How to write an AI policy your firm will actually follow
It is 6.10pm. A first year solicitor has a chambers deadline tomorrow, a half finished submission, and a browser tab open on a chatbot. Somewhere on the firm's shared drive there is a document called Artificial Intelligence Policy v3 FINAL. She has not read it. She is not going to read it now.
That gap is the whole problem. Most firm AI policies are written to satisfy a professional indemnity insurer or a future regulator, not to help the person at the keyboard decide whether this particular task is allowed. So they get signed at induction and ignored forever, and the actual usage moves onto personal devices where nobody can see it.
A policy that works looks different. It is short, it names tasks rather than technologies, it tells people exactly what to verify, and it makes asking a question cheaper than guessing. Below is how to build one, in the order the decisions actually need to be made.
Why the policy sitting on your shared drive is not working
Three failure patterns turn up again and again. The first is a blanket ban. Bans do not stop use, they move it. A solicitor who cannot use an approved tool on a firm laptop will use an unapproved one on a personal phone, and now you have the same confidentiality exposure with none of the visibility.
The second is principles language. Use AI responsibly, ethically and in accordance with your professional obligations is not a rule, it is a mood. It gives no answer to the only question anyone is actually asking, which is whether they can paste this particular clause into that particular tool right now.
The third is ownership. If the policy is owned by IT or by the practice manager, it will be written around systems and licences. It needs a practising solicitor as owner, ideally someone who still drafts, with IT advising on the tooling underneath.
Write it around tasks, not around tools
Tool lists date within a month. Task categories do not. A policy organised around what the work is, rather than which product is being used, still makes sense after your document management provider ships a new assistant you never approved.
Sort the firm's work into tiers by consequence, then attach one rule to each tier. Most practices land on four or five tiers, and the majority of daily work sits in the bottom two, which is exactly the point. If your policy makes low risk work feel risky, people stop reading it and apply their own judgment to the high risk work as well.
Pay particular attention to anything that goes to a court. The Supreme Court of New South Wales and the Supreme Court of Victoria have both issued guidance on generative AI in litigation, and other Australian courts have followed with their own material. Your policy should point to the relevant court guidance rather than paraphrase it, because that guidance changes and your policy will not keep pace.
The verification rule carries most of the weight
If you only get one clause right, get this one. Fabricated citations are the failure mode that has embarrassed practitioners in Australia and overseas, and it happens for a boring reason: a general purpose model produces text that looks exactly like a real case reference because it has been trained on thousands of real case references.
The rule has to be specific enough to follow while tired. Not verify AI output, but check the citation in the primary source, then check that the case says what the draft claims it says. Those are two separate failures. A model can name a real decision and still misstate the ratio, and the second error is harder to spot because the first check passed.
Write the rule so it survives the worst moment in a matter, which is the night before a hearing. That means it should take minutes, not an afternoon, and it should be attached to a habit people already have, such as the file note.
Confidentiality, privilege and what actually leaves the building
Pasting client material into a consumer chatbot is a disclosure to a third party. Whether it is a breach depends on the product terms, the client's instructions and your retainer, but the disclosure has already happened by the time anyone asks the question.
The practical control is not a paragraph about confidentiality, which every solicitor already understands. It is naming the approved environment, turning off the training and retention defaults where the product allows it, and being blunt about which products are consumer tier. Staff will use the default settings, so the default setting is your real policy.
Two Australian specifics belong in the document. Cross border disclosure obligations under the Privacy Act apply where personal information goes to an overseas provider, and most of these providers are overseas. And the effect on legal professional privilege of routing client material through a third party is not settled, which is a reason to be conservative rather than a reason to wait for authority. Where a matter is sensitive, get the client's informed consent in the engagement letter rather than after the fact.
Roll it out in a way people notice
A policy released by email is a policy nobody reads. The rollout matters as much as the drafting, and the goal in the first quarter is not compliance paperwork, it is getting the firm to a shared understanding of where the line sits.
Train on failures, not features. A twenty minute session where the group reads a draft containing a plausible but non existent citation, and tries to spot it, does more for adherence than an hour on prompting technique. People adopt a rule once they have felt why it exists.
- Owner named, and it is a practising solicitor
- Task tiers agreed by the partners in one meeting, not by circulation
- One page draft written, no appendices
- Name the approved tools and the tier each one is cleared for
- Turn off training and retention where the product allows it
- Read the data handling terms of anything already embedded in your practice management system
- Run the fabricated citation exercise with every fee earner
- Walk through the verification rule on a live research task
- Publish a no blame route for reporting a mistake
- Sample file notes to see whether use is being recorded
- Collect the questions people asked, they show where the policy is silent
- Amend and reissue with a version date, then diarise the next review
Supervision, enforcement and the version that survives
Enforcement is where good policies go quiet. If the only stated consequence is disciplinary, the first person who makes a mistake will hide it, and you will find out from the other side. Build in an explicit route to self report an error with no penalty for coming forward promptly, and reserve the disciplinary language for concealment and for going outside the approved environment.
Principals carry supervision duties regardless of what the policy says, so make supervision concrete. That means the supervising practitioner knows a tool was used, the verification line is on the file, and nobody is signing their name to text they have not read line by line. Review the document twice a year and after any court or regulator guidance changes, and put the version date at the top so people can tell whether they are reading the current one.
The tooling choice reduces the burden but does not remove it. Research tools built on Australian law that return the primary source alongside the answer, Legal Brain among them, make the verification step take minutes rather than making it optional. The signature at the bottom of the advice is still yours, and the policy exists to make sure everyone in the firm knows that before the deadline, not after.
Frequently asked questions
Do Australian courts require you to disclose if you used AI to prepare a document?
It depends on the court and the document. The Supreme Court of New South Wales and the Supreme Court of Victoria have both published guidance on generative AI in litigation, and other Australian courts have issued their own material, with restrictions that are strictest for affidavits, witness statements and the content of expert reports. Check the current practice note or guideline for the specific court and division before filing. Your firm policy should link to that guidance rather than restate it, because it is updated more often than your policy will be.
Should a small firm ban ChatGPT entirely?
A ban rarely works, because it moves use onto personal devices where you lose all visibility and control. A better position for a small firm is a short approved list, training and retention settings switched off, a clear prohibition on pasting client material into consumer tier products, and the verification rule applied to every authority. That gives you the same protection with a rule people will actually follow.
What should an AI policy for a law firm actually contain?
Four things: which tasks are open, supervised or restricted, which tools are approved for each tier, the verification steps for any authority or proposition, and what must be recorded on the file. Anything beyond that belongs in a separate guidance note. If it does not fit on one page, most of your staff will never read past the first heading.
Can using AI waive legal professional privilege over client material?
The position is not settled in Australia, which is a reason for caution rather than a reason to wait. Sending client material to a third party provider is a disclosure, and the risk profile depends on the terms of the product, the retention settings and the sensitivity of the matter. Use an environment with contractual confidentiality protections, keep the most sensitive material out of general purpose tools, and get informed client consent in the engagement letter where the work warrants it.
Two quick questions
No score is stored. Pick an answer to see why it is right.
-
1A draft submission cites a decision with a plausible medium neutral citation. You open it on AustLII and the case exists. What is the next step under a well drafted verification rule?
A real citation and a correct proposition are two separate checks. Models frequently attach a genuine decision to a principle it does not stand for, and that error is more dangerous precisely because the citation check passed.
-
2Which structure gives a firm AI policy the best chance of being followed day to day?
Task tiers survive tool changes and answer the only question a busy solicitor is asking, which is whether this specific piece of work is permitted. Product lists date within weeks, principles give no operational answer, and blanket bans push usage onto personal devices where the firm has no visibility.
Research Australian law without handing over client data
Legal Brain searches Australian legislation and case law, shows you the source behind every answer, and anonymises client-identifying detail before anything reaches a model.