We respect attorney-client confidentiality. No tracking pixels in our emails.
We respect attorney-client confidentiality. No tracking pixels in our emails.

A step-by-step guide to building an AI policy for law firms, covering approved tools, data handling, client disclosure, and ABA ethics compliance.
Material claims in this article were checked against the public sources below on 2026/07/26.
Move from this guide to practical legal AI tool shortlists and comparison pages.
A second-year associate used ChatGPT to draft a client memo, pasted the output into an email, and sent it before checking. The memo cited a case that does not exist. Nobody had told her not to. The firm had no policy.
The partner found out when the client called. The associate spent three hours finding the source case — a case that was not there. The client lost confidence. The firm spent more time managing the aftermath than the memo would have taken to write from scratch.
This is our guide to building an AI policy for law firms in 2026, written for managing partners, general counsel, and legal ops managers responsible for AI governance.
LawyerAI built this guide. We earn no affiliate revenue from these tools.
Here are the 4 rules we set for ourselves before writing this:
We re-review this list every quarter.
Short answer: BigLaw and mid-size firms need a formal AI governance document reviewed by IT security and ethics counsel. Solo practitioners and small firms need a one-page approved-tools list plus a verification checklist. The structure scales down; the core obligations do not.
Bar associations are not waiting. As of 2026, over 20 state bars have issued formal guidance on attorney AI use. The ABA's Formal Opinion 512 (2023) made clear that using AI tools to assist in client work triggers existing competence obligations under Model Rule 1.1. That means understanding how the tool works, verifying its output, and protecting client confidences.
The risk is not just malpractice. It is bar discipline. Submitting a hallucinated citation to a court — even unknowingly — has resulted in sanctions in jurisdictions including New York, Texas, and Florida. Judges have made clear they will not accept "I did not know the AI fabricated it" as a defense when the attorney signed the filing.
A written AI policy does two things. First, it forces the firm to make deliberate decisions about which tools are appropriate, rather than letting individual attorneys make those decisions ad hoc. Second, it creates a documented compliance framework that demonstrates professional responsibility in the event of an ethics inquiry.
We score AI tools across five dimensions, each rated 1-5. See /blog/how-we-score-legal-ai-tools for full methodology.
For AI policy purposes, Security and Accuracy are the dimensions that most directly determine which tools belong on your approved list.
| Tool | Category | Starting Price | Best For | 5D Score |
|---|---|---|---|---|
| Harvey AI | Legal AI platform | $140K+/year | Enterprise BigLaw AI | 4.2/5 |
| Lexis+ AI | Legal research | Not published | Research-heavy practices | 4.0/5 |
| Spellbook | Contract review | $89/seat/month | Law firms using Word | 3.8/5 |
Your policy must begin with a clear boundary: which AI tools are covered, and which are prohibited without explicit approval.
The cleanest approach is an approved tools list — a document that names every AI tool the firm has vetted and permits attorneys to use. Anything not on the list requires approval before use. This is more manageable than trying to enumerate prohibited tools, because the prohibited category would need to include every general-purpose AI that an attorney might be tempted to use: ChatGPT, Google Gemini, Claude, Copilot in personal Microsoft accounts, and any browser-based AI tool.
Your approved list should distinguish between:
An example approved list entry: "Harvey AI — Approved for: legal research, memo drafting, contract analysis. Data handling: SOC 2 Type II certified, no training data retention confirmed via signed DPA. Approved by: [Name, Date]."
The policy must specify which tasks require a human review gate before the output reaches a client or court.
Consider three categories:
Permitted without additional review gate: Internal knowledge management queries, time tracking assistance, scheduling, non-client-facing document organization.
Permitted with attorney review before delivery: Research memoranda, contract drafts, form pleadings, intake summaries. The attorney must verify AI-generated citations against the primary source before submitting to client or court.
Not permitted even with review: Signing AI-generated documents without substantive attorney review of every clause, submitting AI-generated briefs without independently verifying every citation, using AI to communicate directly with opposing counsel or courts without attorney oversight.
ABA Model Rule 1.1 requires competence, defined to include keeping abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology. This means attorneys cannot delegate the verification step — they must understand what the tool produces and confirm it.
This is the section where most firms underinvest. The core question is: when an attorney pastes client documents into an AI tool, what happens to that data?
The answers vary dramatically. General-purpose AI tools — ChatGPT, Gemini, Claude.ai (consumer) — typically use conversation data to improve their models unless enterprise agreements are in place. This means client confidences could, in theory, be used in training data. That is an attorney-client privilege problem.
Legal-specific enterprise tools are different. Harvey AI operates under a contract that includes zero data retention: the firm's data is processed and not stored or used for model training. Lexis+ AI similarly operates under LexisNexis's enterprise data terms. Spellbook has a no-training data policy under its paid plans.
Your policy should specify:
The policy should also address geographic restrictions. EU clients may have GDPR implications for where data is processed. Some government clients require FedRAMP-authorized tools only.
Every AI output that reaches a client or a court must pass through attorney verification. The policy should define what verification means in practice.
For legal research: the reviewing attorney must confirm that each cited case exists, that the cited proposition accurately represents the holding, and that the case has not been overruled or distinguished in a way that affects the argument. Checking a citation in Westlaw or Lexis takes thirty seconds per case. It is not optional.
For contract drafts: the reviewing attorney must read every clause, not just the AI-highlighted changes. AI contract review tools such as Spellbook or Ironclad flag issues they detect; they do not guarantee that they have detected all issues.
The policy should create a specific workflow: AI draft → attorney review → attorney-marked version delivered to client. The attorney's name goes on the work product. That has not changed.
Reference the audit log capabilities of approved tools. Enterprise tools such as Harvey and Ironclad maintain logs of AI queries and outputs. These logs may become relevant in a malpractice or ethics proceeding. Knowing that logs exist — and retaining them appropriately — is part of the policy.
This is the most unsettled area in legal AI ethics. Bar opinions vary by jurisdiction, and the area is evolving rapidly.
The conservative approach — which the ABA and most state bars implicitly support — is to disclose AI use when:
The practical approach is to update your standard engagement letters to address AI use. A sample clause: "Our firm uses AI-assisted tools to improve the quality and efficiency of our work. These tools may be used to assist with legal research, document review, and drafting. All AI-generated work product is reviewed and verified by a licensed attorney before delivery to you."
ABA Formal Opinion 512 (2023) does not impose a blanket disclosure obligation, but notes that existing duties of communication (Rule 1.4) may require disclosure in specific circumstances. If AI use materially affects the cost or scope of the work, the client should know.
Some courts have gone further. Several federal judges have issued standing orders requiring attorneys to certify whether AI was used in preparing any filing. Your policy should track these requirements by jurisdiction and build compliance into your filing workflows.
ABA Model Rule 1.1 requires technological competence. For AI tools, this means understanding not just how to operate the tool, but what kinds of errors the tool is prone to make.
Your policy should specify minimum training requirements before an attorney is permitted to use an approved AI tool on client matters:
The ai-competency-lawyers standard is not about being a power user. It is about understanding hallucination risk, knowing how to verify output, and knowing when to not use the tool (complex, novel legal questions where AI training data may be thin or outdated).
Document completion of training. Create a record that each attorney has completed training before gaining access to approved tools. This documentation matters if a discipline complaint is ever filed.
An AI policy without an owner is not a policy. Someone must be responsible for:
For large firms, this typically sits with a legal technology committee or legal operations function, with ethics counsel involved in any policy changes that touch on professional responsibility. See /solutions/big-law for enterprise governance structures.
For small firms, a single partner can own the policy, with a quarterly review calendar item to check for new bar guidance and update the approved tools list. See /solutions/small-law-firms for a lightweight governance structure.
The ai-governance-legal standard is developing. A firm that documents its governance process — even a simple one — is in a substantially better position than a firm with no process at all.
The following is a sample template for a small firm's AI use policy. Adapt it to your jurisdiction and practice.
[FIRM NAME] AI Use Policy — Effective [Date]
1. Purpose. This policy governs the use of artificial intelligence tools in connection with client matters and firm operations.
2. Approved Tools. Attorneys may use only tools listed in Appendix A (Approved AI Tools). Use of any other AI tool in connection with client matters requires prior written approval from [Partner/Legal Ops].
3. Prohibited Uses. No AI tool, approved or otherwise, may be used to: (a) enter client confidential information unless the tool appears in Appendix A with a confirmed zero-retention data processing agreement; (b) generate content submitted to a court or client without attorney review and verification; (c) communicate directly with clients, opposing counsel, or courts.
4. Verification. Before delivering any AI-assisted work product to a client or filing, the responsible attorney must verify: (a) all citations exist and accurately reflect the cited proposition; (b) all factual statements are accurate; (c) the work product meets the attorney's independent professional judgment.
5. Client Disclosure. [Insert disclosure approach per jurisdiction requirements and firm policy.]
6. Data Handling. Client confidential information may be entered only into tools in Appendix A. Attorneys must not use personal or consumer-tier accounts of any AI tool for client work.
7. Training. Attorneys must complete required training before using approved tools on client matters. Training records are maintained by [Name/Role].
8. Policy Updates. This policy is reviewed [quarterly/annually] or when relevant bar guidance is issued. Questions: contact [Name/Email].
If you are a BigLaw or Am Law 200 firm: You need a formal AI governance document reviewed by IT security, ethics counsel, and firm management. Approved tools should go through a vendor security assessment process. Consider a dedicated legal technology committee with quarterly review cycles. Compare Harvey AI vs Paxton AI to understand enterprise-tier tool requirements.
If you are a small firm (2-25 attorneys): You need a one-to-two page approved tools list with clear data handling rules and a client disclosure clause in your engagement letter. Quarterly review by one designated partner. See /solutions/small-law-firms.
If you are a solo practitioner: You need a minimal policy: a list of the tools you use and have vetted, a personal commitment to verify all AI output before delivery, and a clause in your engagement letter addressing AI use. The ABA and most state bars do not require more than this — but they do require this.
If you handle government or regulated-industry clients: Add jurisdiction-specific requirements (FedRAMP, HIPAA, CJIS) to your policy. The approved tools list will be shorter, and the review process for adding tools will be more rigorous.
Do law firms legally need an AI policy? No statute requires it — but professional responsibility obligations effectively compel one. ABA Model Rule 1.1 (competence), Rule 1.6 (confidentiality), and Formal Opinion 512 (2023) collectively require attorneys to understand AI tools they use, protect client data from unauthorized disclosure, and verify AI output. An AI policy is the documented mechanism for meeting those obligations. Firms without one are exposed in the event of an ethics complaint or malpractice claim.
What should be on the approved tools list? Start with tools that have (a) a signed data processing agreement confirming zero data retention, (b) SOC 2 Type II certification, and (c) legal-specific training or customization. Enterprise-grade tools like Harvey AI, Lexis+ AI, and Spellbook (paid tier) meet these criteria. General-purpose consumer AI tools (ChatGPT free tier, Claude.ai without enterprise agreement) do not, and should not appear on an approved list for client-matter use.
How do I handle client disclosure of AI use? Update your standard engagement letter to include a clause disclosing that the firm uses AI tools and that all AI-generated work is reviewed by a licensed attorney. For jurisdictions where courts require filing certifications about AI use, build a certification step into your filing workflow. When AI materially affects scope or cost, ABA Rule 1.4 (communication) may require proactive disclosure. When in doubt, disclose.
How often should the policy be updated? Minimum: annually. Better: quarterly check-in against new bar guidance. The ABA and state bars are issuing AI-specific opinions regularly. A firm whose AI policy cites only 2023 guidance in 2026 may have significant gaps. Designate one person to monitor bar announcements and flag relevant guidance for policy review.
Who should own AI policy at a law firm? At large firms: a legal technology committee or legal operations function, with ethics counsel sign-off on professional responsibility provisions. At small firms: a designated partner. At solo practices: the attorney themselves. The owner is responsible for maintaining the approved tools list, monitoring bar guidance, and handling incidents. Without a named owner, the policy will not be maintained.
LawyerAI evaluations are independent. We do not accept payment that influences our editorial scores. Featured placements are clearly labeled and do not affect our 5-dimension methodology (Accuracy / Speed / Usability / Value / Security). We re-review tools every 6 months.
If you believe any information is inaccurate, contact editor@lawyerai.directory.
| Clio | Practice management | $99/mo (Essentials) | Small to mid-size firms | 4.1/5 |
| Ironclad | Contract lifecycle management | $30K+/year | In-house CLM | 4.0/5 |