ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Generative AI Policy Outline for Small and Mid-Size Law Firms

Staff are already using AI tools. A clear written policy sets approved tools, data rules and review steps so the firm can use AI without creating ethics risk.

3 min readBy Counsel Cyber Team

Whether or not the firm has formally approved any AI tools, it is likely that someone in the office has already pasted text into one. A written policy lets you set expectations before a problem occurs, and it shows clients and carriers that the firm is managing the issue.

This outline is a starting point for firm leadership and counsel to adapt. It is not legal advice.

What the ABA Has Said

In July 2024 the ABA issued Formal Opinion 512 on generative artificial intelligence tools. It addresses how existing duties apply, including competence (Model Rule 1.1), confidentiality (Rule 1.6), communication with clients (Rule 1.4), supervision (Rules 5.1 and 5.3), and fees. The opinion emphasizes that lawyers should understand the capabilities and limits of the tools they use, protect confidential information, and independently verify output. Read it, and check your state bar's guidance, since rules and opinions differ across jurisdictions.

Policy Outline

1. Purpose and scope

State who the policy covers: attorneys, staff, contractors and interns. Cover all generative AI, including chat assistants, drafting tools, transcription services, and AI features built into other software.

2. Approved tools

List the tools the firm has reviewed and approved, and say that anything not on the list requires approval before use. Tie approval to a review of:

  • How the vendor handles and stores inputs
  • Whether inputs are used to train models
  • Security controls such as MFA, encryption and access logs
  • Contract terms on confidentiality and data deletion
  • Where data is processed

Consumer versions of tools often have different terms than business versions, so name the specific plan or configuration approved.

3. Data rules

This is the heart of the policy. Define categories:

  • Never permitted: client names or identifying details, privileged communications, or sensitive personal data entered into unapproved tools
  • Permitted with approved tools only: work product and matter information, subject to the vendor review above
  • Always permitted: public information and general non-client tasks such as drafting a firm newsletter

Be explicit. Staff follow clear examples better than abstract principles.

4. Verification and review

Require that every AI-assisted output be reviewed by a responsible attorney before use. Legal citations, quotations and factual claims must be independently verified against primary sources. Courts have sanctioned lawyers who filed citations generated by AI that turned out to be fabricated, so verification is not optional. Some courts and judges also have disclosure or certification requirements, so check local rules.

5. Client communication and consent

Decide when the firm will tell clients about its use of AI and when it will seek consent. Opinion 512 discusses this; engagement letters and outside counsel guidelines may also contain requirements. Some clients prohibit AI use on their matters, so track those restrictions.

6. Billing

Address how time saved by AI will be reflected in billing, consistent with the rules on reasonable fees and your engagement letters.

7. Supervision and training

Name who is responsible for overseeing AI use. Require training before use, and refresh it as tools change.

8. Incident reporting

If someone enters confidential information into an unapproved tool, they should report it immediately without fear of punishment. A quick report allows the firm to assess and respond.

9. Review schedule

Revisit the policy at least twice a year. This field changes quickly.

Making It Stick

  • Share the policy in a short staff meeting, not just by email
  • Provide an approved tool so staff have a legitimate alternative to shadow use
  • Use IT controls to block or monitor unapproved tools where feasible
  • Keep a record of approvals and training

Common Mistakes

  • Banning AI outright and driving use underground
  • Approving a tool without reading its terms
  • Writing a policy but never training staff
  • Assuming the vendor's security claims cover your use

Where We Come In

Counsel Cyber helps law firms evaluate AI tools for security, configure approved options within Microsoft 365 and other platforms, and monitor for unsanctioned use. If you want help drafting or operationalizing a policy, we are glad to start with a short conversation.