ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Outline for a Law Firm AI Policy Built Around ABA Opinion 512

A practical outline for a law firm AI policy covering approved tools, confidentiality, verification, client consent and training, grounded in ABA Opinion 512.

3 min readBy Counsel Cyber Team

Whether or not your firm has approved any AI tools, your people are almost certainly using some. Associates ask a chatbot to summarize a deposition, assistants use a browser plug-in to draft emails, and someone is pasting a contract into a free tool to check it. A written policy turns that scattered, invisible use into something you can manage.

ABA Formal Opinion 512, issued in July 2024, addresses lawyers' use of generative AI. It discusses competence, confidentiality, communication with clients, supervision, candor to tribunals, and reasonable fees. Read it, and confirm with your state bar whether additional guidance applies where you practice. A good policy is how a firm puts those themes into daily practice.

Principles before rules

Short policies get followed. Start with a few principles everyone can remember:

  • Client confidences stay protected, regardless of the tool.
  • A lawyer is responsible for everything that goes out under their name.
  • Only approved tools touch client information.
  • When in doubt, ask before you paste.

Policy outline

1. Purpose and scope

State that the policy covers all attorneys, staff, contractors, and temporary workers, and all generative AI tools, including those built into products the firm already uses, such as word processors, email, and research platforms.

2. Approved and prohibited tools

Keep a short list of approved tools with the permitted uses of each. Everything else is unapproved by default. Explain that consumer versions of a tool and enterprise versions often have very different terms on data retention and training, so the firm approves specific products and plans, not brand names in general.

3. Confidentiality

Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. Before approving a tool, the firm should review:

  • Whether inputs are stored, and for how long
  • Whether inputs are used to train models
  • Who at the vendor can access them
  • Where data is processed
  • Whether the vendor will sign a data-protection agreement

Define what may never be entered into an unapproved tool: client names, case facts, privileged communications, personal identifiers, and financial data.

4. Verification of output

Generative tools can produce confident, fluent, and wrong answers, including invented citations. The policy should require that a lawyer personally verify every citation, quotation, and factual claim before it appears in work product, and that no AI output goes to a client or court without attorney review.

5. Client communication and consent

Opinion 512 discusses when lawyers may need to tell clients about AI use. Some clients and some engagement letters restrict it entirely. The policy should say who decides when disclosure or consent is needed and require a check of client outside-counsel guidelines before using AI on that client's matters.

6. Billing

Describe how AI-assisted work is billed. The firm should decide in advance how it will treat time saved and tool costs, consistent with fee rules and client agreements.

7. Supervision

Under Model Rules 5.1 and 5.3, partners and managers must make reasonable efforts to ensure that lawyers and nonlawyer assistants follow the rules. The policy should assign an owner, such as a technology partner or administrator, for approving tools and answering questions.

8. Training and review

Require training before anyone gets access to an approved tool, and review the policy at least twice a year, because the tools change quickly.

9. Incident reporting

If someone pastes confidential material into an unapproved tool, they should report it immediately and without fear of punishment. Early reports let the firm assess exposure. Silence makes it worse.

Rolling it out

  1. Survey staff anonymously about the AI tools they already use.
  2. Draft the policy with input from a partner, the administrator, and IT.
  3. Approve a small set of tools and block the obvious risky ones where you can.
  4. Hold a 30-minute walkthrough with real examples.
  5. Collect written acknowledgments.

Where we fit

Counsel Cyber helps firms vet AI tools, configure access controls, and draft policies that match how attorneys actually work. If you want a review of the tools already in use at your firm, we can start there. This post is general information and not legal advice.