Compliance · 6 min read
AI policy template for law firms
Last checked 05/10/2026 · England and Wales
Which tools people may use, what client information can go into them and who checks the results, written around the SRA's AI warning notice of 17 August 2026.
Does a law firm need an AI policy?
No rule names one. The SRA expects firms to have effective governance, systems and controls for the risks AI brings (paragraph 2.1 of the Code for Firms), and its AI notice points to confidentiality and supervision. A short written policy is the simplest way to show you have them.
What should an AI policy for a law firm cover?
Approved tools and what they're for, what client information can go into them, who checks the output, what AI isn't used for, training, and what to do when something goes wrong. Keep it short, and keep the approved tools in a register you can update.
- Why we have this policy
- Who it applies to
- Approved tools
- Client information
- Checking what AI produces
- What AI is not used for
- Training
- When something goes wrong
- Review and sign-off
Who should sign off a law firm's AI policy?
The managers and the COLP. Every manager is responsible for the firm's compliance (paragraph 8.1 of the Code for Firms), and the COLP must take all reasonable steps to make sure the firm complies (paragraph 9.1). Name one person to own the register, and review the policy at least yearly.
Do we need a data protection impact assessment for an AI tool?
Sometimes. Under Article 35 of the UK GDPR, you assess the impact before processing likely to result in a high risk to people's rights, in particular with new technologies. If a tool will process client personal data, check the ICO's guidance on AI and data protection first.
The template
AI policy for law firms
Fill in the square brackets. Review it at least once a year.
1. Why we have this policy
AI tools can draft, check, find and summarise. Using them doesn't change anyone's professional duties. This policy sets out the tools we use, what client information may go into them and who checks their output.
2. Who it applies to
Everyone who works for [firm name], on any device used for firm work.
3. Approved tools
Use only the tools in the register below for firm work. Ask [name and role] before using anything else.
| Tool | What it may be used for | Client information allowed? | Approved by | Review date |
|---|---|---|---|---|
| [Tool name] | [e.g. drafting attendance notes from dictation] | [Yes, inside our Microsoft 365 / No] | [Name] | [DD/MM/YYYY] |
4. Client information
Client information goes only into tools the register allows. Before approving one, [name and role] checks that it has contractual, technical and organisational safeguards: the information stays secure, isn't used for training unless authorised, and isn't kept longer than needed.
Never put client information into a free public AI tool.
5. Checking what AI produces
A named fee earner checks every output before it reaches a client, a court or another party, and stays responsible for it.
Every authority AI produces is checked against the original before it is relied on.
6. What AI is not used for
Legal advice, conflict and money laundering decisions, or approving anything for the firm. AI can gather the information a person needs to decide.
7. Training
Everyone is shown this policy and the approved tools before using them. [Name and role] records who has been trained.
8. When something goes wrong
Tell [the COLP] straight away if client information has gone into the wrong tool, or an AI error has reached a client, a court or another party. The COLP records it in the breach record and decides whether to report it to the SRA.
9. Review and sign-off
Owned by [name and role], and reviewed at least once a year or when the tools or rules change.
Approved by [managing partner] and [COLP] on [DD/MM/YYYY]. Next review: [DD/MM/YYYY].
Policy in place? Find the first job to hand to AI.
About two minutes.