A law firm AI use policy should do four things: name the tools lawyers are allowed to use, state exactly what may never be entered into them, require verification of every AI output before it leaves the firm, and put a named person in charge of enforcing it. Everything else is detail. The policy exists because ABA Model Rules 5.1 and 5.3 make supervising lawyers responsible for how AI is used across the firm, and a written policy is the record that proves you supervised.
You do not need a twenty-page document. A tight one-to-three page policy that people actually read beats a binder no one opens. This guide walks through each section, what to write, and the decisions you have to make before you circulate it. It sits alongside our broader AI in Legal Practice library.
Related: AI in Legal Practice ยท Can Lawyers Use ChatGPT? ยท AI & Client Confidentiality ยท Bar Rules on AI ยท AI Data Security ยท Practice-Area AI
Why a written policy, and why now
The alternative to a policy is not "no AI" โ it is shadow AI. Your associates and staff are already pasting text into consumer ChatGPT, Claude, and Gemini on personal logins, without training, retention controls, or any record of what was shared. That is the worst configuration a firm can be in: all of the confidentiality risk, none of the supervision. A policy converts uncontrolled personal use into governed firm use.
The regulatory pressure is concrete. ABA Formal Opinion 512 (July 2024) reads the supervision rules to cover AI tools, and Canadian law societies โ including the Law Society of Ontario and the Law Society of British Columbia โ direct firms to have policies and training before confidential use. Malpractice insurers on both sides of the border now ask about AI governance on renewal applications. A written policy is the answer to every one of those questioners.
Section 1 โ Approved tools and account tiers
List the specific tools lawyers may use and the tier required for each type of work. Do not write "AI tools" โ name them. The distinction that matters is not brand but data terms:
- Consumer tiers (free ChatGPT, free Gemini): permitted only for non-client work โ learning, drafting text that contains no client information, internal templates.
- Business/enterprise tiers (ChatGPT Team or Enterprise, Google Workspace Gemini, Microsoft Copilot with enterprise data protection): the minimum tier for anything touching a live matter, because they contractually commit not to train on inputs and let administrators configure retention.
- Grounded legal research tools (Westlaw CoCounsel, Lexis+ AI, vLex Vincent): the only permitted source of candidate legal authority โ and even then output is verified before it is cited.
State plainly that any tool not on the list requires sign-off from the AI supervisor before use on client matters. New tools appear monthly; a closed list with an approval path keeps the firm from drifting onto whatever a vendor demoed last week.
Section 2 โ The confidentiality red line
This is the section people will actually reference, so make it unmissable. Under Model Rule 1.6 and FLSC Model Code Rule 3.3-1, the firm must prevent unauthorized disclosure of information relating to a representation. Translate that into a bright line: no client-identifying information, privileged material, or case facts go into any consumer-tier tool, and "anonymized" facts that could be re-identified from context count as identifying.
Address client consent directly. ABA Op. 512 says inputting representation information into a self-learning tool can require the client's informed consent, and engagement-letter boilerplate is not enough for consumer tools. Decide the firm's default โ many firms add an AI clause to the engagement letter and require specific consent for anything beyond enterprise tools โ and write it down. The full analysis lives in our guide to client confidentiality and AI tools.
Add the rule that every prompt is a record. What a lawyer types can be retained by the vendor, produced in vendor litigation, or exposed in a breach โ so the policy should treat prompts like documents and centralize AI use on firm-managed accounts where administrators can see and control it.
Section 3 โ Mandatory verification
State that AI output is a draft, never authority, and that a responsible lawyer verifies it before it is filed, sent, or relied upon. Spell out the checks so "verify" is not left to interpretation:
- Every case is pulled by citation and party name in Westlaw, Lexis, or CanLII โ if it is not in a real database, it does not exist.
- Every quotation is confirmed against the reporter text at the pinpoint given.
- Every stated holding is confirmed by reading enough of the case, then run through KeyCite, Shepard's, or CanLII noteup to confirm it is still good law.
- Every statute and deadline is confirmed against the official current consolidation and the rules of court.
Require a short certification in the file โ "authorities verified in [database] on [date] by [initials]" โ as a condition of filing, the same way a second signature gates a trust disbursement. This exists because the sanctions cases turn on verification failures, not on AI use; the failure mode covered in AI hallucinations in legal research.
Section 4 โ Supervision and the named owner
Name a specific partner or senior lawyer as the firm's AI supervisor. Rules 5.1 and 5.3 make supervision a person's job, not a document's. That person maintains the approved-tool list, fields approval requests, runs training, spot-checks AI-assisted work product quarterly, and tracks the regulator's evolving guidance. State that supervising lawyers remain responsible for the work of anyone โ associate, paralegal, or AI tool โ under their direction. Where the firm uses grounded research tools, the policy should route new lawyers through the applicable bar and law society rules during onboarding.
Section 5 โ Billing and court disclosure
Two rules that catch firms off guard. On billing: under Model Rule 1.5, if AI turns a six-hour draft into forty minutes, the firm bills the forty minutes plus verification time, not the six hours โ and AI subscription costs pass to clients only as disclosed, actual disbursements. Consider whether AI-compressed tasks should move to flat fees that price value rather than hours.
On disclosure: a growing set of US federal judges' standing orders and Canadian practice directions โ the Federal Court of Canada, Manitoba's Court of King's Bench, and Alberta's courts among them โ require certification or disclosure when generative AI contributed to a filing. The policy should require lawyers to check each court's standing orders before filing and log AI-assisted filings where disclosure applies.
Rolling it out
Circulate the policy, then train to it โ a policy no one is trained on is a liability, not a shield. Run a short session covering the confidentiality red line, the verification protocol, and a live demonstration of a tool hallucinating a case, which does more to change behavior than any memo. Review the policy at least annually; this area moves fast enough that last year's safe harbor can be this year's footnote. Firms that treat AI as a supervised skill, not as cheating, get honest disclosure of how it is being used โ which is the only way to manage the risk at all. For a firm-wide plan covering adoption and client-facing systems, book a strategy call with LexScale.ai.
Frequently Asked Questions
Grow your AI in Legal Practice practice with AI
LexScale.ai builds AI search visibility, websites, and intake systems for ai in legal practice firms across North America. Book a free strategy call to see what would move the needle for your practice.
Book a Free Strategy Call →