AI for law firms comes down to two rules, and everything else in this guide hangs off them. Know exactly where the text goes when someone pastes it into a tool: who stores it, who can read it, whether it trains somebody's model. And never let the machine be the last thing that touches work product before it leaves the building. Hold those two lines and you get most of the upside with very little of the exposure.
That's a duller answer than either side of the current argument wants. Vendors would like you to believe the practice of law is being rebuilt this quarter. The nervous half of your partnership would like you to believe that any use of AI is a bar complaint waiting to happen. Both are wrong the same way. They're arguing about the technology when the only thing that determines your risk is the data flow.
What follows is the long version. Where the risk actually sits, which uses hold up under a hard question and which ones fall apart, how to write a policy that fits on one page, what to ask a vendor before client information touches their servers, and what to say to the client who asks whether a computer wrote their memo.
The risk is narrower than the anxiety
Most firm-wide nervousness about AI is one undifferentiated feeling. Break it into its three actual parts and it becomes manageable, because each part has a different fix.
Confidentiality. Model Rule 1.6 obliges you to make reasonable efforts to prevent unauthorized disclosure of client information. Paste a settlement agreement into a free consumer chatbot and you've handed that text to a third party under terms nobody at your firm read. Whether that's a violation depends on the terms, the data, and what "reasonable" means for the sensitivity involved. Which is exactly why the question to answer is never "is AI allowed" but "where does this specific text end up."
Accuracy. Language models produce fluent text with total confidence and no idea whether it's true. Courts around the country have sanctioned lawyers for filings that cited cases which did not exist, and every one of those stories has the same shape: the tool did what tools do, and the verification step that was supposed to catch it never happened. The failure was procedural, not technological.
Supervision. You are responsible for work that leaves your firm regardless of what produced it. A model is not a co-author or an excuse. It's closer to a very fast, very well-read first-year with no judgment and no fear, which is a category of help you already know how to supervise.
Here's the uncomfortable part. The version of this risk you can't see is already running. An associate somewhere in your firm has a consumer chatbot open on a second monitor right now, because it's faster than waiting for the research answer and nobody ever told them not to. That's the real starting position for most firms, and it means a ban is not a policy. It's a wish with no enforcement behind it. The firms in the worst shape are the ones that never approved anything and therefore believe nothing is happening.
Where the text goes, in plain terms
Every AI decision your firm makes reduces to one diagram: the text leaves a lawyer's screen, travels somewhere, gets processed, and either persists or doesn't. Learn to sketch that diagram for any tool and you can evaluate anything, including whatever launches next spring.
Consumer accounts and business accounts are different products
This is the single most useful distinction in the whole conversation, and most firms discover it late. The same vendor will offer a free or personal-tier product and an enterprise or API tier, and the terms attached to them are not close to the same. Consumer tiers commonly reserve the right to use your inputs to improve the service. Business and enterprise tiers typically don't, offer a data processing agreement, and let an administrator configure retention.
So the tool your associate is using at home is often the wrong tool at the office, even though the interface is identical. That's a confusing thing to explain and a very easy thing to fix: buy the business tier, provision accounts through the firm, and make the approved version the one that's already logged in when they sit down. People take the path of least resistance. Make the compliant path the shortest one.
Retention is a setting, training is a promise
Two separate questions that get collapsed into one. Retention is how long the vendor keeps your inputs and outputs, and it's usually a configurable setting or a contract term (some vendors will offer zero retention on request for API traffic, some won't). Training is whether your text becomes part of a future model, and no setting undoes it after the fact.
Ask both questions separately, get both answers in writing, and put the answers in the file where your malpractice carrier can find them. A vendor that answers quickly and specifically is telling you something about their engineering. A vendor that sends a marketing page instead is also telling you something. Our deeper treatment of the whole data-handling question lives in how law firms can use AI without risking client confidentiality.
Privilege, and why the answer is boring
Partners ask whether sending privileged material through a vendor's servers waives privilege. The prevailing view treats a vendor bound by confidentiality obligations much like any other agent you use, the way you already treat your document management host, your ediscovery platform, and the copy shop. Privilege turns on the confidentiality of the relationship, not on the number of servers involved.
That's the general answer, and general answers have a way of not covering the matter you're worried about. When the material is sensitive enough that the question is keeping you up, the sensible move is the one you'd make anyway: use a vendor with a signed agreement, restrict what goes in, and encrypt what sits at rest. Our client data encryption service handles the last part for firms who don't want to think about key management.
The uses that hold up
Sort candidate uses by one test: if this output went out wrong, how bad is it, and would anyone catch it. Uses where the answer is "not very" and "yes, immediately" are where you start.
Meeting notes and call summaries
The best first use in most firms, because the value is obvious in week one and the failure mode is a bad summary rather than a bad filing. A tool joins the client call or the deposition prep session, transcribes it, and produces a summary with action items. What used to be twenty minutes of writing up notes after the call, usually skipped when the day got long, becomes a two-minute edit.
Two cautions. Recording consent law varies by state and several require all parties to agree, so the announcement at the top of the call isn't a courtesy, it's the compliance step. And a transcript is a record: it's discoverable, it's storable, and it needs a retention rule like any other document. Decide where the transcripts live and how long they stay before you turn the feature on, not after. The practical setup is in AI note taking and meeting summaries for professional services.
Internal knowledge search
Your firm has already written the answer to most questions it gets asked. The problem is that the answer is in a 2019 memo, in a folder named after a matter that closed, on a shared drive with three competing naming conventions. So the associate asks a partner, the partner answers from memory, and the firm pays twice for work it did once.
AI-assisted search over your own documents fixes a real and unglamorous problem: finding what you already know. The value shows up fastest for firms with deep practice-area repetition, where the third motion to compel of the quarter should be faster than the first. The important design decision is permissions. The tool has to inherit your existing access controls, or you've built a very efficient way for the wrong people to read the wrong matter file. That trap and the way around it are covered in using AI for internal knowledge search without losing control of data.
First-pass document review
Summarizing a long agreement, pulling every defined term, finding the indemnity provisions across a stack of vendor contracts, flagging the clauses that differ from your standard form. These are pattern tasks, and the machine is good at pattern tasks. Treat the output as a map, not as the territory. A lawyer still reads the provision that matters.
The productivity story here is genuine but narrower than the pitch. It doesn't replace the review. It changes where the review starts, from page one to the four pages that actually need argument.
The words that aren't work product
A large amount of a law firm's writing has nothing to do with anybody's legal position. Practice-area pages, the newsletter, job postings, the reply to an intake inquiry, internal process documentation nobody has ever gotten around to writing. Drafting help on that material carries almost no confidentiality exposure, because there's no client information in it, and it's a good way to let cautious people get comfortable with the tools before anything sensitive is in play.
Answering the phone
The most underrated one, and the one nobody puts on the AI roadmap. A prospective client with a problem calls three firms on a Sunday evening. The one that answers gets the matter. In a small firm, on a Sunday, nobody answers, and voicemail is where that person's urgency goes to die.
A voice assistant that picks up every call, captures the caller's situation, screens for conflicts-relevant details, and books the consultation is a business development tool disguised as a phone feature. It doesn't give legal advice and shouldn't be configured to try. It takes a good message and books a time. That's it, and it's worth more than most software your firm pays for. See our virtual receptionist service, and the wider treatment in our guide to business phone systems.
The uses that don't hold up
Shorter list, and worth being blunt about.
Research you don't verify. Not research itself, which general-purpose models are increasingly decent at, and which purpose-built legal research platforms with grounded citations are better at. The unacceptable part is treating any of it as verified. Every citation gets pulled and read. Every quote gets checked against the source. If your firm can't commit to that step as an absolute, don't allow the use.
Anything filed or sent without a human read. Obvious, routinely violated under deadline pressure, which is precisely when it happens.
Client-identifying facts in unapproved tools. The consumer app on someone's phone is the whole problem in one sentence.
Judgment. Whether to take the deal, how a specific judge will react, what the client actually needs as opposed to what they asked for. This is the part clients pay for, and no current tool is close. Firms that blur this line don't get caught by a rule. They get caught by a client who notices the advice sounds like everyone else's.
A policy people will actually read
Most firm AI policies fail for a reason that has nothing to do with AI. They're eleven pages long, written by committee, circulated once, and never opened again. Nobody remembers a policy they read once in March.
Aim for one page and seven decisions. Which tools are approved, by name, and how to get an account. What must never be entered into any tool, in specific terms rather than "confidential information." What must be verified before anything leaves the firm, and by whom. Whether and how the firm discloses AI use to clients. Who to ask when something falls outside the list, with an actual name attached. What happens if someone gets it wrong (make this survivable, or people will hide mistakes instead of reporting them). And a review date, because your list of approved tools will be stale in six months.
Then do the part that matters more than the document. Train on it for thirty minutes, get an acknowledgment, and repeat it when the policy changes. A signed acknowledgment is also the artifact your carrier and your larger clients will ask for, which makes it worth the small administrative annoyance. The full build, including sample language you can cut down, is in how to build an AI policy for your firm.
One design note that saves you a rewrite. Write the policy around categories of use, not around product names. Name the approved products in an appendix. Otherwise every new tool means a new policy, and after the third revision nobody is reading it anyway.
What to tell clients
Three flavors of this conversation, and they need different answers.
Sophisticated clients with outside counsel guidelines are increasingly writing AI terms into those guidelines, and some of them require notice or consent before you use AI on their matters. Read them. Firms have signed guidelines containing terms they were already violating on the day of signature.
Ordinary clients mostly don't ask, and when they do, they're asking whether their information is safe and whether a person is actually working on their case. The honest answer, delivered plainly, tends to reassure: yes, the firm uses software to handle routine parts of the work faster, no, your information doesn't go into public tools, and yes, a lawyer reviews everything. Firms that get defensive about this question create a problem where there wasn't one.
Then there's billing, which is where the real tension lives. If a task took three hours last year and takes forty minutes now, billing three hours is a problem you don't want to have to explain. This is the actual reason some firms are slow-walking adoption, and nobody says it out loud in the partner meeting. Worth saying out loud.
Questions to ask before client data touches a vendor
Print these. Ask them before the demo ends, while the salesperson still wants something from you.
Where is our data stored, and in which country. How long do you retain inputs and outputs, and can we configure that. Do you use our data to train models, ever, including in aggregate or de-identified form. Who at your company can access it, and under what circumstances. Which subprocessors touch it, and will you tell us when that list changes. Do you have a current SOC 2 Type II report, and will you send it under NDA today. Will you sign a data processing agreement and a confidentiality agreement. What's your breach notification commitment, in hours. And what happens to our data when we cancel, in writing.
The pattern to watch for is not a bad answer. It's a slow one. Vendors who have done this work answer these questions in the meeting, because they get asked every week. Vendors who haven't will offer to "loop in" somebody and then send a page about their commitment to security. That delay is the finding. The same discipline applies to every vendor holding client data, not only the AI ones, which is why this section rhymes with a good chunk of our cybersecurity guide for firms.
The math, and the awkward part of it
Run the arithmetic on your own numbers rather than a vendor's slide. Take a task your firm does constantly. Estimate the hours it consumes across the firm in a year. Estimate honestly what portion of it the tool absorbs, then subtract the review time the tool creates, because review time is real and vendors leave it out. What's left is your recovered capacity. Compare it to the total cost of the tool, setup and training included.
For a hypothetical ten-lawyer firm, suppose meeting summaries and first-pass document work give back an average of two hours a week per lawyer. Call it a thousand hours a year of capacity. That number is either enormous or meaningless depending on one decision: whether the firm turns recovered hours into more matters, better response times, and fewer weekends, or lets them quietly refill with the same work moving slower.
And then the awkward part, again, because it's the thing that actually decides adoption in a law firm. Efficiency and hourly billing point in opposite directions. Firms with meaningful fixed-fee or flat-rate work capture the gain immediately and adopt fast. Firms billing purely by the hour have to decide whether the gain shows up as capacity for more matters or as a smaller invoice. There's no clever way around this, only a decision, and it belongs to the partners rather than to whoever runs technology.
A ninety-day rollout that won't blow up
Weeks one through four: find out what's already happening. Ask, without consequences attached, what people are using. You'll get an honest answer only if the amnesty is genuine, and the answer is the most useful input to everything that follows. While you're there, inventory which of your existing platforms shipped AI features you're already paying for and haven't turned on. Firms routinely buy a tool they already own.
Weeks five through eight: approve two things and write the page. Pick the two lowest-risk uses with the clearest payoff, which for most firms means meeting summaries and internal search. Buy the business tier. Get the vendor answers in writing. Draft the one-page policy against the two approved uses instead of against the abstract idea of AI.
Weeks nine through twelve: train, measure, and widen. Thirty minutes of training with real examples from your own practice, not the vendor's demo data. Then measure something specific: how many hours the summaries actually save, how often the search finds the memo. Bring numbers to the partner meeting rather than enthusiasm. Enthusiasm gets you one meeting.
After that, add one use at a time, on the same pattern. Firms that try to do everything in a quarter end up with five half-configured tools and a partnership that has decided the whole category was oversold.
Where this leaves you
The firms handling this well are not the ones with the most tools. They're the ones that decided where client data is allowed to travel, wrote it down, bought the right tier of the right software, and left a human on the last step of everything that leaves the building. That's a governance posture, and it's achievable this quarter by a firm of eight.
What you get for it is time back on the parts of the week nobody bills well anyway: the notes after the call, the search for the memo, the first pass through a contract you've read forty versions of. What you keep is the judgment, which was always the product. If your firm also handles tax and accounting work, the parallel version of this argument is in our guide to AI for accounting firms, where the documents are different and the discipline is identical.

