AI Acceptable Use Policy for Law Firms: What It Should Say | Cyooda

Your firm already has an AI policy. You just didn't write it.

Right now, in the absence of anything official, every member of your staff is making their own individual decision about what to paste into ChatGPT. Some have decided client names are fine as long as they change them slightly. Some have decided a contract is fine as long as they delete the parties' details. Some have decided nothing is fine and are quietly falling behind colleagues who've decided everything is.

That's your current policy: dozens of private judgement calls, made alone, by people with no security training, under time pressure. The question isn't whether to have an AI acceptable use policy. It's whether the one you have should be an accident.

I've now reviewed AI policies at a number of firms, and I've noticed the same failure mode at both ends of the spectrum. Firms with no policy have the problem above. Firms with a forty-page policy have the same problem — because nobody has read it, so the private judgement calls continue, just with a false sense of coverage on top.

The useful AI policy is one page. Here's what should be on it.

Why One Page Beats Forty

A policy is only a control if people read it, remember it, and can apply it at the moment of decision — which for AI use is dozens of times a day, mid-task, with a deadline looming.

A forty-page document fails all three tests. It gets skimmed once during induction, filed, and never consulted again. Worse, long policies tend to be written defensively, to protect the firm in a dispute rather than to guide behaviour. They answer the questions a lawyer drafting a policy finds interesting, not the questions a paralegal at 4:45pm actually has.

The questions staff actually have are short: *Can I use this tool? Can I put this document into it? Who's responsible if the output is wrong?* A policy that answers those three questions in plain language, on one page, will change behaviour. A policy that answers three hundred questions across forty pages will not.

Design for adoption, not for completeness.

The Nine Things the Page Should Cover

1. Which tools are approved — by name. Not "enterprise-grade AI tools may be used with appropriate caution." Name them. "Staff may use [tool] under the firm's enterprise licence. No other AI tools are approved for client work." Ambiguity here is where the whole policy unravels.

2. Which tools are prohibited — and why, briefly. One sentence on the reason lands better than a bare prohibition: free public tools may retain and train on whatever is entered, which is inconsistent with our confidentiality obligations. Staff follow rules they understand.

3. What may be entered. Give categories, not abstractions. Public information, general legal research questions, your own drafting with no client identifiers — fine.

4. What may never be entered. Client names and identifying details. Privileged material. Anything subject to a confidentiality obligation or court order. Identity documents. If in doubt, treat it as confidential. This is the paragraph that matters most; write it so a new starter could apply it on day one.

5. Who owns the output. The practitioner does. AI-assisted work is still your work: you verify authorities exist, you check the reasoning, and your name goes on it. The tool is never the author and never the excuse. Australian courts have already had to deal with fabricated citations in filings; make it explicit that "the AI got it wrong" will not be an available answer at this firm.

6. Disclosure and the duty to the court. Where a court practice note or direction requires disclosure of AI use in preparing material, the practitioner is responsible for knowing and complying. Several Australian courts have issued guidance in this area and it's still moving — the policy should require compliance with whatever applies to the matter, not attempt to restate it.

7. Records and auditability.  For substantive matter work, keep the record you'd want if the work product were ever challenged: what was generated versus what you wrote, and what you verified. This is lighter than it sounds — often a file note — and it's what turns "we used AI responsibly" from an assertion into evidence.

8. Who to ask.  A named person or role for the grey areas. Grey areas are where incidents happen; give people somewhere to take them that isn't their own best guess.

9. When it gets reviewed. This field is moving fast enough that a policy dated more than twelve months ago is a museum piece. Put a review date on the page and honour it.

That's the whole document. Everything else — vendor assessments, procurement standards, technical configuration — belongs in supporting material that risk and IT own, not on the page staff are expected to internalise.

The Sanctioned-Alternative Principle

Here's the part most policies get wrong, and it's the part that decides whether yours works.

A prohibition without a replacement fails. Every time.

Your staff aren't using public AI tools because they're careless. They're using them because the tools genuinely save hours, and because the firm hasn't given them a sanctioned way to capture that saving. If your policy is a list of "don'ts" with no "do," you haven't eliminated the behaviour — you've pushed it onto personal devices and personal accounts, where you have no visibility, no logging, and no enterprise data protections. Security teams call this shadow IT, and AI has made it the fastest-growing variety.

So the policy has to arrive in the same breath as an approved tool: an enterprise-grade offering where the vendor contractually doesn't train on your data, where access is tied to firm identity, and where usage is visible to the firm. Pair the two and compliance becomes the path of least resistance. Publish the prohibition alone and the policy is theatre.

The Confidentiality Line Is Not Hypothetical

If you need a way to make this concrete for partners, here it is.

An employment tribunal decision in the UK considered material that had been entered into a public AI tool, and the reasoning treated information put into a public tool as having lost its confidential quality — on the logic that you cannot hand information to a system that may retain and reuse it and still claim you kept it secret.

To be clear about what that is and isn't: it's a UK tribunal, it's one decision, and it is not settled Australian law. But the principle it illustrates maps uncomfortably well onto duties Australian practitioners already carry — confidentiality, competence, and supervision don't have an AI carve-out. Nobody should want their firm to be the Australian test case for whether pasting a client's affidavit into a free chatbot was consistent with those duties.

The point of the policy is to make sure that question never has to be answered about your firm.

The Fix Is Cheap. The Incident Isn't.

Here's the full remediation plan for the risk described in this post: one page, one approved tool, one thirty-minute briefing, one named owner, one annual review.

That's it. No new platform, no six-month project, no committee. It's one of the highest ratios of risk-reduced to effort-spent available to a law firm right now — which is exactly why it's frustrating to watch firms either ignore it or bury it under forty pages.

Compare that to the incident: a client's confidential material in a public tool, a mandatory conversation with the client about it, possibly a notifiable breach assessment, and a partner explaining to the practice's insurers how the firm's AI policy worked. There isn't a version of that conversation that goes well when the honest answer is "each staff member decided for themselves."

The policy already exists at your firm today. The only question is who's writing it — you, or everyone individually.

The nine components above are yours to lift — most firms can draft the page themselves. Where firms tend to want help is the part behind it: evaluating which tools are actually safe for privileged material, and standing up the sanctioned alternative that makes the policy stick.

If that's the conversation you want → [Cyber Chat]

John Reeman - Virtual CISO

John Reeman

I'm the CEO and Founder of Cyooda Security, an independent cybersecurity and digital forensics advisory consultancy based in Sydney. The former CISO of King & Wood Mallesons a global law firm, with 30 years of cybersecurity leadership, protecting organisations and government agencies from data breaches, ransomware, and cyber espionage.

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders. Threats, regulatory shifts, and practical tools from the field. No fluff.

The Legal Cyber Brief
Monthly cyber intelligence for law firm leaders.

The Legal Cyber Brief — monthly cyber intelligence for law firm leaders.

The Legal Cyber Brief
Monthly cyber intelligence for law firm leaders.