# GENERATIVE ARTIFICIAL INTELLIGENCE POLICY **Template version:** 1.0 **Effective as of [EFFECTIVE DATE]** > **Template note:** Bracketed text in ALL CAPS (e.g., `[FIRM NAME]`) must be customized before adoption. See the [Customization Guide](../../CUSTOMIZATION_GUIDE.md) for a complete checklist. This policy is one component of AI governance, not the whole of it: adopting firms should align it to a broader AI governance program, such as one structured around the [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework). This template is provided for informational purposes only and does not constitute legal advice. Each firm should review and adapt this policy with its own counsel before adoption. # 1. Purpose and Scope [FIRM NAME] (the "Firm") recognizes that generative AI tools ("AI Tools") can enhance legal services but also present risks to attorney-client privilege, confidentiality, data security, accuracy, and professional ethics. This Generative Artificial Intelligence Policy (the "Policy") establishes mandatory requirements for the responsible use of AI Tools by all Firm partners, attorneys, paralegals, staff, independent contractors, and other personnel (together, "Personnel") and is designed to ensure compliance with applicable professional conduct rules in all jurisdictions in which the Firm practices. Except where a provision specifies otherwise, references in this Policy to AI Tools also encompass Background AI, AI Notetakers, and Agentic AI Tools, whether or not they are generative. You must agree to this Policy to maintain access to Firm-provided AI Tools. This Policy applies to all Firm-related activities, whether performed on Firm premises, remotely, or on personal devices. The Firm has attorneys in various jurisdictions, and all Personnel must comply with jurisdiction-specific obligations (see **Appendix B**). If you are unsure of your obligations generally, or in a specific jurisdiction, please contact the Administrator of this Policy. # 2. Definitions - **"Administrator":** the administrator of this Policy is [ADMINISTRATOR NAME], the [ADMINISTRATOR TITLE] of the Firm, and may be contacted at [ADMINISTRATOR EMAIL]. - **"Agentic AI Tools":** AI Tools capable of performing multi-step tasks, making autonomous decisions, or taking actions without direct human intervention for each step. - **"Approved AI Tools":** AI Tools specifically vetted and approved by the Firm, as listed in **Appendix A**. For Firm attorneys and staff, this is primarily [PRIMARY LEGAL AI PLATFORM]. Only Firm-issued enterprise licenses may be used. If you are granted access by the Administrator to a tool not included on **Appendix A**, the tool is deemed approved for use in connection with Firm business once that approval is confirmed in writing, subject to this Policy. - **"[PRIMARY LEGAL AI PLATFORM]":** [DESCRIPTION OF PRIMARY LEGAL AI PLATFORM — e.g., a legal-specific AI platform for drafting and analysis]. Approved for use with Client Confidential Information, subject to client consent. - **"Background AI":** Software used by the Firm that incidentally includes AI features, as identified in the non-exhaustive list set forth in **Appendix A**. These platforms do not train on customer data without explicit consent. All Background AI output must be reviewed for accuracy. - **"Client Confidential Information":** All information relating to client representation, including client identity, legal advice, privileged communications, work product, case strategy, case details, and financial records. - **"Inputs":** All data, information, prompts, documents, or other content submitted to an AI Tool by Personnel. - **"Outputs":** All results, responses, content, or materials generated by an AI Tool in response to Inputs. - **"Sensitive Information":** Client Confidential Information, Firm proprietary information, personal data, Material Nonpublic Information ("MNPI"), and any information subject to privilege or work product protection. - **"Work Product":** Materials created by Firm Personnel in providing legal services, including documents reflecting legal analysis, opinions, advice, or strategy. # 3. Core Principles ## 3.1 Ethical and Professional Compliance All AI use must comply with applicable laws, regulations, court rules, and Rules of Professional Conduct. Personnel must maintain competence in AI technology (ABA Rule 1.1), protect client confidentiality (Rule 1.6), supervise subordinates' AI use (Rules 5.1, 5.3), exercise candor to tribunals (Rule 3.3), communicate with clients about AI use when relevant (Rule 1.4), and bill appropriately while using AI tools (Rule 1.5). Attorneys must stay current with jurisdiction-specific rules, including local court rules for any tribunal in which Work Product will be submitted. For detailed jurisdiction-specific ethics guidance applicable to each state in which the Firm practices, see **Appendix B**. ## 3.2 Client Consent and Engagement Letters The Firm has endeavored to ensure that all Firm clients have engagement letters that include default AI disclosure and informed consent language. In our representation of clients, Firm Personnel must ensure that the Firm uses AI responsibly in the course of representation and must use reasonable efforts to advise clients regarding the responsible use of AI, including a prohibition on the Firm's use of public AI chatbots or other services that train on client or Firm data or that would waive client confidentiality or privilege. ## 3.3 Data Security and Privacy Firm Personnel should comply with all Firm policies and use appropriate safeguards (encryption, secure passwords, multi-factor authentication) consistent with the Firm's data security policies. Personnel should use AI Tools responsibly, including by adhering to the following: use reasonable judgment in inputting only the minimum information necessary, including using de-identified, redacted, or hypothetical data where feasible; avoid inputting Sensitive Information into AI Tools, as such data is subject to heightened regulatory protections and poses elevated security risks. ## 3.4 Approved Tools Only The Firm permits AI Tool usage exclusively through Firm-approved enterprise accounts. The use of non-approved AI tools, personal AI accounts, free-tier AI chatbots, AI tools which train on customer data, or consumer-tier subscriptions for ANY client work or Firm business is strictly prohibited and is grounds for termination of employment or engagement. To request an exception or evaluation of a new AI Tool, contact the Administrator. # 4. Mandatory Verification of Citations and Fact-Checking All Personnel must independently fact-check and verify everything generated by AI Tools before submitting it to any supervisor, partner, client, court, or other recipient. This includes all case citations, statutes, regulations, factual assertions, dates, names, and quotations. AI Tools, including [PRIMARY LEGAL AI PLATFORM], can generate fabricated ("hallucinated") citations (of both law and facts) that appear legitimate but are fictitious. While legal-specific tools may hallucinate at a lower rate than non-legal-specific tools, all output must be meticulously verified. **Failure to verify AI-generated Work Product before submission is grounds for termination of employment or engagement. In each instance:** - Verify all citations through the appropriate reporter or legal research database. Cite-check every case to confirm existence, holding, and validity (e.g., using KeyCite or an equivalent citator). - Use [LEGAL RESEARCH PLATFORM]'s citation-verification tools (e.g., Westlaw's Quick Check) to confirm accuracy of all citations and quoted text. - Verify all factual assertions against primary sources. - Do not present AI-generated content as original Work Product without human review. Where a client agreement, court rule, or standing order requires disclosure of AI use, include an appropriate AI-use disclaimer in the form approved by the Administrator or supervisor, as appropriate. - Comply with all applicable court rules, standing orders, and individual judge rules governing the disclosure of AI use in filings in any tribunal in which Work Product will be submitted. Confirm the requirements applicable to the assigned judge and forum before each filing. # 5. Tool-Specific Usage Guidelines ## 5.1 Non-Enterprise Tools The Firm regularly vets and provisions enterprise AI tools for Firm Personnel and requires that Firm Personnel only use Firm enterprise tools for Firm business and Work Product. Accordingly, Firm Personnel are prohibited from using personal or unapproved non-enterprise AI tools for any Firm business or Work Product without the Administrator's approval. At minimum, for personal non-Firm work, we strongly recommend that all Personnel use a paid account with training disabled. If there are any tools that you would like the Firm to provision as an enterprise tool, please contact the Administrator. ## 5.2 Enterprise AI Workspaces (e.g., Foundational LLMs) **Permissible uses:** General-purpose enterprise AI workspaces (e.g., foundational LLMs like ChatGPT and Claude) are primarily intended for drafting non-confidential communications unrelated to a client of the Firm, marketing or business development, non-client-facing content, summarizing publicly available information, brainstorming, and internal administrative documents or workflows. Approved AI Tools that are cleared for client-confidential use in Appendix A may be used for Client Confidential Information and Work Product subject to the conditions in Appendix A and this Section 5.2. **Specific Workspace Use Cases:** A. **On-device or agentic use cases (e.g., Claude Cowork):** To enable these use cases, please contact the Administrator. Firm Personnel may be required to undertake additional training to access such features. B. **Connectors:** Firm Personnel may request that the Administrator enable Connectors to other Firm enterprise tools. C. **[PRIMARY LEGAL AI PLATFORM]:** The Firm recommends that all Personnel use [PRIMARY LEGAL AI PLATFORM] for Client Work Product, including (without limitation) drafting, contract analysis, substantive legal research, pleading preparation, and legal analysis involving Client Confidential Information. D. **[PRIMARY LEGAL AI PLATFORM] document workspaces (e.g., vaults):** Personnel can use [PRIMARY LEGAL AI PLATFORM]'s document workspace features to create and store Work Product but should ensure that any material documents are saved to the Firm's document management system ([DOCUMENT MANAGEMENT SYSTEM]). E. **[PRIMARY LEGAL AI PLATFORM] shared or collaborative spaces:** May be enabled on a client-by-client basis, with the approval of the Administrator. ## 5.3 Background AI Background AI platforms (i.e., software that runs passively or incidentally includes AI features as part of broader functionality, such as legal research, productivity, communications, document management, scheduling, marketing, or workflow tools) may be used consistent with this Policy. A non-exhaustive list of currently-used Background AI platforms is set forth in **Appendix A**. All AI-generated content must be reviewed for accuracy. ## 5.4 Client Use of AI Notify all clients that using personal AI tools in connection with legal matters is not confidential and may waive attorney-client privilege and work product protections. Advise clients not to input attorney-client communications or work product into public AI tools, as such inputs and corresponding outputs may be discoverable in current or future litigation. Document this notification in the client file. # 6. AI Notetakers and Transcription Tools AI-powered notetaking and transcription tools ("AI Notetakers") pose risks to privilege, confidentiality, and wiretap law compliance. These tools process audio through third-party servers, creating permanent records that may be discoverable and potentially waive privilege. Accordingly, Firm Personnel may not use AI Notetakers not provisioned by the Firm. ## 6.1 Consent Requirements Obtain informed, affirmative consent from all participants before activating any AI Notetaker, regardless of the jurisdiction in which any participant is located and regardless of whether applicable wiretap law would require single-party or all-party consent. Many AI Notetakers announce their presence automatically; that announcement alone is not sufficient, and silence does not constitute consent. For client communications, disclose the intended use in advance and explain the recording and third-party processing risks before obtaining consent. For communications with opposing counsel, co-counsel, or third parties, provide verbal notice and obtain affirmative consent. Treat all resulting recordings, transcripts, and derived work product as privileged and confidential to the same extent as the underlying communication, and store, transmit, and dispose of them in accordance with the Firm's privilege and data-security protocols. The Firm adopts this all-party consent standard as a matter of policy, which may be stricter than the consent required by applicable law. ## 6.2 Data Security and Approved Tools Use only Firm-approved AI Notetakers, as identified in Appendix A. Personal accounts, free-tier services, and any other third-party or consumer-grade notetaking or transcription tools are prohibited for client communications. For client communications, [APPROVED AI NOTETAKER] is the only approved AI Notetaker and may be used only after advance disclosure to, and consent from, the client in accordance with Section 6.1. Personnel must review, correct, and approve any summaries, minutes, or action items generated by AI Notetakers before internal or external circulation or archiving. Transcripts, recordings, and any derived work product generated from client communications must remain at all times within the Firm's controlled environment: store them in the Firm's document management system, disable automatic cloud storage and third-party integrations, and do not export, forward, sync, or otherwise transmit them to any vendor cloud, personal device, personal account, or external service. Third-party integrations that would transmit these materials outside the Firm's enterprise environment must remain disabled. ## 6.3 Client Use of AI Notetakers Client-generated transcripts of attorney-client communications may not be privileged and may be discoverable. At the outset of each engagement, advise clients that using personal AI Notetakers may waive privilege, particularly if the tool transmits data externally. Request that clients not record attorney-client communications with AI tools; if a client insists, document the Firm's risk advisement in writing and in the client file. # 7. Agentic AI Tools Obtain prior written consent from the Administrator before using any Agentic AI Tools. Agentic AI Tools must be configured to request human confirmation before executing state-changing actions; an Agentic AI Tool that cannot be configured to require such human confirmation may not be used for state-changing actions absent a specific written exception from the Administrator. Prohibited uses include: autonomous access to Sensitive Information without authorization; unattended tasks involving client data unless Firm-approved and configured to halt on error; and chaining multiple Agentic AI Tools without written approval. If an Agentic AI Tool takes unauthorized action, immediately cease use and report to the Administrator. # 8. Prohibition on AI Use in Firm Employment Decisions AI Tools may not be used in connection with any Firm employment decision, including any activity subject to NYC Local Law 144's requirements for bias audits, public disclosure, and advance notice to candidates. As a best practice, and consistent with the standards set forth in the EU AI Act (Regulation (EU) 2024/1689, Annex III, point 4), this prohibition also extends to any AI use that would be classified as high-risk in the employment context. This prohibition covers recruiting, selecting, or evaluating candidates, as well as decisions affecting promotion, compensation, performance evaluation, discipline, termination, or task allocation based on individual behavior or traits. Permitted administrative uses, such as drafting job descriptions, scheduling, or generating HR templates, are allowed only if the AI output does not inform or contribute to an employment decision. # 9. Oversight, Enforcement, and Administration ## 9.1 AI Governance Committee and Contacts The Firm's AI Governance Committee ("AIGC"), chaired by the Administrator, oversees AI policies, compliance, tool evaluation, and training. ## 9.2 Monitoring, Security, and Incident Response The Firm reserves the right to monitor and audit all use of Firm systems, Firm accounts, and Firm-provisioned AI Tools, including prompts, Inputs, and Outputs. Only authorized Personnel with proper credentials may access AI Tools; do not share credentials. AI access will be revoked upon termination. Report any AI incident (violation of this Policy, security breaches, material errors, or disclosure of privileged information) immediately to the Administrator. ## 9.3 Disciplinary Action **The following violations are grounds for termination of employment or engagement:** - Use of any non-approved AI tool, personal AI account, or consumer-tier subscription for client work or Firm business; - Failure to fact-check and verify AI-generated Work Product (including all citations) before submission to any recipient or tribunal; - Inputting Client Confidential Information into any non-approved AI Tool; and - Misuse of Firm AI Tools for non-Firm business. Other violations may result in disciplinary action up to and including termination of employment or engagement. ## 9.4 Billing, Training, and Policy Administration Consistent with ABA Model Rule 1.5 and its state-law analogs, when AI reduces time on a task, billing must reflect actual time and effort; do not bill for time saved. AI subscription costs not attributable to a specific client are Firm overhead. Personnel must complete the required AI training before being granted access, covering ethical obligations, data security, hallucination risks, jurisdiction-specific requirements, and tool-specific guidance. This Policy will be reviewed periodically and updated as necessary. The Firm reserves the right to modify this Policy at any time with or without notice. # Acknowledgment I acknowledge that I have received, read, understood, and agree to comply with this Generative Artificial Intelligence Policy. I understand that: (1) the Firm owns all Inputs and Outputs, and all such Inputs and Outputs are Firm records subject to the Firm's legal holds, discovery obligations, and regulatory requests, except that this provision does not alter the client's ownership of, or right to, client files, client property, and Work Product belonging to the client under applicable rules of professional conduct; (2) use of non-approved AI tools for client work or Firm business is grounds for termination of employment or engagement; (3) I must independently fact-check and verify all AI-generated Work Product before submission, and failure to do so is grounds for termination of employment or engagement; and (4) violations may result in disciplinary action, including termination, bar referral, and personal liability. Signature: _______________________________________________ Date: ____________________________________________________ Printed Name: ____________________________________________ Title / Position: ________________________________________ # Appendix A: Approved AI Tools and Background AI Platforms *Effective as of [EFFECTIVE DATE].* > **Template note:** Replace the entries below with the tools your firm has actually vetted, licensed, and approved. The entries shown are illustrative examples drawn from one firm's adoption of this policy; they are not endorsements, and your firm's list will differ. ## Approved AI Tools **[GENERAL-PURPOSE AI TOOL 1] (Enterprise Plan) — [VENDOR].** *Example: ChatGPT Enterprise — OpenAI.* Approved for legal drafting, analysis, and client-specific work, including contracts, pleadings, and substantive research. May be used with Client Confidential Information subject to: (i) supervising attorney approval; (ii) client consent via engagement letter or documented informed consent; and (iii) compliance with Section 5.2 of the Policy. All citations must be independently verified. **Accounts which are not part of the Firm's Enterprise plan may not be used.** **[GENERAL-PURPOSE AI TOOL 2] (Enterprise Plan) — [VENDOR].** *Example: Claude Enterprise — Anthropic.* Approved for legal drafting, analysis, and client-specific work, including contracts, pleadings, and substantive research. May be used with Client Confidential Information subject to: (i) supervising attorney approval; (ii) client consent via engagement letter or documented informed consent; and (iii) compliance with Section 5.2 of the Policy. All citations must be independently verified. **Accounts which are not part of the Firm's Enterprise plan may not be used.** **[PRIMARY LEGAL AI PLATFORM] — [VENDOR].** *Example: Harvey — Counsel AI Corporation.* Approved for legal drafting, analysis, and client-specific work, including contracts, pleadings, and substantive research. May be used with Client Confidential Information subject to: (i) supervising attorney approval; (ii) client consent via engagement letter or documented informed consent; and (iii) compliance with Section 5.2 of the Policy. All citations must be independently verified. ## Approved AI Notetakers **[APPROVED AI NOTETAKER]** *(Example: Zoom Workplace AI)* — the only AI Notetaker approved for client communications, subject to the consent and data-handling requirements of Section 6. ## Background AI Platforms The following platforms incidentally include AI features and may be used consistent with the Policy. All AI-generated output must be reviewed for accuracy. *(Replace with your firm's actual software stack; examples shown.)* - [LEGAL RESEARCH PLATFORM] *(e.g., Westlaw)* — AI-powered case briefs, precedent identification, and legal concept summaries - [VIDEOCONFERENCING PLATFORM] *(e.g., Zoom Workplace AI)* — AI Companion meeting summarization, action item capture, and smart scheduling - [OFFICE PRODUCTIVITY SUITE] *(e.g., Microsoft 365 / Copilot)* — AI-powered content generation, suggestions, and task automation - [PROJECT MANAGEMENT TOOL] *(e.g., ClickUp)* — AI-powered task summarization, task creation, and writing assistance - [TIMEKEEPING TOOL] *(e.g., Laurel)* — AI-powered timekeeping and time entry automation - [CRM / MARKETING PLATFORM] *(e.g., HubSpot)* — AI features for marketing, sales, and customer service - [DOCUMENT WORKFLOW TOOL] *(e.g., PandaDoc)* — AI-enhanced document creation and workflow management # Appendix B: Jurisdiction-Specific Ethics Obligations *Effective as of [EFFECTIVE DATE].* > **Template note:** Edit this appendix to reflect the jurisdictions in which your firm practices. The entries below were current as of June 2026 for one firm's jurisdictions and are provided as drafting examples; verify each authority before adoption and delete entries that do not apply. In addition to ABA Formal Opinion 512 (2024), Personnel must comply with the following jurisdiction-specific guidance when using AI Tools. This list reflects the jurisdictions in which the Firm currently practices and is not exhaustive; Personnel who are unsure of their obligations in any jurisdiction should contact the Administrator: - **New York:** NYC Bar Formal Opinion 2024-5 (August 2024) (comprehensive AI ethics guidance, implicating NY Rules 1.1–8.4); NYC Bar Formal Opinion 2025-6 (December 22, 2025) (AI recording/transcription of client conversations); NYSBA Task Force Report (April 2024); NY UCS Interim AI Policy (October 10, 2025); 22 NYCRR Part 161 (effective June 1, 2026) (attorney certification against AI-fabricated content in court filings; individual judges retain discretion to require disclosure of AI use). Monitor all applicable court disclosure requirements. - **New Jersey:** NJ Supreme Court Preliminary Guidelines on AI (January 2024, emphasizing RPC 3.1, 4.1(a)(1), 8.4(c), 1.6, 5.1–5.3); NJSBA Task Force Report (May 2024); CLE technology credit requirement (April 2025). - **Connecticut:** CT Rule 1.1, Comment [8] (duty of technology competence); CT Judicial Branch Committee on AI (monitoring ongoing). Apply ABA Formal Opinion 512 and peer jurisdiction guidance pending CT-specific opinions. - **Florida:** Florida Bar Advisory Ethics Opinion 24-1 (January 2024): Confidentiality (Rule 4-1.6), competence (Rule 4-1.1), billing (Rule 4-1.5), advertising (Rule 4-7.13), and supervision of AI as nonlawyer assistant (Rule 4-5.3(a)). - **California:** State Bar Practical Guidance for Use of Generative AI (November 2023): Confidentiality (Rules 1.6, 1.8.2), competence (Rules 1.1, 1.3), candor, supervision (Rules 5.1–5.3), non-discrimination (Rule 8.4.1), and AI billing practices. - **Texas:** Professional Ethics Committee Opinion No. 705 (February 2025): Competence (TDRPC Rule 1.01), confidentiality (Rule 1.05), verification/candor, and fair billing. Monitor N.D. Tex. LR 7.2(f) and S.D. Tex. General Order 2025-04 on use of generative AI in court filings. - **Washington, D.C.:** D.C. Bar Ethics Opinion 388 (April 2024): Competence (Rule 1.1), confidentiality (Rule 1.6(f)), supervision (Rules 5.1, 5.3), candor (Rules 3.3, 3.4), fees (Rule 1.5), and client file obligations (Rule 1.16(d)). D.C. adopted formal duty of technology competence in 2025. --- *This template is adapted from the Generative Artificial Intelligence Policy of Falcon Rappaport & Berkman LLP ("FRB") and is dedicated to the public domain under [CC0 1.0](https://creativecommons.org/publicdomain/zero/1.0/); attribution is appreciated but not required. It is not legal advice. Firms adopting this template are responsible for tailoring it to their own practice, jurisdictions, tools, and risk tolerance, and for keeping the cited authorities current. If you would like attorneys to review your customized policy or advise on your AI governance program, FRB is available to help: visit [ai.frblaw.com](https://ai.frblaw.com) or email [ai@frblaw.com](mailto:ai@frblaw.com). Reaching out does not create an attorney-client relationship.*