Your Law Firm Is Already Using AI. Did Anyone Set Up Guardrails?
Most law firm AI use is happening without oversight, without compliance monitoring, and without anyone clearly accountable. Here's how to fix that.
9 min read
Nick Stevens : August 25, 2026
Most law firm AI use is happening without oversight, without compliance monitoring, and without anyone clearly accountable. Here's how to fix that.
TL;DR: Sixty-nine percent of legal professionals now use AI for work, more than doubling in a single year. The governance hasn't kept pace with the adoption. Forty-three percent of firms have no formal AI policy and no plans to create one, and only 9 percent have a written policy that's actually enforced. That means most AI use in law firms today is happening without oversight, without compliance monitoring, and without anyone clearly accountable for what these tools are doing with client data. That's not a technology problem. It's a management one.
Think about the last time a new tool showed up at your firm without anyone planning for it. Not a major technology initiative, just something that arrived because it was useful: a Chrome extension someone installed, a free trial that became a subscription, a new platform one practice group adopted because the old one was too slow. By the time anyone asked whether it was approved, it had already been in use for three months.
AI adoption in law firms is following exactly that pattern, just at a much larger scale and with much higher stakes. Someone downloads ChatGPT to help with a first draft. Someone else uses an AI research tool because it finds relevant case law faster than the old method. A paralegal discovers that an AI summarization tool cuts document review time in half. None of these decisions go through a formal approval process. None of them get evaluated against the firm's data handling policies. And none of them come with a clear answer to the question of where the client data being fed into those systems actually goes.
Sixty-nine percent of legal professionals now use AI for work, according to the 8 am 2026 Legal Industry Report, more than doubling from 31 percent just one year earlier. Forty-three percent of firms have no formal AI policy and no plans to create one. Only 9 percent have a written policy that's actually enforced.
The tools are in. The guardrails mostly aren't. This post covers what AI governance actually requires for a law firm and what happens when it gets skipped.
The numbers on AI adoption in legal are striking, but the numbers on governance are the ones worth paying attention to.
Most firms didn't make a deliberate decision to let AI adoption outpace oversight. It just happened, the same way it always happens with technology that's genuinely useful and frictionless to adopt. Someone found a tool that worked. Someone else found a different one. By the time anyone thought to ask whether there was a policy, there was already a practice.
The result is that the majority of AI use in law firms today is happening without anyone clearly accountable for it. No inventory of which tools are in use. No documented standards for what can and can't be fed into them. No training on what the ethical obligations actually require in an AI context. And no visibility into whether the outputs being used in client work are being verified before they go out the door.
The gap between individual enthusiasm and institutional readiness is the defining tension in legal technology right now. And it's not abstract. Sixty percent of in-house legal teams don't know whether their outside firms are using AI on their active matters. That transparency gap is already showing up in outside counsel guidelines, and it's going to show up in client conversations sooner than most managing partners expect.
The tools arrived. The oversight hasn't caught up yet. That's the problem this blog is about.
The risk with AI in a legal context isn't that the tools don't work. Most of them work reasonably well. The risk is what happens to the data that goes into them.
When an attorney pastes a confidential brief into a consumer AI tool to get a quick summary, a few things happen simultaneously. The text leaves the firm's environment. It enters a third-party system with its own data retention policies, terms of service, and potential for model training on user inputs. The ethical wall that existed in iManage or NetDocuments doesn't travel with the document. The access controls stay behind. The privilege protection may not survive the transfer.
This isn't hypothetical. In February 2026, a court in the Heppner ruling held that using a consumer AI tool whose terms of service allowed data retention and third-party disclosure destroyed attorney-client privilege and eliminated work-product protection. That's a real case, a real ruling, and a real consequence for a firm that was probably just trying to work faster. According to Clio's 2025 Legal Trends Report, 46 percent of legal professionals use generic, non-legal AI tools. Most of them are probably not thinking about what their terms of service say about data retention.
The ABA addressed this directly in Formal Opinion 512, establishing clear ethical guardrails for AI use in legal practice. Competence under Rule 1.1 now includes understanding how AI tools handle data. Confidentiality under Rule 1.6 requires reasonable efforts to ensure client information isn't being retained, reused, or exposed by third-party systems. Those obligations existed before AI. AI just created a lot of new ways to inadvertently violate them.
Good AI governance for a law firm isn't a 50-page policy document. It's a practical framework that covers the decisions attorneys are actually making every day. The ABA's Formal Opinion 512 organizes it around five areas: acceptable use, data security and client confidentiality, verification and quality control, client communication, and billing. That's a useful starting point because it maps directly to where the exposure lives.
Acceptable use. Which tools are approved for which tasks, and which aren't. Consumer-grade AI tools that retain user inputs for model training don't belong anywhere near client data. Enterprise tools with contractual confidentiality protections and clear data handling policies are a different conversation. The firm needs a documented list of approved tools, updated as new ones get adopted, so attorneys know what's sanctioned and what isn't.
Data security and confidentiality. Access controls, data residency, and matter separation. An AI tool that can't separate one client's data from another's isn't appropriate for legal work, regardless of how useful it is for other purposes. This is also where the connection to the firm's broader IT security posture matters most. For a full picture of what that looks like across the whole environment, Your Law Firm's IT Partner Is Either an Asset or a Liability. Which One Do You Have? covers the complete framework.
Verification and quality control. Stanford HAI research found that even sophisticated legal AI tools produce incorrect information at rates between 17 and 34 percent. Every AI output used in client work needs human review before it goes out the door. That's not a limitation of the technology. It's just how competent legal work with AI works right now.
Client communication and billing. Clients increasingly want to know whether AI was used on their matter and how it affected their bill. Having clear, consistent answers to both questions before they ask is considerably better than figuring it out in the moment.
There's a useful distinction between what firms are required to do and what firms that are serious about AI governance actually do. The required floor is lower than most people expect. The smart standard is higher.
ABA Formal Opinion 512 doesn't create new ethics rules. It applies the existing ones, competence, confidentiality, supervision, communication, and fees, to AI use. That's actually the right framing: the ethical obligations didn't change when AI arrived. The ways to violate them got more numerous. At a minimum, Opinion 512 requires that lawyers maintain a reasonable understanding of the AI tools they use, protect client confidentiality before inputting any client data, verify AI outputs before they go to clients or courts, and supervise everyone on the team using AI, including non-lawyer staff.
State bars are building on that baseline. California's professional responsibility committee approved proposed amendments to its Rules of Professional Conduct in March 2026, weaving AI-specific language directly into Rule 1.6 on confidentiality and Rule 5.1 on managerial responsibility, which would explicitly require firms to establish AI policies. New York's court system adopted a system-wide AI policy effective June 1, 2026, requiring disclosure and certification for AI-generated filings. Over 1,300 cases worldwide have now involved fabricated AI citations submitted to courts. Multiple firms have been sanctioned six figures. The enforcement environment is no longer theoretical.
The smart standard goes beyond the required floor. It means a written AI policy that covers approved tools, data handling, verification protocols, client disclosure, and incident response. It means regular training so everyone using AI understands the boundaries. And it means someone with actual authority owning the governance function, not just a document that exists somewhere on the shared drive that nobody references.
The ethical obligations are real and they matter. But the reason AI governance is becoming urgent for most law firms isn't just the bar association. It's the clients.
Eighty-five percent of clients now expect disclosure when AI is used on their matter, and nearly half describe that expectation as extremely important. That's not a preference. It's a threshold expectation, and firms that treat it as optional are accumulating reputational liability one undisclosed matter at a time. Outside counsel guidelines are already beginning to require verifiable AI governance, not just a policy document. The firms that can demonstrate technical controls over client data, rather than just describe them, will have a meaningful advantage as that becomes standard.
The in-house picture reinforces this. Sixty-four percent of corporate legal teams expect to rely less on outside counsel as they build AI capabilities internally. The firms they'll continue to work with are the ones that can show their house is in order, that client data is handled appropriately, that outputs are verified, and that someone is actually accountable for how AI is being used. A governance framework isn't just about avoiding discipline. It's about being the kind of firm clients trust with their most sensitive work.
The pilot phase is over. AI is operational infrastructure now, whether firms are ready for that or not. Governance is what makes it defensible.
Most firms didn't arrive at their current AI situation through bad decisions. They arrived through a lot of small, reasonable ones made without a shared framework for what was acceptable, what wasn't, and who was responsible for knowing the difference. The tools showed up because they were useful. The governance didn't follow because nobody specifically made it someone's job.
That's the fixable part. A written acceptable use policy, a documented list of approved tools, clear standards for how client data gets handled, verification protocols before AI outputs go anywhere near a client, and someone with actual authority owning the whole thing. None of that requires a massive compliance program. It requires someone to decide it matters and follow through.
Heroic Technologies works with law firms and professional services organizations across Oregon, Washington, and California. They've spent 14-plus years helping firms build technology environments that hold up under scrutiny, and AI governance is increasingly where that work starts. Not because firms are doing something wrong, but because the gap between how AI is being used and how it's being governed is closing, and the firms that close it deliberately will be in a better position than the ones that get pushed into it.
When it comes to AI governance specifically, that means helping firms understand what's actually in their environment, building the policy and technical framework that makes AI use defensible, and making sure the oversight structure holds up when a client, a regulator, or an insurer asks for proof.
The guardrails don't have to be complicated. They just have to exist. Get in touch with Heroic Technologies and let's make sure yours do.
1. Does ABA Formal Opinion 512 require our firm to have a written AI policy?
Opinion 512 requires managerial lawyers under Model Rule 5.1 to establish clear standards governing AI use firm-wide. A written policy is the practical way to meet that obligation, train people against it, and demonstrate compliance if a disciplinary authority or malpractice carrier ever asks. California's proposed Rule 5.1 amendments would make it explicit. Getting there before it's required is considerably less stressful than scrambling after.
2. Can we use consumer AI tools like ChatGPT for client work?
It depends on the tool's data handling terms and what you're putting into it. Consumer tools that retain user inputs for model training or allow third-party data access create confidentiality exposure under Rule 1.6 and potentially destroy privilege, as the Heppner ruling demonstrated. Enterprise tools with contractual confidentiality protections and clear data residency controls are a different conversation. The line is client data. Once that's involved, the tool needs to be built to protect it.
3. What's the first thing a firm should do to get AI governance in place?
Start with an inventory. Find out which tools are actually being used across the firm, not just the officially sanctioned ones. The gap between what IT knows about and what attorneys are actually using is almost always larger than anyone expects. From there, build a short, practical, acceptable use policy covering approved tools, data handling standards, verification requirements, and client disclosure. It doesn't need to be 50 pages. It needs to be something people will actually follow.
Most law firm AI use is happening without oversight, without compliance monitoring, and without anyone clearly accountable. Here's how to fix that.
Your new hire can't work and your former employee still can. Both are IT problems. Here's what good onboarding and offboarding actually require.
Not every process deserves an AI bot. Here's how to tell which ones do and why the first one matters most.