top of page

AI Governance for Small Law Firms: What Happens When Your Employees Are Already Using AI

  • Writer: Shay
    Shay
  • 1 day ago
  • 14 min read

A managing partner may tell me the firm isn't using AI because nobody has purchased Microsoft Copilot or signed a company agreement with an AI provider. My next question would be whether they are sure their employees aren't using it.


An attorney can have a personal ChatGPT account. A paralegal can find an AI tool that summarizes a long document in a few minutes. Someone in the office may have installed a browser extension because it helps with writing, while another employee may have found an AI service that saves them an hour every week. None of those things require the firm to formally adopt AI, approve a product or even know that it is being used.


That is the part of the AI conversation I think small law firms need to pay attention to. The decision about whether a firm is going to use AI may already be happening one employee and one account at a time, without anyone ever sitting down and deciding what the rules should be.


AI use among legal professionals has grown quickly, while many firms are still working through policies, training and oversight. I don't think that means law firms should be afraid of AI. I use AI in my own business and see a lot of value in it. What concerns me is when employees are using these tools for company work without knowing whether the firm has approved them, what happens to the information they put into them, or what they are expected to do with the answer they get back.


Is Your Law Firm Already Using AI Without Knowing It?

Before I would write an AI policy or recommend that a firm purchase another piece of software, I would want to find out what employees are already using and why. Some of those uses may be perfectly reasonable, while others may create concerns depending on the tool, the account being used and the information being given to it. I don't want to make that determination without understanding what is actually happening inside the firm.

I also don't think the best first response is necessarily to send an email tomorrow telling everyone that AI is banned. If employees have already found ways that AI makes their jobs easier, simply prohibiting it doesn't necessarily tell you whether they have stopped using it.

In some cases, it may only mean they stop talking about it.


I would rather bring the use out into the open, find out which tools people have found useful and what they are doing with them, and then make deliberate decisions about what the firm is comfortable allowing. There may be tools that make perfect sense for the business once they have been properly evaluated, and there may be others that the firm decides it does not want employees using at all.


Can Lawyers and Law Firm Employees Put Client Information Into AI?

This is one of the places where I think it is important to separate my role from the attorney's role. From the IT side, I can evaluate a particular AI service and look at how accounts are managed, what privacy and security controls are available, how the provider handles submitted information and whether there are administrative controls that make the service appropriate for business use. I can also help the firm put technical controls and procedures around the decisions it makes.


What I cannot do is decide an attorney's professional-responsibility obligations for them.

The American Bar Association addressed lawyers' use of generative AI in Formal Opinion 512. Among other things, the opinion discusses competence, protecting client information, communication with clients, supervision, candor and fees. It also makes an important point that applies to this entire conversation: attorneys do not have to become AI experts, but lawyers using these technologies need a reasonable understanding of the capabilities and limitations of the tools they are using.


From a practical standpoint, there is a big difference between an employee asking an AI tool to help come up with ideas for the firm's holiday party and uploading a document containing information related to a client's representation. If an employee is sitting in front of a long document and discovers that an AI tool can summarize it in a few minutes, I completely understand why that is attractive. Before the document gets uploaded, though, the firm should have already worked through the questions that employee is otherwise going to have to answer alone.


Is the tool approved? Is the employee using a personal account or an account controlled by the firm? What information is contained in the document? How does this particular service handle information submitted to it? Has the firm decided that this type of information can be used with this particular tool?

Those answers may be different depending on the product and what the employee is trying to do. What I don't want is an employee having to make that entire decision for the firm simply because they are trying to get through a long document faster.


What Is Shadow AI, and Why Does It Matter to a Law Firm?

You may hear the term shadow AI, which is really a newer version of a problem IT providers have dealt with for years. An employee finds a technology that helps them do their job and starts using it without going through whatever approval process the business normally uses. AI has made this especially easy because an employee often doesn't need IT to install anything. They can open a website, create an account or add a browser extension and start using it within minutes.


For me, the biggest problem with shadow AI is visibility. This is one of the reasons SNL-Tech Services starts with understanding what employees are actually using rather than immediately trying to block everything. I can't properly evaluate a technology nobody knows is being used, and the firm's leadership can't make an informed decision about a tool it doesn't know employees have adopted.


If several employees have independently discovered the same AI product because it solves a real problem for them, I want to know that. Maybe it is worth evaluating and formally approving. There may be a business version with better administrative controls, or perhaps the firm already owns another product that can accomplish the same thing. After reviewing it, we may also decide that it isn't something employees should be using for company work.

Any of those outcomes gives the firm more control than simply pretending the tool isn't there.


Can Lawyers Trust Information Generated by AI?

One of the things people learn fairly quickly when they start using AI regularly is that it can give you an answer that sounds extremely confident and still be wrong. The quality of the writing can make an answer feel more authoritative than it actually is because the response may be detailed, well organized and professionally written even when it contains a bad conclusion, an invented fact or something the system misunderstood.


For attorneys, the consequences of relying on incorrect information can obviously be much more serious than they are for someone using AI to plan a vacation or write a social media post. ABA Formal Opinion 512 addresses this directly. Lawyers remain responsible for their work and need an appropriate degree of independent verification or review rather than relying uncritically on AI-generated information.

I think the employee version of that can be explained pretty simply: an answer from AI is not automatically a verified answer.


How much review is appropriate for a particular legal task is something the attorneys need to determine. From the technology and governance side, I want the firm's expectations documented and I want employees to understand those expectations before AI becomes part of their everyday workflow.


Does a Small Law Firm Really Need an AI Policy?

I think it does, although when I say "AI policy," I am not talking about creating a giant corporate document that gets handed to employees once, signed and then stored somewhere nobody looks at again.


A useful policy should answer the questions employees are actually going to have while they are working. That is how I approach AI governance through SNL-Tech Services. I want the documentation to be something a small business can actually use, not something created simply so the business can say it has an AI policy.


If someone finds an AI tool tomorrow that would save them a considerable amount of time, they should know what they are supposed to do before they create an account and start using it. Depending on the firm, that may involve whoever handles IT, a managing partner or both, particularly if the tool is going to be used with client information.

The American Bar Association has also been addressing AI governance as part of the larger conversation around responsible AI use in legal practice, which makes having a defined process increasingly important rather than leaving individual employees to make these decisions on their own.


What I don't want is an employee thinking, Nobody has told me I can't use it, so I guess it is okay, creating a personal account and moving on. The policy needs to make sense to the people who are expected to follow it, because if an employee has to read six pages of policy language to figure out whether they can put a particular document into an AI tool, I don't think we have solved very much.


What Should an AI Policy for a Small Law Firm Actually Cover?

The exact policy will depend on the firm, the type of work it does and the decisions its attorneys make about their professional obligations, but there are some basic questions I think employees should be able to answer without having to hunt through a policy document:

  • Which AI tools has the firm approved?

  • Can those tools be used for client work, internal work or both?

  • What types of information should not be submitted to an AI tool?

  • Are employees allowed to use personal AI accounts for company work?

  • Who reviews and approves a new AI tool?

  • What review is expected before AI-generated information is used?

  • What should an employee do when they aren't sure?

I prefer company-managed accounts for approved business tools when that option makes sense. If someone leaves the firm, I want the business to know which systems that person was using and be able to remove their access. I don't want to find out during an offboarding that company or client information has been sitting in a personal account nobody knew existed.


Training is another piece of this. An employee can sign a policy and still not understand why a particular rule exists or recognize a situation where the rule applies. I would much rather have people understand what the firm is trying to protect and know who to ask when they are unsure than expect them to memorize a policy.


There is another reason firms should get ahead of this instead of waiting until there is a problem. The legal industry is moving toward greater scrutiny of how firms use AI, including how it is incorporated into client service and business processes. Recent ABA coverage of law firm RFPs, for example, shows AI becoming part of the information clients and legal departments consider when evaluating outside counsel.


A small firm may not be responding to a large corporate RFP today, but I think the direction this is going is fairly clear. Being able to explain how your firm handles AI is going to become more important, and “we don't really know what our employees are using” is not going to be a very comfortable answer.


What Happens When a Law Firm's Clients Are Using AI Too?

There is another part of this conversation that I don't think law firms can ignore forever. Their employees aren't the only people with access to ChatGPT, Claude, Gemini and other AI tools. Their clients have them too.


Imagine an attorney sends a client a detailed email about their matter. The client reads it, doesn't completely understand something and copies the email into an AI tool with a simple request to explain what their attorney is telling them in plain English. The firm didn't choose the AI service or control the account, but information from the attorney's communication has now been provided to another system.


Whether and how a law firm should address that with clients is a decision for the attorneys, not for me as their IT provider. I do think it illustrates how much the environment has changed. It used to be easier to think about information security in terms of the computers, networks and applications the business itself controlled. Today an employee or a client can move information into an entirely different service from a web browser in a matter of seconds.


I see AI governance as part of that larger information-management conversation rather than something that begins and ends with an AI policy.


Why SNL-Tech Services Created an AI Governance Kit for Small Businesses

I created the SNL-Tech Services AI Governance Kit because I kept seeing the same gap with small businesses. They knew AI was becoming part of the workplace, and many knew they probably needed some rules around it, but they weren't sure what those rules should look like or how to turn them into something employees could actually follow.

I would rather start with how the business actually operates and what employees are already doing. Once we understand which tools people are using, what the company wants to allow, what information it needs to protect and how new tools should be approved, those decisions can be documented in a way that actually makes sense for that business.


For a law firm, there is an additional piece because the attorneys need to determine the legal and professional-responsibility requirements that apply to their practice and jurisdiction. I am not replacing that analysis. My role is to help take the decisions the firm makes and build the technology and governance around them so employees have something practical to follow.


I don't see an AI Governance Kit as something that should be written once and forgotten. AI products are changing, the way businesses use them is changing, and the firm's own decisions may change as it becomes more comfortable with the technology. The documentation should be able to change along with that.


Should a Law Firm Review Microsoft 365 Before Deploying Copilot?

I would, because Microsoft 365 Copilot works within the access a user already has. If someone can already access information they should no longer have access to, introducing Copilot doesn't correct the underlying permission problem. Copilot respects the existing Microsoft 365 permissions and security boundaries, which makes the condition of those permissions important before a broader rollout.


Consider an employee who changed roles three years ago but still has access to an old SharePoint site. Maybe a site was shared broadly during a project and nobody went back later to clean up the permissions, or perhaps access accumulated gradually as employees and responsibilities changed. That access existed before Copilot, but AI can make finding information considerably easier, which gives me another reason to want those permissions reviewed.


Microsoft has also been building tools around this problem. Restricted Content Discovery can temporarily limit how content from selected SharePoint sites appears in organization-wide search and Microsoft 365 Copilot while permissions and governance are being reviewed. It does not change the underlying permissions, which is an important distinction. Someone who already has access to the content can still access it.


This is also a good example of why Microsoft 365 needs ongoing attention. Microsoft changes features, replaces older approaches and introduces new security and governance capabilities as the platform evolves. A small law firm shouldn't be expected to keep track of every Microsoft change like that. It is part of what I am supposed to be paying attention to when I am helping manage their technology.


How Can a Microsoft 365 Audit Help Before a Copilot Rollout?

This is one of the reasons SNL-Tech Services offers a Microsoft 365 Audit. If a firm is considering Copilot but isn't completely sure what its Microsoft 365 environment looks like today, I can review the environment and identify areas that may need attention before another layer of technology is added.


That could mean finding SharePoint permissions that need to be cleaned up, access that is broader than anyone realized, or other Microsoft 365 configurations that should be addressed first. I don't see that as a reason to be afraid of Copilot; I see it as getting the foundation right before we build on top of it.


I cover Microsoft 365 security and configuration drift in more detail in Cybersecurity for Small Law Firms: Microsoft 365 and Business Email Compromise.


Where Should a Small Law Firm Start With AI Governance?

If a small law firm called me tomorrow and said, “We need an AI policy,” I wouldn't start by opening a Word document and writing one. I would start with a conversation about what is already happening, because a policy written without understanding how people are actually using AI is likely to miss the problem we are trying to solve.


I would want to know what AI tools employees are already using and what they are using them for, whether people are creating personal accounts for company work, whether documents are being uploaded, whether anyone has installed AI browser extensions and whether the firm has ever formally approved any of those tools. There may be some surprises in that conversation, and that's okay. The point is to establish where the firm actually is before deciding where it should go.


The attorneys can then determine the legal and professional-responsibility requirements that apply to their practice. From there, I can help with the technology side, governance, approved tools, account management, Microsoft 365 considerations and the documentation employees need so they aren't making these decisions on their own.

I don't think the goal should be to make employees afraid to use AI. Used appropriately, these tools can save time and make people more productive. I want the business to be the one deciding how AI is used inside the business, rather than finding out after the fact that everyone has been making those decisions for themselves.


If the managing partner doesn't know which AI tools employees are using, employees don't know what information they are allowed to put into them, or nobody knows what happens when someone wants to try a new AI product, those are good places to start.


Frequently Asked Questions About AI in Small Law Firms

Can lawyers use ChatGPT or other generative AI tools for legal work?

Generative AI can be used in legal practice, but attorneys need to consider the particular tool, what it is being used for, what information is being submitted and the professional obligations that apply. ABA Formal Opinion 512 provides guidance involving competence, confidentiality, client communication, supervision, candor and fees.


Does a lawyer have to tell a client when AI is being used?

Not necessarily in every circumstance. ABA Formal Opinion 512 explains that the answer depends on how the technology is being used and the circumstances of the representation. Attorneys should evaluate the professional rules and guidance applicable to their practice and jurisdiction, particularly when information relating to a representation may be provided to an AI tool.


Should law firm employees use personal ChatGPT or other personal AI accounts for work?

For approved business tools, I generally prefer company-managed accounts when they are available and appropriate. That gives the firm more control over access and offboarding and provides better visibility into which services are being used for company work. Whether a particular AI product is appropriate for client information is a separate question that should be evaluated before it is approved.


Who should approve new AI tools in a law firm?

That will depend on the size and structure of the firm. I think the important part is having a process established before an employee needs it. The technology may need to be evaluated from an IT and security standpoint, while the attorneys need to address any legal or professional-responsibility issues associated with the way the firm intends to use it.


How often should a law firm review its AI policy?

I would not treat an AI policy as a document that is written once and forgotten. AI products and their capabilities are changing quickly, employees will find new uses for them, and the firm's own requirements may change. A significant new tool or a new way of using AI should be a reason to revisit the policy rather than waiting for an arbitrary date on the calendar.


Sources and Further Reading


This article provides general information about AI technology, cybersecurity and AI governance. It is not legal advice or a determination of a law firm's professional-responsibility obligations. Attorneys and law firms should evaluate the legal and ethical requirements applicable to their jurisdiction and practice.

Comments


bottom of page