The question for law firms is no longer whether generative AI will be used in practice — associates are already using it. The question is whether it is being used under a policy the firm wrote, or one it is improvising.
The Professional Responsibility Frame
Bar guidance has coalesced around familiar duties applied to a new tool:
- Competence includes understanding the capabilities and limits of the technology used to deliver legal services
- Confidentiality governs what client information may be entered into which tools, under what terms
- Supervision makes the firm responsible for how lawyers and staff use these tools
- Candor puts verification of AI-assisted output squarely on the lawyer signing the filing
Courts have sanctioned lawyers for filing briefs with fabricated citations. Those cases were not AI failures; they were verification failures.
The Policy Core
A workable firm policy usually answers six questions:
- Which tools are approved? Consumer chatbots and enterprise legal tools have very different confidentiality postures.
- What data may go in? Define categories — public information, anonymized facts, client-identifying information — and match each to approved tools.
- What uses are permitted? Research assistance, first drafts, summarization; and which uses are prohibited outright.
- What must be verified? Every citation, every factual assertion, every characterization of authority — by a human, before it leaves the firm.
- Who must know? Engagement letter language and, in some matters, court-required disclosures.
- Who owns the policy? A named partner or committee that reviews tools, handles exceptions, and updates the rules as the technology moves.
Beyond the Policy Document
The firms doing this well pair the policy with vendor diligence — data handling, training-use terms, retention — and with actual training, because the failure mode is rarely malice; it is a lawyer under deadline pressure using an unapproved tool because it was faster.
The Opportunity Side
Handled properly, this is not merely defensive. Firms that can tell clients precisely how they use AI — and how they protect client data while doing it — are answering a question that sophisticated clients have started asking in RFPs. A real governance program is becoming a business development asset.