Legal Team Generative AI Use Policy Drafter
When your firm or legal department is adopting AI tools, or already using them informally, and needs a written policy that people can follow and that maps to the ethics guidance.
Most legal teams are already using generative AI in some form, often without anyone having decided which tools are allowed, what can be pasted into them or who checks the output. That gap is an ethics problem as much as an operational one. ABA Formal Opinion 512 frames lawyers' use of generative AI around existing duties such as competence, confidentiality, client communication, supervision, candor and reasonable fees, and a written policy is the most practical way to show your team is meeting them.
This prompt drafts that policy from your actual setup: the tools you use and their data terms, any client restrictions and whatever state bar guidance you paste. It organizes the policy around the Opinion 512 themes and covers approved tools, prohibited inputs, verification of citations and facts, client disclosure and consent with a short engagement-letter clause, court disclosure checks, supervision, billing and incident reporting. It quotes the guidance it relies on and marks every other jurisdiction-specific point for confirmation.
A policy drafted from general principles is a starting point, not a compliance determination. State bars have issued their own guidance, courts keep adding standing orders, and your clients may impose stricter terms in their guidelines. Claude should not be trusted to recall any of these accurately, which is why the prompt relies only on what you paste. The lawyer responsible for ethics compliance should review, adapt and approve the final policy, and the output is a draft for attorney review.
The Prompt
Draft a generative AI use policy for [FIRM OR LEGAL DEPARTMENT NAME], a [DESCRIBE: e.g. litigation firm / in-house legal department of a software company] practicing in [JURISDICTION]. <document name="state_bar_guidance"> [PASTE STATE BAR GUIDANCE, ETHICS OPINIONS OR COURT RULES ON AI THAT APPLY TO US, OR WRITE "NONE PROVIDED"] </document> <document name="current_practices"> [DESCRIBE: TOOLS IN USE AND THEIR DATA TERMS, WHO USES THEM, CLIENT REQUIREMENTS ABOUT AI, EXISTING CONFIDENTIALITY OR IT POLICIES] </document> Organize the policy around the themes of ABA Formal Opinion 512: competence, confidentiality, communication with clients, supervision of lawyers and nonlawyers, candor and meritorious filings, and fees. Include these sections: 1. Purpose and scope (who and what the policy covers). 2. Approved tools and the approval process for new tools. 3. Prohibited and restricted inputs (client confidential information in unapproved tools, personal data, material under protective order, client-prohibited uses). 4. Verification requirements: every citation, quotation and factual statement checked against the source before use; who signs off. 5. Client communication and consent: when disclosure or informed consent is needed, and a short engagement-letter AI clause. 6. Court filings: checking standing orders and local rules on AI disclosure before filing. 7. Supervision and training. 8. Billing for AI-assisted work. 9. Incident reporting and policy review. Rules: do not state what any specific state's rules require unless it appears in the pasted guidance; quote the guidance you rely on and mark everything else [CONFIRM UNDER STATE BAR GUIDANCE]. Do not describe the contents of ABA Formal Opinion 512 beyond its theme headings unless I paste it. Use short numbered paragraphs that people will actually read. After the policy, list open decisions for leadership and any conflicts between the pasted guidance and our current practices. This is a draft for attorney review.
Example Output
A numbered policy organized around the ABA Formal Opinion 512 themes with approved tools, prohibited inputs, verification steps, a client-disclosure clause and billing rules, followed by open decisions for leadership.
Illustrative example — names, figures, and facts are fictional.
GENERATIVE AI USE POLICY (DRAFT FOR ATTORNEY REVIEW) Fennimore & Clay LLP | Litigation practice | [JURISDICTION] 1. PURPOSE AND SCOPE 1.1 This policy applies to all lawyers, paralegals and staff who use generative AI tools for firm or client work. 1.2 It is organized around the themes of ABA Formal Opinion 512: competence, confidentiality, client communication, supervision, candor and fees. 2. APPROVED TOOLS 2.1 Approved: [TOOL NAME] under the firm's business plan, whose terms state inputs are not used for model training (per current_practices). 2.2 Personal or free accounts may not be used for client work. 2.3 New tools require approval from the Technology Committee after review of data terms. 3. PROHIBITED AND RESTRICTED INPUTS 3.1 No client confidential information in any unapproved tool. 3.2 No material covered by a protective order without confirming the order permits it. 3.3 Clients whose guidelines prohibit AI use (currently: "Client B outside counsel guidelines, Sec. 12") are excluded entirely. 4. VERIFICATION 4.1 Every citation, quotation and factual assertion in AI-assisted work must be checked against the original source before it is sent or filed. 4.2 The signing attorney confirms verification in the filing checklist. 5. CLIENT COMMUNICATION 5.1 Engagement letter clause: "We may use secure generative AI tools to assist with tasks such as drafting and document review. A lawyer reviews all work product, and we do not use tools that train on your information." [CONFIRM UNDER STATE BAR GUIDANCE whether informed consent is required for any use.] 6. COURT FILINGS 6.1 Before filing, check the assigned judge's standing orders and local rules for AI disclosure or certification requirements. [Section 7, Supervision and Training, omitted from this excerpt.] 8. BILLING 8.1 Bill for the lawyer time actually spent, including review. Do not bill for time saved. [CONFIRM UNDER STATE BAR GUIDANCE] [Section 9, Incident Reporting and Policy Review, omitted from this excerpt.] OPEN DECISIONS FOR LEADERSHIP - Whether to require client consent for all AI use or only for specified tasks. - Who owns the approved-tools list. CONFLICTS NOTED - current_practices says associates use a free chatbot account for research; section 2.2 would prohibit this.
Tips
- •Paste your state bar's AI guidance if it exists. The policy should quote it rather than rely on Claude's memory of a fast-changing area.
- •Paste the actual data terms of the tools you use. The approved-tools and prohibited-inputs sections depend on whether a tool retains or trains on inputs.
- •Keep the verification section concrete: who checks citations, against what source and how it is recorded. Vague verification rules are the ones that fail.
- •Revisit the policy on a schedule. Ethics guidance, court orders and tool terms change, and a policy that names last year's tools invites workarounds.
- •Have the final policy reviewed by the lawyer responsible for ethics compliance. The output is a draft for attorney review, and any cited rule or opinion must be verified.
Frequently Asked Questions
What does ABA Formal Opinion 512 cover?
Issued in 2024, it addresses lawyers' use of generative AI tools under existing Model Rules, organized around competence, confidentiality, communication with clients, candor toward tribunals and meritorious claims, supervision, and fees. ABA ethics opinions are advisory and do not bind any state, so the prompt uses its themes as the policy's structure and relies on the state guidance you paste for jurisdiction-specific requirements. Read the opinion itself before finalizing the policy.
Does the policy need an engagement letter clause?
Many firms add one so clients know AI tools may be used and how their information is protected. Whether disclosure or informed consent is required depends on the tool, the task, the information involved and your jurisdiction's guidance. The prompt drafts a short clause and marks the consent question for confirmation rather than asserting a rule that may not apply to you.
Can in-house legal departments use this prompt?
Yes. Describe the department in the first line and paste the company's existing IT, data and confidentiality policies in the current practices block. The structure stays the same, but the client communication section will focus on internal business clients and the company's own data rules, and billing will usually be replaced with guidance on charging back or tracking time saved.
How specific should the approved-tools section be?
Specific enough that a new associate knows exactly which account to use and which never to use. Name the approved tools and plans, state why they were approved (for example, data terms that exclude training on inputs) and name who approves new tools. Vague language like "secure tools only" leaves everyone to make their own judgment, which is the problem the policy is meant to solve.
Related Prompts
Get New Prompts Like This Every Week
Join the free Claude for Lawyers newsletter — weekly prompts, tutorials, and practice-specific guides.