Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Resources2026-08-28By Securing Your Law Firm

Law Firm AI Policy: What to Include + Sample Language

What should a law firm AI policy include? Learn the core sections, sample language, and practical controls law firm managers need before anyone uses AI on client matters.

Law Firm AI Policy: What to Include + Sample Language

Blog post - By Securing Your Law Firm

Free Zero-Access Exposure Review™ | See pricing

What should a law firm AI policy include?

That is the right question for law firm managers and office managers.

Many firms are already using AI before they have a written policy.

That is where avoidable risk starts.

A good AI policy does not need to be long. It needs to be clear.

It should tell the firm who may use AI, which tools are approved, what data is off limits, who reviews the output, and when the client needs to know.

The policy also has to match the real technical environment. If the policy says one thing and the tool settings say another, the firm does not have a policy. It has a document.

In this article:

  • Why the policy matters
  • What it should say about scope and ownership
  • How to define approved and banned tools
  • What to do with confidential and client data
  • How to require human review and supervision
  • When disclosure and billing rules matter
  • How to keep the policy current

Why the policy matters

AI use is no longer a future issue. It is already in the workflow at many firms, often without much oversight.

That creates three problems right away:

  • people use tools the firm never approved;
  • client data gets entered where it should not go; and
  • no one is clearly responsible for checking the output.

A written policy gives the firm a standard. It helps attorneys, staff, and contractors make the same decision the same way every time.

1. Define scope and ownership

The policy should say who it covers.

If it only mentions attorneys, it can miss staff, contractors, and vendors who also touch firm data.

It should also name the person or role that owns the policy and the review cycle.

Sample language:

2. Approve tools before anyone uses them

A policy should not simply say "AI is allowed." It should say which tools are allowed and for what purpose.

The best version of this section uses simple categories:

  • approved for public information only;
  • approved for internal drafting with no client data;
  • approved for client-matter use; or
  • not approved.

Before a tool is approved for firm use, the firm should check the vendor terms.

At minimum, ask whether the vendor can train on firm inputs, how long it keeps data, whether it supports SSO and MFA, and whether audit logs are available.

Consumer tools and personal accounts should be off limits for client matters unless the firm has explicitly reviewed and approved them.

Sample language:

3. Set clear data-handling rules

This section should be very direct. People should not have to guess whether a prompt is safe.

At minimum, the policy should separate public information from confidential, privileged, client-identifying, financial, and matter-strategy information.

If the task can be done with less data, the policy should say to use less data.

Sample language:

4. Require human review and supervision

AI output should be treated as draft material, not final work.

The policy should require a licensed attorney to review any AI-assisted work product before it is filed, sent to a client, or relied on for legal advice.

That review should include facts, citations, quotes, math, and anything else that could matter to the client or the court.

Sample language:

5. Cover disclosure and billing

Disclosure rules can vary by jurisdiction and by client agreement. The policy should not pretend one rule fits every matter.

Instead, it should say when the firm must check local requirements, when the client should be informed, and how billing should be handled if AI changes the work.

If AI changes the scope, staffing, or cost of a matter, the client agreement should be clear about that.

Sample language:

6. Train people and review the policy

A policy is only useful if people know it exists and understand it.

The firm should train attorneys and staff on the approved tools list, the data rules, the review requirement, and how to report a problem.

The policy should also be reviewed on a set schedule, and again whenever the firm adopts a new tool or changes how AI is used.

Sample language:

A simple checklist for your final draft

Before you finalize the policy, check whether it covers these basics:

  • who the policy applies to;
  • which tools are approved;
  • which tools are banned;
  • what data may never go into AI;
  • who reviews the output;
  • when disclosure is required; and
  • when the policy will be reviewed again.

If any one of those items is missing, the policy is probably too vague to guide real decisions.

Related reading

If you are building a broader AI program, these related resources are a good next step:

Bottom line

The best law firm AI policy is short, specific, and easy to follow. It should tell people what to do in plain English.

It should also match the firm’s actual controls. A policy that allows a tool the firm has not reviewed is not much help when something goes wrong.

If you want to know what your firm is already exposing publicly before you roll out more AI, a Free Zero-Access Exposure Review™ is a practical place to start.