Law Firm AI Policy: The One-Page Template You Can Adapt Today
Half the AI-ethics advice ends with 'adopt a one-page AI policy' and then leaves you to write it. This is that page — a ready-to-adapt one-page law firm AI policy grounded in ABA Formal Opinion 512 and the Garner v. Kadince sanctions case, with a section-by-section table and five adaptation notes by firm type.
A law firm AI policy is a short internal document that says which AI tools your firm allows, what client information each may touch, and the rules everyone follows before AI-touched work reaches a court or a client. It should fit on one page. A lot of the AI-ethics advice you have read — including two of our own guides — ends by telling you to "adopt a one-page AI policy" and then leaves you to write it. This article is that page.
Below is a template built around the duties that govern the question, a table mapping each section to the rule behind it, and five notes on adapting it by firm type. Copy it, cut what does not fit, and run it past your own counsel before it goes on the wall.
Why your firm needs one now
Two developments turned "you should probably write something down" into a supervision obligation.
First, the American Bar Association told firms to. ABA Formal Opinion 512 (July 29, 2024), the first national ethics guidance on generative AI, reads the existing rules onto the technology: competence in a tool's limits (Rule 1.1), protection of client confidences (Rule 1.6), candor to the court (Rule 3.3), honest billing (Rule 1.5), and — the operative one here — supervision. Under Model Rules 5.1 and 5.3, lawyers with managerial authority must establish clear policies on permissible AI use and make sure everyone in the firm, including nonlawyer staff and outside contractors, follows them. A firm-wide practice with no written rule is the thing the opinion tells you to fix.
Second, a court proved what happens without one. In Garner v. Kadince, 2025 UT App 80, the Utah Court of Appeals sanctioned a firm after a petition cited cases that did not exist — one, Royer v. Nelson, lived only in ChatGPT's output. An unlicensed law clerk had drafted it with AI, and the signing attorney filed it without checking the citations. The court called it a failure of the attorneys' "gatekeeping responsibilities" and ordered them to pay the opposing party's fees, refund the client, and donate $1,000 to the legal-aid group "and Justice for All." It is not an outlier: a public database of AI-hallucination court incidents now tracks well over a thousand in the United States alone.
The through-line from Opinion 512 to Garner is that the firm, not just the individual lawyer, owns the risk. A one-page policy is how you own it on purpose. (For the national picture, see our guide on whether lawyers can use AI for legal research; for the Utah authorities specifically, what governs Utah lawyers using AI.)
What the policy has to cover
Seven sections, each tied to a duty. Keep the whole thing on one page — a policy nobody finishes is a policy nobody follows.
| Policy section | What it covers | Anchored in |
|---|---|---|
| Approved tools | Which AI tools may touch client work, and the bar a tool must clear to qualify | Rule 1.1 (competence); Op. 512 |
| Client data by tier | What client information each class of tool may receive | Rule 1.6 (confidentiality); Op. 512 |
| Verification | No AI-touched citation or proposition reaches a filing or client unchecked | Rule 3.3 (candor); Garner |
| Disclosure | When the firm tells clients — and courts — about AI use | Op. 512; state AI statutes |
| Billing | Bill time actually spent; do not charge clients to learn the tool | Rule 1.5 (fees); Op. 512 |
| Training | Everyone who uses AI reads the policy; supervisors enforce it | Rules 5.1 / 5.3 (supervision) |
| Incident protocol | What to do when a bad citation surfaces after filing | Rule 3.3 (duty to correct) |
The billing row does more work than its single line suggests: AI compresses the hours behind a task, and billing honestly for AI-assisted work is its own question under Rule 1.5 that Section 5 only summarizes.
The one-page policy (copy and adapt)
[Firm Name] — Generative AI Use Policy Adopted [date]. Applies to every lawyer, paralegal, law clerk, and contractor who works on firm matters. This is a starting draft — adapt it with your own counsel and your state bar's guidance before adopting.
1. Approved tools. The firm's approved AI tools are: [list them by name]. Use only approved tools for any work touching a client matter. To be approved, a tool must (a) retrieve and link its sources rather than generate citations from a model's memory, and (b) keep firm data isolated from other customers and out of model training by contract, not by a settings toggle. Personal accounts on consumer chatbots are not approved for client work. Requests to add a tool go to [name/role].
2. Client data by tool tier.
- Tier A — approved legal tools with contractual confidentiality and per-firm isolation: client matter data permitted.
- Tier B — business/enterprise general AI under a no-training agreement: de-identified work only; no client names or identifying facts without [supervising lawyer] approval.
- Tier C — consumer or free chatbots: no information relating to any representation, ever — no facts, drafts, or documents.
3. Verification. No AI-touched citation, quotation, or statement of law reaches a filing, a client, or opposing counsel until a person confirms it against the primary source: existence first, then support, then current treatment. The signing lawyer owns this. It cannot be delegated to a clerk or to the tool.
4. Disclosure. The firm [does / does not] routinely note internal AI use in engagement letters. The firm discloses when a client asks, when AI use is material to the representation, or when a client interacts with an AI tool directly (for example, a website intake bot), consistent with Rule 1.6, ABA Opinion 512, and any applicable state AI statute.
5. Billing. Bill the time actually spent, not the time the task used to take. Do not bill a client for time spent learning an AI tool, and do not pass the tool's subscription through as a line item unless the client has agreed to it.
6. Training. Anyone who uses AI on firm work reads this policy and completes [the firm's AI onboarding] before doing so. Supervising lawyers are responsible for the compliance of the staff and contractors they oversee.
7. Incident protocol. If a fabricated or unsupported citation is discovered after a filing goes out: notify the supervising lawyer immediately, and correct the record with the tribunal promptly. Candor comes first — a prompt correction is a duty under Rule 3.3, and concealment is what turns a mistake into misconduct. Then identify how it got through unverified and close that gap.
That last line about adapting with your own counsel is not boilerplate. State bars are moving at different speeds, and a few states now layer statutory duties on top of the Rules, so a policy that is airtight in one jurisdiction may be missing a disclosure line in another.
Where the product angle is honest
Two sections touch what a research tool actually does. Section 1's approval test — retrieves and links its sources, keeps firm data isolated by contract — is the filter that separates a research tool from a drafting toy. Those happen to be the properties CaseRead is built on: answers cite only sources the system retrieved, and each firm's files sit in their own isolated schema rather than shared rows. But the test is the point, not the vendor; apply it to everyone, us included. Our three filters that sort legal AI tools and the four questions to ask before client data touches any tool are the longer versions of Sections 1 and 2.
Section 3 is the one that gets skipped under deadline — which is exactly how Garner happened, and how a filing draws Rule 11 sanctions. The Hallucination Shield checks every citation in AI-drafted text for existence and support, free and with no signup, so the verification line has a two-minute default action instead of a good intention; the deeper pre-filing verification workflow covers support and treatment by hand.
Adapt it by firm type
The template is a floor. Five common situations that change a line or two:
- Solo practitioner. You are the supervising lawyer, the staff, and the signer. Sections 5 and 6 shrink, but Section 3 gets more important — there is no second set of eyes, so the verification habit is your only backstop. Keep the incident protocol even though "notify the supervising lawyer" means notify yourself in writing.
- Litigation-heavy firm. Filings are where the sanctions live. Tighten Section 3 into a checklist tied to your filing process, and require a verification sign-off initial on anything headed to a court or arbitrator. Your associates and clerks are the Garner fact pattern, so Section 6 is load-bearing.
- Transactional or estate-planning firm. You file less but handle dense confidential documents, so Section 2 does the heavy lifting. Be explicit that client financials, medical facts, and identifying details never touch a Tier C tool.
- Firm with paralegals and non-lawyer staff. Rules 5.1 and 5.3 reach every one of them. Name in Section 6 who trains staff and who signs off on their AI-assisted work; a paralegal's AI use is the supervising lawyer's responsibility, exactly as in Garner.
- Firm using client-facing AI. If clients interact with an intake bot or receive AI-drafted communications, Section 4 is no longer optional. Some states — Utah among the first — impose a statutory disclosure duty when a consumer interacts with AI directly in a regulated service.
The bottom line
A law firm AI policy is not a compliance artifact you file and forget. It is the one page that turns "we should be careful with AI" into named tools, tiered data rules, a non-delegable verification step, and a plan for the day something slips through. Opinion 512 asks for it and Garner shows the cost of skipping it. Draft it from the template above, size it to your practice, and have your own counsel bless it.
Then wire the verification line to something real: run any AI-drafted text through the Hallucination Shield before it reaches a court or client — free, no signup, and the two-minute habit that keeps your firm off the sanctions tracker.
Frequently asked questions
What should a law firm AI policy include? Seven things fit on one page: the list of approved AI tools, what client data each tool tier may receive, a verification rule that no AI-touched citation reaches a filing or client unchecked, the firm's disclosure posture, billing honesty, a training expectation for everyone who uses AI, and an incident protocol for a bad citation discovered after filing. Each maps to a specific ethics duty, so a short policy covers the obligations without becoming a manual nobody reads.
Does a law firm legally need an AI policy? No rule uses the words "AI policy," but the duty is effectively there. ABA Formal Opinion 512 says lawyers with managerial authority must establish clear policies on generative-AI use and supervise staff for compliance, under Model Rules 5.1 and 5.3. Garner v. Kadince sanctioned a Utah firm precisely because a supervising attorney signed a clerk's AI-drafted filing without checking it. A written policy is how a firm discharges the supervision duty rather than hoping.
Is there a free law firm AI policy template? Yes. The template in this article is free to copy and adapt, and it is built around the duties in ABA Formal Opinion 512 and the lesson of Garner v. Kadince. It covers approved tools, client data by tool tier, verification, disclosure, billing, training, and an incident protocol. Treat it as a starting draft: run it past your own counsel and check it against your state bar's guidance and any state AI statute before adopting it firm-wide.
What should a firm's AI policy say about client data and ChatGPT? Sort tools by tier. Approved legal tools with contractual confidentiality and per-firm isolation may receive client matter data. Business or enterprise AI with a no-training agreement should be limited to de-identified work. Consumer or free chatbot tiers get no information relating to any representation — no facts, drafts, or documents — because those tiers may retain and train on what you paste. Rule 1.6 and ABA Opinion 512 make where the data goes the whole question.
What should a firm do if it discovers a fake AI citation after filing? Candor first. Tell the supervising lawyer immediately and correct the record with the tribunal promptly. Model Rule 3.3 imposes a duty of candor toward the court, including correcting a false statement of law previously made, and courts have treated lawyers who own the error and fix it far better than those who conceal it. Then find how the citation got in unverified and close that gap in the policy so it does not recur.
CaseRead Team
AI-powered legal research built for practicing attorneys.