Five decisions, written down. Everything else in a policy is commentary on those five.
Start a conversation with the AI Adoption Concierge, already scoped to the firm AI policy. Pick a starting point, or describe your situation directly.
A firm AI policy exists to answer questions at the point they arise: can I use this tool, can I put this document into it, does someone need to check the output, does the client need telling, and who do I call if it has gone wrong. A document that answers those five clearly will be consulted. A document that opens with a definition of large language models and a statement of the firm's commitment to innovation will not. The discipline is to resist the pull toward comprehensiveness — the policy is an operational instrument, and any obligation it creates that people cannot follow under deadline is an obligation the firm has decided to breach in advance.
Anything a policy contains beyond these should earn its place or move to a separate document.
A named list mapped to permitted uses. The most-consulted line in any firm policy, and the one that goes stale fastest.
Client-confidential material, privileged content, personal data — stated concretely rather than by category.
The review obligation, tied to where the work is going rather than to who produced it.
The firm's disclosure position, so nobody has to invent one on a call.
A named person and the instruction to escalate early. This line does more work than the rest combined.
Named, with a review date. Unowned policies are indistinguishable from expired ones within a year.
How a usable policy is produced.
Chiefly whether the firm can say what its own position was, on the day someone asks.
Reported decisions have turned as much on what happened after the error as on the error — courts have responded far more severely where a problem was minimised, or surfaced by the court rather than disclosed. A policy that makes early escalation obviously safe buys more protection than any prohibition.
One that people follow, plus separate documents for other audiences. Firms often need something longer for clients, insurers or regulators — a description of controls, vendor diligence and governance structure. Keeping that separate from the operational policy protects the short one from growing. What does not work is different rules per practice group; permitted uses can vary sensibly by work type, but the prohibitions and the escalation route should be identical firm-wide or nobody knows which version applies to them.
Specific about prohibitions, permissive about uses. A policy that enumerates every allowed task will be out of date within a quarter and will make people ask permission for things nobody thought to list — which in practice means they either stop or proceed unrecorded. The more durable structure is a short list of things that may never happen, a named set of approved tools, and a review obligation scaled to where the output is going. That accommodates new uses without a policy amendment.
Increasingly it comes up, particularly where a client supplies AI-generated material the firm will rely on or file. The prudent position most firms reach is that anything the firm signs or files carries the firm's verification obligation regardless of who drafted it — a client-supplied draft is not a reason to skip the citation check, and courts have not treated it as one. Whether to say that explicitly in the policy is a judgement call; firms with sophisticated clients increasingly do.
Look at usage data against the approved tool list, and at whether escalations happen at all. A firm with an AI policy, meaningful AI use, and zero reported near misses over a year is almost certainly not seeing them rather than not having them — the sanctions record suggests near misses are common. Some reporting is evidence the escalation route is trusted. None is usually evidence people are handling problems quietly, which is the state the firm least wants and is least likely to detect.
Describe the firm and what exists today. The Institute will help you draft it.