ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Writing a Generative AI Acceptable Use Policy for Your Firm

A short AI policy gives attorneys and staff clear boundaries. Here is an outline covering approved tools, confidentiality, review duties and client disclosure.

3 min readBy Counsel Cyber Team

Whether or not your firm has approved any AI tools, your people are probably using some. Attorneys try chatbots to summarize a deposition, staff use writing assistants to polish emails and vendors add AI features to software you already pay for. A written acceptable use policy replaces guesswork with clear rules.

The ABA addressed this area in Formal Opinion 512 in July 2024. It discusses competence, confidentiality, communication with clients, supervision and fees when lawyers use generative AI. It is worth reading, and it is a sensible backbone for a policy. Your state bar may have issued its own guidance, so check it before finalizing.

Keep the policy short

A two-page document that people read beats a twenty-page one they ignore. Aim for plain language, concrete examples and a named contact for questions.

Section 1: Purpose and scope

State that the policy covers any generative AI tool, including chatbots, drafting assistants, transcription tools, research tools and AI features inside other software. Apply it to attorneys, staff and contractors.

Section 2: Approved and prohibited tools

Approved tools

List the tools the firm has vetted, who may use them and for which tasks. Vetting should cover where data is stored, whether inputs are used to train models, how long data is retained, what security certifications the vendor holds and whether a business agreement with confidentiality terms is in place. Consumer versions of tools often have different terms than business versions, so name the specific plan.

Everything else

Make the default clear: tools that are not on the approved list may not be used with client information. Provide a simple process to request a new tool, so people have an alternative to going around the rules.

Section 3: Confidentiality and data handling

Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, and the ABA opinion discusses informed consent before putting client information into a tool that could expose it. Your policy can set practical categories.

  • Never enter privileged or confidential client information, personal identifiers, health information or sealed material into an unapproved tool.
  • Permitted with approved tools only the data classes you have decided are acceptable.
  • Anonymize where possible, removing names and identifying details when a task allows it.

Section 4: Verification and accountability

Generative tools can produce confident but wrong output, including fabricated citations. Courts in a number of matters have sanctioned lawyers who filed unverified AI-generated citations. State plainly that:

  1. A licensed attorney is responsible for any work product, regardless of how it was drafted.
  2. Every citation and factual assertion must be checked against primary sources.
  3. AI output is a draft, not an authority.
  4. Staff using AI for work product must have the output reviewed by a supervising attorney, consistent with the supervision duties in Rules 5.1 and 5.3.

Section 5: Client communication and billing

Decide when the firm will tell clients it uses AI, and check your engagement letter language. The ABA opinion discusses disclosure and also notes that fees should reflect actual work, so a lawyer should not bill for time saved by a tool as though it had been spent manually. Ask your partners to settle how you handle this, and write it down.

Section 6: Transcription and meeting tools

Recording and transcription bots raise special questions about consent, privilege and storage. Require approval before any bot joins a client call, and address recording notice requirements, which vary by state.

Section 7: Training and reporting

Train everyone on the policy when it is adopted and when it changes. Tell people to report any accidental disclosure immediately, without blame, so the firm can contact the vendor and assess the exposure.

Section 8: Review

AI products change quickly. Review the policy at least twice a year, and whenever a vendor changes its terms or a new tool is proposed.

Common mistakes

  • Banning AI outright without offering an approved option, which pushes use out of sight.
  • Approving a tool without reading its data terms.
  • Writing a policy and never training anyone on it.

Getting started

Counsel Cyber helps law firms evaluate AI vendors, configure approved tools and draft policies in line with current bar guidance. If you would like a template tailored to your practice areas, ask us.