A policy nobody can recall under deadline is not governance. The test is whether it changes behaviour at eleven at night.
Start a conversation with the AI Adoption Concierge, already scoped to governance & policy. Choose the question closest to yours, or describe your situation directly.
Most firm AI policies are written to satisfy a risk committee rather than to guide a lawyer at the point of decision, which is why so many of them sit unread. A policy that works is short, names the approved tools, states plainly what may and may not go into them, says who checks output before it leaves, and tells people what to do when something goes wrong. Everything beyond that is commentary. The harder governance question is not the document at all — it is whether the firm knows what its people are actually using, because the tools are one browser tab away and a policy the firm cannot see compliance with is a statement of hope.
The policy itself, the gap between the policy and reality, and what happens when the gap produces an incident.
Two pages that answer the question someone actually has at the moment they have it.
investigateThe gap between what the firm permits and what its people are actually using.
investigateThe first hour, decided in advance — because the reported cases turned as much on the response as the error.
investigateHow the Institute approaches governance — drafting and structure, not advice on your jurisdiction.
Short enough that a lawyer will read it once and remember the shape of it. The working versions tend to run to two pages: which tools are approved and for what, what may never go into any of them, who verifies output before it leaves the firm, what to disclose to clients, and who to tell immediately if something goes wrong. Long policies get approved and ignored. If the firm needs a longer document for regulators or clients, keep it separate from the one people are expected to follow.
Most firms restrict them for client-confidential work and find that a blanket ban does not hold. The reason is structural: the tools are free, capable and one tab away, so prohibition without an approved alternative simply moves usage out of view. That is the worst configuration — the confidentiality exposure without any of the governance. Firms that provide a sanctioned tool that is genuinely good enough, and are specific about what may never go into anything, get far better compliance than firms that prohibit.
Someone with authority and enough proximity to practice to know when a rule is unworkable. Firms have placed it with general counsel, a managing partner, an innovation or knowledge role, or a small committee — the specific home matters less than that it is one identifiable owner rather than a committee that meets quarterly. What consistently fails is ownership by IT alone: the questions that matter are professional-responsibility and client-relationship questions with a technology component, not the reverse.
It does not prescribe a policy document. Issued in July 2024 as the ABA's first ethics guidance on generative AI, it addresses the duties the technology engages — competence, confidentiality, communication, candour toward the tribunal, supervisory responsibility and fees. Supervision and competence are the ones that most directly imply firm-level process, since a firm has to be able to show that people using these tools understand them and that output is reviewed. States have issued their own guidance and it is not uniform, so a firm should read its own jurisdictions rather than treat the ABA opinion as governing.
Describe what exists today. The Institute will help you write something people will follow.