Guide
A firm AI policy template for lawyers: one page you can adapt (free)
A law firm AI policy template: one adaptable page covering approved tools, data rules, verification, supervision, client disclosure, billing and review.
By Raghav R Handa, practising lawyer17 min read
TL;DR
- A small firm needs a short policy: what AI may and may not be used for, what data may go in, who checks the output, how clients are told and when it is reviewed.
- A one-page policy that people read beats a long one they do not. Back it with a tools register, an incident log and a short training.
- The template below is a starting point. Adapt it to your regulator's guidance, your clients' rules and your insurer's requirements.
- It is a template for a lawyer to adapt, not legal advice.
A small firm's AI policy should fit on one page: what AI may and may not be used for, what data may go in, who checks the output, how clients are told and when the policy is reviewed. Below is a template with commentary on each clause, plus an approved-tools register, an incident log, a training outline and an adoption roadmap. Adapt it to your regulator's guidance, your clients' rules and your insurer's requirements. It is a template for a lawyer to adapt, not legal advice.
The template, clause by clause
1. Purpose and scope
This policy governs the use of generative artificial intelligence tools by everyone working for [firm], including partners, associates, paralegals, contractors and temporary staff. It supplements our duties of competence, confidentiality, supervision, candour and honest billing.
Commentary: state who is covered and tie the policy to the duties it serves, so it reads as part of professional practice, not IT compliance.
2. Approved tools
Only the tools on the approved list may be used for client work: [list]. A new tool needs approval from [role] after a due diligence check. Personal accounts and unapproved tools must not be used for client work.
Commentary: a short list, with the plan and settings approved. See the vendor checklist.
3. Permitted uses
[Summarising non-sensitive documents; first drafts of internal notes; checklists; plain-language rewrites; research starting points to be verified; brainstorming questions.]
Commentary: be concrete. People follow lists of examples better than principles.
4. Prohibited uses
[Entering information from matters marked Restricted or Declined; relying on output without verification; using unapproved tools; filing or sending AI output without lawyer review; entering credentials or tier-4 data; using AI to make decisions about clients or staff without human review.]
5. Data rules
Do not enter [categories of information] into any tool unless approved for that purpose. Remove client-identifying details wherever the task does not need them. Use the minimum information the task requires.
Commentary: tie this to your data tiers (see client data and Notion).
6. Verification
Every citation, fact, quotation and figure produced by AI must be checked against a primary source before use. The responsible lawyer is accountable for the final work.
7. Supervision
[Role] is responsible for this policy. Staff using AI must be trained and supervised. Supervisors are responsible for the AI-assisted work of those they supervise.
8. Clients
We disclose AI use to clients as [describe]. Where a client declines or restricts AI use we record it on the matter and comply. We follow client outside-counsel guidelines.
Commentary: see the client consent template.
9. Billing
We charge for the work done and its value, [describe], and never for time not spent. AI tool costs are firm overhead unless agreed otherwise.
10. Incidents
Any suspected disclosure of confidential information or material error from AI must be reported immediately to [role] and recorded in the incident log.
11. Review
This policy is reviewed every six months and when a tool, its terms or regulatory guidance changes. Last reviewed: [date]. Next review: [date].
Approved-tools register (template)
| Tool and plan | Approved uses | Data tier allowed | Settings required | Owner | Approved on | Review by |
|---|---|---|---|---|---|---|
| [Tool], [plan] | [Tasks] | Tier 1 and 2 | MFA; AI scoped; no tier 3 | [Name] | [Date] | [Date] |
| [Tool], [plan] | [Tasks] | Tier 1 only | Firm account only | [Name] | [Date] | [Date] |
Incident log (template)
| Date | What happened | Matter and data involved | Reported to | Assessment | Action | Lesson added to policy? |
|---|---|---|---|---|---|---|
| [Date] | [Description] | [Details] | [Name] | [Exposure or error] | [Steps taken] | [Yes or no] |
A 60-minute training outline
- What it is (10 minutes). How generative AI works at a high level; what it is good at; why it can be fluent and wrong.
- Failures (10 minutes). Real examples of invented citations and wrong summaries; why a lawyer is still responsible.
- The data rules (15 minutes). Tiers, what never goes in, de-identification, client restrictions.
- Verification (15 minutes). A live exercise: take an AI output with errors and find them.
- Procedures (10 minutes). Approved tools, incident reporting, who to ask.
An adoption roadmap
| Phase | What | Output |
|---|---|---|
| Week 1 | Inventory current AI use (including unofficial); list data tiers | A baseline and a risk list |
| Week 2 | Draft and adopt the policy; approve tools; set access | Policy, register, settings |
| Week 3 | Train staff | Attendance record |
| Weeks 4 to 7 | Run a pilot on low-risk tasks with scoring | Pilot report |
| Week 8 | Review; extend or restrict | Updated policy |
| Every six months | Review | Dated review record |
Make it real in Notion
- Keep the policy in the firm wiki with an owner and a review date (firm wiki).
- Keep an approved-tools register (vendor due diligence).
- Record client AI preferences on each matter (consent template).
- Set up AI access to match the policy (a Notion AI setup for law firms).
- Keep an incident log with restricted access.
Common mistakes
- A long policy nobody reads. Keep the front page short.
- A ban that drives use underground.
- No owner, so the register and review lapse.
- Policy and practice diverging: check against actual use.
- Skipping training because the policy exists.
See also the ABA Model Rules for cloud and AI, Notion AI and confidential work and AI for lawyers.
Frequently asked questions
Does a small law firm need an AI policy?
Yes, a short one. Even a solo benefits from deciding in writing what AI may be used for, what information may go in, who checks the output and how clients are told. It is also evidence of a reasoned approach if a regulator or insurer asks.
What should a law firm AI policy cover?
Purpose and scope, approved tools, permitted and prohibited uses, rules on confidential data, verification of output, supervision and responsibility, client disclosure and consent, billing, incident handling and review.
How often should we review the AI policy?
At least twice a year, and whenever a tool, its terms or your regulator's guidance changes materially.
Who should own the AI policy?
A named lawyer, usually a partner or the managing lawyer, with a backup. Ownership means keeping the tools register current, approving new tools, handling incidents and running the review.
Should staff be allowed to use personal AI accounts for work?
Generally no. Personal accounts bypass your due diligence, data terms and access controls. The policy should require use of approved tools under firm accounts only.
How do we handle a mistake made with AI?
Report it at once to the policy owner, contain it, assess any exposure or error, follow your duties on informing the client or correcting a court, log it, and add the lesson to the policy and training.
Do we need to train staff?
Yes. A short session on what the tools can and cannot do, examples of failures, the verification routine and the data rules, repeated when tools or rules change, is the cheapest control you have.
Should the policy ban AI?
A blanket ban rarely works: people use tools anyway, without controls. A policy that permits defined uses with safeguards, and prohibits the risky ones, is easier to follow and enforce.