AI & IP
    Back to Insights

    AI Policies for Law Firms: What to Put in Place Before Your Team Uses Generative AI

    AILaw FirmsProfessional Responsibility

    Anthony Clemenza, Founding Partner

    Admitted in New York, 2009 · nearly twenty years in practice

    · Updated · 8 min read

    Share

    The question for law firms is no longer whether generative AI will be used in practice — associates are already using it. The question is whether it is being used under a policy the firm wrote, or one it is improvising.

    The Professional Responsibility Frame

    Bar guidance has coalesced around familiar duties applied to a new tool:

    • Competence includes understanding the capabilities and limits of the technology used to deliver legal services
    • Confidentiality governs what client information may be entered into which tools, under what terms
    • Supervision makes the firm responsible for how lawyers and staff use these tools
    • Candor puts verification of AI-assisted output squarely on the lawyer signing the filing

    Courts have sanctioned lawyers for filing briefs with fabricated citations. Those cases were not AI failures; they were verification failures.

    The Policy Core

    A workable firm policy usually answers six questions:

    1. Which tools are approved? Consumer chatbots and enterprise legal tools have very different confidentiality postures.
    2. What data may go in? Define categories — public information, anonymized facts, client-identifying information — and match each to approved tools.
    3. What uses are permitted? Research assistance, first drafts, summarization; and which uses are prohibited outright.
    4. What must be verified? Every citation, every factual assertion, every characterization of authority — by a human, before it leaves the firm.
    5. Who must know? Engagement letter language and, in some matters, court-required disclosures.
    6. Who owns the policy? A named partner or committee that reviews tools, handles exceptions, and updates the rules as the technology moves.

    Beyond the Policy Document

    The firms doing this well pair the policy with vendor diligence — data handling, training-use terms, retention — and with actual training, because the failure mode is rarely malice; it is a lawyer under deadline pressure using an unapproved tool because it was faster.

    The Opportunity Side

    Handled properly, this is not merely defensive. Firms that can tell clients precisely how they use AI — and how they protect client data while doing it — are answering a question that sophisticated clients have started asking in RFPs. A real governance program is becoming a business development asset.

    Found this useful? Share it.

    Share

    By email

    The Private Brief, in your inbox

    One piece at a time, whole, on the day it is published. Not a digest, not a roundup, and not a monthly summary of things you have already seen.

    Your address is used for this and nothing else, and every issue carries an unsubscribe link that works on the first click.

    Need Guidance?

    Let’s discuss your situation.

    Request an Introduction