sanctions arguments. As courts and regulators become more attentive to AI-generated errors, parties may increasingly probe whether briefs, declarations, document reviews, or expert analyses were prepared with AI assistance and whether the necessary human review occurred. That creates new risk not only for outside counsel, but also for clients whose internal teams are using AI in investigations, contract analysis, or records management.
For in-house counsel and compliance teams, the emerging state-by-state approach makes governance harder. A company policy that appears sufficient under one state’s framework may fall short in another, especially where legal services, consumer interactions, and employment decisions intersect. Organizations operating nationally may need to build AI controls around the strictest applicable standard, with tailored training for legal staff, business users, and vendors.
The broader takeaway is that regulation is moving closest to the point of use. Rather than waiting for Congress or federal agencies to impose a single nationwide rule, states are starting to regulate AI where it affects professional conduct and adjudicative processes most directly. For the legal industry, that means AI compliance is becoming inseparable from legal ethics and litigation strategy.
Expect more firms and law departments to revisit AI policies, vendor contracts, privilege protections, and review workflows as these proposals mature. The jurisdictions that move first may end up setting the operational baseline for everyone else.