Dutch lawyers may use AI, as long as they remain personally responsible for every piece of advice and every court document. The NOvA, the Netherlands Bar Association, issued recommendations on AI and LLM use in December 2025, not binding rules; what does bind are the core values in the Dutch Lawyers Act, professional secrecy, the GDPR and the EU AI Act. In July 2026 a Dutch disciplinary court showed where it goes wrong: AI-generated case references that nobody had checked.
In short
- The NOvA recommendations of 16 December 2025 give direction per core value. They are not a regulation, not a rule of professional conduct and not a directive.
- No supervisor has announced AI checks during office visits. Deans do act on signals about AI use. In 2026 the supervisors are still exploring how to supervise it.
- The concrete risk sits with the disciplinary courts: in July 2026 a lawyer was reprimanded after AI-generated case references turned out to be wrong.
- The EU AI Act reaches a law firm mainly through AI literacy (Article 4). Article 50 rarely requires anything of a firm, and certainly not a disclosure in every court document.
- Put four things in place: an AI policy, a list of approved tools, a fixed source check and sound vendor agreements.
May a Dutch lawyer use AI?
Yes. No statute and no conduct rule prohibits a lawyer from using AI. The question is not whether you use it, but how.
The yardstick is Section 10a of the Dutch Lawyers Act (Advocatenwet). It lists five core values: the lawyer is independent, partisan (on the client's side), competent, of integrity, and a confidant bound by professional secrecy. These core values apply to everything you do, including work where AI helps.
By AI we mainly mean generative AI: large language models (LLMs) that write, summarise or analyse text. Such a model predicts which text is likely to come next. That is why its answers often sound convincing even when they are wrong. A fabricated ruling or a wrong statutory reference is called a hallucination.
The NOvA puts it this way: AI is a valuable tool, provided it is used with the core values in mind. The lawyer always remains responsible for the advice and for protecting the client's interests.
What is the NOvA guidance on AI use in Dutch law firms?
On 16 December 2025 the NOvA published its Aanbevelingen AI in de advocatuur (Recommendations on AI in legal practice), drawn up on the advice of its Digitalisation & AI working group. The recommendations are organised per core value, with concrete points for daily practice.
What they are: direction. The NOvA describes its role as informing lawyers about the responsible use of AI. In a NOvA article from March 2026, a member of the working group calls the recommendations a living document that will be built on as insight develops.
What they are not: a regulation, a rule of professional conduct or a directive. No sanction attaches to them as such. They still matter. They show how the Bar reads the core values when AI is involved, and the disciplinary courts do apply those core values.
The recommendations per core value, in brief:
| Core value | What the NOvA recommends |
|---|---|
| Competence | Invest in knowledge of AI and the rules around it. Gain hands-on experience. Always verify the output, and agree with vendors in advance how quality and safeguards are handled. |
| Confidentiality | No confidential data in free tools or public AI models. Share only what is strictly necessary, know your data flows and choose vendors carefully. |
| Independence | AI supports, it does not steer. Watch out for tools that tend to confirm your prompt, even when the prompt is wrong. Supervise staff and vendors. |
| Integrity | Never adopt AI output without checking it. Adopt a firm-wide AI policy and inform clients about it. Be open internally about AI use. |
| Partisanship | You remain responsible for partisan but lawful representation. AI must never lead. |
Two recommendations are the sharpest in practice. Under competence: always check quotes, case law and facts by hand before use, and only use tools that cite their sources so the output can be verified. Under integrity: never adopt AI output unchecked.
Does the dean check AI use during an office visit?
Not as a standard item. No supervisor has announced AI checks during office visits. The claim circulates online, but the primary documents say something else. (In the Netherlands, the local deken or dean of each bar district supervises the lawyers in that district.) Deans do act on signals about AI use: the disciplinary case below started with a signal from the court to the dean.
The Supervisory Board (College van Toezicht) oversees how the deans supervise; it does not supervise lawyers directly. Its 2026 work plan puts AI on the agenda for its talks with the deans. The tone is inquisitive: the board sometimes receives signals about AI use and would like to hear how the supervisors deal with it.
The deans' council (dekenberaad) takes the same step in its 2026 supervision plan. AI is a new focus area with its own portfolio, and the plan for 2026 is to explore how responsible AI use is supervised. Its annual report for 2025 says the portfolio will partly focus on enforcement, but that its design is still being worked out. And in its April 2026 progress report the Supervisory Board names the key question as which questions a supervisor can and should be asking.
The conclusion is sober. The direction is set, the execution is not. There is no AI inspection regime in 2026. That does not make the risk small, because the disciplinary courts need no new framework.
What did the disciplinary court say about AI references?
In July 2026 the Disciplinary Court in 's-Hertogenbosch reprimanded a lawyer (ECLI:NL:TADRSHE:2026:93). A reprimand (berisping) is, after a warning, the lightest of the five disciplinary measures in Section 48 of the Dutch Lawyers Act. The case was brought by the local dean.
The AI complaint came first. The lawyer had copied case law generated by an AI tool into a statement of defence, without checking the references or even reading the rulings. Of the eight rulings cited, one ECLI number did not exist. The other seven belonged to entirely different rulings than described. (An ECLI is the European Case Law Identifier, the unique number of a court decision.) The court called this extremely careless.
Everyone involved in proceedings, the court held, must be able to rely on case law cited by a lawyer actually existing and on the references being correct. Uncritically adopting AI output breached the core values of competence and integrity and conduct rule 8 (no incorrect information). Earlier, the subdistrict court had found a breach of Article 21 of the Dutch Code of Civil Procedure: the duty to state the relevant facts fully and truthfully.
Three qualifications belong with this:
- The reprimand rests on more than AI. Besides the AI point, the court upheld four further shortcomings (paras 5.7 to 5.10), including a failure to appear at hearings. The AI point came first, but it was not the only one.
- The confidentiality ground was dismissed. The dean's suspicion that confidential data had been entered into the tool was not enough.
- Timing counted. The documents dated from July 2025. According to the court, AI literacy was not yet common ground then and the Bar's recommendations did not yet exist. Anyone working today will find that argument hard to use.
Which tool was involved is not established. We discuss the ruling in more detail in the reprimand over AI references.
Can you put client data into an AI tool?
Only in an environment with strong safeguards. Professional secrecy under Section 11a of the Dutch Lawyers Act covers everything you learn in your professional capacity. By law it also binds staff and anyone else involved in the practice.
The NOvA is specific. Do not use confidential data in free tools: the less you pay, the more of your data is probably used. Do not enter confidential or client data into public AI models. In its FAQ, the NOvA says client documents can only go into an AI tool with strong contractual safeguards, or in a tool hosted and managed within the firm.
The NOvA also asks you to know your data flows. Where is data stored and processed: in which country, by which subcontractors, with which security? Watch for what a tool reads without being asked, such as a plug-in that sees more than your prompt.
And the client? The recommendations say: ask the client's consent for AI use in the file, and inform clients about your AI policy. The NOvA's FAQ adds nuance. There is no general rule that you must report every use of AI. Transparency is often desirable, especially when AI plays a substantial role or affects confidentiality, quality, cost or personal data. When in doubt, inform the client beforehand and ask for consent where needed.
What does the GDPR require when you use AI?
As soon as an AI tool processes personal data, the GDPR applies. In a client file, that is almost always the case.
- Processor agreement (Article 28 GDPR). If a vendor processes data for you, you are the controller and the vendor is your processor. You may only use processors that offer sufficient guarantees, and they may not engage sub-processors without your written authorisation.
- DPIA (Article 35 GDPR). A data protection impact assessment maps the risks of a processing operation in advance and how you reduce them. It is mandatory where processing is likely to result in a high risk, especially with new technologies. The NOvA recommends a DPIA whenever personal data is involved.
- Record your choices. The NOvA asks you to document why you chose an AI tool and to keep track of which services process personal data.
What does the EU AI Act mean for a law firm?
Less than is often claimed. A firm that uses AI tools is, in the language of the AI Act, a deployer: someone who uses an AI system under its own authority. The heaviest duties rest with the provider, the party that develops the system and places it on the market.
AI literacy (Article 4). This has applied since 2 February 2025 to every organisation that uses AI. As of 27 July 2026 the article was amended by the Digital Omnibus on AI. You take measures that support the AI literacy of your people. You do not have to guarantee a particular level per person. Training, house rules and an AI policy are such measures. See also our article on AI literacy under the EU AI Act.
Transparency (Article 50). This article has applied since 2 August 2026. It asks far less of a law firm than some articles suggest:
- A chatbot must tell people they are dealing with an AI system. That duty rests with the provider.
- AI output must be marked in a machine-readable format. That too is a provider duty. For systems already on the market before 2 August 2026, the omnibus allows until 2 December 2026.
- A deployer must disclose a deepfake, and AI-generated text published to inform the public on matters of public interest. The latter duty falls away where a human has reviewed the text and someone holds editorial responsibility.
- Anyone using emotion recognition or biometric categorisation must inform the people concerned. That rarely arises in a law firm.
A court document or advice to a client is none of these. Article 50 does not oblige you to state in a pleading that you used AI. Whether you disclose it follows from the core values and your arrangements with the client.
High risk. Legal AI used by lawyers generally does not fall into the high-risk category. Annex III covers AI intended to be used by or on behalf of a judicial authority, or in a similar way in alternative dispute resolution. The high-risk obligations have, moreover, been postponed to 2 December 2027 and 2 August 2028.
How do you choose a responsible AI vendor?
Read the terms yourself and ask your questions up front. The NOvA warns: do not rely only on FAQs or marketing promises. Check the terms on data ownership, intellectual property, liability and exit. Watch out for vendor lock-in: becoming dependent on a supplier you cannot easily leave.
Who is liable when a vendor's software makes a mistake, and what the contract and product liability cover, is explained in AI liability: who is responsible when an agent makes a mistake?.
Questions to put to any vendor:
- Where is my data stored, and where do the models run?
- Is my input used to train models? How long does the model provider keep anything?
- Which sub-processors are involved, and can I object to them?
- Does the tool show the source for every answer, and can I open that source?
- What happens when the tool cannot find a source: does it say so, or does it fill the gap?
- Who at the vendor can access my data, and is that logged?
- How do I get my data back when I leave?
Test it yourself as well. The NOvA warns about tools that tend to confirm your prompt even when it is wrong. So ask a question with a deliberate error in it, and see whether the tool pushes back.
Checklist: what should a firm put in place?

Matrix: per topic what the NOvA recommends, what the law requires and what a firm records
Use this list as the starting point for your firm's policy:
- AI policy. Record which tasks may involve AI, which may not, and who is ultimately responsible. Tell clients about it.
- Approved tools. Keep a list of approved tools. Rule out free and public tools for confidential data.
- Data flows. Know for each tool where data is stored and processed, and which sub-processors are involved.
- Processor agreement and DPIA. Sign a processor agreement with every vendor that processes personal data. Carry out a DPIA before rollout.
- Source check. No ruling, statutory provision or quote leaves the firm until someone has opened and read the source.
- Training. Make sure everyone who uses AI knows the basics: what a language model is, where it goes wrong and how to check it.
- Supervision. Agree who supervises the AI use of staff and vendors, and review it regularly.
- Client arrangements. Decide when you inform a client in advance or ask for consent.
How it works at Prudai
We build LEO, an AI assistant for lawyers. So here is how we have handled the points in this article in our own product, and where the limits are.
Sources you can open. LEO works with more than 100 sources, including legislation and case law. For disciplinary law, LEO searches the rulings of the Dutch disciplinary tribunals live. Which sources LEO consults is public on the sources page (in Dutch). How this works for case law is explained in why AI invents Dutch case law.
A gate for ECLI numbers. The disciplinary case above turned on ECLIs that came from nowhere. In LEO's chat, a mechanical gate checks every answer for exactly that. If an answer cites an ECLI that did not come from a source, a tool or your own documents in that conversation, the model must retrieve the ruling first. If that fails, the answer visibly carries an "unverified" notice. The limit: the gate checks whether a ruling was retrieved, not whether it supports your argument. Reading it remains your job.
First a plan, then your approval. A LEO workflow first proposes a plan. In 67 of the 72 workflows, LEO then waits for your approval before the specialists start. You can approve, adjust or stop. That keeps the lawyer in charge, which is exactly what the NOvA means by "AI supports, it does not steer".
Models pass a compliance gate first. Before a model may go into production with us, it must pass a compliance gate: contractual EU processing, an acceptable processor chain and no vendor-mandated data retention that cannot be switched off, such as the 30 days Anthropic requires for Claude Fable. On PrudentBench we publish which models pass and how they score. To be clear: an independent, peer-reviewed benchmark for legal research in Dutch, based on Dutch law, does not exist at this moment. That is why we are building our own test set; it has no results yet.
Storage. Client data is stored on our own servers in EU data centres. More on how security is organised is on the security page (in Dutch).
For a practice-area view, see AI in personal injury law. The same question arises outside the Bar too, for example for bailiffs.
For the specialist
Dutch Lawyers Act. Section 10a(1) lists the core values: independent (a), partisan (b), competent (c), of integrity (d) and confidant observing secrecy within the limits of the law (e). Section 11a(1) lays down professional secrecy, also for staff and others involved in the practice. Under Section 11a(2) the duty continues after the work ends. This may also extend to a vendor involved in your practice, so put it in the contract too. Section 45a governs supervision by the dean, Section 48 the disciplinary measures.
Rules of professional conduct 2018. Rule 3 concerns confidentiality, rule 8 the provision of incorrect information. In ECLI:NL:TADRSHE:2026:93 rule 8 was held breached alongside the core values of competence and integrity (para. 5.6). The confidentiality complaint was dismissed (para. 5.12). The sentencing reasoning is in para. 6.2.
AI Act, Regulation (EU) 2024/1689.
- Article 3(4): definition of deployer. Use in a personal, non-professional activity is excluded.
- Article 4, as amended by Regulation (EU) 2026/1744 of 8 July 2026 (OJ 24 July 2026, in force 27 July 2026): the duty is to take measures to support the development of AI literacy, expressly without guaranteeing a particular level.
- Article 50: paragraphs 1 and 2 address providers, paragraphs 3 and 4 deployers. New Article 111(4) gives providers of systems placed on the market before 2 August 2026 until 2 December 2026 for the marking in paragraph 2.
- Edge case: if a firm puts its own chatbot on its website, the firm may be the provider and paragraph 1 does apply. If a firm publishes AI text on matters of public interest without human editorial control, Article 50(4), second subparagraph, applies.
- Annex III, point 8(a): AI for judicial authorities and, in a similar way, alternative dispute resolution. High-risk application dates have moved to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
European level. On its recommendations page the NOvA refers to the CCBE guide on the use of generative AI by lawyers of 2 October 2025.
Frequently asked questions
Is the NOvA guidance on AI binding?
No. The recommendations give direction; they are not a regulation or a rule of professional conduct. They do work through the core values in Section 10a of the Dutch Lawyers Act, which the disciplinary courts apply. Ignoring the recommendations in a way that breaches a core value therefore carries real disciplinary risk.
Do I have to tell my client that I use AI?
There is no general rule that you must report every use of AI. The NOvA does recommend informing clients about your AI policy and asking consent for AI use in the file. If AI plays a substantial role, or affects confidentiality, cost or personal data, informing the client in advance is wise.
Do I have to state in a court document that AI was used?
Not under Article 50 of the AI Act. For deployers, that article mainly covers deepfakes and text published to inform the public. Everything in the document must still be correct: Article 21 of the Dutch Code of Civil Procedure and conduct rule 8 require accurate and complete information, with or without AI.
Can I use ChatGPT for a client file?
Not with confidential or client data in a free or public version. That touches professional secrecy and the GDPR. With a business environment, strong contractual safeguards and a processor agreement it can be done, provided you always check the output yourself.
What happens if an AI reference turns out to be wrong?
You risk a disciplinary measure. In July 2026 a Dutch lawyer was reprimanded, partly because AI references pointed to rulings that did not exist or were different rulings. A court may also find that you did not state the facts truthfully (Article 21 of the Dutch Code of Civil Procedure).
Sources
- NOvA, Aanbevelingen AI in de advocatuur (in Dutch; published 16 December 2025, consulted 2 October 2026)
- NOvA, Digitalisering & AI, with FAQ (in Dutch; consulted 2 October 2026)
- Supervisory Board, 2026 work plan (PDF) (in Dutch; adopted 18 December 2025, published January 2026)
- Deans' council, 2026 supervision plan (PDF) (in Dutch; January 2026)
- Disciplinary Court 's-Hertogenbosch, 27 July 2026, ECLI:NL:TADRSHE:2026:93
- Dutch Lawyers Act (Advocatenwet) (in Dutch; version in force from 1 January 2026)
- AI Act, Regulation (EU) 2024/1689
- Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 July 2026)
Would you like to know how LEO makes the NOvA recommendations workable in your practice? Read how LEO supports verification, data flows and firm policy (in Dutch) and request a demo there.
Updated on 2 October 2026
Photo: BunteAufnahmen via Pixabay
