BC lawyers and law firm leaders

What does the Law Society of BC's generative AI guidance require?

Sources verified Sanitized Ai Team

The short answer

The Law Society of British Columbia has not created AI-specific rules. Its practice resource, Guidance on Professional Responsibility and Generative AI, applies existing BC Code duties: competence (rule 3.1-2), confidentiality (rule 3.3-1), candour, supervision (rule 6.1-1), fair fees, and the records security obligations in Law Society Rules 10-3 and 10-4. Its core advice on confidentiality is to leave client confidential and identifying information out of generative AI tools, and to consider informed client consent where redaction is not possible.

The situation

A Vancouver IP firm of 25 people is updating its engagement letters. A client in the life sciences sector wants to know whether the firm uses generative AI, and if so, what stops its confidential research from ending up in someone else's model. The operations director has a draft policy that says "no client information in public AI tools." The managing partner wants to know whether that matches what the Law Society of British Columbia expects, and whether one line is enough.

The Law Society's answer is that the usual duties apply, with a specific emphasis: keep client confidential information out of the tool unless you have a sound reason and, where needed, the client's informed consent. Making that hold across a busy office is the harder part.

What the rules actually say

The practice resource

The Law Society's Guidance on Professional Responsibility and Generative AI was prepared in October 2023. It walks through competence, confidentiality, candour, responsibility for work product, information security, court requirements, fees, copyright, fraud and bias. The Law Society has since listed AI among its strategic priorities, and that page remains the place to check for new material.

Competence (rule 3.1-2)

Rule 3.1-2 of the BC Code requires lawyers to perform all legal services to the standard of a competent lawyer. In March 2024, the Code added commentary [4.1] and [4.2]: competence includes understanding the benefits and risks of relevant technology, recognizing the duty to protect confidential information. The guidance adds that a lawyer who uses generative AI to perform tasks needs to be knowledgeable in how the technology works.

Confidentiality (rule 3.3-1)

Rule 3.3-1 requires strict confidentiality, with very limited exceptions. The guidance suggests that, ideally, client confidential information, including anything that identifies the client, is left out of whatever is given to a generative AI tool. If redaction is not possible, a lawyer can explore informed client consent, using the Code's definitions of consent and disclosure in rule 1.1-1. The guidance flags two risks the lawyer must be able to explain: that the tool may reuse what it receives for purposes outside the lawyer's control, and that using the tool could raise arguments about privilege waiver. Our post on how one AI prompt can waive privilege looks at that second risk.

Supervision (rule 6.1-1)

Rule 6.1-1 gives a lawyer complete professional responsibility for all business entrusted to them and requires direct supervision of staff and assistants. The guidance acknowledges that the rule was written for human supervision, but treats it as a reminder that lawyers are responsible for all work product they oversee, whether staff or technology produced it.

Records security (Rules 10-3 and 10-4)

The guidance also points to the Law Society Rules. Rule 10-4 requires reasonable security arrangements against unauthorized access, use or disclosure of practice records, and immediate written notice to the Executive Director if a lawyer has reason to believe they have lost custody or control of records. The guidance says AI tools deserve the same scrutiny as other software.

Courts

The BC Court of Appeal's filing directive reminds litigants that they are responsible for the authenticity and accuracy of everything they file.

Why policies and bans fall short

A policy line such as "no client information in public AI tools" states the duty correctly. It does not tell anyone, in the moment, that the paragraph they just copied contains a client name, a compound structure, or a licensing term. People paste whole blocks of text, and identifying details come along. LayerX found in 2025 that 71% of generative AI connections use personal, non-corporate accounts, which a firm typically has no view into.

Bans push the same behaviour onto personal devices and accounts. The supervision duty in rule 6.1-1 does not shrink because the use is hidden; it just becomes harder to show that it was met. And there is no undo. Once confidential information is submitted to a public AI tool, it cannot be recalled, and it becomes subject to the provider's terms, which can permit retention, sub-processing, and in some cases training.

What a practical control looks like

A BC firm can turn the guidance into a working program:

  1. Write a short, specific policy. Name the approved tools, the accounts to use, and the data that must never be entered: client names and identifiers, invention details, privileged advice, deal terms, and personal information.
  2. Vet each tool like other software. Review terms, data retention and security against Rules 10-3 and 10-4 before approval, and record the decision.
  3. Build a consent path. Where redaction is not workable, prepare a plain-language disclosure and record the client's informed consent, as the guidance describes.
  4. Train at onboarding and at the prompt. Explain why identifying details matter, not only that they are banned.
  5. Define an incident response. Decide in advance who assesses an exposure, whether the client is told, and whether notice to the Law Society under Rule 10-4 needs to be considered with counsel.
  6. Verify output separately. Citation and accuracy checks for court filings stay with a lawyer.

If your firm has already rolled out a sanctioned tool and staff still reach for personal accounts, our guide on sanctioned AI rollouts and shadow AI covers that gap. Firms practising in Ontario too can compare this with the Law Society of Ontario's guidance.

Sanitized Ai is a browser extension that puts steps 1 and 4 to work in the browser, where the AI tools are. When someone pastes or uploads client identifiers, invention details, personal information, or deal terms into an AI assistant, it detects that data and redacts or blocks it before submission, then explains to the person in plain language what was flagged and why. The confidential detail is not submitted, and the person learns the policy at the moment it applies. Coverage spans the major AI assistants and keeps growing.

For supervising lawyers, the administrator dashboard shows flagged-event metadata (which tool, what type of data, which policy, when) and never shows prompt content. That record can serve as evidence that reasonable safeguards were in place, without anyone reading privileged text. It does not check citations or legal accuracy. Confirm your approach with a Law Society practice advisor or your own counsel, and see how it fits a firm's workflow on our law firms page.

Frequently asked questions

Is the Law Society of BC guidance on generative AI binding?

The guidance is a practice resource, not a rule. It explains how binding obligations in the BC Code and the Law Society Rules apply to generative AI. The Law Society notes that lawyers must exercise their own professional judgment and invites them to contact a practice advisor with specific questions.

Has the Law Society of BC updated its AI guidance?

The practice resource was prepared in October 2023. Since then, the BC Code added technological competence commentary to rule 3.1-2 in March 2024, and the Law Society has named AI a strategic priority, including a consultants' presentation to the Benchers in April 2026. Check the Law Society's AI page for anything newer.

Can a BC lawyer put client information into ChatGPT with client consent?

The guidance treats consent as a fallback when redaction is not possible, not as the default. Consent must be informed and voluntary, given after disclosure, either in writing or orally with a written record. The lawyer must understand the tool well enough to explain the risks, including possible arguments that privilege was waived.

Do BC courts require lawyers to disclose AI use?

Requirements vary by court. The BC Court of Appeal's filing directive reminds all litigants that they are responsible for the authenticity and accuracy of materials they file, and the Provincial Court has published guidance on checking AI-assisted material. Check the current directions of the court or tribunal before filing.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading