Building an AI policy for your law firm:

Building an AI policy for your law firm: One that actually gets used

The decisions AI forces you to make, the sections firms forget, and why this policy dates faster than any others you own.

AI Policies

By now most firms know they need an AI policy.

The harder question is what goes in it, and why so many of the ones already written aren’t really doing what they’re supposed to be doing.

 A policy that bans everything gets ignored and drives people to their phones. A forty-page one nobody finishes protects no one. A policy written last year already lists tools that have changed underneath it. The document isn’t the point; what the document changes is.

This page is about writing one that earns its place: the calls AI forces you to make that your existing policies never had to, the sections firms routinely forget, and how to keep it alive once the tools move on (which they will, faster than the policy).

What an AI policy is actually for

An AI policy is the document that tells everyone in the firm what they can do with AI, what they can't, and who to ask when it isn't clear.
Its job is less to restrict than to give people the confidence to act – the difference between a fee earner using a sanctioned tool well and the same person guessing, or even worse – using something they shouldn’t.

That reframing matters, because it changes what a good policy looks like. The regulator doesn’t ask for a prohibition list. The SRA’s expectation is that firms have leadership and oversight, risk and impact assessments, documented policies, staff training, and ongoing monitoring in place – with the COLP responsible for regulatory compliance when new technology is introduced.

A policy is how those pieces get written down and made real. Think of it as a permission framework with clear edges, not a set of things not to do.

Standalone, or part of what you already have?

The first decision isn’t what the policy says, it’s whether it’s a document of its own at all.

AI use touches ground your existing policies already cover – information security, outsourcing and supplier management, supervision, data protection.

So, there’s a real choice between a standalone AI policy and threading AI through the policies you already maintain. Both are defensible.

There's no right answer, only a fit with how your firm's documents already work.

A standalone policy gives AI visibility and a single obvious home, which helps while it’s still novel and while people need somewhere clear to look. Folding it into existing policies avoids policy sprawl, keeps AI alongside the controls it actually interacts with, and signals that it’s business as usual rather than a special case. Plenty of firms start standalone for the clarity, then integrate as AI settles into normal practice.

There’s no right answer, only a fit with how your firm’s documents already work. What matters more than the container is that the decisions below are made and written down somewhere a fee earner can find them.

Why so many AI policies fail
Three failure modes account for nearly all of them, and none is a failure of intent.

The first is the blanket ban. Prohibiting AI outright feels safe and does the opposite – people use it anyway, on personal accounts, out of sight, which is precisely the exposure the ban was meant to prevent. A ban doesn’t stop AI use; it stops you knowing about it.

The second is length. A policy written to cover every eventuality becomes something no one reads to the end, which means in practice it governs nothing. The version people actually follow is short enough to hold in your head.

The third is staleness. The tools change monthly – a policy that names specific products, or assumes a landscape that’s already moved, is out of date before it’s even circulated.

A ban doesn't stop AI use; it stops you knowing about it.

The decisions AI forces you to make
You already know how to write a policy. What’s new is the set of positions AI requires you to take that none of your existing documents ever had to, and it’s those decisions, not the structure around them, that make an AI policy worth writing. A handful are load-bearing:
Where the confidentiality line sits

Which information is safe to put into which kind of tool – the distinction between a tool the firm holds under contract and a public one it doesn’t. It’s the single position fee earners most need spelled out. We go into it in depth in our guide to client confidentiality and AI.

AI output has to be checked against source before it’s relied on, because the solicitor stays personally responsible for every piece of work and must verify AI outputs. The decision is how far that duty goes and how you evidence it – the clause that keeps the firm out of the fabricated-citation headlines.
Not just which tools are sanctioned, but the route for getting a new one assessed and added, because without it, the list becomes a bottleneck people will route around, which is where governance breaks down.
The firm’s position on when and how AI use is disclosed, since the SRA expects firms to be clear with clients about where they interface with AI (including any standard engagement-letter wording).
Where AI touches personal data, the policy needs to point at the machinery you already run – a DPIA before high-risk processing, and the DPO’s sign-off – rather than treat AI as a separate track. The link is the point: AI governance and data-protection compliance are the same obligation just seen from two angles.
The parts most firms leave out
Beyond those, a few positions come up only once a firm has lived with AI for a while, which is exactly why they’re worth taking from the start.

Billing and recorded time

If a tool does in ten minutes what used to take three hours, how is that billed and recorded? It’s a genuinely unsettled question, and clients are starting to ask it. A policy that takes a clear position (even a provisional one), spares every fee earner from improvising their own answer.

The client who says no

Some clients restrict or prohibit AI in their own engagement terms or outside counsel guidelines. A policy should tell fee earners to check the client’s position, not just the firm’s approved list, because the client’s instruction binds regardless of what the firm permits.

Third-party and counterparty information

The confidentiality duty runs beyond your own client – material under an undertaking, a confidentiality ring, or an NDA carries obligations a general “don’t share client data” line doesn’t obviously cover.

The AI nobody chose

Note-takers on calls, transcription, features folded into email and the document system – a policy that only addresses tools people deliberately open misses the ones that arrive switched on.
Why this policy dates faster than all your other ones
Your conflicts or AML policies can sit for a year between reviews without much drift.

An AI policy can’t – the tools it governs change monthly, and a document that named a specific product or assumed a particular landscape can be out of date within weeks of circulation.

Keep it short and current rather than exhaustive and frozen – with AI, an out-of-date policy is arguably worse than none, because people follow it.

The one maintenance point worth building in from the start is a shorter half-life: a named review cadence measured in months, not years, and a document lean enough that revising it isn’t a project. Keep it short and current rather than exhaustive and frozen – with AI, an out-of-date policy is arguably worse than none, because people follow it.

Who should own it

A policy owned by everyone is owned by no one.

The SRA expects the COLP to be responsible for regulatory compliance when new technology is introduced, which makes the COLP the natural home, though the day-to-day can sit with whoever holds risk or operations, provided the accountability is clear.

A policy owned by everyone is owned by no one.

The owner’s job isn’t to write every line or make every call. It’s to be the point where it connects: the person who can say what the current position is, keep the approved list moving, and decide the judgement calls the policy can’t fully anticipate.

A named owner is also what turns the review cadence from a good intention into something that actually happens.

Beyond The Hype
A starting point you can make your own ​
You don’t need to write an AI policy from a blank page.
We’ve built a template that covers the decisions – the confidentiality line, verification, keeping the approved list current, client transparency, the data-protection link, billing and the parts firms forget. All written for a UK firm to adapt rather than adopt wholesale, and short enough that people will actually read the end result.
AI Policy Cover
We’ve built a template that covers the decisions – the confidentiality line, verification, keeping the approved list current, client transparency, the data-protection link, billing and the parts firms forget. All written for a UK firm to adapt rather than adopt wholesale, and short enough that people will actually read the end result.
Rising Tide AI
Where Rising Tide AI Fits
We build AI tools for UK law firms, so we spend a lot of time on the practical side of this – helping firms work out which tools to sanction, and how to put governance around them without grinding adoption to a halt. If that’s the stage you’re at, we’re glad to talk it through.
FAQs
Governing AI in Your Firm
Do we need a standalone AI policy, or can we fold it into existing ones?
Either works. A standalone policy gives AI a clear, visible home while it’s still novel; folding it into your information security, supervision and data protection policies avoids sprawl and keeps it alongside related controls. Many firms start standalone for clarity and integrate later. What matters is that the decisions are written down somewhere findable.
There’s no standalone rule requiring one, but the SRA expects firms to have documented policies, oversight, risk assessment, training and monitoring around AI, with the COLP responsible when new technology is introduced. A policy is how you evidence that, so while it isn’t a tick-box obligation, being without one is hard to defend.
They’re closely linked. Where AI processes personal data, your existing data-protection machinery applies – a DPIA before high-risk processing, reviewed by the DPO. A good AI policy points at that process rather than duplicating it, treating AI governance and data-protection compliance as the same obligation from two angles.
It rarely works. A blanket ban tends to push usage onto personal accounts and out of sight, which is the exact exposure it was meant to prevent. A clear permission framework actually gives you more control than a prohibition.
It’s an unsettled area, and clients are beginning to ask. Rather than leave each fee earner to decide, a policy should take a clear position on how AI-assisted time is recorded and billed.