Key takeaways
- California has passed legislation setting specific requirements for lawyers using generative AI, including verification, confidentiality and disclosure obligations.
- The legislation reinforces a wider principle that professional responsibility remains with the human professional, even when AI performs substantial parts of the work.
- New Zealand professional services firms should consider putting equivalent controls into practice now rather than waiting for AI-specific legislation.
California has taken an important step in regulating AI in professional practice. On 31 August 2026, its legislature passed Senate Bill 574, which sets specific requirements for lawyers using generative AI.
For New Zealand firms, the significance is not whether California’s rules apply here. It is that principles already appearing in professional guidance are starting to move into legislation elsewhere.
Human responsibility remains central
One of the clearest provisions in SB 574 is that a lawyer must not delegate the practice of law to generative AI. AI may assist with research, document analysis or drafting, but responsibility for the work remains with the lawyer.
The same underlying principle applies in New Zealand. Lawyers remain responsible for the legal services they provide and must continue to exercise professional judgement when using AI.
This principle is also relevant to accountants, financial advisers, consultants and other professionals. AI can support professional judgement, but it should not quietly become the decision-maker where responsibility rests with a person.
Verification is becoming a defined control
SB 574 would require lawyers using generative AI to take reasonable steps to verify the accuracy of outputs, including legal citations, and correct erroneous or hallucinated material before use. For court filings, the attorney responsible must personally verify citations.
This highlights a practical governance problem. Many organisations tell staff to “check” AI output, but the required level of checking is often unclear.
Verification should instead reflect the consequence of an error. A low-risk internal summary may need basic review, while legal advice, financial calculations, regulatory submissions or court material should be checked against authoritative sources.
Confidential information needs stronger controls
The Bill would also restrict lawyers from entering confidential, personally identifying or other non-public information into AI systems where access is not appropriately protected.
New Zealand firms face the same underlying issue. They need to understand whether information entered into AI tools is retained, reused, accessible to providers or processed in other jurisdictions.
The risk is increasingly broader than someone copying confidential information into a public chatbot. Connected AI tools may be able to access documents, email, client files and other systems directly, making permissions, access controls and system configuration part of AI governance.
Disclosure is becoming part of the discussion
SB 574 also addresses disclosure of generative AI use in court-related work.
New Zealand does not currently impose an equivalent general disclosure requirement, but the issue is likely to become more important as AI plays a greater role in substantive professional work.
Using AI to improve grammar is very different from using an AI agent to analyse evidence or produce substantive conclusions. Firms should therefore consider when AI involvement becomes significant enough to require disclosure, client agreement or additional review.
Agentic AI raises the stakes
AI tools are increasingly moving beyond individual prompts into systems that can retrieve information, interact with other applications and complete multiple tasks.
That changes the governance challenge. Firms need to consider not only what an AI model can generate, but also what information it can access, what actions it can take and where human approval is required.
Controls designed solely around individual prompts may no longer be enough.
What this means for your organisation
Professional services firms do not need to copy California’s legislation, but its requirements provide a useful governance benchmark.
Define human responsibility. Identify tasks where AI may assist but a qualified professional must remain responsible for the final judgement, advice or decision.
Make verification risk-based. Set stronger verification requirements for higher-consequence work and require authoritative sources where appropriate.
Protect confidential information. Confirm which AI tools may process client information and review access, retention, integrations and provider controls.
Review connected AI separately. Treat tools with access to email, documents or client systems as a higher governance risk than isolated chatbots.
Set disclosure thresholds. Decide when material AI involvement should be disclosed to a client, regulator, court or other party.
The direction is becoming clearer
California’s legislation is not a New Zealand rule, but it illustrates where AI governance is heading: towards specific and demonstrable controls around confidentiality, verification, human responsibility and transparency.
For New Zealand professional services firms, these are sensible controls to implement now. As AI becomes more deeply connected to client information and professional workflows, governance needs to move from broad principles into everyday operating rules.
General information disclaimer
This article provides general information and commentary only. It is not legal, regulatory, technology or other professional advice. Organisations should assess AI use against their own professional obligations, contracts, information requirements and risk environment.
Sources
- California Legislature – SB 574: Attorneys, arbitrators, judicial officers, and alternative resolution providers
- New Zealand Law Society – Generative AI guidance for lawyers
- Courts of New Zealand – Guidelines for use of generative artificial intelligence in Courts and Tribunals

