ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Building a Sanctioned AI Toolkit Instead of Banning ChatGPT

Banning AI tools tends to push them underground. Here is how a law firm can approve a short list of tools, set clear rules and keep client data protected.

3 min readBy Counsel Cyber Team

Many firms respond to generative AI by announcing a ban. The memo goes out, partners nod, and within a month several lawyers and staff are quietly pasting text into whatever free tool they like. A ban feels safe, but it removes your visibility and your control at the same moment.

A more durable approach is to sanction a small set of tools, define what may and may not go into them, and train people. This post outlines how to do that without a large budget.

Why Prohibition Backfires

People adopt AI because it saves time on real work: summarizing, drafting first versions, organizing notes. If the firm provides no approved path, individuals choose their own, often consumer accounts with unclear terms on data retention and model training. That is the opposite of what the firm wants.

ABA Formal Opinion 512, released in July 2024, discusses a lawyer's duties of competence, confidentiality, communication, supervision and reasonable fees when using generative AI. It does not say lawyers must avoid the tools. It emphasizes understanding their capabilities and limits, protecting client information and verifying output.

Step 1: Find Out What Is Already in Use

Ask, without blame, which tools lawyers and staff have tried. Your IT provider may also be able to identify AI-related web traffic and browser extensions. You are looking for the real picture, not a list of violators.

Step 2: Evaluate a Short List of Tools

For each candidate tool, get written answers to these questions:

  • Is our data used to train the provider's models? Can that be turned off contractually?
  • Where is data stored, for how long, and can we delete it?
  • Does the tool support single sign-on and multi-factor authentication?
  • Can administrators see and control usage?
  • What are the provider's security attestations and breach notification terms?
  • Does it integrate with the document and email systems we already use, honoring existing permissions?

Business or enterprise tiers generally offer stronger commitments than free consumer accounts. Review the actual terms rather than the marketing page.

Step 3: Write a One-Page Policy

Keep it short enough that people will read it. Cover:

  1. Approved tools and how to request a new one.
  2. Data rules. What categories of information may never be entered, such as certain client confidences, health data or privileged strategy, and what may be entered with caution.
  3. Verification. All AI output must be checked by a lawyer before use, especially citations and facts. Courts have sanctioned lawyers for filing unverified AI-generated citations, so this is not theoretical.
  4. Client communication. When disclosure to a client or consent may be appropriate, consistent with engagement terms and your state bar's guidance.
  5. Billing. How time saved by AI is reflected in fees.
  6. Accountability. Who owns the policy and how violations are handled.

Step 4: Train and Repeat

A 30-minute session with real examples will do more than a long document. Show a good prompt, a risky prompt and an example of plausible but wrong output. Refresh the training as tools change.

Step 5: Set Up Technical Guardrails

  • Require sign-in through firm accounts for approved tools.
  • Use data loss prevention features in Microsoft 365 where available.
  • Block or restrict tools you have not approved on firm devices, with a simple exception process.
  • Review access logs periodically.

What to Watch Over Time

AI features are appearing inside tools you already own, including email, document and practice-management software. Each new feature is a new data flow. Ask vendors what is switched on by default and who can control it. Revisit your policy at least twice a year.

A Caution on Overconfidence

Even good tools make mistakes and can sound authoritative while doing so. Treat output as a draft from a capable but unreliable junior colleague. Confirm state-specific guidance from your bar, as it continues to develop.

Where Counsel Cyber Fits

Counsel Cyber helps law firms select, configure and govern AI tools, from vendor review to policy templates and staff training. If you would like help drafting your firm's sanctioned-use policy, we are happy to start with a short conversation.