← All workflows

Workflow · September 4, 2026

Draft a Client-Facing AI Use Policy for Your Firm in 30 Minutes

✓ TestedLegalFor Legal
Time saved3-4 hours per policy draft

The task

When a client's GC sends the "tell us about your AI use" email — usually attached to an outside counsel guideline update — someone at the firm has to produce a coherent, defensible written response fast. This workflow is for the partner or knowledge-management lawyer who owns that response and doesn't want to spend a Saturday on it. Above the Law flagged the underlying question: what should the response framework actually contain?

Before AI

Today this usually means pulling three or four peer-firm policies from a shared folder, re-reading ABA Formal Opinion 512 and the applicable state bar guidance, and stitching together a Word doc that survives a partner review. Realistically, four to six hours over two sittings — longer if the client sent a questionnaire with specific asks about tool inventory, training data, or human review.

The workflow

1. Extract what the client is actually asking for.

Drop the client's inbound email or OCG excerpt in as the sample input. The prompt below pulls out the specific commitments they want you to make — so you draft against real asks, not a generic template.

Prompt
You are helping a law firm respond to a client's request about the firm's use of generative AI. Below is the inbound message from the client. 

Extract and list, as a structured checklist:
1. Every explicit commitment or disclosure the client is asking the firm to make (verbatim quotes where possible).
2. Every implicit expectation you can reasonably infer (label these clearly as "inferred").
3. Any specific tools, vendors, or use cases the client names.
4. Any hard prohibitions (e.g., "no client data in public LLMs").
5. Deadline or response format if stated.

Be exhaustive but concise. Use short bullets. Do not draft a response yet.

CLIENT MESSAGE:
Sample input
From: Priya Ramaswamy, Deputy General Counsel, Meridian Rowe Industries
To: [Relationship Partner]
Subject: Updated Outside Counsel Guidelines — AI Addendum, response requested by Sept 30

Counsel,

As part of our 2026 OCG refresh, Meridian Rowe is asking all outside firms to complete the attached AI disclosure. Key items we need in writing:

1. A list of the generative AI tools your firm currently uses on Meridian Rowe matters, including the vendor, hosting model (tenant-isolated vs. shared), and whether prompts/outputs are used to train third-party models.
2. Confirmation that no Meridian Rowe confidential information, work product, or personally identifiable information will be entered into any public or consumer-tier AI tool (ChatGPT free/Plus, Gemini consumer, Claude.ai free, etc.).
3. Your firm's human-review protocol before AI-assisted work product is delivered to us — specifically for research memos, contract redlines, and deposition summaries.
4. Whether AI-assisted time is billed at the same rate as attorney time, and how you handle efficiency gains.
5. Your breach notification commitment if a prompt containing our information is inadvertently sent to a non-approved tool.

We are not asking firms to stop using AI. We are asking for transparency and a clear allocation of risk. Please respond by September 30. A 2-3 page policy statement is sufficient; we do not need a full questionnaire.

Thanks,
Priya

2. Pressure-test the ask against ethics guardrails.

Before drafting, map each client ask to the relevant duty. This is where you catch the ask that quietly demands something you can't ethically promise (e.g., a blanket waiver of privilege review, or a billing commitment that conflicts with your engagement letter).

Prompt
For each item in the checklist above, do three things:

A. Map it to the relevant professional-responsibility duty (confidentiality under Model Rule 1.6, competence under 1.1, communication under 1.4, supervision under 5.1/5.3, or fees under 1.5). Reference ABA Formal Opinion 512's framework where it applies.

B. Flag any ask the firm should NOT agree to as drafted, and explain why in one sentence (e.g., conflicts with the engagement letter, unenforceable across co-counsel, or promises something no vendor contract can guarantee).

C. Suggest the safer counter-formulation the firm should offer instead.

Output as a three-column table: Client Ask | Duty & Risk | Recommended Response Position.

3. Draft the client-facing policy statement.

Now generate the actual document. Keep it in the voice of a firm memo, not marketing copy.

Prompt
Draft a 2-3 page client-facing AI Use Policy Statement addressed to the client, using the Recommended Response Positions from the table above. 

Structure:
- Opening paragraph: firm's overall posture on generative AI (one paragraph, no hedging, no marketing language).
- Section 1: Approved tools and hosting model. Use a table with columns: Tool | Vendor | Hosting | Training on our data? | Approved use cases.
- Section 2: Data handling — what does and does not go into any AI tool. Be specific about tiers (public consumer tools vs. enterprise tenant-isolated deployments).
- Section 3: Human review protocol, broken out by work product type (research memos, contract redlines, deposition summaries, correspondence).
- Section 4: Billing treatment of AI-assisted time, referencing the engagement letter.
- Section 5: Incident and breach notification commitment, with a specific notification window.
- Closing: named point of contact at the firm for AI questions.

Where a specific fact is firm-dependent (tool names, notification windows, contact person), insert a bracketed placeholder like [FIRM TO CONFIRM: notification window, suggest 72 hours]. Do not invent firm-specific facts.

Tone: sober, plain English, no adjectives like "cutting-edge" or "robust." Write it the way a general counsel would want to read it.

4. Generate a partner-review redline checklist.

The last step is the one people skip. Ask the model to attack its own draft the way a skeptical partner would — so you walk into the review meeting with the objections pre-answered.

Prompt
You are now a skeptical senior partner reviewing the draft policy statement above before it goes to the client. Produce a redline checklist:

1. Every sentence that overpromises or that the firm cannot actually enforce across all matter teams.
2. Every sentence that could be read as waiving privilege, admitting a duty the firm doesn't owe, or creating a contractual obligation beyond the engagement letter.
3. Every bracketed placeholder that the responsible partner must fill before sending.
4. Two or three questions the client is likely to ask in follow-up, and a suggested one-line answer for each.

Keep the checklist to one page.

Gotchas

  • State bar variation is real. The workflow leans on the ABA Model Rules and Opinion 512 framing. If you practice in California, New York, Florida, or a jurisdiction with its own AI opinion, add a step that cross-checks against local guidance — Justia's 50-state ethics survey is a decent starting point.
  • Tool inventory drift. The draft is only as accurate as the tool list you feed it (or that the reviewing partner fills into the brackets). If your firm has shadow-IT AI use — associates on personal ChatGPT accounts — a policy that says "we don't do that" is worse than no policy. Run the inventory question through IT before the client sees the document.
  • Don't send the draft to the client-facing AI tool that trains on prompts. Obvious, but worth saying. Use an enterprise deployment with a no-training data processing agreement. A public-model prompt containing a client's OCG ask is itself the confidentiality problem you're trying to solve — and there is now at least one ruling treating public-tool exposure as a privilege waiver.
  • The billing section is where deals get made. Model output will default to "AI-assisted time billed at standard rates." Your firm may have already agreed to something different with this client. Check the engagement letter before you send.
  • This is a draft, not a filing. Partner sign-off, conflicts check on the client's named tools, and a read from your GC or ethics counsel are non-negotiable before this goes out the door.

Time saved

Conservative estimate: 3-4 hours per policy draft. Baseline is 4-6 hours of drafting plus review; the workflow gets you to a partner-ready draft in about 30 minutes, leaving the review cycle roughly the same. The saving compounds if the firm is fielding these requests from multiple clients in a quarter — the Step 2 duty-mapping table is reusable across clients with light edits.

What we got when we ran it

We executed every prompt above, in order, against the sample input (model: claude-sonnet-4-6). Outputs below are real and unedited apart from length truncation.

Step 1 output

Structured Checklist: Meridian Rowe AI Addendum Request --- ### 1. Explicit Commitments / Disclosures Requested (verbatim or near-verbatim) - **AI Tool Inventory:** "A list of the generative AI tools your firm currently uses on Meridian Rowe matters, including the vendor, hosting model (tenant-isolated vs. shared), and whether prompts/outputs are used to train third-party models." - **Data Prohibition Confirmation:** "Confirmation that no Meridian Rowe confidential information, work product, or personally identifiable information will be entered into any public or consumer-tier AI tool." - **Human-Review Protocol:** "Your firm's human-review protocol before AI-assisted work product is delivered to us — specifically for research memos, contract redlines, and deposition summaries." - **Billing Disclosure:** "Whether AI-assisted time is billed at the same rate as attorney time, and how you handle efficiency gains." - **Breach Notification Commitment:** "Your breach notification commitment if a prompt containing our information is inadvertently sent to a non-approved tool." --- ### 2. Implicit / Inferred Expectations - **[Inferred]** The firm should have a documented, firm-wide AI governance policy already in place — not create one ad hoc in response to this request. - **[Inferred]** Approved tools should be enterprise/professional-tier with contractual data protections (i.e., not consumer-grade products). - **[Inferred]** The firm should be able to identify which specific matters or matter types AI has touched — implying some logging or tracking capability. - **[Inferred]** Human review is expected to be substantive, not perfunctory — a named attorney or supervising timekeeper should be accountable. - **[Inferred]** Efficiency gains from AI should

…output truncated at 250 words.

Step 2 output

# AI Addendum: Professional Responsibility Mapping & Response Positioning --- | Client Ask | Duty & Risk | Recommended Response Position | |---|---|---| | 1. List all GenAI tools used on Meridian Rowe matters (vendor, hosting model, training use) | Duty: Competence (MR 1.1) — lawyers must understand technology used in representation. Communication (MR 1.4) — client entitled to information material to the representation. ABA 512: Firms must evaluate whether a tool is appropriate before use; disclosure of tool characteristics is part of that competence obligation. Flag: ⚠️ "Currently uses" is a static snapshot — agreeing to a one-time list without a refresh mechanism creates a false assurance as the firm's tech stack evolves. | Agree to disclose current approved tools at time of response, with a commitment to notify Meridian Rowe within [30] days of adopting any new tool used on their matters, rather than promising a permanently exhaustive static list. | | 2. Confirmation no MRI confidential info / work product / PII entered into public or consumer-tier AI tools | Duty: Confidentiality (MR 1.6) — firm may not voluntarily disclose client information. Competence (MR 1.1) — requires understanding of how each tool handles data. ABA 512: Firms must take reasonable precautions against unauthorized disclosure; using a consumer-tier tool with no data-isolation guarantee is a per se risk. Flag: ⚠️ Blanket confirmation is problematic if the firm cannot technically enforce this across all timekeepers, contract attorneys, or co-counsel on the matter. An unqualified promise may be unenforceable and

…output truncated at 250 words.

Step 3 output

# Artificial Intelligence Use Policy Statement Prepared for: Meridian Rowe Industries Prepared by: [FIRM NAME] Date: [DATE] Contact: [AI GOVERNANCE CONTACT NAME, TITLE, EMAIL, DIRECT PHONE] --- ## Opening This statement describes how [FIRM NAME] uses generative AI tools on client matters, including those of Meridian Rowe Industries ("Meridian Rowe"). We use these tools on certain matters to improve accuracy, consistency, and efficiency. We do not use them as a substitute for attorney judgment, and every work product delivered to Meridian Rowe reflects the professional responsibility of a named supervising attorney at this firm. This statement is current as of [DATE] and will be updated annually each [MONTH], or within 30 days of any material change to the tools or practices described here. --- ## Section 1: Approved Tools and Hosting Model The following table lists every generative AI tool currently approved for use on Meridian Rowe matters. No tool outside this list may be used by firm personnel on Meridian Rowe matters. | Tool | Vendor | Hosting Model | Prompts/Outputs Used to Train Third-Party Models? | Approved Use Cases on Meridian Rowe Matters | |---|---|---|---|---| | [TOOL NAME] | [VENDOR] | [FIRM TO CONFIRM: e.g., tenant-isolated enterprise deployment / private cloud / on-premises] | [FIRM TO CONFIRM: Yes / No — cite vendor DPA or terms] | [FIRM TO CONFIRM: e.g., legal research, contract review, summarization] | | [TOOL NAME] | [VENDOR] | [FIRM TO CONFIRM] | [FIRM TO CONFIRM] | [FIRM TO CONFIRM] | | [TOOL NAME]

…output truncated at 250 words.

Step 4 output

# Senior Partner Redline Checklist Document: AI Use Policy Statement — Meridian Rowe Industries Reviewer: [SENIOR PARTNER NAME] Status: DO NOT SEND until all items below are resolved. --- ## 1. Overpromises / Unenforceable Commitments - Opening, sentence 3: "every work product delivered to Meridian Rowe reflects the professional responsibility of a named supervising attorney" — "named" creates a traceable accountability record the firm may not consistently maintain; change to "a supervising attorney" and remove "named." - Section 2, consumer-tier prohibition: "No Meridian Rowe information of any kind will be entered into any AI tool" — "of any kind" is absolute and unenforceable across lateral hires, contract attorneys, and after-hours remote work; add "firm personnel are prohibited from" and qualify with "in accordance with firm policy and training requirements." - Section 2, third-party/vendor paragraph: "the firm will flow down these data handling requirements as a condition of engagement" — enforceable only if vendor contracts are actually amended; confirm with procurement before sending or soften to "will use reasonable contractual efforts to flow down." - Section 3, Research Memoranda: "independently verifies all cited authorities for accuracy, currency, and correct characterization" — "all" and "independently" together set a standard of care the firm may not meet on every matter; change to "reviews and verifies AI-generated citations before delivery." - Section 3, Deposition Summaries: "reviewed against the underlying transcript for accuracy and completeness" — "completeness" is a near-absolute standard; remove "completeness" or qualify as "material completeness." - Section 5, Notification Content (a): "a

…output truncated at 250 words.

---

This content is for informational purposes only and is not legal advice. Confirm confidentiality, privilege, and jurisdictional rules before using any AI tool with client matters.

Source: abovethelaw.com

More for Legal professionals →

Get the next one in your inbox

One daily brief. Every story gets a hype verdict.

No spam. Unsubscribe anytime.

Exact prompts included · Untested steps are marked · Corrections are public