Most small firms adopt AI in the wrong order. A paralegal starts drafting with ChatGPT, an associate runs client emails through a summariser, and six months later someone asks the obvious question: what are the rules? By then you already have habits — some good, some risky — and no way to prove to a client, an insurer or the regulator that you had things under control.
An internal AI policy fixes that. It doesn't have to be long, and it shouldn't read like a piece of legislation. The best policies for a small practice are short, specific and written so that everyone from the front desk to the principal actually understands them. This article walks through exactly what to cover, structured as a checklist you can adapt.
Why a small firm needs a written AI policy
Three reasons, in order of importance.
First, confidentiality and privilege. Your professional obligations don't change because the tool is new. If a staff member pastes a client's affidavit into a free consumer chatbot, you may have disclosed confidential information to a third party — and possibly used it to train a model. A policy sets the boundary before the mistake happens.
Second, quality and accountability. Generative AI produces confident, fluent, and sometimes completely fabricated output. There have already been well-publicised cases overseas of lawyers filing submissions citing cases that never existed. A policy makes clear that AI output is a draft, never a final work product, and that a named human is always responsible.
Third, consistency. Without a policy, every person invents their own rules. With one, you get predictable behaviour you can supervise, audit and improve.
The seven things your AI policy must cover
Use these as the sections of your document. Each one should be a few plain sentences, not a page of qualifications.
1. Scope — who and what this covers
State plainly that the policy applies to everyone in the firm — partners, solicitors, paralegals, admin and contractors — and to all AI tools, whether the firm pays for them or someone uses a free version on their own login. Make it explicit that using a personal ChatGPT account for firm work is still covered. The most common gap in early policies is that they only mention the tools the firm officially bought.
2. Approved tools
List the specific tools staff are allowed to use, and for what. Don't write "AI tools are permitted where appropriate" — that tells people nothing. Instead, maintain a short table like this:
| Tool | Approved for | Not approved for |
|---|---|---|
| Microsoft Copilot (firm licence) | Drafting, summarising internal documents | — |
| ChatGPT (paid Team plan) | Research prompts, drafting with no client-identifying detail | Uploading client documents |
| Free / personal chatbots | Nothing firm-related | All firm work |
The key distinction is between tools with an enterprise or business agreement — where the vendor contractually agrees not to train on your data — and consumer versions where your inputs may be retained. Favour paid business tiers, and read the data-handling terms before you approve anything. When a new tool is proposed, route it through one person (usually the principal or practice manager) rather than letting it spread informally.
3. Client confidentiality and data handling
This is the heart of the policy. Set a clear default and a clear exception.
- Default rule: no client-identifying information goes into any AI tool unless that specific tool has been approved for it.
- Anonymise first: where staff need to use a general tool, they strip names, addresses, matter numbers and any detail that could identify a party before pasting anything in.
- Know where the data goes: only tools with data residency and no-training guarantees may handle confidential material. If you can't answer "where is this stored and who can see it?", the tool isn't approved for client data.
It's worth reminding staff that the Australian Privacy Principles and your duty of confidentiality apply to AI inputs exactly as they apply to email and cloud storage. Nothing about the technology creates an exemption.
4. Approval gates for anything that touches advice
Draw a hard line between administrative use and substantive legal work. Admin tasks — summarising a long internal document, drafting a booking confirmation, tidying up a file note — carry low risk. Anything that could form part of advice to a client, a court submission, or a contract carries high risk and needs a human gate.
Spell out the gate. For example:
- AI may produce a first draft of a letter, clause or memo.
- A qualified solicitor must review every substantive point, verify every citation against a primary source, and confirm the reasoning.
- The solicitor's name goes on the work product. AI is never cited as the author or the authority.
- Nothing AI-generated leaves the firm without that review.
The rule to burn into everyone's mind: AI drafts, humans decide. Verifying case citations deserves its own line, because that is precisely where firms have been publicly embarrassed.
5. Logging and record-keeping
You can't supervise what you can't see. Decide how the firm records AI use, proportionate to your size. For a small practice, a lightweight approach works:
- For substantive matters, a short file note stating that AI assisted with a draft and that a named solicitor reviewed it.
- A central register of approved tools, who owns each one, and when the terms were last reviewed.
- Retention of prompts and outputs where a tool allows it, so you can reconstruct what happened if a question arises later.
This doesn't need to be heavy. The goal is that if a client, your insurer or the Legal Services Commission asks how AI was used on a matter, you have an answer on file rather than a shrug.
6. Disclosure to clients
Decide your position on telling clients when AI is used, and write it down. Many firms are comfortable with internal, administrative use going undisclosed, while flagging any material use in the engagement terms. At minimum, make sure your costs agreement and privacy notice don't contradict what actually happens. If you're unsure, disclosing your use of AI tools in your engagement documents is the safer default.
7. Training, breaches and review
State who is responsible for the policy, how staff are trained on it, and what happens when someone breaches it — treated the same as any other confidentiality or supervision breach. Set a review date. AI tools and their terms change quickly, so a policy that's reviewed once and forgotten is worse than useless because it creates false comfort. A six-monthly review is reasonable for most firms.
A note on automation, not just chatbots
Most AI policies focus on staff typing into a chatbot. But firms increasingly connect AI into automated workflows — intake, document generation, email triage — that run without a person watching each step. Those deserve the same scrutiny. If you're building automations with tools like Zapier, apply the same confidentiality and approval rules to the data flowing through them. Our guide to Zapier for lawyers covers where automation genuinely saves time, and the same governance principles apply. If you automate client intake with Notion and Zapier, make sure the AI steps in that pipeline only touch data they're approved to touch.
Keep it to two pages
A policy nobody reads protects nobody. Resist the urge to make it comprehensive. Aim for two pages: the seven sections above, a table of approved tools, and a one-line summary at the top that anyone can remember. Something like:
Only approved tools. No client-identifying data in general tools. A qualified solicitor reviews everything substantive and puts their name to it. If in doubt, ask before you paste.
That single paragraph will prevent more problems than ten pages of caveats ever will.
Where to start this week
Don't wait for the perfect document. Draft the approved-tools table today, circulate the one-line summary to your team, and book a 30-minute conversation to agree the confidentiality default. You can refine the rest over the following fortnight. The important thing is to replace "whatever people are already doing" with a shared, written standard.
If you'd like a fuller framework to build from, the governance section of our free guide, 10 AI Workflows to Save 10+ Hours a Week, walks through how to introduce AI across a professional services firm safely — including the guardrails that turn a scattered set of habits into a policy you can stand behind.
Want these ideas working in your firm? We build controlled AI workflows for Australian professional services firms — starting with a free automation audit.