IT First Response

Guides

What a small law firm's AI policy needs to say

By Mario Del MazoAugust 2, 20266 minute read

At most small firms, someone is already using AI: to summarize a document, draft a letter, or untangle an email thread. That is happening whether or not the firm has a policy, and having no policy is not the same as having no exposure. The Florida Bar and the ABA have both issued guidance on generative AI, and the questions they raise, confidentiality, supervision, and candor, all run through decisions that are practical before they are ethical: which tool, on what terms, visible to whom, reviewed by whom. This guide is that practical side. It is not an ethics opinion, and your Bar's guidance is the controlling document.

The risk is not the robot, it is the paste

The single scenario an AI policy exists to prevent is simple: a staff member pastes client facts into a free consumer chatbot to save twenty minutes. Whatever the intent, that is a disclosure of client information to a third party, and it happens the moment the text is submitted. Some tools retain what they are given and some use it to train their models; some contractually commit to doing neither. That difference lives in the vendor's terms, which almost nobody at a busy firm has read. The policy's job is to make sure nobody has to read them at the moment of temptation, because the decision was already made.

Why banning AI outright backfires

The instinctive answer is to prohibit all of it, and it is the one answer that reliably fails. A ban does not remove the demand; it moves the same activity onto personal phones and home computers, where the firm has no visibility, no terms, and no logs. The firms that govern this well do the opposite: they pick one tool whose terms they have verified, make it available, and block the rest. Staff get the twenty minutes back, and the firm knows where its information goes.

The six things the policy has to say

A useful AI policy for a small firm fits on two pages and answers six questions:

Where the ethics guidance sits

The Florida Bar's ethics guidance on generative AI and the ABA's formal opinion on the subject cover the lawyer's side of this ground: confidentiality, competence, oversight of the technology, and honesty about fees when AI shortens the work. Read them, or ask the Bar's ethics hotline how they apply to your practice; that part is legal territory and stays yours. The boundary runs the other way too. Whether an AI-assisted draft is correct is legal judgment, and no IT provider belongs in that loop. What an IT provider can do is make the six mechanics above true: the approved tool configured, the unvetted ones blocked, the usage visible, and the records kept.

Start by finding out what is already in use

Most firms that go looking find AI use they did not know about, which is not a scandal; it is the baseline the policy has to meet. DNS and web filtering, the same layer that blocks malicious sites, can show which AI services firm devices are reaching and enforce the approved list once one exists. This is also now a standing section of the cybersecurity assessment I run for law firms: whether a policy exists, whether staff have acknowledged it, whether an approved tool is available, and whether anyone can see what is actually being used.

FAQ

Can we just block ChatGPT on the office network?

You can, but a block on its own tends to move the same activity onto personal phones, where the firm can see nothing at all. Blocking unvetted tools while providing one approved alternative is the combination that actually changes behavior.

Is the paid version of a chatbot safe for client information?

Not automatically. What decides it is the vendor's terms: business tiers often commit in writing not to train on or retain what you submit, while consumer tiers often say the opposite. Read the terms for the specific tier you are on, keep a copy, and treat any tool without that commitment as off limits for client and matter information.

Does this apply if we only use AI for marketing, never client work?

Yes, because the policy is what keeps that boundary real. A written scope stating where AI may be used is how marketing use stays marketing use. Advertising content also has its own Bar rules, and that part is a question for the Bar, not for an IT provider.

What does help with this cost?

Reviewing AI use is a standing section of the cybersecurity assessment I run for law firms, so it is covered there rather than sold separately. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.

Want to know what your staff are already using? AI governance is one section of the assessment I run for small law firms, alongside the controls insurers and clients ask about. The first conversation is free, and there is nothing to decide at the end of it. What ongoing support costs is published in what IT support costs a small law firm in Florida.

About the author

Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.