79% of legal professionals now use AI (Clio 2025 Legal Trends), and firms are shipping AI-built intake forms, chatbots, and client portals in days. But CVE-2025-48757 showed 170+ Lovable apps exposing client data because row-level security was off by default - and for a law firm, a leaky app isn't just a breach. It's a violation of ABA Model Rule 1.6(c), a tech-competence problem under Rule 1.1, and a potential privilege waiver. We audit AI-built legal apps for the risks that trigger bar discipline, not just CVEs.
AI use among lawyers nearly tripled from 11% to 30% in a single year (ABA), while 53% of firms have no AI policy or don't know if they have one. AI builders generate a working intake form or chatbot in minutes - not a defensible one.
AI builders ship Supabase-backed intake forms fast, often with row-level security left off by default - CVE-2025-48757 found 170 of 1,645 sampled Lovable apps (10.3%) critically exposed, with RLS disabled in roughly 70% of cases. Intake data (injury details, opposing parties, even SSNs) queryable with the public anon key also triggers ABA Rule 1.18 prospective-client duties, even for people who never sign as clients.
A chatbot conversation can create a prospective-client relationship under Rule 1.18 and DC Bar Opinion 374 the moment it starts collecting facts. Gathering details from an adverse party can conflict the firm out of a matter; sending representation details to a self-learning vendor implicates Rule 1.6 and ABA Opinion 512's informed-consent requirement; and an unsupervised bot dispensing legal answers risks unauthorized practice of law (Rule 5.5) and misleading-communication exposure (Rule 7.1).
Broken auth and IDOR (insecure direct object references) let one client - or anyone - pull up another client's matter. One Lovable-built app exposed roughly 18,000 users this way (The Register, Feb. 27, 2026). A privileged-document leak through a portal like this triggers ABA Formal Opinion 483 notification duties on top of any state breach law, and can waive privilege on the exposed material.
IDs, medical records, and tax or financial documents collected through an AI-built upload flow routinely land in unencrypted buckets - Escape.tech found 400+ exposed secrets and 175 PII instances across 5,600 vibe-coded apps it scanned. A firm holding client PHI for a healthcare client can be a HIPAA business associate with direct liability: Thompson Coburn's breach of 305,088 patient records from a hospital client ended in a .5M settlement.
Home-rolled AI e-signature flows often skip real audit trails and identity verification. Even established vendors aren't immune - the Dropbox Sign breach (April 24, 2024) exposed emails, hashed passwords, API keys, OAuth tokens, and MFA data for every user of the service, and drew a class action.
Payment or settlement-disbursement features touching IOLTA or trust funds are the #1 financial target: business email compromise actors impersonate attorneys to redirect wire instructions, with one documented case moving from an estate to fraudsters. Client-money losses are treated as near-strict-liability under trust-accounting rules, regardless of how the leak happened.
| Rule / Regulation | When it applies | Penalty |
|---|---|---|
| ABA Model Rule 1.6(c) | Failure to make "reasonable efforts" to prevent unauthorized disclosure of client info - e.g., an intake app with no access controls | Bar discipline, reprimand to disbarment |
| ABA Model Rule 1.1, cmt. 8 (tech competence - 40 states + DC + Puerto Rico) | Deploying AI-built tools without understanding their risks | Bar discipline; malpractice standard-of-care basis |
| ABA Formal Opinion 512 (Jul. 29, 2024) | Using generative AI without competence, safeguards, or client informed consent | Discipline under Rules 1.1, 1.6, 5.1/5.3, 1.4, 1.5 |
| ABA Formal Opinion 483 | A breach with a substantial likelihood of material client harm | Duty to stop, mitigate, and notify current clients; failure is itself a violation |
| State breach-notification laws (all 50 states) | Unauthorized acquisition of client PII held in the firm's app | NY SHIELD up to ; TX up to /violation; AZ up to |
| HIPAA (firm as business associate) | Firm's app stores or processes PHI for a healthcare client | to per violation category, per year; criminal penalties up to + prison |
Possibly. ABA Model Rule 1.6(c) requires "reasonable efforts" to prevent unauthorized access to client information, and Rule 1.1, cmt. 8 imposes a tech-competence duty in 40 states plus DC and Puerto Rico. An intake form, chatbot, or portal built on AI defaults - with row-level security or access controls left off - can violate both, independent of whether any regulator ever gets involved.
Yes, if the tool uses generative AI. Opinion 512 (July 2024) requires competence in how the tool works, reasonable data safeguards, and informed client consent before representation information goes into a self-learning system - obligations that run through Rules 1.1, 1.6, 5.1/5.3, 1.4, and 1.5.
CVE-2025-48757 is a 2025 disclosure that found 170 of 1,645 sampled Lovable apps (10.3%) critically exposed, with row-level security disabled in roughly 70% of cases, letting unauthenticated visitors query app databases with the public anon key. If your intake form, portal, or chatbot was built on Lovable, it's worth confirming RLS is actually enabled on every table.
It can. Exposing confidential or privileged material to third parties through a leaky app can waive privilege and work-product protection on that material, permanently damaging a client's litigation position - turning a software bug into malpractice exposure and an ethics violation under Rule 1.6(c), on top of ABA Formal Opinion 483's notification duties.
If your firm's app stores or processes protected health information for a healthcare client, you likely are, with direct HIPAA liability. Thompson Coburn's breach of 305,088 patient records from a hospital client ended in a .5 million settlement - a reminder that document-collection apps built without encryption carry this exposure.
A breach with a substantial likelihood of material client harm triggers a duty to stop the breach, mitigate its effects, and notify current clients - a duty that exists independent of, and in addition to, whatever your state's breach-notification statute requires.
Get a free, no-obligation scan of your law firm's AI-built app - RLS gaps, IDOR risk, and ABA Rule 1.6(c)/1.1 exposure, explained in plain English.
Start With a Free Scan →