MatterLayer / Field note
Policy and controlsA law-firm AI policy needs more than a ban
A policy that only prohibits public AI tools leaves staff without a safe path for legitimate use and gives leaders little evidence about behavior. Effective policy connects principles to approved workflows, technical controls, review and exceptions.
Describe allowed work, not only prohibited tools
Begin with purposes and data, because the same product may support workflows with very different risk. Define approved low-risk uses, uses requiring matter or governance approval and prohibited handling. Give concrete examples of client information, confidential or privileged material, legal research, drafting, administrative support and client-facing output, while recognising that the applicable duties vary by jurisdiction and matter. Victorian and Queensland guidance provides important jurisdiction-specific direction on practitioner responsibilities, confidentiality, verification and provider terms; firms should also consider rules, court guidance and client obligations relevant to their work. A policy should not imply that choosing an approved tool transfers accountability to the vendor. Nor should it imply that all AI is forbidden if the firm intends to permit bounded uses. People need a clear route to request a new workflow instead of working around an unrealistic rule.
Bind approval to a workflow and configuration
An approved product name is too broad. Record the users, matter cohort, input categories, output, purpose, model or feature where relevant, provider settings, retention, integrations and required review. Technical controls can reinforce the decision through identity, least privilege, blocked public accounts, data-loss prevention, approved connectors, logging and disabled training or sharing features where available. Controls must be tested rather than assumed from marketing labels. The policy should identify who can change a configuration and which changes trigger reassessment, such as a new subprocesser, data location, model behavior or client-facing capability. Australian Government AI safety and adoption resources are voluntary governance aids and do not themselves establish a general private-sector AI law. Use them to structure accountability and risk management while analysing the existing law and professional obligations that apply to the firm.
Make verification and transparency observable
Tell users what review means for each workflow. Legal research may require every authority to be opened in an authoritative source and checked for currency and the proposition asserted. A draft may require fact, instruction, recipient, confidentiality and tone checks. An operational indicator may require opening the source matter and recording a disposition. Define whether and how AI use should be disclosed to a client, court or other party based on applicable requirements and the matter; avoid a universal statement. Training should let staff practise identifying unsafe inputs, hallucinated material, missing context and escalation triggers. Supervisors need evidence that the process is being followed, but monitoring should be proportionate and respectful of matter confidentiality. A checkbox is not proof of substantive verification. The workflow should retain enough context to show who reviewed what and when.
Create a governed exception and review cycle
A practical policy expects new use cases and unusual matters. Provide an exception request that captures purpose, data, urgency, provider, reviewer and proposed safeguards. A qualified owner can approve, narrow or refuse the request and retain the reasons. Emergency or time pressure should not convert uncertainty into silent permission. Define how suspected policy breaches, insecure handling, inaccurate outputs and cyber incidents are triaged; not every event is a notifiable data breach, and classification requires the relevant assessment. Review the policy on a schedule and when providers, law, professional guidance or firm services change. Use incident patterns, questions and Pilot dispositions to improve both policy and technical controls. The goal is not a document that claims risk has been eliminated. It is a living operating system that helps people choose approved paths, stop when the boundary is unclear and keep professional accountability visible.
Source file
Primary reading
- 01Statement on the use of artificial intelligence in Australian legal practice
Victorian Legal Services Board and Commissioner
- 02Guidance Statement No. 37: Artificial Intelligence in Legal Practice
Queensland Law Society
- 03Australian Solicitors' Conduct Rules
Law Council of Australia
- 04The legal landscape for AI in Australia
Australian Department of Industry, Science and Resources