Butler Snow had a written AI policy from June 2023 requiring approval and verification. A partner used ChatGPT anyway, an associate reviewed the result “for grammar and typos”, and in July 2025 Judge Anna Manasco disqualified three partners, referred them to the Alabama State Bar and wrote: “They benefitted from repeated warnings, internal controls, and firm policies about the dangers of AI misuse… And yet here we are” (EDRM). The firm, which then had outside counsel check 2,400 citations across 330 filings, was not sanctioned; the three partners were.

That is the case for a law firm AI policy template in one paragraph: the document will not stop a determined partner, but it is the difference between the firm being sanctioned and the individual being sanctioned. What follows is not a PDF behind an email form. It is the eight clauses, the data classification that makes them enforceable, and the ethics source for each.

Why 57% of firms have no policy and only 9% enforce one

Clio’s 2026 numbers, via the North Carolina Bar Association: 57% of solos and 55% of small firms have no AI policy. The 8am 2026 Legal Industry Report found 43% of legal professionals have no policy and no plans for one, and only 9% work under a written policy that is enforced. Thomson Reuters found 34% use unsanctioned “shadow AI” tools. A Texas Bar respondent in 2026: “Sample AI policies would be very helpful. If they exist, I haven’t found them yet.”

Where policies exist, some are simply bans, and bans fail in a specific way. The NC Bar’s phrase: “prohibition drives usage underground; clear policies bring it into the open where it can be supervised” (Beyond the ban).

The traffic-light model: green, amber, red data

Classify the information, not the vendor, because the same product exists in a tier that trains on your inputs and a tier that does not. Casemark’s tiers, as the NC Bar summarises them, put client data in consumer tools, unverified fact-finding and automated client decisions in red; research, review and first drafts with verification in yellow; admin, marketing and scheduling in green. LeanLaw’s one-page template allows Confidential and Highly Sensitive data only in tools with “contractual no-training terms, data isolation, and role-based access”.

Tier What it covers Where it may go Control
Green Public information, abstract legal questions unlinked to a matter, marketing drafts, admin, learning the tool Any approved tool, including a consumer tier Ordinary review
Amber Client material, anonymised with placeholders and an offline key; first drafts, summaries, research skeletons Commercial no-training tier only: ChatGPT Business or Enterprise, Claude Team or Enterprise, Copilot with enterprise data protection, a legal platform Line-by-line review; log tool, date, reviewer
Red Privileged strategy, witness statements, protective-order and subpoenaed material, health data, pre-announcement deal terms, anything filed with a court Enterprise zero-retention deployment or legal platform under contract; counsel-directed; never consumer Full verification, documented; partner sign-off

The amber line is the one the BRAK draws in Germany for public tools, only “abstract” prompts allowing no inference about a specific matter; the red line is the one Morgan v. V2X (D. Colo. 2026) drew when it barred confidential information from any AI platform whose provider is not contractually prohibited from training on or disclosing inputs.

Clause 1: approved tools and tiers

Clause. “Lawyers and staff may use only the tools in Schedule A, on the tier stated, under firm-managed accounts. Personal or consumer accounts may not be used for amber or red data. New tools require approval by [the AI lead] after the vendor questionnaire in Schedule B.”

The Oregon State Bar Professional Liability Fund’s guidelines say to name approved tools “so staff understand which tools are approved… and are prohibited from using unvetted tools”; ILTA found 48% of firms already restrict use to vetted applications. The schedule needs tiers, not brands: ChatGPT Free, Plus and Pro train on inputs unless the user opts out, Business and Enterprise do not by default; consumer Copilot trains, Copilot on a work tenant with enterprise data protection does not. The confidentiality guide has the tier-by-tier table.

Clause 2: confidentiality and anonymisation

Clause. “No information relating to a client may enter a tool that trains on inputs or shares them with third parties without that client’s informed consent. Amber data is anonymised before use: names, addresses, amounts, dates and identifiers replaced with placeholders, metadata stripped, the key kept offline. Feedback buttons are never used on client material.”

ABA Formal Opinion 512 requires informed consent “prior to inputting information relating to the representation” into a self-learning tool and says “boiler-plate provisions” in engagement letters are not enough; the New York City Bar adds that even with consent lawyers should “avoid entering details that can be used to identify the client”. Two 2026 decisions set the stakes: United States v. Heppner, where a defendant’s consumer Claude exchanges were held protected by neither privilege nor work product, and [2026] UKUT 81 (IAC), where putting client letters into ChatGPT was held “to place this information on the internet in the public domain”. The BRAK’s caution applies everywhere: removing names and addresses is often not enough if the matter can be inferred from context.

Anonymise before any amber-tier use
Before I work with this document, replace every personal name, company name, address, account number, date of birth, case number and unique identifier with consistent placeholders ([PERSON_1], [COMPANY_A], [ACCOUNT_1], [DATE_1]) so the document stays internally coherent. Generalise contextual identifiers that would allow re-identification (unusual job titles, unique events, small towns). Output the anonymised text and a separate key table. Do not summarise or alter any other content.

Run it on a local model or an enterprise tool, never on the consumer tier you are protecting the client from; the anonymisation guide covers metadata and the key.

Clause 3: verification before filing

Clause. “No document is filed, served or sent to a client containing any authority, quotation, fact or figure produced with AI assistance that the responsible lawyer has not personally read and verified in a primary source. Verification is never performed with another AI tool. The verifier records name, database and date in the matter file. Signing a document you have not read is a breach of this policy.”

Every phrase has a case behind it. “Personally read and verified” is the California Court of Appeal in Noland v. Land of the Free, since quoted by the Sixth Circuit. “Never with another AI” is the Mata error, asking ChatGPT whether its own cases were real, now a written rule in New South Wales and Victoria. The Ninth Circuit’s standard in Lnu v. Blanche (June 2026): “A competent and diligent attorney must also read and reason.” The signing rule comes from Wadsworth v. Walmart, where a Morgan & Morgan partner and local counsel paid $1,000 each for signing, unread, a motion with eight fabricated cases, and Judge Rankin called signing a “nondelegable” duty; the firm then emailed more than 1,000 lawyers that fake citations “can result in termination”. The six-layer citation check is the procedure the clause points to.

Build the citation table, then verify it yourself
List every case, statute, rule and secondary source cited in <document>…</document> in a table: Citation as written | Type | Proposition it is cited for (quote the sentence) | Pinpoint given? | Quotation? (Y/N). Do not verify anything and do not say whether any citation exists; a lawyer will check each row in a primary database and record the result.

Clause 4: disclosure to clients and courts

Clause. “The engagement letter describes the categories of AI tool the firm uses, the human-review commitment and the billing rule. Beyond that, a lawyer discloses AI use when the client asks, when client information will enter a self-learning tool, when AI use affects the fee, when substantive work is delegated to a tool, or when a court requires it. Before filing, the lawyer checks the assigned judge’s standing orders.”

ABA 512 calls the engagement agreement “a logical place” for disclosure; North Carolina’s 2024 Formal Ethics Opinion 1 says a lawyer “need not inform her client that she is using an AI tool to complete ordinary tasks” but needs “advanced informed consent” to delegate substantive work. Courts vary: Judge Starr’s certificate in the Northern District of Texas, the Federal Court of Canada’s first-paragraph declaration, Illinois’ policy that disclosure “should not be required in a pleading”, and Lnu’s two-year disclosure order for one firm. The disclosure guide sorts the jurisdictions; AI note-takers on client calls need their own consent rule, covered in the note-taker guide.

Clause 5: billing

Clause. “Hourly clients are billed for actual time, including time spent prompting and reviewing output; never for time saved or for learning a tool. Subscriptions are overhead. Matter-specific AI costs are passed through at cost with prior written consent. Flat fees are permitted where not clearly excessive and consented to.”

NC FEO 1’s hypothetical is the template: a $300-an-hour estate planner whose three-hour draft now takes one hour “may not bill a client for three hours of work when only one hour of work was actually experienced”. ABA 512: “A fee charged for which little or no work was performed is an unreasonable fee”, though a lawyer who spends fifteen minutes inputting information “may charge for that time as well as for the time necessary to review the resulting draft”. Florida Opinion 24-1 forbids prorating subscriptions; California’s 2026 guidance treats them as overhead “similar to library maintenance” and allows matter costs “with no markup or profit element”. Sample outside-counsel guideline clauses now carry the same rules, down to a suggested invoice notation: “AI-assisted; attorney reviewed”.

Clause 6: supervision and training

Clause. “No lawyer or staff member uses an approved tool on amber or red data before completing the firm’s hands-on training. Partners are responsible for AI use by those they supervise and must be told when AI is used on client work. Attendance, content and dates are recorded and refreshed annually.”

ABA 512: “Managerial lawyers must establish clear policies regarding the law firm’s permissible use of GAI, and supervisory lawyers must make reasonable efforts to ensure that the firm’s lawyers and nonlawyers comply with their professional obligations when using GAI tools.” Ayinde warned heads of chambers and managing partners that “the profession can expect the court to inquire whether those leadership responsibilities have been fulfilled”. For EU firms the AI Act’s Article 4 literacy duty has applied since February 2025, and the Commission’s Q&A says “Simply relying on the AI systems’ instructions for use or asking the staff to read them might be ineffective”. Make it hands-on: 54% of legal professionals say their firm provides no training and has no plans to, and Paul Weiss found its first PowerPoint session “ineffective” before switching to a prompting workshop. Clifford Chance’s supervision line is the cleanest on record: “if you use generative AI for client work, you have to tell your supervisor”.

Clauses 7 and 8: incident response and review cadence

Clause 7. “Anyone who discovers an AI-related error in a filed, served or sent document, or a confidentiality breach, reports it to [the AI lead] the same day. The firm corrects the record with the court and the client promptly and candidly. No quiet fixes. Incidents are logged and reviewed.”

Courts punish the cover-up more than the error. The Fifth Circuit in Fletcher v. Experian (2026): had counsel “accepted responsibility and been more forthcoming, it is likely that the court would have imposed lesser sanctions”. Damien Charlotin, whose database passed 2,000 hallucination decisions in 2026, says people are rarely sanctioned for the error alone but for having “refused to own up to it, double-downed, made up stories, or blamed the intern”. Insurance-readiness checklists now list the artefacts to keep for renewal: written policy, vendor due-diligence file, informed-consent language, training records, pre-filing verification log, usage log, incident procedure. The fake-citation playbook is the first-24-hours version.

The worst morning: draft the correction
We have discovered that a document filed on [date] in [court] contains [N] citations that do not exist or do not support the propositions. Draft: (1) a same-day notice to the court and opposing counsel that discloses the errors candidly, withdraws the affected citations, does not blame the tool or a junior, and states the corrective steps taken; (2) an internal incident record (who, which tool, which prompt, which verification steps were skipped); (3) a client notification under [jurisdiction]'s duty to inform. Tone: contrite, factual, brief.

Clause 8: review cadence

Clause. “This policy and Schedule A are reviewed quarterly by [the AI lead] and on any trigger: a vendor changes its terms, a new model or agentic feature is adopted, a court the firm appears in issues an AI order, or an incident occurs. Each review is dated and minuted.”

The triggers are real. Anthropic flipped consumer Claude to train by default on 28 August 2025, with five-year retention; the NYC Bar notes that terms of use “can change frequently and a lawyer’s obligation to understand the system’s use of inputs is continuing”. California’s rewritten 2026 guidance adds agentic systems, “Lawyers must not permit AI systems to autonomously file documents, communicate with the court, or make representations on the lawyer’s behalf”, and calls for “periodic reassessment of the system’s capabilities and risks”. Add that line the day anyone in the firm switches on an agent.

The full law firm AI policy template

  1. Approved tools. Schedule A tools only, on the stated tier, under firm accounts. No consumer accounts for amber or red data. New tools need approval after the Schedule B vendor questionnaire.
  2. Data and confidentiality. Green, amber, red as defined above. Client information never enters a tool that trains on or shares inputs without informed consent. Amber data anonymised, keys offline, no feedback buttons on client material.
  3. Verification. Nothing filed, served or sent contains an AI-assisted authority, quotation, fact or figure the responsible lawyer has not personally read and verified in a primary source. No verification by another AI. Verifier, database and date logged. Unread signatures are a breach.
  4. Disclosure. Engagement letter describes tools, review and billing. Disclose on request, on self-learning input, on fee relevance, on delegation of substantive work, and where a court requires. Check the judge’s standing orders before filing.
  5. Billing. Actual time only. No charge for time saved or for learning tools. Subscriptions are overhead; matter costs at cost with written consent; flat fees if not clearly excessive.
  6. Supervision and training. Hands-on training before amber or red use; records kept; annual refresh; supervisors told of AI use on client work.
  7. Incidents. Same-day report; prompt candid correction with court and client; no quiet fixes; logged.
  8. Review. Quarterly and on triggers; dated and minuted.

Acknowledgement: “I have read and will comply with the firm’s AI policy.” Name, date.

Adapt this template to your firm
Draft a one-page generative-AI use policy for a [12-lawyer firm in [jurisdiction]] from the eight clauses I paste below, naming our approved tools and tiers [ChatGPT Business / Claude Team / Copilot with enterprise data protection / [legal platform]] in Schedule A. Keep the green, amber and red data classes, the verification-log rule and the incident rule intact; adjust the disclosure clause to [jurisdiction]'s ethics opinion, tagged [VERIFY]. Then write a five-question onboarding quiz with answers. Plain English, under 700 words.

Where to go next: the firm implementation hub and the implementation playbook cover rollout beyond the policy, the shadow AI guide explains what your lawyers are doing today without one, and the ABA 512 explainer sets out the duties behind Clauses 2 to 6. The confidentiality session of AI Lab for Lawyers is where these tiers stop being abstract: participants check the settings on their own accounts live, then anonymise a real document, the groundwork every clause above assumes.

Frequently asked questions

What should a law firm AI policy include?

Eight things: a list of approved tools with their tiers; a data classification saying what may go into which tool; a confidentiality and anonymisation rule; a verification rule for anything filed or sent; disclosure to clients and courts; billing for actual time only; supervision and training with records; an incident procedure; and a review cadence. ABA Formal Opinion 512 requires managerial lawyers to establish clear policies on permissible use, and the clauses on this page map to its duties.

Is there a free AI policy template for law firms?

Yes. The eight clauses on this page are free to adapt, and LeanLaw publishes a one-page acceptable-use template with a four-class data scheme, the Oregon State Bar Professional Liability Fund publishes policy-development guidelines, and the North Carolina Bar Association summarises Casemark's traffic-light tiers. Whichever you start from, name your approved tools by tier and add a verification log; a template without those two is a statement of intent.

What is the traffic-light model for AI data?

A three-tier classification of what may go into which tool. Green: public information, abstract legal questions, marketing, admin, any tool. Amber: client material, anonymised, only in a commercial no-training tier, reviewed line by line and logged. Red: privileged strategy, witness statements, protected-order material, health data and anything filed with a court, only in an enterprise zero-retention deployment or a legal platform under contract, with documented verification. Casemark and Clifford Chance use versions of it.

Should the policy ban ChatGPT?

Ban consumer tiers for client data, not the product. ChatGPT Free, Plus and Pro train on inputs by default and a federal court has held consumer-chatbot exchanges neither privileged nor work product; ChatGPT Business and Enterprise do not train by default and offer a data processing agreement. Hill Dickinson blocked access after logging 32,000 ChatGPT hits in a week, and the UK ICO replied that outlawing AI drives staff to use it under the radar. Name the approved tier instead.

How often should an AI policy be reviewed?

Quarterly at minimum, plus on triggers: a vendor changes its terms (Anthropic flipped consumer Claude to train by default in August 2025), a new model or agentic feature ships, a court you appear in issues a standing order, or an incident occurs. The New York City Bar notes that terms of use change frequently and the duty to understand a system's use of inputs is continuing; California's 2026 guidance calls for periodic reassessment of each system's capabilities and risks.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.