Building a Law-Firm AI Use Policy: A Practical Template
8/19/20263 min read


Building a Law-Firm AI Use Policy: A Practical Template
Most firms adopted generative AI faster than they governed it. Associates are already using it; the question is whether the firm has decided how. A written AI use policy is quickly becoming the baseline expectation — the artifact that shows you took reasonable steps rather than hoping for the best.
This is a practical guide to what that policy should contain, and why each piece maps to a duty you already carry.
This is general information, not legal advice.
Why a written policy, and why now
California's professional-responsibility framework already assigns firms this responsibility. Under Rule 5.1, lawyers in a managerial role are responsible for making reasonable efforts to ensure the firm has measures giving reasonable assurance that everyone conducts themselves consistently with the rules — and the State Bar's proposed amendments make explicit that this includes establishing internal policies governing AI use. Rule 5.3 extends the same logic to supervising the staff who use these tools.
Put plainly: if your firm uses AI and can't point to a policy, confidentiality vetting, and supervision practices, you're exposed on duties that are in force today — well before any new rule is adopted. A policy is how you make compliance demonstrable.
What the policy should cover
A good AI use policy is short enough that people actually read it and specific enough that it changes behavior. Build it around these components, each tied to the duty it serves.
1. Scope and approved tools (Rule 1.1 competence)
List which AI tools are approved, for which tasks, and who approved them.
State clearly that unapproved tools ("shadow AI") may not be used for firm work.
Require that anyone using a tool understands its capabilities, limitations, and risks before relying on it.
2. Confidential-data rules (Rule 1.6; § 6068(e))
Prohibit entering confidential, privileged, or client-identifying information into any tool that hasn't cleared vendor review.
Define what counts as sensitive (party and witness identities, dates of birth, financial, medical, and identifying numbers).
Require redaction or anonymization where appropriate, and note any client-specific AI restrictions.
3. Verification and candor (Rules 1.1 and 3.3)
Require independent verification of AI output against primary sources.
Mandate that every citation in a filing be personally read and verified by the responsible attorney — no exceptions, no delegation.
Keep legal judgment with a licensed attorney; AI drafts, people decide.
4. Vendor due diligence (Rule 1.6)
Require documented review of each tool's data handling, retention, training practices, security certifications, and terms before adoption.
Set a re-review cadence (at minimum, at renewal or when terms change).
5. Supervision and training (Rules 5.1 and 5.3)
Name who owns the policy and who approves new tools.
Require training for everyone who touches client work, not just the tech-forward.
6. Client communication (Rule 1.4)
Set the firm's position on when AI use should be disclosed to clients, recognizing that disclosure may be appropriate where AI significantly affects the scope, cost, or decision-making of a representation.
7. Recordkeeping
Maintain the artifacts that make the policy real: an approved-tools log, vendor due-diligence records, citation-verification logs for filings, and a disclosure decision log.
Keep it a living document
AI tools change their features and terms constantly, and California's rules are actively evolving. Treat the policy as something you revisit — not a one-time memo. Assign an owner, set a review date, and update it when the tools or the rules move. (See our related pieces on vendor due diligence, supervising agentic AI, and attorney confidentiality with public AI tools.)
A note on sizing it to your firm
A 200-lawyer firm and a solo practice don't need the same document. What they share is the obligation to have made a reasonable, documented decision. A solo can satisfy much of this with a one-page policy plus saved vendor reviews; a larger firm will want defined owners, training programs, and audit trails. The standard is reasonableness, not length.
Frequently asked questions
Is a firm AI use policy legally required in California?
There is no standalone statute mandating a specific policy, but the supervision duties in Rules 5.1 and 5.3 effectively require managerial lawyers to govern AI use — and the State Bar's proposed amendments make the expectation of internal policies explicit. A written policy is the practical way to meet that duty.
What's the single most important provision?
The confidential-data rule paired with the citation-verification requirement. Those two prevent the most common and most damaging failures.
How often should we update it?
At least annually, and whenever a tool changes its terms or the State Bar updates its rules or guidance.
Do solos need one?
Yes — scaled appropriately. A concise policy plus documented vendor reviews demonstrates the reasonable care the rules require.
This article is general information, not legal advice. Confirm the current State Bar guidance and any applicable rule before relying on specifics.
Sources
California Rules of Professional Conduct 1.1, 1.4, 1.6, 3.3, 5.1, 5.3
California Business & Professions Code § 6068(e)
State Bar of California, Practical Guidance for the Use of Generative Artificial Intelligence in the Practice of Law (2023; updated 2026), and proposed amendments to the Rules of Professional Conduct
ABA Formal Opinion 512 (2024)