Governance

How to write an AI policy your firm will actually follow

By Michael Nadalin, Founder, Market Lead · 7 August 2026 · 8 min read

It is 6.10pm. A first year solicitor has a chambers deadline tomorrow, a half finished submission, and a browser tab open on a chatbot. Somewhere on the firm's shared drive there is a document called Artificial Intelligence Policy v3 FINAL. She has not read it. She is not going to read it now.

That gap is the whole problem. Most firm AI policies are written to satisfy a professional indemnity insurer or a future regulator, not to help the person at the keyboard decide whether this particular task is allowed. So they get signed at induction and ignored forever, and the actual usage moves onto personal devices where nobody can see it.

A policy that works looks different. It is short, it names tasks rather than technologies, it tells people exactly what to verify, and it makes asking a question cheaper than guessing. Below is how to build one, in the order the decisions actually need to be made.

Why the policy sitting on your shared drive is not working

Three failure patterns turn up again and again. The first is a blanket ban. Bans do not stop use, they move it. A solicitor who cannot use an approved tool on a firm laptop will use an unapproved one on a personal phone, and now you have the same confidentiality exposure with none of the visibility.

The second is principles language. Use AI responsibly, ethically and in accordance with your professional obligations is not a rule, it is a mood. It gives no answer to the only question anyone is actually asking, which is whether they can paste this particular clause into that particular tool right now.

The third is ownership. If the policy is owned by IT or by the practice manager, it will be written around systems and licences. It needs a practising solicitor as owner, ideally someone who still drafts, with IT advising on the tooling underneath.

Policy intent versus what happens in the office
Prohibit all use of generative AI across the firm
Use continues on personal devices and nobody reports it
Use AI responsibly and in line with your ethical duties
No one can tell whether a specific task is permitted
A 14 page policy circulated by email
A one page rule sheet pinned next to the precedent bank
IT owns the policy
A practising solicitor owns it, IT advises on the tools
Sign the acknowledgment once at induction
The rule is applied at the point of use and recorded on the file
Every column on the left is a real clause we see in firm policies. The right hand column is what it produces in practice.

Write it around tasks, not around tools

Tool lists date within a month. Task categories do not. A policy organised around what the work is, rather than which product is being used, still makes sense after your document management provider ships a new assistant you never approved.

Sort the firm's work into tiers by consequence, then attach one rule to each tier. Most practices land on four or five tiers, and the majority of daily work sits in the bottom two, which is exactly the point. If your policy makes low risk work feel risky, people stop reading it and apply their own judgment to the high risk work as well.

Pay particular attention to anything that goes to a court. The Supreme Court of New South Wales and the Supreme Court of Victoria have both issued guidance on generative AI in litigation, and other Australian courts have followed with their own material. Your policy should point to the relevant court guidance rather than paraphrase it, because that guidance changes and your policy will not keep pace.

Task tiers, highest consequence first
Anything filed, served or sworn
Submissions, affidavits and witness statements carry the sharpest exposure. Court guidance in several Australian jurisdictions restricts generative AI in the content of affidavits and witness statements, and every authority relied on has to be checked in the primary source before it leaves the office.
Restricted, sign off required
Advice going to a client under your name
The output carries your professional judgment whether or not you drafted the sentence. Supervision has to be real, not a skim, and the supervising practitioner should know a tool was used.
Supervised
Discovery, due diligence and review at volume
The confidentiality surface is enormous and the tooling matters more than the prompt. Approved platforms only, with the data handling terms actually read by someone in the firm.
Approved platforms only
Research and internal first drafts
This is where the productivity actually lives. Allow it openly, on approved tools, with the verification rule attached to every authority and every proposition.
Open, verify before use
Admin and rewriting your own material
Summarising a file note you wrote, tightening an internal email, turning your own notes into a plain English explanation. Low consequence work that should not need permission.
Open
One rule per tier. If a task does not fit a tier, that is the trigger to ask, not to improvise.

The verification rule carries most of the weight

If you only get one clause right, get this one. Fabricated citations are the failure mode that has embarrassed practitioners in Australia and overseas, and it happens for a boring reason: a general purpose model produces text that looks exactly like a real case reference because it has been trained on thousands of real case references.

The rule has to be specific enough to follow while tired. Not verify AI output, but check the citation in the primary source, then check that the case says what the draft claims it says. Those are two separate failures. A model can name a real decision and still misstate the ratio, and the second error is harder to spot because the first check passed.

Write the rule so it survives the worst moment in a matter, which is the night before a hearing. That means it should take minutes, not an afternoon, and it should be attached to a habit people already have, such as the file note.

The five step verification rule
1
1. Treat output as a capable graduate with no accountability
Useful starting point, zero authority. Nothing goes out on the strength of the draft alone.
2
2. Open every authority in the primary source
Court website, authorised report or AustLII. If the citation cannot be opened, it does not exist, and no amount of confident phrasing changes that.
3
3. Read the passage the draft relies on
Confirm the decision actually stands for the proposition. Real case, wrong principle, is the more dangerous error because it looks verified.
4
4. Check currency
Has the decision been overturned, distinguished or superseded by amending legislation. Model training data has a cutoff and will not tell you where it is.
5
5. Record it and sign it
One line on the file: tool used, task, who verified. This is the line that protects the practitioner if the matter is later examined.
Short enough to print. Steps three and four are the ones people skip, and they are the ones that matter.

Confidentiality, privilege and what actually leaves the building

Pasting client material into a consumer chatbot is a disclosure to a third party. Whether it is a breach depends on the product terms, the client's instructions and your retainer, but the disclosure has already happened by the time anyone asks the question.

The practical control is not a paragraph about confidentiality, which every solicitor already understands. It is naming the approved environment, turning off the training and retention defaults where the product allows it, and being blunt about which products are consumer tier. Staff will use the default settings, so the default setting is your real policy.

Two Australian specifics belong in the document. Cross border disclosure obligations under the Privacy Act apply where personal information goes to an overseas provider, and most of these providers are overseas. And the effect on legal professional privilege of routing client material through a third party is not settled, which is a reason to be conservative rather than a reason to wait for authority. Where a matter is sensitive, get the client's informed consent in the engagement letter rather than after the fact.

What happens to a paragraph you paste into a consumer tool
The moment you paste
The text leaves your firm's environment and lands on infrastructure you do not control, usually offshore.
Immediately after
Retention is governed by the provider's terms. Consumer tiers commonly retain conversation history by default. Business and enterprise tiers commonly do not.
In the following days
Some products allow human review of inputs for safety or quality purposes, subject to the terms you agreed to without reading.
Over following months
Consumer inputs may be used to improve future models unless that setting has been switched off at the account level.
At the worst possible time
You are asked, on the record, exactly where the client's material went and who could access it.
Exact behaviour depends on the product and the tier. The point is that the answer is set by someone else's terms, not by your practice.

Roll it out in a way people notice

A policy released by email is a policy nobody reads. The rollout matters as much as the drafting, and the goal in the first quarter is not compliance paperwork, it is getting the firm to a shared understanding of where the line sits.

Train on failures, not features. A twenty minute session where the group reads a draft containing a plausible but non existent citation, and tries to spot it, does more for adherence than an hour on prompting technique. People adopt a rule once they have felt why it exists.

First 90 days
Week 1
Set the boundary
  • Owner named, and it is a practising solicitor
  • Task tiers agreed by the partners in one meeting, not by circulation
  • One page draft written, no appendices
Weeks 2 to 4
Fix the defaults
  • Name the approved tools and the tier each one is cleared for
  • Turn off training and retention where the product allows it
  • Read the data handling terms of anything already embedded in your practice management system
Weeks 5 to 8
Train on the failure mode
  • Run the fabricated citation exercise with every fee earner
  • Walk through the verification rule on a live research task
  • Publish a no blame route for reporting a mistake
Weeks 9 to 12
Check the file, then the policy
  • Sample file notes to see whether use is being recorded
  • Collect the questions people asked, they show where the policy is silent
  • Amend and reissue with a version date, then diarise the next review
Sequenced so the boundary exists before the tools do. Doing it the other way round is why most rollouts stall.

Supervision, enforcement and the version that survives

Enforcement is where good policies go quiet. If the only stated consequence is disciplinary, the first person who makes a mistake will hide it, and you will find out from the other side. Build in an explicit route to self report an error with no penalty for coming forward promptly, and reserve the disciplinary language for concealment and for going outside the approved environment.

Principals carry supervision duties regardless of what the policy says, so make supervision concrete. That means the supervising practitioner knows a tool was used, the verification line is on the file, and nobody is signing their name to text they have not read line by line. Review the document twice a year and after any court or regulator guidance changes, and put the version date at the top so people can tell whether they are reading the current one.

The tooling choice reduces the burden but does not remove it. Research tools built on Australian law that return the primary source alongside the answer, Legal Brain among them, make the verification step take minutes rather than making it optional. The signature at the bottom of the advice is still yours, and the policy exists to make sure everyone in the firm knows that before the deadline, not after.

Frequently asked questions

Do Australian courts require you to disclose if you used AI to prepare a document?

It depends on the court and the document. The Supreme Court of New South Wales and the Supreme Court of Victoria have both published guidance on generative AI in litigation, and other Australian courts have issued their own material, with restrictions that are strictest for affidavits, witness statements and the content of expert reports. Check the current practice note or guideline for the specific court and division before filing. Your firm policy should link to that guidance rather than restate it, because it is updated more often than your policy will be.

Should a small firm ban ChatGPT entirely?

A ban rarely works, because it moves use onto personal devices where you lose all visibility and control. A better position for a small firm is a short approved list, training and retention settings switched off, a clear prohibition on pasting client material into consumer tier products, and the verification rule applied to every authority. That gives you the same protection with a rule people will actually follow.

What should an AI policy for a law firm actually contain?

Four things: which tasks are open, supervised or restricted, which tools are approved for each tier, the verification steps for any authority or proposition, and what must be recorded on the file. Anything beyond that belongs in a separate guidance note. If it does not fit on one page, most of your staff will never read past the first heading.

Can using AI waive legal professional privilege over client material?

The position is not settled in Australia, which is a reason for caution rather than a reason to wait. Sending client material to a third party provider is a disclosure, and the risk profile depends on the terms of the product, the retention settings and the sensitivity of the matter. Use an environment with contractual confidentiality protections, keep the most sensitive material out of general purpose tools, and get informed client consent in the engagement letter where the work warrants it.

Check your understanding

Two quick questions

No score is stored. Pick an answer to see why it is right.

  1. 1A draft submission cites a decision with a plausible medium neutral citation. You open it on AustLII and the case exists. What is the next step under a well drafted verification rule?

  2. 2Which structure gives a firm AI policy the best chance of being followed day to day?

Research Australian law without handing over client data

Legal Brain searches Australian legislation and case law, shows you the source behind every answer, and anonymises client-identifying detail before anything reaches a model.

Request early access