Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.
Note: the partner, the associate, and the timing below are composites drawn from three Ontario law firm engagements between late 2025 and early 2026. The names are changed. The clauses, the rule citations, and the sequence in which disclosure obligations fired are real.
I took the call from a Bay Street partner on a Friday afternoon in March. Her senior associate had filed a factum overnight on a contested motion. One of the cited cases on page eleven did not exist.
Opposing counsel read the factum on Friday morning, checked the citation against CanLII, and emailed back asking for the pinpoint. The associate had used a paid legal research platform with an AI assist feature. She had not verified the citation before signing the factum. The partner’s LawPRO file opened by Monday.
I’m an MSP, not a lawyer. The clause language here belongs with qualified Ontario professional-responsibility counsel before you adopt any of it. What follows is the disclosure architecture I’ve seen surface where AI-assisted research produced a fabricated citation, a privileged-data leak, or both.
The post maps that engagement against LSO Rule 7.8-1 and Rule 7.8-2, the LawPRO program, Rule 4.06.1 of the Rules of Civil Procedure, the Ontario Superior Court’s March 2026 AI practice direction, Zhang v. Chen, and the six-step response we walked the firm through.
Key Takeaways.
- Two rules, not one. LSO Rule 7.8-1 governs telling the client. Rule 7.8-2 governs telling the insurer. Most firm AI policies cite only 7.8-1 and miss the LawPRO duty entirely.
- Rule 7.8-2 requires prompt notice of any circumstance that may give rise to a claim, and the LSO commentary confirms the duty arises whether or not the lawyer considers the claim to have merit.
- The LawPRO primary program carries CA$1 million per claim and CA$2 million in the aggregate, with optional excess coverage up to CA$9 million for new business (LAWPRO, Excess Insurance).
- Rule 4.06.1(2.1) of the Rules of Civil Procedure requires a signed statement certifying the signer is satisfied as to the authenticity of every authority in a factum. An AI hallucination therefore breaches a signed certification, not just a standard of care.
- Zhang v. Chen 2024 BCSC 285 refused special costs against the lawyer and instead made her personally liable for ordinary costs under Supreme Court Family Rule 16-1(30). The frequent claim that the case awarded indemnity costs is wrong.
This piece builds on our AI deployment guide for Canadian law firms. Read that first if you have not landed on a sanctioned-tool architecture. This post assumes the tools are already in the room. Firms standardizing on Microsoft 365 can also see how Copilot connects to NetDocuments and iManage in our DMS integration guide.
The LawPRO Policy: What It Covers and What It Does Not
The Lawyers’ Professional Indemnity Company (LAWPRO) is the mandatory professional liability insurer for Ontario lawyers in private practice. The program responds to civil liability arising from professional services. It does not respond to intentional dishonesty, knowing assistance in a fraud, or losses outside professional services.
| Coverage | Limit |
|---|---|
| Primary program, per claim. | CA$1 million. |
| Primary program, aggregate. | CA$2 million. |
| Optional excess, new business. | Up to CA$9 million per claim and in the aggregate. |
| Optional excess, certain existing customers. | Up to CA$19 million. |
| Run-off coverage while exempt. | CA$250,000 per claim and in the aggregate. |
Source: LAWPRO, Excess Insurance (2026), which states the primary limits and the excess bands, and LAWPRO, Run-Off Insurance Coverage.
Three AI failure modes sit squarely inside that negligence framing. I have worked all three in Ontario practices, and none is intentional misconduct on its face.
- Fabricated authority. A lawyer signs a factum containing a case that does not exist.
- Wrong law. A lawyer relies on an AI-drafted clause that misstates a limitation period.
- Privilege leak. A lawyer pastes privileged material into a consumer tool, and a confidentiality claim follows.
Each is an error in the rendering of legal services, which is what the program is built to absorb.
Two things the program will not rescue, and both are choices rather than errors.
- Staying silent when the Rules required disclosure.
- Certifying at renewal that no claims-triggering circumstance arose when one had.
Either one converts a routine errors-and-omissions file into a disclosure-defect file. That is where personal exposure starts.
I drew that line for the Bay Street partner before we did anything else. The error was insurable. The disclosure question was the file. We spent the afternoon on the timeline, not on the factum.
When AI Errors Trigger a Reportable Claim Under LawPRO
The rule that opens a LawPRO file is Rule 7.8-2, not Rule 7.8-1. It requires prompt notice of any circumstance that may give rise to a claim. Notice goes to the insurer or other indemnitor, so the client’s protection from that source is not prejudiced.
The commentary to Rule 7.8-2 is the part firms miss. A lawyer is contractually required to give written notice to the insurer, including an optional excess insurer. That notice is due immediately after the lawyer becomes aware of the error or the circumstance.
The commentary to Rule 7.8-2 then closes with the sentence that removes the judgment call. The duty to report arises whether or not the lawyer considers the claim to have merit.
- Fabricated case citation in a factum that opposing counsel has flagged is reportable.
- Draft contract that cited a repealed statute and reached execution is reportable.
- Privileged email pasted into a consumer chatbot is reportable the moment the paste is confirmed.
- Unverified authority in a filed factum is reportable even if nobody outside the firm has noticed.
LawPRO’s claims-prevention blog flagged the Ontario Superior Court’s AI practice directions in November 2025, noting they aim to promote transparency, accuracy and accountability in the use of AI tools. The blog does not set a disclosure clock. Rule 7.8-2 does.
The annual LawPRO renewal questionnaire asks whether any circumstance arose during the 12-month period that could reasonably give rise to a claim. An honest yes preserves coverage. A no that turns out to be wrong adds a misrepresentation question on top of the original error.
The partner’s associate had used a sanctioned platform. She skipped the verification step in the firm’s research protocol, which is the step Rule 4.06.1(2.1) now turns into a personal certification.
We treated the error as reportable from minute zero. We did not wait for a motion. We did not wait for the client to ask. The LawPRO file opened Monday morning because the partner picked up the phone on Friday.
Across our 18 Ontario and British Columbia law-firm client engagements since 2024, our team found the same split. Firms that called the insurer first spent less on their own defence. In our practice the underlying error rarely changed the outcome. The delay always changed the bill.
I have sat across from a managing partner in Toronto who learned of her associate’s hallucinated citation only after opposing counsel flagged it. I have watched two other firms hope the issue would resolve quietly. In both, opposing counsel raised it formally first, and the LawPRO file opened anyway.
I keep an incident response template that maps which event triggers Rule 7.8-2 notice. To get the one we use with our law firm clients, book a consultation with Mike Pearlstein, CISSP.
Disclosure Obligations: Client, Court, Opposing Counsel, Regulator
An AI-generated error in an Ontario court filing opens four disclosure tracks at once. Each runs on its own clock. A delay on any single track converts a recoverable error into a disclosure-defect file that follows the lawyer personally.
| Track | Governing rule | What it requires |
|---|---|---|
| Client. | Rules 3.2-2 and 7.8-1. | Honesty and candour when advising, then prompt notice of the error itself. |
| Court. | Rule 5.1-2(e). | No knowing deception of a tribunal, including suppressing what ought to be disclosed. |
| Opposing counsel. | Rule 7.2-1. | Courtesy, civility and good faith in all dealings during the practice. |
| LawPRO. | Rule 7.8-2. | Prompt notice of any circumstance that may give rise to a claim. |
Ontario firms routinely put client candour under Rule 7.2-1. That is the wrong rule. Rule 7.2-1 is the courtesy-and-good-faith duty owed to everyone a lawyer deals with. Client candour lives at Rule 3.2-2, which requires a lawyer advising a client to be honest and candid and to disclose all information that may affect the client’s interests.
The client track is the one most lawyers try to delay. The instinct is to investigate first and report once the picture is clear. Rule 3.2-2 does not support that instinct.
A holding email saying “we have identified an issue with a citation in the factum; I am investigating and will report by end of day” satisfies Rule 3.2-2. Silence for a week does not.
The court track under Rule 5.1-2(e) is the most serious of the four. The rule prohibits knowingly deceiving a tribunal by misstating facts or law, or by suppressing what ought to be disclosed. A filing already before the court that contains a fabricated citation puts the lawyer on the wrong side of that line until the record is corrected.
I have seen four correction mechanisms used in Ontario matters. The form is judgment. The fact of correction is mandatory.
- A letter to the case management judge.
- A withdrawal of the offending paragraph.
- A corrected factum filed with leave.
- An oral correction on the record at the next appearance.
Opposing counsel is the track the associate started involuntarily, because opposing counsel had already spotted the citation. Acknowledging the error in writing, withdrawing reliance on it, and confirming a corrected filing schedule discharges Rule 7.2-1 without admitting more than the facts require.
The LawPRO track runs on the Rule 7.8-2 clock and should generally be the first call. The partner’s firm followed that sequence: LawPRO first thing Monday, client by 10am, opposing counsel by noon with a corrected factum on Tuesday, court at the next case management appearance.
That sequence is not mandatory. Completing all four tracks before the next status hearing is. If your firm wants a single escalation path for all four, book a consultation and we will share the sequence our CISSP-led team uses.
LSO Rule 7.8-1 vs Rule 7.8-2: What Each Duty Requires
Rule 7.8-1 fires when a lawyer discovers an error or omission that is or may be damaging to the client and that cannot be rectified readily. It then imposes three duties, and the third one is the one firms consistently get wrong.
- 7.8-1(a) promptly inform the client, being careful not to prejudice any rights of indemnity either of them may have under an insurance or indemnity plan.
- 7.8-1(b) recommend that the client obtain legal advice from an independent lawyer about any rights arising from the error.
- 7.8-1(c) advise the client that in the circumstances the lawyer may no longer be able to act for the client.
A great deal of Canadian AI-and-ethics commentary states that 7.8-1(c) requires the lawyer to tell the client that professional indemnity insurance may apply. It does not. Subrule (c) is about the retainer ending. Insurance appears in subrule (a), and only as a caution against prejudicing indemnity rights.
That distinction is not academic. Telling a client “my insurance may cover this” can itself prejudice indemnity rights, which is the outcome Rule 7.8-1(a) exists to prevent.
Rule 7.8-2 is the separate insurer duty, and it has no rectification threshold at all. There is no “cannot be rectified readily” qualifier. A circumstance that may give rise to a claim is reportable even where the lawyer fixes the problem the same afternoon.
The ambiguity AI introduces sits in Rule 7.8-1’s phrase “cannot be rectified readily.” A fabricated citation in an unfiled draft is readily rectifiable. The same citation in a factum already before the court, signed under Rule 4.06.1(2.1), is not.
The line between the two is a single business day in most matters. My running rule is simpler than Rule 7.8-1 makes it look. I treat any AI-assisted output that has touched a client communication, a filed document, or an externally circulated draft as past the threshold from the moment it leaves the office.
The Zhang v. Chen and Mata v. Avianca Precedent Set
Two cases now sit on every AI-and-law-firm panel I attend. Zhang v. Chen, 2024 BCSC 285 is the Canadian anchor. Mata v. Avianca, 22-cv-1461 (S.D.N.Y. 2023) is the American one. They share a fact pattern and diverge on how disclosure unfolded.
The detail that matters for disclosure sits at paragraph 37. Masuhara J. wrote that it was “unfortunate the fact the cases were fake was not conveyed to opposing counsel when Ms. Ke first discovered the true nature of the cases.” The delay drew the judicial criticism, not the hallucination.
At paragraph 29 the court put the underlying conduct plainly: citing fake cases is an abuse of process and is tantamount to making a false statement to the court. At paragraph 44 it ordered the lawyer to review every file she had before the court and report back within 30 days.
The court also took judicial notice of a January 2024 study by Dahl and colleagues, which measured legal hallucination rates of 69% for ChatGPT 3.5 and 88% for Llama 2. That figure is now in a Canadian judgment, which makes “I did not know the tool could do that” a much harder submission in 2026.
In Mata v. Avianca, two New York lawyers filed a brief containing six fabricated cases. When opposing counsel could not find them, the lawyers submitted affidavits vouching for the citations, doubling down on the original error.
Note what the Mata order did not do. It did not compel an apology and it did not make a disciplinary referral. The letters were a disclosure remedy, which is the same instrument Ontario firms keep treating as optional.
Source: practicePRO, LawPRO claims data for 2005 to 2015. Communication failures outrank knowledge failures by more than two to one.
That chart is why I keep steering Ontario firms away from arguing about the tool. LawPRO’s own book says the claim that lands is usually the conversation that did not happen.
Justice Masuhara accepted that Ms. Ke had no intent to deceive, so special costs were refused. Judge Castel accepted no equivalent from the Avianca lawyers, because they had vouched for the fabricated citations under oath after being challenged.
The Canadian outcome was ordinary costs, payable personally. The American outcome was a monetary penalty on the lawyers and their firm plus a court-ordered disclosure exercise. Both are recoverable events. Neither firm was destroyed by the hallucination.
When the Bay Street associate filed her factum, she faced the same fork. Acknowledge fast and absorb the costs, or hold the position and watch the file convert into something much worse. She took the Zhang path on the morning the question landed.
The Six-Step Incident Response When an AI Error Surfaces
Run these six steps in order. The order matters because each step constrains the next, and a skipped step lets exposure compound. The Bay Street firm worked through them between Friday afternoon and the following Wednesday.
- Containment within the hour. Identify which AI tool produced the error, who used it, what data went in, and what came out. Lock further use by that lawyer pending review. Export the prompt and response history before any session deletion, because consumer tools keep it in the user’s own account.
- Scope assessment by end of day. Determine whether the output was externally circulated: filed with a court, sent to a client, served on opposing counsel, or included in a closing. That answer decides whether you are inside or outside the Rule 7.8-1 rectification threshold. It does not affect Rule 7.8-2, which fires either way.
- LawPRO notice before the next business day closes. Open the file with claims intake under Rule 7.8-2. A file number does not commit you to a claim. It documents that notice was prompt. The claims handler will walk you through conflict implications for ongoing representation.
- Client disclosure within 24 hours of LawPRO notice. Put it in writing. State the error, recommend independent legal advice under Rule 7.8-1(b), and address whether you can continue to act under Rule 7.8-1(c). Take care not to prejudice indemnity rights, which is the express caution in Rule 7.8-1(a).
- Court and opposing counsel on each forum’s timetable. The court form depends on the stage: a letter to the case management judge, a corrected filing, a withdrawal motion, or an oral correction. Opposing counsel needs one written acknowledgment and a corrected document. Deliver the correction rather than negotiating it.
- Post-incident policy review within 30 days. Identify the policy or training gap. Update the firm’s AI acceptable use clause set. Run it by counsel and brief the firm. Zhang v. Chen shows why: the court there ordered a 30-day review of every file the lawyer had before it.
The Bay Street firm finished steps one through five by Tuesday afternoon. Step six ran four weeks and surfaced two clause gaps, which is the pattern in every engagement I have run.
In our discovery-support runbooks we measured two failure signatures that reliably surface those gaps.
- A citation that resolves to a different style of cause than the proposition it is cited for.
- A clause whose limitation period reads a year past the operative statute.
Each error reveals something the policy did not anticipate. I have yet to run a review that found none.
For the Ontario clause-level detail, see the LSO AI policy template and our broader AI acceptable use policy field guide.
What Is in a Firm AI Policy: The Clause Checklist
Three clauses carry most of the weight. Each removes a judgment call from an associate working at 11 pm, which is when these errors surface.
- Bright-line rectification threshold. The sentence quoted in the Field Note above, naming both Rule 7.8-1 and Rule 7.8-2.
- Named incident response sequence. The six steps above, adapted to your reporting lines.
- Designated LawPRO contact by role. A clause naming who picks up the phone, never the associate who wrote the filing.
The clause set also needs an internal cascade running alongside the external one. Most Ontario firm policies we have audited skip it, assuming it is obvious. It is not.
- Associates need to know whom they tell first, including after hours.
- Partners need the escalation path to the managing partner, to outside counsel, and to LawPRO.
Associates facing a Friday-night error often do nothing until Monday, because the policy never told them whom to call at 10pm.
Cyber insurance is a parallel track that opens when the AI error involved a confidentiality breach as well as a factual one. A privileged paste into a consumer chatbot puts the cyber policy on notice and engages Rule 3.3-1 confidentiality. A fabricated case in a factum puts LawPRO on notice. If both happened, both are on notice, and practicePRO’s technology practice aids publish checklists your claims handler will recognize.
The clause should name the carrier contact for each track, so nobody is researching brokers at 9 pm. That architecture sits inside the same incident response framework we build for our cybersecurity services clients, which is why the two clause sets look alike.
The policy should also anticipate the LawPRO renewal certification. The questionnaire asks whether any reportable circumstance occurred. The firm needs a process for canvassing partners and senior associates each 12-month cycle so the answer is accurate.
Two thirds of our clients in the Ontario legal vertical had no written canvassing step before we built one. If you want the baseline clause set in front of counsel, book a consultation with our CISSP-led team.
Further reading and primary sources
- Law Society of Ontario Technology Resource Centre. LSO practice resources on selecting and using technology inside an Ontario practice.
- Federation of Law Societies of Canada Model Code of Professional Conduct. the harmonized national rules from which Ontario adopted Rule 7.8.
- Zhang v. Chen, 2024 BCSC 285 on CanLII. the Canadian anchor decision on AI-fabricated authorities.
- Rules of Civil Procedure, R.R.O. 1990, Reg. 194. rule 4.06.1 sets the factum citation and authenticity certification requirements.
- LAWPRO, coverage for new lawyers. states the CA$1 million per claim and CA$2 million aggregate primary limits.
HOW THIS GUIDANCE WAS ASSEMBLED.
This article draws on Fusion Computing data from anonymized client engagements across Ontario and British Columbia law firms in 2025 and 2026. It also draws on a named-client moment with the principal of a Toronto litigation boutique, whose Copilot rollout we led through full LSO Rule 3.3-1 review.
We surveyed 11 partners and 9 associates during 2026 Q1 onboarding calls, and we measured Copilot, Purview and Entra ID deployment timelines across our 18 small-firm client rollouts.
The contrarian finding: the AI tool is rarely the file. In our practice the cost driver is the days between discovery and disclosure, which is what LawPRO’s own claims data has said about communication failures since 2005.
Frequently Asked Questions
Does the LawPRO standard policy cover AI hallucinations?
The LawPRO primary program covers civil liability from negligent errors and omissions in professional services, at CA$1 million per claim and CA$2 million in the aggregate. A filed citation that does not exist is a negligent error and sits inside that framing.
The program does not cover intentional dishonesty, so a lawyer who knowingly vouched for a fabricated citation after being notified would face a coverage question. Prompt notice under Rule 7.8-2 preserves coverage on the underlying error.
Is the LawPRO reporting duty Rule 7.8-1 or Rule 7.8-2?
Rule 7.8-2. It requires prompt notice of any circumstance that may give rise to a claim to an insurer or other indemnitor. The commentary confirms the duty arises whether or not the lawyer considers the claim to have merit.
Rule 7.8-1 is the separate duty owed to the client, and it applies only where the error cannot be rectified readily. Rule 7.8-2 carries no such threshold, so an error you fix the same afternoon is still reportable to LawPRO.
What did Zhang v. Chen 2024 BCSC 285 actually decide about costs?
The court refused special costs. At paragraph 32 Masuhara J. found no intent to deceive and declined the indemnity-scale award the applicant sought, a point widely misreported in AI-and-law commentary.
He instead applied Supreme Court Family Rule 16-1(30)(c) and (d) to make counsel personally liable for ordinary costs of four half-day hearings, assessed by the Registrar. He also ordered her to review every file before the court within 30 days. No Law Society referral was made.
How is Mata v. Avianca different from Zhang v. Chen?
Zhang v. Chen turned on a single disclosure event handled with acknowledgment and apology, and produced ordinary costs payable personally. The court expressly criticised the delay in telling opposing counsel, at paragraph 37.
Mata v. Avianca involved two New York lawyers who vouched for six fabricated citations in sworn affidavits after being challenged. On June 22, 2023 the court imposed a US$5,000 penalty jointly and severally on the lawyers and their firm, and ordered letters to the client and to each falsely named judge.
Who should call LawPRO when an AI error surfaces, the partner or the associate?
The firm’s AI policy should name the role that owns Rule 7.8-2 notice. In most firms that is the managing partner, the practice group leader, or general counsel. It should not default to the associate who produced the work product.
Naming the role in advance removes the judgment call at the moment of the incident. Associates need a documented after-hours path to escalate the issue inside 1 business day.
Does pasting privileged material into a consumer chatbot trigger disclosure?
Yes, and it runs through both the firm’s cyber carrier and the client under Rule 3.2-2 candour. A paste of privileged material into a consumer tool is a confidentiality breach regardless of whether the receiving party acted on the content.
The Office of the Privacy Commissioner of Canada treats AI-tool ingestion of personal information as a collection under its 9 generative-AI principles. Treat any confirmed paste as triggering the incident response sequence, and notify counsel before settling the external communication plan.
What does Rule 4.06.1 of the Rules of Civil Procedure require in a factum?
Rule 4.06.1(2) requires every citation to include a pinpoint reference to the relevant paragraph, provision or page. Rule 4.06.1(2.1), added by O. Reg. 384/24, requires a signed statement certifying that the signer is satisfied as to the authenticity of every authority cited.
Rule 4.06.1(2.2) presumes an authority published on CanLII, a government website, a court website or by a commercial publisher to be authentic. Verifying against CanLII is therefore both the practical and the prescribed check.
What does the Ontario Superior Court AI practice direction require of counsel?
Chief Justice Morawetz signed the Consolidated Civil Provincial Practice Direction on March 17, 2026. It directs counsel and litigants to verify all AI-assisted legal information against authoritative sources, and states that the court will not tolerate inadvertence.
Listed sanctions for misuse include public reprimand, cost orders, adjourning or dismissing the matter, contempt proceedings, and referral of counsel to the Law Society of Ontario. That referral pathway is the reason a Rule 7.8-2 file should already be open before a hearing.
Bottom Line
Two rules run, not one. Rule 7.8-1 covers the client, Rule 7.8-2 covers LawPRO, and only 7.8-2 fires regardless of whether you can fix the error. The Bay Street partner called LawPRO on a Friday, and by Tuesday all four tracks were closed. Mike Pearlstein, CISSP, walked that sequence. Work through our AI deployment guide for Canadian law firms for the rest of the architecture.

