What a small law firm's AI policy needs to say
At most small firms, someone is already using AI: to summarize a document, draft a letter, or untangle an email thread. That is happening whether or not the firm has a policy, and having no policy is not the same as having no exposure. The Florida Bar and the ABA have both issued guidance on generative AI, and the questions they raise, confidentiality, supervision, and candor, all run through decisions that are practical before they are ethical: which tool, on what terms, visible to whom, reviewed by whom. This guide is that practical side. It is not an ethics opinion, and your Bar's guidance is the controlling document.
The risk is not the robot, it is the paste
The single scenario an AI policy exists to prevent is simple: a staff member pastes client facts into a free consumer chatbot to save twenty minutes. Whatever the intent, that is a disclosure of client information to a third party, and it happens the moment the text is submitted. Some tools retain what they are given and some use it to train their models; some contractually commit to doing neither. That difference lives in the vendor's terms, which almost nobody at a busy firm has read. The policy's job is to make sure nobody has to read them at the moment of temptation, because the decision was already made.
Why banning AI outright backfires
The instinctive answer is to prohibit all of it, and it is the one answer that reliably fails. A ban does not remove the demand; it moves the same activity onto personal phones and home computers, where the firm has no visibility, no terms, and no logs. The firms that govern this well do the opposite: they pick one tool whose terms they have verified, make it available, and block the rest. Staff get the twenty minutes back, and the firm knows where its information goes.
The six things the policy has to say
A useful AI policy for a small firm fits on two pages and answers six questions:
- What may never go in. Client and matter information stays out of any tool the firm has not vetted and approved, full stop. Names, facts, documents, and anything that could identify a client or a matter.
- Which tool is approved. Name it. A policy that only prohibits leaves staff to improvise; a policy that names the sanctioned tool, set up on business terms with data protection in place, gives them somewhere legitimate to go.
- What the vendor does with what you type. The approved tool's terms have been read, they state whether submissions are retained or used for training, and a copy is on file. When the terms change, someone rechecks them.
- Who can see usage. The firm can see which AI services are being reached from firm systems. Use that nobody can see cannot be governed, and the first time it surfaces should not be during an incident.
- Who reviews the output. A named person reviews AI-assisted work before it leaves the firm. Responsibility for the work product stays with the firm no matter what produced the first draft.
- Who has acknowledged it. Staff sign the policy and are trained on it, and the acknowledgments are kept. A policy nobody has read governs nothing.
Where the ethics guidance sits
The Florida Bar's ethics guidance on generative AI and the ABA's formal opinion on the subject cover the lawyer's side of this ground: confidentiality, competence, oversight of the technology, and honesty about fees when AI shortens the work. Read them, or ask the Bar's ethics hotline how they apply to your practice; that part is legal territory and stays yours. The boundary runs the other way too. Whether an AI-assisted draft is correct is legal judgment, and no IT provider belongs in that loop. What an IT provider can do is make the six mechanics above true: the approved tool configured, the unvetted ones blocked, the usage visible, and the records kept.
Start by finding out what is already in use
Most firms that go looking find AI use they did not know about, which is not a scandal; it is the baseline the policy has to meet. DNS and web filtering, the same layer that blocks malicious sites, can show which AI services firm devices are reaching and enforce the approved list once one exists. This is also now a standing section of the cybersecurity assessment I run for law firms: whether a policy exists, whether staff have acknowledged it, whether an approved tool is available, and whether anyone can see what is actually being used.
FAQ
Can we just block ChatGPT on the office network?
You can, but a block on its own tends to move the same activity onto personal phones, where the firm can see nothing at all. Blocking unvetted tools while providing one approved alternative is the combination that actually changes behavior.
Is the paid version of a chatbot safe for client information?
Not automatically. What decides it is the vendor's terms: business tiers often commit in writing not to train on or retain what you submit, while consumer tiers often say the opposite. Read the terms for the specific tier you are on, keep a copy, and treat any tool without that commitment as off limits for client and matter information.
Does this apply if we only use AI for marketing, never client work?
Yes, because the policy is what keeps that boundary real. A written scope stating where AI may be used is how marketing use stays marketing use. Advertising content also has its own Bar rules, and that part is a question for the Bar, not for an IT provider.
What does help with this cost?
Reviewing AI use is a standing section of the cybersecurity assessment I run for law firms, so it is covered there rather than sold separately. Work for businesses not on a plan is billed at $125 per hour, and larger projects are quoted up front so you approve the number before the work starts.
Want to know what your staff are already using? AI governance is one section of the assessment I run for small law firms, alongside the controls insurers and clients ask about. The first conversation is free, and there is nothing to decide at the end of it. What ongoing support costs is published in what IT support costs a small law firm in Florida.
About the author
Mario Del Mazo is the owner of IT First Response, a managed IT and security practice in Fort Myers serving Lee County, Florida. His background is corporate IT for a healthcare organization operating under HIPAA and HITRUST standards. He publishes his prices, and every client environment is documented so nothing has to be explained twice. More about Mario.
