AI changes the practical terms of an outside counsel relationship. It can affect how company data is handled, how lawyers produce and check work, how time is recorded, and which technology costs are passed through.
A blanket ban may be unnecessary, but “use AI responsibly” is too vague to help. A useful policy tells firms which uses require disclosure or approval, what may happen to company data, who remains accountable for the work, and how AI-assisted work should appear on an invoice.
Ethical duties depend on the lawyer’s jurisdiction and the facts of the matter. But current guidance gives legal departments a practical foundation. ABA Formal Opinion 512 addresses competence, confidentiality, client communication, supervision, and fees when lawyers use generative AI. The State Bar of California’s practical guidance also notes that lawyers must follow client instructions or guidelines restricting AI use.
Outside counsel billing guidelines are the natural place to set company-specific expectations.
Start by defining what your AI policy covers
“AI” is too broad to function as a useful rule. Your guidelines should cover systems that generate, select, summarize, analyze, recommend, or act on information, not just public chatbots.
At a minimum, address:
Generative AI used for research, drafting, summarization, document review, or analysis
AI features embedded in legal research, document-management, e-discovery, or productivity tools
Systems that process company documents or other information relating to a matter
Agentic tools that can sequence tasks, access connected systems, send communications, or take other actions with limited human prompting
Draw a clear line between material and incidental use. A grammar correction generally does not need a separate notice. Disclosure or approval makes more sense when AI processes company information, materially informs legal advice, produces substantive work product, changes a staffing plan, or affects the cost of the engagement.
A risk-based definition gives firms a rule they can actually follow.
The 8 AI clauses to add
1. Disclosure and approval
State which uses must be disclosed, when the disclosure is due, and who can approve an exception.
For material use, ask outside counsel to identify:
The tool and provider
The proposed use case
Whether company or client-confidential information will be entered
Whether the tool retains inputs or outputs or uses them for model training
The planned human review
Any expected effect on timing, staffing, or fees
Do not make the process so burdensome that every minor feature requires a new email. A sensible threshold is more enforceable than an absolute disclosure rule that everyone ignores.
2. Approved tools and prohibited uses
Require firms to use tools that have passed an appropriate internal security and legal review. Prohibit company information from being entered into public, consumer, or otherwise unapproved tools.
Your policy can also prohibit AI from making unsupervised strategic decisions, sending external communications, filing documents, or taking actions in company systems without written approval. This becomes more important as tools gain persistent access to email, repositories, matter files, and other connected systems.
3. Confidentiality, data use, and retention
“Enterprise AI” is not a complete security standard. Require outside counsel to understand how a system collects, uses, stores, discloses, and deletes information.
Useful requirements include:
Company data may not be used to train a provider’s or third party’s models
Inputs and outputs may be retained only for an approved period
Access must be limited to authorized personnel and systems
Data must be encrypted in transit and at rest
Subprocessors and underlying model providers must be identified or appropriately governed
Company data must be deleted or returned at the end of the matter or engagement
Any use involving information relating to the representation must comply with applicable confidentiality, privilege, privacy, and security obligations
The D.C. Bar’s Ethics Opinion 388 tells lawyers to determine whether an AI product saves submitted information or uses it in outputs for other users. ABA Formal Opinion 512 likewise recommends examining terms, privacy policies, retention, security, and vendor practices instead of relying on general assurances.
For your own technology review, see Poppy’s security principles.
4. Human review and professional responsibility
Say plainly that the firm and its lawyers remain responsible for the final work.
Require an appropriately qualified lawyer to review AI-assisted work for factual accuracy, legal support, completeness, confidentiality, bias where relevant, and compliance with court or agency rules. Citations and quoted language should be checked against authoritative sources.
The required review should reflect the task and risk. A brainstorming list does not require the same process as a dispositive motion, regulatory submission, or analysis that drives a settlement recommendation. But “the AI produced it” should never be an answer to a quality problem.
5. Billing for time actually spent
For hourly matters, require invoices to reflect the time people actually spend on the matter, including reasonable prompting, review, correction, and integration of AI output. Do not permit reconstructed “equivalent time,” double billing, or billing the hours a task might have required without AI.
ABA Formal Opinion 512 explains that hourly billing must reflect actual time spent even when AI makes work faster. The Florida Bar’s Ethics Opinion 24-1 likewise warns against improper billing practices such as double billing.
Your guideline should also say whether general training on an AI product is billable. A clean default is that learning a generally used tool is firm overhead unless the company specifically requests training on a particular tool for its matter and approves the charge in advance.
6. AI tool costs and expenses
Separate ordinary firm overhead from a matter-specific expense.
A general subscription used across the firm will often look more like word-processing, research-library, or other practice overhead. A per-use charge for a specialized review of a large, matter-specific dataset may be different.
Require written preapproval before any AI or technology charge is passed through. Ask the firm to disclose the basis of the charge and prohibit markups unless separately agreed. Formal Opinion 512 treats this as a fact-specific reasonableness question and distinguishes general practice tools from actual out-of-pocket, matter-specific costs.
7. Staffing, efficiency, and invoice narratives
If AI changes neither the staffing model nor the fee, ask what value the client is receiving. Require firms to explain when material AI use changes the matter plan, budget, delegation, or proposed fee arrangement.
For repeatable work, an alternative fee arrangement may better align price with value than trying to translate every AI-assisted task into tenths of an hour. See our guide to using billing guidelines to explore AFAs.
For invoices, require enough information to understand the task and human work performed without forcing the firm to reproduce sensitive prompts or confidential source material. A standardized notation such as “AI-assisted; attorney reviewed” can be more useful than vague or overly detailed language. Pair this with clear invoice narrative standards.
8. Incidents, auditability, and policy changes
Require prompt notice of an AI-related event that may affect company information, legal work, deadlines, or the integrity of an output. The notice should include what happened, the systems and data involved, containment steps, and the firm’s corrective action.
For higher-risk uses, request a record of the tool, material version, use case, responsible reviewer, and approval. Keep enough information to investigate a problem and confirm compliance; for most matters, that will not require retaining every prompt indefinitely.
Require the firm to notify you when a material tool, model, provider, retention practice, or integration changes. Because AI products change quickly, approval should be revisited after a material change.
Copy-and-adapt sample AI clause
The following is a practical starting point, not jurisdiction-specific legal advice:
Use of artificial intelligence. Outside Counsel may use artificial intelligence in connection with Company matters only in compliance with applicable law, professional obligations, engagement terms, and these Guidelines. Outside Counsel must disclose and obtain written approval before using an AI system that will receive Company Confidential Information, materially inform legal advice or substantive work product, materially affect staffing, timing, or fees, or take external or autonomous action. The disclosure must identify the tool, provider, use case, categories of data involved, applicable retention and training settings, planned human review, and any proposed charge.
Outside Counsel may not enter Company Confidential Information into a public, consumer, or otherwise unapproved AI system. Company data may not be used to train any model. Outside Counsel must apply reasonable security, access, retention, deletion, and incident-response controls and remains responsible for its providers and subprocessors.
An appropriately qualified lawyer must independently review and verify all AI-assisted substantive work. Outside Counsel remains fully responsible for the accuracy, legal sufficiency, confidentiality, and quality of the final work product and for compliance with applicable court, agency, and professional requirements.
Hourly invoices must reflect only time actually spent by authorized timekeepers. General AI subscriptions, general tool training, and hypothetical time saved are not billable. Any matter-specific AI expense requires advance written approval and must be billed at actual cost unless Company agrees otherwise in writing. Outside Counsel must promptly report any AI-related incident that may affect Company data, work product, deadlines, or the representation.
Customize that language with your information-security team and counsel. In particular, define “Company Confidential Information,” approval owners, incident-notice timing, approved tools, and matter categories that need stricter controls.
How to roll out the policy without creating friction
Inventory your risk. Identify the matter types and data that need the strongest controls.
Align internal owners. Have Legal, Privacy, Information Security, Procurement, and Finance agree on approval and exception paths.
Pilot with a few firms. Ask how they approve tools, protect matter data, review outputs, and record AI-assisted time.
Add the rules to engagement and onboarding. Do not bury the policy in an email after work begins.
Review the first invoices together. Clarify ambiguous entries before treating them as violations.
Revisit the policy periodically. Trigger a review when material tools, integrations, or bar guidance change.
Start with Poppy’s free outside counsel billing guidelines and Word template, then tailor the AI section to your organization’s actual risk and operating model.
Frequently asked questions
Should outside counsel disclose every use of AI?
Not necessarily. Applicable ethics duties are fact-specific, and a client may set a clearer contractual rule. A practical policy defines material uses that require disclosure while excluding incidental features that do not process company information or affect substantive work, staffing, or cost.
Can a law firm charge for AI-assisted work?
It depends on the fee arrangement, applicable rules, and your agreement. For hourly work, current ethics guidance emphasizes actual time spent. General subscriptions will often be treated as overhead, while an approved matter-specific, out-of-pocket service may be chargeable. State the rule in advance.
Should we prohibit AI entirely?
A blanket prohibition may be appropriate for particular matters or data, but it can also eliminate legitimate efficiency gains and be difficult to administer. Many teams are better served by risk tiers: permitted low-risk use, disclosed or approved use involving company data, and prohibited high-risk use.
Do agentic AI systems need different rules?
Yes. A tool that can access repositories, sequence tasks, communicate externally, or take action creates a different risk profile than an isolated prompt. Require narrower permissions, explicit approval, stronger logging, and meaningful human checkpoints.
How should AI use appear on a legal invoice?
Require a concise, standardized indicator for material use, plus the human task performed and time actually spent. Do not require firms to place confidential prompts or sensitive source material in invoice narratives.
Write a policy firms can actually follow
A workable guideline lets firms use tools that improve delivery while protecting company information, keeping lawyers accountable, and billing only for the work and costs the client agreed to.
The standard is straightforward: use AI where it helps, with controls that match the risk.
This article provides general operational information, not legal advice. Rules vary by jurisdiction and matter; consult appropriate legal, privacy, and security professionals when adopting an AI policy.
