Whether or not your firm has approved any AI tools, your people are almost certainly using some. Associates ask a chatbot to summarize a deposition, assistants use a browser plug-in to draft emails, and someone is pasting a contract into a free tool to check it. A written policy turns that scattered, invisible use into something you can manage.
ABA Formal Opinion 512, issued in July 2024, addresses lawyers' use of generative AI. It discusses competence, confidentiality, communication with clients, supervision, candor to tribunals, and reasonable fees. Read it, and confirm with your state bar whether additional guidance applies where you practice. A good policy is how a firm puts those themes into daily practice.
Principles before rules
Short policies get followed. Start with a few principles everyone can remember:
- Client confidences stay protected, regardless of the tool.
- A lawyer is responsible for everything that goes out under their name.
- Only approved tools touch client information.
- When in doubt, ask before you paste.
Policy outline
1. Purpose and scope
State that the policy covers all attorneys, staff, contractors, and temporary workers, and all generative AI tools, including those built into products the firm already uses, such as word processors, email, and research platforms.
2. Approved and prohibited tools
Keep a short list of approved tools with the permitted uses of each. Everything else is unapproved by default. Explain that consumer versions of a tool and enterprise versions often have very different terms on data retention and training, so the firm approves specific products and plans, not brand names in general.
3. Confidentiality
Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. Before approving a tool, the firm should review:
- Whether inputs are stored, and for how long
- Whether inputs are used to train models
- Who at the vendor can access them
- Where data is processed
- Whether the vendor will sign a data-protection agreement
Define what may never be entered into an unapproved tool: client names, case facts, privileged communications, personal identifiers, and financial data.
4. Verification of output
Generative tools can produce confident, fluent, and wrong answers, including invented citations. The policy should require that a lawyer personally verify every citation, quotation, and factual claim before it appears in work product, and that no AI output goes to a client or court without attorney review.
5. Client communication and consent
Opinion 512 discusses when lawyers may need to tell clients about AI use. Some clients and some engagement letters restrict it entirely. The policy should say who decides when disclosure or consent is needed and require a check of client outside-counsel guidelines before using AI on that client's matters.
6. Billing
Describe how AI-assisted work is billed. The firm should decide in advance how it will treat time saved and tool costs, consistent with fee rules and client agreements.
7. Supervision
Under Model Rules 5.1 and 5.3, partners and managers must make reasonable efforts to ensure that lawyers and nonlawyer assistants follow the rules. The policy should assign an owner, such as a technology partner or administrator, for approving tools and answering questions.
8. Training and review
Require training before anyone gets access to an approved tool, and review the policy at least twice a year, because the tools change quickly.
9. Incident reporting
If someone pastes confidential material into an unapproved tool, they should report it immediately and without fear of punishment. Early reports let the firm assess exposure. Silence makes it worse.
Rolling it out
- Survey staff anonymously about the AI tools they already use.
- Draft the policy with input from a partner, the administrator, and IT.
- Approve a small set of tools and block the obvious risky ones where you can.
- Hold a 30-minute walkthrough with real examples.
- Collect written acknowledgments.
Where we fit
Counsel Cyber helps firms vet AI tools, configure access controls, and draft policies that match how attorneys actually work. If you want a review of the tools already in use at your firm, we can start there. This post is general information and not legal advice.