Lawyers are already using generative AI, whether the firm has approved it or not. Some are drafting emails with a free chatbot, others are summarizing depositions in a browser tab. A written policy does not stop that on its own, but it gives people clear lines and gives the firm something to point to when clients and insurers ask how AI is handled.
The goal is a policy short enough to be read and specific enough to be followed. Here is an outline you can adapt.
Why a Policy, and Why Now
In July 2024 the ABA issued Formal Opinion 512 on generative AI. It discusses competence, confidentiality, communication with clients, supervision, candor to the tribunal and fees. You do not need to memorize it, but your policy should speak to each of those themes. Confirm with your state bar whether it has issued its own guidance, since states vary.
Section 1: Scope and Definitions
State plainly what the policy covers: chatbots, AI features built into Word, Outlook or research platforms, transcription tools, and AI note-takers on video calls. Many firms miss that last one, which can record privileged conversations and store them with a third party.
Section 2: Approved and Prohibited Tools
Make a list, and keep it short.
- Approved tools: named products the firm has vetted, with business-grade terms.
- Conditionally approved: tools allowed only for non-confidential work, such as brainstorming a seminar outline.
- Prohibited: consumer-grade tools for any client information, and any tool not on the list until it has been reviewed.
Assign one person to maintain the list and a simple way for staff to request a review.
Section 3: Confidentiality Rules
This is the section that matters most. ABA Model Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. For AI, that translates to questions you can ask before approving a tool:
- Does the vendor use our inputs to train its models?
- Where is data stored, and for how long?
- Who at the vendor can see our prompts?
- Can we delete data on request, and can we get that in writing?
- What happens if the vendor is breached?
Then state the working rule: no client-identifying or privileged information goes into any tool that has not been approved for it.
Section 4: Verification and Candor
AI tools can produce fluent text that cites cases or facts that do not exist. Courts have sanctioned lawyers over fabricated citations. Your policy should say:
- Every citation, quotation and factual assertion from an AI tool must be independently verified against a primary source.
- The signing attorney remains responsible for the work product.
- Check local rules and individual judges' standing orders, since some require disclosure or certification of AI use in filings.
Section 5: Supervision
Model Rules 5.1 and 5.3 deal with supervising lawyers and nonlawyer assistance. Make clear that partners are responsible for how their teams use AI, and that junior lawyers should say when AI contributed to a draft so reviewers know where to look harder.
Section 6: Client Communication and Billing
- Decide when you will tell clients about AI use. Some engagement letters now include a short clause.
- Respect client instructions. Some corporate clients prohibit AI use on their matters, and outside counsel guidelines may say so.
- Do not bill for time you did not spend. Think through how AI-assisted efficiency is reflected in fees.
Section 7: Training and Enforcement
A policy no one has heard of is not a policy.
- Walk everyone through it in a live session with real examples.
- Add it to onboarding.
- State what happens when it is violated, and make a safe path for self-reporting mistakes.
- Review it twice a year, since the tools change quickly.
Keep It Short
Two pages beats ten. Put the rules at the top, the definitions at the bottom, and give people a name to ask when they are unsure.
Counsel Cyber helps firms evaluate AI tools for security and set up sanctioned, controlled use. If you want a second opinion on a draft policy or a particular vendor, we can help you work through it.