ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

A Generative AI Use Policy Outline for Your Law Firm

A practical outline for a firm AI policy: approved tools, banned inputs, review requirements and client disclosure, framed around ABA Formal Opinion 512.

3 min readBy Counsel Cyber Team

Most law firms already have AI in the building, whether or not anyone approved it. Associates paste text into chatbots, assistants appear inside Word and Outlook, and vendors quietly add "AI features" to tools you have used for years. A written policy is the fastest way to turn that scattered, invisible use into something the firm can manage.

The ABA addressed this in Formal Opinion 512, issued in July 2024, which discusses how the Model Rules apply to lawyers' use of generative AI, including competence, confidentiality, communication, supervision and fees. It is not a template, but it gives you a useful skeleton for a policy. Confirm your own state bar's position as well, since guidance varies.

What a Good Policy Covers

Keep it to two or three pages. A policy nobody reads protects nobody.

1. Scope and definitions

State which tools the policy covers: standalone chatbots, AI features embedded in productivity software, transcription and note-taking bots, and AI built into practice-management or research platforms. Say that it applies to attorneys, paralegals, staff and contractors.

2. Approved tools list

Name the tools the firm has vetted and licensed. Anything not on the list is not approved for client work. Assign one person, usually the administrator or managing partner, to own the list and update it.

3. Data rules

This is the core of the policy. Spell out what may never be entered into an unapproved tool:

  • Client names, matter details and any information protected by Rule 1.6
  • Privileged communications and work product
  • Personal data such as Social Security numbers, medical records and financial account details
  • Documents under protective orders or subject to confidentiality agreements

For approved tools, define what is allowed. Many firms permit general drafting help on non-confidential text but require a business-grade account with contractual data protections for anything touching client information.

4. Verification and review

Generative tools can produce confident, wrong output, including fabricated citations. Require that a lawyer verify every citation, quotation and factual claim before it leaves the firm, and that a human remains responsible for the final work product. Tie this to Rule 1.1 and its Comment 8 on keeping up with the benefits and risks of technology.

5. Supervision

Rules 5.1 and 5.3 address the duty to supervise lawyers and nonlawyer assistance. Your policy should say that supervising attorneys are responsible for how their teams use AI, and that junior staff should ask before trying a new tool.

6. Client communication and billing

Decide when the firm will tell clients about AI use. Engagement letters are a natural place for a short disclosure. Also decide how AI-assisted time is billed so that fees stay reasonable and explainable.

Rolling It Out

A policy only works with a few supporting steps:

  1. Collect a quick, no-blame inventory of what people are already using.
  2. Pick one or two approved tools and make them easy to access.
  3. Train everyone for thirty minutes with real examples from your practice areas.
  4. Have each person sign an acknowledgment.
  5. Review the policy every six months, because the tools change quickly.

Common Mistakes

  • Banning everything. Blanket bans push use underground. Offer a safe, approved route instead.
  • Ignoring embedded AI. Features switched on inside tools you already own can send data to new places. Check settings and vendor terms.
  • No technical enforcement. A policy without controls relies on goodwill. Web filtering and data loss prevention rules can block unapproved tools on firm devices.
  • Forgetting personal devices. If staff use phones for work, the policy needs to address them.

Where Counsel Cyber Fits

Counsel Cyber helps firms evaluate AI tools, configure the settings that keep client data protected, and turn a policy into controls you can actually enforce. If you want a second set of eyes on a draft, we are glad to review it with you. This post is general information, not legal advice, so confirm your obligations with your state bar.