How to Write a Law Firm AI Policy Your Team Will Follow

A short, specific AI policy beats a long, vague one. Here is what to include and how to roll it out.

· 5 min read · eLaw Platform

Two tables in a glass-walled conference room inside a high-ceilinged building
Photo by Crew on Unsplash

If your firm has no written rules on generative AI, people are still using it. Associates try chatbots on research questions, staff paste emails into writing assistants and partners experiment with drafting. A law firm AI policy turns that scattered experimentation into consistent practice, so the firm gets the benefits while managing confidentiality, accuracy and supervision risks.

This guide sets out the sections a practical policy needs, sample wording ideas and a rollout plan. It is aimed at managing partners, practice group leads and operations staff at small and mid-sized firms.

This article is general information, not legal advice. Tailor any policy to your jurisdiction's professional conduct rules and your clients' requirements.

Principles before rules

A policy works better when people understand why it exists. Open with three or four principles, for example:

  • Lawyers remain responsible for all work product, however it was produced.
  • Client information is used only in tools the firm has approved for it.
  • AI output is checked before anyone relies on it.
  • We are honest with clients and courts about how we work.

These map to existing professional duties, which ABA Formal Opinion 512 connects to AI use: competence, confidentiality, communication, supervision, candour and fees.

Sections to include

1. Scope

Say who the policy covers (lawyers, paralegals, staff, contractors) and what counts as AI for this purpose. A broad definition, such as "any tool that generates text, summaries, analysis or images from prompts," avoids arguments about whether a feature inside existing software counts.

2. Approved tools

Keep a list, maintained by a named person, of tools approved for:

  • Client information: tools whose data handling terms have been reviewed and contracted.
  • Non-client use only: tools allowed for general tasks with no client or confidential data.
  • Prohibited: tools or account types not to be used for firm work, such as personal consumer accounts.

Make the list easy to find and explain how to request a new tool.

3. Tiered use rules

Tier Examples Requirement
General Rewording public text, brainstorming, learning a topic Approved tool; no client data
Client work, internal Summaries, chronologies, first drafts Approved-for-client tool; reviewer checks against sources
Client-facing or filed Advice, research conclusions, court filings All authority independently verified; supervising lawyer signs off

4. Verification

State the minimum checks. For research: every authority confirmed to exist, read and checked for current validity. For drafting: every substantive term compared with instructions. For summaries: spot-checked against the source.

5. Confidentiality

Restate what may not be entered into any tool, such as material under protective order, and when anonymisation is required. Refer to client outside counsel guidelines, which may impose stricter rules.

6. Client communication and disclosure

Explain when clients are told about AI use, for instance through engagement letter language, and when specific consent is required. Name who decides in unclear cases.

7. Court filings

Some courts require certification or disclosure of AI use in filings. Require lawyers to check local rules and standing orders for each court before filing.

8. Billing

Set out how AI-assisted work is billed. Common approaches include billing actual time spent, flat fees for defined tasks, or agreed technology charges. Make clear that time spent learning general tools is not billed to clients.

9. Training and supervision

Require short training before using approved tools on client work, and describe how supervisors review AI-assisted output by juniors and staff.

10. Incidents and review

Explain how to report a mistake, such as client data entered into an unapproved tool, and commit to reviewing the policy at a set interval, given how quickly tools change.

Keep it short and specific

A two-to-four page policy that people read beats a twenty-page document nobody opens. Put detailed procedures, like the tool approval checklist, in appendices. Use examples: "Do not paste a client's draft agreement into a personal chatbot account" is clearer than "exercise appropriate caution with client data."

Rolling it out

  1. Draft with input from at least one partner, one associate and one staff member, so the rules fit real work.
  2. Brief everyone in a short meeting, focused on the approved list and the verification rules.
  3. Ask for current use. An amnesty-style survey of tools already in use tells you where the risk is.
  4. Name an owner who updates the tool list and answers questions.
  5. Review in six months and adjust based on what people actually ran into.

Choosing tools to approve

When deciding which tools make the approved-for-client list, look at data use, retention, isolation and whether outputs cite sources. eLaw is one option built for law firms and legal teams, with document analysis, legal research and purpose-built agents, cited answers and firm-isolated data. Review its terms as you would any vendor's.

Get a first version out

  1. Write the four principles and circulate them this week.
  2. Build the approved-tools list from what people already use.
  3. Draft the tiered use table and verification rules.
  4. Set the review date before you publish.

FAQ

Does every law firm need an AI policy?

Even firms that do not formally adopt AI tools benefit from one, because staff may use them anyway. A short policy clarifies what is allowed, protects client information and shows that the firm is supervising technology use as professional rules expect. Small firms can keep it to a page or two.

Should a firm AI policy ban generative AI entirely?

Some firms start there, but blanket bans can be hard to enforce and may push use into unapproved personal tools. Many firms instead approve specific tools for specific tasks with clear verification rules. The right approach depends on the firm's practice, clients and risk tolerance.

How often should an AI policy be reviewed?

Given how quickly tools and guidance change, many firms review at least every six to twelve months, and sooner when a major vendor changes its terms, a relevant bar opinion is issued or a court adopts new filing rules. Assign a named owner so reviews actually happen.

What should happen if someone breaches the AI policy?

The policy should explain how to report incidents promptly, such as client data entered into an unapproved tool, so the firm can assess any confidentiality or notification obligations. Encouraging early reporting without automatic blame tends to surface problems faster than a purely punitive approach.

← All articles