AI Governance
AI Governance for Law Firms
A policy nobody enforces is not governance. We write the policy and configure the controls that make it true.
The problem
AI use is already inside your firm, whether you approved it or not.
Do not turn Copilot on until you know what it can see.
What we do
Four engagements, one baseline, and a yearly refresh.
Founding client pricing applies on the pricing page. Every scope is published before you sign, and the catalog is organized so your firm can choose a narrow first step or a full governance program.
AI Use Discovery Report
$850
What your firm is actually using, versus what the partners believe it is using. We review Entra ID enterprise application consent grants and OAuth authorizations, Microsoft 365 sign-in activity checked against a known AI vendor catalog, and browser extension inventory across managed devices. We also run an anonymous staff usage survey, because personal-device use never appears in tenant logs. Includes vendor terms triage: which tools in use permit training on your input, where your data is stored, and how long it is retained.
View matching pricing entryCopilot Readiness Assessment
$2,450
A go or no-go assessment before you enable Microsoft Copilot. Permission blast-radius analysis, oversharing and broken-inheritance reporting, sensitivity label verification, and ethical wall testing, delivered with a prioritized remediation list.
View matching pricing entryAI Governance Assessment and Policy
$3,950
Includes the AI Use Discovery Report, plus a written AI acceptable use policy built on a prohibited, oversight-required, and standard-use classification. Also includes a supervision framework addressing Model Rules 5.1 and 5.3, a client disclosure template, a matter intake AI clause, a mandatory citation verification protocol, an approved tool register with documented vendor-terms rationale, a jurisdiction annex keyed to your state's guidance, and a staff training session with attendance record and signed acknowledgments.
View matching pricing entryAI Controls Implementation
$2,850
Configuration, not just documentation. Sensitivity labels applied and enforced, data loss prevention policies covering AI endpoints, Entra ID application consent restricted to admin approval with existing risky grants revoked, Copilot scoped to approved SharePoint sources with oversharing remediated, and Conditional Access rules for unmanaged AI tool access. Delivered with a full before-and-after evidence pack.
View matching pricing entryAI Governance Baseline
Flagship$8,950
All four engagements as a single scoped program, saving $1,150 versus purchasing separately.
View matching pricing entryAnnual AI Policy Refresh
$750 per year
Bar guidance is changing faster than any other area of professional responsibility. A policy written today and never revisited becomes a liability.
View matching pricing entryWho this is for
Build this when your firm needs governance that survives contact with real users.
This is a good fit if
- your firm is considering or has enabled Microsoft Copilot
- attorneys or staff use AI tools and there is no written policy
- a client's outside counsel guidelines address AI use
- your cyber insurance renewal asks about AI
- you maintain active ethical screens and have not verified them since moving to Microsoft 365
Not the right fit
Use this when you need the program, not a template.
This is not the right service if
- you need an opinion on whether a specific practice satisfies your professional responsibility obligations
- you want only a policy template with no technical implementation
- you do not want discovery, controls, documentation, or training
Why us
A policy is not enough if the tenant still does whatever it wants.
Templates and general IT support can help, but AI governance only becomes real when the policy, the tenant, and the training all point in the same direction.
Legal consultants and policy templates
Write the policy, cannot configure your tenant
MSPs and IT providers
Can configure the tenant, have never read Rule 1.6
Generic AI policy downloads
One template for every business
We build the policy and the controls. Your firm retains the legal judgment call on what its jurisdiction requires.
Scope of our work
Frequently asked questions
Questions we hear before firms approve AI use.
Model Rules 5.1 and 5.3 require managerial lawyers to establish policies reasonably ensuring compliance with the rules of professional conduct, and supervisory lawyers to ensure those they supervise comply. Bar guidance across the country now treats AI use as falling within that obligation. If attorneys or staff at your firm use AI tools, a written policy and documented training are what demonstrate the firm addressed it.
It can be, but the answer depends on your tenant rather than on Copilot. Copilot surfaces content the requesting user can already access. If your SharePoint and OneDrive permissions are accurate, exposure is limited. If they carry years of accumulated oversharing, which is the norm, Copilot will surface that content on request. That is what the Copilot Readiness Assessment measures.
Copilot cannot defeat a correctly implemented screen. It can expose an incorrectly implemented one. Because screens are usually enforced as SharePoint or Teams permissions and are often set up under time pressure, gaps are common: a stray copy in a shared library, an attachment in a Team, a file in someone's OneDrive. Every active screen should be tested before Copilot is deployed.
It depends entirely on the account tier and what is entered. Consumer and free tiers of most tools carry terms permitting the vendor to train on input, which is difficult to reconcile with the duty of confidentiality. Business and enterprise tiers frequently carry different terms. The tool matters less than the tier and the data.
You can, and a template is better than nothing. What a template cannot do is tell you which tools your firm actually uses, whether those tools' terms permit training on your input, or whether your tenant is configured to enforce any of it. A policy that does not match your environment is a document, not a control.
The AI Use Discovery Report takes about a week. The full AI Governance Assessment and Policy runs three to four weeks including your review cycle and the training session. Controls Implementation runs alongside or after, depending on tenant complexity.
No. We build the governance and technical program. Your managing partner or ethics counsel determines what your professional responsibility obligations require in your jurisdiction. Our deliverables are built to support that determination.
Yes. Guidance differs by jurisdiction and is changing quickly. The policy we deliver includes a jurisdiction annex, and we complete one for every jurisdiction in which your attorneys are admitted.
Related services
The usual next steps after AI governance.
Free starting point
Start with the free Proprietary Exposure Review
The free review is how we see the public exposure before we build the policy, controls, and training that make AI governance enforceable.
