# Template Firm AI Policy

> Use when a law firm needs a ready-to-adopt AI use policy governing how associates, paralegals, and staff may use Louis or other AI tools. Covers permitted uses, prohibited uses, mandatory safeguards (citation verification, matter-file documentation, bar-rule compliance), and links to relevant professional responsibility rules. Adaptable for MENA and common-law jurisdictions.

- Skill: `sboghossian-mini-claude-for-legal/template-firm-ai-policy` (Agent Skill)
- Install (CLI): `npx skillmds@latest add sboghossian-mini-claude-for-legal/template-firm-ai-policy`
- Raw SKILL.md: https://api.skillmd.com/api/skills/sboghossian-mini-claude-for-legal/template-firm-ai-policy/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Docs & Writing
- License: MIT
- Author: sboghossian (https://skillmd.com/u/sboghossian-mini-claude-for-legal)
- Updated: 2026-09-10
- Page: https://skillmd.com/skills/sboghossian-mini-claude-for-legal/template-firm-ai-policy

---


# Template — Firm AI Use Policy

## When to use this

Use this template when:
- A law firm is adopting Louis and needs an internal policy before rolling out access to associates and paralegals.
- An in-house legal team is formalising its AI-governance framework.
- A managing partner or GC asks "what policy should we have in place before our team starts using AI?"
- Bar-association guidance requires a written AI policy as a condition of compliant AI use.

Adapt the template to the firm's jurisdiction, practice areas, and seniority structure. Have a supervising partner or GC review before circulation.

## Policy template

---

**[FIRM NAME] — Policy on Use of AI-Assisted Legal Tools**

*Version: [date] | Approved by: [Managing Partner / GC]*

### 1. Purpose

This policy governs the use of artificial intelligence tools — including Louis (HAQQ Legal AI) and any other AI-assisted legal research, drafting, or review tool — by all lawyers, trainees, paralegals, and support staff at [Firm Name]. It is intended to ensure that AI use is consistent with our professional obligations, client confidentiality duties, and the standards set by applicable bar regulations.

### 2. Permitted uses

The following uses are permitted, subject to the safeguards in Section 4:

- **Legal research support:** Using AI to identify potentially relevant statutes, regulations, and case law. All citations must be independently verified before reliance.
- **First-draft preparation:** Using AI to generate first drafts of contracts, letters, pleadings, or legal memoranda. All AI-generated drafts must be reviewed, edited, and approved by a qualified lawyer before use.
- **Document summarisation:** Using AI to summarise lengthy documents (contracts, court bundles, due-diligence materials) as an aid to review. The reviewing lawyer remains responsible for the underlying documents.
- **Pre-litigation document organisation:** Using AI to sort, categorise, and extract key data from document sets. Results must be verified by a lawyer or trained paralegal.
- **Translation drafts:** Using AI to produce working translations of foreign-language documents. Translation accuracy must be verified by a qualified translator or lawyer with relevant language competency before the translation is relied upon.

### 3. Prohibited uses

The following uses are prohibited:

- **Submitting AI output as final work product** without attorney review and sign-off.
- **Pasting client-confidential information** into any AI tool not approved under the firm's IT and data-governance policy.
- **Court filings generated or substantially drafted by AI** without: (a) attorney review; (b) disclosure to the court where required by applicable court rules or professional guidelines.
- **Establishing attorney-client relationships via AI** — no AI tool may be used in a manner that creates the impression that a client is receiving independent legal advice from the AI rather than from a named lawyer.
- **Sending privileged or confidential content** to any AI tool outside the firm-approved toolset.
- **Relying on AI-generated citations without verification** — fabricated citations are a disciplinary and malpractice risk.

### 4. Mandatory safeguards

When using AI tools in legal work, all users must:

1. **Verify all citations.** Every statute, regulation, and case law reference generated by AI must be independently confirmed against the primary source before use in any work product or court submission.

2. **Document AI use in the matter file.** A note must be added to the matter file recording: (a) which AI tool was used; (b) for what purpose; (c) the scope of attorney review applied. This supports privilege analysis and professional responsibility documentation.

3. **Comply with applicable bar rules.** In particular:
   - Duty of competence: a lawyer must have sufficient understanding of AI outputs to exercise independent professional judgment (see [[safety-bar-rule-1-1-competence-ai]]).
   - Duty of confidentiality: client information may only be processed through approved tools with adequate data-protection terms.
   - Supervision: supervising lawyers are responsible for AI outputs produced by lawyers under their supervision, to the same extent as they are responsible for other supervised work.

4. **Flag jurisdiction uncertainty.** If an AI tool's jurisdiction coverage for a specific matter is unclear, escalate to a supervising lawyer before relying on AI-generated analysis.

### 5. Approved tools

The following AI tools are approved for use under this policy:
- **Louis (HAQQ Legal AI)** — approved for drafting, research, review, and summarisation as described above, subject to data-processing terms on file with IT.
- [Add other approved tools as applicable]

All other AI tools are prohibited for matter work without prior written approval from [IT Security / Managing Partner].

### 6. Confidentiality and data

All AI use must comply with the firm's data-protection and client confidentiality obligations. Do not use personal data of individuals in AI prompts without a lawful basis. For questions on data handling, see [[template-client-data-explainer]].

### 7. Review

This policy will be reviewed annually or when significant changes to AI tools or bar guidance occur.

---

## Jurisdictional adaptation notes

| Jurisdiction | Key adaptation |
|---|---|
| UAE / DIFC / ADGM | UAE Federal Decree-Law on Personal Data Protection applies; ensure approved tools have UAE-compatible DPA. DIFC and ADGM have their own data-protection frameworks (DIFC DP Law 2020; ADGM GDPR-equivalent). |
| KSA | Personal Data Protection Law (PDPL) requires consent for personal data processing; AI prompts containing employee/client personal data must comply. Court filing disclosure requirements are evolving — check latest Saudi Bar Association guidance. |
| Lebanon | Bar of Beirut has issued informal guidance on AI; no formal rule yet. Apply the general competence-verification standard. |
| EU / UK | GDPR applies to personal data in prompts; AI Act may apply to high-risk legal AI uses. Disclose AI use in court where required under Civil Procedure Rules (UK) or equivalent. |

## Related skills

- [[template-client-data-explainer]]
- [[template-vendor-security-questionnaire-responses]]
- [[safety-bar-rule-1-1-competence-ai]]

