Law Firms · Compliance

How to write an AI use policy for your firm.

Your staff are probably already using AI. The only question is whether they're doing it under a policy you wrote, or under no policy at all. A clear AI use policy is the difference between AI as a managed tool and AI as an unmanaged liability. Even a solo firm needs one.

By Ty McDuffey, J.D.  ·  June 2026  ·  8 min read

Most firms are skipping a step. They debate whether to "allow" AI while their people quietly use it to draft letters and summarize documents, with no written rules at all. That gap, unofficial use without an official policy, is where confidentiality problems and the occasional fabricated citation come from. The fix is not banning AI. It is writing down how your firm uses it. Here is what that policy needs and how to build one.

Why every firm needs one, even a solo

It is tempting to assume a written policy is overkill for a two-person shop. It is actually the opposite. At a small firm, there is no IT department quietly setting guardrails in the background, which means whatever your people decide to do with AI becomes the firm's de facto policy by default. A written policy does three concrete things: it protects client confidentiality, it gives your staff clear permission and clear limits so they are not guessing case by case, and it gives you something solid to point to if the bar, a client, or a court ever asks how your firm uses these tools. That third one alone is worth the afternoon it takes to write.

What ABA Opinion 512 expects of you

ABA Formal Opinion 512, issued July 29, 2024, is the profession's first formal ethics guidance on generative AI. It does not prohibit AI. Instead it frames the duties that come with using it: competence in the tools you choose, protection of confidential information under Model Rule 1.6, supervision of AI-assisted work product, candor to tribunals, reasonable fees and billing, and a duty to evaluate the AI vendors you rely on. A good policy is simply how you turn those duties into day-to-day practice. And remember that your own state's Rules of Professional Conduct sit on top of the ABA guidance and ultimately govern your obligations.

The components of a solid AI use policy

A workable policy does not need to be long, but it does need to cover these:

  • Permitted and prohibited uses. Spell out what AI may be used for (drafting, summarizing, brainstorming, research support) and what it must never be used for. Vagueness here is what gets firms in trouble.
  • Approved tools only. Name the specific tools the firm has vetted and configured. Staff do not get to drop client matters into whatever free app they found that week.
  • The confidentiality rule. Client information goes only into tools configured for zero data retention, under a written agreement. Casual consumer chatbots are off-limits for anything client-related, full stop.
  • Mandatory human review. A lawyer reviews and remains responsible for every AI-assisted output before it reaches a client or a court, and every citation gets independently verified. Always.
  • Disclosure. How and when the firm tells clients about its use of AI, consistent with your obligations and engagement terms.
  • Training. Everyone who touches AI is trained on the policy, not just emailed a link to it. A policy nobody has read is not a policy.
  • The "when in doubt, don't" rule. A clear default: if you are unsure whether a use is allowed, you stop and ask before you act.

A starter outline you can build from

If you are staring at a blank page, here is a skeleton to fill in:

  • 1. Purpose and scope — who and what the policy covers.
  • 2. Definitions — what "AI tools" means for your firm.
  • 3. Approved tools and configuration — including the zero-retention requirement.
  • 4. Permitted uses.
  • 5. Prohibited uses.
  • 6. Confidentiality and data handling.
  • 7. Human review and verification — the rule that nothing goes out unreviewed and no citation goes unverified.
  • 8. Client disclosure.
  • 9. Training and acknowledgment — staff sign that they have read and understood it.
  • 10. Review schedule — revisit it as tools and rules change.

One honest caveat: that is a skeleton, not a finished policy. The substance, what actually goes into each section, has to fit your specific practice areas, the tools you use, and the rules of your jurisdiction. A copied template that you never tailor is barely better than nothing.

Common mistakes

  • Copying a generic template off the internet and never adapting it to the firm.
  • Naming no specific approved tools, which quietly tells staff to use whatever they like.
  • Writing the policy and then never training anyone on it.
  • Leaving out the verification rule, which is exactly how invented cases end up in real filings.
  • Treating it as one-and-done instead of revisiting it as the technology and the rules keep moving.

Turning a policy into a real system

A policy on paper is the start, not the finish. The harder and more valuable part is making the safe way the easy way: configuring your approved tools for zero retention, getting the vendor terms in writing, and building the workflows so that following the policy is the path of least resistance instead of a hurdle. That operational side is the work we do with firms, paired with documentation you could hand to the bar tomorrow. One boundary worth stating plainly: we are an AI implementation vendor, not your firm's lawyer, and this article is informational, not legal advice. Your state's rules govern, and your attorneys stay responsible for every output.

For more on the confidentiality side of this, read Is AI safe for client data? And for how we build and run compliant systems end to end, see our compliant AI for law firms page.

Free, no pressure

Want help turning this into a real policy?

Book a short, free assessment. We'll talk through how your firm could use AI safely, build the documented system behind it, and keep it compliant. No obligation.

Or call / text 573-280-5774