Claude and AI training

Writing an AI Policy for Your Law Firm

A partner asks whether the firm has an AI policy. You do not, and the reason is not indifference. It is that every draft you have seen is either a paragraph that says "use good judgment" or a twenty-page document that nobody will read and that would ban the tools people are already using. Neither one protects the firm.

This page is an outline for a policy that fits on two pages, that staff will follow because it answers their actual questions, and that lines up with the ethics guidance now in place. It is not legal advice about your obligations. It is the structure we see work.

Why a two-page policy beats no policy and a twenty-page one

A policy has one job: to make the right behavior the default so that people do not have to reason about ethics at 6 p.m. with a deadline. That requires the policy to be short enough to remember and specific enough to answer "can I paste this into the tool." A long policy fails the first test. A vague policy fails the second.

Write it as a set of rules with a short reason after each, because staff follow rules they understand. Circulate it with a walkthrough, not an email.

The eight sections every firm policy should cover

Approved tools. Name the tools and the plans. "Claude on the firm's Team plan" is a rule; "AI tools" is not. State that personal accounts may not be used for client work, and say who can approve a new tool. Our page on Claude for law firms explains why the plan matters as much as the product.

Confidential information. Define what may go into an approved tool and what may not. Most firms allow client documents in an organizational plan whose terms exclude training on customer data, and prohibit any client information in unapproved tools. Some carve out categories that stay out regardless (protected health information, sealed material, information subject to a protective order). Say which.

Review requirements. Every AI output used in client work is a draft until a responsible person has reviewed it. Citations are verified in a research platform. Facts drawn from a document are checked against the document. The person who sends or files the work owns it. Our page on AI hallucinations in legal work explains why this rule is not optional and what a practical verification routine looks like.

Disclosure. State when clients are told. Options range from a standing paragraph in the engagement letter to matter-specific consent when confidential information is involved. State whether and how the firm discloses to courts, since some judges now require it in standing orders.

Billing. Say how AI-assisted work is billed. The consistent guidance is that a firm may not bill a client for time it did not spend, and may not pass through tool costs as a disbursement unless the engagement letter provides for it. Decide and write it down.

Supervision. Attorneys are responsible for work produced with AI by the staff they supervise, the same as any other delegated work. Name the checkpoint (usually the review requirement above) and make clear that "the tool wrote it" is not a defense.

Incidents. What to do if confidential information goes into the wrong tool, or an unverified citation reaches a court. Who to tell, within what time. A policy that has no incident section teaches people to hide mistakes.

Training. Nobody uses an approved tool for client work until they have completed the firm's training. Say what the training is and who tracks completion. Our AI training for paralegals and legal staff page describes what that training should cover by role.

Matching the policy to ABA Opinion 512 and your state bar

ABA Formal Opinion 512 (2024) is the reference point. It addresses competence, confidentiality, client communication, supervision, candor to the tribunal, and fees in the context of generative AI. Your eight sections map directly to those duties, which is the point: the policy is the firm's operational answer to the opinion.

Several state bars have issued guidance as well, and they differ on details such as when client consent is required. Read your own state's material before finalizing the confidentiality and disclosure sections, and note the date of what you relied on inside the policy.

Enforcement: who approves tools and who checks work

A policy without an owner decays. Assign one person (often the firm administrator) to approve tools, maintain the approved list, and track training completion. Assign the review requirement to the supervising attorney on each matter, which is where it already sits for every other kind of work product.

Once a quarter, look at a sample of AI-assisted work and confirm the review step happened. Ask staff what they wish they could use the tool for; that question surfaces unapproved uses before they become incidents.

Keeping it current

Put a review date on the policy, six months out at first. Tools change their terms, bars issue new opinions, and your own use expands. At each review, update the approved tool list, reread the confidentiality section against the current vendor terms, and add any new workflow that staff have adopted. This is the same discipline we teach in our Claude training for lawyers work, because the policy and the training are two halves of one thing.

Questions we get

Should the policy ban AI for anything?

Most firms ban it for two things: unapproved tools with client information, and final work product that has not been reviewed. Beyond that, blanket bans on tasks tend to be ignored. A rule that says "you may draft with it, and you must review it" is followed more often than a rule that says "no drafting."

Do we need a lawyer to write the policy?

You need someone who has read Opinion 512 and your state's guidance, and someone who knows how the firm actually works. The eight sections above give you the skeleton; the judgment calls (which information categories, what disclosure) are yours to make with your ethics counsel.

How do we handle a vendor's AI features inside tools we already use?

Treat them as tools. Case management platforms, research databases, and document systems now include AI features with their own data terms. Add them to the approved list only after someone has read those terms; a feature inside an approved product is not automatically approved.

If you would like a review of a draft policy, or a starting outline tailored to your practice areas, tell us what you are working with.

Next step

Talk to us.

Tell us what is not working. We reply within one business day with a straight answer on whether and how we can help.

What do you need help with?