Start HiringCreate accountTalk to us
The BlogEthics & Compliance

High AI Use, Low AI Governance: Why Your Firm Needs an AI Policy Now

By Kristin Tyler, Co-Founder LawclerkSep 30, 20269 min read

High AI Use, Low AI Governance: Why Your Firm Needs an AI Policy Now

Eight in 10 lawyers are already using AI. That number was 23% just two years ago — a 3.4x jump. But adoption has sprinted ahead of professional oversight: fewer than half of legal professionals report being sufficiently trained, and only about 21% of firms have adopted AI firm-wide.

The gap between use and governance is where malpractice exposure, sanctions, and reputational harm live.

Infographic showing 78% of attorneys use AI, under 50% are sufficiently trained, and only 21% have firm-wide adoption — a 57-point gap. Usage without policy equals risk.
Source: Litify 2025; ABA Legal Industry Report 2025.

The good news is you do not need to become a technologist to close it. You need to become minimally competent in how generative AI works, where it fails, and how your existing ethical duties apply — then put a few concrete safeguards in place. Here’s where to start.


Know What You’re Actually Working With

In practice, firms encounter three overlapping categories of AI:

  • Generative AI (GenAI) — Tools like ChatGPT, Copilot, and legal-specific assistants that create text, summaries, or drafts from prompts. They are probabilistic: they predict plausible language, not guaranteed truth.
  • Predictive AI and machine learning — Systems that classify documents, score privilege logs, or flag billing anomalies. These tools are only as good as their training data and validation.
  • Embedded AI — Features already built into the research platforms, document management systems, and practice management software your firm uses today.

The mechanics matter because they explain the risk. A large language model is trained on vast text and generates a statistically likely response to your prompt. Unless it is connected to authenticated databases or your own uploaded documents (retrieval-augmented generation, or RAG), it does not “look up” the law the way Westlaw does. That’s how hallucination happens: the model can invent cases, quotes, rules, or facts with complete confidence.

ABA Model Rule 1.1 already requires competence, including understanding the benefits and risks of the technology you use in representation, and 39 jurisdictions have adopted technology-competence commentary.

In July 2024, the ABA issued Formal Opinion 512, its first formal guidance on generative AI. The standard it sets is simple to state and easy to skip in practice: AI drafts. Lawyers decide.

AI drafts. Lawyers decide. — ABA Formal Opinion 512

Protect Confidential Client Information

Free, consumer-grade AI tools were built for consumers, not law firms. They typically come with weaker or shifting terms of service, less transparency about data retention and model training, and limited contractual remedies if something goes wrong.

Florida Ethics Opinion 24-1 puts it directly: before entering client information into any tool, lawyers must understand whether the program is self-learning — meaning your input could shape what it tells other users later.

California’s Practical Guidance advises reviewing terms of use, avoiding confidential input into tools without adequate protections, and consulting cybersecurity resources when in doubt.

Before any client data goes into an AI tool, get the vendor to confirm, in writing:

  • Client data is not used to train public models, or training is contractually disabled
  • Retention settings meet your firm’s policy, with zero retention where possible
  • Encryption in transit and at rest, with SOC 2 or an equivalent attestation
  • Access controls and audit logs for firm administrators
  • Acceptable data residency (U.S. or client-required region)
  • A BAA or DPA if health or other regulated data applies
  • Clear incident notification terms

Then build data-minimization habits across the team: strip identifiers and use “Client A” instead of a real name, never paste privileged strategy into an unvetted tool, use separate tenants or workspaces per client where the platform allows it, and train everyone on one rule — if you would not email it to a stranger, do not prompt it into an AI tool.

It’s also worth a five-minute call to your malpractice carrier; insurers are updating their underwriting questions about AI, and that call can clarify what’s covered and what documentation supports it.


Put a Policy in Writing — and Supervise Accordingly

AI policy is the modern equivalent of your email, BYOD, and social media policies. It also fulfills your obligations under Rules 5.1 and 5.3, which require reasonable efforts to ensure that everyone you supervise — associates, paralegals, staff, and contractors — conforms to the Rules of Professional Conduct.

A firm AI policy should cover eight things: scope (who it applies to), approved tool tiers (green/approved, yellow/needs partner approval, red/prohibited), prohibited conduct (like pasting identifiable client data into consumer ChatGPT), a verification protocol requiring mandatory citation and record checks before filing, when and how AI use is disclosed to clients, a no-double-billing rule for how efficiency gains are passed through, an incident-reporting process for things like a wrong citation or a vendor breach, and a training plan with an attendance log.

You can roll this out in 90 days:

Phase Action
Days 1–30 Appoint an AI governance lead; inventory current tool use
Days 31–60 Publish the policy; train all personnel; approve a vendor list
Days 61–90 Audit sample work product; update engagement templates

Address AI Use in Your Engagement Agreement

Rule 1.4 requires reasonable communication with clients, and best practice is to disclose AI use and get consent before confidential information is processed by a third-party tool — particularly since Florida, California, New York, and Texas each now have guidance touching on client consent for GenAI use.

Your engagement letter should address whether the firm uses, may use, or does not use GenAI on the matter; what types of use are in play (drafting, research, transcription, e-discovery, marketing); the safeguards in place (enterprise tools, no training on client data, human attorney review); the client’s options (opt-out, escalation for sensitive issues); and how billing reflects attorney skill and effort rather than charging as if AI output were fully lawyer-drafted from scratch. Sample language, adapted with your ethics counsel:

“The Firm may use secure, firm-approved generative AI tools to assist with legal research, drafting, and administrative tasks in your matter. All AI-assisted work product is reviewed by a licensed attorney before it is relied upon, shared with opposing counsel, or filed with a court. The Firm will not enter your confidential information into any AI tool that does not provide contractual confidentiality protections comparable to those the Firm uses for other legal-technology vendors. You may request that specific tasks be performed without generative AI.”


Close the Gap Before It Closes You

High usage with low governance is not a temporary phase — it’s the current state of the profession, and it’s a liability sitting in plain sight. Firms that govern AI well recapture time, improve throughput, and serve clients faster without sacrificing quality. Firms that use AI casually — free tools, no verification, no client communication — invite exactly the exposure this article describes.

You don’t have to build this infrastructure alone. Explore our full whitepaper, How AI Is Reshaping the Attorney Role, for the complete governance framework, jurisdiction-by-jurisdiction guidance, and a ready-to-use firm AI governance checklist.

This article was developed with the assistance of AI tools and edited by Kristin Tyler.


FAQ: AI Governance, Ethics, and Law Firm Policy

What is AI governance for a law firm?

AI governance is the set of policies, approvals, and supervision practices that control how a firm’s attorneys and staff use artificial intelligence tools. It typically includes an approved-tool list, rules about what can and cannot be entered into an AI system, a verification step before AI-assisted work is relied on or filed, client disclosure practices, and a training program — the same structure firms already use for email, BYOD, and social media policies.

Why do so few law firms have an AI policy if adoption is this high?

Eight in 10 lawyers now use AI in some form, up from 23 percent just two years earlier, but only about 21 percent of firms have adopted AI firm-wide and fewer than half of legal professionals say they’ve been sufficiently trained. Governance has simply not kept pace with how fast individual attorneys picked up the tools, which is what creates malpractice, confidentiality, and supervision risk.

What ethics rules apply to AI use in legal practice?

ABA Model Rule 1.1 requires competence, including understanding the benefits and risks of the technology used in representation, and 39 jurisdictions have adopted technology-competence commentary. Rules 5.1 and 5.3 require reasonable supervision of everyone at the firm — associates, paralegals, staff, and contractors — and Rule 1.4 requires reasonable communication with clients about how their matter is being handled, including AI use. The ABA’s Formal Opinion 512, issued in July 2024, is the first formal guidance tying these duties directly to generative AI.

What is AI hallucination, and why does it matter for lawyers?

Hallucination is when a generative AI tool produces a confident, plausible-sounding answer that is factually wrong — inventing a case citation, misquoting a rule, or fabricating a fact. It happens because most general-purpose models predict statistically likely language rather than retrieving verified law, unless the tool is connected to authenticated databases or your own documents through retrieval-augmented generation (RAG). This is why every AI policy needs a mandatory citation and record-verification step before anything goes to a client or a court.

Is it safe to use free AI tools like consumer ChatGPT with client information?

Not without verification. Free, consumer-grade tools are built for general use, not law firm confidentiality obligations, and often come with weaker terms of service and less transparency about data retention or model training. Florida Ethics Opinion 24-1 requires lawyers to confirm whether a tool is self-learning — meaning client input could shape what it tells other users — before entering any client information, and California’s guidance recommends reviewing terms of use and avoiding confidential input into tools without adequate protections.

Do I need client consent to use AI on their matter?

Best practice, and increasingly the expectation under Rule 1.4, is yes. Florida, California, New York, and Texas all have guidance touching on client consent for generative AI use, and the safest approach is to address AI directly in the engagement letter — what types of AI use are in play, what safeguards are in place, and how the client can opt out of AI on sensitive tasks.

What should a law firm AI policy actually cover?

Eight things: scope (who the policy applies to), approved tool tiers (green/approved, yellow/needs partner approval, red/prohibited), prohibited conduct such as pasting identifiable client data into consumer tools, a mandatory verification protocol before filing, client disclosure practices, a no-double-billing rule so efficiency gains are passed through rather than billed as full attorney time, an incident-reporting process, and a training plan with an attendance log.

How long does it take to roll out an AI governance program?

A firm can build a working program in about 90 days: appoint an AI governance lead and inventory current tool use in the first 30 days, publish the policy, train all personnel, and approve a vendor list in days 31 through 60, then audit sample work product and update engagement templates in the final 30 days.

Share

Ready to scale

Get the help you need. Skip the overhead

Free to get started, create your account now.