Jump to section
Someone at your firm used an AI tool this week. Maybe it was you, drafting a demand letter at 9 p.m. Maybe it was an articling student running a research question through a chatbot, or an assistant asking a tool to summarize a client email. It already happened. The only question is whether it happened inside a rule you set, or in the quiet space where no rule exists yet.
A small firm does not need a governance framework the size of a bank's. It needs one page that a busy person will read once, remember, and follow. Here is how to write that page and put it to work this week.
Why a One Page Policy Beats a Binder Nobody Reads
Long policies fail for a simple reason: nobody reads them, so nobody follows them. A twelve-page document full of defined terms and cross-references feels responsible when you draft it and does nothing when a stressed associate is deciding, in real time, whether to paste a client's affidavit into a chatbot.
Your duties are already clear. Every Canadian law society expects competence, confidentiality, and supervision. Those duties do not change because the tool is new. A good AI policy just translates them into concrete rules for the tools your people actually touch. Keep it to one page and it becomes a reference someone can pull up in the moment. That is worth more than any binder.
Tip. Write the policy so a new hire could follow it on their first day without asking a single question. If a rule needs a paragraph of explanation, it is probably two rules pretending to be one.
Decide What Tools Are Allowed and Who Approves Them
Start with a list, not a philosophy. Name the specific tools your firm permits, and state plainly that anything not on the list needs approval before it touches firm work. This is the single most useful sentence in the whole document, because it turns a vague worry into a clear yes or no.
Pick one person as the approver. In a solo shop that is you. In a small firm it might be a partner or your practice manager. The approver's job is not to become an AI expert. It is to ask a few questions before a new tool enters the workflow: Where does the data go? Is it used to train the vendor's models? Can we turn that off? Those questions overlap with how you should vet any software vendor, so you are not inventing a new process from scratch.
| Category | Example use | Status |
|---|---|---|
| General drafting | Outlining a letter, rephrasing a paragraph | Allowed on approved tools |
| Legal research | Framing an issue, finding starting points | Allowed, verify every citation |
| Client documents | Uploading files with client data | Approved tools only |
| New tool | Anything not on the list | Ask the approver first |
Draw a Clear Line Around Client Data
This is the part that keeps people up at night, so make it the sharpest rule on the page. Confidentiality does not soften because the recipient is a machine. When you paste a client's information into a tool, you are disclosing it to whoever runs that tool, under whatever terms buried in their agreement.
Your policy should state, in one line, which category of information can go into which tool. Public facts and hypotheticals are one thing. A client's name, financial details, or the substance of their matter are another. The same instincts you bring to confidentiality in any cloud tool apply here, only faster, because AI tools invite you to type freely.
Confidentiality does not soften because the recipient is a machine. A rule worth putting on the page
Two practical moves make this real. First, prefer tools that contractually promise not to train on your inputs, and confirm that setting is switched on. Second, get in the habit of stripping identifying details when the tool does not strictly need them. Understanding what metadata is and why it matters helps here too, because a document can carry more than what you see on the page.
Watch out. Free consumer versions of popular AI tools often reserve the right to use your inputs to improve their models. Read the actual terms for the version your firm uses, not the enterprise marketing page.
Set Rules for Reviewing and Owning the Output
Here is the rule that protects your licence: you own everything that leaves your firm, no matter what produced it. AI can draft, suggest, and speed you up. It cannot be responsible. You are.
Write that ownership into the policy as a workflow, not a slogan. Every AI-assisted output gets read by a human who understands the matter. Every citation gets checked against a real source. Nothing goes to a client, a court, or opposing counsel until a lawyer has verified it the way they would verify a junior's work. We wrote a fuller guide on reviewing AI output responsibly, and the short version is that the tool changes how fast you get a draft, never who is accountable for it.
- A person who knows the matter reads the full output.
- Every citation and quotation is verified against the source.
- Facts about the client are confirmed against the file, not assumed.
- The final work product is yours, and you can defend every line.
Roll It Out to Staff Without a Lecture
A policy people resent is a policy people route around. So do not roll it out as a warning. Roll it out as permission with guardrails, which is what it actually is. Most staff are not looking to be reckless. They are looking to be told what is fine so they can stop guessing.
Hold one short conversation. Walk through the page, take questions, and name the approver out loud so people know who to ask. Then put the page somewhere everyone can find it, next to your other firm standards in a shared document management approach or your internal knowledge base. If your practice runs on a system like A1 CMS, keep the policy where the rest of your firm's reference material lives so nobody has to hunt for it.
Note. Pair the policy with your broader security habits. AI rules land better when they sit alongside things people already accept, like multi-factor authentication for the whole firm.
Review the Policy Every Quarter
AI tools change monthly. A policy you write today will have a stale line in it by autumn, and that is fine, as long as you have a standing date to fix it. Put a recurring quarterly reminder on the approver's calendar. Fifteen minutes, four times a year, keeps the page honest.
At each review, ask three questions. Did anyone use a tool that is not on the list? Did any approved vendor change its terms? Did we hit a situation the policy did not cover? Update the page, note the date, and move on. That rhythm is how a one-page document stays alive instead of becoming another file nobody opens.
The firms that handle AI well are not the ones with the longest policies. They are the ones who wrote something short, tied it to the duties they already owe, and actually followed it. You can draft this page in an afternoon and adopt it this week. If you want to see how other small firms approached the same problem, our legal tech and AI writing digs into the practical side, and Priya's other posts cover the operational habits that make policies like this stick. Start with one page. Your future self, and your law society, will thank you.