AI for the Defense / Resources
Make it yours · Articulate · Connect · Extend

The ACE Framework Companion

Turn every point of the session into something you can use
Three moves that take an idea from heard to owned. You restate it, you tie it to your own practice, then you put it to work on something new.

ACE is a simple way to move a lesson from heard to owned. For each idea below, you do three things in order. First you restate it in your own words, which proves you actually understood it. Then you connect it to something you already do, which is what makes it stick. Finally you extend it, putting it to work on a problem you have not seen before. That last step is where the learning lands.

ArticulateYou restate the core concept in your own words.
ConnectYou link the idea to something you already know or do.
ExtendYou apply the concept to a brand-new situation or problem.

Every scenario below is fictional and for reflection only. Nothing here is legal advice. Rule references follow the Texas Disciplinary Rules of Professional Conduct and may change, so verify the current text.

0 Opener · Taking your own measure

1.Know your own AI fluency before you build on it

A

Articulate. In one sentence, describe your current relationship with AI at work, and why you place yourself there.

Three ways to say it
  • “I avoid it. I don’t trust it yet, and I haven’t tested where it helps.”
  • “I dabble. I use it for quick drafts, but I check nothing systematically.”
  • “I lean on it. It’s in my workflow, with rules for what I will and won’t feed it.”
C

Connect. Match where you are with AI today to where you once were on some tool you now use without thinking.

Think back to the first e-filing you ever submitted. You clicked through unsure which field mattered, kept a cheat sheet by the keyboard, and asked the clerk to confirm it went through. Six months later you filed without a second thought. AI sits somewhere on that same curve for you right now. Name the spot.
E

Extend. Name one AI habit you will build this year, and the first case type where you’ll test it.

Three ways to try it
  • Draft one low-stakes item this week, like a client-update letter, and edit it hard.
  • Adopt a single rule you follow every time, such as verifying every cite before it leaves your desk.
  • Block twenty minutes to test one tool on a fictional fact pattern before any real matter.

1 Ethical foundations

2.Ethical responsibility cannot be delegated to software

A

Articulate. Restate why “the tool did it” is never a defense, and who owns the output.

Three ways to say it
  • “My signature certifies the work. The tool has no license and no duty to the client.”
  • “Responsibility can’t move to something that can’t be disciplined.”
  • “I can delegate the drafting, but never the duty.”
C

Connect. Notice that AI changes nothing about a rule you already live by when other people draft your work.

A trusted paralegal drafts a motion, and it goes out under your signature with a misstated standard. When the judge questions it, “my paralegal wrote it” does not answer for you. Swap the paralegal for a chatbot, and nothing about that answer changes.
E

Extend. A colleague says the AI “signed off” on a filing. Draft the two-sentence correction you’d give.

Three ways to try it
  • Name the misconception: software certifies nothing, and only a licensed attorney can.
  • Point back to the duty: the reviewing lawyer owns every word once it’s filed.
  • Offer the fix: treat the output as a first draft to verify, not an approval.

3.Your existing duties already govern AI, so supervise it like a nonlawyer assistant

A

Articulate. In plain words, map each duty to AI use.

Three ways to say it
  • Competence (1.01): know the tool’s failure modes before you rely on it.
  • Confidentiality (1.05): what you paste can be retained, so protect client data.
  • Supervision (5.01–5.03) and candor (3.03): check its work, and confirm what you file is true.
C

Connect. See the AI draft as arriving with the exact trust level of any first draft you review.

When a first-year hands you a suppression memo, you don’t file it on faith. You check the cited standard, confirm the record support, and fix the overconfident sentence. An AI draft arrives with the same trust level: none, until you’ve read it line by line.
E

Extend. Pick one recurring task and write the supervision step you’d add before AI output leaves your desk.

Three ways to try it
  • Add “verify every citation in a real database” to your pre-filing routine.
  • Require a de-identification pass before any client facts touch a tool.
  • Keep a one-line file note: the tool used, the task, and that you reviewed it.

4.Competence now includes the technology you choose to use

A

Articulate. Restate the expanded competence standard: what you must know about a tool before relying on it.

Three ways to say it
  • Know what the tool keeps, trains on, and exposes.
  • Know the tasks it’s bad at, like current case law and jurisdiction-specific rules.
  • Know when the competent answer is “not this tool,” or “get help.”
C

Connect. Notice that declining a tool you don’t understand is a reflex you already trust.

A potential client once brought you an immigration-adjacent issue and you referred it out. Not because you couldn’t read the statute, but because competent representation called for someone who lives in that area. Declining an AI tool you don’t yet understand is that same reflex, pointed at software.
E

Extend. Take an AI tool you’ve never used and list three questions to answer before using it on a real matter.

Three ways to try it
  • Does it train on or retain what I type, and where does that data go?
  • How does it handle citations, and does it flag when it’s unsure?
  • What does it do badly, and is my task on that list?

5.Hallucinated case law is inherent to how models work

A

Articulate. Explain, without jargon, why a model invents citations that look and read right.

Three ways to say it
  • It predicts likely-sounding text. It isn’t looking anything up.
  • A fake cite in perfect format is exactly what “likely-sounding” produces.
  • It has no built-in check that a case exists, and it states fiction as confidently as fact.
C

Connect. Tie the abstract risk to the concrete headlines you’ve already read.

You’ve seen the stories. A lawyer files a brief citing cases that never existed, then ends up sanctioned, publicly named, and explaining himself to the court. Every one of those stories turns on a single missing step: nobody pulled the opinion.
E

Extend. Ask a free chatbot for three Texas suppression cases, then verify each one and sort it.

Three ways to try it
  • Confirmed: you opened the real opinion and the holding matches.
  • Unconfirmed: you can’t find it, so treat it as non-existent until proven.
  • Invented: the cite or quote appears nowhere. Note how confidently it was offered.

6.Client data can leak the moment you paste it

A

Articulate. State where the confidentiality risk actually lives in a consumer chatbot.

Three ways to say it
  • Inputs may be retained and logged, and sometimes reviewed by a human.
  • Free tools may train on what you type.
  • A name plus two facts can identify a matter instantly.
C

Connect. Feel the exposure by putting it where you already guard your words.

You would never say “my client Maria, charged with the Westside burglary, admits she was there” in a crowded elevator. Pasting those same facts into a free chatbot is that elevator, except the walls have a memory, and the recording may never be deleted.
E

Extend. Take a real fact pattern and rewrite it as a de-identified stand-in you could safely paste.

Three ways to try it
  • Replace names with initials or a fictional placeholder, like “client R.”
  • Blur the specifics that pinpoint the matter: dates, locations, cause numbers.
  • Keep only the legal shape of the problem, not the identifying facts.

7.AI output is never a substitute for legal judgment

A

Articulate. Draw the line between what the tool does and what only you do.

Three ways to say it
  • The tool drafts, summarizes, and suggests options.
  • You decide strategy, weigh risk, and choose what to file.
  • You sign, and the signature is the judgment.
C

Connect. Recall a call from your own year that no tool could have made.

This year you decided whether to put a nervous client on the stand. You weighed how a jury would read them, what the prosecutor might do on cross, and what your client could survive. No model sat in that room or carried that risk. The call was judgment, and it was yours.
E

Extend. Given an AI-suggested defense strategy, find the one decision that must stay with you and the client.

Three ways to try it
  • Spot the choice with client consequences: a plea, testimony, a waiver.
  • Spot the choice that needs client consent, not just legal analysis.
  • Spot the risk trade-off only you can weigh for this client.

2 Risk-reducing practices · TCDLAi

8.Start from the problem, not the tool

A

Articulate. Restate the difference between problem-first and tool-first, and why problem-first is measurable.

Three ways to say it
  • Tool-first starts with a feature and hunts for a use.
  • Problem-first starts with a pain point and asks whether AI solved it.
  • Only problem-first leaves you with a yes-or-no test at the end.
C

Connect. Remember the last purchase that dazzled in the demo and then solved nothing.

A while back the office paid for a slick case-management add-on after a great demo. Nobody could say which problem it solved, so it quietly went unused by renewal. That’s tool-first, and AI makes it easy to fall into the same trap twice.
E

Extend. Name one real pain point in your practice and define a “good result” before you touch a tool.

Three ways to try it
  • Pick a task that eats hours or carries risk, like suppression research.
  • Write, in one line, what “good” looks like before you prompt.
  • Decide how you’ll judge whether AI actually got you there.

9.Structure reduces fabrication: role, context, task, format, and limits

A

Articulate. Explain why a vague prompt is an ethics problem, not just a quality one.

Three ways to say it
  • The less you specify, the more the model invents to fill the gap.
  • Invention is the exact failure, fabricated cites, that you’re trying to avoid.
  • Structure shrinks the room to make things up. It’s a safeguard, not polish.
C

Connect. Picture handing the same vague instruction to a person and seeing what comes back.

Imagine telling a new associate “write me a motion to suppress” and walking away, with no file, no jurisdiction, and no theory. You’d get something confident, generic, and probably wrong. A one-line prompt hands the model that exact non-assignment.
E

Extend. Rebuild “write me a motion to suppress” into a four-part structured prompt for a fictional stop.

Three ways to try it
  • Role: “Act as a Texas criminal defense attorney preparing a suppression hearing.”
  • Context and task: paste fictional facts and jurisdiction, then ask for five angles with the legal basis.
  • Format and limits: “Cite only sources I provide. Flag anything you’re unsure of.”

10.The TCDLAi framework, where the lowercase “i” is the point

A

Articulate. Say what each letter does, and why inspect is deliberately yours.

Three ways to say it
  • T, C, D: Target the issue, Compile the facts, Define the law from your sources.
  • L, A: List strategies tied to facts, Analyze them against the prosecution.
  • i: inspect, which is the human review the other five letters set up.
C

Connect. Recognize the six moves as the sequence you already run to build a case.

Think about how you actually work a new case. You pin down the charge and the issue, gather the facts, pull the governing statutes, sketch defense theories, then stress-test them against what the State will do. TCDLAi is that same sequence. You already run it in your head.
E

Extend. Run one fictional fact pattern through all six letters, and stop to inspect what the model produced.

Three ways to try it
  • Use one Scenario Lab pattern: DWI, possession, or assault.
  • Paste the provided statute at the D step so the model stays grounded.
  • At the i, open one cited source yourself and see what the model missed.

11.Grounding (RAG) holds the AI to sources you trust

A

Articulate. Restate the difference between answering from memory and answering from documents you provide.

Three ways to say it
  • Ungrounded, it recalls a blurry average of everything, and fills the gaps.
  • Grounded, it answers from the statute or opinion you handed it.
  • A grounded answer is one you can check line by line against the source.
C

Connect. Hold the model to the standard you hold yourself to in front of a judge.

You would never argue “I think there’s a case that says…” in open court. You pull the opinion and quote the holding. Grounding makes the model work the same way: from the text you put in front of it, not a foggy memory of ten thousand cases.
E

Extend. Paste a public statute excerpt, then ask a question it doesn’t cover and watch what happens.

Three ways to try it
  • Ask something just outside the pasted text and see whether it admits the gap.
  • Add “if the source doesn’t say, tell me” and compare the answer.
  • Note the moment it invents a bridge. That’s the risk grounding still leaves.

12.Verification is the inspect habit

A

Articulate. Describe the four-step check in your own words.

Three ways to say it
  • Get the draft, then pull each cited source yourself.
  • Match the claim: confirm the quote, the holding, and the pinpoint are really there.
  • Correct what fails, and note what you verified.
C

Connect. Treat the inspect prompt as a cross-examination of the model’s own work.

On cross you don’t accept “the light was red.” You make the witness show how they know. The inspect prompt is that cross: “For each citation, quote the exact sentence in the source I gave you that supports it.” Watch which claims suddenly can’t answer.
E

Extend. Run the inspect prompt on a grounded answer, then open a source yourself.

Three ways to try it
  • Ask it to quote its supporting sentence for every claim.
  • Flag any claim it can’t ground, and strike it.
  • Then open one source yourself. The model’s self-check isn’t the last word.

3 Guardrails and takeaways

13.The eight-point ethical guardrail checklist

A

Articulate. From memory, name as many of the eight checks as you can.

Three ways to say it
  • Data and tool: confidentiality, competence.
  • Substance: grounding, verification, judgment.
  • Court and record: candor, supervision, record.
C

Connect. Trust the list the way you already trust a checklist when the cost of forgetting is high.

Before trial you don’t rely on memory for exhibits, witness order, and the elements you have to prove. You run a checklist, because forgetting one item is too costly. The guardrail checklist is that same discipline for AI work: eight boxes, under a minute, every time.
E

Extend. Apply all eight to a piece of AI-assisted work you might produce next week, and find the weak box.

Three ways to try it
  • Walk a real upcoming task through each of the eight checks.
  • Circle the box most likely to be skipped under time pressure.
  • Build one habit to catch that box. The others usually take care of themselves.

14.The do and do-not bright lines

A

Articulate. State one “do” and one “do not” you consider non-negotiable.

Three ways to say it
  • Do: verify every citation in a real database before you cite it.
  • Do not: paste privileged or client-identifying facts into a consumer tool.
  • Do not: let the model make the client’s call or pick the strategy.
C

Connect. Trace each bright line back to the duty it protects.

Every line traces to a rule you already answer to. “Read the case before you cite it” is candor to the tribunal (3.03). “No client-identifying facts in a consumer tool” is confidentiality (1.05). “You make the strategic call” is your duty to the client. The rules aren’t new. Only the surface is.
E

Extend. Draft a two-line AI-use rule you could actually post in your office.

Three ways to try it
  • Line one is what the office will always do: verify, and de-identify.
  • Line two is what it will never do: file unread cites, or paste client data.
  • Keep it short enough to post by the printer.

15.Document, review, and verify: the record that protects you

A

Articulate. Explain how a one-line file note answers a future question from a court or bar committee.

Three ways to say it
  • Document: which tool, for which task, on what facts.
  • Review: you read the full output as the responsible attorney.
  • Verify: every authority confirmed against a real source.
C

Connect. See it as the same instinct behind the notes you already keep.

You already keep file notes and time entries, because a contemporaneous line beats a reconstructed memory months later. If a bar committee ever asks how a filing was produced, a one-line note like “drafted with X, facts de-identified, all cites verified in Westlaw” turns a hard question into a short answer.
E

Extend. Write the single sentence you’d want in the file to show you supervised and verified an AI-assisted draft.

Three ways to try it
  • Name the tool and the task in plain terms.
  • State that the facts were de-identified before use.
  • State that you reviewed the output and verified every authority.

16.The fit test: can you supervise and verify it?

A

Articulate. Restate the one question that decides whether AI belongs on a task.

Three ways to say it
  • Ask yourself: can I supervise and verify this output?
  • If yes, it may fit: first drafts, summaries, brainstorming.
  • If no, it doesn’t: unchecked final authority, privileged facts, strategy.
C

Connect. Watch the test sort two real tasks from your own week.

Drafting a plain-language client update you’d edit anyway lets you supervise and verify every line, so it fits. Advising whether to take the plea is judgment you can’t outsource or check against a source, so it doesn’t. Same week, opposite answers, one question.
E

Extend. Take a task you assumed AI couldn’t help with, and test whether de-identifying or grounding it changes the answer.

Three ways to try it
  • Try de-identifying the facts. Does the confidentiality barrier drop?
  • Try grounding it in a statute. Does the accuracy barrier drop?
  • If both barriers fall and you can still verify, it may fit after all.

17.The closing habit: “Draft with the tool. Decide as the lawyer.”

A

Articulate. Say the one habit you’ll keep, and why “verify every citation” is the whole session in a sentence.

Three ways to say it
  • “Draft with the tool, decide as the lawyer.”
  • The tool proposes, and you dispose.
  • One habit above all: open the source and verify the cite, every time.
C

Connect. Return to the habit you named at the start and test whether it held.

An hour ago you named one AI habit you wanted to build. Since then you’ve seen fabricated cites, the confidentiality trap, TCDLAi, and the checklist. Look back at that habit. Does it still hold, or would you make it sharper, more specific and more verifiable, now that you know what you know?
E

Extend. Commit to the first real, de-identified matter where you’ll run TCDLAi plus the checklist.

Three ways to try it
  • Pick the matter and the task this week.
  • De-identify the facts before anything touches a tool.
  • Name the one thing you’ll verify first.

Keep exploring

Handout

Ethical Guardrail Checklist

The eight-point, one-page check the Extend tasks send you back to.

Discussion · 15 min

Legal Ethics Scenario Randomizer

Fictional dilemmas tied to a Texas rule, and good fuel for the Connect and Extend moves.