Blog
What should a small law firm's AI policy actually say?
A workable AI policy names the tools people may use, the work they may use them for, what must never be pasted into a general tool, and who checks the output before it leaves the firm.
Alesis · · 5 min read
An AI policy for a firm of four to fifty fee earners does not need to be long. It needs to answer four questions: which tools are approved, what work they may be used for, what information may never go into an unapproved tool, and who is accountable for checking the output. Everything else is commentary.
Start with the obligations you already have
You are not writing on a blank page. Your existing duties on competence, supervision, confidentiality and client care already cover most of what an AI policy needs to say. The Solicitors Regulation Authority expects work to be supervised and services to be competent, whatever tools are used to produce them. UK GDPR and the Information Commissioner's Office expectations already govern what happens to personal data. The Legal Ombudsman still looks at the service the client received.
So the policy's job is narrow: to apply obligations you already have to a new category of tool, and to remove the ambiguity that leads people to improvise. If your file closing procedure or your outsourcing policy already covers part of the ground, point at it rather than rewriting it.
The decisions the policy has to make
Be specific. A policy that says "staff should use AI responsibly" tells nobody anything.
- Approved tools. Name them. If a tool is not on the list, it is not approved, including free consumer tools and anything bundled into software the firm already pays for. Say who can add to the list and what they must check first.
- Approved uses. Distinguish between work that never touches client information (drafting an internal note, summarising a public article) and work that does (reviewing a matter file, checking a date, drafting a letter). The controls differ.
- Client information. State plainly what must never be pasted into an unapproved tool: client names, case papers, correspondence, anything from which a client or matter could be identified. Anonymising is harder than people think in a small jurisdiction with distinctive facts, so do not treat it as a safe default.
- Checking and sign-off. Say that output is a draft until a named person with the relevant competence has checked it, and that the check includes verifying every source and every figure against the underlying document or the official text. Say who signs off in each team.
- Client consent and disclosure. Set out when the firm tells a client, and where that is recorded. Check your client care letters and any client-imposed conditions in panel or retainer terms.
- Records. Say what goes on the file: which tool was used, for what, and who checked it. This is what protects the fee earner if the work is questioned two years later.
Write it so people can follow it under pressure
Most policy failures are not defiance. They are a fee earner at six o'clock with a hearing in the morning, reaching for whatever is to hand.
Three things reduce that risk. First, give people an approved tool that is good enough for the work they actually do, or they will find their own. Second, keep the rules short enough to remember without opening a document: two or three sentences that a paralegal can recite. Third, make the approved route faster than the unapproved one for the tasks people do most.
Avoid absolute bans you cannot enforce. A blanket prohibition that everyone quietly ignores is worse than a permission with conditions, because you lose all visibility of what is happening.
Cover supervision, not just tools
The supervision questions matter more than the technology questions. Ask them explicitly in the policy:
- Can a junior use an AI tool on work that will not be reviewed line by line? If the answer is no, say so.
- Does the supervisor need to know a tool was used? In most firms the answer is yes, and it should be visible on the file rather than mentioned in passing.
- What happens when the tool and the fee earner disagree? The fee earner's judgement governs, and if they cannot resolve the point they escalate rather than pick the answer they prefer.
- How does a trainee or paralegal build judgement if a tool produces a first draft? Someone senior needs to think about this deliberately, because it will not resolve itself.
Review it, and keep the evidence
Date the policy and set a review point. Record who approved it and when staff were trained on it. If something goes wrong, the question will be what the firm had in place and whether it was followed, so keep the training register and the file records where a reviewer or an insurer can find them.
One short policy, genuinely applied, is worth more than a comprehensive one nobody has read.
Where Alesis fits
Alesis is an AI assistant for UK law firms, made by L25 Limited, used through the web browser with one conversation for a matter. It prepares drafts for a qualified person to review and sign off; it does not file, serve or email anything. The firm's information is held and processed in the UK, kept apart from every other firm, and never used to train anything for anyone else, and inside a firm people see only the matters they are on. It assists qualified professionals and does not replace them, and it does not provide legal advice.