Your firm has ethical walls. They’re documented. You run conflict checks before opening matters. You’ve trained the team on information barriers. You believe the screen holds.
Then you deploy Harvey or CoCounsel to speed up client intake. Within two weeks, the generalist AI agent starts drafting conflict research without knowing it’s accessing a matter your firm is ethically screened from. Or the agent pulls a confidential client profile to help with due diligence, and the system never logs the access. Your walls didn’t stop it because the wall was built for lawyers, not for machine-executed workflows that move faster than your access-control system can track.
The core problem: agentic AI systems operate differently than human workflows. According to the State Bar of California, “agentic AI introduces an additional degree of autonomy, including the ability to initiate tasks or interact with external tools, and the capacity to conclude tasks without human review or approval.” This autonomy means the agent executes across your systems in parallel, hitting all three of them before your ethical walls can synchronize across them.
This is not hypothetical. It’s the seam that’s causing malpractice insurers to rethink how they price law firm cyber and E&O policies.
Ethical walls (sometimes called ethics walls or information barriers) are systems of controls that prevents confidential information from flowing between lawyers or teams who would otherwise create a conflict of interest. Under California Rule 5.1 Comment [1], recently amended to address AI governance, firms must establish explicit policies and procedures for AI use. Your firm’s ethical walls were built for lawyers navigating manually. They don’t account for how agentic AI executes across multiple systems in parallel.
The problem is this: most ethical walls are built as a series of disconnected controls. One system enforces file-level access. Another enforces email restrictions. A third blocks matter-level searches in the practice management system. When these controls are applied to human workflows alone, the gaps between them often go unnoticed. A lawyer tries to access a screened file, the system says no, and the wall holds.
But when you introduce AI agents that execute tasks across multiple systems simultaneously, those gaps become exploitable seams.
Gap one: the handoff between systems
Most ethical walls live in one place. Your practice management system knows which matters are screened and restricts database access. But the firm’s document repository is a separate system. The email system is a third. When a lawyer manually tries to access a screened matter, each system independently enforces the wall. The human being has to navigate from practice management to the document repository to email, and each transition is a checkpoint.
Agentic AI systems don’t navigate that way. They execute tasks across all systems in parallel. An AI agent tasked with drafting a conflict-of-interest analysis might simultaneously query the practice management database, search the document repository, scan email for related-party references, and cross-reference the firm’s client list. If the wall is enforced in practice management but not in the document repository, the agent finds the information in the second system and includes it in the draft.
The firm’s ethical wall was correctly configured in one place. The gap exists because nobody verified that the wall follows the matter into every system where data lives. This is the most common failure mode. The wall in one place does not magically appear in three others.
Gap two: the audit trail that doesn’t exist
When a lawyer accesses a confidential file they shouldn’t, the access control system says no and the lawyer gets denied. The denial creates a log entry. Someone can later audit that entry and see the blocked attempt. The wall enforces and the wall records.
AI agents are different. When you give an AI tool access to your systems, it often gets broad query permissions so it can work efficiently. You configure the ethical wall in that tool’s matter-level settings. The wall is real inside the tool. But the tool doesn’t create a user-facing log every time it respects a screen. It respects the screen silently. And if the wall ever fails silently (a configuration drift, a missing parameter in an API call, a version mismatch between the tool and your file server), you have no audit trail showing that the breach happened.
This gap creates two problems. First, when a conflict question arises later (a lateral partner wants to move to a new practice, a client asks if you can handle a related matter), you can’t pull the audit trail and prove the wall held during the relevant period. Second, if the wall did fail silently, you may not discover it until a client notices something odd, or until a disqualification motion surfaces the breach in discovery.
The walls are only as real as their audit trails. For AI systems, that trail is often missing or incomplete.
Gap three: the moment the matter opens
Most ethical walls are configured retroactively. A potential conflict emerges. The firm runs a conflict check. The check returns a hit. The firm implements a wall around the conflicted matter. The screen takes effect going forward.
But the moment between the conflict check completing and the wall being activated is a gap. If that window is thirty seconds, the risk is usually low. But when an AI agent is running multiple conflict checks in parallel across many matters, and when the matter is being simultaneously opened in several systems (practice management, billing, document management, email), the window expands.
An agent might query the database and get a conflict-clear result. The matter begins opening. Before the walls are fully configured in all relevant systems, the agent has already created a matter record, assigned initial documents, or triggered automated workflows. If the conflict-check result was a false negative, or if a related conflict emerges immediately after the initial check, the walls were incomplete at the critical moment when the matter was being set up. Data has already moved into a matter that should have been screened.
How firms are discovering these gaps
According to AI Vortex, 61% of malpractice carriers now ask about AI use in law firm intake applications. More than half of the thirteen major carriers surveyed—which together provide 80% of malpractice coverage to Am Law 200 firms — reported a rise in AI-related claims over the past year, according to Best Law Firms.
The discovery process is expensive. A firm realizes the gap only after something breaks. A conflict emerges. The firm’s AI tool should have caught it. It didn’t. The question then becomes not just “did we miss this conflict” but “what else did we miss while that gap was open.”
Carriers are responding by hardening their underwriting questions. They’re asking specifically about AI systems and information barriers. They’re increasing premiums for firms that haven’t documented their controls. And they’re flagging to risk officers that policies written before 2023 likely don’t cover AI-related incidents at all.
Speak with our team about governed AI for law firms.