Insights · Ethics
How to Write a Law Firm AI-Use Policy: A Practical Guide
What a one-to-two page firm AI-use policy should contain, grounded in ABA Formal Opinion 512 and the duties of competence, confidentiality, and supervision.
Most small and mid-sized firms already have lawyers and staff using generative AI, whether or not the firm has decided to allow it. A short written policy is the difference between supervised, defensible use and the kind of improvisation that produces a sanctions order. This guide sets out what a workable one-to-two page firm AI-use policy should contain, and grounds each part in the duties that already govern your practice.
The governing authority is ABA Formal Opinion 512, issued by the ABA Standing Committee on Ethics and Professional Responsibility on July 29, 2024. It is the ABA's first formal ethics opinion on generative AI, and it maps lawyers' existing obligations, competence, confidentiality, communication, candor toward tribunals, supervision, and reasonable fees, onto the use of these tools. Opinion 512 does not create new rules. It applies familiar ones, which is why a sound policy is mostly a matter of writing down what the rules already require.
Why one page beats a binder
The goal is a document people actually read and follow. A law firm AI policy that runs to twenty pages will sit unread in a shared drive while associates paste client facts into a chatbot. Aim for one to two pages, written in plain language, with five components: approved tools, a confidentiality rule, a verification protocol, a training requirement, and a named owner. If you are looking for an AI use policy template, lawyers are better served by this short, enforceable spine than by a long document borrowed from a corporation with a very different risk profile.
Two framing points belong at the top of the document. First, state that the firm permits AI use within these rules rather than banning it, because a ban tends to drive use underground where it cannot be supervised. Second, state that the lawyer remains fully responsible for any work product, and that the tool is never a substitute for the lawyer's own judgment. Opinion 512 is explicit that AI tools cannot replace a lawyer's competent legal work.
Section 1: Approved tools and prohibited tools
The single most useful line in the policy is a list of the specific tools the firm has vetted and approved, by name and version, for specific kinds of work. Vague permission to use AI is not supervision. Naming the tools is.
Distinguish at least three categories:
- Enterprise or paid accounts the firm has configured, where the vendor contractually agrees not to train on your inputs and retention is controlled. These are the tools approved for matter work.
- Consumer or free accounts, which often reserve the right to use inputs to improve the model. Permit these only for general, non-confidential tasks such as drafting a CLE outline or rephrasing marketing copy.
- Prohibited uses, stated plainly. No client confidential information goes into a tool the firm has not approved for that purpose.
Opinion 512 draws attention to self-learning tools, where information a user inputs can resurface in outputs to later, unrelated prompts. That risk is the reason the tool list and the data rules in Section 2 have to work together. Approving a tool means someone has actually read its terms on training, retention, and access, not assumed them. Build in a simple process for adding a tool to the approved list so that the answer to a new product is review, not quiet adoption.
Section 2: The confidentiality rule
Confidentiality is where most firms get into trouble, and it deserves the clearest sentence in the policy. Under Model Rule 1.6 the duty covers all information relating to the representation, regardless of source. Opinion 512 instructs that before a lawyer inputs information relating to a representation into an AI tool, the lawyer must evaluate the risk that the information will be disclosed to or accessed by others outside the firm.
Translate that into a rule a busy associate can apply at the keyboard:
- Client confidential information may be entered only into tools on the firm's approved, configured list.
- For everything else, the default is to anonymize: strip names, account numbers, and identifying facts before using a general tool.
- When in doubt, ask the policy owner before pasting.
The policy should also address client consent, because Opinion 512 takes a firm position. It concludes that a lawyer should obtain the client's informed consent before inputting the client's confidential information into a self-learning AI tool, and that boilerplate language buried in an engagement letter is not enough. Informed consent requires an actual explanation of the relevant risk. Decide, in the policy, how your firm handles this: which tools are configured well enough that consent is unnecessary, and for which situations a specific conversation and engagement-letter provision are required. State and local rules may go further than the ABA guidance, so the policy should note that lawyers must follow the rules of every jurisdiction in which they practice.
Section 3: A verification protocol
This is the section that keeps your firm out of the news. Generative AI produces fluent, confident text that can be entirely fabricated, including citations to cases that do not exist. The cautionary example is Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), in which Judge P. Kevin Castel sanctioned two attorneys 5,000 dollars under Rule 11 after they submitted a brief containing fictitious case citations generated by ChatGPT. The court found the lawyers had acted in subjective bad faith, in part by standing behind the fake cases when questioned. Numerous similar sanctions have followed in courts around the country since.
Opinion 512 ties this to the duty of competence: the level of verification required depends on the tool and the task, but the lawyer must review AI output rather than rely on it. A verification protocol makes that concrete. At a minimum:
- Every citation is independently confirmed in a primary source or an established legal database before it goes into any document filed with a court or sent to a client or opposing counsel. The AI's assurance that a case is real does not count.
- Every factual assertion drawn from AI output is checked against the record or a reliable source.
- A human lawyer reviews and adopts the work product and is accountable for it. The reviewing lawyer's name, not the tool, owns the result.
It helps to require a brief note in the file, even one line, recording that AI was used on a matter and that outputs were verified. That record costs nothing and is valuable if the use is ever questioned.
Section 4: Supervision, training, and a named owner
Opinion 512 invokes the supervisory duties under Model Rules 5.1 and 5.3, which require partners and managers to make reasonable efforts to ensure that lawyers and nonlawyer staff conform to the rules. Those duties extend to AI tools, including AI features embedded in vendor products that paralegals and assistants use. A policy that no one is responsible for enforcing is not supervision.
So the policy must name an owner: a specific person, the AI policy partner or a small committee, responsible for maintaining the approved-tool list, fielding questions, reviewing incidents, and updating the document. In a firm of three to thirty lawyers this is usually one partner with an interest in technology, supported by whoever manages IT.
The policy should also require training, because competence under Model Rule 1.1 includes understanding the benefits and risks of relevant technology. Training does not need to be elaborate. A short annual session covering what the approved tools are, the confidentiality rule, the verification protocol, and the lessons of cases like Mata is enough to establish that the firm took reasonable steps. Onboarding for new lawyers and staff should include the policy. Document that the training happened.
Two further items belong here. Address fees and billing: Opinion 512 cautions that lawyers may not bill for time AI saves them, and that the cost economics of these tools should be passed through fairly rather than used to inflate hours. And require incident reporting: anyone who realizes confidential information went into the wrong tool, or that an unverified AI citation reached a filing, reports it to the owner promptly so the firm can respond.
A one-page checklist
The finished policy can close with a short checklist that captures the operative rules:
- We use only firm-approved tools for client matters, by name.
- We do not put client confidential information into unapproved tools.
- We obtain informed client consent where the rules and our tools require it.
- We independently verify every citation and material fact in AI-assisted work.
- A named lawyer reviews and is responsible for all AI-assisted work product.
- We train everyone annually and at onboarding.
- We do not bill clients for time AI saved.
- We report mistakes to the policy owner promptly.
A policy in this form is short enough to be read and specific enough to be followed. It does not try to predict every future tool. It writes down the duties of competence, confidentiality, and supervision that already bind you, points them at the technology your people are already using, and assigns one person to keep it current. That is the realistic standard Opinion 512 sets, and it is well within reach for a firm of any size.
This is general information for lawyers and law-firm leaders, not legal advice, and it does not create an attorney-client relationship. The authorities are cited so you can read them yourself.
The longer argument continues in AI in the Defender’s Office, a national field guide now in production.
Read about the book →