What belongs in a law firm AI use policy
A policy is not a compliance artifact you produce to have one. It is the firm's written answer to a question someone will eventually ask under unpleasant circumstances: how did you know this was safe to use on that matter? Eight sections answer it.
Why the policy exists
Model Rules 5.1 and 5.3 require managerial lawyers to make reasonable efforts to ensure the firm has measures in effect giving reasonable assurance that lawyers and non-lawyer assistance conform to professional obligations. For any firm past a handful of people, a written policy is simply the most practical way to demonstrate those measures exist.
It is worth being precise on one point, because the internet is not. ABA Formal Opinion 512 recommends that firms consider adopting policies on generative AI. It does not, in its text, mandate a written policy in a prescribed form. The supervision rules are what make one practically necessary. Getting this right matters because a compliance file that misdescribes the authority it relies on invites scrutiny of everything else in it.
The eight sections
1. Scope
Who the policy binds and what it covers. Name partners, associates, paralegals, staff, and contractors explicitly. State whether it applies to personal accounts used for firm work, because that is where most uncontrolled use actually happens.
2. Approved tools
A named list. Not a category, not "enterprise AI tools," a list of products with versions or tiers. Each entry should record the date of vendor review, who conducted it, and what tier of data the tool may touch. A tool approved for internal brainstorming is not thereby approved for client medical records.
3. Prohibited tools, with reasoning
The reasoning is the part firms skip and the part that does the work. "Not approved" invites argument. "Not approved because the consumer tier retains inputs for 30 months and reserves training rights" ends it, and it tells the next reviewer what would have to change for the answer to be different.
4. Task-level restrictions
What may be done, with what data, in which tool. The useful structure is a grid of data sensitivity against task, because attorneys do not think in terms of tools, they think in terms of the thing they are trying to get done.
| Data | Permitted | Prohibited |
|---|---|---|
| No client information | Any approved tool, general research and drafting | Nothing specific |
| Anonymized or hypothetical facts | Approved tools, issue-spotting and research | Anything reidentifiable from the surrounding detail |
| Client confidential information | Enterprise-tier approved tools only, per matter | Consumer tiers, personal accounts, unapproved products |
| Privileged or sealed material | Only tools cleared specifically for it | Everything else, including approved general tools |
5. Human review requirements
Tiered by consequence, because a rule requiring attorney review of every output is a rule nobody follows. Court filings, client advice, and anything sent to an opposing party get full review. Citations, statutory references, and deadlines get verified against the primary source in every tier without exception. Internal summaries get spot checks and an AI-assisted label.
The citation rule earns its exception-free status. Courts in multiple jurisdictions have sanctioned lawyers for filings containing citations that did not exist, and it remains the most reliably damaging AI failure in practice.
6. Client disclosure
State when disclosure is required rather than leaving it to individual judgment. Rule 1.4 requires reasonable communication about the means used to pursue the client's objectives, and disclosure is most clearly indicated where confidential information is entered into a tool, where outside counsel guidelines address technology, or where AI materially shapes billed work product. Institutional clients increasingly address this in their guidelines, and those terms control over your policy.
Rule 1.5 belongs here too. A firm may not bill a client for hours the tool did not take. It is the most concrete obligation in Opinion 512 and the one most often left out of secondhand summaries.
7. Incident response
The section firms omit and then need. It should answer four questions in advance: who is notified and within what period when confidential information reaches an unapproved tool; who assesses whether a disclosure has occurred; what is preserved for the record; and what triggers client notification. Write it while nobody is panicking.
8. Review schedule and owner
A named person, annual review at minimum, plus a standing rule that no new tool touches client data until it is on the approved list. The standing rule does more work than the calendar, because it forces evaluation at the moment of adoption rather than eleven months later.
Three mistakes that make a policy unenforceable
- It bans a tool people already depend on, with no alternative. Use goes underground, which is strictly worse than governed use, because now you also cannot see it. Approve a compliant substitute in the same document.
- It requires review of everything. A universal rule is treated as advisory within a month. Tier it so the mandatory tier is small enough to actually hold.
- Nobody owns it. A policy assigned to a committee is assigned to no one. The test: can one identifiable person tell you, without checking, which tools are currently approved for client data?
Before you write section two. Inventory what the firm is already using. Most firms find tools in active use on client matters that no one approved, which changes the drafting problem from prevention to migration. An hour of asking beats a month of drafting against an imagined baseline.
What the policy asks of your vendors
Section two is only as good as the vendor review behind it, and most reviews fail on the same two questions: whether one client's data can reach another, and who holds the encryption keys. Both should have concrete answers.
For reference, ours: each firm's integration credentials are sealed under a data key belonging to that firm alone, held in a dedicated table that denies all access by default and is reachable through exactly one service path. The key that wraps those keys is derived through a separate derivation step, so holding one firm's encrypted material does not assist in reaching another's. Integrations are configured centrally by administrators rather than by individual users, which keeps credentials out of accounts nobody is tracking.
The full evaluation checklist is in how law firms can implement AI safely. For where a policy sits in the broader operating model, see what makes a firm AI-native.
Frequently asked questions
What should the policy include?
Scope, approved tools with review dates, prohibited tools with reasoning, task-level restrictions by data sensitivity, tiered human review, client disclosure guidance, incident response, and a review schedule with a named owner.
Does Opinion 512 require a written policy?
Not in those terms. It recommends firms consider adopting policies. Rules 5.1 and 5.3 supervision duties are what make a written policy the practical answer.
Who should own it?
A named managerial lawyer with authority to approve and remove tools, supported by technology staff. Not a committee.
Should the firm tell clients it uses AI?
The policy should specify when. Disclosure is most clearly indicated where confidential information is entered, where outside counsel guidelines address it, or where AI materially shapes billed work product.
How often should it be reviewed?
Annually at minimum, plus on any new tool, material change in vendor terms, or new guidance from the firm's jurisdiction.
This article is general information about legal technology governance. It is not legal advice, not an ethics opinion, and not a policy template for adoption without review. Firms should consult their own counsel and their state bar's guidance, which may differ from the ABA Model Rules.