The Duty of Technology Competence: What Lawyers Need to Know

Competence now includes understanding the benefits and risks of the technology you use. Here is what that means day to day.

· 5 min read · eLaw Platform

A neatly arranged set of gadgets including a laptop, phone and a business book
Photo by Oscar Nilsson on Unsplash

For most of legal history, competence meant knowing the law and how to apply it. Over the past decade it has come to include something more: understanding the technology you use to practise, well enough to use it safely. The duty of technology competence now shapes how lawyers are expected to handle email security, e-discovery, cloud storage and, most recently, generative AI.

This guide explains where the duty comes from, what it covers in practice and how to build a manageable plan to meet it. It is aimed at lawyers in private practice and in-house teams who want a clear picture without wading through every state opinion.

This article is general information, not legal advice. Whether and how the duty applies depends on your jurisdiction's rules.

Where the duty comes from

In 2012 the American Bar Association amended Comment 8 to Model Rule 1.1 on competence to say that keeping abreast of changes in the law and its practice includes "the benefits and risks associated with relevant technology." A large majority of US states have since adopted similar language, and some have added continuing education requirements focused on technology.

The rule does not require lawyers to become engineers. It requires enough understanding to make informed decisions, or to get help from someone who has it.

What it covers in practice

Bar opinions and disciplinary cases have applied the duty across several areas.

Communication and data security

Knowing how to send sensitive information securely, recognise phishing and protect devices. Opinions on email encryption and cloud storage generally ask whether the lawyer took reasonable precautions given the sensitivity of the information.

Electronic discovery

Understanding how clients store data, what preservation obligations mean for electronic records and how to supervise vendors. Courts have criticised lawyers who did not grasp their own clients' systems well enough to preserve or produce evidence.

Cloud services and practice software

Vetting providers of document storage, practice management and billing software for security, confidentiality and data ownership.

Video and remote practice

Managing confidentiality in virtual meetings and remote hearings, including who else may be in the room or on the call.

Generative AI

The ABA's Formal Opinion 512 applies competence directly to AI: lawyers should understand the capabilities and limitations of the tools they use, including the risk of inaccurate output, and should not rely on them uncritically.

What "competent" looks like

The standard is reasonableness, not perfection. A practical way to think about it is three levels of knowledge for each technology you use:

Level What you should know Example for an AI drafting tool
Purpose What it does and when to use it Produces first drafts of routine documents
Risks How it can fail or expose information May invent citations; vendor may retain inputs
Safeguards What you do to manage those risks Verify all authority; use only approved, contracted tools

If you cannot fill all three columns for a tool you use on client matters, that is a gap worth closing.

Building a realistic plan

Audit what you use

List every tool that touches client information: email, document storage, practice management, e-signature, video, AI. For each, note who approved it and whether anyone has read its data terms.

Pick a few priorities a year

You cannot master everything at once. Choose two or three areas where your practice is most exposed, for example email security and AI use, and focus learning there.

Use the resources available

  • Technology-focused CLE programmes, which some states now require.
  • Your state bar's ethics opinions on technology.
  • Your malpractice insurer's risk management materials.
  • Vendor documentation, read critically.

Delegate with supervision

You may rely on IT staff, consultants or vendors, but the duty to supervise remains. Know enough to ask the right questions and understand the answers.

Document decisions

Record why you chose a tool and what safeguards you put in place. If questions arise later, a written rationale shows you took the duty seriously.

Common gaps

  • Using personal email or consumer file-sharing for client documents.
  • Not knowing whether an AI tool retains or trains on inputs.
  • Failing to understand a client's data systems before a litigation hold.
  • Assuming a vendor's marketing claims about security are accurate without checking terms.

When evaluating legal AI, competence means understanding where answers come from and how data is handled. eLaw describes its platform as giving cited answers on firm-isolated data across document analysis and legal research. Citations and isolation make verification and confidentiality easier to manage, but they do not replace your own review.

Your next three moves

  1. List every technology you use on client matters.
  2. Fill in the purpose, risks and safeguards columns for each.
  3. Choose two areas to strengthen this year and book relevant CLE.

FAQ

Is technology competence required in every state?

Most US states have adopted language similar to ABA Model Rule 1.1 Comment 8, but not all, and wording varies. Some states also require technology-related continuing education. Check your own jurisdiction's version of the rule and any related ethics opinions.

Do I have to use AI to be technologically competent?

Generally no. The duty concerns understanding the benefits and risks of relevant technology, not adopting any particular tool. However, as technologies become standard in practice, lawyers may need to understand them well enough to advise clients or to recognise when using them would serve a client better.

Can I rely entirely on my IT provider for technology competence?

You can rely on experts for implementation, but the professional duty remains yours. You should understand enough to make informed decisions, ask meaningful questions and supervise the provider. Keeping a record of the advice you received and your decisions is a sensible practice.

What is a reasonable first step for a solo practitioner?

Start with an inventory of the tools that touch client information and read the data and security terms for each. Then fix the most obvious gaps, such as enabling two-factor authentication and moving client files out of personal accounts. Many state bars offer free resources aimed at small practices.

← All articles