A law firm’s AI policy needs six real pieces to do its job: a plain
statement of acceptable use, a clear line on what data can never go into
an AI tool, a human review requirement before AI-assisted work goes out
under the firm’s name, a defined process for approving any new AI tool
before staff can use it, a training requirement so the policy is not
just a document nobody read, and a plan for what happens if something
goes wrong. Most firms that have a policy at all are missing at least
two or three of these. Most firms do not have one written down at
all.
This is not legal advice, and the specific obligations your firm has
around client data and professional responsibility are between your firm
and your bar association’s ethics guidance. What follows is the
operational and technology side of that decision, the actual pieces a
policy needs to hold together.
Why don’t more
law firms have a written AI policy?
Because writing one down forces decisions that are easier to leave
vague. Clio’s 2025 Legal Trends Report found 53% of legal professionals
say their firm has no AI policy, or they are not sure if it has one.
That is not a small gap. It means more than half the industry is either
operating with no rules or operating with rules nobody can point to.
The same report found firms are not standing still on AI use while
they figure this out. Eighty-two percent of legal professionals plan to
increase their AI use over the next 12 months. A firm without a written
policy is not a firm where nobody is using AI. It is a firm where
everyone is deciding the rules for themselves, tool by tool, one staff
member at a time.
What counts
as acceptable use of AI at a law firm?
It starts with naming which tools are approved and for what. A policy
that just says “use AI responsibly” is not a policy, it is a wish. An
acceptable use section names the specific tools staff are cleared to
use, what tasks each one is cleared for, and what is explicitly off
limits regardless of the tool. Drafting a first pass of a routine
internal memo is a different risk category than drafting a filing that
goes to a court. The policy should say so directly instead of leaving
staff to guess where a given task falls.
What data should
never go into an AI tool?
Anything client-identifying, case-specific, or covered by
attorney-client privilege does not belong in a tool without a real
business data agreement behind it, and it certainly does not belong in a
free consumer account someone signed up for on their own. That includes
client names paired with case facts, draft settlement positions,
internal strategy discussions, anything under a protective order, and
documents produced in discovery. This is the section most firms already
have some version of, even informally. The mistake is leaving it as a
verbal rule instead of writing down the specific categories, because a
verbal rule does not survive a new hire’s first week.
Does a
human need to review AI output before it goes out?
Yes, and this is the piece that protects the firm, not just the
client. The American Bar Association’s Formal Opinion 512, issued July
29, 2024, maps generative AI use onto existing duties under the Model
Rules of Professional Conduct, including candor to the tribunal: a
lawyer remains personally responsible for verifying anything AI-assisted
before it gets filed. A policy that skips a human review requirement is
not just a client-confidentiality gap, it is the gap that has already
put firms in front of judges over AI-hallucinated citations elsewhere in
the profession. The review step does not need to be complicated. It
needs to exist, and it needs to say who is responsible for it on a given
matter.
Who decides
which AI tools the firm actually uses?
Someone specific, not “IT will look into it eventually.” A vendor and
tool approval process names who evaluates a new AI tool before anyone at
the firm is allowed to use it on client work, what that evaluation
actually checks, and who has final sign off. Without this, the real
approval process becomes whichever staff member downloads the tool
first, and the firm finds out what it agreed to after the fact instead
of before.
Does the policy
need a training requirement?
It does, because a policy nobody was trained on is a policy that
exists on paper and nowhere else. Training does not need to be
elaborate. It needs to happen before someone touches an AI tool on
client work, not sometime after, and it needs a record that it happened.
A written policy with no training behind it puts the firm in the
position of enforcing a rule that staff were never actually told
about.
What happens if something
goes wrong?
The policy needs an answer to this before it needs one, not after.
Who gets told first if an AI tool touched information it should not
have. What happens next, and how fast. Firms write incident response
plans for data breaches as a matter of course. An AI policy needs the
same instinct applied to a narrower, more specific risk: the tool that
got used on the wrong thing.
What
can a firm actually borrow from Simpatico’s own AI policy?
Our own approach, since we built and use one. Every Simpatico
employee went through required AI training and signed a written company
AI use policy before using AI tools on the job. That is not a
hypothetical framework, it is what we actually require internally before
anyone here touches an AI tool on client work: which tools are approved,
what data can and cannot go into them, and who signs off before a new
tool gets added. If your firm does not have a written policy yet, the
fact that we built one, trained our own staff on it, and required sign
off before anyone used an AI tool is a reasonable starting template for
the shape yours could take.
Why does
client disclosure belong in this policy too?
Because clients want to know, and most firms are not telling them.
Clio’s 2025 report found 78% of clients want AI use disclosed to them,
and only 18% of law firms say they always disclose it. That gap sits at
the center of our Legal AI Market Research Report, which walks through
the adoption data, the disclosure gap, and what it means for a firm’s
billing conversations and malpractice exposure in more depth than fits
here. A disclosure line in the policy, when AI use gets mentioned to a
client and by whom, closes a real gap most firms have not written down
anywhere.
How does
Simpatico think about this differently?
The same way we approach the rest of a firm’s technology,
infrastructure and process first, then the policy that governs what sits
on top of it. We are not an AI agency selling a template, we are an MSP
that already runs a proven AI-for-Legal-Services practice, the same
practice behind the Microsoft Copilot case management deployment Pax8
published as a third-party case study. That is part of why we describe
ourselves as evolving from a managed services provider into what we call
a Managed Intelligence Provider, MIP for short, the same partner
handling a firm’s technology, applied to making sure the AI policy
actually holds up in practice and not just on paper.
What should a firm do
with this today?
Do not try to write the whole thing in one sitting. Start with the
two pieces that are doing the most work: what data never goes into an AI
tool, and who has to sign off before a new one gets added. Get those two
down in writing this week. The training requirement, the review step,
and the incident plan can follow once the first two are settled, and
settling them first is what keeps the rest from being guesswork.
Is this legal advice?
No. We are not your firm’s ethics counsel, and this post is not legal
advice about your specific professional responsibility obligations. Talk
to your bar association or ethics counsel about what your jurisdiction
requires from a written policy. What we can help with is the technology
side, the tools, the data handling, and the approval process that a
working AI policy actually depends on.
If your firm is ready to put a real policy in place instead of a
placeholder, that is worth a real conversation. Schedule
a Strategy Session
Does your firm have a written AI policy yet, or is it still an
unwritten rule everyone is guessing at? Tell us in the comments.