Management Assistance Program
Develop AI Policies for Your Staff and Firm: Don’t Wait Until Something Goes Wrong
By Julie Bays, OBA Management Assistance Program Director
The biggest AI risk for many law offices is not the technology itself. It is using it without clear expectations. Lawyers are already trying AI tools, and in many offices staff members are too. The real question is whether the lawyer has set those expectations before confidential client information, unverified research or client work product gets entered into a tool without proper supervision.
That is why it helps to put the ground rules in writing before problems arise. A written AI policy does not have to be complicated. For many
solo and small firm lawyers, a short practical policy is better than a long document no one reads. The goal is to answer the basic questions before someone must guess.
Which AI tools are approved for firm use? What information may never be entered into an AI tool? Who is responsible for reviewing AI-generated work? How will legal citations, quotations and factual statements be verified? May staff use AI tools for client-related work? When should a client be told that AI was used? Who in the firm is responsible for revisiting the policy as the technology changes?
These are management questions as much as technology questions.
One common mistake is assuming that no policy is needed because the lawyer has not formally adopted AI. But lawyers and staff may experiment with free tools because they are convenient, interesting or built into products they already use. That is how confidential information can be copied into the wrong place. It is also how a draft, summary or research result can become part of a client matter without proper review.
Another common mistake is assuming that the AI tool is the problem. Usually, the bigger issue is workflow. If a lawyer uses AI to summarize a document, who checks the summary? If a staff member uses AI to draft a client email, who reviews it before it is sent? If a lawyer uses AI to assist with research, how are the authorities verified? If the firm uses a paid legal AI product, who understands the limits of that product and the terms governing data use?
A basic AI policy should include at least these points:
- Approved tools. Identify which tools may be used for firm work and which tools are prohibited.
- Confidentiality limits. State clearly that confidential client information, personally identifying information, privileged communications and sensitive documents should not be entered into any unapproved AI tool.
- Human review. Require lawyer review of any AI-assisted work before it is used in a client matter, sent to a client or filed with a court.
- Verification. Require independent verification of citations, quotations, legal rules, deadlines, calculations and factual summaries.
- Staff use. Explain whether and how staff may use AI tools, and who supervises that use.
- Client communication. Identify situations where client disclosure or consent may be appropriate.
- Updates. Set a reminder to review the policy regularly because the tools, risks and court expectations are changing quickly.
This is not about discouraging innovation. AI tools can be useful when lawyers understand their limitations and build appropriate safeguards. But technology competence includes understanding both the benefits and risks associated with relevant technology. A simple written policy helps lawyers protect client information, supervise work, verify accuracy and improve the quality of legal services.
Oklahoma lawyers also have an explicit ethics reference point for this issue. Comment 6 to ORPC 1.1 provides that, “to maintain the requisite knowledge and skill, a lawyer should keep abreast of changes in the law and its practice, engage in continuing study and education, and comply with continuing legal education requirements, including the benefits and risks associated with relevant technology.” That language supports the practical point here: lawyers do not need to become technologists, but they do need to understand enough about the tools they use to protect client information, supervise staff and verify AI-assisted work.
For lawyers looking for additional policy ideas, Catherine Sanders Reach outlined a practical guardrails approach that addresses risks such as shadow AI, embedded AI tools and the need for approved workflows rather than unrealistic blanket prohibitions. She also has a list of other types of AI policies at the end of her article Beyond the Ban: Why Your Law Firm Needs a Realistic AI Policy in 2026.
Do not wait for a mistake, a client concern or a court order to decide how AI may be used in your office. Decide now, write it down and train everyone who works with you.