ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Writing an AI Acceptable Use Policy for Your Law Firm

Staff are already using generative AI tools. Here is an outline for a practical AI acceptable use policy that reflects confidentiality and supervision duties.

3 min readBy Counsel Cyber Team

If your firm has no AI policy, it still has AI use. Associates draft with chatbots, paralegals summarize documents with browser extensions, and marketing staff try image tools. Some of this is harmless. Some of it may send confidential client information to a service the firm never evaluated.

ABA Formal Opinion 512, issued in July 2024, addressed lawyers' use of generative AI and discussed duties of competence, confidentiality, communication, supervision and reasonable fees. It is a useful framework for building a policy. This post gives an outline you can adapt. It is not legal advice, and you should confirm your state bar's guidance.

Start with the principles

A good policy opens with a short statement of purpose, such as: the firm permits the use of approved AI tools to improve work quality and efficiency, while protecting client confidentiality and meeting professional obligations. A lawyer remains responsible for all work product, regardless of whether AI helped create it.

Core sections to include

1. Scope

Define which tools the policy covers: standalone chatbots, AI features inside existing software, transcription tools, browser extensions and any tool that processes firm information.

2. Approved tools list

Maintain a list of vetted tools, with the approved use case and any restrictions. Anything not on the list requires approval before use. Make the request process quick, or people will bypass it.

3. Confidentiality rules

This is the heart of the policy. Address:

  • What information may never be entered into a tool that has not been approved: client names, matter details, privileged communications, personal data
  • Whether the approved tool's terms prevent your inputs from being used to train models, and whether it retains your data
  • Rules for anonymizing information where appropriate
  • Whether client consent or notice is needed for particular uses. Opinion 512 discusses informed consent in some circumstances, so discuss this with your ethics counsel.

4. Verification and review

Outputs can be wrong or fabricated, including citations that do not exist. The policy should require that:

  1. A lawyer independently verify every legal authority and factual assertion
  2. A qualified person review all AI-assisted work product before it leaves the firm
  3. Staff not rely on AI for legal conclusions without supervision

Courts in several instances have sanctioned lawyers for filing briefs with fictitious AI-generated citations. Court-specific rules on AI disclosure also exist in some jurisdictions, so check local requirements.

5. Supervision and training

Rules 5.1 and 5.3 concern supervision of lawyers and nonlawyers. Require training before anyone uses approved tools, and make clear that supervisors are accountable for their team's use.

6. Billing

Opinion 512 touches on billing. In general, charge for actual time spent, and consider how efficiency gains are communicated to clients. Include a rule on how AI-assisted work is recorded on time entries.

7. Client communication

State when and how the firm will tell clients about AI use, and include any client-imposed restrictions. Some outside counsel guidelines now prohibit or limit AI use.

8. Security and vendor review

Before approving a tool, evaluate: where data is processed and stored, encryption, access controls, retention, whether the vendor has security attestations, and what happens to your data if you leave.

9. Incident reporting

Tell staff to report immediately if they enter confidential information into an unapproved tool. A no-blame culture for prompt reporting helps contain problems.

10. Review cycle

Technology moves quickly. Schedule review at least twice a year, and update the approved list as terms and products change.

Implementation tips

  • Keep the policy to two or three pages in plain language
  • Pair it with a 30-minute training session including real examples
  • Require signed acknowledgment
  • Use technical controls where possible, such as blocking unapproved tools on firm devices

Support from Counsel Cyber

We help firms select and configure sanctioned AI tools and draft policies that fit their practice. If you would like a starting template and a review of the tools staff already use, get in touch.