Tools for independent law firms
Client journeyProofPublic guidesCoverage & security
Sign in
DocketBuddyfor firms
Overview
PracticesPricingWhy DocketBuddy
30-day free trialNo credit card to start
Back to the Practice Library

Attorney Practice Guide

A Practical AI Policy Checklist for Small Law Firms

Build a usable law firm AI policy covering approved tools, client data, permitted work, review, citations, client communication, audit records, incidents, and training.

Reviewed August 13, 2026

Resource record

Build a usable law firm AI policy covering approved tools, client data, permitted work, review, citations, client communication, audit records, incidents, and training.

Reviewed
Aug 13, 2026
Evidence
ABA Formal Opinion 512 and model rules
Useful artifact
Firm AI policy checklist

Review note: Added an operational tool register, prospective-client treatment, risk ownership, evidence requirements, and current California Bar and NIST sources.

In this guide+

A useful law firm AI policy should help a lawyer or staff member decide what to do in the next five minutes. A statement that “AI must be used responsibly” is not enough.

The policy should identify approved tools, permitted data, allowed work, required review, prohibited actions, and the person who resolves an exception. It should also reflect how the firm actually uses intake, documents, research, drafting, communications, billing, and practice-management software.

This checklist is a starting framework, not a finished policy for every firm or jurisdiction.

1. State the purpose and boundary

Begin with a short operating principle:

The firm may use approved AI to support defined administrative and legal workflows. A lawyer remains responsible for professional judgment, source verification, client advice, filings, and work released in the lawyer’s name.

Define which offices, employees, contractors, matters, and systems the policy covers.

2. Maintain an approved-tool register

For each approved product, record:

  • Product and feature name
  • Approved account or plan
  • Firm administrator
  • Permitted users
  • Permitted workflows
  • Permitted information categories
  • Model or subprocessors, where relevant
  • Retention and training posture
  • Contract and policy review date
  • Next review date

Approval should attach to the specific feature and account configuration. “ChatGPT,” “Copilot,” or “the AI in our case-management system” can each describe several materially different data paths.

Use a register that can support an actual approval decision:

Feature and accountApproved jobData allowedHuman reviewEvidence checkedOwner and next review
Document readiness in firm workspaceCompare requested period with uploaded selectable PDFClient financial record within approved matterStaff checks highlighted source; attorney receives exceptionsContract, retention, training, access, incident pathManaging attorney, Nov. 13
General public chatbotPublic brainstorming onlyNo prospective-client or client informationUser verifies every retained fact and sourceConsumer terms and account controlsOperations lead, monthly

“Approved” should be a dated decision supported by evidence, not a product name on a white list.

3. Classify information before use

Define practical information classes, such as:

  • Public or published material
  • Internal firm operations
  • Prospective-client information
  • Confidential client information
  • Highly sensitive financial, medical, immigration, child, criminal, or identity information
  • Information restricted by protective order, client instruction, contract, or law

For each class, state which approved tools and workflows may receive it. Include file names and metadata in the review.

ABA Model Rule 1.18 makes prospective-client information its own operational concern. A policy that protects only opened matters leaves the intake path uncovered.

4. Define permitted uses

Examples of bounded uses can include:

  • Classifying an uploaded document
  • Extracting explicit dates or identifiers for review
  • Comparing a client upload with a known request
  • Preparing a plain-language administrative correction
  • Organizing intake facts by source
  • Summarizing known matter activity for a draft update
  • Drafting an internal checklist from attorney-approved instructions
  • Preparing a first draft that will receive substantive attorney review

Avoid permissions such as “use AI for anything that saves time.” The approved job should be specific enough to test.

5. Define prohibited or restricted uses

Consider expressly restricting:

  • Client information in unapproved public tools
  • Unverified AI citations in advice, negotiation, or filings
  • Autonomous engagement, conflict, strategy, or legal-sufficiency decisions
  • Client-facing legal explanations without required review
  • Recording or transcribing a conversation without the required authority and notice
  • Bypassing matter permissions or ethical walls
  • Representing AI output as attorney-reviewed when it was not
  • Using AI to fabricate facts, evidence, quotations, time, or activity

The firm can create an exception process for unusual needs rather than relying on silent workarounds.

6. Set review standards by output

Not every output needs the same review.

OutputExample review
Administrative extractionCompare the extracted fact with the highlighted source
Client-fixable requestConfirm the request, tone, recipient, and absence of legal advice
Matter summaryCheck material facts, omissions, sources, and uncertainty
Legal researchIndependently verify authority, currency, jurisdiction, quotation, and proposition
Filing or legal work productFull attorney review under the same standard as any other work released by the firm

Name who may perform each review and how approval is recorded.

7. Address legal sources separately

The policy should require verification of every legal citation and quoted proposition through an appropriate primary or trusted legal source.

The reviewer should confirm:

  • The authority exists
  • The court and jurisdiction are correct
  • The authority remains current
  • The quotation is exact
  • The cited passage supports the proposition
  • Contrary or limiting authority was not hidden by the prompt
  • The source is appropriate for the intended use

A correct citation does not make the surrounding analysis correct.

8. Define client communication and disclosure

ABA Formal Opinion 512 explains that communication and informed-consent questions depend on the facts and use. A firm policy should identify who decides whether disclosure or consent is required and how the decision is documented.

The policy can also address how automated administrative messages identify themselves and when a client is routed to a person.

9. Preserve a useful decision trail

For material workflows, retain enough information to show:

  • Which source was used
  • Which machine job was performed
  • What output appeared
  • Who reviewed it
  • What was corrected or rejected
  • What final work entered the matter

Do not retain confidential prompts indefinitely merely to say the system is auditable. The audit design should follow the firm’s information-governance and retention rules.

10. Create an incident path

Staff should know what to do when:

  • Confidential information enters an unapproved tool
  • Output containing a false citation is used
  • The wrong matter or recipient receives content
  • A vendor changes a material term
  • A user discovers cross-matter access
  • An automated message leaves the firm unexpectedly

The response path should identify immediate containment, internal reporting, preservation, vendor contact, client or authority analysis, and policy correction.

11. Train with examples from the firm

Training should use representative situations:

  • A public filing in an approved research tool
  • A medical record in a general chat account
  • A client upload that does not match the request
  • An AI-generated case citation
  • A draft client update containing a legal conclusion
  • A staff member who wants to try a new browser extension

Employees learn a usable boundary faster through examples than through abstract warnings.

12. Review the policy on a schedule and after change

Review when:

  • A product adds or changes an AI feature
  • The model provider or subprocessor changes
  • Contract, retention, or training terms change
  • A new practice or information type enters the workflow
  • Professional guidance or court rules change
  • An incident or pilot reveals an unanticipated risk

Record the review date and owner.

NIST’s Generative AI Profile is not a law-firm ethics rule. It is useful as a current risk-management reference because it organizes generative-AI risks and actions across governance, measurement, and management. A small firm can adapt that discipline without building a large compliance program: identify the job and risk owner, require evidence before approval, test the output and stop condition, record incidents and corrections, and review after a material change.

A one-page operating summary

Every user should be able to find a short version containing:

  1. Approved tools
  2. Approved workflows
  3. Information that may not be entered
  4. Required review for each output
  5. Citation-verification rule
  6. Client-communication boundary
  7. Incident contact
  8. How to request an exception

The complete policy can hold the reasoning and controls. The one-page summary supports daily compliance.

Common Questions

Does every small law firm need an AI policy? If anyone at the firm uses or may encounter AI features, written operating rules can reduce inconsistent handling and silent use. The formality and scope should fit the firm.

Can a law firm copy a generic AI policy template? A template can identify issues, but the final policy should match the firm’s approved tools, jurisdictions, matters, client requirements, staff roles, and actual workflows.

Should the policy prohibit all AI legal research? That is a firm decision. If research is allowed, the policy should define approved tools and require independent verification of authority, currency, jurisdiction, quotations, and propositions.

How often should a law firm AI policy be updated? Use a regular schedule and trigger review after material product, contract, workflow, guidance, staffing, or incident changes.


Method and scope

This checklist organizes operational controls around ABA Formal Opinion 512, ABA Model Rule 1.18, the State Bar of California’s practical guidance for generative AI, and NIST’s Generative AI Profile. Sources were checked on August 13, 2026. The checklist is not a substitute for a policy drafted or reviewed for the firm’s jurisdiction, clients, technology, and professional obligations.

Article feedback

Was this helpful?

What should we improve?

Thanks for telling us

We’ll use this to improve the guide.

In this guide

Turn the idea into one bounded pilot

Find the first AI workflow worth changing

Use the interactive readiness check to define the source record, machine job, attorney decision boundary, and measurable outcome before choosing a tool.

Build the first pilot See the one-file proof
DocketBuddyfor firms

Client acquisition, document preparation, case intelligence, and practice operations for independent law firms.

Products

DocketBuddy SitesOpportunity CampaignsAttorney WorkpapersDocketBuddy PreflightDocketBuddy ReadyPracticeOS

Explore

DocketBuddy in 60 secondsCase Stress TestProof LibraryPublic guidesProduct documentationPractice workflowsPricing

Trust and company

Coverage and sourcesSecurityAboutPrivacyTerms
© 2026 DocketBuddy · Atlanta, Georgiahello@docketbuddy.org