Supervising a Non-Lawyer Who Uses AI: The RPC 5.3 Exposure Most NJ Small Firms Haven't Thought About
AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published September 23, 2026. Reviewed September 23, 2026.
When a solo attorney uses an AI tool to draft a motion or research a statute, at least one professional judgment sits between the output and the client. The attorney reviews it, questions it, and signs off. That loop, imperfect as it is, offers some ethical insulation.
But here's the scenario that's playing out quietly in NJ small firms right now: the paralegal is the one using the AI. The legal assistant is running client intake summaries through ChatGPT. The office manager is generating draft correspondence. And the supervising attorney is reviewing final work product with little visibility into how it was produced.
That's not a technology problem. It's an RPC 5.3 problem.
What RPC 5.3 Actually Requires
New Jersey's RPC 5.3 places responsibility on attorneys, partners, and supervising lawyers to ensure that non-lawyer staff conduct is compatible with the attorney's professional obligations. The rule doesn't just require that you catch mistakes after the fact. It requires that you put reasonable measures in place to prevent them from happening.
In practice, that means if your paralegal is using an AI tool on client matters, you're responsible for the outputs of that tool as much as if you'd used it yourself. The NJSBA and the broader ABA guidance on AI supervision (see ABA Formal Opinion 512, released in 2024) make clear that supervision of AI-assisted work by non-lawyers triggers the same obligations as any other non-lawyer supervision, and arguably raises the stakes because the error modes are less familiar.
A paralegal who makes a research error will often flag uncertainty. An AI tool that makes a research error sounds authoritative and cites sources that may not exist. The supervisory burden is higher, and most NJ small firms haven't adjusted for it.
The Specific Gaps That Create Exposure
Staff using personal or free-tier AI accounts. If your paralegal is running client information through a free ChatGPT account to summarize deposition transcripts, that data is potentially being used to train future models. Your firm has no data processing agreement, no audit trail, and no ability to assert that client confidentiality was maintained. The attorney is still responsible under RPC 5.3, even if they had no idea it was happening.
No firm-level policy covering staff AI use. Most law firm AI policies, where they exist at all, are written from the attorney's perspective. They don't address what non-lawyers in the firm may or may not do with AI tools, which tools are approved, or what review steps are required before AI-assisted work product reaches a client file.
Assuming staff AI use mirrors attorney AI use. Attorneys who use AI tend to know enough to verify outputs. Non-lawyers with less legal training may not know what a citation-heavy hallucination looks like, or why a confident-sounding summary of a statute might be wrong. The supervision framework has to account for that knowledge gap, not assume it away.
No intake or workflow flagging. If a non-lawyer produces a document and the attorney reviews it without knowing it was AI-assisted, the attorney can't apply the right level of scrutiny. At minimum, internal workflows should require staff to flag whenever AI was used in preparing work product.
What a Reasonable Supervisory Structure Looks Like
First, your firm's written AI policy needs to explicitly address non-lawyer use. List the approved tools by name. Specify that unapproved tools (including personal accounts on approved platforms) cannot be used for client matters. Require that any AI-assisted work product be labeled as such in the file.
Second, build a review checkpoint into your workflow, not just a general instruction to "check your work." For AI-generated drafts, that means the supervising attorney reviews the underlying sources, not just the output. If your paralegal used AI to summarize a deposition, you should look at the key portions of the actual transcript, not just the summary.
Third, train your non-lawyer staff on AI error modes specifically. They need to understand hallucination as a concept, know that AI tools can produce plausible-sounding citations to cases that don't exist, and recognize when a task is too legally complex to delegate to an AI tool without closer attorney involvement.
Finally, document what you've put in place. If a disciplinary matter ever involves non-lawyer AI use at your firm, the first question from a grievance committee will be what supervision structure was in place. "We had a policy and we trained on it" is a defensible answer. "We assumed they knew what they were doing" is not.
RPC 5.3 has always required attorneys to supervise the people working under them. AI tools in the hands of non-lawyers haven't changed that obligation, but they've made it considerably easier to miss the moments when supervision matters most.
Get the weekly roundup
New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.