A generative AI policy does not need to be a thirty-page document. The best ones are short enough that people read them and specific enough that people know what to do. This outline gives you a structure you can adapt, along with the reasoning behind each section.
ABA Formal Opinion 512, issued in July 2024, discusses lawyers' use of generative AI tools in connection with competence, confidentiality, communication, supervision, candor to tribunals and fees. A written policy is a practical way to put those themes into daily practice. Have your partners, and if appropriate outside counsel, review the final draft, and check your state bar for local guidance.
1. Purpose and scope
Open with two or three sentences on why the policy exists: to allow useful tools while protecting client confidentiality and the quality of legal work. State who it covers: attorneys, staff, contractors and anyone using firm systems or handling firm data. State which tools it covers, including standalone chatbots, AI features inside existing software, browser extensions and note-taking bots.
2. Definitions
Keep it plain. Define generative AI, "approved tool," "confidential information" and "firm data." Avoid jargon that makes staff tune out.
3. Approved and prohibited tools
Refer to a maintained list of sanctioned tools, kept by the technology owner. State that anything not on the list is not approved for firm work. Explain how to request a review of a new tool, and who decides.
4. Confidential information rules
This is the heart of the policy. Specify, in concrete terms:
- What may never be entered into a non-approved tool, such as client names, matter facts, privileged communications and personal data.
- What may be entered into approved tools, and any limits that remain.
- Whether and how anonymization is acceptable. Be careful here: removing a name does not always make facts unidentifiable.
- Rules for uploading documents, audio and images.
5. Competence and verification
Require human review of all AI output. Set expectations that lawyers verify every citation, quotation and factual statement before relying on it or filing it. Courts have sanctioned lawyers for submitting AI-generated citations that did not exist, so make clear that responsibility remains with the signing attorney. Remind staff that AI can sound confident while being wrong.
6. Supervision
Rules 5.1 and 5.3 address supervisory responsibilities for lawyers and nonlawyer assistance. Describe who supervises AI use by junior lawyers and staff and how work product is reviewed. State that a person cannot delegate judgment to a tool.
7. Client communication and consent
Decide, with your partners, how the firm will address AI in engagement letters and client conversations. Consider whether certain clients, such as those with outside counsel guidelines, prohibit or restrict AI. Require staff to check client instructions before using AI on a matter.
8. Billing
State how AI-assisted work will be billed. Opinion 512 touches on fees, noting that lawyers should not bill for time they did not spend. Decide how efficiency gains are reflected and how the firm treats the cost of AI tools.
9. Court rules and disclosure
Some courts and judges have issued standing orders about AI use or certification. Assign someone to check applicable requirements before filing, and require lawyers to comply.
10. Security requirements
Specify that approved tools must be accessed with firm-managed accounts, with MFA, on firm-managed devices. Prohibit personal accounts for firm work. Require that browser extensions and meeting bots be reviewed by IT before use.
11. Incident reporting
Tell people what to do if they paste something they should not have. Provide a contact, ask for prompt reporting and say that good-faith reports will not result in punishment. Early reports allow the firm to contact the vendor, request deletion where possible and assess notification duties.
12. Training and acknowledgment
Require training on hire and annually. Collect a signed acknowledgment. Keep the records.
13. Review and ownership
Name a policy owner and commit to reviewing the policy at least twice a year. This area changes rapidly, so build in updates.
Drafting tips
- Use examples. "Do not paste a client's deposition transcript into a public chatbot" beats abstract language.
- Keep it to a few pages, with a one-page quick-reference summary.
- Align it with your information security policy, confidentiality agreements and employee handbook.
- Make sure the technical controls match the rules. If you ban something, block it where possible.
Getting help
Counsel Cyber helps firms write AI policies and configure the controls behind them. If you want a starting template or a review of a draft, contact us and we will work through it with you.