Artificial intelligence has transformative potential for enhancing efficiency for law firms, but its adoption requires thoughtful care. Law firms have an ethical responsibility to protect confidentiality and maintain the highest standards. By adopting a firm-wide AI policy, law firms can ensure that clients benefit from the enhancements offered by AI while protecting against risks. To help law firms with controls-driven AI integration, Jaffe has developed a complimentary comprehensive AI policy template.
We offer this policy template for law firms to benefit from our thorough consideration of how legal organizations can systematize AI adoption. For further assistance with the integration and adoption of AI in law firm communications, please contact us at info@jaffepr.com.
[FIRM NAME]
Artificial Intelligence (AI) Acceptable Use & Governance Policy
Effective Date: [Month Day, Year]
Policy Owner: NAME/ROLE/DEPARTMENT
Last Reviewed: [Month Day, Year]
Next Review Date: [Month Day, Year]
At [FIRM], we understand the great benefit and value that the introduction and rapidly evolving roles of artificial intelligence (“AI”) tools can offer to our clients and our firm. With national, state and local governments implementing varying AI laws, it is imperative to ensure understanding and consistency across the firm. Therefore, we have carefully developed a firm-wide policy that establishes standards for the safe, ethical, and professional use of AI tools in the delivery of our legal services and internal business operations.
This policy is intended to ensure that AI is used in a manner consistent with:
- Attorney-client privilege, confidentiality, and work-product protections
- Applicable rules of professional conduct and court rules
- Client engagement obligations and contractual requirements
- Firm cybersecurity and data governance standards
- Accuracy, reliability, and accountability in legal work product
The policy covers all use of AI in legal research, drafting, discovery, case strategy, client communications, and administrative operations.
AI may improve efficiency and quality; however, AI is not a substitute for attorney judgment. Attorneys remain responsible for all legal services, work product, and communications provided to clients and courts.
Questions regarding this policy should be addressed to:
NAME/ROLE/DEPARTMENT
Phone:
Email:
[NOTE: Consider designating an "AI task force" to respond to questions and concerns about the use of AI within the Firm, requests for new tools, and violation reports, which could be established through a dedicated email address or other reporting mechanism.]
Scope
This policy applies to all personnel of [FIRM], including:
- Attorneys (partners, associates, counsel)
- Paralegals, legal assistants, and staff
- Contract attorneys, interns, and temporary personnel
- Any third party granted access to Firm systems or Firm data
This policy governs the use of all AI-enabled systems, including:
- Enterprise-approved AI tools adopted by the Firm (“Enterprise AI”)
- AI-enabled features in Firm-approved platforms (e.g., Microsoft 365, document management, research tools)
- Public or consumer AI tools (subject to additional restrictions in the Approved Tools and Prohibited Tools section below)
- AI tools used by third-party vendors on Firm matters
Definitions
Artificial Intelligence (“AI”): Software or systems that generate content, predictions, recommendations, or analyses based on large datasets or statistical models, including generative AI.
Enterprise AI: AI tools approved by the Firm and configured with enterprise security controls (e.g., single sign-on (“SSO”), multifactor authentication (“MFA”), contractual confidentiality protections, and no training on Firm or client data).
Client Confidential Information: Any information relating to a client or matter that is confidential, privileged, protected by work-product doctrine, or subject to contractual/ethical restrictions.
Firm Confidential Information: Internal Firm information not publicly available, including policies, pricing, strategy, financials, credentials, and sensitive operational data.
Policy Principles
All AI use must comply with the following principles:
- Client confidentiality and privilege are paramount.
- Humans remain accountable for all legal work.
- AI output is not authoritative and must be verified.
- No AI tool is used unless approved or permitted under this policy.
- Court filings must be accurate, traceable, and compliant with court rules.
- Billing must be fair, transparent, and consistent with engagement terms.
Roles and Responsibilities
Attorneys
Responsible for:
- Supervising AI-assisted work
- Reviewing and validating all substantive outputs used in legal advice, drafting, filings, or client communications
- Ensuring compliance with privilege/confidentiality requirements
- Confirming compliance with court rules and judge-specific orders
Firm’s Office of General Counsel (“OGC”) / Risk Management (or similar contact or role)
Responsible for:
- Policy oversight, updates, and interpretation
- Advising on client disclosure/consent requirements
- Reviewing high-risk AI use cases and incident escalations
IT Department / Information Security
Responsible for:
- Approving tools from a security standpoint
- Maintaining access controls, logging, monitoring, and data loss prevention (“DLP”) safeguards
- Investigating AI-related incidents
- Staying updated on new technologies
Firm Leaders and Practice Group Leaders
Responsible for:
- Identifying approved use cases and workflows
- Developing training and best-practice guidance
- Monitoring emerging legal standards and court requirements
NOTE: Federal, state, and local regulations and laws governing AI are frequently evolving. Be sure to follow laws and guidelines in each jurisdiction where the Firm has a presence, and include information about those laws or relevant links in this policy as appropriate. Determine internally who will be responsible for ongoing monitoring of developing laws and regulations, determining the impact they will have on the Firm’s AI infrastructure, and ensuring compliance.
Approved Tools and Prohibited Tools
Approved Tools
Only Firm-approved Enterprise AI tools may be used for Firm work involving:
- Client matters
- Client documents
- Firm confidential materials
- Any information not publicly available
OPTIONAL: List here or provide: Approved tools are maintained in Appendix A: Approved AI Tools List.
Prohibited Tools
Unless explicitly approved in writing by NAME/ROLE/DEPARTMENT, the following are prohibited for any Firm or client work:
- Consumer/public AI tools where prompts may be retained or used to train models
- AI tools lacking enterprise access controls (SSO/MFA)
- Tools that transmit data through unapproved plug-ins/extensions
- AI tools whose terms claim ownership rights over inputs or outputs in a manner inconsistent with Firm obligations
New tools may be considered for approval. Attorneys or staff must provide in writing the purpose and reason for using the tool to perform work tasks to NAME/ROLE/DEPARTMENT to request permission.
OPTIONAL: List here or provide: Prohibited tools are maintained in Appendix B: Prohibited AI Tools List.
Confidentiality, Privilege, and Data Handling Requirements (High Risk)
General Rule
No user may input, upload, or disclose Client Confidential Information or Firm Confidential Information into any AI system unless the system is approved as Enterprise AI and use is consistent with this policy and any client restrictions.
Data Minimization
When using Enterprise AI:
- Use the minimum necessary information
- Avoid client identifiers when feasible (names, docket numbers, unique facts)
- Use placeholders or redaction when possible
Prohibited Inputs (including in Enterprise AI, unless specifically approved)
Users must not enter:
- Highly sensitive personal data (SSNs, financial account numbers)
- Protected health information (“PHI”)
- Client trade secrets
- Sealed or restricted court documents
- Data subject to protective orders or “attorneys’ eyes only” restrictions
- Any information subject to export control or sanctions laws
Retention and Logging
Enterprise AI use may be logged for compliance and security purposes. Users should assume that prompts and output may be retrievable in the event of:
- Discovery obligations
- Internal audits
- Security incident review
Approved Use Cases (Examples)
The following are permitted uses of Enterprise AI, subject to attorney review:
- Drafting outlines and first drafts of internal memos or briefs
- Generating checklists, timelines, and issue spotters
- Summarizing documents or transcripts using approved tools
- Contract clause comparison and drafting suggestions
- Editing for clarity, grammar, and format
- Brainstorming deposition or interview questions
- Preparing internal training materials
- Creating matter management summaries (non-sensitive when possible)
Restricted or High-Risk Use Cases
The following uses require heightened scrutiny and may require written approval depending on the client/matter:
- Legal conclusions presented as definitive without independent analysis
- Jurisdiction-specific advice without source validation
- Use in criminal or immigration matters involving liberty interests
- Substantive advice in regulated fields (healthcare, securities, employment)
- Any use involving sensitive client strategies or privileged communications
- Use involving predictive analytics on judges, juries, or outcomes
- AI-assisted drafting of public statements, press releases, or crisis communications
If uncertainty exists, users must consult:
- Matter partner
- Practice group leader
- OGC / Risk
CRITICAL RISK AREAS
- Court Filings and Litigation Conduct Standards
- Client Communications and Consent
- Billing and Timekeeping Standards
Court Filings and Litigation Conduct Standards (Critical Risk)
AI must never be used in a manner that compromises the accuracy or integrity of court filings.
Mandatory Verification Requirements
Before filing any document prepared with AI assistance, the responsible attorney must verify:
- Veracity of all cited cases and accurate quotations thereof
- Authorities, statutes, and regulations are current and correctly cited
- Quotes match source documents exactly
- All factual assertions are supported by the record
- All defined terms and exhibits are accurate and consistent
No AI-generated citations may be used without confirmation in an authoritative source (e.g., Westlaw, LexisNexis, official reporters, PACER/CM/ECF).
Disclosure Requirements
Some courts require disclosure of AI use and/or certification that citations were verified. Attorneys must:
- Review applicable local rules and standing orders
- Comply with judge-specific requirements
- Consult the Firm’s OGC / Risk if disclosure may be required
Prohibited Litigation Uses
AI must not be used to:
- Fabricate evidence, exhibits, deposition transcripts, or witness statements
- Alter images, audio, or video intended for use in litigation without express authorization and disclosure
- Generate filings without attorney review
- Create misleading depictions of real people or events
Client Communications and Consent (Critical Risk)
Client Disclosure
The Firm may use Enterprise AI to improve efficiency and quality. However, disclosure to clients may be required when:
- The client’s confidential information is processed through a third-party AI vendor
- Engagement terms prohibit or require disclosure of AI use
- The client has issued outside counsel guidelines restricting AI
- The use may materially affect the nature of the legal services
Client Restrictions
If a client prohibits AI use (or restricts categories of use), those restrictions must be:
- Documented in the matter file
- Communicated to the matter team
- Followed without exception
Billing and Timekeeping Standards (Critical Risk)
AI changes how legal work is performed. Billing must remain consistent with ethical obligations, client agreements, and fairness.
No Billing for Non-Work
Users may not bill for time:
- Not actually spent
- Inflated due to AI efficiency
- Representing “review” that did not occur
AI-Assisted Efficiency
If AI materially reduces time required, attorneys should bill:
- Based on the time actually spent performing and reviewing the work
- In compliance with the engagement arrangement (hourly, fixed fee, alternative fee)
Billing Narratives
If appropriate under client rules, attorneys may describe work as:
- “Drafted and revised [document], including attorney review and validation.”
- Avoid describing work as “AI-generated” unless required; do not misrepresent work performed.
Client Guidelines
Follow rules where clients require:
- Prior consent
- Disclosure
- Special coding for AI-assisted work
Quality Control, Review, and Supervision
AI output may contain errors, hallucinations, bias, or omissions.
Required controls:
- Attorneys must review AI output before use in any deliverable to independently verify information.
- Use checklists for:
- Citations
- Quotes
- Factual assertions
- Formatting
- Confidentiality compliance
- High-risk work must undergo peer review, where appropriate.
Intellectual Property, Copyright, and Ownership
Users must avoid copyright or IP violations.
Rules:
- Do not upload or copy proprietary content (client or third-party templates) into AI tools unless permitted.
- Assume AI output may be non-original or similar to existing copyrighted content.
- Review AI output for:
- Plagiarism
- Copyright infringement
- Unintended disclosure of sensitive material
- All AI-assisted work product created in the course of Firm engagement remains the Firm’s and/or client’s work product, as applicable; the use of AI does not alter ownership rights.
Bias, Fairness, and Ethical Use
AI may generate biased results.
Firm users must:
- Evaluate output for bias, fairness, and inappropriate assumptions
- Avoid use in a manner that could lead to discriminatory outcomes
- Avoid automated profiling or outcome prediction involving:
- juries
- witnesses
- protected classes
- sensitive personal characteristics
Security Controls and Technical Requirements
All Enterprise AI use must comply with Firm security standards, including:
- SSO and MFA
- Approved devices only
- No unapproved browser plug-ins/extensions
- No data export from Enterprise AI to personal accounts
- DLP and logging enabled, where available
Third-Party / Vendor Use of AI
If a vendor uses AI for Firm work or processes Firm/client data via AI, the vendor must:
- Be approved under Firm vendor management processes
- Agree in writing to:
- confidentiality
- security controls
- data retention limits
- no training on Firm/client data unless expressly permitted
- breach notification requirements
- Be subject to OGC / Risk and Security review
Training and Competency
All attorneys and staff must complete AI training, as conducted by NAME/DEPARTMENT:
- At onboarding
- Annually thereafter
- Before using Enterprise AI on client matters
Training includes:
- Policy review
- Safe prompting and redaction
- Verification and citation checking
- Court filing and disclosure rules
- Billing guidance
- Vendor and confidentiality risks
Incident Reporting and Response
Failure to comply with this policy may expose the Firm and individual attorneys to court sanctions, adverse rulings, or professional discipline.
AI-related incidents must be reported immediately, including:
- Inadvertent disclosure of client information
- Use of an unapproved AI tool
- AI-generated errors included in client work or filings
- Any suspected breach, prompt injection, or malicious content
Report to:
- IT Security: [email / portal]
- OGC / Risk: [email]
- Matter Partner: [name]
- AI Task Force: [email]
Enforcement
Violations of this policy may result in disciplinary action, up to and including termination. The Firm may also:
- Revoke access to AI tools
- Report violations to appropriate authorities, where required
Appendix A: Approved Enterprise AI Tools List (Sample)
Approved:
- [Enterprise AI Platform Name]
- Microsoft 365 Copilot (configured with Firm controls)
- Westlaw Advantage / CoCounsel Legal / Lexis+ AI (as configured)
- Approved document review AI: [Tool Name]
- Approved knowledge management AI: [Tool Name]
Owner: IT / Security + Knowledge Management
Review cadence: Quarterly
Appendix B: Prohibited Tools / Red Flag List (Sample)
- Any consumer AI tool without enterprise controls
- AI browser extensions not approved by IT
- Tools that retain prompts for model training
- Tools that lack contractual confidentiality commitments
- Tools that store data outside approved geographic or security boundaries
Appendix C: Safe Prompting Guide (Quick Reference)
Good prompt:
“Summarize the following contract clause and suggest alternative language for clarity. Replace client names with placeholders.”
Bad prompt:
“Here is the full [Client Name] agreement with deal terms and pricing. Draft a termination letter.”
Rules:
- Remove client identifiers
- Avoid unique facts that identify the matter
- Do not paste entire confidential documents unless necessary and permitted
- Use internal templates, not client work product, when possible
Appendix D: Court Filing Verification Checklist
Before filing AI-assisted work, confirm:
- All cases exist in official sources
- Quotes match the source
- Citations are accurate and current
- Factual assertions are record-supported
- No hallucinated authorities exist
- Court/judge standing orders reviewed
- Disclosure certification requirements satisfied
- Other:
Appendix E: Billing Guidance for AI-Assisted Work
- Bill time actually spent (including review time)
- Do not “pad” entries
- Use approved narratives
- Follow client OGC restrictions
- If in doubt, consult Billing Partner or OGC / Risk
Optional Add-On: AI Playbook (Recommended Companion Document)
A separate AI Playbook may include:
- Approved prompt libraries
- Use case workflows by practice group
- Example disclaimers and client communications
- Tool-specific how-to guides
- FAQs and troubleshooting
NOTE: A signed acknowledgement return receipt or signature line should be required at the end of the document to verify that everyone has read and understood the policy. Give notice that it is the responsibility of every individual at the firm to comply with this policy.
