Legal AI & Compliance

Your Firm's AI Policy Needs Six Pieces. Most Have Two.

Most firms with an AI policy are missing at least two or three of the six pieces it actually needs — and most firms don't have one written down at all. Here's what belongs in it, and what doesn't.

6
Pieces a real AI policy needs
53%
Of firms have no AI policy, or aren't sure
78%
Of clients want AI use disclosed to them
Published September 8, 2026 Simpatico Systems Legal AI & Compliance 10 Min Read

A law firm's AI policy needs six real pieces to do its job: a plain statement of acceptable use, a clear line on what data can never go into an AI tool, a human review requirement before AI-assisted work goes out under the firm's name, a defined process for approving any new AI tool before staff can use it, a training requirement so the policy is not just a document nobody read, and a plan for what happens if something goes wrong.

Most firms that have a policy at all are missing at least two or three of these. Most firms do not have one written down at all.

This is not legal advice, and the specific obligations your firm has around client data and professional responsibility are between your firm and your bar association's ethics guidance. What follows is the operational and technology side of that decision — the actual pieces a policy needs to hold together.

Key Takeaways

  • A working AI policy needs six pieces: acceptable use, prohibited data categories, human review before work goes out, a tool-approval process, a training requirement, and an incident response plan.
  • Clio's 2025 Legal Trends Report found 53% of legal professionals say their firm has no AI policy, or aren't sure if one exists, while 82% plan to increase their AI use over the next 12 months.
  • The ABA's Formal Opinion 512 (July 29, 2024) confirms a lawyer remains personally responsible for verifying AI-assisted work before it's filed — the reason a human review step is non-negotiable.
  • 78% of clients want AI use disclosed to them, but only 18% of law firms say they always disclose it.
  • Simpatico requires every employee to complete AI training and sign a written AI use policy before using AI tools on the job — a working internal template firms can borrow the shape of.

The Six Pieces, At A Glance

Acceptable Use

Which tools are approved, for which tasks, and what's off limits regardless of the tool.

Prohibited Data

What can never go into an AI tool: client-identifying, case-specific, or privileged information.

Human Review

A named review step before any AI-assisted work goes out under the firm's name.

Tool Approval

Who evaluates and signs off on a new AI tool before staff can use it.

Training

A requirement, with a record, before anyone touches an AI tool on client work.

Incident Plan

Who gets told first, and what happens next, if a tool touches information it shouldn't.

Why Don't More Law Firms Have A Written AI Policy?

Because writing one down forces decisions that are easier to leave vague. Clio's 2025 Legal Trends Report found 53% of legal professionals say their firm has no AI policy, or they are not sure if it has one. That is not a small gap. It means more than half the industry is either operating with no rules or operating with rules nobody can point to.

The same report found firms are not standing still on AI use while they figure this out. Eighty-two percent of legal professionals plan to increase their AI use over the next 12 months. A firm without a written policy is not a firm where nobody is using AI. It is a firm where everyone is deciding the rules for themselves, tool by tool, one staff member at a time.

What Counts As Acceptable Use Of AI At A Law Firm?

It starts with naming which tools are approved and for what. A policy that just says "use AI responsibly" is not a policy, it is a wish. An acceptable use section names the specific tools staff are cleared to use, what tasks each one is cleared for, and what is explicitly off limits regardless of the tool. Drafting a first pass of a routine internal memo is a different risk category than drafting a filing that goes to a court. The policy should say so directly instead of leaving staff to guess where a given task falls.

What Data Should Never Go Into An AI Tool?

Anything client-identifying, case-specific, or covered by attorney-client privilege does not belong in a tool without a real business data agreement behind it, and it certainly does not belong in a free consumer account someone signed up for on their own. That includes client names paired with case facts, draft settlement positions, internal strategy discussions, anything under a protective order, and documents produced in discovery. This is the section most firms already have some version of, even informally. The mistake is leaving it as a verbal rule instead of writing down the specific categories, because a verbal rule does not survive a new hire's first week.

Does A Human Need To Review AI Output Before It Goes Out?

Yes, and this is the piece that protects the firm, not just the client. The American Bar Association's Formal Opinion 512, issued July 29, 2024, maps generative AI use onto existing duties under the Model Rules of Professional Conduct, including candor to the tribunal: a lawyer remains personally responsible for verifying anything AI-assisted before it gets filed. A policy that skips a human review requirement is not just a client-confidentiality gap, it is the gap that has already put firms in front of judges over AI-hallucinated citations elsewhere in the profession. The review step does not need to be complicated. It needs to exist, and it needs to say who is responsible for it on a given matter.

A lawyer remains personally responsible for verifying anything AI-assisted before it gets filed.
— ABA Formal Opinion 512, July 29, 2024

Who Decides Which AI Tools The Firm Actually Uses?

Someone specific, not "IT will look into it eventually." A vendor and tool approval process names who evaluates a new AI tool before anyone at the firm is allowed to use it on client work, what that evaluation actually checks, and who has final sign off. Without this, the real approval process becomes whichever staff member downloads the tool first, and the firm finds out what it agreed to after the fact instead of before.

Does The Policy Need A Training Requirement?

It does, because a policy nobody was trained on is a policy that exists on paper and nowhere else. Training does not need to be elaborate. It needs to happen before someone touches an AI tool on client work, not sometime after, and it needs a record that it happened. A written policy with no training behind it puts the firm in the position of enforcing a rule that staff were never actually told about.

What Happens If Something Goes Wrong?

The policy needs an answer to this before it needs one, not after. Who gets told first if an AI tool touched information it should not have. What happens next, and how fast. Firms write incident response plans for data breaches as a matter of course. An AI policy needs the same instinct applied to a narrower, more specific risk: the tool that got used on the wrong thing.

What Can A Firm Actually Borrow From Simpatico's Own AI Policy?

Our own approach, since we built and use one. Every Simpatico employee went through required AI training and signed a written company AI use policy before using AI tools on the job. That is not a hypothetical framework, it is what we actually require internally before anyone here touches an AI tool on client work: which tools are approved, what data can and cannot go into them, and who signs off before a new tool gets added. If your firm does not have a written policy yet, the fact that we built one, trained our own staff on it, and required sign off before anyone used an AI tool is a reasonable starting template for the shape yours could take.

Why Does Client Disclosure Belong In This Policy Too?

Because clients want to know, and most firms are not telling them. Clio's 2025 report found 78% of clients want AI use disclosed to them, and only 18% of law firms say they always disclose it. That gap sits at the center of our Legal AI Market Research Report, which walks through the adoption data, the disclosure gap, and what it means for a firm's billing conversations and malpractice exposure in more depth than fits here. A disclosure line in the policy — when AI use gets mentioned to a client and by whom — closes a real gap most firms have not written down anywhere.

78% Want To Know

Clients who want AI use disclosed to them, per Clio's 2025 Legal Trends Report.

18% Actually Disclose

Law firms that say they always disclose AI use to clients. That gap is the disclosure problem.

How Does Simpatico Think About This Differently?

The same way we approach the rest of a firm's technology: infrastructure and process first, then the policy that governs what sits on top of it. We are not an AI agency selling a template, we are an MSP that already runs a proven AI-for-Legal-Services practice, the same practice behind the Microsoft Copilot case management deployment Pax8 published as a third-party case study. That is part of why we describe ourselves as evolving from a managed services provider into what we call a Managed Intelligence Provider, MIP for short — the same partner handling a firm's technology, applied to making sure the AI policy actually holds up in practice and not just on paper.

What Should A Firm Do With This Today?

Do not try to write the whole thing in one sitting. Start with the two pieces that are doing the most work: what data never goes into an AI tool, and who has to sign off before a new one gets added. Get those two down in writing this week. The training requirement, the review step, and the incident plan can follow once the first two are settled, and settling them first is what keeps the rest from being guesswork.

Frequently Asked Questions

What are the six pieces of a law firm AI policy?
A plain statement of acceptable use, a clear line on what data can never go into an AI tool, a human review requirement before AI-assisted work goes out under the firm's name, a process for approving new AI tools, a training requirement, and a plan for what happens if something goes wrong.
Do most law firms have a written AI policy?
No. Clio's 2025 Legal Trends Report found 53% of legal professionals say their firm has no AI policy, or aren't sure if one exists, while 82% plan to increase their AI use over the next 12 months.
Does a lawyer have to review AI-generated work before it goes out?
Yes. The ABA's Formal Opinion 512, issued July 29, 2024, maps generative AI use onto existing duties under the Model Rules of Professional Conduct, including candor to the tribunal — a lawyer remains personally responsible for verifying anything AI-assisted before it's filed.
What client data should never go into an AI tool?
Anything client-identifying, case-specific, or covered by attorney-client privilege — including client names paired with case facts, draft settlement positions, internal strategy discussions, anything under a protective order, and documents produced in discovery — unless a real business data agreement is in place.
Who should approve new AI tools at a law firm?
Someone specific and named in the policy, not "IT will look into it eventually." A vendor and tool approval process should name who evaluates a new AI tool, what the evaluation checks, and who has final sign-off before staff can use it on client work.
Do clients want to know if their law firm uses AI?
Yes. Clio's 2025 report found 78% of clients want AI use disclosed to them, but only 18% of law firms say they always disclose it.
Is this blog post legal advice?
No. This is not legal advice about a firm's specific professional responsibility obligations — those questions belong with a firm's bar association or ethics counsel. This covers the operational and technology side: the tools, data handling, and approval process a working AI policy depends on.
Where should a firm start if it doesn't have a policy yet?
With the two pieces doing the most work: what data never goes into an AI tool, and who has to sign off before a new tool gets added. Get those two down in writing first; the training requirement, review step, and incident plan can follow.

Put It In Writing

If your firm is ready to put a real policy in place instead of a placeholder, that's worth a real conversation. We help with the technology side — the tools, the data handling, and the approval process a working AI policy actually depends on.

  • Which AI tools are already in use
  • What data needs a hard line
  • A policy your staff are actually trained on
30 minutes · No pressure · No obligation