Ask most managing partners whether their firm uses generative AI and the answer is "not officially." Ask the staff and you will often hear something different: a paralegal pasting a paragraph into a public chatbot to tighten the wording, an associate using a free browser extension to summarize a deposition. The tools arrived before the policy did.
The practical response is not a blanket ban, which tends to push use out of sight. It is a short, maintained list of sanctioned tools, with clear rules about what can go into each one. This post walks through how to build that list.
Why a list works better than a ban
A ban relies on every person understanding why it exists and agreeing to follow it. A sanctioned list gives people an easy, approved path. When the firm provides a tool that is reasonably safe, the temptation to use a personal account drops.
ABA Formal Opinion 512, issued in July 2024, addresses lawyers' use of generative AI and touches on competence, confidentiality, communication with clients, supervision and fees. It does not hand firms a vendor checklist, but it makes clear that lawyers need to understand the tools they use and protect client information. A defined list is one way to show that your firm has thought about it. Confirm with your state bar for any local guidance.
Step 1: Inventory what is already in use
Before approving anything, find out what staff are actually doing.
- Run a short, non-punitive survey asking which AI tools people use and for what tasks.
- Ask your IT provider to review web traffic and installed browser extensions for AI services.
- Check which AI features are already switched on inside software you license, such as your email, document, practice-management and research platforms.
Promise amnesty for honest answers. You want the real picture.
Step 2: Sort tools into three tiers
A simple structure keeps the list usable.
- Approved for client data. Tools reviewed by the firm, covered by a business agreement, with settings configured by IT.
- Approved for non-client work only. Tools acceptable for marketing copy, generic research or scheduling, but never for confidential material.
- Not approved. Free consumer tools and unreviewed extensions.
Most firms will start with only a handful of tools in the first tier. That is fine.
Step 3: Review each candidate against the same questions
Use one set of questions for every tool so the decisions are consistent.
- Does the vendor use our inputs to train its models? Can that be turned off by contract?
- Where is data stored, and how long is it retained?
- Does the product support single sign-on and multi-factor authentication?
- Can we control who has access and see an audit log?
- Does the vendor offer a signed agreement that addresses confidentiality?
- What happens to our data if we cancel?
Write down the answers. A one-page record per tool is plenty, and it is useful later when a client's security questionnaire asks how you govern AI.
Step 4: Set rules that match the tiers
The list is only half the work. Staff also need to know the rules of use.
- Never enter client names, matter details or privileged facts into a tool outside the first tier.
- Treat all output as a draft from an unsupervised junior. A lawyer must review it before it goes anywhere.
- Do not use personal accounts for firm work.
- Report mistakes and accidental disclosures quickly, without blame, so the firm can respond.
Rule 5.3 on supervising nonlawyer assistance and Rule 5.1 on supervisory responsibility are commonly raised in this context, because partners are generally expected to have measures in place that give reasonable assurance staff follow the rules.
Step 5: Enforce with technology, not just memos
Policies that depend on memory fail. Ask IT to help with:
- Blocking unapproved AI sites and browser extensions on firm devices.
- Restricting which accounts can sign in to approved tools.
- Applying data loss prevention rules to catch obvious client identifiers leaving through unapproved channels.
- Reviewing licensing for built-in AI features and turning off those you have not evaluated.
Step 6: Review the list on a schedule
AI products change quickly. Features appear in existing software, vendors change their data terms, and new tools show up every month. Assign an owner, such as the firm administrator or a technology committee, and revisit the list quarterly. Add a simple request process so staff can propose a tool and get a decision within a reasonable time.
Where to start this week
If this feels large, do three things: survey your staff, list the AI features already inside your current software, and draft a one-page rule set. You can refine from there.
Counsel Cyber helps law firms review their AI exposure, configure approved tools safely and write policies staff can follow. If you would like a second set of eyes on your list, we are glad to do a short review with your firm.