Securing Your Law Firm logoSecuring Your Law Firm

AI Governance

AI Governance for Law Firms

A policy nobody enforces is not governance. We write the policy and configure the controls that make it true.

The problem

AI use is already inside your firm, whether you approved it or not.

Attorneys and staff at most firms are already using AI tools the firm never approved. They draft with them, summarize with them, and research with them, often through personal accounts on consumer tiers whose terms permit the vendor to train on whatever is entered. The firm usually finds out during an incident, a client questionnaire, or an insurance renewal.
The ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 512 on July 29, 2024, its first formal opinion on generative AI, addressing competence, confidentiality, communication, candor, supervision, and fees. State bars across the country have followed with their own guidance. Formal Opinion 512 should be read alongside the rest of your jurisdiction's guidance.
Model Rules 5.1 and 5.3 place the obligation on the firm, not the individual user. Managerial lawyers must establish policies reasonably ensuring compliance, and supervisory lawyers must ensure those they supervise comply. In practice that means a written policy, an approved tool list, and documented training. Rule 5.1 and Rule 5.3 apply.
Courts have added requirements of their own. Some now require disclosure or certification regarding AI-generated content in filings, varying by court and sometimes by individual judge. Check the filing rules in each court before using AI in a filing.
Industry survey data shows the large majority of legal professionals now use AI tools, while a substantial share of firms have no formal governance policy at all.
Microsoft Copilot inherits the permissions of whoever is asking. It grants no new access, which is exactly why firms underestimate it. The moment Copilot is switched on, years of accumulated SharePoint and OneDrive permission sprawl becomes searchable in plain English. A staff member asks a reasonable question and receives a summary drawn from a matter they were never authorized to see.
Before Copilot, obscurity was doing the work permissions were not. Nobody browsed document libraries, so overshared content stayed undiscovered. Copilot removes obscurity as a control.
For a law firm this is not only a confidentiality problem. Ethical walls are usually implemented as SharePoint or Teams permissions, often set up quickly at the moment a conflict was identified. If a screen has a gap, Copilot will find it and summarize it, with no alert, no access-denied log, and no indication that anything unusual happened.

Do not turn Copilot on until you know what it can see.

What we do

Four engagements, one baseline, and a yearly refresh.

Founding client pricing applies on the pricing page. Every scope is published before you sign, and the catalog is organized so your firm can choose a narrow first step or a full governance program.

AI Use Discovery Report

$850

What your firm is actually using, versus what the partners believe it is using. We review Entra ID enterprise application consent grants and OAuth authorizations, Microsoft 365 sign-in activity checked against a known AI vendor catalog, and browser extension inventory across managed devices. We also run an anonymous staff usage survey, because personal-device use never appears in tenant logs. Includes vendor terms triage: which tools in use permit training on your input, where your data is stored, and how long it is retained.

View matching pricing entry

Copilot Readiness Assessment

$2,450

A go or no-go assessment before you enable Microsoft Copilot. Permission blast-radius analysis, oversharing and broken-inheritance reporting, sensitivity label verification, and ethical wall testing, delivered with a prioritized remediation list.

View matching pricing entry

AI Governance Assessment and Policy

$3,950

Includes the AI Use Discovery Report, plus a written AI acceptable use policy built on a prohibited, oversight-required, and standard-use classification. Also includes a supervision framework addressing Model Rules 5.1 and 5.3, a client disclosure template, a matter intake AI clause, a mandatory citation verification protocol, an approved tool register with documented vendor-terms rationale, a jurisdiction annex keyed to your state's guidance, and a staff training session with attendance record and signed acknowledgments.

View matching pricing entry

AI Controls Implementation

$2,850

Configuration, not just documentation. Sensitivity labels applied and enforced, data loss prevention policies covering AI endpoints, Entra ID application consent restricted to admin approval with existing risky grants revoked, Copilot scoped to approved SharePoint sources with oversharing remediated, and Conditional Access rules for unmanaged AI tool access. Delivered with a full before-and-after evidence pack.

View matching pricing entry

AI Governance Baseline

Flagship

$8,950

All four engagements as a single scoped program, saving $1,150 versus purchasing separately.

View matching pricing entry

Annual AI Policy Refresh

$750 per year

Bar guidance is changing faster than any other area of professional responsibility. A policy written today and never revisited becomes a liability.

View matching pricing entry

Who this is for

Build this when your firm needs governance that survives contact with real users.

This is a good fit if

  • your firm is considering or has enabled Microsoft Copilot
  • attorneys or staff use AI tools and there is no written policy
  • a client's outside counsel guidelines address AI use
  • your cyber insurance renewal asks about AI
  • you maintain active ethical screens and have not verified them since moving to Microsoft 365

Not the right fit

Use this when you need the program, not a template.

This is not the right service if

  • you need an opinion on whether a specific practice satisfies your professional responsibility obligations
  • you want only a policy template with no technical implementation
  • you do not want discovery, controls, documentation, or training

Why us

A policy is not enough if the tenant still does whatever it wants.

Templates and general IT support can help, but AI governance only becomes real when the policy, the tenant, and the training all point in the same direction.

Typical MSP
Securing Your Law Firm

Legal consultants and policy templates

Write the policy, cannot configure your tenant

MSPs and IT providers

Can configure the tenant, have never read Rule 1.6

Generic AI policy downloads

One template for every business

We build the policy and the controls. Your firm retains the legal judgment call on what its jurisdiction requires.

Scope of our work

"We build the technical and governance program: discovery, controls, documentation, and training. Your firm's managing partner or ethics counsel retains responsibility for determining what your professional responsibility obligations require in your jurisdiction. Our deliverables are designed to support that determination, not substitute for it. Advisory ethics opinions are not binding, and the rules of your jurisdiction control."

Frequently asked questions

Questions we hear before firms approve AI use.

Model Rules 5.1 and 5.3 require managerial lawyers to establish policies reasonably ensuring compliance with the rules of professional conduct, and supervisory lawyers to ensure those they supervise comply. Bar guidance across the country now treats AI use as falling within that obligation. If attorneys or staff at your firm use AI tools, a written policy and documented training are what demonstrate the firm addressed it.

It can be, but the answer depends on your tenant rather than on Copilot. Copilot surfaces content the requesting user can already access. If your SharePoint and OneDrive permissions are accurate, exposure is limited. If they carry years of accumulated oversharing, which is the norm, Copilot will surface that content on request. That is what the Copilot Readiness Assessment measures.

Copilot cannot defeat a correctly implemented screen. It can expose an incorrectly implemented one. Because screens are usually enforced as SharePoint or Teams permissions and are often set up under time pressure, gaps are common: a stray copy in a shared library, an attachment in a Team, a file in someone's OneDrive. Every active screen should be tested before Copilot is deployed.

It depends entirely on the account tier and what is entered. Consumer and free tiers of most tools carry terms permitting the vendor to train on input, which is difficult to reconcile with the duty of confidentiality. Business and enterprise tiers frequently carry different terms. The tool matters less than the tier and the data.

You can, and a template is better than nothing. What a template cannot do is tell you which tools your firm actually uses, whether those tools' terms permit training on your input, or whether your tenant is configured to enforce any of it. A policy that does not match your environment is a document, not a control.

The AI Use Discovery Report takes about a week. The full AI Governance Assessment and Policy runs three to four weeks including your review cycle and the training session. Controls Implementation runs alongside or after, depending on tenant complexity.

No. We build the governance and technical program. Your managing partner or ethics counsel determines what your professional responsibility obligations require in your jurisdiction. Our deliverables are built to support that determination.

Yes. Guidance differs by jurisdiction and is changing quickly. The policy we deliver includes a jurisdiction annex, and we complete one for every jurisdiction in which your attorneys are admitted.

Free starting point

Start with the free Proprietary Exposure Review

The free review is how we see the public exposure before we build the policy, controls, and training that make AI governance enforceable.

Must match your domain so another firm cannot request your review.

Public records only. Your report goes only to the verified inbox that requested it. We do not sell, share, or broker firm data, and we delete it after 30 days unless you engage us.