Why does a firm of 20 to 200 people need an AI policy?
Because staff are already using AI, whether or not the firm has decided anything. Without a policy, each person makes their own call about which tool to use and what to paste into it. Some will be too cautious and get no benefit. Others will put confidential client material into a personal account without thinking twice. Both are problems, and a policy fixes both by making the rules clear.
A good policy is not a legal document written to protect the firm after the event. It is a working guide that tells a fee earner, on a busy afternoon, what they can and cannot do. If they need to ask someone every time, the policy has not done its job.
What should an AI policy cover?
This structure works for most professional services firms. Each section should be a few short paragraphs or a list, not pages.
1. Purpose and scope
One paragraph. Why the firm uses AI, who the policy applies to (partners, staff, contractors, anyone working on firm or client material) and which tools it covers. Define AI broadly enough to include assistants built into software you already use, not only standalone chat tools.
2. Approved tools
A named list of tools staff may use, the account type they must use (firm accounts, not personal ones) and what each is approved for. A simple table works well: the tool, the information allowed in it, and the tasks it may be used for. Anything not on the list is not approved for firm or client work until it has been assessed.
3. Information rules
The heart of the policy. Classify information in a way staff already understand and say which categories may go into which tools. A workable set for most firms:
- Public: published material. Any approved tool.
- Internal: firm documents with no client or personal data. Approved firm tools only.
- Client confidential: anything a client has shared or that relates to a matter, engagement or case. Only tools approved for client work, and only within the terms of the client's engagement and any confidentiality agreement.
- Special category and highly sensitive: health information, criminal records, and material a client has flagged as sensitive. Named tools only, with extra approval, or not at all.
Link this section to your data protection arrangements. Our guide to data protection and AI on client work sets out the UK GDPR questions to answer first.
4. Permitted and prohibited uses
Give concrete examples. Permitted uses might include drafting from the firm's own templates, summarising meeting notes, preparing first drafts of reports and searching internal knowledge. Prohibited uses might include giving advice to a client without professional review, making decisions about individuals without a person involved, and producing anything presented as the work of a named professional who has not checked it.
5. Review and accountability
State the rule plainly: AI drafts, people approve. Every output that goes to a client, a regulator or a counterparty is reviewed and signed off by a named, suitably qualified person, who is accountable for it as if they had written it. Set out what the reviewer checks. Reviewing AI output on client work gives a checklist you can adapt.
6. Client disclosure
Say when and how the firm tells clients about AI use: in engagement letters, in response to questions, or where a client's terms require it. Some firms disclose in general terms to all clients; others only where asked. Either can be defensible, but the policy should decide rather than leave it to each fee earner. Telling clients you use AI explores the choice.
7. Professional and regulatory duties
Remind staff that professional obligations do not change because a tool was involved. Firms regulated by bodies such as the SRA, ICAEW, ACCA, RICS or the FCA should reference their regulator's expectations on competence, supervision and confidentiality in general terms, and check any guidance the regulator has issued on technology.
8. Requesting a new tool or use
A short route for staff to propose a new tool or a new use: who they ask, what information they provide and how long a decision takes. Without this, people go around the policy instead of through it.
9. Incidents
What to do if confidential or personal data goes into the wrong tool, or if AI produced output reaches a client with an error. Point to your existing data breach and complaints procedures rather than inventing new ones.
10. Training, ownership and review
Who owns the policy, how staff are trained on it, and how often it is reviewed. AI tools and their terms change quickly, so a review every few months is sensible in the early period, plus a review whenever a new tool is approved.
How do you write it without it becoming shelfware?
- Write it with fee earners. Test each rule against a real task: can someone preparing tomorrow's client report tell from the policy what they may do?
- Use plain language. "Do not paste client documents into personal accounts" beats a paragraph of definitions.
- Put a one page summary at the front. Most people will only ever read that page.
- Provide the approved route. A policy that restricts personal tools but offers no approved alternative will be ignored. This is how shadow AI grows.
- Make it part of how work is done. The strongest control is a process where the approved tool and the review step are simply built in, so following the policy takes no extra effort.
What order should you do this in?
- Find out what staff use today. Ask openly, without blame.
- Decide the information categories and which tools each may go into.
- Choose and set up at least one approved tool on firm accounts.
- Draft the policy using the structure above, then test it with a handful of fee earners.
- Have the partners or board approve it.
- Brief everyone, with examples from their own work.
- Review it after the first few months of real use.
Is a policy enough to get value from AI?
No. A policy makes AI use safe. It does not make it useful. Firms that stop at the policy often find people follow the rules and still get little from the tools, because nothing about their actual jobs has changed. Pair the policy with one process rebuilt properly, and the rules and the benefit arrive together. The audit points to the process to start with, and getting a team to adopt AI covers what happens next.