AI · Policy Template
A copy-and-paste AI use policy with eleven sections, sensible data categories and a rollout plan.
Last updated: October 2026. Written by Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions.
Quick answer
An AI use policy for a law or accounting firm should cover purpose and scope, approved tools, data rules, human review, prohibited uses, transparency, records, vendor assessment, training, incident reporting and review. The core rules are: use only approved tools, never enter confidential client data unless a tool is approved for it, treat AI output as a draft that a qualified person must verify, and log and review use. This is a template, not legal advice.
Key takeaways
- Eleven sections from purpose and scope to review cycle.
- Define data categories: public, internal, confidential and restricted.
- AI output is a draft; a qualified person must verify and own it.
- Assess vendors on data location, retention, training use, security and exit.
- Provide approved tools so staff have a safe alternative.
In this guide
Why does a firm need an AI use policy?
Staff are already using AI tools, with or without permission. Without a policy, client information may be pasted into tools with unsuitable terms, unchecked output may reach clients and nobody can say who used what. A short, clear AI use policy sets safe boundaries, protects client confidentiality and gives staff confidence about what is allowed. This is a general template, not legal advice. Check your regulator’s guidance and your contractual and data protection obligations, and have the final version reviewed.
What should an AI use policy cover?
| Section | What it settles |
|---|---|
| Purpose and scope | Why the policy exists and who it applies to |
| Approved tools | Which AI tools may be used, and for what |
| Data rules | What information may and may not be entered |
| Human review | Who must check output, and when |
| Prohibited uses | What staff must never do with AI |
| Transparency | When and how AI use is disclosed to clients |
| Records | What is logged and kept |
| Vendor assessment | How new tools are approved |
| Training | What staff must know |
| Incidents | What to do if something goes wrong |
| Review | How often the policy is updated |
A copy-and-paste template
1. Purpose and scope
This policy sets out how [Firm name] staff may use artificial intelligence tools in their work. It applies to all partners, employees, contractors and temporary staff, and to all AI tools, whether provided by the firm or used independently.
2. Approved tools
Only tools on the firm’s approved list may be used for work. The list is maintained by [named owner]. Staff must not use unapproved tools or personal accounts for client work.
To request a new tool, submit it to [named owner] for assessment against the criteria in section 8.
3. Data rules
Never enter: client names, identifying details, privileged or confidential information, financial account details, health information or any data the firm is obliged to protect, unless the tool has been approved for that category of data.
May enter: general, non-confidential information and material that has been anonymised so that no individual or client can be identified.
When unsure, ask before using.
4. Human review
AI output is a draft. A qualified member of staff must review and take responsibility for anything used in client work. Output must be checked for accuracy, including every figure, citation and legal or technical statement, against reliable sources.
5. Prohibited uses
Staff must not: use AI to give advice to clients without review; submit AI output to a court, regulator or client without checking it; use AI to make final decisions about people; attempt to bypass tool restrictions; or use AI in ways that breach confidentiality, professional duties or the law.
6. Transparency
Where required by professional rules, contract or client request, the firm will disclose when AI has been used in work. Staff must follow the firm’s guidance on disclosure.
7. Records
The firm will keep a record of approved tools, their versions or settings and, where appropriate, logs of use. Significant AI-assisted work should be noted on the file.
8. Vendor assessment
Before approval, a tool must be assessed for: where data is stored and processed; retention; whether data is used to train models and whether that can be disabled; security measures; access controls and logging; contract terms on confidentiality and breach notification; and the ability to export or delete data.
9. Training
All staff must complete training on this policy before using AI tools, and refresher training at least annually.
10. Incidents
If confidential information is entered into an unapproved tool, or AI output causes or may cause a problem, report it immediately to [named owner]. Do not attempt to resolve it alone.
11. Review
This policy will be reviewed at least annually, and whenever regulations, tools or risks change. Version: ____ Date: ____ Approved by: ____
What are sensible data categories?
| Category | Examples | Typical rule |
|---|---|---|
| Public | Published articles, general guidance | May be used with approved tools |
| Internal | Templates, internal procedures | Approved tools only |
| Confidential | Client details, financials, privileged material | Only with tools specifically approved for it, with minimal data |
| Restricted | Health data, identification numbers, special categories | Do not enter unless an approved tool and legal basis exist |
How do you roll the policy out?
- Draft it with input from partners, operations and compliance.
- Review it with legal or professional advisers.
- Publish it with a short plain-language summary.
- Train staff with real examples.
- Provide approved tools so people have a safe alternative.
- Check use periodically and update the policy.
How do systems help enforce it?
Policies work best when tools make the safe path the easy one. A custom system can keep AI features inside access-controlled workflows, log every request and limit what data reaches a model. See our security guide and what to cut before you build. Our Discovery Sprint can scope a secure AI workflow for your firm: $345, delivered in 24 hours and credited toward a build starting at $3,500.
Frequently asked questions
Does a small law or accounting firm need an AI policy?
Yes. Even a short policy reduces the risk of confidentiality breaches and unchecked output, and it clarifies expectations for staff.
What should never be entered into AI tools?
Confidential client information, privileged material and regulated personal data, unless the tool is specifically approved for it and the legal basis exists.
Should we tell clients we use AI?
It depends on professional rules, contracts and client expectations. Many firms choose transparency. Check your regulator’s guidance.
Who should own the AI policy?
A named senior person, often with input from compliance, IT and partners.
How often should the policy be updated?
At least annually, and whenever tools, regulations or your use of AI change.
Want a secure AI workflow to go with your policy?
Email us how your team wants to use AI. We will outline a safe, logged and access-controlled way to do it.
Athar Ahmad, Certified Bubble.io Developer and Tech Architect, Simple Automation Solutions
About Simple Automation Solutions (SA Solutions)
Simple Automation Solutions is a Bubble.io development studio led by Athar Ahmad, a Certified Bubble.io Developer and Tech Architect. It builds web and mobile apps, client portals and SaaS products for founder-led businesses such as law firms, accounting firms, boutique agencies and consultants. Services include a free 30-minute Idea Audit, a $345 Discovery Sprint (a Product Requirements Document delivered within 24 hours, credited toward the build) and builds starting at $3,500. Website: sasolutionspk.com.