Lawyers and staff are already experimenting with generative AI, whether or not the firm has approved it. Without a written policy, individuals decide for themselves what client information goes into which tool. A short, clear policy is the fastest way to bring those choices into the open.
In July 2024 the ABA issued Formal Opinion 512 on generative AI, which discusses competence, confidentiality, client communication, supervision and fees. It does not prescribe a product or a specific policy, but it provides a useful frame. Your state bar may have issued its own guidance, so check what applies to you. This post is general information, not legal advice.
Section 1: purpose and scope
Say in two or three sentences why the policy exists and who it covers: attorneys, staff, contractors and anyone handling firm data. Cover both standalone chatbots and AI features built into tools you already use, such as writing assistants in word processors or email.
Section 2: approved tools
Maintain a list of tools the firm has reviewed and approved, and state that anything not on the list may not be used with client information. A basic vendor review should ask:
- Are our inputs used to train the vendor's models?
- Where is data stored, how long is it retained, and can we delete it?
- What does the contract say about confidentiality and breach notice?
- Can we require MFA, control access and view an audit trail?
- Does the vendor use subprocessors, and who are they?
Free consumer tools often fail these questions, which is why a business-grade option matters.
Section 3: what data may go where
This is the section people read most. Be specific:
- Never enter client names, privileged communications, personal information, health information or material covered by a protective order into a non-approved tool.
- For approved tools, describe permitted uses, such as summarizing public documents or drafting internal templates.
- State when client consent or notice is required. Opinion 512 discusses when informed consent may be needed, so ask ethics counsel where your firm should land.
Section 4: verification duty
Anything produced by AI and used in work product must be reviewed by a lawyer who takes responsibility for it.
- Verify every citation against a primary source.
- Check quotations, dates and facts against the record.
- Do not rely on AI output for legal analysis without independent judgment.
- Remember that AI can produce confident but fabricated content.
Courts have sanctioned lawyers for submitting unverified AI-generated citations, so this section protects the firm.
Section 5: client communication, disclosure and fees
Decide how the firm discusses AI use with clients, including engagement-letter language. Check court rules and judges' standing orders regarding disclosure. Billing should be honest: time saved through AI should be reflected in what clients pay, consistent with the fee rules in your jurisdiction.
Section 6: supervision and ownership
Name a policy owner and a person who approves new tools. Partners remain responsible for supervising associates and staff under Model Rules 5.1 and 5.3. Make it easy to ask questions, so people do not hide uncertainty.
Section 7: incident reporting
If someone enters client data into an unapproved tool, they should report it immediately, with no punishment for prompt self-reporting. Quick reports let the firm request deletion, assess exposure and consider notification duties. ABA Formal Opinion 483 addresses lawyers' obligations after a data breach.
Section 8: training and review
Train everyone when the policy launches, then at least yearly. Use real examples of acceptable and unacceptable prompts. Review the policy every six months at first, because tools and guidance change quickly.
Tips for adoption
- Keep it to two or three pages.
- Provide an approved tool so people are not tempted to use personal accounts.
- Offer short demonstrations of good use, so people see the benefits as well as the limits.
- Treat the policy as a living document and log changes.
Common mistakes
- A blanket ban that nobody follows
- No approved alternative
- No mention of AI features embedded in existing software
- Failing to update the policy after new tools or guidance appear
Next step
Counsel Cyber helps law firms evaluate AI vendors, configure approved tools and draft policies they can actually enforce. If you would like a starting template reviewed against your firm's real workflows, we are happy to help.