• Legal
  • Intapp Celeste
  • Intapp Walls

The three hidden gaps in your ethical walls

Your firm has ethical walls. They’re documented. You run conflict checks before opening matters. You’ve trained the team on information barriers. You believe the screen holds.

Then you deploy Harvey or CoCounsel to speed up client intake. Within two weeks, the generalist AI agent starts drafting conflict research without knowing it’s accessing a matter your firm is ethically screened from. Or the agent pulls a confidential client profile to help with due diligence, and the system never logs the access. Your walls didn’t stop it because the wall was built for lawyers, not for machine-executed workflows that move faster than your access-control system can track.

The core problem: agentic AI systems operate differently than human workflows. According to the State Bar of California, “agentic AI introduces an additional degree of autonomy, including the ability to initiate tasks or interact with external tools, and the capacity to conclude tasks without human review or approval.” This autonomy means the agent executes across your systems in parallel, hitting all three of them before your ethical walls can synchronize across them.

This is not hypothetical. It’s the seam that’s causing malpractice insurers to rethink how they price law firm cyber and E&O policies.

Ethical walls (sometimes called ethics walls or information barriers) are systems of controls that prevents confidential information from flowing between lawyers or teams who would otherwise create a conflict of interest. Under California Rule 5.1 Comment [1], recently amended to address AI governance, firms must establish explicit policies and procedures for AI use. Your firm’s ethical walls were built for lawyers navigating manually. They don’t account for how agentic AI executes across multiple systems in parallel.

The problem is this: most ethical walls are built as a series of disconnected controls. One system enforces file-level access. Another enforces email restrictions. A third blocks matter-level searches in the practice management system. When these controls are applied to human workflows alone, the gaps between them often go unnoticed. A lawyer tries to access a screened file, the system says no, and the wall holds.

But when you introduce AI agents that execute tasks across multiple systems simultaneously, those gaps become exploitable seams.

Gap one: the handoff between systems

Most ethical walls live in one place. Your practice management system knows which matters are screened and restricts database access. But the firm’s document repository is a separate system. The email system is a third. When a lawyer manually tries to access a screened matter, each system independently enforces the wall. The human being has to navigate from practice management to the document repository to email, and each transition is a checkpoint.

Agentic AI systems don’t navigate that way. They execute tasks across all systems in parallel. An AI agent tasked with drafting a conflict-of-interest analysis might simultaneously query the practice management database, search the document repository, scan email for related-party references, and cross-reference the firm’s client list. If the wall is enforced in practice management but not in the document repository, the agent finds the information in the second system and includes it in the draft.

The firm’s ethical wall was correctly configured in one place. The gap exists because nobody verified that the wall follows the matter into every system where data lives. This is the most common failure mode. The wall in one place does not magically appear in three others.

Gap two: the audit trail that doesn’t exist

When a lawyer accesses a confidential file they shouldn’t, the access control system says no and the lawyer gets denied. The denial creates a log entry. Someone can later audit that entry and see the blocked attempt. The wall enforces and the wall records.

AI agents are different. When you give an AI tool access to your systems, it often gets broad query permissions so it can work efficiently. You configure the ethical wall in that tool’s matter-level settings. The wall is real inside the tool. But the tool doesn’t create a user-facing log every time it respects a screen. It respects the screen silently. And if the wall ever fails silently (a configuration drift, a missing parameter in an API call, a version mismatch between the tool and your file server), you have no audit trail showing that the breach happened.

This gap creates two problems. First, when a conflict question arises later (a lateral partner wants to move to a new practice, a client asks if you can handle a related matter), you can’t pull the audit trail and prove the wall held during the relevant period. Second, if the wall did fail silently, you may not discover it until a client notices something odd, or until a disqualification motion surfaces the breach in discovery.

The walls are only as real as their audit trails. For AI systems, that trail is often missing or incomplete.

Gap three: the moment the matter opens

Most ethical walls are configured retroactively. A potential conflict emerges. The firm runs a conflict check. The check returns a hit. The firm implements a wall around the conflicted matter. The screen takes effect going forward.

But the moment between the conflict check completing and the wall being activated is a gap. If that window is thirty seconds, the risk is usually low. But when an AI agent is running multiple conflict checks in parallel across many matters, and when the matter is being simultaneously opened in several systems (practice management, billing, document management, email), the window expands.

An agent might query the database and get a conflict-clear result. The matter begins opening. Before the walls are fully configured in all relevant systems, the agent has already created a matter record, assigned initial documents, or triggered automated workflows. If the conflict-check result was a false negative, or if a related conflict emerges immediately after the initial check, the walls were incomplete at the critical moment when the matter was being set up. Data has already moved into a matter that should have been screened.

How firms are discovering these gaps

According to AI Vortex, 61% of malpractice carriers now ask about AI use in law firm intake applications. More than half of the thirteen major carriers surveyed—which together provide 80% of malpractice coverage to Am Law 200 firms — reported a rise in AI-related claims over the past year, according to Best Law Firms.

The discovery process is expensive. A firm realizes the gap only after something breaks. A conflict emerges. The firm’s AI tool should have caught it. It didn’t. The question then becomes not just “did we miss this conflict” but “what else did we miss while that gap was open.”

Carriers are responding by hardening their underwriting questions. They’re asking specifically about AI systems and information barriers. They’re increasing premiums for firms that haven’t documented their controls. And they’re flagging to risk officers that policies written before 2023 likely don’t cover AI-related incidents at all.

Speak with our team about governed AI for law firms.

Frequently asked questions

The amendment to Comment [1] clarifies that firms must configure agentic AI systems with appropriate matter-level access controls, the same way you’d configure access for a new attorney joining a department. The rule doesn’t require you to stop using AI. It requires you to verify that when you deploy an AI tool to a workflow, the ethical wall travels with the matter through that tool. If the tool accesses three systems, the wall needs to be enforced in all three, not just one.

Most firms discover this by testing. You document which systems contain client data. You map where your current ethical walls are enforced (practice management, email, document repository, billing). You then deploy a test AI agent with access to the same systems and give it a matter that should be screened. If the agent finds information it shouldn’t, you have a gap. If the agent produces an audit trail of every screen it respected, you have better coverage. Few firms have done this testing yet.

Malpractice carriers are pricing this risk now: 61 percent of major carriers ask about AI use in intake applications, and more than half report a rise in AI-related claims over the past year. The exposure has two edges. First, policies written before 2023 likely exclude AI entirely, leaving a coverage gap if a claim surfaces. Second, firms without documented AI governance controls are charged higher premiums or face non-renewal. The real exposure is a breach discovered during client audit or litigation—at which point the question shifts from “did we miss this?” to “why didn’t our controls catch it?”

Document your ethical walls coverage. Map out where information lives (which systems, which databases, which repositories). For each system, verify that your ethical walls are actually enforced there. For any system where the walls are missing, either add them or restrict your AI agents’ access to that system. Then test the configuration with a low-risk scenario before running it at scale.

California’s proposed amendments to Rule 5.1 Comment [1] emphasize that firms must establish internal policies and procedures governing AI use. Other jurisdictions are following suit. Malpractice carriers have already made it clear that firms without documented AI governance are now a higher risk category. And the window is closing—by the time your next policy renewal rolls around, your carrier will ask questions specifically about how your firm’s ethical walls have been configured for AI systems. The good news is that this problem is solvable. It’s not a product issue. It’s a configuration and audit issue. But it requires intentional work now, before a gap turns into a claim.