How to Write a Law Firm AI Usage Policy

How to Write a Law Firm AI Usage Policy
Gökçen Beyazoğlu

Gökçen Beyazoğlu LL.B.

Chief Product Officer · Attornaid

Short answer: A law firm AI usage policy should settle six things in writing: which tasks it may and may not be used for, when client data must be anonymised, the obligation to verify output and record that verification, an approved tool list, the rule on disclosing use to clients, and who owns the policy and how often it is reviewed. Without a policy, accountability stays scattered across individual lawyers.

AI tools usually enter a firm through individual use rather than a policy decision. One lawyer starts using an assistant on a personal account, it works, and the practice spreads. The problem is that at no point in that spread does anyone record who did what with which data. The purpose of a policy is not to restrict use but to make it visible.

1. Scope of use

This is the most concrete part of the policy. The line is drawn by two properties of the task: whether the output can be verified and how expensive an error is.

TaskUseRationale
Document and matter summarisationPermittedOutput can be checked against the source
First draftsPermittedThe draft will be reviewed anyway; errors are cheap
Search across large volumesPermittedThe located passage is opened and confirmed
Translation for comprehensionPermittedExcludes translations requiring legal validity
Case law and legislative researchPermitted with verificationCannot be used without reading the full text
Deadline and amount calculationsPermitted with verificationConfirmation from a second source required
Final legal opinionProhibitedNot a verifiable output; the lawyer is accountable
Litigation strategyProhibitedRests on information not in the file
Commitments to clientsProhibitedTiming, outcome or amount cannot rest on AI output

Sample clause: "AI tools may be used only for task types marked permitted or conditional in the attached table. Use for any task type not listed requires written approval from firm management."

2. Client data and anonymisation

A lawyer's duty of confidentiality cannot be transferred to a tool vendor. The policy must define which data may go to which tool under what conditions.

  • No data leaves the approved tool list. Uploading client data to tools used on personal accounts should be prohibited.
  • Define the anonymisation threshold. Write down when names, identifiers, matter numbers, addresses and party titles must be masked.
  • Check cross-border processing. If the tool processes data abroad, a documented transfer basis is required.
  • Require a model-training clause. The tool's contract must state explicitly that uploaded files will not be used for training.

Sample clause: "Client matter data may be uploaded only to tools on the approved list whose contracts expressly exclude use for model training. In all other cases data is anonymised before upload."

3. Verification and its record

This is the clause most often breached and the one with the most expensive consequences. AI systems can link to a real decision and assert something it does not say, so it is the accuracy of the citation that must be verified, not its presence.

  • No case citation enters any document without its full text having been read.
  • Deadline and amount calculations are confirmed from a second source.
  • Who verified, and when, is recorded.
  • Content that cannot be verified is removed, however supportive it appears.

Sample clause: "Every case citation in a document produced with AI assistance is read in full from the official source before the document is filed, and the verifier and date are noted in the matter record. A document containing an unverified citation may not be submitted for signature."

4. Approved tool list

The policy should carry an annex naming the tools that may be used, kept up to date. Define the minimum checks for adding a tool to that list.

CheckRequired
Processing locationWritten statement
Cross-border transfer basisDocumented mechanism
Model trainingProhibition clause in contract
Sub-processorsList plus change notification
Source attributionClickable citations in output
AuditPast queries viewable

5. Disclosure to clients

Whether AI use is disclosed to clients should be assessed alongside professional rules and contractual commitments. The policy should take a position rather than leave it open.

  • Whether use is mentioned in the engagement letter or an information notice.
  • What happens if a client objects to its use.
  • How to comply where corporate clients have their own policies.

6. Ownership and review

  • Policy owner: firm management or a designated partner.
  • Review frequency: at least every six months, and immediately on a change in regulation or professional rules.
  • Training: every new lawyer and staff member confirms in writing that they have read the policy.
  • Breach: how use contrary to the policy is handled.

Drafting checklist

  • Are permitted, conditional and prohibited task types listed in a table?
  • Are the fields to be anonymised enumerated?
  • Is the approved tool list prepared as an annex?
  • Is the processing location and training clause documented for each tool?
  • Is it defined where the verification record is kept?
  • Is there a clear rule on disclosure to clients?
  • Are the policy owner and review frequency stated?
  • Is there a flow for new joiners to confirm they have read it?

Frequently asked questions

Why does a law firm need an AI usage policy?

AI tools usually enter a firm through individual use rather than a policy decision, and the practice spreads without anyone recording who used what with which data. The purpose of a policy is not to restrict use but to make it visible, so that accountability does not stay scattered across individual lawyers.

What should the policy cover as a minimum?

Six areas: which tasks AI may and may not be used for, when client data must be anonymised, the obligation to verify output and record that verification, an approved tool list, the rule on disclosing use to clients, and who owns the policy and how often it is reviewed.

Which tasks should be prohibited?

Those whose output cannot be verified or whose errors are expensive: final legal opinions, litigation strategy decisions, and commitments to clients on timing, outcome or amount. Case law research and deadline calculations are not prohibited but conditional, requiring verification.

Can client data be uploaded to an AI tool?

Only to tools on the approved list whose contracts expressly exclude use for model training. In all other cases the data should be anonymised before upload. A lawyer's duty of confidentiality cannot be transferred to a tool vendor; the responsibility stays with the firm.

What should the policy say about verifying citations?

That every citation is read in full from the official source before the document is filed, that the verifier and date are recorded, and that a document containing an unverified citation may not be submitted for signature. The presence of a citation is not enough: a system can link to a real decision and assert something it does not say.

How often should the policy be updated?

At least every six months, and immediately on a change in regulation or professional rules. A policy owner should be designated and there should be a flow for every new lawyer and staff member to confirm in writing that they have read it. A policy with no owner does not get applied in practice.