Skip to content
Insights

A law firm AI policy people will follow, with a template

Blanket bans fail because AI is already inside the tools the firm pays for. What a workable policy decides, in what order, and a template you can adapt in an afternoon.

The most common law firm AI policy is one sentence long: do not use it. It is also the least effective, for a reason the North Carolina Bar’s practice management center put well in January 2026. AI is embedded in the software lawyers already use every day. The research platform summarizes cases with it. The office suite drafts with it. A ban does not stop the use; it stops the reporting of the use, which is worse, because the firm now has the exposure and none of the visibility.

A policy that works starts from the opposite assumption: AI is in the building, and the job is to decide what it may touch, who checks its work, and what the client is told.

What the policy has to decide

Six decisions. Everything else in the document is explanation.

1. What is prohibited. A short list, and specific. Entering client information into a consumer AI account on a personal login. Filing anything containing an AI-generated citation that has not been resolved by a person. Using AI to make a decision the rules reserve to a lawyer.

2. What needs review. The middle category, and the one that does the work. Drafting from client material, legal research, summarizing a record: allowed, in approved tools, with a named review step before the output is relied on.

3. What is allowed by default. Internal drafting with no client material, formatting, first-pass summaries of public documents. Naming this category is what makes the policy credible; a policy with no green list reads as a ban with extra steps.

The North Carolina Bar’s recommended structure is exactly this three-colour system, red, yellow and green, and it is the right one because it maps to how people actually decide in the moment.

4. Whose systems client information may enter. This is the decision ABA Formal Opinion 512 places under the duty of confidentiality. The policy names the approved tools, states for each whether the vendor may train on firm content and where content is retained, and says who may add a tool to the list. Texas Opinion 705 reaches the same place: the lawyer has to understand the tool’s terms well enough to know whether confidentiality survives contact with it.

5. Who verifies output, and how. Opinion 512 treats this as competence. The policy should say that the person relying on an output is responsible for it, and for anything with authorities it should require the cite-check routine: resolve the citation, then confirm it supports the proposition. The sanctions cases all involve a lawyer who skipped that step, not a lawyer who used a tool.

6. What clients are told. Whether the engagement letter mentions AI use, in what terms, and whether any client may opt out. Opinion 512 says disclosure depends on the circumstances; the policy should say what the firm’s default is so that lawyers are not improvising it matter by matter.

Two things that keep it alive

A policy that is adopted and filed is a ban with better formatting. Two mechanisms keep it working.

A register. One page listing each approved tool, its tenancy decision, the date it was reviewed and who approved it. When someone asks “can I use X”, the answer is on the register or it is “not yet”. This is what the NIST generative AI profile means by governance functions that continue after deployment.

A place to record failures. When an output is wrong in a way that matters, the lawyer who caught it writes three lines: what was asked, what came back, what was wrong. Reviewed quarterly, that log is the best training material the firm will ever have, and it is what turns the yellow list into a set of specific instructions rather than a general warning.

Training is part of the policy, not a follow-up

The North Carolina piece pairs the document with mandatory education, and that is right for a practical reason: a policy people have not practised against is a policy people interpret. A half-day with a practice group, working on their own material against the firm’s own three lists, does more than any redraft. That is what AI training for lawyers on this site is for.

The template

Adapt it. Delete what does not apply. Keep it under two pages; nobody reads the third.


[Firm name] Policy on the use of artificial intelligence

1. Purpose. This policy governs the use of artificial intelligence tools, including generative AI, in the firm’s work. Its aims are to protect client confidentiality, to ensure that work relied on by clients or courts has been verified by a lawyer, and to make the firm’s use of these tools consistent and reviewable.

2. Scope. It applies to all partners, lawyers, staff and contractors, and to all tools with AI features, whether the firm licenses them or an individual does.

3. Approved tools. Only tools on the firm’s AI register may be used with client information. The register records, for each tool, whether the vendor may use firm content for training, where content is stored and retained, who approved it and when it was last reviewed. [Named role] maintains the register and decides additions.

4. Prohibited uses (red).

  • Entering client, matter or personal information into any tool not on the register, including personal accounts.
  • Relying on, filing or sending any authority, quotation or factual claim generated by an AI tool that a person has not verified against the source.
  • Using an AI tool to make a decision that the rules of professional conduct require a lawyer to make.
  • Representing AI-generated content as the personal work of a person where that would mislead.

5. Uses requiring review (yellow). The following are permitted in approved tools and must pass through the named review step before the output is relied on: drafting from client material; legal research; summarizing records, transcripts or discovery; client-facing communications.

6. Permitted by default (green). Internal drafting containing no client information; formatting and proofreading; summarizing public documents; learning and experimentation using non-client material.

7. Verification. The person relying on an AI output is responsible for it. For any output containing legal authorities, that person must resolve each citation and confirm it supports the proposition for which it is cited before the output leaves the firm. [Reference the firm’s cite-check procedure.]

8. Client communication. [Choose one.] The firm’s engagement letter discloses that AI tools may be used in the delivery of services under this policy. / The responsible lawyer decides whether to disclose AI use on a matter, having regard to the client’s instructions and the nature of the work. Clients may instruct that AI tools not be used on their matter, and that instruction is recorded on the file.

9. Failures. Any AI output that is materially wrong in a way that could have affected a client is recorded in the firm’s AI failure log by the person who found it. The log is reviewed [quarterly] by [named role] and the register and this policy are updated as needed.

10. Training. All lawyers and staff complete the firm’s AI training before using approved tools on client material, and annually thereafter.

11. Review. This policy is reviewed [every six months] and when a tool is added to or removed from the register.

Adopted [date]. Owner: [named role].


What this is not

It is not a security policy; the tenancy decisions in section 3 need the firm’s IT function, and the register should reference the vendor terms rather than paraphrase them. It is not legal advice; the professional rules that apply to your firm are your state’s, and someone qualified should read the draft against them. And it is not finished when it is adopted. It is finished when the failure log has entries in it and the policy has changed because of them.

Sources and methodology

Scope
Written for US firms, with the ethics authorities cited from the ABA, Texas and North Carolina. The professional rules that apply to you are your state's; the template is a starting structure, not legal advice, and a qualified person at the firm should review it against local rules before adoption.
How this was produced
Built from the author's work designing governance for AI systems in legal workflows and from the cited bar guidance. The traffic-light structure follows the North Carolina Bar Association's published recommendation; the control language follows the NIST generative AI profile. The template has not been adopted by a named firm and is offered as a draft.
  1. Beyond the Ban: Why Your Law Firm Needs a Realistic AI Policy in 2026North Carolina Bar Association, Center for Practice Management
  2. Formal Opinion 512: Generative Artificial Intelligence ToolsAmerican Bar Association, Standing Committee on Ethics and Professional Responsibility
  3. Opinion 705: Lawyers' use of generative artificial intelligenceProfessional Ethics Committee for the State Bar of Texas
  4. Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence ProfileNational Institute of Standards and Technology

Read the editorial standards, corrections policy and AI-use disclosure.