Some of your lawyers are already using generative AI. They may be drafting emails, summarizing deposition transcripts, or checking a clause with a free chatbot on a personal account. If your firm has no written policy, those choices are being made one person at a time, with no consistent rules about what client information goes where.
A good AI policy does not need to be long. The firms that get compliance are the ones whose policy fits on two pages and answers the questions people actually have. Here is an outline you can adapt.
Start with the guidance that exists
In July 2024 the ABA issued Formal Opinion 512 on generative AI tools. It discusses competence (Model Rule 1.1), confidentiality (1.6), communication with clients (1.4), supervision (5.1 and 5.3), and reasonable fees. It does not tell you which product to buy, but it gives a useful frame: understand the tool, protect client information, verify output, and supervise use. Check with your state bar for any local guidance, since states have moved at different speeds.
Policy outline
1. Purpose and scope
State in a sentence or two why the policy exists and who it covers: attorneys, paralegals, staff, contractors, and anyone using firm data. Include AI features embedded in tools you already own, such as writing assistants in your email or document platform, not just standalone chatbots.
2. Approved tools
List the specific tools the firm has reviewed and approved, and say that anything not on the list is not allowed for client work. Approval should rest on a short vendor review:
- Does the vendor use your inputs to train its models?
- Where is data stored, and for how long?
- Does the contract address confidentiality and breach notification?
- Can you control who has access and see an audit trail?
- Is single sign-on and multifactor authentication supported?
Consumer accounts and free tiers usually fail these questions.
3. Data rules
This is the section people read most carefully, so be concrete. Define what may never be entered into a non-approved tool: client names, matter details, privileged communications, personal data, medical records, and anything covered by a protective order or NDA. For approved tools, define what is allowed, and whether client consent or notice is needed for certain uses. Opinion 512 discusses when informed consent may be needed, so ask your ethics counsel where your firm lands.
4. Verification duty
Every AI output used in work product must be reviewed by a lawyer who takes responsibility for it. Spell out the basics:
- Check every citation against a primary source
- Confirm quotes, dates and facts against the record
- Do not rely on AI for legal conclusions without independent analysis
Courts have sanctioned lawyers for filing unverified AI-generated citations, so this section protects both clients and lawyers.
5. Disclosure and billing
Decide how the firm handles client communication about AI use, court disclosure requirements, and billing. Time saved by AI should be reflected honestly in what clients are charged. Add a reminder to check each judge's standing orders.
6. Supervision and accountability
Partners remain responsible for the work of associates and staff. Name who owns the policy, who approves new tools, and who staff should ask when unsure. Make it easy to ask, because people hide questions in a punitive environment.
7. Incident reporting
If someone pastes client data into an unapproved tool, they should report it immediately with no fear of a lecture. A quick report lets you ask the vendor for deletion, assess exposure, and consider whether notice obligations apply. ABA Formal Opinion 483 covers lawyers' duties after a data breach.
8. Training and review
Run a short training when you roll out the policy and again at least annually. Use real examples of acceptable and unacceptable prompts. Review the policy every six months at first, since tools change faster than most firm documents.
Make it stick
A policy only works if the approved option is better than the workaround. If associates use personal chatbots because the firm provides nothing, a ban will not hold. Provide a sanctioned tool, show people how to use it well, and keep the rules readable.
Next steps
Counsel Cyber helps firms evaluate AI vendors, configure approved tools with sensible access controls, and draft policies like this one. If you want help turning this outline into a document for your firm, we can start with a short conversation about the tools your people already use. This post is general information, not legal advice.