AI Use Policy Template for Small Law Firms (2026)

Published September 22, 2026 · Updated September 2026 · By The Crossing Report · 12 min read

Summary

  • Most law firm AI policies written in 2023–2024 are already out of date — bar guidance has moved fast, and a policy that doesn't address ABA Formal Opinion 512 or your state bar's 2025–2026 guidance is a compliance gap.
  • The three ABA rules that govern attorney AI use are not new rules written for AI — they are existing professional responsibility obligations (competence, confidentiality, supervision) applied to a new class of technology.
  • This template covers the six sections every small law firm needs: approved tools, client data rules, disclosure obligations, quality review, staff training, and policy review schedule.
  • Copy and customize the template language below. You don't need outside counsel to implement this — you need 90 minutes and an honest assessment of which AI tools your firm is currently using.

What This Template Covers

This is an internal AI use policy template for small law firms — the document you give your staff, get signed, and file in your operations folder. It is not a guide to bar ethics rules (we cover that at AI Compliance for Law Firms: Professional Responsibility Guide). It is the policy itself.

The AI use policy template for law firms below is designed for firms with 1 to 50 attorneys. It is built around three ABA Model Rules that every firm using AI must address:

  • Rule 1.1 (Competence): Attorneys must understand the AI tools they use, including their limitations and error types.
  • Rule 1.6 (Confidentiality): Client information cannot be shared with AI vendors without adequate data handling protections.
  • Rule 5.3 (Supervision): Attorneys must supervise AI-generated work product before it reaches clients or courts.

The template language below addresses all three. Each section includes customization guidance in plain text after the template block.


What Every Law Firm AI Policy Must Cover

Before the template, a brief orientation. Six areas create the material compliance risk at small law firms:

  1. Which tools are authorized — staff will use whatever is easiest if you don't say otherwise. You need an approved list.
  2. What client data can go into those tools — the data handling question is where Rule 1.6 lives.
  3. When to tell clients — disclosure requirements vary by jurisdiction. Your policy should set the firm default.
  4. Who reviews AI output — Rule 5.3 requires attorney supervision of every AI-generated work product.
  5. Who is responsible for training — competence under Rule 1.1 requires that someone is accountable for making sure staff understand the tools.
  6. When the policy gets updated — bar guidance is changing. A static policy becomes a liability.

The six sections below map directly to these six risk areas.


AI Use Policy Template — Full Text

Copy this template, fill in the bracketed fields, and adapt the language to your firm's practice areas and current tool stack. If you are unsure which tools to list in Section 1, start with the ones your attorneys are already using and build from there.


[FIRM NAME] Artificial Intelligence Tools Use Policy

Effective Date: [DATE]

Policy Owner: [MANAGING PARTNER / DESIGNATED ATTORNEY]

This policy governs the use of artificial intelligence tools by all attorneys, staff, and contractors at [FIRM NAME]. It applies to all AI tools used in connection with client matters, firm operations, and legal research. All attorneys and staff must read, understand, and sign the acknowledgment at the end of this policy before using any AI tool for firm work.

Customization note: The effective date and policy owner fields are required. For the policy owner, designate a specific attorney — not "management" generally — who will be responsible for annual review and updates.


Section 1: Permissible AI Tools and Use Cases

1.1 Approved Tools

The following AI tools are approved for use in connection with client matters at [FIRM NAME]:

  • [TOOL NAME] — approved uses: [legal research / document drafting / contract review / other]
  • [TOOL NAME] — approved uses: [specify]
  • [TOOL NAME] — approved uses: [specify]

1.2 Tools Requiring Partner Approval

The following AI tools may be used for client matters only with prior written approval from [MANAGING PARTNER / PARTNER DESIGNEE]:

  • Any AI tool not listed in Section 1.1
  • Any AI tool that processes client identifying information and whose data handling policy has not been reviewed and approved by the firm

1.3 Prohibited Tools

The following uses are prohibited without exception:

  • Using consumer-grade AI tools (including the free tier of ChatGPT, Google Bard/Gemini consumer version, or similar tools) to input or process confidential client information
  • Using any AI tool to generate a final work product delivered to a client without attorney review (see Section 4)
  • Using any AI tool to conduct legal research without verification of all cited cases, statutes, and regulations in primary sources

Customization note: Fill in Section 1.1 with your actual approved tools. If you currently use no AI tools, use this section to establish your review process before tools are introduced. Update Section 1.1 whenever a new tool is added. Separating the approved list from the approval-required list is important — you want staff to have a clear answer to "can I use this today?" without having to ask every time.


Section 2: Client Data and Confidentiality Rules

2.1 General Rule

No confidential client information may be entered into an AI tool unless that tool's vendor agreement includes confidentiality obligations that protect client information from disclosure to third parties and from use in training AI models.

2.2 Client Identifying Information

Client names, matter numbers, identifying facts, financial information, and any information that would allow a third party to identify a client may not be entered into any AI tool unless that tool appears on the approved list in Section 1.1 with explicit data handling approval.

2.3 Privileged Communications

Attorney-client privileged communications — including client emails, intake notes, and confidential communications — may not be entered into any AI tool without client consent. When in doubt, anonymize the communication before inputting it into any AI tool.

2.4 Vendor Review Requirement

Before adding any AI tool to the approved list, the policy owner must review the vendor's data handling policy and confirm: (1) the vendor does not use firm data for model training; (2) the vendor agreement includes confidentiality protections; and (3) the vendor's data security practices are consistent with the firm's obligations to clients.

Customization note: Section 2.3 is the most commonly violated provision at small firms. Attorneys routinely paste client emails into AI tools for summarization or drafting assistance without considering privilege implications. The anonymization requirement in 2.3 is a practical workaround that preserves the AI workflow while managing the confidentiality risk.


Section 3: Disclosure to Clients

3.1 Default Position

[FIRM NAME]'s default position is to [DISCLOSE / NOT DISCLOSE] AI use to clients in the absence of a specific jurisdiction requirement. [Select one and delete the other.]

3.2 Mandatory Disclosure Situations

Attorneys at [FIRM NAME] must disclose AI use to clients in the following circumstances:

  • When the jurisdiction's bar guidance or ethics rules require disclosure
  • When the AI tool processed client-identifiable information and the client has not previously been informed that AI tools may be used in their matter
  • When the AI tool generated a substantial portion of a work product delivered to the client (threshold: [attorney judgment / more than 25% of the final document])

3.3 Disclosure Language

When disclosure is required, use the following language in the engagement letter or in a separate written communication: "[FIRM NAME] uses AI tools to assist with [legal research / document drafting / other]. All AI-assisted work product is reviewed and approved by a supervising attorney before delivery. AI tools are not provided access to confidential client information without your consent."

Customization note: The "default position" in 3.1 is a firm-wide policy decision. Most small firms default to disclosure — it builds trust and reduces the risk of a client complaint later. Fill in the mandatory disclosure threshold in 3.2 with either "attorney judgment" or a specific percentage. The ABA's guidance under Formal Opinion 512 is that disclosure is required when the attorney has a duty to communicate material information to the client — if the AI tool's use would be material to the client's decision-making, disclose it.


Section 4: Quality Review Requirements

4.1 Mandatory Attorney Review

All AI-generated work product must be reviewed by a supervising attorney before delivery to any client, court, or opposing party. No AI-generated document, research memorandum, brief, contract, letter, or other work product may be delivered without attorney review and approval.

4.2 Verification of Legal Research

All legal research generated by AI tools — including case citations, statutory references, and regulatory citations — must be verified in primary sources (Westlaw, Lexis, official court or regulatory databases) before use in any work product. AI hallucination of citations is a known risk. Verification is not optional.

4.3 Responsibility

The supervising attorney is responsible for the accuracy and quality of all AI-assisted work product, regardless of which staff member used the AI tool. Responsibility cannot be delegated to the AI tool or to non-attorney staff.

Customization note: Section 4.2 is non-negotiable. AI hallucination of legal citations has resulted in sanctions in multiple jurisdictions. Your policy must state explicitly that verification is required — and training must reinforce it. If your firm uses an AI tool with a built-in citation verification feature, you may note it here as a required verification step, but it does not replace verification in primary sources.


Section 5: Staff Training and Acknowledgment

5.1 Initial Training

All attorneys and staff must complete AI tools training before using any approved AI tool for client matters. Training must cover: (1) the tools approved under this policy; (2) data handling requirements; (3) quality review obligations; and (4) the disclosure policy in Section 3.

5.2 Annual Training

All attorneys and staff must complete a refresher training annually. The policy owner is responsible for scheduling annual training and maintaining a training log.

5.3 Acknowledgment

All attorneys and staff must sign the acknowledgment below upon initial hire and annually thereafter. Signed acknowledgments must be retained in each employee's personnel file.


I have read and understood [FIRM NAME]'s AI Tools Use Policy dated [DATE]. I agree to comply with all provisions of this policy in my work for the firm.

Signature: _________________________ Date: _____________

Print Name: _______________________

Customization note: The training log and signed acknowledgments are your evidence of reasonable precaution if a disciplinary matter arises. Use a simple spreadsheet: employee name, training date, policy version acknowledged. This takes ten minutes per year to maintain and is valuable documentation if questions arise.


Section 6: Policy Review Schedule

6.1 Annual Review

This policy will be reviewed annually by [DATE] each year by the policy owner listed above.

6.2 Event-Triggered Review

This policy must also be reviewed within 30 days of any of the following events:

  • New formal guidance on AI use issued by [YOUR STATE BAR] or the ABA
  • A significant change to the AI tools used by the firm
  • A disciplinary matter or client complaint arising from AI use at the firm or a peer firm in your jurisdiction

6.3 Version History

Version Date Summary of Changes Approved By
1.0 [DATE] Initial adoption [NAME]

Customization note: Bar guidance on AI is changing faster than most firm policies are being updated. Assign the event-triggered review responsibility to a specific attorney, not to "management generally." List your state bar in 6.2 — and if your practice areas cross jurisdictions, list each relevant bar.


How to Customize This Template

Four adjustments make this template fit your firm:

  • Firm size. Firms with one or two attorneys can combine Sections 4 and 5 — the supervising attorney and the training-responsible attorney are the same person. The substance doesn't change; the process simplifies.
  • Practice area. Estate planning, immigration, and family law practices handle particularly sensitive client data and should tighten Section 2. Litigation practices should add explicit language in Section 4 about court filings — verify all citations before any document filed with a court.
  • State bar. Substitute your state bar's specific guidance in Sections 3 and 6. California, New York, Florida, and Texas have all issued detailed AI guidance with specific disclosure and supervision requirements that may differ from the ABA baseline used here.
  • Tool-specific language. If your firm has committed to a specific platform (Clio, Westlaw AI, Thomson Reuters CoCounsel, Harvey), add that tool's data handling specifics to Section 2.4 rather than leaving the vendor review requirement generic.


Subscribe to The Crossing Report for updates as bar guidance evolves — and take the AI Readiness Checklist to see if your firm is ready to implement this policy.

This is the kind of intelligence premium subscribers get every week.

Deep analysis, cross-sector patterns, and the frameworks that help professional services firms make the crossing.

Related Reading

This is a sample issue — new ones go to subscribers

New issues of The Crossing Report ship exclusively to subscribers every week. Free in your inbox.