How to read the map
Last checked: 3 October 2026. Each row is marked documented (the source so provides) or configuration-dependent (the outcome depends on account, version, settings or contract). There are no scores, no vendor comparison and no approval of any tool. The full text is not copied; each row links to the exact source page. The map is maintained by CLOAK — Corporate Intelligence & Oversight, CIDAH's intelligence unit.
1. Resolution 60/24 — 23 provisions (10 documented · 13 configuration-dependent)
| Section | Provision (mapped summary) | Status | Source (flipbook) |
|---|---|---|---|
| — | The Bar's official publication of 18/09/2026 points to the current flipbook (28 pages), which is to be read as the updated text of Resolution 60/24. | documented | Source |
| §4 | Non-compliance with the guidance may create a rebuttable prima facie presumption of an ethical breach; compliance is a significant indication but does not exempt from the law or from case-by-case assessment. | documented | Source |
| §9 | An agent is defined by a degree of autonomy, workflow planning, tool selection and external interaction; not every generative-AI system or chatbot is an agent. | documented | Source |
| §§10–11 | "Open" vs "closed" is determined by the contract, the features and actual use — account, version and settings — not by a marketing name. | configuration-dependent | Source |
| §§12–14 | Restricted information includes non-public information subject to a duty to limit exposure; removing a name does not guarantee anonymisation. ISO/IEC 27001 and 42001 may help carry the classification burden, not authorise use automatically. | configuration-dependent | Source |
| §§29–31 | AI output must be verified before reliance, integration into work, delivery to a client or presentation to a third party; retrieval from a database or source references do not remove independent verification. | documented | Source |
| §§32–33 | Claims, authorities, analyses and wording must be checked independently; a system's description as advanced, reliable or widely used cannot be relied upon. | documented | Source |
| §§37.1–37.3 | Confidentiality and privilege apply when information is given to an AI vendor; the vendor's identity, access, retention, deletion and protections must be examined, and the client informed or asked for informed consent as circumstances require. | configuration-dependent | Source |
| §§38.1–38.2 | Restricted information requires examining the suitability of the system type, the processing and the permissions; omitting a name or number is insufficient if the client or matter can be identified by cross-referencing. | documented | Source |
| §§39.2–39.4 | The starting point is to refrain from entering restricted information into an open platform or an environment without sufficient certainty; departure only in narrow circumstances. | configuration-dependent | Source |
| §§40.1–40.2 | A closed environment is assessed by commitments, version, account, settings, access, retention/deletion and protections; a service offered to the public or a public-cloud service is not disqualified by itself. | configuration-dependent | Source |
| §§40.3–40.4 | Even a closed environment does not exempt from caution; a new, autonomous or powerful system requires heightened care and sometimes isolated testing before integration. | configuration-dependent | Source |
| §§41.1–41.2 | Unauthorised internal access must be prevented, ethical walls preserved and permissions and monitoring set by role and need; technological controls are preferred over procedure. | configuration-dependent | Source |
| §§41.3–41.4 | Ethical walls must be preserved also in training and system linking; whether the vendor is a "holder" must be examined and processing, security, retention, deletion and access regulated by contract. | configuration-dependent | Source |
| §§42.1–42.3 | No automatic duty to disclose every routine or technical use; transparency is required mainly when the use is material to the representation or a decision, involves restricted information in an open platform, or the client asks. | configuration-dependent | Source |
| §§43.1–43.3 | Restricted information in an open platform requires prior informed consent where a risk of identification or linkage remains; consent must be explicit, specific and informed — not blanket. | configuration-dependent | Source |
| §§45.1–45.3 | A reasonable firm policy is required defining systems, accounts and configurations, permitted tasks, prohibited information, senior review, verification, handling of requests and documentation; firm size affects scope, not the minimum threshold. | documented | Source |
| §46.1 | Documentation of material or exceptional uses is recorded as appropriate within firm procedures; a technical login record is not a record of agent actions. | documented | Source |
| §46.2 | The firm must train lawyers, interns, legal staff and administrative staff who use the system; providing a licence or tool is not enough. | documented | Source |
| §§47–48 | The vendor, its contractual commitments, security, access, deletion and subprocessors must be reviewed and changes monitored; marketing to the legal sector or a "secure" label does not exempt. | configuration-dependent | Source |
| §§52–54 | An agent may not make substantive decisions, give independent advice, or file or perform a legal act without sufficient human supervision and approval; technical, bounded, documented and reversible actions under a prior human decision are permitted. | configuration-dependent | Source |
| §53 | Section 53 mentions an immediate stop button among the controls to be observed, especially with connections to firm systems; section 54 also allows prior policy, permissions, alerts, documentation and intervention capability. | configuration-dependent | Source |
| §61 | The opinion complements and does not derogate from privacy laws, regulations and professional duties; the result under section 4 does not replace examination of other law. | documented | Source |
2. Israel — complementary sources (16 rows: 13 documented · 2 configuration-dependent · 1 not shown)
| Tag | Finding | Status | Source |
|---|---|---|---|
| Bar footnotes | Footnotes 1, 2 and 28 of the opinion refer to seven separate proceedings in different courts and dates; each judgment must be checked separately. | documented | Source |
| Privacy regulator | The Privacy Protection Authority's July 2026 recommendations on AI agents address personal use by individuals; they do not regulate business processing or legal work. | documented | Source |
| Research status | No separate March 2026 PPA document dedicated to AI agents was located in the official sources checked; a limited search finding, not proof of absence. | not shown | Source |
| Privacy regulator | The PPA's April 2025 draft on applying the Privacy Law to AI systems is a draft for public comment, not a final directive. | documented | Source |
| Privacy regulator | The PPA's consent opinion of 25/02/2026 is a separate document on the consent principle; not an AI-agent recommendation. | documented | Source |
| Regulation 15 | Per the PPA FAQ, "external party" under Regulation 15 is broader than "holder": it may include anyone with actual access to the database or its systems in the course of the service. | documented | Source |
| Regulation 15 | A vendor usually also becomes a "holder" when it stores or processes data for the controller; the test is functional, not by contract label. | configuration-dependent | Source |
| Regulation 15 | The Regulation 15 guide after Amendment 13 directs the controller to assess vendor risk, specify the service and systems, and regulate a written agreement, permissions, oversight and termination. | documented | Source |
| Cloud | Per the PPA FAQ, legal responsibility for database security remains with the controller in the cloud; operational responsibility is split by service model. | configuration-dependent | Source |
| Case law | HCJ 38379-12-24 Plonit v. Sharia Court of Appeals (23/02/2025): petition dismissed; the court mapped possible tools against pleadings with fabricated authorities but did not apply them in that first case. | documented | Source |
| Case law | HCJ 23602-01-25 Association for Dog Rights v. Minister of Agriculture (28/02/2025): petition dismissed; the petitioner was ordered to pay NIS 7,000 costs; no personal costs on counsel in that decision. | documented | Source |
| Case law | AAA 63194-08-25 Nevo Ben Cohen v. Ramat Gan Municipality (22/03/2026): the municipality was ordered to pay NIS 30,000 costs; the court refrained from personal costs on counsel; responsibility for a filed document lies with the signing lawyer. | documented | Source |
| Case law | Khuald v. Menora (Labour Court) (30/04/2025): plaintiff's counsel ordered to pay NIS 1,000 personal costs after a response citing non-existent or wrong case law. | documented | Source |
| Case law | CC Digger Center v. Abu Guider (01/09/2025): claim dismissed; defendant's counsel personally ordered to pay NIS 7,500 to the State Treasury for fabricated, unchecked authorities. | documented | Source |
| Case law | CC Ploni v. Tzachi (09/07/2025): 5 of 10 authorities in the summations were not found; NIS 3,000 personal costs on plaintiff's counsel to the State Treasury. | documented | Source |
| Case law | Class Action Mahala Association v. Clalit Health Services et al. (May 2025): certification motion struck; the applicant ordered to pay NIS 10,000 to each of four respondents; counsel personally ordered to pay NIS 5,000 to a respondent and NIS 5,000 to the State Treasury. | documented | Source |
3. Israel vs ABA Formal Opinion 512 (10 rows)
| Tag | Comparison | Status |
|---|---|---|
| Scope / status | ABA Formal Opinion 512 (29/07/2024) interprets the ABA Model Rules for generative AI; it is not Israeli law and does not by itself determine the law in every US state. | documented |
| Competence | Both frameworks require a reasonable understanding of capabilities and limits, not engineering expertise; Israel (ss. 19–24) adds AI literacy and ongoing monitoring. | documented |
| Verification | Both require checking outputs and leaving responsibility with the lawyer; Israel (ss. 29–33) states verification of every output explicitly. | documented |
| Confidentiality | ABA applies a risk analysis and requires informed consent before entering information into self-learning tools; Israel defines open/closed/cloud categories in detail; no absolute Israeli ban on public cloud (s. 40.2). | configuration-dependent |
| Disclosure / transparency | Neither sets automatic disclosure for every use; both point to circumstances such as client request, professional significance, important decisions and fee impact. | configuration-dependent |
| Supervision and vendors | Both require procedures, training, supervision and vendor review; Israel (ss. 45–48) details configuration, permissions, subprocessors, access and retention/deletion. | documented |
| Agents | Israel (ss. 52–54) addresses autonomous systems explicitly; ABA 512 predates the agent era. Not a general prohibition and not unique to the supervision principle worldwide. | configuration-dependent |
| Fees | ABA details billing for actual time, overhead vs direct expense and reasonable fees; Israel (s. 42.2) requires transparency when AI is relevant to the fee basis. | documented |
| Documentation | Israel (s. 46.1) speaks of policy and documentation of material or exceptional uses, s. 53 of logs for connected agents; ABA suggests marking outputs — guidance, not a technical log. | configuration-dependent |
| Local vs global | The professional core is global; the Israeli application layer includes the Bar opinion, Regulation 15 / Amendment 13 and PPA positions. Compliance with ABA 512 is not sufficient in Israel, and not all barriers are unique to Israel. | documented |
Source: ABA Formal Opinion 512, American Bar Association, 29 July 2024
4. Distinctions to keep — as the firm reads the opinion (version of 18/09/2026)
- Section 40.2 does not prohibit public cloud; "closed" or "enterprise" labels prove nothing by themselves.
- Section 53 mentions an immediate stop button in the context of system connections and risk; section 54 does not require real-time approval of every action.
- Section 4: non-compliance may create a rebuttable prima facie presumption; compliance is a significant indication, not an exemption.
- Section 46.1 concerns firm-level documentation of material or exceptional uses; a login log, a system audit log and an agent action log are different records.
- The Privacy Protection Authority's July 2026 recommendations on AI agents address personal use by individuals; they are not binding business guidance.
- "External party" under Regulation 15 is broader than "holder"; legal responsibility for database security stays with the controller, including in the cloud.
Frequently asked questions
What does the map cover?
The map covers 23 provisions of Israel Bar Resolution 60/24 (version of 18 September 2026), 16 complementary Israeli sources — the Privacy Protection Authority, Regulation 15 as amended by Amendment 13, and seven court proceedings from 2025–2026 — and 10 comparison points with ABA Formal Opinion 512. Each row is marked documented or configuration-dependent and carries a source link.
What does "configuration-dependent" mean in a normative map?
That the legal outcome depends on facts: the account, version, settings, contract or actual connections. For example, the same product can be an open platform in a personal account and a closed one in an organisational account with suitable commitments. Such a row cannot be applied without checking the specific configuration.
Does the map approve any tool?
No. The Israel Bar Association does not approve AI products, and the map contains no scores or vendor comparison. It is a navigation aid to sources, not a legal opinion. Assessing fit to a matter, contract and configuration remains with the lawyer.
When was the map last checked and what happens when the law changes?
All rows were checked on 3 October 2026; document dates are stated separately from check dates. The Bar opinion (section 48) requires monitoring of changes, and the Privacy Protection Authority updates its FAQ and guidance. The map is re-checked periodically; the date of the last check is stated above.
How does this map differ from the opinion itself?
The opinion is the primary and binding source; the map is a section-by-section summary with a link to the exact page in the official flipbook. The full text is not copied here. When in doubt, read the source.