A law firm does not become responsible in its use of artificial intelligence by adding one sentence to an employee handbook: “Use AI carefully.”
Responsible adoption requires a system. The firm needs to know which tools are approved, what information may be used with those tools, who reviews the output, how sources are verified, and what happens when the process fails.
That is AI governance.
It is not a technology buzzword. It is the practical bridge between a promising workflow and the duties lawyers already carry: protecting confidential information, supervising work, exercising independent judgment, communicating accurately with clients, and remaining accountable for the final work product.
Part 1 of this series identified the work AI can assist and the work it cannot do alone. Part 2 described a controlled 90-day pilot. This article explains the controls that should exist before a firm expands AI use beyond a limited experiment.
Start with a plain-language policy
A good AI policy does not need to read like a software license agreement. It should be short enough that attorneys and staff will use it, specific enough that they know what to do, and flexible enough to evolve with the technology.
At a minimum, the policy should answer five questions:
Which AI tools are approved for firm use?
What client or firm information may be entered into each approved tool?
What work may AI assist with, and what work requires attorney review or approval?
How must users verify facts, authorities, quotations, calculations, and other material output?
Who should be notified when there is an error, confidentiality concern, unsupported citation, or unexpected result?
The policy should not assume that every AI product has the same privacy, security, access, retention, or training practices. Tool approval must be specific to the product and the firm’s intended use.
Confidentiality begins before the prompt
The confidentiality question is not limited to whether an AI tool can generate a useful answer. It begins with what information leaves the firm’s control and how the platform handles it.
Before using any AI platform with client or matter information, the firm should understand:
whether prompts, uploads, and outputs are retained;
whether they may be used to train or improve a provider’s models;
who can access the information within the vendor’s organization;
where the information is stored and processed;
what encryption, authentication, and access controls apply;
whether the firm can control user permissions and remove access promptly; and
what happens to the information when the firm ends its relationship with the vendor.
This is not a reason to avoid AI. It is a reason to use approved tools deliberately.
The practical rule
Do not enter client information into an AI tool unless the firm has approved that tool for that type of information and workflow.
That rule should apply equally to lawyers, staff, contract professionals, interns, and vendors working on the firm’s matters. Convenience is not a substitute for a confidentiality review.
Privilege is not a label you can add later
Attorney-client privilege and work-product protection depend on the nature and handling of the communication or material. A firm should not assume that calling an AI output “privileged” resolves the question.
The safest operational approach is to treat AI-assisted work as part of the firm’s legal workflow only when:
the use serves a legitimate purpose connected to legal representation or legal work;
access is limited to authorized users;
the approved platform’s information practices have been reviewed; and
the resulting work is stored, reviewed, and handled through the firm’s normal matter-management and confidentiality processes.
The firm should also instruct users not to paste privileged or sensitive material into consumer-facing, unapproved, or personal AI accounts simply because the task appears urgent or routine.
Human review must be defined, not assumed
“Human in the loop” is not a meaningful control unless the firm identifies who the human is and what that person must do.
Review should be scaled to the risk of the work. A first-pass inventory of produced documents is different from a legal memorandum, a client recommendation, a settlement communication, or a court filing.
A practical review standard should require the reviewer to confirm:
the output is grounded in the correct source materials;
no material fact was omitted, distorted, or invented;
authorities are real, current, and accurately characterized;
quotations, citations, and calculations have been checked against the original source;
confidential information is handled consistently with the firm’s policy; and
the final work product reflects the lawyer’s own legal judgment and the client’s objectives.
The reviewer’s responsibility is not to make the output sound more polished. It is to decide whether the output is accurate, complete enough, and fit for its intended purpose.
Vendor diligence is an ongoing process
An initial security questionnaire is not the end of vendor review. AI products change quickly: models change, features change, integrations change, and data-handling terms can change.
Before approving a tool—and periodically afterward—the firm should assess the practical questions that affect client information and work quality.
Review area
Questions the firm should ask
Data use
Are prompts, documents, and outputs retained? Are they used for training or model improvement?
Access controls
Can the firm control user access, apply multi-factor authentication, and remove users promptly?
Security
What encryption, incident-response, audit, and monitoring practices does the provider maintain?
Storage and processing
Where is data stored or processed, and are there applicable client, contractual, or regulatory requirements?
Integrations
What other systems can the tool access, and what information may flow through those connections?
Administrative control
Can the firm review usage, control settings, and manage users centrally?
Contract terms
Do the provider’s terms match the firm’s intended use and confidentiality expectations?
Support and change management
How will the firm learn about material product, policy, or model changes?
The goal is not to demand that every vendor be risk-free. No technology is risk-free. The goal is to understand the risk well enough to decide whether the tool is appropriate for the work the firm intends to perform.
Source verification is not optional
AI can produce citations, summaries, quotations, and legal propositions that appear authoritative. Appearance is not verification.
Every lawyer and staff member using AI for legal research or legal drafting should understand this rule:
If a source matters to the conclusion, open the source and verify it.
That means checking:
the existence and citation of an authority;
the holding and factual context of the authority;
the current status of a case, statute, or regulation;
the proposition for which the source is being cited;
the accuracy of a quotation or pinpoint citation; and
whether contrary authority or a limiting rule changes the analysis.
The same principle applies to documents. If an AI-generated summary says a contract contains a termination right, a liability cap, or a notice deadline, the reviewer should locate and confirm the actual provision before relying on it.
Build an escalation path before something goes wrong
A firm should make it easy for users to report an issue without embarrassment. The goal is early correction, not blame.
The AI-use protocol should specify whom to notify when a user finds:
an unsupported or nonexistent authority;
a factual error in a matter summary or chronology;
a confidential document entered into an unapproved tool;
unexpected sharing, access, or retention of information;
a result that appears biased, unsafe, or outside the approved workflow; or
a client-facing or filed document that may contain unverified AI-assisted content.
The firm should then have a simple response process: preserve the relevant information, assess whether the output was used or shared, notify the appropriate internal decision makers, correct the work product, and determine whether a client communication or other remedial action is necessary.
A near miss is useful information. It can show that training, tool settings, workflow design, or review requirements need improvement.
Keep records of the process, not every prompt
Firms do not need to create a burdensome file for every AI interaction. But they should be able to show that their use of AI is controlled and supervised.
Useful governance records may include:
the approved-tool list and dates of review;
the AI-use policy and training materials;
workflow-specific protocols for approved pilots or recurring use cases;
the identity of workflow owners and reviewers;
reports of material errors or incidents and the corrective action taken; and
periodic assessments of whether a workflow remains appropriate.
The point is operational accountability. If the firm cannot explain which tool was used, why it was approved, who reviewed the output, and how an error would be handled, then the workflow is not ready for high-stakes client work.
The AI governance checklist
Before expanding an AI workflow beyond a limited pilot, confirm the following:
Control
Checkpoint
Approved tool
The firm has approved the specific platform, account type, and intended workflow.
Confidentiality review
The firm understands how the platform handles prompts, uploads, outputs, access, retention, and training.
Defined use case
The workflow is documented; users know what the tool may and may not do.
Human review
A qualified person is assigned to verify output before external use or reliance.
Source verification
The protocol requires review of material source documents and authorities.
Access management
User permissions, authentication, and offboarding procedures are in place.
Training
Participants understand the workflow, limitations, review standards, and escalation process.
Incident response
Users know how to report an error, confidentiality concern, or unexpected output.
Periodic review
The firm reevaluates the tool and workflow as technology, terms, and practice needs change.
Governance should enable responsible use, not freeze innovation
A useful governance system is not designed to prevent every new idea. It is designed to let the firm test new ideas responsibly.
When users know which tools are approved, what information may be used, how review works, and where to ask questions, the firm can move more quickly—not more slowly. It replaces hidden, unmeasured experimentation with deliberate improvement.
That is especially important in law practice. The firm’s value is not just that it can produce words quickly. Its value is that clients can trust the firm to protect their information, exercise judgment, identify risk, and stand behind the work.
Bottom line
AI governance is professional responsibility made operational. It turns broad duties of confidentiality, competence, supervision, and accuracy into everyday decisions about tools, information, review, and accountability.
The right policy is not “never use AI” and not “use AI whenever it saves time.” It is: use approved tools for approved work, protect client information, verify material output, maintain human judgment, and learn from the process.
Part 4 of this series will address the final question: how does a firm measure whether AI is actually improving client service, capacity, and profitability?
This article is for general informational purposes only and is not legal advice. Firms should evaluate their own professional obligations, client-information practices, technology contracts, and supervision procedures before implementing or expanding an AI-assisted workflow.



