A Law Firm AI Policy People Will Actually Follow
A practical AI policy for law firms: approved tools, permitted information, required review, and a clear route for questions and exceptions.
A useful AI policy has to survive contact with a busy Tuesday afternoon. If the rules amount to “never use AI,” people will experiment through personal accounts. If the rules say “use good judgment,” no one knows what the firm has actually approved.
The better approach is a short policy built around the work lawyers and staff already do. It should answer four questions without making anyone hunt through a manual:
- Which tools may I use?
- What information may I put into them?
- What review is required before I rely on the result?
- Who can approve a new use?
Start with tasks, not product names
“Approved AI” is too broad. A tool may be sensible for turning public information into an outline and unsuitable for analyzing an unredacted client file. Approval should cover a tool, a type of information, and a task.
A small firm might begin with three lanes:
Routine assistance. Brainstorming, formatting, or summarizing public material. A quick human review may be enough.
Matter work. Organizing discovery, comparing supplied documents, drafting correspondence, or proposing research paths. This lane needs an approved environment, careful handling of client information, and substantive review by someone qualified.
Decisions and representations. Final legal advice, filings, deadlines, conflicts, trust accounting, and other work where an error can directly harm a client. AI may help prepare the work, but a lawyer must independently verify the relevant facts and law and own the final decision.
This structure is easier to remember than a long list of prohibited prompts. It also gives the firm room to approve a narrow use without approving everything the product can do.
Be specific about client information
ABA Formal Opinion 512 connects generative AI use to duties of competence, confidentiality, communication, candor, supervision, and reasonable fees. A policy should therefore say what counts as protected information, where it may be processed, and what must happen before it leaves systems the firm controls.
Do not rely on “anonymize it” as the whole rule. A detailed fact pattern can identify a client even after names are removed. The combination of a location, transaction, date, medical condition, or unusual dispute may be enough.
For every approved tool, record:
- whether prompts and files are retained;
- whether customer material is used to train or improve models;
- who can access the material, including subprocessors;
- what contractual confidentiality terms apply;
- how data is deleted; and
- whether client consent is required for the intended use.
Provider terms and settings change. Give one person responsibility for checking them on a schedule and when the firm receives a product-change notice.
Define review in plain language
“Human review required” sounds reassuring but says very little. The policy should tell the reviewer what to check.
For a legal research draft, that means opening every cited authority, checking the quotation in context, confirming current validity and jurisdiction, and looking for contrary authority. For a summary of a record, it means comparing material statements with the source documents and looking for omissions. For client correspondence, it includes tone, factual accuracy, advice, and whether AI use itself should be discussed with the client.
The reviewer must have the knowledge, time, and authority to reject the output. Clicking approve is not supervision.
Include fees, courts, and client communication
AI may reduce the time required for a task. Under hourly billing, a lawyer should bill time actually spent, not the time the task might once have taken. Charges for an AI tool must also be reasonable and explained consistently with the engagement.
Court rules are not uniform. Some judges and courts have adopted AI-related certifications or disclosure requirements. The person filing a document should check the applicable rules and standing orders, just as they would check formatting and filing requirements.
Client disclosure is also contextual. A policy should require escalation when AI will receive confidential information, materially influence advice, perform a function the client reasonably expects the lawyer to perform, or affect the fee arrangement.
Give people a safe way to ask
Most policy failures happen at the edge, when someone encounters a useful feature the policy did not anticipate. Make the response easy: pause the matter-specific use, send a short request describing the tool, data, task, and proposed review, and get a prompt answer from a named person.
Avoid punishing good-faith questions. People will hide experiments if asking for help feels like confessing misconduct.
A one-page core policy
The main page can be simple:
- Use only approved tools for approved tasks.
- Do not enter client or firm-confidential information unless that exact use is approved.
- Treat AI output as unverified work product.
- Check material facts, quotations, citations, calculations, and legal conclusions against authoritative sources.
- A lawyer remains responsible for final advice, filings, deadlines, and decisions.
- Follow client instructions, engagement terms, and applicable court rules.
- Bill only actual, reasonable time and properly disclosed charges.
- Report unexpected output, suspected disclosure, or a new use promptly.
Put the detailed tool register and review checklists behind that page. Review the policy after incidents, major product changes, and at least once a year.
A good policy does not try to settle every future question. It makes the common uses clear, puts firm boundaries around sensitive work, and gives people a quick route through the questions no one could predict.
Primary reference
This article is general information for legal professionals, not legal advice or an ethics opinion. Rules of professional conduct vary by jurisdiction—consult yours.