AI · Policy Template

A copy-and-paste AI use policy with eleven sections, sensible data categories and a rollout plan.

Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.

Quick answer

An AI use policy for a law or accounting firm should cover purpose and scope, approved tools, data rules, human review, prohibited uses, transparency, records, vendor assessment, training, incident reporting and review. The core rules are: use only approved tools, never enter confidential client data unless a tool is approved for it, treat AI output as a draft that a qualified person must verify, and log and review use. This is a template, not legal advice.

Key takeaways

  • Eleven sections from purpose and scope to review cycle.
  • Define data categories: public, internal, confidential and restricted.
  • AI output is a draft; a qualified person must verify and own it.
  • Assess vendors on data location, retention, training use, security and exit.
  • Provide approved tools so staff have a safe alternative.

Why does a firm need an AI use policy?

Staff are already using AI tools, with or without permission. Without a policy, client information may be pasted into tools with unsuitable terms, unchecked output may reach clients and nobody can say who used what. A short, clear AI use policy sets safe boundaries, protects client confidentiality and gives staff confidence about what is allowed. This is a general template, not legal advice. Check your regulator’s guidance and your contractual and data protection obligations, and have the final version reviewed.

What should an AI use policy cover?

SectionWhat it settles
Purpose and scopeWhy the policy exists and who it applies to
Approved toolsWhich AI tools may be used, and for what
Data rulesWhat information may and may not be entered
Human reviewWho must check output, and when
Prohibited usesWhat staff must never do with AI
TransparencyWhen and how AI use is disclosed to clients
RecordsWhat is logged and kept
Vendor assessmentHow new tools are approved
TrainingWhat staff must know
IncidentsWhat to do if something goes wrong
ReviewHow often the policy is updated

A copy-and-paste template

1. Purpose and scope

This policy sets out how [Firm name] staff may use artificial intelligence tools in their work. It applies to all partners, employees, contractors and temporary staff, and to all AI tools, whether provided by the firm or used independently.

2. Approved tools

Only tools on the firm’s approved list may be used for work. The list is maintained by [named owner]. Staff must not use unapproved tools or personal accounts for client work.

To request a new tool, submit it to [named owner] for assessment against the criteria in section 8.

3. Data rules

Never enter: client names, identifying details, privileged or confidential information, financial account details, health information or any data the firm is obliged to protect, unless the tool has been approved for that category of data.

May enter: general, non-confidential information and material that has been anonymised so that no individual or client can be identified.

When unsure, ask before using.

4. Human review

AI output is a draft. A qualified member of staff must review and take responsibility for anything used in client work. Output must be checked for accuracy, including every figure, citation and legal or technical statement, against reliable sources.

5. Prohibited uses

Staff must not: use AI to give advice to clients without review; submit AI output to a court, regulator or client without checking it; use AI to make final decisions about people; attempt to bypass tool restrictions; or use AI in ways that breach confidentiality, professional duties or the law.

6. Transparency

Where required by professional rules, contract or client request, the firm will disclose when AI has been used in work. Staff must follow the firm’s guidance on disclosure.

7. Records

The firm will keep a record of approved tools, their versions or settings and, where appropriate, logs of use. Significant AI-assisted work should be noted on the file.

8. Vendor assessment

Before approval, a tool must be assessed for: where data is stored and processed; retention; whether data is used to train models and whether that can be disabled; security measures; access controls and logging; contract terms on confidentiality and breach notification; and the ability to export or delete data.

9. Training

All staff must complete training on this policy before using AI tools, and refresher training at least annually.

10. Incidents

If confidential information is entered into an unapproved tool, or AI output causes or may cause a problem, report it immediately to [named owner]. Do not attempt to resolve it alone.

11. Review

This policy will be reviewed at least annually, and whenever regulations, tools or risks change. Version: ____ Date: ____ Approved by: ____

What are sensible data categories?

CategoryExamplesTypical rule
PublicPublished articles, general guidanceMay be used with approved tools
InternalTemplates, internal proceduresApproved tools only
ConfidentialClient details, financials, privileged materialOnly with tools specifically approved for it, with minimal data
RestrictedHealth data, identification numbers, special categoriesDo not enter unless an approved tool and legal basis exist

How do you roll the policy out?

  1. Draft it with input from partners, operations and compliance.
  2. Review it with legal or professional advisers.
  3. Publish it with a short plain-language summary.
  4. Train staff with real examples.
  5. Provide approved tools so people have a safe alternative.
  6. Check use periodically and update the policy.

How do systems help enforce it?

Policies work best when tools make the safe path the easy one. A custom system can keep AI features inside access-controlled workflows, log every request and limit what data reaches a model. See our security guide and what to cut before you build. Our Discovery Sprint can scope a secure AI workflow for your firm: $345, delivered in 24 hours and credited toward a build starting at $3,500.

Frequently asked questions

Does a small law or accounting firm need an AI policy?

Yes. Even a short policy reduces the risk of confidentiality breaches and unchecked output, and it clarifies expectations for staff.

What should never be entered into AI tools?

Confidential client information, privileged material and regulated personal data, unless the tool is specifically approved for it and the legal basis exists.

Should we tell clients we use AI?

It depends on professional rules, contracts and client expectations. Many firms choose transparency. Check your regulator’s guidance.

Who should own the AI policy?

A named senior person, often with input from compliance, IT and partners.

How often should the policy be updated?

At least annually, and whenever tools, regulations or your use of AI change.

Want a secure AI workflow to go with your policy?

Email us how your team wants to use AI. We will outline a safe, logged and access-controlled way to do it.

Email info@sasolutionspk.com

Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions

About Simple Automation Solutions (SA Solutions)

Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.

Simple Automation Solutions

Business Process Automation, Technology Consulting for Businesses, IT Solutions for Digital Transformation and Enterprise System Modernization, Web Applications Development, Mobile Applications Development, MVP Development