A law firm AI policy is a written statement of which AI tools a firm allows, what client information may go into them, who reviews their output, and when a client gets told. The rules it encodes (competence, confidentiality, disclosure, supervision, and candor) already apply to AI use whether or not a firm writes them down.
By Chris Kaneshiro, who runs Brand75's law firm systems practice. More about Chris.
A law firm AI policy is a written statement of which AI tools a firm allows, what client information may go into them, who reviews their output, and when a client gets told. It is not optional paperwork. Forty-three percent of law firms have no formal AI policy, and 54% provide no AI training, according to the 8am 2026 Legal Industry Report. The gap is dangerous because the rules that govern AI use are already in force: a lawyer can be disciplined for how they use AI whether or not the firm ever wrote a policy down.
This page is the playbook: the rules as they stand in mid-2026, the five duties every policy has to cover, a state-by-state snapshot, and three fill-in templates your firm can adapt today: an AI use policy, a client disclosure, and a tool-vetting checklist.
This is the governance half of what Brand75 builds into its law firm systems: the same operated approach we run for AI consulting and AI intake, applied to staying clean while you use the tools.
Why a policy isn't optional anymore
Two things changed in the last two years.
First, the guidance stopped being abstract. In July 2024 the American Bar Association issued Formal Opinion 512, its first on generative AI. It didn't invent new duties. It said the existing Model Rules already apply to AI, and walked through exactly how. Since then the states have moved on their own timetable: formal ethics opinions in Florida, Texas, and New York, rule amendments in Colorado and Florida, practical guidance in California, and standing orders in the federal district courts.
Second, the consequences stopped being hypothetical. A federal judge in Mississippi removed four attorneys over AI errors in June 2026. Colorado sanctioned lawyers over fabricated citations twice in the same case, including a second $5,000 sanction in May 2026. A Texas state judge sanctioned a lawyer over AI-generated citations in October 2025. A firm without a policy isn't just behind the market; it's exposed.
The five duties every AI policy has to cover
ABA Formal Opinion 512 maps the existing rules onto generative AI, and the state opinions and rule amendments since follow the same skeleton. A policy that covers these five duties is a policy that survives an audit or a bar complaint.
| Duty | Rule | What it means in practice |
|---|---|---|
| Competence | 1.1 | You don't have to become an AI expert, but you must understand the capabilities and limitations of the specific tools you use, and keep that understanding current. |
| Confidentiality | 1.6 | Client information that goes into an AI tool stays protected. Know where the tool sends data, whether it trains on it, and get informed consent before putting confidences into a "self-learning" tool. |
| Communication & disclosure | 1.4 | A boilerplate "we may use AI" line in an engagement letter is not enough. Whether you must disclose depends on the tool and the task, and several states now require more. |
| Supervision | 5.1 / 5.3 | You are responsible for what nonlawyers and AI tools produce under your supervision. That means training, and a human review gate before anything reaches a client or a court. |
| Candor & fees | 3.3 / 3.1 / 1.5 | You must verify AI output, especially citations, before it reaches a tribunal. And you can't bill clients for the time you spend learning the tool. |
The through-line across all five: the lawyer stays responsible for the output, no matter who or what produced the first draft. That's the sentence every policy ultimately exists to enforce.
State-by-state: where the rules stand in 2026
California, Florida, and New York are setting the pace, and Florida and Colorado have moved the fastest on actual rule changes. But the direction is uniform even where the letter differs: competence, confidentiality, and candor apply everywhere.
- California: Practical Guidance for the Use of Generative AI in the Practice of Law (published November 2023, updated and approved May 14, 2026), which is non-binding guidance rather than a numbered formal opinion. Proposed amendments that would fold AI duties into the Rules of Professional Conduct are still working through the process; the California Supreme Court directed the State Bar to consider them in August 2025, and they have not been adopted.
- Florida: Ethics Opinion 24-1 (January 2024) treats submitting unverified AI output as a candor problem under the Mata v. Avianca facts, and Florida is the state to watch on filings: on May 28, 2026, the Florida Supreme Court amended Rule 2.515(d)(2) to require every signer of a filing to certify that the legal authorities cited "exist and are accurately cited," with express sanction authority. That took effect June 15, 2026, and it replaced the patchwork of circuit-level AI disclosure orders with one statewide accuracy-certification standard.
- New York: City Bar Formal Opinion 2024-5 (August 2024) walks the duties a New York lawyer must consider, and Opinion 2025-6 addresses AI recording and transcribing. Statewide court rule 22 NYCRR Part 161 permits AI in court papers as long as existing duties are met.
- Texas: Opinion 705 (February 2025), the light-touch general opinion, covers competence (1.01) and confidentiality (1.05) plus verification and billing, with no hard disclosure mandate.
- Colorado: the first state to actually amend its rules: on January 8, 2026, the Colorado Supreme Court adopted AI-specific amendments to the Rules of Professional Conduct (new Scope [20A] and new/revised comments to Rule 1.1), effective immediately.
- Virginia: Legal Ethics Opinion 1901 (approved November 24, 2025) specifically addresses reasonable fees when generative AI makes work faster.
- New Jersey and Illinois: New Jersey's guidance comes as a sequence of Supreme Court notices (January 2024, April 2025, March 2026) rather than a numbered opinion; Illinois has the ARDC's non-binding Attorney's Guide to Implementing AI (October 2025).
On top of the bars, individual courts are acting faster than any rulemaking body. Standing orders in multiple federal districts, including the Northern, Central, and Southern Districts of California and the Southern and Eastern Districts of New York, require counsel either to disclose AI use or to certify that AI-generated content has been personally verified.
The practical takeaway: if your firm practices in California, Florida, New York, or Colorado, or in any federal district with a standing order, your obligations are effectively already here, policy or no policy.
What an AI policy actually needs in it
A real policy isn't a memo that says "use AI responsibly." It has to answer operational questions a compliance person or a bar investigator would actually ask. Seven sections cover it:
- Permitted tools: the named, approved list, and the rule for everything not on it.
- Prohibited uses: what never goes into an unapproved tool (client confidences, privileged material, sealed or settlement content).
- Input rules: what data may be entered, and what gets scrubbed first.
- Review and verification: who must review AI output before it's used, and the citation-verification rule.
- Disclosure: when and how clients and tribunals get told.
- Training: who must complete AI training, and how often.
- Vendor due diligence: the checklist a tool has to pass before it joins the approved list.
The three templates below map one-to-one onto those sections, so you can adopt them without starting from a blank page.
Template 1: Law Firm AI Use Policy
> 1. Purpose. [Firm name] uses artificial intelligence to serve clients faster and more accurately. This policy sets the rules for that use. It applies to every lawyer, paralegal, and staff member, and to any outside contractor working on firm matters. > > 2. Approved tools. The following tools are approved for firm use: [list tools]. No other AI tool may be used on client work without written approval from [managing partner / firm administrator]. Personal AI accounts used for client work are prohibited. > > 3. Prohibited uses. AI tools may never be used to: (a) draft, revise, or complete a filing without human review; (b) generate or check citations without verification against primary sources; (c) input client confidences, privileged material, or sealed/settlement content into a tool that trains on input, unless the client has given informed consent; (d) make unsupervised decisions about case strategy, settlement, or billing. > > 4. Input rules. Before any client matter enters an AI tool, staff must: remove names, case numbers, and any information that could identify the matter; confirm the tool does not use input for training, or, if it does, confirm that client informed consent has been obtained for that specific matter; and log the use in [firm's matter management / AI log]. > > 5. Review and verification. A licensed attorney must review every AI output before it is sent to a client, a court, or opposing counsel, or used in a filing. Every citation must be verified against the primary source. AI may draft; a lawyer signs. > > 6. Disclosure. Client disclosure follows Template 2. Court disclosure follows the rules of the specific court and the standing orders of the specific judge. When in doubt, disclose. > > 7. Training. All lawyers and staff must complete [annual / onboarding] AI training covering this policy, the tool list, and the risks of hallucination and confidentiality leakage. Completion is logged in [system]. > > 8. Violations. A violation of this policy is a violation of [firm]'s professional obligations and will be handled under the firm's existing disciplinary procedures. > > Adopted: [date] · Review date: [date, no more than 12 months out]
Template 2: Client Disclosure and Informed Consent
> Engagement letter / addendum language. > > "[Firm name] may use artificial-intelligence tools to assist with [drafting, research, document review, or other specified task] in your matter. These tools are used under attorney supervision, and every AI-generated draft or result is reviewed by a licensed attorney before it is used. We only enter client information into tools that do not train on the input, and [describe any additional safeguard, e.g., 'no client-identifying information is entered']. Using these tools can [benefit: lower cost / faster turnaround]. > > In the rare case that work on your matter requires a tool that does use input for training, we will not use it for your matter without your explicit prior consent. You may decline the use of AI at any time without affecting our representation of you." > > When to send: at engagement, and again before any use that puts client information into a third-party tool. A blanket line in the original engagement letter is not sufficient for uses that require informed consent. Confirm at the moment of the specific use.
Template 3: AI Tool Vetting Checklist
Run every candidate tool through this before it joins the approved list. Document the answers; a bar investigator will ask for them.
- Data handling. Does the vendor train on your input? Where is data stored, and who can access it? Is the vendor SOC 2 / ISO 27001 certified?
- Confidentiality posture. Can the tool be configured to not retain or train on data? Is there an enterprise tier that excludes your data from model training?
- Legal fit. Is it a general tool or legal-specific? Does it make claims about accuracy or citations that need verification?
- Output review. What does the tool produce, and what's the review burden before a lawyer can rely on it? Does it surface sources?
- Access controls. Who in the firm can use it, and is that logged? Can per-matter or per-user restrictions be set?
- Vendor reputation. Any public incidents of data leakage, hallucinations in filings, or regulator action tied to this vendor?
- Contract terms. Does the agreement indemnify you? Does it meet your malpractice carrier's requirements?
A tool that fails any item doesn't necessarily get rejected. It gets restricted (for example, allowed only for non-client work, or only with de-identified input). The point is that the decision is made and written down, not left to whoever finds the tool first.
FAQ
Is a law firm AI policy legally required?
No single state mandates a written AI policy for every firm, but the underlying duties (competence, confidentiality, supervision, and candor) are mandatory and already apply to AI use. A written policy is how a firm demonstrates it meets them.
Do lawyers have to tell clients they use AI?
It depends on the tool, the task, and the state. If client information goes into a tool that trains on input, informed consent is generally required. If AI produces substantive work, disclosure is increasingly expected, and several states and courts now require more. When in doubt, disclose.
Can a firm be disciplined for AI use without a policy?
Yes. Discipline attaches to the underlying conduct, not the absence of a policy. Courts and bars have already sanctioned lawyers over AI-generated filings with fabricated citations in Florida, Colorado, Texas, and the federal courts. A missing policy isn't the violation. It just removes your defense.
What's the single most important rule?
A licensed attorney reviews every AI output before it is used, and every citation is verified against the primary source. That one rule covers most of the competence, candor, and supervision exposure on its own.
Does Brand75 write these policies for firms?
Brand75 builds the systems that a policy governs: AI consulting, AI intake, and Agent OS. Talk to Brand75 if you want the governance and the tooling done together, not as two separate projects.
Sources
- ABA Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512: Generative Artificial Intelligence Tools (July 29, 2024).
- State Bar of California, Practical Guidance for the Use of Generative AI in the Practice of Law (Nov. 16, 2023; updated revisions approved May 14, 2026).
- Florida Bar Ethics Opinion 24-1 (Jan. 19, 2024); In re Amendments to Florida Rule of General Practice and Judicial Administration 2.515, Case No. SC2026-0673 (Fla. May 28, 2026, eff. June 15, 2026).
- New York City Bar Association, Formal Opinion 2024-5 (August 2024) and Formal Opinion 2025-6; 22 NYCRR Part 161.
- State Bar of Texas, Professional Ethics Committee Opinion 705 (Feb. 2025).
- Colorado Supreme Court, Rule Change 2026(02), amendments to the Colorado Rules of Professional Conduct (Jan. 8, 2026).
- Virginia State Bar, Legal Ethics Opinion 1901, Reasonable Fees and the Use of Generative AI (approved Nov. 24, 2025).
- New Jersey Supreme Court, AI notices (Jan. 2024, Apr. 2025, Mar. 2026); Illinois ARDC, Attorney's Guide to Implementing AI (Oct. 2025).
- 8am, 2026 Legal Industry Report (Nicole Black, 8am.com, March 2026), source of the 43%-no-policy, 54%-no-training, and 9%-enforced figures, as reported by the ABA and others.

