LOADING 0%
ServicesWorkBlogGet in touch
Home / Blog / IT Support
IT Support October 6, 2026 · 4 min read

IT for Colorado Law Firms: What the Rules of Professional Conduct Now Expect

Since January 2026, Colorado's Rule 1.1 comment names technology risks. What Rules 1.1, 1.6(c) and 5.3 expect of a firm's IT, vendors and AI use.

On January 8, 2026, the Colorado Supreme Court amended the Rules of Professional Conduct to say outright what had been implied: a lawyer's competence includes understanding the technology the practice runs on. For a small or mid-sized firm, that turns IT from an overhead question into a professional-responsibility question.

Here is what changed, what the existing rules already required, and what it looks like in a firm's day-to-day IT.

What changed in January 2026

Comment [8] to Rule 1.1 (Competence) now reads, in part, that "a lawyer should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology, engage in continuing study and education."

The same order added a new comment [9] on artificial intelligence: "A lawyer's use of technology, particularly artificial intelligence, can implicate a number of other Rules … Reliance on technology does not diminish the lawyer's duty to exercise independent judgment in the representation of a client."

It also added paragraph [20A] to the Scope section: "A lawyer who uses, directly or indirectly, technology in performing or delivering legal services may be subject to discipline for a resulting violation of these Rules."

The rule that was already there: 1.6(c)

Since 2016, Colorado's Rule 1.6(c) has required that "a lawyer shall make reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client."

"Reasonable efforts" is not a product list. It is a process you can describe. You know where client data lives, who can reach it, how it is protected, and how you would find out if something went wrong.

Your vendors are your responsibility: Rule 5.3

Rule 5.3 covers "nonlawyers employed or retained by or associated with a lawyer," and its comment [3] names the modern case directly: outside services include "using an Internet-based service to store client information." The lawyer must "make reasonable efforts to ensure that the services are provided in a manner that is compatible with the lawyer's professional obligations."

In practice, that covers your IT provider, your cloud document management system, your e-discovery vendor and the AI tools your staff use.

When something goes wrong

The Colorado Bar Association's Formal Opinion 141, Ethical Duties Arising from Data Breach (2020), sets the expectation: "A lawyer must make reasonable efforts to prevent, monitor for, halt, and investigate any security breach of data the lawyer controls."

Notice the verbs: prevent, monitor for, halt, investigate. A firm that can't tell whether a mailbox was accessed can't meet the last three. A firm is also a Colorado business, so the state's 30-day breach-notification statute applies too. We explain it in your 30-day notification clock.

What this looks like in a firm's IT

  • Multi-factor authentication on email, the document management system and remote access, for everyone, including partners.
  • Encrypted devices for laptops and phones that hold client material, and a way to wipe a lost one.
  • A map of where client data lives: the DMS, email, shared drives, personal phones and the scanner's hard drive. You can't protect what you haven't listed.
  • Vendor review: what each service stores, where, who at the vendor can access it, and what your contract says about breaches.
  • Logging you can use. Sign-in and mailbox audit logs, kept long enough to answer "was anything accessed?" That is the monitor for and investigate in Opinion 141.
  • Backups the firm controls, outside your Microsoft or Google tenant. See what Microsoft 365 actually keeps.
  • An AI-use policy: which tools are approved, what client information may go into them, and who reviews the output before it reaches a client or a court. That is comment [9] in practice.
  • Offboarding: when someone leaves, their access ends the same day, and their files stay with the firm.

Where we fit

We provide managed IT support and information security for Colorado firms. We also build legal technology, from a secure practice-management platform to a virtual legal assistant. If you want AI without sending client files to a public service, see on-premise vs cloud AI for regulated businesses. More on our legal work: technology for Colorado law firms.

Frequently asked questions

Is there a Colorado ethics opinion on generative AI? Not a formal CBA opinion as of October 2026. The bar's formal opinion index runs through No. 151 without one. The guidance is in the January 2026 rule amendments: comments [8] and [9] to Rule 1.1 and Scope [20A].

Do the rules require specific technology, like encryption? No. They require reasonable efforts, judged by the sensitivity of the information and the circumstances. Encryption and multi-factor authentication are simply the most common way to show them today.

If our IT vendor causes a breach, is it their problem? It is theirs and yours. Rule 5.3 requires the firm to make reasonable efforts to ensure the vendor's work is compatible with your obligations, which starts with choosing and reviewing vendors deliberately.

This article summarizes the Colorado Rules of Professional Conduct as amended through January 2026 and CBA Formal Opinion 141. It is not legal or ethics advice. For your firm's obligations, consult ethics counsel.

Want an outside look at your firm's IT? Get in touch.

Eboxlab Team
Denver, CO

Have a platform in mind?

We scope, design, and build systems that outlast the spreadsheet they replace.

Start a project →