An AI use policy for a small firm, section by section
Updated August 10, 2026 · 10 min read · Claude configuration facts checked against claude.com and support.claude.com on August 10, 2026. ABA Formal Opinion 512 was issued July 2024.
What goes in an AI use policy for a small firm?
An AI use policy for a small firm fits on two or three pages and answers six questions: which tools are approved and on which accounts, which data may never be entered, who reviews what before it leaves the office, how the training and retention settings are configured, what gets disclosed and to whom, and how access ends when someone leaves. Justo’s position is that the policy is signed before the first workflow turns on, because a policy written after an incident is a remediation document. This guide is a starting point for drafting one, not legal advice.
What does an AI use policy actually have to do?
It has to make six decisions in advance, in writing, so that nobody has to make them at speed on a Friday afternoon. A policy that does that in two pages is worth more than a twenty-page document nobody has read, because the test of a policy is whether a new hire can follow it in their first week.
The six sections below are the whole document. Each one closes with a sample clause written to be edited rather than admired.
| Section | The question it settles | What goes wrong without it |
|---|---|---|
| 1. Approved tools and accounts | Which AI tools may be used for firm work, on which accounts | Client material ends up in personal free accounts with no logs and no terms the firm has read |
| 2. Data that never goes in | Which matters, documents, and categories are off limits | Restricted or protected material is entered by someone who did not know it was restricted |
| 3. Review and signoff | Who checks what before it leaves the office | AI-drafted work reaches a client or a court without a responsible person reading it |
| 4. Settings and configuration | How training, retention, and access settings are set | Nobody can answer a client asking what happens to their data |
| 5. Disclosure | What is told to clients, courts, or counterparties, and who decides | The disclosure decision gets made ad hoc, differently, by whoever is under deadline |
| 6. Access and offboarding | How access is granted and how it ends | A departed employee keeps a working account into the firm’s document store |
Which AI tools should a small firm approve, and on which accounts?
Name the tools, by product name, and name the account type. A policy that says "approved AI tools" without a list has settled nothing, because every reader supplies their own list. The account clause is the half that gets skipped and the half that does the work: the exposure a small office should plan for is not an exotic tool but a good tool used on a personal free account, where the firm has no logs, no administrative control, and no terms it has reviewed.
Two provisions are worth adding while the section is open. First, a route for requesting a new tool, so the answer to "can I try this" is a process rather than a quiet yes. Second, a line covering AI features that arrive inside software the firm already runs, since those appear without anyone deciding to adopt them.
Sample clause. Approved AI tools are Claude Team on firm-provisioned accounts. Personal, free, or individually purchased AI accounts may not be used for any firm work, including drafting, summarizing, research, and file organization. AI features built into other firm software must be reviewed and approved in writing before use. Requests to add a tool go to the managing partner and are decided in writing.
Which client data should never go into an AI tool?
Write the exclusion list as a list, and keep it somewhere a person can check in ten seconds. Categories beat adjectives: "sensitive information" is unenforceable, while a named list of matters, document types, and data categories is something a paralegal can actually apply at four in the afternoon.
- Matters under a protective order, or where the order’s scope has not been confirmed.
- Clients who have restricted AI use in an engagement letter or by written instruction.
- Categories the firm has decided to exclude outright, such as health information, financial account numbers, or government identifiers, unless the setup carries the agreements that work requires.
- Anything the responsible professional has not confirmed is covered by the firm’s vendor agreements.
Pair the list with a default. A policy that lists exclusions without stating what happens to an unlisted edge case leaves the edge case to a guess, and the guess will be made by whoever is busiest.
Sample clause. The excluded-matter list is maintained by the managing partner and reviewed quarterly. Material on that list may not be entered into any AI tool, in whole or in summary. Where a matter or document type is not addressed by this policy, it is treated as excluded until the managing partner confirms otherwise in writing.
Who reviews AI-drafted work before it leaves the firm?
This is the section that keeps a firm out of trouble, and it should be the most specific one in the document. Name the categories of work product, name who signs off on each, and state plainly that nothing goes out automatically. ABA Formal Opinion 512, issued in July 2024, applies the duties lawyers already carry to generative AI: competence, confidentiality, communication, supervision, candor, and reasonable fees. None of those are new obligations, and none of them are satisfied by a tool.
Citation checking deserves its own sentence rather than a clause buried in a paragraph. It is the failure mode with the shortest path from convenience to sanction, and a policy that names it explicitly gives a junior person permission to take the time.
Sample clause. No AI-assisted work product leaves the firm without review by the responsible attorney. This applies to client correspondence, filings, letters to counterparties, and anything submitted to a court or agency. Every legal authority produced with AI assistance is verified against the source by a person before it is cited. Automatic sending of AI-drafted material is prohibited without exception.
How should a firm configure AI training and data-retention settings?
Record the configuration, with the date it was checked, so the answer to a client’s question is a document rather than a recollection. As of August 2026, Anthropic does not train models on Team and Enterprise content by default, and Enterprise adds custom data retention, audit logs, SCIM, and a HIPAA-ready configuration option. Those are facts about a plan, and plans change, which is why the date belongs in the policy next to the fact.
One configuration detail is easy to miss and worth writing down. Anthropic documents that history from a Claude Cowork session running locally is stored on the user’s own computer, outside standard retention, where an administrator cannot centrally manage or export it. A firm with retention obligations should decide deliberately whether local sessions are permitted at all. What each control actually does, in plain terms, is set out in Is Claude safe for client data?.
Sample clause. The firm uses Claude Team, on which Anthropic does not train models on firm content by default, confirmed against vendor documentation on the date recorded in Appendix A. Data retention, access, and connector permissions are configured by the administrator named in Appendix A and reviewed at least annually. The configuration and the date of each review are recorded in that appendix.
Do you have to tell clients you used AI?
Decide the rule once, in advance, and name the person who decides the exceptions. Formal Opinion 512 discusses when the duty of communication with a client is triggered by AI use, and the analysis turns on the specific use, the engagement, and the jurisdiction. A guide cannot settle that for a particular firm. What a policy can do is stop the question being answered differently by four people under deadline.
Three disclosure surfaces are worth naming separately, because they have different answers: clients, courts and agencies with their own standing orders, and counterparties. One rule written for all three will be the wrong rule for at least one.
Sample clause. The firm’s default is to describe its use of AI tools in the engagement letter. Any disclosure beyond that default, and any court or agency requirement regarding AI-assisted filings, is decided by the responsible attorney, who confirms current requirements in the relevant jurisdiction before filing. Standing orders on AI use are checked at the start of each matter.
How does a firm remove AI access when someone leaves?
Access ends the day the job does, and the policy should say so with the same flatness as the rest of the document. This section is short, and it is the easiest one to leave out, because a small office that adds seats one at a time has no natural moment to write down how a seat is removed.
Cover the mirror image too. A policy that only handles departures leaves onboarding undefined, and an unsigned new hire with a provisioned seat is the same exposure viewed from the other end.
Sample clause. AI tool access is provisioned only after this policy is signed, and only to the matters and connected systems the role requires. On separation, AI accounts are deactivated on the final working day, together with all other firm access, and connected tool permissions are removed. Deactivation is recorded on the offboarding checklist.
Who signs the AI use policy, and how often should it be reviewed?
Everyone with an account signs it, before the account exists. That includes partners, and it includes contract and temporary staff, whose document-heavy work is exactly what an AI tool gets bought for.
- 01Everyone with an AI account signs before the account is provisioned, and new hires sign during onboarding.
- 02One named person owns the policy. A document owned by a committee is a document nobody updates.
- 03Review annually at minimum, and immediately whenever a plan tier changes, a new tool is approved, or a vendor changes its data terms.
- 04Record the review date on the document itself, so an outdated policy is visible rather than assumed current.
Training is the other half of adoption. A signed policy that was never explained produces compliance on paper, and someone who has never had the excluded-matter list explained to them cannot apply it.
What does an AI use policy not cover?
A policy is a management document. Whether it satisfies a particular bar rule, a regulator, a client contract, or a court’s standing order is a question for the professional responsible in that jurisdiction, and the answer varies by all four. A firm in a regulated practice should have counsel review the finished document before it circulates.
The other limit is scope. This document governs how people use approved tools; it does not decide which workflows are worth automating or how access to a document store should be scoped in the first place. Those decisions come earlier, and the beachhead version of them is in Claude for law firms.
Justo writes and delivers this document as part of a flat-fee engagement, alongside secure setup and training on your real work, from $3,500. Justo is attorney-founded; one of our three owners is a practicing attorney in Miami. Scope is on the pricing section of our main page.
Straight questions
How long should an AI use policy be?
Two or three pages for a small firm. The document has to make six decisions: approved tools and accounts, excluded data, review and signoff, configuration, disclosure, and offboarding. A longer document is not a stronger one, and the practical test is whether a new hire can read it and follow it in their first week.
Do we need a policy if only one or two people use AI?
Yes, and a two-person rollout is the cheapest moment to write an AI use policy. The exposure does not scale with headcount: one person entering material from a restricted matter into a personal account is the whole problem, and it is easier to write the rule before habits form than to correct them afterwards.
Can we just ban AI instead of writing a policy?
You can, but a ban is the weaker control. Without an approved alternative it leaves personal-account use as the only route, which is the worst available configuration: client material on consumer terms, no administrative logs, and no review rule. A ban still has to be written down, name the tools it covers including AI features inside software the firm already runs, and say who enforces it.
Who should sign the AI use policy?
Everyone with an account, before the account is provisioned, including partners and including contract and temporary staff. One named person should own the document, review it at least annually, and record the review date on the policy itself so an outdated version is visible rather than assumed current.
How often should the policy be reviewed?
Review an AI use policy annually at minimum, and immediately on any of three triggers: a change of plan tier, approval of a new tool, or a change to a vendor’s published data terms. Recording configuration facts with the date they were checked, as the configuration section of the policy does, makes those reviews quick rather than investigative.