California SB 574: The Two AI Requirements That Are Actually IT Problems
SB 574 would take the AI guidance lawyers have been getting from bar associations and turn it into enforceable state law. It does not ban AI in legal practice. It says the duties you already had still apply when a machine does part of the work — and two of its four requirements come down to what your technology setup can prove.
California SB 574 would take the AI guidance lawyers have been getting from bar associations and turn it into enforceable state law, with four requirements: keep confidential and nonpublic information out of public AI systems, take reasonable steps to remove biased or offensive content from AI-generated material, personally read and verify every citation in a court filing, and stop arbitrators from handing decisions to AI.
Here is the part most coverage skips. One of those four is purely a lawyer's judgment call. One only applies if you sit as an arbitrator. The two left over are the ones that will actually catch a law firm out, and neither of them is a legal problem. They depend on things your technology setup either does or does not do, and most firms cannot currently prove theirs does.
Key Takeaways
- SB 574 passed the full California Legislature on August 31, 2026 and is now on Governor Newsom's desk, with a decision window running to roughly mid-October.
- The bill writes four attorney AI duties into state law: confidentiality at the prompt, reasonable steps against biased output, personal citation verification, and no AI delegation by arbitrators.
- It carries no new penalties — it plugs into court sanctions and State Bar discipline, machinery that already exists and already works.
- Two of the four requirements are technology problems: proving client data never entered a public AI system, and enforcing an approved tool list, both depend on your IT configuration.
- 53% of legal professionals say their firm has no AI policy or are unsure one exists, while 82% plan to increase AI use in the next 12 months (Clio, 2025).
- A written policy is a statement of intent; under a statute enforced through discipline, proof has to come from your systems.
Where Does California SB 574 Stand Right Now?
It passed. SB 574 cleared the California Senate on January 29, 2026 on a unanimous 39 to 0 vote, moved through Assembly committees over the summer, and passed the full Legislature in the final days before the session adjourned on August 31, 2026. The bill is now enrolled and sits on Governor Newsom's desk, where he has roughly 30 days from adjournment to sign or veto it — a decision expected by roughly mid-October 2026.
Technically the bill amends Section 6173 of the Business and Professions Code and adds Section 6068.1, and amends Section 128.7 of the Code of Civil Procedure while adding Sections 180 and 1282.1. The author is Senator Tom Umberg, who chairs the Senate Judiciary Committee. Coverage of the final version also notes it would require attorneys to disclose the use of generative AI to the court for documents submitted to it — an addition beyond the four core requirements below.
We are not lawyers and this is not legal advice. What your firm owes its clients under the Rules of Professional Conduct is between your firm and your bar association. What follows is the technology side: the part where somebody has to configure something.
What Are the Four Things SB 574 Would Require?
1. Keep Nonpublic Info Out of Public AI
Attorneys using generative AI have to make sure confidential, personally identifying, or otherwise nonpublic information does not get typed into a public AI system.
2. Reasonable Steps Against Biased Output
Take reasonable steps to remove biased or offensive content from AI-generated material — even when it was prepared by someone else on the attorney's behalf.
3. Personally Verify Citations
The filing attorney reads and verifies every citation in a filing. Not just the AI-generated ones. Every one.
4. Arbitrators Cannot Delegate to AI
Arbitrators cannot hand decision-making to AI, and have to be transparent about how they use it.
The bill carries no independent penalties of its own. It is enforced the way attorney conduct is already enforced, through court sanctions and the State Bar disciplinary process.
That last detail is easy to skim past and it is the whole point. A rule with no new penalty attached is not a soft rule. It is a rule that plugs into machinery that already exists and already works.
Which SB 574 Requirements Are Actually IT Problems?
Sort them by who can act on them and the picture changes.
Requirement three is a lawyer reading a case. Nobody can configure that for you. Requirement four is about arbitrators, so unless someone at your firm sits as one, it is not your problem this year.
That leaves requirements one and two. Both have a technology half, and it is the half that decides whether you can demonstrate compliance or only assert it.
Take requirement one, the confidentiality rule. "Do not put client information into a public AI system" is a sentence any firm can put in a handbook. Proving it did not happen is a completely different job. To know that, you need to know which AI tools are reachable from firm devices, which accounts staff are signed into, whether those accounts are consumer or business tier, and whether anything is logging it. Most small firms have none of that, which means their honest answer to "can you show client data never went into a public model" is no.
Requirement two has the same shape. Taking reasonable steps about AI output that somebody else prepared means you need to know what tools that somebody used, which means you need an approved tool list and a way to enforce it.
The Gap Between Having a Rule and Being Able to Prove It
A written AI policy is the necessary first step, and most firms still do not have one. Clio's 2025 Legal Trends Report found 53% of legal professionals say their firm has no AI policy or they are not sure whether it has one, while 82% plan to increase their AI use over the next 12 months.
But a policy on its own is a statement of intent. Under a statute enforced through sanctions and bar discipline, intent is not the thing anyone will ask you about. They will ask what happened, and the answer has to come from your systems.
How Do You Keep Client Information Out of Public AI Systems?
Four things, in the order we would actually do them.
Find Out What Is Already in Use
Not what the policy says. What people are signed into right now. In a Microsoft 365 environment you can see a lot of this from the admin center and from Entra ID sign-in and application data, without buying anything new. Firms are regularly surprised here, and the surprise is the useful part.
Give People a Sanctioned Tool Good Enough to Win
This is the step firms skip and it is the one that decides everything else. If the approved option is worse than the free one somebody found on their own, the free one wins and your policy becomes decoration. A business-tier AI tool inside your own tenant, where your data is covered by a real agreement instead of consumer terms, is what makes "do not use the public one" a reasonable thing to ask.
Draw the Line at the Device and the Network
Block or flag consumer AI endpoints on managed devices. Use data loss prevention rules so a document labeled as client-confidential cannot be pasted into an unapproved web app. This is where "keep nonpublic information out of public AI systems" stops being a promise and starts being a control.
Keep a Record
Which tools are approved, who approved them, when, who has access, and what training they completed. Under a rule enforced through discipline, the record is the deliverable.
Does SB 574 Apply to Your Firm If You Are Not in California?
Directly, no. It governs attorneys licensed in California and arbitrators in California proceedings.
Practically, treat it as a preview. Over 20 state bars have already issued formal ethics opinions or guidance on attorney AI use, led by ABA Formal Opinion 512, issued July 29, 2024. SB 574 is the first serious attempt to move that guidance from advisory to statutory. California tends not to be the only state to do a thing.
There is also a client-driven version of this that arrives sooner than any statute. Corporate clients with California counsel, or with their own AI governance requirements, ask their outside firms what controls they have. That question does not wait for a bill to be signed.
What Is the Argument Against SB 574?
Worth knowing, because it is not a fringe position. The bill includes a flat statement that an attorney shall not delegate the practice of law to generative AI, with no stated exceptions, unlike its other provisions which are framed around supervision. Critics point out that "the practice of law" has been argued over in California courts for more than a century without a precise definition, and that a blanket prohibition resting on an undefined term could sweep in ordinary legal AI tools where a person reviews everything before it goes out.
We think that debate matters for vendors more than it changes what a firm should do this month. Whether the delegation clause survives a veto, gets amended later, or gets read narrowly by a court, none of the four requirements above are things a firm would regret being able to demonstrate.
What Should Your Firm Do in the Next 30 Days?
Start with the question you would least like to be asked: if a judge or your bar wanted proof that no client information went into a public AI tool from your firm this year, what would you hand them?
If the answer is a policy document, you have a gap between what you have written down and what you can show. Closing it is mostly configuration work in systems you already pay for. Run the discovery on what is actually in use, get a sanctioned tool in place that people will actually prefer, put the controls at the device and data layer, and keep the record.
We do this work for law firms as their outside IT and security team. Simpatico is a managed service provider, meaning we run and secure a firm's technology as an ongoing service rather than showing up when something breaks.
Frequently Asked Questions
What is California SB 574?
Does SB 574 ban lawyers from using AI?
When does SB 574 take effect?
Can lawyers use ChatGPT with client information?
What penalties does SB 574 carry?
Does SB 574 apply to law firms outside California?
Do we need a written AI policy to comply with SB 574?
What is the difference between having a policy and proving compliance?
Who has to verify citations under SB 574?
What should a small law firm do first?
What Would You Hand a Judge?
If you cannot currently answer "which AI tools is my firm using, and can I prove client data never went into a public one," that is the gap — and it is fixable with configuration rather than a rewrite. We will start with what is actually running in your environment.
- The AI tools actually in use at your firm
- The policy-to-proof gap
- Controls at the device and data layer