Writing a Law Firm AI Policy From Scratch: A Practical Guide for NJ Solo and Small Firms
Photo by Gylain Omer on Unsplash
7 min readOctober 2, 2026

Writing a Law Firm AI Policy From Scratch: A Practical Guide for NJ Solo and Small Firms

Law Firm AI PolicyNJ RPC 5.1Small Firm AI Compliance

AI-assisted, reviewed by Adam Elias. This post was drafted with AI under Adam's editorial rules and published under his name. It is commentary, not legal advice. Verify any rule or citation against the primary source before you rely on it. Published October 2, 2026. Reviewed October 2, 2026.

Most NJ solo attorneys and small firms using AI have one thing in common: they're making it up as they go. There's no written policy, no approved tool list, no guidance for the paralegal who started running client intake notes through ChatGPT last month. That informality creates real exposure under New Jersey's Rules of Professional Conduct, particularly RPC 5.1, which places supervisory responsibility squarely on partners and firm principals.

A written AI use policy doesn't need to be a 40-page compliance manual. For a solo or two-attorney firm, a working policy might be three to five pages. What matters isn't length. It's specificity. Vague policies get ignored. Specific ones get followed.

Here's how to build one that actually functions.

Start With Your Tool Inventory, Not Your Rules

Before writing a single policy sentence, list every AI tool currently in use at your firm. Include the obvious ones (ChatGPT, Clio Duo, Westlaw AI, Microsoft Copilot) and the less obvious ones: AI features embedded in your email client, document management system, or e-discovery platform. You may be surprised how many tools are already on the list once you look closely.

For each tool, note three things: what data goes into it, where that data is processed and stored, and whether you have a signed data processing agreement (or BAA, if health information is ever involved) with the vendor. This inventory becomes the backbone of your policy's approved tools section.

If a tool isn't on your approved list, the default answer should be that staff don't use it for client-related work. That single boundary eliminates the most common data exposure scenario in small firms: a well-meaning employee testing a new AI app with real client information.

Define What "Client Data" Means in the AI Context

Your policy needs to define what counts as confidential client information for AI purposes, and the definition should be broader than attorneys instinctively think. It's not just names and Social Security numbers. It includes matter-specific facts, transaction details, deposition summaries, and anything that could identify a client or their legal situation if it surfaced outside the firm.

Any AI tool that processes this information either needs to be contractually prohibited from training on your inputs or must be used in a configuration that prevents it. Many consumer-facing tools, including free tiers of popular platforms, do not offer that protection by default. Your policy should say explicitly: free-tier AI tools are not approved for any client-related work.

Separate Acceptable Uses From Prohibited Ones

Rather than writing a general "use AI responsibly" statement, be specific about what's in and what's out.

Acceptable uses might include: drafting and editing non-client-specific templates, legal research summarization (with attorney verification), internal administrative tasks like scheduling and billing descriptions, and proofreading of already-anonymized documents.

Prohibited uses should include: inputting client names or identifying details into unapproved tools, using AI to generate final legal advice without attorney review, running conflicts checks exclusively through AI without cross-referencing your firm's conflicts database, and generating court filings without full attorney review of every citation.

That last item matters. NJ federal courts, including the District of New Jersey, have seen cases nationally where AI-generated citations turned out to be fabricated. The District of New Jersey has not yet issued a standing order on AI disclosure as of mid-2025, but that window is closing. Some NJ judges are already asking about it in case management conferences. Your policy should address this before a judge does.

Build in a Verification Requirement, Not Just a Review Requirement

There's a difference between "an attorney reviews AI output" and "an attorney verifies AI output." Review can be passive. Verification requires actually checking citations against primary sources, confirming that summarized case holdings are accurate, and reading generated contract language against the client's specific facts.

Your policy should specify that any AI-assisted work product submitted to a court, opposing counsel, or client requires attorney verification, not just a quick read-through. Build a simple checklist into your workflow: citation checked, factual summary confirmed, client-specific details reviewed for accuracy. This protects you under RPC 1.1's competence requirement and gives you a documented basis to show the work was actually supervised.

Address Staff Use Directly

If you have a paralegal, legal assistant, or virtual assistant, your policy needs a section written for them. Don't assume that your own understanding of AI limitations transfers automatically.

This section should cover: which tools they're approved to use, which tasks they can start with AI assistance, and what requires attorney sign-off before it goes anywhere. It should also include a reporting line. If a staff member isn't sure whether a particular use is covered by the policy, who do they ask? That person should be named in the document.

Under RPC 5.3, NJ attorneys are responsible for ensuring that non-lawyer staff conduct is compatible with the attorney's professional obligations. A policy that addresses staff AI use, distributed and signed off on, creates a record that supervision actually happened.

Review the Policy on a Schedule

AI tools change faster than ethics opinions do. Set a calendar reminder to review your policy every six months. Check whether any approved tools have updated their data use terms, whether new tools warrant addition or removal from the list, and whether any NJ ethics opinions or court orders issued since your last review require a policy change.

The NJ Office of Attorney Ethics has not issued a standalone AI ethics opinion as of this writing, but the Advisory Committee on Professional Ethics has fielded AI-adjacent questions, and guidance is coming. A policy review cycle keeps you positioned to adapt quickly when it does.

If you want a practical starting point, the ABA's Formal Opinion 512 (2024) on generative AI offers a framework you can adapt to NJ's specific RPCs. It's not binding here, but it's the clearest organized statement of the considerations a working policy needs to address.

A written policy takes an afternoon to draft and might take ten minutes to update twice a year. The alternative is improvising under pressure when something goes wrong, and explaining to a client, or a disciplinary panel, why there were no guardrails in place.

Get the weekly roundup

New AI Sidebar articles delivered to your inbox. No spam, unsubscribe anytime.