# California SB 574: What Lawyers Can and Cannot Put Into AI

> California SB 574 would bar attorneys from entering confidential client data into public AI systems. What the bill requires and how to work within it.

- **Author:** Neetusha
- **Published:** 2026-09-11
- **URL:** https://www.redactifyai.com/blog/california-sb-574-attorney-ai-rules/

---

On August 31, 2026, the California Assembly passed Senate Bill 574 by a vote of 75 to 0. Not a single member voted against it. The bill now sits on Governor Newsom's desk awaiting a signature or a veto.

If he signs it, California becomes the first state to put attorney obligations around generative AI into statute rather than leaving them to ethics guidance. One of its provisions matters more than the others for day-to-day practice, and it has received the least attention: **SB 574 would make it a statutory duty not to enter confidential client information into a public generative AI system.**

That is a different kind of obligation than "be careful with ChatGPT." It names specific categories of information, and it attaches to every attorney in the largest legal market in the United States.

> **Status as of September 11, 2026:** SB 574 has passed the legislature but has not been signed. Governor Newsom's deadline to act falls roughly 30 days after the legislature's August 31 adjournment. Nothing in this post is law yet. Verify the current status on the [official bill page](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202520260SB574) before relying on it.

> **Quick answer:** [Can I trust AI to redact confidential client information?](/answers/can-ai-redact-confidential-client-information/) The evaluation criteria, in about 400 words.

---

## What is California SB 574?

California SB 574 is a bill that would add Section 6068.1 to the Business and Professions Code, creating statutory duties for attorneys who use generative AI in the practice of law. Introduced by Senator Tom Umberg, who chairs the Senate Judiciary Committee, it also covers arbitrators, judicial officers, and alternative dispute resolution providers.

The attorney provisions break into four obligations:

1. **Confidentiality.** An attorney would have a duty to ensure that confidential information is not entered into a public generative AI system.
2. **No delegation.** Proposed Section 6068.1(a)(2) states that an attorney shall not delegate the practice of law to generative AI.
3. **Verification.** An attorney would have to take reasonable steps to verify the accuracy of AI output, including every case and statutory citation, and correct erroneous or fabricated material before using it.
4. **Disclosure.** Attorneys would have to disclose their use of generative AI to the court for documents submitted to it.

The citation rule is written tightly: a brief, pleading, motion, or any other paper filed in any court could not contain citations that the attorney responsible for submitting it has not personally verified, including any citation supplied by generative AI.

Arbitrators get their own rules. They could not delegate any part of decision-making to a generative AI tool, and could not rely on AI-generated information outside the record without disclosing that to the parties beforehand.

Most of the coverage has focused on the citation provisions, because the hallucinated-citation sanctions of the past two years made that the visible problem. The confidentiality provision is the one that changes daily workflow.

---

## What counts as confidential under SB 574

This is where the bill gets specific, and specificity is what makes a duty operational.

The statutory language reaches confidential, personal identifying, and other nonpublic information. The bill enumerates what personal identifying information includes:

- Driver's license numbers
- Dates of birth
- Social Security numbers
- National Crime Information and Criminal Identification and Information numbers
- Contact information of parties and court personnel
- Medical or psychiatric information
- Financial information
- Account numbers
- Any content sealed by court order or deemed confidential by rule or statute

Read that list against a real document. A personal injury demand package contains dates of birth, medical information, and financial information on nearly every page. An employment file contains Social Security numbers and account numbers. A family law declaration contains all of it plus contact information for parties.

Under the proposed rule, pasting any of that into a public generative AI system to summarize, rewrite, or analyze it would be a violation of an attorney's statutory duties. Not a best practice failure. A duty violation.

---

## The confidentiality provision is not a ban on using AI

Read carefully, the provision is conditional rather than absolute, and the condition is what creates the compliant paths.

The operative language bars entering that information into a generative AI system for which access to the information the attorney inputs **is not restricted to the attorney and persons authorized by the attorney under obligations to protect the confidentiality of the information.**

That phrasing leaves two ways to work:

**Path one: use a system that restricts access appropriately.** Enterprise AI deployments with contractual confidentiality terms, no training on your inputs, and controlled access can satisfy the condition. This is a procurement and contract-review exercise, and it is worth doing if your firm is standardizing on a single AI vendor.

**Path two: do not put the confidential information in.** If the driver's license number, the date of birth, and the medical history are removed from the document before it reaches the AI system, there is no confidential information being entered. The condition never triggers, because the input is no longer confidential.

Neither path is a workaround. Both follow the plain reading of the rule. Which one fits depends on what you are doing: path one for a firm-wide AI platform, path two for the common case of wanting to use a general-purpose model on a specific document without procuring anything.

The second path is where redaction does work that nothing else does, and the overlap between the bill's enumerated list and what a detection tool looks for is close to exact. That is not a coincidence. Both lists are derived from the same underlying categories of identifying information.

One practical warning before you rely on a redacted copy: confirm the redaction actually removed the text rather than drawing a box over it. A visually masked PDF still contains the original characters in its content stream, and pasting or uploading that file into an AI system transmits the underlying text along with it. The [free PDF Redaction Checker](/tools/check-pdf-redaction/) tests a file for recoverable text in a few seconds. For the technical detail on why data cannot be pulled back once a model has ingested it, we covered that in [why you must redact documents before feeding them to AI](/blog/redact-documents-before-ai-llm/).

---

## This duty already exists in California, just not in statute

SB 574 is worth acting on whether or not Newsom signs it, because the underlying obligation is not new.

In November 2023, the State Bar of California approved its Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law. That guidance already tells attorneys they must not input confidential client information into any generative AI product that lacks adequate confidentiality and security protections. It reads the duty out of the existing confidentiality rules rather than inventing a new one.

The State Bar went further in May 2026, publishing [proposed amendments to the Rules of Professional Conduct](https://www.calbar.ca.gov/public/public-meetings-comment/public-comment/public-comment-archives/2026-public-comment/proposed-amendments-rules-professional-conduct-related-artificial-intelligence) addressing AI, including a requirement that lawyers verify AI output.

The same duty exists outside California. [ABA Model Rule 1.6](https://www.americanbar.org/groups/professional_responsibility/publications/model_rules_of_professional_conduct/rule_1_6_confidentiality_of_information/) obligates a lawyer to make reasonable efforts to prevent unauthorized disclosure of information relating to the representation, and most states have adopted a version of it.

What SB 574 would change is the character of the obligation. Ethics guidance is interpreted through a reasonableness lens after the fact. A statutory duty with an enumerated list of covered identifiers is a much harder thing to argue around, and it gives opposing counsel and disciplinary bodies a cleaner standard to measure against.

There is also a reasonable chance other states follow. A 75 to 0 vote is not a close call, and first-in-the-nation legal-profession rules tend to get copied.

---

## What to do before January

If SB 574 is signed, it would take effect January 1, 2027 under California's default rule for non-urgency statutes. That is a short runway for a firm that has not thought about this. Four steps cover most of it.

1. **Find out what your team is actually pasting into AI tools.** Most firms discover the behavior is more widespread than partners assume, because it is useful and nobody asked. Ask without penalty attached, or you will get an inaccurate answer.
2. **Decide your path per tool.** For a firm-standard AI platform, review the contract for training use, access restrictions, and confidentiality terms. For general-purpose consumer models, assume the condition is not satisfied and plan to remove confidential information before use.
3. **Make the clean-copy step routine rather than discretionary.** A rule that depends on an associate remembering to strip identifiers at 11pm before a filing deadline is a rule that will be broken. It needs to be a step in the workflow, not a judgment call.
4. **Keep a record.** If a question ever arises about whether confidential information went into an AI system, a log showing which documents were processed, when, and by whom is the difference between demonstrating compliance and asserting it. The same logic applies after a security incident, as we covered in [what the 2026 law firm data breaches reveal about document security](/blog/law-firm-data-breaches-2026/).

RedactifyAI fits at step three. It detects and permanently removes more than 40 entity types, including the driver's license numbers, dates of birth, Social Security numbers, medical information, financial information, and account numbers the bill enumerates, and it logs each processed document with a timestamp and user reference for step four. What it produces is a copy you can paste into a general-purpose model without entering confidential information into it.

For the related question of whether your AI conversations carry privilege in the first place, a federal court addressed that in February 2026, and we wrote about it in [your law firm's AI conversations are not privileged](/blog/attorney-client-privilege-ai-tools/).

---

## Frequently asked questions

### What is California SB 574?

SB 574 is a California bill that would add Section 6068.1 to the Business and Professions Code, creating statutory duties for attorneys using generative AI. It passed the Assembly 75 to 0 on August 31, 2026 and awaits Governor Newsom's signature or veto. It covers confidentiality, non-delegation of legal practice, verification of AI output, and disclosure of AI use to courts.

### Does SB 574 ban lawyers from using ChatGPT?

No. The confidentiality provision is conditional. It bars entering confidential information into a generative AI system where access to that input is not restricted to the attorney and authorized persons under confidentiality obligations. A lawyer can use a general-purpose model on material that contains no confidential client information, or use a system whose access terms satisfy the condition.

### What information does SB 574 treat as confidential?

The bill reaches confidential, personal identifying, and other nonpublic information, and enumerates driver's license numbers, dates of birth, Social Security numbers, National Crime Information and Criminal Identification and Information numbers, contact information of parties and court personnel, medical or psychiatric information, financial information, account numbers, and anything sealed by court order or deemed confidential by rule or statute.

### When would SB 574 take effect?

If Governor Newsom signs it, SB 574 would take effect January 1, 2027 under California's default rule for statutes that do not carry an urgency clause. As of September 11, 2026 the bill had passed the legislature but had not been signed, and the governor retains the option to veto it.

### Does SB 574 apply outside California?

No, SB 574 would bind California attorneys. But the underlying confidentiality duty is not California-specific: ABA Model Rule 1.6 requires lawyers to make reasonable efforts to prevent unauthorized disclosure of information relating to a representation, and most states have adopted a version of it. A 75 to 0 vote also makes this a likely template for other states.

### Is redacting a document enough to comply with SB 574?

It addresses the confidentiality provision specifically, by ensuring there is no confidential information in what you enter. It does not address the bill's other duties. You would still need to verify every citation personally, disclose AI use to the court, and refrain from delegating legal judgment to the model. Redaction handles the input problem, not the output problem.

---

If you want to see what would need to come out of a document before it goes near a general-purpose model, [upload a PDF to our free redaction tool](/tools/redact-pdf-free/) and look at what gets flagged. No account required.