All professional firms
Your staff are using AI tools. Here is a policy that works.
· PS ProTech · 4 min read
Someone at your firm has pasted a client's document into an AI chatbot this week. Probably to summarize it, tidy up a letter or draft a reply. They did it because it saves time, and nobody told them not to.
That isn't a reason to panic. It's a reason to have a rule.
What the risk is
When text goes into a public AI tool, it leaves your firm. Depending on the tool and the account, it may be stored, reviewed by the provider's staff, or used to improve the service. For most text that doesn't matter. For a client's confidential information it does.
Think about what your firm holds: privileged correspondence, tax returns, financial statements, medical details in a claim file, the terms of a deal that hasn't been announced. You have professional and contractual duties to keep those confidential. A member of staff pasting them into a consumer chatbot may have broken those duties without knowing it.
There are two smaller risks as well:
- Wrong answers that sound right. AI tools state errors with confidence, including invented citations and figures. Work that goes to a client unchecked carries your name.
- Tools nobody chose. Browser extensions and meeting recorders that staff install themselves can read email, documents and calls.
Why a ban doesn't work
Firms that forbid AI outright find that staff use it anyway, on personal phones and personal accounts, where you can see nothing and control nothing. You end up with the same risk and less visibility.
A workable policy says yes to something specific. That's what makes the "no" stick.
A policy in six rules
Adapt this to your firm. It fits on one page.
1. Use only approved tools. Name them. Choose business versions that commit in their terms not to train on your data and that let you manage accounts centrally. If your firm uses Microsoft 365 or Google Workspace, the AI assistant built into your plan is usually the place to start, because your data stays inside the service you already trust.
2. Sign in with your work account. Never a personal one. That way access ends when someone leaves, which ties into your offboarding checklist.
3. Never put these into any AI tool that isn't approved for them:
- Client names with their confidential information
- Social Security numbers, account numbers and tax identifiers
- Health information
- Passwords and access codes
- Anything covered by privilege or a confidentiality agreement
4. Check everything. A person reviews every output before it's used. Verify every citation, figure and quotation against the source. The person who sends the work is responsible for it.
5. Ask before installing. No AI browser extensions, note-takers or plugins without approval. This is the rule staff break most often, because these tools install in one click.
6. Tell us when something goes wrong. If confidential information goes into the wrong tool, report it straight away. Make it clear that honest reports won't be punished. You can't fix what you don't hear about.
Check what your clients require
Before you settle rule one, read your engagement terms and any client security requirements. Some corporate clients now forbid their outside advisers from using AI on their matters, or require consent first. If you answer client security questionnaires, expect AI questions on the next one. We cover how to handle those in how to answer a client security questionnaire.
Your profession may have its own guidance too. Check with your bar, your board or your regulator. This article is general information, not legal advice.
Back the policy with settings
A policy that relies only on memory will slip. A few technical controls make it hold:
- Manage which apps and extensions can be installed on firm computers. See device monitoring and patching.
- Set permissions properly before turning on a built-in AI assistant. These assistants can find any file a person has access to. If your shared drives are open to everyone, the assistant will surface the partners' compensation spreadsheet to whoever asks. Fix the permissions first. See Microsoft 365 and Google Workspace.
- Watch for unusual account activity, which also catches a compromised AI account.
- Cover it in training, with real examples from your own work. See security awareness training.
How to roll it out
- Ask first. Find out what staff already use and what for. You'll learn which tools to approve.
- Pick the approved tools and set them up with work accounts.
- Write the one-page policy and have everyone sign it.
- Spend twenty minutes on it in a team meeting, with examples of what's fine and what isn't.
- Review it every six months. The tools change quickly.
Getting help
Which AI tools your staff use, and what goes into them, is one of the five things we cover in our free IT and cybersecurity review. If you'd like the policy written and the settings put in place, that's part of our compliance support. You can also work through the full security checklist on your own.
