How to Write a Law Firm AI Usage Policy

Short answer: A law firm AI usage policy should settle six things in writing: which tasks it may and may not be used for, when client data must be anonymised, the obligation to verify output and record that verification, an approved tool list, the rule on disclosing use to clients, and who owns the policy and how often it is reviewed. Without a policy, accountability stays scattered across individual lawyers.
AI tools usually enter a firm through individual use rather than a policy decision. One lawyer starts using an assistant on a personal account, it works, and the practice spreads. The problem is that at no point in that spread does anyone record who did what with which data. The purpose of a policy is not to restrict use but to make it visible.
1. Scope of use
This is the most concrete part of the policy. The line is drawn by two properties of the task: whether the output can be verified and how expensive an error is.
| Task | Use | Rationale |
|---|---|---|
| Document and matter summarisation | Permitted | Output can be checked against the source |
| First drafts | Permitted | The draft will be reviewed anyway; errors are cheap |
| Search across large volumes | Permitted | The located passage is opened and confirmed |
| Translation for comprehension | Permitted | Excludes translations requiring legal validity |
| Case law and legislative research | Permitted with verification | Cannot be used without reading the full text |
| Deadline and amount calculations | Permitted with verification | Confirmation from a second source required |
| Final legal opinion | Prohibited | Not a verifiable output; the lawyer is accountable |
| Litigation strategy | Prohibited | Rests on information not in the file |
| Commitments to clients | Prohibited | Timing, outcome or amount cannot rest on AI output |
Sample clause: "AI tools may be used only for task types marked permitted or conditional in the attached table. Use for any task type not listed requires written approval from firm management."
2. Client data and anonymisation
A lawyer's duty of confidentiality cannot be transferred to a tool vendor. The policy must define which data may go to which tool under what conditions.
- No data leaves the approved tool list. Uploading client data to tools used on personal accounts should be prohibited.
- Define the anonymisation threshold. Write down when names, identifiers, matter numbers, addresses and party titles must be masked.
- Check cross-border processing. If the tool processes data abroad, a documented transfer basis is required.
- Require a model-training clause. The tool's contract must state explicitly that uploaded files will not be used for training.
Sample clause: "Client matter data may be uploaded only to tools on the approved list whose contracts expressly exclude use for model training. In all other cases data is anonymised before upload."
3. Verification and its record
This is the clause most often breached and the one with the most expensive consequences. AI systems can link to a real decision and assert something it does not say, so it is the accuracy of the citation that must be verified, not its presence.
- No case citation enters any document without its full text having been read.
- Deadline and amount calculations are confirmed from a second source.
- Who verified, and when, is recorded.
- Content that cannot be verified is removed, however supportive it appears.
Sample clause: "Every case citation in a document produced with AI assistance is read in full from the official source before the document is filed, and the verifier and date are noted in the matter record. A document containing an unverified citation may not be submitted for signature."
4. Approved tool list
The policy should carry an annex naming the tools that may be used, kept up to date. Define the minimum checks for adding a tool to that list.
| Check | Required |
|---|---|
| Processing location | Written statement |
| Cross-border transfer basis | Documented mechanism |
| Model training | Prohibition clause in contract |
| Sub-processors | List plus change notification |
| Source attribution | Clickable citations in output |
| Audit | Past queries viewable |
5. Disclosure to clients
Whether AI use is disclosed to clients should be assessed alongside professional rules and contractual commitments. The policy should take a position rather than leave it open.
- Whether use is mentioned in the engagement letter or an information notice.
- What happens if a client objects to its use.
- How to comply where corporate clients have their own policies.
6. Ownership and review
- Policy owner: firm management or a designated partner.
- Review frequency: at least every six months, and immediately on a change in regulation or professional rules.
- Training: every new lawyer and staff member confirms in writing that they have read the policy.
- Breach: how use contrary to the policy is handled.
Drafting checklist
- Are permitted, conditional and prohibited task types listed in a table?
- Are the fields to be anonymised enumerated?
- Is the approved tool list prepared as an annex?
- Is the processing location and training clause documented for each tool?
- Is it defined where the verification record is kept?
- Is there a clear rule on disclosure to clients?
- Are the policy owner and review frequency stated?
- Is there a flow for new joiners to confirm they have read it?
Frequently asked questions
Why does a law firm need an AI usage policy?
AI tools usually enter a firm through individual use rather than a policy decision, and the practice spreads without anyone recording who used what with which data. The purpose of a policy is not to restrict use but to make it visible, so that accountability does not stay scattered across individual lawyers.
What should the policy cover as a minimum?
Six areas: which tasks AI may and may not be used for, when client data must be anonymised, the obligation to verify output and record that verification, an approved tool list, the rule on disclosing use to clients, and who owns the policy and how often it is reviewed.
Which tasks should be prohibited?
Those whose output cannot be verified or whose errors are expensive: final legal opinions, litigation strategy decisions, and commitments to clients on timing, outcome or amount. Case law research and deadline calculations are not prohibited but conditional, requiring verification.
Can client data be uploaded to an AI tool?
Only to tools on the approved list whose contracts expressly exclude use for model training. In all other cases the data should be anonymised before upload. A lawyer's duty of confidentiality cannot be transferred to a tool vendor; the responsibility stays with the firm.
What should the policy say about verifying citations?
That every citation is read in full from the official source before the document is filed, that the verifier and date are recorded, and that a document containing an unverified citation may not be submitted for signature. The presence of a citation is not enough: a system can link to a real decision and assert something it does not say.
How often should the policy be updated?
At least every six months, and immediately on a change in regulation or professional rules. A policy owner should be designated and there should be a flow for every new lawyer and staff member to confirm in writing that they have read it. A policy with no owner does not get applied in practice.



