New York Made AI Review a Signed Certification. Most Firms Can't Prove They Did It.
On June 1, a court rule took effect in New York that changed what every attorney in the state is now responsible for the moment they use an AI tool to help prepare a filing. Most of the coverage read it as "New York allows AI." That isn't the part that matters for how a firm operates.
New York's Part 161 applies to all civil and criminal courts statewide. It permits the use of AI in preparing filings and, notably, does not require attorneys to disclose that they used it. What it does require is review: any attorney who uses an AI tool has to carefully read the resulting paper and independently confirm that it contains no fabricated cases, no invented statutes, and no misstated authority. By signing the filing, the attorney certifies that the review happened. Individual judges keep discretion to adopt the model rule, write their own, or add nothing.
Read that again as an operational requirement rather than a policy headline. The rule does not ask what tool you used — it treats your signature as a standing statement that a human checked the work. The duty moved from "should lawyers use AI" to "you may, and your name on the filing means you verified it."
The recordkeeping problem hiding inside the rule
A certification is a claim about a process. The signature says a review took place. The question that follows is one most small firms have not asked themselves: if a court, a bar grievance committee, or a malpractice carrier ever asks you to show that the review actually happened, what do you have?
For a lot of firms, the honest answer is nothing usable. The review happened in someone's head, against a draft that has since been edited and overwritten, on a date nobody logged, checking citations in a browser tab that closed days ago. The work was done, but there is no proof of it.
Why this is about more than New York
New York is not an outlier; it is early. The pressure behind Part 161 is the same pressure showing up in federal courts. Earlier this month, the Ninth Circuit suspended two attorneys for six months in Lnu v. Blanche after their briefs were found to contain nonexistent cases and misattributed quotations. The fabrications alone did not drive the six-month suspension — it was the attorneys' repeated failure of candor about how the fake citations got there: they characterized them as typographical errors and denied that AI had played any role, conceding the likely cause only after the court pressed them. The panel was explicit that if the attorneys had disclosed the AI use and apologized up front, lesser sanctions might have followed. The court went further still, ordering every attorney at their firm — for the next two years — to include a sworn statement in all future filings, disclosing whether AI was used and which tool, and certifying that the signing attorney personally reviewed the filing and that every citation and quotation refers to an authority that actually exists.
What connects these cases to Part 161 is simple: a signature attests that the signer personally verified the work, and the firms in trouble could not show they had. Part 161 makes that gap a standing exposure rather than a problem that only surfaces after a mistake.
What a defensible record actually looks like
The good news is that the record Part 161 implies is not exotic. It is four facts: which version of the document was reviewed, who reviewed it, when, and what they checked — citations pulled and confirmed against a reporter, statutes verified, quotations matched to source. None of that requires special AI features. It requires that the matter keep its own history, so the timeline of the work exists without anyone having to remember it.
This is where a fragmented tech stack fails. If the draft lives in a document management system, the citations get checked in a browser, the filing goes out from email, and the time entry lands (or doesn't) in a separate billing tool, there is no single place that can answer "show me the review." The record is scattered across four systems that don't talk to each other. That is the same fragmentation that costs firms productivity everywhere else in the practice. Under a certification rule, it costs them defensibility.
When every version, every edit, and every action on a matter is stored under that matter, the record of review becomes a byproduct of doing the work rather than a separate compliance chore someone has to maintain by hand. The history is already there because the platform timestamped it as the work happened. A firm that operates this way can answer the certification question in minutes; a firm running a scattered stack often cannot answer it at all.
What a small firm should do before the next state copies the rule
Two steps, and most firms have done the first and skipped the second.
First, write a one-paragraph internal standard for what "independently reviewed" means at your firm — which elements of an AI-assisted document get checked, against what, and by whom. This is the cheap part, and many firms already have a version of it.
Second, make sure your tools can show, after the fact, that the standard was followed. This is the part almost no one has handled, because it depends on whether the firm's systems keep a usable history or rely on memory. A standard nobody can demonstrate is a standard that does not help you when it matters.
Part 161 raised the cost of one specific gap: using AI without keeping a record of how the review happened. The firms most exposed under this rule, and under whatever other states copy it over the next year, are the ones whose review lives only in memory. Building the record into how the work gets done is the cheapest insurance a small firm can buy right now, and most firms haven't bought it yet.
Thinking through what a defensible AI-review record would look like for your practice? walk through how matter-centric by design creates that history automatically — no separate compliance system to maintain.