ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Writing a Generative AI Policy for Your Law Firm: An Outline

A section-by-section outline for a law firm generative AI policy, drawing on the ABA's July 2024 Formal Opinion 512 and practical administrator decisions.

3 min readBy Counsel Cyber Team

Your attorneys are almost certainly already using generative AI, whether or not the firm has approved it. Some use a free chatbot on a personal phone to tidy an email. Others paste a paragraph of a draft agreement into a public tool to simplify it. A written policy is the quickest way to bring that use into the open and set boundaries that protect clients.

This post offers an outline you can adapt. It is not a finished policy and not legal advice. Your managing partners and, where appropriate, your professional liability carrier and state bar guidance should shape the final version.

Start with what the ABA has said

In July 2024, the ABA issued Formal Opinion 512 on generative AI tools. It discusses how several existing Model Rules apply, including competence (Rule 1.1), confidentiality (Rule 1.6), communication with clients (Rule 1.4), supervision (Rules 5.1 and 5.3), candor to the tribunal, and reasonable fees. The opinion does not forbid AI use. It stresses that lawyers need a reasonable understanding of the tools, must protect client information, and remain responsible for the work product. Confirm with your state bar whether it has issued its own guidance.

Policy outline

1. Purpose and scope

State why the policy exists and who it covers: attorneys, paralegals, staff, contractors, and anyone using firm data. Specify that it covers generative AI features embedded in other software, not just standalone chatbots.

2. Approved tools

List the tools the firm has reviewed and approved, and the accounts to use. Make clear that personal or free accounts are not approved for client information. If no tool is approved yet, say so and explain the process for requesting one.

3. Data classification rules

Spell out what may and may not be entered into AI tools. A simple three-tier approach works for many firms:

  • Never enter: privileged communications, client-identifying details, health information, financial account data, and anything under a protective order or confidentiality agreement, unless the tool has been specifically approved for that data.
  • Allowed in approved tools only: internal drafts and research questions that have been de-identified.
  • Allowed anywhere: general public information.

4. Vendor review criteria

Before approving a tool, ask the vendor in writing:

  1. Is our input used to train models, and can we opt out contractually?
  2. Where is data stored, and for how long?
  3. Who at the vendor can access our prompts and outputs?
  4. What security attestations does the vendor hold?
  5. How are prompts and outputs deleted on request or at contract end?

5. Verification and supervision

Require attorney review of all AI-assisted work product. Cite-checking is non-negotiable: generated citations must be confirmed in a trusted legal research source before they appear in any filing. Remind supervising attorneys that Rules 5.1 and 5.3 concern oversight of lawyers and nonlawyers, and that the same habits of oversight logically extend to AI-assisted work.

6. Client communication and billing

Decide when the firm will disclose AI use to clients, and check whether engagement letters or outside counsel guidelines address it. Some clients prohibit it outright. Set a billing approach that reflects actual attorney time rather than time saved by automation, and confirm with your state bar how fees should be handled.

7. Training

Require a short orientation before anyone uses an approved tool, with refreshers as the tools change. Cover prompt hygiene, verification, and what to do if sensitive data is entered by mistake.

8. Incident reporting

Tell people to report accidental disclosures immediately without penalty. Define who evaluates the incident and how the firm decides whether client notification is warranted.

9. Review cycle

AI products change quickly. Commit to reviewing the policy every six months, or sooner when a vendor changes its terms.

Practical tips for rollout

  • Interview a few attorneys first to learn what they are already doing. You will likely find legitimate uses worth supporting.
  • Make the approved path easy. If the approved tool is clumsy, people will drift back to consumer apps.
  • Keep the policy to two or three pages. A policy nobody reads protects nobody.
  • Have every attorney and staff member acknowledge it in writing.

Where we can help

Counsel Cyber helps law firms evaluate AI tools, configure them so that they respect existing permissions, and draft policies like this one. If you would like a review of your current AI exposure before putting a policy in front of your partners, we are happy to start there.