Blog

AI Policy for Law Firms: A Practical Template and Checklist

Professional woman in a blazer works on a laptop with a blue holographic AI policy dashboard beside her.

Picture this: without an AI policy for law firms, an attorney on your team opens a popular AI chatbot, pastes in a client’s full case summary, and asks it to draft a motion. The output is clean, the attorney makes a few edits, and it gets filed. Nobody asked whether that platform retains user inputs. Nobody checked whether that data trains the model. Nobody said not to. The firm has no written AI policy, no approved-tools list, and no disclosure language in its engagement letters.

That gap is where malpractice exposure lives. AI is already embedded across legal workflows, research, drafting, intake, case summaries, and marketing, and it’s not slowing down. ABA Formal Opinion 512, issued in 2024, makes the stakes plain: existing professional duties under the Model Rules apply directly to every AI tool your firm uses. Competence, confidentiality, supervision, candor, communication, and reasonable fees all have teeth here. No new rules are needed because the existing ones already cover every AI decision your attorneys make.

This guide gives you the working components of a defensible AI policy for law firms: required elements, a vendor-vetting checklist, ready-to-adapt client disclosure language, and a training and audit framework. Use it to build something real, not a document that sits in a shared drive and does nothing.

Why law firms can’t operate on informal AI rules anymore

Many firms have embraced AI to stay competitive. The problem is that when everyone uses it differently, different tools, no documented guardrails, the firm carries liability that no individual attorney can manage alone. That informal, everyone-does-their-own-thing approach is now a professional liability problem with a paper trail.

What ABA Formal Opinion 512 actually requires

The 2024 opinion is clear on one central point: generative AI does not create new professional duties, but it triggers all the existing ones. Competence requires understanding a tool’s capabilities and failure modes before using it on client matters. Confidentiality requires protecting client information from exposure through AI systems. Supervision requires that managing attorneys establish firm-wide AI practices and ensure all AI-generated work is reviewed by a lawyer. Candor requires independent verification of any AI content submitted to a tribunal. Firms without a written policy aren’t operating in a gray zone; they’re operating against documented guidance.

The documented consequences of having no policy

The pattern of consequences is well-established. Courts have sanctioned attorneys who filed AI-generated citations that turned out to be fabricated, in cases such as Mata v. Avianca (S.D.N.Y. 2023) and subsequent proceedings in multiple circuits, and bar authorities have treated those filings as attorney misconduct rather than tool failure. Confidentiality breaches from client data entered into public AI platforms have also surfaced in disciplinary records. From 2023 through 2026, the documented risk has only grown. Several federal district courts and state courts now require attorneys to certify AI involvement in filings through standing orders; the Northern District of Texas and courts in Florida and California have issued such requirements. The risk isn’t theoretical anymore, it’s showing up in real sanctions orders and disciplinary proceedings.

How to build an AI policy for law firms: core components

Not every policy element carries equal weight. Some are minimum professional-duty requirements drawn directly from bar guidance. Others are best-practice additions that make your governance framework much harder to challenge. Knowing which is which helps you build in the right order.

The non-negotiable required elements

These five pillars appear consistently across ABA guidance and state bar opinions, including New York, California, and Florida bar guidance published between 2023 and 2025, and each maps to an existing professional rule:

  • Competence requirements: Attorneys must understand a tool’s capabilities, limitations, and failure modes before using it on any client matter.
  • Confidentiality controls: Written rules on what client information may and may not be entered into AI systems, including distinctions between public and enterprise tools.
  • Client communication and disclosure: Clear guidance on when and how to tell clients AI is being used, especially when confidential data is processed.
  • Supervision and human review: A licensed attorney must review and approve all AI-generated work before it reaches a client or a court.
  • Accuracy and candor verification: Independent verification of AI-generated content is required for any filings or tribunal submissions, full stop.

Recommended governance additions that strengthen your policy

Beyond the required core, the firms with the most defensible AI governance programs maintain several additional controls. On the data and vendor side, that means an approved-tools list specifying which platforms are cleared for client data, data-classification rules defining what categories of information are allowed or restricted in AI tools, and vendor due-diligence requirements that must be satisfied before any tool makes the approved list.

On the operational side, add billing guidance that explains how AI-assisted time is handled, an incident response procedure for when something goes wrong, and a named AI policy owner responsible for keeping the policy current as the technology and bar guidance evolve.

How to vet AI tools before they touch client data

Your approved-tools list is only as strong as the process you used to build it. Vetting an AI tool for legal use is not the same as reading app reviews. You’re evaluating it against confidentiality obligations, privilege protection, and data governance standards that can be tested in a disciplinary proceeding.

Vendor checklist for an AI policy for law firms

Before approving any tool for use with client data, get clear answers to these questions:

  • Does the vendor contractually commit to not using customer data to train or improve its model?
  • Is data encrypted in transit and at rest?
  • Does the vendor offer an enterprise or private deployment rather than a public consumer version?
  • Can the vendor provide audit logs and admin-level usage monitoring?
  • What are the retention, deletion, and ownership terms for AI-generated outputs?
  • Does the vendor hold SOC 2 Type II or ISO 27001 certification?
  • Where is data stored and processed, and who are the sub-processors?

Red flags that should disqualify a tool immediately

Some answers should end the evaluation right there. Vague or missing data-training opt-out language in the terms of service is a disqualifier. The absence of an enterprise data-handling tier, meaning a contractual data-processing addendum, private deployment, or dedicated tenancy separate from the consumer product, is another hard stop; without it, you’re effectively running client data through a consumer platform. Inability to provide breach-notification commitments rounds out the list. If a vendor can’t give you a straight answer on where client data is retained or who can access it, remove that tool from consideration. It doesn’t matter how useful it looks in a demo.

Client disclosure language you can use right now

Good disclosure language serves a clear purpose: clients learn what AI is used for, understand how their data is protected, and know that a licensed attorney reviews and takes responsibility for every output. It doesn’t need to be a full page, but it does need to appear in the engagement letter before any AI-assisted work begins.

General AI use clause for engagement letters

The following language is adapted from the New York State Bar Association’s April 2024 Report on Artificial Intelligence and the Legal Profession and is consistent with ABA Formal Opinion 512. Adapt it to your firm’s specific tools and workflows:

“Use of AI-Assisted Tools. Our firm may use artificial intelligence tools to assist with legal research, document drafting, case analysis, and administrative tasks. All AI-generated work product is reviewed and verified by a licensed attorney before use or delivery. We do not input personally identifiable client information into unsecured or public AI platforms. We maintain confidentiality and data-protection safeguards appropriate to the tools we use. If you have questions about how AI tools are used in your matter, please contact us directly.”

Informed consent language for sensitive matter processing

When confidential client information will be processed by a generative AI tool, ABA Formal Opinion 512 is explicit: general boilerplate is not sufficient for informed consent. The client needs to understand the purpose of using the tool, the specific risks involved, what kinds of information will be disclosed, how it may be used or accessed, and the benefits to the representation. A more detailed consent paragraph would identify the tool category, the safeguards in place, and the client’s right to object or request that AI not be used for specified tasks.

For court filings where AI disclosure or certification is required, such as filings in courts with standing AI disclosure orders, attorneys can adapt this language: “I certify that artificial intelligence was used to assist in drafting portions of this document. I have reviewed all AI-generated content for accuracy and completeness, verified all citations and quotations against original sources, and I take full professional responsibility for the contents of this filing.”

Training, logging, and incident response protocols

A written AI policy that nobody follows isn’t a defense, it’s evidence that the firm knew what it should do and didn’t enforce it. Implementation requires training before access, ongoing accountability, and a documented response path for when something goes wrong.

Building a training and recertification schedule

ABA Formal Opinion 512 and state bar governance templates published since 2023 point to a consistent training cadence: initial training before access or within 30 days of hire, annual recertification for all AI-using personnel, and supplemental briefings after major tool changes or significant policy updates. Role-based training matters more than one-size sessions. A litigation team, a corporate team, and intake staff face different AI use scenarios. Training that reflects their actual workflows is far more effective than a generic overview.

What to log and how to handle an AI incident

Audit-readiness requires logging prompts, outputs, matter associations, and human review steps. Immutable logging gives you a professional responsibility defense if a question ever arises about what happened and when, bar governance templates from 2023 onward consistently recommend retaining evidence-grade records including timestamps and reviewer attestations alongside the AI content itself. Incident response trigger points include use of an unapproved tool, suspected confidential data exposure, and any filed document later found to contain unverified AI content.

When an incident occurs, the response follows a clear path: identify the exposure, assess notification obligations under applicable ethics rules, remediate the controls that failed, and document the involved person’s training status at the time of the incident.

Your law firm AI policy rollout checklist

Having the policy elements mapped out is one thing. Sequencing them into an actual rollout turns a document into a governance system. A phased approach keeps the process manageable without cutting corners on the essentials.

Phase-by-phase implementation steps

  1. Audit current AI tool use across the firm, including shadow AI discovery to find tools attorneys or staff are already using without approval.
  2. Draft the core policy using the required elements covered above, assign a named AI policy owner, and get leadership sign-off before distribution.
  3. Vet tools against the vendor checklist, finalize the approved-tools list, and update all engagement letter templates with the appropriate disclosure and consent language.
  4. Train all attorneys and staff before granting access, document completion, and put the first annual review date on the calendar before you close out the rollout.

Extending AI governance to your vendor stack

One area firms regularly overlook: the vendors they already work with. Marketing agencies, intake platforms, and CRM providers may use AI in their own workflows on your firm’s behalf. That means your AI governance audit needs to extend to those relationships. You want partners who can answer the same vendor checklist questions you’d ask of any tool you’re approving internally.

At Thrive Business Marketing, we recognize that law firms need vendor partners who take data governance seriously. We’ve built AI risk management considerations into how we structure our marketing work for legal clients, so firms can ask the right questions and get straight answers, rather than discovering an exposure gap mid-engagement.

Build it now, not after the incident

The risk of operating without a formal AI policy for law firms is not a future problem. It’s a current one, and the documented disciplinary record confirms it. A defensible law firm AI policy template doesn’t need to be 40 pages. It needs clear rules on approved tools, confidentiality controls, disclosure requirements, and supervision obligations, backed by training and audit processes that prove the policy is real and enforced.

Use the components outlined here as your starting point. Adapt the disclosure language for your engagement letters, run your current tools through the vendor checklist, and schedule your first training session before the next onboarding cycle. The firms building a structured model AI policy for law firms now will reduce their ethics exposure, operate more efficiently, and build stronger client trust as AI becomes a permanent fixture in legal practice.

Start with the checklist and build from there. Adopt an AI policy for law firms today, many firms still lack any formal policy at all, and a well-structured framework, even an imperfect one, is a meaningful improvement over starting from zero.

Are You Ready To Thrive?

Or send us a message

Name(Required)

Below you agree to our Privacy Policy and Terms of Service.

Categories