
Artificial intelligence probably entered your law firm before your AI policy did.
An attorney asks AI to summarize a document.
A paralegal uses it to organize information.
Someone in marketing uses it to draft an article.
An administrator uses it to rewrite an email.
And before long, several people inside the firm are using several different AI tools for several different purposes.
But has anyone established the rules?
For law firms, an AI acceptable use policy is becoming an important part of technology governance because attorneys and staff regularly handle confidential client information, personally identifiable information, financial records, legal documents, privileged communications, and other sensitive data.
The goal shouldn't necessarily be to stop employees from using AI.
The goal should be to answer a much more practical question:
How can our law firm use AI productively without creating unnecessary risks for our clients, our data, or our business?
A well-designed AI acceptable use policy can help answer that question.
What Is an AI Acceptable Use Policy for a Law Firm?
An AI acceptable use policy is a written set of rules explaining how attorneys and employees may use artificial intelligence in connection with firm business.
At minimum, the policy should answer questions such as:
- Which AI tools are approved?
- Which AI tools are prohibited?
- What information can employees enter?
- What information should never be entered?
- Can employees use personal AI accounts for firm work?
- Who approves new AI applications?
- When must AI-generated information be reviewed?
- How should potential AI-related security incidents be reported?
- Who is responsible for managing the firm's AI environment?
Think of it as a set of guardrails.
Your law firm can benefit from AI while establishing boundaries around how the technology interacts with your people, systems, and information.
Does a Law Firm Really Need an AI Policy in 2026?
For many firms, there is a compelling reason to establish one: employees may already be using AI.
As we discussed in our previous article, “Your Attorneys Are Already Using AI. Does Your Law Firm Know Where the Data Is Going?”, unsanctioned AI use can create a form of Shadow AI, where employees adopt applications without the firm's IT department or leadership fully understanding what tools are being used or what information is entering them.
That makes an AI policy useful even for firms that haven't formally implemented an AI platform.
In fact, those firms may need one the most.
The State Bar of Texas AI Toolkit provides resources covering ethical AI use, evaluating AI vendors, data privacy, regulatory considerations, and practical legal workflows. Texas Professional Ethics Committee Opinion 705 also addresses attorneys' ethical responsibilities when using generative AI.
The American Bar Association's Formal Opinion 512 similarly identifies professional obligations attorneys should consider when using generative AI, including competence, confidentiality, communication, supervision, candor to tribunals, and reasonable fees.
An acceptable use policy can help translate these broader concerns into everyday expectations employees can understand.
What Should a Law Firm's AI Acceptable Use Policy Include?
Every firm's requirements will be different, so the final policy should be developed with appropriate legal, ethics, compliance, cybersecurity, and technology input.
But from an IT and cybersecurity perspective, there are several areas worth addressing.
1. Define Which AI Tools Are Approved
Start with a simple rule:
Employees should know which AI applications they are authorized to use for firm business.
Without this rule, attorneys and staff can independently sign up for whatever tool happens to solve today's problem.
That creates Shadow AI.
Your firm can quickly end up with multiple platforms, personal accounts, free applications, browser extensions, AI meeting assistants, document-analysis tools, and other services interacting with business information.
Consider maintaining an approved AI application list that identifies:
Approved tool → Approved account type → Permitted business uses → Data restrictions → Responsible administrator
That gives employees a clear answer instead of forcing them to guess.
2. Define What Information Employees Cannot Enter Into AI
This may be one of the most important sections of the policy.
Employees need clear instructions about the types of information that require special handling or may not be entered into particular AI systems.
Depending on your firm's requirements, that could include:
- Confidential client information
- Attorney-client communications
- Personally identifiable information
- Financial information
- Passwords and credentials
- Medical or health information
- Sensitive case information
- Discovery materials
- Personnel information
- Proprietary firm information
- Documents subject to confidentiality agreements
- Information restricted by a client or contract
The policy shouldn't simply say:
"Be careful with confidential information."
That's too vague.
Employees should understand what types of information require additional protection and what they should do when they're uncertain.
3. Establish Rules for Personal AI Accounts
This is easily overlooked.
Imagine an attorney has a personal account with an AI provider.
They start using it occasionally for work.
Eventually they upload documents, build custom prompts, create workflows, and accumulate conversation history related to firm business.
Then they leave the firm.
Who controls that account?
Who controls the information associated with it?
Can the firm remove access?
Can IT investigate activity if there's a security concern?
This is why your AI policy should address whether employees may use personal AI accounts for firm business.
Whenever possible, manage business technology through firm-controlled accounts, identities, permissions, and administrative controls.
4. Require Human Review of AI-Generated Work
AI can produce answers that sound confident and professional but are still incorrect.
For attorneys, that isn't merely inconvenient.
It can become a serious professional issue.
ABA Formal Opinion 512 discusses lawyers' duties involving competence and candor when using generative AI. The opinion notes that lawyers cannot simply rely on AI output without appropriate review.
Your policy should therefore make one principle unmistakably clear:
AI assists people. It does not replace professional judgment.
Attorneys and appropriate staff should review AI-generated work before relying on it, submitting it, communicating it to a client, or using it to make an important decision.
This is especially important for:
- Legal research
- Case citations
- Court filings
- Contracts
- Client communications
- Legal analysis
- Financial calculations
- Factual claims
AI should accelerate the work.
It shouldn't eliminate accountability for the work.
5. Establish an Approval Process for New AI Tools
Suppose an employee discovers an AI application that promises to review contracts in seconds.
It looks great.
They shouldn't necessarily be able to create an account, upload client documents, and start using it immediately.
Instead, your firm should establish a simple review process.
Before adopting a new AI platform, appropriate personnel should consider questions such as:
What data will this application access?
Where is the information stored?
How long is it retained?
Is the information used for model training?
Can the firm's administrator manage accounts?
Does it support multifactor authentication or single sign-on?
What happens to the data when the account is closed?
Does the provider use subcontractors or other third parties?
What security and privacy commitments does the vendor make?
Can the firm meet applicable client, contractual, ethical, or regulatory obligations while using it?
The State Bar of Texas AI Toolkit specifically includes resources for evaluating AI vendors, privacy considerations, and responsible AI adoption.
6. Don't Forget Microsoft 365 Permissions
This will become increasingly important as AI connects directly to business information.
Microsoft explains that Copilot can respect the permissions already established within Microsoft 365. When appropriately configured, it can reference organizational information the individual is already authorized to access.
At first glance, that sounds reassuring.
And it can be.
But consider the opposite side of the equation.
What if your existing permissions are wrong?
Suppose an employee still has access to a SharePoint site they haven't needed for three years.
Or a folder was shared too broadly.
Or a former employee's access wasn't completely removed.
AI doesn't necessarily create that permission problem.
It can make existing permission problems more consequential because information becomes easier to discover and use.
Before connecting AI deeply to your Microsoft 365 environment, review your existing access controls.
Your AI policy and your cybersecurity strategy should work together.
7. Address AI Meeting Assistants
This deserves its own section.
AI meeting assistants can record meetings, create transcripts, summarize conversations, identify action items, and automatically distribute notes.
That can be incredibly useful.
But law firms should consider what happens when those meetings involve:
- Clients
- Case strategy
- Personnel issues
- Financial matters
- Confidential information
- Privileged conversations
- Opposing counsel
- Third parties
Your policy should establish whether AI meeting assistants are permitted and under what circumstances.
Employees should understand that clicking "Add AI Notetaker" isn't necessarily the same as opening an ordinary productivity application.
It may introduce another system into a conversation containing sensitive information.
8. Define Rules for AI Browser Extensions and Plug-Ins
Some AI tools don't require employees to visit a separate website.
They live directly inside browsers, email platforms, document applications, CRM systems, or other software.
Depending on the permissions granted, those applications may potentially interact with information employees access throughout their workday.
That means your AI inventory shouldn't only ask:
"Do you use ChatGPT, Copilot, Gemini, or another chatbot?"
It should also ask:
"What AI-enabled applications, browser extensions, meeting tools, document tools, and plug-ins have access to firm information?"
The answer may surprise you.
9. Include AI in Employee Onboarding and Offboarding
Your existing IT onboarding checklist probably includes things like:
- Microsoft 365 account
- Multifactor authentication
- Laptop
- File access
- Practice-management software
- Security training
AI should increasingly become part of that process.
New employees should know the firm's AI policy from the beginning.
Likewise, when someone leaves the firm, IT should identify and remove access to firm-controlled AI accounts along with other business systems.
If employees use personal AI accounts for work, offboarding becomes considerably more complicated.
That's another reason to establish the rules early.
10. Tell Employees What to Do When Something Goes Wrong
Policies shouldn't only describe what employees shouldn't do.
They should tell people what to do when they make a mistake.
Suppose someone accidentally uploads a sensitive document into an unapproved AI application.
What happens next?
Employees should know whom to contact.
The worst outcome is often an employee realizing they made a mistake and hiding it because they're afraid of getting in trouble.
Your policy should establish a straightforward reporting process:
Stop → Report → Preserve information → Let the appropriate team investigate.
The faster your IT, security, and appropriate leadership teams know what happened, the faster they can evaluate the situation.
11. Train Your Employees Instead of Just Sending Them the Policy
Imagine sending employees a six-page AI policy and then never discussing it again.
How many people will remember it six months later?
An AI policy works better when employees understand why the rules exist.
Training should include realistic scenarios.
For example:
Scenario 1
"I have a 70-page discovery document. Can I upload it into an AI tool and ask for a summary?"
Employees should know how to determine the answer.
Scenario 2
"I need help rewriting an internal email. Can I use AI?"
They should know which approved tool and account to use.
Scenario 3
"I found an AI contract-review tool that looks great. Can I try it?"
They should know the approval process.
Scenario 4
"I accidentally uploaded the wrong document."
They should know exactly whom to contact.
Policies create expectations.
Training turns those expectations into behavior.
12. Review Your AI Policy Regularly
Your AI policy shouldn't be something you write in 2026 and rediscover in a folder in 2030.
AI products are changing quickly.
Features change.
Data practices change.
Integrations change.
Employees discover new tools.
Your firm's use of AI changes.
Even government and industry frameworks keep evolving. NIST describes its AI Risk Management Framework as a voluntary framework designed to help organizations manage AI risks, and its Generative AI Profile provides additional guidance specific to generative AI. NIST also notes that AI risk management should span governance, mapping, measurement, and management rather than being treated as a one-time technical exercise.
Set a regular schedule to revisit:
Approved applications
Data-handling rules
Security settings
Employee access
Vendor terms
Training
Incident-response procedures
New AI capabilities
AI governance should evolve along with the technology.
What Should an AI Acceptable Use Policy Include? A Quick Checklist
For managing partners, COOs, office administrators, and IT leaders who want the short version, start here:
- Purpose and scope - Explain who and what the policy covers.
- Approved AI tools - Identify applications authorized for firm business.
- Prohibited tools or uses - Define what's off-limits.
- Data classification rules - Explain what information may and may not be entered.
- Business-account requirements - Establish whether personal AI accounts are permitted.
- Human-review requirements - Require appropriate review of AI-generated work.
- Vendor approval process - Establish how new AI applications are evaluated.
- Access and permissions - Connect AI governance with Microsoft 365 and other business systems.
- Client and matter considerations - Address situations requiring additional restrictions or guidance.
- Meeting and transcription tools - Establish rules for AI recording and summarization.
- Employee training - Teach people how to apply the policy.
- Incident reporting - Tell employees what to do if information is exposed.
- Onboarding and offboarding - Add AI accounts and permissions to existing procedures.
- Policy review - Revisit the policy as technology, risks, and requirements change.
The exact policy should reflect your firm's technology, practice areas, client requirements, professional obligations, and risk tolerance.
Should Law Firms Ban AI?
For many firms, the more useful question is not:
"Should we ban AI?"
It is:
"How are we going to govern it?"
A blanket prohibition may not address the underlying problem if employees continue using AI without management's knowledge.
On the other hand, unrestricted AI use can create unnecessary data and cybersecurity risks.
A managed approach gives employees clearer boundaries:
Use this tool.
Use this account.
Don't enter this type of information.
Have a human review this type of output.
Ask before installing something new.
Report mistakes quickly.
That's much easier for employees to follow than simply saying:
"Be careful with AI."
Frequently Asked Questions About AI Policies for Law Firms
Does every law firm need an AI acceptable use policy?
A law firm's specific requirements will depend on its circumstances and professional obligations. However, if attorneys or employees are using generative AI for firm business, establishing written expectations can help the organization manage approved tools, sensitive information, employee access, human review, and cybersecurity.
The State Bar of Texas provides AI resources specifically intended to help Texas legal professionals consider ethical AI use, vendor evaluation, privacy, and other issues.
What should attorneys never put into public AI tools?
No universal list applies to every AI product or legal matter. Firms should establish restrictions based on the sensitivity of the information, the particular AI provider's terms and security controls, client requirements, and the firm's professional obligations.
Texas ethics guidance emphasizes protecting confidential client information when attorneys use generative AI.
Can a law firm use Microsoft Copilot securely?
The answer depends on the firm's configuration, licensing, permissions, and intended use.
Microsoft states that Copilot Chat provides enterprise data protection when users sign in with eligible work or school accounts. Microsoft also states that prompts and responses covered by enterprise data protection aren't used to train foundation models.
However, implementing AI securely also means reviewing identity, access, permissions, data governance, and employee practices.
Who should create a law firm's AI policy?
AI governance shouldn't necessarily belong to one department.
Depending on the firm's size and structure, input may be appropriate from:
Firm leadership + Attorneys/Ethics counsel + IT/Cybersecurity + HR + Compliance/Risk Management
Each sees a different part of the risk.
Your IT provider can help address the technology and cybersecurity controls, while appropriate legal and ethics professionals can address the firm's professional obligations.
How often should a law firm update its AI policy?
There isn't one universal timetable. Because AI products, integrations, risks, and vendor terms change rapidly, firms should establish a regular review cycle and also reconsider the policy when adopting significant new AI technologies or workflows.
An AI Policy Is Only as Strong as the Technology Behind It
Here's the part that can easily get overlooked.
A beautifully written AI policy won't fix poorly configured Microsoft 365 permissions.
It won't automatically detect unauthorized applications.
It won't remove an employee's access when they leave.
It won't enable multifactor authentication.
It won't review third-party integrations.
And it won't tell you where sensitive information is stored.
Policy establishes the rules.
Technology helps enforce them.
That's why AI governance shouldn't be treated as a separate project from cybersecurity and IT management.
They are becoming increasingly connected.
Before You Roll Out More AI, Get the Foundation Right
AI offers enormous opportunities for law firms.
But adopting AI responsibly isn't simply about choosing the best AI application.
It's about knowing:
Who is using it.
What they're using it for.
What information it can access.
Where that information is going.
Who controls the account.
How output is reviewed.
What happens when someone leaves.
And what happens when something goes wrong.
For North Texas law firms, establishing those answers now can create a much stronger foundation for using AI as the technology becomes increasingly integrated into everyday legal work.
Is Your Technology Ready for AI?
Datatex Computer Services has been helping North Texas businesses manage their technology since 1975.
As AI becomes part of everyday legal operations, your cybersecurity strategy needs to account for more than laptops, servers, and email. Identity, permissions, cloud applications, data access, employee practices, and AI governance increasingly work together.
Before adding another AI tool, make sure the technology underneath it is ready.
Datatex can help your law firm review the IT and cybersecurity side of your AI environment, including Microsoft 365, identities, permissions, security controls, and technology policies.
Schedule a no-cost technology and security assessment with Datatex Computer Services.
This article provides general technology and cybersecurity information and is not legal, ethics, or compliance advice. Law firms should consult appropriate legal and professional ethics resources when establishing policies governing the practice of law.
