Whether or not the firm has formally approved any AI tools, it is likely that someone in the office has already pasted text into one. A written policy lets you set expectations before a problem occurs, and it shows clients and carriers that the firm is managing the issue.
This outline is a starting point for firm leadership and counsel to adapt. It is not legal advice.
What the ABA Has Said
In July 2024 the ABA issued Formal Opinion 512 on generative artificial intelligence tools. It addresses how existing duties apply, including competence (Model Rule 1.1), confidentiality (Rule 1.6), communication with clients (Rule 1.4), supervision (Rules 5.1 and 5.3), and fees. The opinion emphasizes that lawyers should understand the capabilities and limits of the tools they use, protect confidential information, and independently verify output. Read it, and check your state bar's guidance, since rules and opinions differ across jurisdictions.
Policy Outline
1. Purpose and scope
State who the policy covers: attorneys, staff, contractors and interns. Cover all generative AI, including chat assistants, drafting tools, transcription services, and AI features built into other software.
2. Approved tools
List the tools the firm has reviewed and approved, and say that anything not on the list requires approval before use. Tie approval to a review of:
- How the vendor handles and stores inputs
- Whether inputs are used to train models
- Security controls such as MFA, encryption and access logs
- Contract terms on confidentiality and data deletion
- Where data is processed
Consumer versions of tools often have different terms than business versions, so name the specific plan or configuration approved.
3. Data rules
This is the heart of the policy. Define categories:
- Never permitted: client names or identifying details, privileged communications, or sensitive personal data entered into unapproved tools
- Permitted with approved tools only: work product and matter information, subject to the vendor review above
- Always permitted: public information and general non-client tasks such as drafting a firm newsletter
Be explicit. Staff follow clear examples better than abstract principles.
4. Verification and review
Require that every AI-assisted output be reviewed by a responsible attorney before use. Legal citations, quotations and factual claims must be independently verified against primary sources. Courts have sanctioned lawyers who filed citations generated by AI that turned out to be fabricated, so verification is not optional. Some courts and judges also have disclosure or certification requirements, so check local rules.
5. Client communication and consent
Decide when the firm will tell clients about its use of AI and when it will seek consent. Opinion 512 discusses this; engagement letters and outside counsel guidelines may also contain requirements. Some clients prohibit AI use on their matters, so track those restrictions.
6. Billing
Address how time saved by AI will be reflected in billing, consistent with the rules on reasonable fees and your engagement letters.
7. Supervision and training
Name who is responsible for overseeing AI use. Require training before use, and refresh it as tools change.
8. Incident reporting
If someone enters confidential information into an unapproved tool, they should report it immediately without fear of punishment. A quick report allows the firm to assess and respond.
9. Review schedule
Revisit the policy at least twice a year. This field changes quickly.
Making It Stick
- Share the policy in a short staff meeting, not just by email
- Provide an approved tool so staff have a legitimate alternative to shadow use
- Use IT controls to block or monitor unapproved tools where feasible
- Keep a record of approvals and training
Common Mistakes
- Banning AI outright and driving use underground
- Approving a tool without reading its terms
- Writing a policy but never training staff
- Assuming the vendor's security claims cover your use
Where We Come In
Counsel Cyber helps law firms evaluate AI tools for security, configure approved options within Microsoft 365 and other platforms, and monitor for unsanctioned use. If you want help drafting or operationalizing a policy, we are glad to start with a short conversation.