home  /  governance & policy
department of governance & policy

The documents that decide what actually happens.

A policy nobody can recall under deadline is not governance. The test is whether it changes behaviour at eleven at night.

begin here

Where is your firm?

Start a conversation with the AI Adoption Concierge, already scoped to governance & policy. Choose the question closest to yours, or describe your situation directly.

AI Adoption Conciergegovernance & policy · orientation, not legal or ethics advice
Tell me what exists today — a policy, an approved tool list, or nothing yet — and roughly the firm's size. I'll help you scope it. I can't advise on what your jurisdiction requires.

Most firm AI policies are written to satisfy a risk committee rather than to guide a lawyer at the point of decision, which is why so many of them sit unread. A policy that works is short, names the approved tools, states plainly what may and may not go into them, says who checks output before it leaves, and tells people what to do when something goes wrong. Everything beyond that is commentary. The harder governance question is not the document at all — it is whether the firm knows what its people are actually using, because the tools are one browser tab away and a policy the firm cannot see compliance with is a statement of hope.

specialization areas

Areas in this part of the practice.

The policy itself, the gap between the policy and reality, and what happens when the gap produces an incident.

methodology

How this department investigates.

How the Institute approaches governance — drafting and structure, not advice on your jurisdiction.

Policy draftingShort enough to be read, specific enough to answer the question someone actually has at the point of use.
Approved tool registerWhat is permitted for what, kept current — the single most-consulted part of any firm policy.
Usage visibilityWorking out what the firm can actually see, which usually turns out to be less than assumed.
Incident responseA defined first hour, decided before it is needed rather than during it.
OwnershipA named owner for the policy and the register, since both go stale in months without one.
Review cadenceA scheduled revisit, because the tools, the guidance and the case law all move faster than annual policy cycles.
common questions

Governance — the questions firms ask.

How long should the policy be?

Short enough that a lawyer will read it once and remember the shape of it. The working versions tend to run to two pages: which tools are approved and for what, what may never go into any of them, who verifies output before it leaves the firm, what to disclose to clients, and who to tell immediately if something goes wrong. Long policies get approved and ignored. If the firm needs a longer document for regulators or clients, keep it separate from the one people are expected to follow.

Should the policy ban consumer AI tools?

Most firms restrict them for client-confidential work and find that a blanket ban does not hold. The reason is structural: the tools are free, capable and one tab away, so prohibition without an approved alternative simply moves usage out of view. That is the worst configuration — the confidentiality exposure without any of the governance. Firms that provide a sanctioned tool that is genuinely good enough, and are specific about what may never go into anything, get far better compliance than firms that prohibit.

Who should own AI governance?

Someone with authority and enough proximity to practice to know when a rule is unworkable. Firms have placed it with general counsel, a managing partner, an innovation or knowledge role, or a small committee — the specific home matters less than that it is one identifiable owner rather than a committee that meets quarterly. What consistently fails is ownership by IT alone: the questions that matter are professional-responsibility and client-relationship questions with a technology component, not the reverse.

What does ABA Formal Opinion 512 actually require of a policy?

It does not prescribe a policy document. Issued in July 2024 as the ABA's first ethics guidance on generative AI, it addresses the duties the technology engages — competence, confidentiality, communication, candour toward the tribunal, supervisory responsibility and fees. Supervision and competence are the ones that most directly imply firm-level process, since a firm has to be able to show that people using these tools understand them and that output is reviewed. States have issued their own guidance and it is not uniform, so a firm should read its own jurisdictions rather than treat the ABA opinion as governing.

Does your policy change what people do?

Describe what exists today. The Institute will help you write something people will follow.

AI adoption conciergeorientation · not legal or ethics advice
Tell me what exists today — a policy, an approved tool list, or nothing yet — and roughly the firm's size. I'll help you scope it. I can't advise on what your jurisdiction requires.