Lawyers and staff are already using generative AI, whether or not the firm has approved it. Some use it to summarize documents, others to draft emails or brainstorm arguments. A written policy does not need to be long, but it needs to exist, because the alternative is each person making their own judgment about confidential client information. This post outlines what a practical policy covers.
This is not legal advice. In July 2024 the ABA issued Formal Opinion 512 on generative AI tools, which discusses competence, confidentiality, communication, supervision, candor to the tribunal and fees. Check your state bar for any guidance specific to your jurisdiction.
Section 1: Purpose and scope
State who the policy applies to: attorneys, paralegals, staff, contractors and interns. Define what counts as an AI tool: chatbots, writing assistants, transcription tools, AI features inside existing software such as email or document platforms, and browser extensions. Many firms forget that AI is now built into products they already own.
Section 2: Approved and prohibited tools
Keep a short, maintained list of approved tools and state that anything not on the list is not allowed for client work. For each approved tool, record:
- What it may be used for
- Which plan or license is approved, since business tiers often have different data terms than free consumer versions
- Who owns the decision to approve or remove it
Before approving a tool, review its terms: whether inputs are retained, whether they are used to train models, where data is stored, who can access it, and how it handles deletion. ABA Opinion 512 notes that lawyers should understand how a tool uses information, and that informed consent may be needed in some situations before putting confidential information into a self-learning tool.
Section 3: Data rules
This is the heart of the policy. Spell out what can and cannot be entered into AI tools.
- Never enter client-identifying or confidential information into unapproved tools.
- For approved tools, define categories: for example, public information is acceptable, client confidential information only in tools approved for it, and certain highly sensitive categories prohibited altogether.
- Remove names and identifying details when feasible.
- Do not upload documents covered by protective orders or sealing without explicit review.
Section 4: Verification and human review
AI tools can produce confident but wrong output, including citations to cases that do not exist. Courts in several matters have sanctioned lawyers for submitting fabricated citations. The policy should require that:
- A lawyer reviews every AI-assisted work product before it leaves the firm.
- All citations and quotations are checked against primary sources.
- Output is never treated as a final legal conclusion.
Include any local court rules on AI disclosure or certification that apply to your practice.
Section 5: Supervision
Model Rules 5.1 and 5.3 address supervising lawyers and nonlawyers. Assign responsibility: who approves tools, who answers questions, who monitors use. Make clear that supervising attorneys remain responsible for work produced with AI assistance by those they supervise.
Section 6: Client communication and billing
Decide when you will tell clients about AI use. Review engagement letters and any outside counsel guidelines, since some clients restrict or require disclosure of AI use. On billing, ABA Opinion 512 discusses fees, noting that lawyers should bill for actual time and should not charge for time saved by technology as though it were worked. Talk with your partners about how your firm handles this.
Section 7: Training
A policy nobody understands will not be followed. Cover the following in onboarding and at least annually:
- What the approved tools are and how to use them well
- Examples of what not to enter
- How to verify output
- Whom to ask when unsure
Section 8: Incident reporting and review
Tell staff to report accidental disclosures, such as pasting client data into the wrong tool, right away and without fear of blame. Review the policy at least twice a year, since tools and rules change quickly.
Practical tips
- Start with a short pilot using one or two approved tools and a small group.
- Turn off features that retain chat history where the vendor offers that option.
- Use your IT provider to block unapproved AI sites on managed devices where appropriate.
- Pair the policy with a Microsoft 365 or practice-management review, since embedded AI features inherit your existing permissions. If your permissions are messy, AI search can surface documents people should not see.
Getting started
You can draft a first version in an afternoon using the sections above, then refine it as people use it. Counsel Cyber helps law firms select and configure approved AI tools, set data boundaries, and train staff. If you want a second opinion on your draft policy, we are happy to review it with you.