Artificial intelligence has transformative potential for enhancing efficiency for law firms, but its adoption requires thoughtful care. Law firms have an ethical responsibility to protect confidentiality and maintain the highest standards. By adopting a firm-wide AI policy, law firms can ensure that clients benefit from the enhancements offered by AI while protecting against risks. To help law firms with controls-driven AI integration, Jaffe has developed a complimentary comprehensive AI policy template.

We offer this policy template for law firms to benefit from our thorough consideration of how legal organizations can systematize AI adoption. For further assistance with the integration and adoption of AI in law firm communications, please contact us at info@jaffepr.com.

 

 

 

 


 

[FIRM NAME]

Artificial Intelligence (AI) Acceptable Use & Governance Policy

Effective Date: [Month Day, Year]
Policy Owner: NAME/ROLE/DEPARTMENT
Last Reviewed: [Month Day, Year]
Next Review Date: [Month Day, Year]

At [FIRM], we understand the great benefit and value that the introduction and rapidly evolving roles of artificial intelligence (“AI”) tools can offer to our clients and our firm. With national, state and local governments implementing varying AI laws, it is imperative to ensure understanding and consistency across the firm. Therefore, we have carefully developed a firm-wide policy that establishes standards for the safe, ethical, and professional use of AI tools in the delivery of our legal services and internal business operations.

This policy is intended to ensure that AI is used in a manner consistent with:

  • Attorney-client privilege, confidentiality, and work-product protections
  • Applicable rules of professional conduct and court rules
  • Client engagement obligations and contractual requirements
  • Firm cybersecurity and data governance standards
  • Accuracy, reliability, and accountability in legal work product

The policy covers all use of AI in legal research, drafting, discovery, case strategy, client communications, and administrative operations.

AI may improve efficiency and quality; however, AI is not a substitute for attorney judgment. Attorneys remain responsible for all legal services, work product, and communications provided to clients and courts.

Questions regarding this policy should be addressed to:

NAME/ROLE/DEPARTMENT
Phone:
Email:

[NOTE: Consider designating an "AI task force" to respond to questions and concerns about the use of AI within the Firm, requests for new tools, and violation reports, which could be established through a dedicated email address or other reporting mechanism.]

Scope

This policy applies to all personnel of [FIRM], including:

  • Attorneys (partners, associates, counsel)
  • Paralegals, legal assistants, and staff
  • Contract attorneys, interns, and temporary personnel
  • Any third party granted access to Firm systems or Firm data

This policy governs the use of all AI-enabled systems, including:

  • Enterprise-approved AI tools adopted by the Firm (“Enterprise AI”)
  • AI-enabled features in Firm-approved platforms (e.g., Microsoft 365, document management, research tools)
  • Public or consumer AI tools (subject to additional restrictions in the Approved Tools and Prohibited Tools section below)
  • AI tools used by third-party vendors on Firm matters

Definitions

Artificial Intelligence (“AI”): Software or systems that generate content, predictions, recommendations, or analyses based on large datasets or statistical models, including generative AI.

Enterprise AI: AI tools approved by the Firm and configured with enterprise security controls (e.g., single sign-on (“SSO”), multifactor authentication (“MFA”), contractual confidentiality protections, and no training on Firm or client data).

Client Confidential Information: Any information relating to a client or matter that is confidential, privileged, protected by work-product doctrine, or subject to contractual/ethical restrictions.

Firm Confidential Information: Internal Firm information not publicly available, including policies, pricing, strategy, financials, credentials, and sensitive operational data.


Policy Principles

All AI use must comply with the following principles:

  1. Client confidentiality and privilege are paramount.
  2. Humans remain accountable for all legal work.
  3. AI output is not authoritative and must be verified.
  4. No AI tool is used unless approved or permitted under this policy.
  5. Court filings must be accurate, traceable, and compliant with court rules.
  6. Billing must be fair, transparent, and consistent with engagement terms.

Roles and Responsibilities

Attorneys

Responsible for:

  • Supervising AI-assisted work
  • Reviewing and validating all substantive outputs used in legal advice, drafting, filings, or client communications
  • Ensuring compliance with privilege/confidentiality requirements
  • Confirming compliance with court rules and judge-specific orders

Firm’s Office of General Counsel (“OGC”) / Risk Management (or similar contact or role)

Responsible for:

  • Policy oversight, updates, and interpretation
  • Advising on client disclosure/consent requirements
  • Reviewing high-risk AI use cases and incident escalations

IT Department / Information Security

Responsible for:

  • Approving tools from a security standpoint
  • Maintaining access controls, logging, monitoring, and data loss prevention (“DLP”) safeguards
  • Investigating AI-related incidents
  • Staying updated on new technologies

Firm Leaders and Practice Group Leaders

Responsible for:

  • Identifying approved use cases and workflows
  • Developing training and best-practice guidance
  • Monitoring emerging legal standards and court requirements

NOTE: Federal, state, and local regulations and laws governing AI are frequently evolving. Be sure to follow laws and guidelines in each jurisdiction where the Firm has a presence, and include information about those laws or relevant links in this policy as appropriate. Determine internally who will be responsible for ongoing monitoring of developing laws and regulations, determining the impact they will have on the Firm’s AI infrastructure, and ensuring compliance.


Approved Tools and Prohibited Tools

Approved Tools

Only Firm-approved Enterprise AI tools may be used for Firm work involving:

  • Client matters
  • Client documents
  • Firm confidential materials
  • Any information not publicly available

OPTIONAL: List here or provide: Approved tools are maintained in Appendix A: Approved AI Tools List.

Prohibited Tools

Unless explicitly approved in writing by NAME/ROLE/DEPARTMENT, the following are prohibited for any Firm or client work:

  • Consumer/public AI tools where prompts may be retained or used to train models
  • AI tools lacking enterprise access controls (SSO/MFA)
  • Tools that transmit data through unapproved plug-ins/extensions
  • AI tools whose terms claim ownership rights over inputs or outputs in a manner inconsistent with Firm obligations

New tools may be considered for approval. Attorneys or staff must provide in writing the purpose and reason for using the tool to perform work tasks to NAME/ROLE/DEPARTMENT to request permission.

OPTIONAL: List here or provide: Prohibited tools are maintained in Appendix B: Prohibited AI Tools List.


Confidentiality, Privilege, and Data Handling Requirements (High Risk)

General Rule

No user may input, upload, or disclose Client Confidential Information or Firm Confidential Information into any AI system unless the system is approved as Enterprise AI and use is consistent with this policy and any client restrictions.

Data Minimization

When using Enterprise AI:

  • Use the minimum necessary information
  • Avoid client identifiers when feasible (names, docket numbers, unique facts)
  • Use placeholders or redaction when possible

Prohibited Inputs (including in Enterprise AI, unless specifically approved)

Users must not enter:

  • Highly sensitive personal data (SSNs, financial account numbers)
  • Protected health information (“PHI”)
  • Client trade secrets
  • Sealed or restricted court documents
  • Data subject to protective orders or “attorneys’ eyes only” restrictions
  • Any information subject to export control or sanctions laws

Retention and Logging

Enterprise AI use may be logged for compliance and security purposes. Users should assume that prompts and output may be retrievable in the event of:

  • Discovery obligations
  • Internal audits
  • Security incident review

Approved Use Cases (Examples)

The following are permitted uses of Enterprise AI, subject to attorney review:

  • Drafting outlines and first drafts of internal memos or briefs
  • Generating checklists, timelines, and issue spotters
  • Summarizing documents or transcripts using approved tools
  • Contract clause comparison and drafting suggestions
  • Editing for clarity, grammar, and format
  • Brainstorming deposition or interview questions
  • Preparing internal training materials
  • Creating matter management summaries (non-sensitive when possible)

Restricted or High-Risk Use Cases

The following uses require heightened scrutiny and may require written approval depending on the client/matter:

  • Legal conclusions presented as definitive without independent analysis
  • Jurisdiction-specific advice without source validation
  • Use in criminal or immigration matters involving liberty interests
  • Substantive advice in regulated fields (healthcare, securities, employment)
  • Any use involving sensitive client strategies or privileged communications
  • Use involving predictive analytics on judges, juries, or outcomes
  • AI-assisted drafting of public statements, press releases, or crisis communications

If uncertainty exists, users must consult:

  • Matter partner
  • Practice group leader
  • OGC / Risk

CRITICAL RISK AREAS

  • Court Filings and Litigation Conduct Standards
  • Client Communications and Consent
  • Billing and Timekeeping Standards

Court Filings and Litigation Conduct Standards (Critical Risk)

AI must never be used in a manner that compromises the accuracy or integrity of court filings.

Mandatory Verification Requirements

Before filing any document prepared with AI assistance, the responsible attorney must verify:

  • Veracity of all cited cases and accurate quotations thereof
  • Authorities, statutes, and regulations are current and correctly cited
  • Quotes match source documents exactly
  • All factual assertions are supported by the record
  • All defined terms and exhibits are accurate and consistent

No AI-generated citations may be used without confirmation in an authoritative source (e.g., Westlaw, LexisNexis, official reporters, PACER/CM/ECF).

Disclosure Requirements

Some courts require disclosure of AI use and/or certification that citations were verified. Attorneys must:

  • Review applicable local rules and standing orders
  • Comply with judge-specific requirements
  • Consult the Firm’s OGC / Risk if disclosure may be required

Prohibited Litigation Uses

AI must not be used to:

  • Fabricate evidence, exhibits, deposition transcripts, or witness statements
  • Alter images, audio, or video intended for use in litigation without express authorization and disclosure
  • Generate filings without attorney review
  • Create misleading depictions of real people or events

Client Communications and Consent (Critical Risk)

Client Disclosure

The Firm may use Enterprise AI to improve efficiency and quality. However, disclosure to clients may be required when:

  • The client’s confidential information is processed through a third-party AI vendor
  • Engagement terms prohibit or require disclosure of AI use
  • The client has issued outside counsel guidelines restricting AI
  • The use may materially affect the nature of the legal services

Client Restrictions

If a client prohibits AI use (or restricts categories of use), those restrictions must be:

  • Documented in the matter file
  • Communicated to the matter team
  • Followed without exception

Billing and Timekeeping Standards (Critical Risk)

AI changes how legal work is performed. Billing must remain consistent with ethical obligations, client agreements, and fairness.

No Billing for Non-Work

Users may not bill for time:

  • Not actually spent
  • Inflated due to AI efficiency
  • Representing “review” that did not occur

AI-Assisted Efficiency

If AI materially reduces time required, attorneys should bill:

  • Based on the time actually spent performing and reviewing the work
  • In compliance with the engagement arrangement (hourly, fixed fee, alternative fee)

Billing Narratives

If appropriate under client rules, attorneys may describe work as:

  • “Drafted and revised [document], including attorney review and validation.”
  • Avoid describing work as “AI-generated” unless required; do not misrepresent work performed.

Client Guidelines

Follow rules where clients require:

  • Prior consent
  • Disclosure
  • Special coding for AI-assisted work

Quality Control, Review, and Supervision

AI output may contain errors, hallucinations, bias, or omissions.

Required controls:

  • Attorneys must review AI output before use in any deliverable to independently verify information.
  • Use checklists for:
    • Citations
    • Quotes
    • Factual assertions
    • Formatting
    • Confidentiality compliance
  • High-risk work must undergo peer review, where appropriate.

Intellectual Property, Copyright, and Ownership

Users must avoid copyright or IP violations.

Rules:

  • Do not upload or copy proprietary content (client or third-party templates) into AI tools unless permitted.
  • Assume AI output may be non-original or similar to existing copyrighted content.
  • Review AI output for:
    • Plagiarism
    • Copyright infringement
    • Unintended disclosure of sensitive material
  • All AI-assisted work product created in the course of Firm engagement remains the Firm’s and/or client’s work product, as applicable; the use of AI does not alter ownership rights.

Bias, Fairness, and Ethical Use

AI may generate biased results.

Firm users must:

  • Evaluate output for bias, fairness, and inappropriate assumptions
  • Avoid use in a manner that could lead to discriminatory outcomes
  • Avoid automated profiling or outcome prediction involving:
    • juries
    • witnesses
    • protected classes
    • sensitive personal characteristics

Security Controls and Technical Requirements

All Enterprise AI use must comply with Firm security standards, including:

  • SSO and MFA
  • Approved devices only
  • No unapproved browser plug-ins/extensions
  • No data export from Enterprise AI to personal accounts
  • DLP and logging enabled, where available

Third-Party / Vendor Use of AI

If a vendor uses AI for Firm work or processes Firm/client data via AI, the vendor must:

  • Be approved under Firm vendor management processes
  • Agree in writing to:
    • confidentiality
    • security controls
    • data retention limits
    • no training on Firm/client data unless expressly permitted
    • breach notification requirements
  • Be subject to OGC / Risk and Security review

Training and Competency

All attorneys and staff must complete AI training, as conducted by NAME/DEPARTMENT:

  • At onboarding
  • Annually thereafter
  • Before using Enterprise AI on client matters

Training includes:

  • Policy review
  • Safe prompting and redaction
  • Verification and citation checking
  • Court filing and disclosure rules
  • Billing guidance
  • Vendor and confidentiality risks

Incident Reporting and Response

Failure to comply with this policy may expose the Firm and individual attorneys to court sanctions, adverse rulings, or professional discipline.

AI-related incidents must be reported immediately, including:

  • Inadvertent disclosure of client information
  • Use of an unapproved AI tool
  • AI-generated errors included in client work or filings
  • Any suspected breach, prompt injection, or malicious content

Report to:

  • IT Security: [email / portal]
  • OGC / Risk: [email]
  • Matter Partner: [name]
  • AI Task Force: [email]

Enforcement

Violations of this policy may result in disciplinary action, up to and including termination. The Firm may also:

  • Revoke access to AI tools
  • Report violations to appropriate authorities, where required

Appendix A: Approved Enterprise AI Tools List (Sample)

Approved:

  • [Enterprise AI Platform Name]
  • Microsoft 365 Copilot (configured with Firm controls)
  • Westlaw Advantage / CoCounsel Legal / Lexis+ AI (as configured)
  • Approved document review AI: [Tool Name]
  • Approved knowledge management AI: [Tool Name]

Owner: IT / Security + Knowledge Management
Review cadence: Quarterly


Appendix B: Prohibited Tools / Red Flag List (Sample)

  • Any consumer AI tool without enterprise controls
  • AI browser extensions not approved by IT
  • Tools that retain prompts for model training
  • Tools that lack contractual confidentiality commitments
  • Tools that store data outside approved geographic or security boundaries

Appendix C: Safe Prompting Guide (Quick Reference)

Good prompt:
“Summarize the following contract clause and suggest alternative language for clarity. Replace client names with placeholders.”

Bad prompt:
“Here is the full [Client Name] agreement with deal terms and pricing. Draft a termination letter.”

Rules:

  • Remove client identifiers
  • Avoid unique facts that identify the matter
  • Do not paste entire confidential documents unless necessary and permitted
  • Use internal templates, not client work product, when possible

Appendix D: Court Filing Verification Checklist

Before filing AI-assisted work, confirm:

  • All cases exist in official sources
  • Quotes match the source
  • Citations are accurate and current
  • Factual assertions are record-supported
  • No hallucinated authorities exist
  • Court/judge standing orders reviewed
  • Disclosure certification requirements satisfied
  • Other:

Appendix E: Billing Guidance for AI-Assisted Work

  • Bill time actually spent (including review time)
  • Do not “pad” entries
  • Use approved narratives
  • Follow client OGC restrictions
  • If in doubt, consult Billing Partner or OGC / Risk

Optional Add-On: AI Playbook (Recommended Companion Document)

A separate AI Playbook may include:

  • Approved prompt libraries
  • Use case workflows by practice group
  • Example disclaimers and client communications
  • Tool-specific how-to guides
  • FAQs and troubleshooting

NOTE: A signed acknowledgement return receipt or signature line should be required at the end of the document to verify that everyone has read and understood the policy. Give notice that it is the responsibility of every individual at the firm to comply with this policy.