Building an AI policy for your law firm: One that actually gets used
The decisions AI forces you to make, the sections firms forget, and why this policy dates faster than any others you own.
By now most firms know they need an AI policy.
A policy that bans everything gets ignored and drives people to their phones. A forty-page one nobody finishes protects no one. A policy written last year already lists tools that have changed underneath it. The document isn’t the point; what the document changes is.
This page is about writing one that earns its place: the calls AI forces you to make that your existing policies never had to, the sections firms routinely forget, and how to keep it alive once the tools move on (which they will, faster than the policy).
What an AI policy is actually for
That reframing matters, because it changes what a good policy looks like. The regulator doesn’t ask for a prohibition list. The SRA’s expectation is that firms have leadership and oversight, risk and impact assessments, documented policies, staff training, and ongoing monitoring in place – with the COLP responsible for regulatory compliance when new technology is introduced.
A policy is how those pieces get written down and made real. Think of it as a permission framework with clear edges, not a set of things not to do.
Standalone, or part of what you already have?
AI use touches ground your existing policies already cover – information security, outsourcing and supplier management, supervision, data protection.
So, there’s a real choice between a standalone AI policy and threading AI through the policies you already maintain. Both are defensible.
There's no right answer, only a fit with how your firm's documents already work.
A standalone policy gives AI visibility and a single obvious home, which helps while it’s still novel and while people need somewhere clear to look. Folding it into existing policies avoids policy sprawl, keeps AI alongside the controls it actually interacts with, and signals that it’s business as usual rather than a special case. Plenty of firms start standalone for the clarity, then integrate as AI settles into normal practice.
There’s no right answer, only a fit with how your firm’s documents already work. What matters more than the container is that the decisions below are made and written down somewhere a fee earner can find them.
Why so many AI policies fail
The first is the blanket ban. Prohibiting AI outright feels safe and does the opposite – people use it anyway, on personal accounts, out of sight, which is precisely the exposure the ban was meant to prevent. A ban doesn’t stop AI use; it stops you knowing about it.
The second is length. A policy written to cover every eventuality becomes something no one reads to the end, which means in practice it governs nothing. The version people actually follow is short enough to hold in your head.
The third is staleness. The tools change monthly – a policy that names specific products, or assumes a landscape that’s already moved, is out of date before it’s even circulated.
A ban doesn't stop AI use; it stops you knowing about it.
The decisions AI forces you to make
Where the confidentiality line sits
Which information is safe to put into which kind of tool – the distinction between a tool the firm holds under contract and a public one it doesn’t. It’s the single position fee earners most need spelled out. We go into it in depth in our guide to client confidentiality and AI.
What "verified" means in practice
How the approved-tools list stays current
What clients are told
How it connects to data protection
The parts most firms leave out
Billing and recorded time
The client who says no
Third-party and counterparty information
The AI nobody chose
Why this policy dates faster than all your other ones
An AI policy can’t – the tools it governs change monthly, and a document that named a specific product or assumed a particular landscape can be out of date within weeks of circulation.
Keep it short and current rather than exhaustive and frozen – with AI, an out-of-date policy is arguably worse than none, because people follow it.
The one maintenance point worth building in from the start is a shorter half-life: a named review cadence measured in months, not years, and a document lean enough that revising it isn’t a project. Keep it short and current rather than exhaustive and frozen – with AI, an out-of-date policy is arguably worse than none, because people follow it.
Who should own it
A policy owned by everyone is owned by no one.
The SRA expects the COLP to be responsible for regulatory compliance when new technology is introduced, which makes the COLP the natural home, though the day-to-day can sit with whoever holds risk or operations, provided the accountability is clear.
A policy owned by everyone is owned by no one.
The owner’s job isn’t to write every line or make every call. It’s to be the point where it connects: the person who can say what the current position is, keep the approved list moving, and decide the judgement calls the policy can’t fully anticipate.
A named owner is also what turns the review cadence from a good intention into something that actually happens.