Operating guides / Legal AI operations

The one-page AI policy for a small law firm: a working template

by Hamza Suleman. Published . Operational guidance, not legal advice.

Get this done in a morning

The half-day AI adoption workshop leaves your firm with this policy adopted, the approved tools register built, and a named owner for every AI decision. See how the workshop runs, or book a fit call.

The SRA's warning notice on the misuse of AI, published 17 August 2026, tells firms what it is concerned about. It does not tell you what your AI policy should say. This post does. Below is a complete one-page policy that a firm of two to twenty fee earners can adopt this week, followed by a clause-by-clause note on what each part is doing and which regulatory expectation it answers.

The short version: the notice is outcomes-focused. In the SRA's own words, it sets "the standards we expect solicitors and firms to meet, but we do not prescribe exactly how those standards should be met in different circumstances". So no regulator will ever hand you a template. What the notice does demand is evidence of control: effective governance under paragraph 2.1 of the Code of Conduct for Firms, competent and supervised work under paragraphs 3.2 and 3.5 of the Code of Conduct for Solicitors, and confidentiality under paragraph 6.3 of both Codes. One page, signed, dated and enforced, is the cheapest evidence of control a small firm can produce. Here it is.

This is the second piece in the SRA implementation-kit series. The first, the five-part implementation kit for managing partners, covers the order of operations: named owner, shadow AI audit, policy, verification rule, insurer and client conversations. This post fills in Part 3, the policy itself.

Why one page is enough

A small firm does not need a forty-page AI governance framework. It needs a page every fee earner has actually read. The notice asks whether the firm can demonstrate that AI use is owned, controlled and checked. A framework nobody opened demonstrates nothing. A one-page policy that is signed, dated, circulated and enforced demonstrates exactly what the notice asks for, and it takes an afternoon, not a procurement cycle.

Two qualifications before the template. First, a policy on top of usage you have not inventoried is decoration. If you do not know which tools your fee earners actually use, run the shadow AI audit in Part 2 of the implementation kit first; the audit's output is the approved tools register this policy points to. Second, this template is operational drafting, not legal advice on your firm's specific regulatory position. It is a starting point a competent firm can adapt in an afternoon, and your COLP should read it before it is signed.

The template

Copy everything between the lines. Fill in the brackets. It fits on one page.


[FIRM NAME] - AI USE POLICY

Version [1], approved [date]. Owner: [name, role]. Next review: [date, no more than 12 months out].

1. Who and what this covers. Everyone who works for or with the firm: partners, employees, consultants, contractors and temps. It covers every AI tool, paid or free, on firm or personal accounts and devices.

2. Ownership. [Name] owns AI use in the firm. They keep the approved tools register, approve new tools, and answer for the firm's AI use to clients, insurers and the SRA.

3. Approved tools only. Only tools on the approved register may be used for client work. Anything not on the register is not used for client work. For each tool, the register records what it is approved for, the account type, and the data terms reviewed.

4. What never goes into an AI tool. Unless the tool is on the register with data terms covering confidentiality and a commitment not to train on inputs, none of the following is entered into any AI tool: client or matter identity, client documents or data, anything privileged, anything confidential to a third party. When in doubt, it does not go in.

5. Verification. Nothing AI-assisted leaves the firm - to a court, a client, a counterparty or a regulator - until a named person has checked every citation, quotation and factual claim against the primary source. The checker's name goes on the file. Reviewed is not the standard. Verified is.

6. Firm accounts only. AI use for firm work happens on firm-controlled accounts, never personal ones.

7. Exceptions. Only the owner approves an exception, in writing, recorded on the register with a date and a reason.

8. Raising a problem. Anyone who thinks AI output was wrong, or that something confidential went into an AI tool, tells the owner the same day. There is no blame for raising it. Concealment is the disciplinary issue, not the mistake.

9. Breach. Deliberate breach of this policy is a conduct matter.

Signed: [managing partner]. Date: [date].


Want this adopted and the tools register built in a morning? That is the half-day workshop.

Clause by clause: what each part is doing

Clause 1 (scope). The notice's confidentiality concern applies to "both paid for and free-to-use AI tools" and the real-world leakage path is the personal account and the home laptop, not the sanctioned platform. If the policy only covers firm tools on firm machines, it misses where the risk actually lives.

Clause 2 (ownership). Paragraph 2.1 of the Code of Conduct for Firms requires effective governance structures, systems and controls, and paragraph 9.1 puts the COLP on the hook to take all reasonable steps to ensure compliance. Governance that belongs to everyone belongs to no one. One named person is the whole point.

Clause 3 (approved register). This is what "control" looks like when an insurer, a client or the SRA asks. It also serves paragraph 7.2 of the solicitors' Code: you must be able to justify your decisions and actions. A register with dates and reviewed data terms is a justification. A verbal understanding is not.

Clause 4 (confidentiality). This is the clause the notice cares most about. Its language: client information "should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place". The Upper Tribunal put the consequence bluntly in R (on the application of Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC) at paragraph 21: "to put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain". The Tribunal's broader observation was that putting privileged material into a public AI tool is itself a waiver of privilege over it. That is why the default in this clause is exclusion, not permission.

Clause 5 (verification). The notice is explicit that accountability does not move: "AI has no separate legal personality; solicitors and regulated individuals who use AI in the course of delivering legal services remain accountable for their work and outputs, regardless of how that work has been prepared." In R (on the application of Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), fabricated AI citations were put before the court, the lawyers faced a wasted costs application, and they were referred to their regulators. The judgment notes at paragraph 29 that it is "likely to be appropriate for the court to make a reference to the regulator" where false citations are placed before the court. The named-checker rule exists so that the verification is not a culture or an aspiration; it is a name on a file.

Clause 6 (firm accounts). Consumer accounts carry consumer data terms. This clause is the cheap companion to clause 4: it removes the ambiguity about which terms govern the input.

Clause 7 (exceptions). A policy with no exception route gets quietly worked around, and then you have shadow use again. A written exception with a date and a reason keeps the exception inside the governance instead of outside it.

Clause 8 (no-blame reporting). The notice records that the SRA has received self-reports from solicitors who relied on AI tools that generated inaccurate content. Firms find problems early only when raising them is safe. In a small firm this is a cultural line more than a legal one, and it is the cheapest risk control in the document.

Clause 9 (breach). Without a consequence line, the document is guidance. With one, it is a policy. Keep it short.

What the notice requires, and what this template adds

Be straight with yourself about the difference, because it is the difference between compliance and comfort.

The notice requires: effective governance, supervision and controls (Firms Code 2.1, 4.3, 4.4); competent, supervised service (Solicitors Code 3.2, 3.5); confidentiality (6.3 in both Codes); properly arguable submissions to the court (2.4); and the ability to justify your decisions (7.2). Its summary line is the one to remember: "The use of AI does not diminish or transfer your professional responsibilities."

The template goes further than the letter of the notice in two places, deliberately. The named-checker verification rule extends the notice's explicit discussion of verifying legal authorities to anything AI-assisted that leaves the firm. And the blanket exclusion of client material from unregistered tools is stricter than a case-by-case risk assessment. Both are cheap bright lines a small firm can actually enforce, and both produce the evidence trail the notice is asking firms to be able to show. Proportionate does not have to mean vague.

Adopting it in a week

Monday: the managing partner names the owner and fills in the brackets on the template. If you have not inventoried actual usage, run the anonymous five-question survey from the implementation kit the same morning.

Wednesday: build the approved tools register from what the audit found. For each tool, record the account type and the data terms you reviewed. Two unapproved tools in real use is a normal finding; the register is how they get handled rather than hidden.

Friday: the owner signs, dates and circulates the policy with a two-line covering note, and it goes on the intranet banner or the shared drive where people actually look. Diary the review date.

Total cost: an afternoon of partner time. If a client, an insurer or the SRA asks how your firm controls AI use next month, the answer is a document, a register and a name. That is the whole exercise.

The US parallel, in one paragraph

For US-qualified colleagues, the shape is identical. The American Bar Association's Formal Opinion 512 (July 2024) reaches the same destination through existing duties - competence, confidentiality, candour and reasonable fees applied unchanged to generative AI - and the same operational answer falls out: named ownership, controlled tools, verified output. One page works there too.

Where tooling fits

Nothing in the template requires buying anything. Tooling enters later, when the firm has a named workflow, real numbers from its register and audit, and a decision to make - which is the shape of our half-day Workshop and the questions we collect in Answers. On the product side: Margo, our contract-review tool, is in controlled development and not generally available; the verification and data-handling rules above are what we are building it to satisfy. You can read the approach at /margo/.

Frequently asked questions

Does the SRA require a written AI policy?

No. The notice is outcomes-focused and prescribes no format. What the Code of Conduct for Firms requires is effective governance structures, systems and controls (paragraph 2.1), and the solicitors' Code requires you to be able to justify your decisions (paragraph 7.2). A signed, dated one-pager plus an approved tools register is the cheapest way to evidence both.

Can we just ban AI instead?

You can, and the notice does not stop you. The practical problem is enforcement: adoption data consistently shows individual use running far ahead of firmwide approval, so a ban nobody follows produces exactly the shadow use the notice is worried about. A short enforced policy beats a long ignored ban.

Does the policy need to cover free tools like ChatGPT?

Yes. The notice states that both free and paid tools may lack the contractual and technical safeguards needed to maintain client confidentiality, and the confidentiality breach the Upper Tribunal described in R (Munir) v SSHD [2026] UKUT 81 (IAC) involved a public tool. Free and personal accounts are the main leakage path, so the template puts them in scope from the first clause.

Who should own AI use in a two-partner firm?

One of the partners, named. Usually the managing partner or the COLP. The answer cannot be "both of us", because a question with two owners has none when an insurer or the SRA asks it.

How often should the policy be reviewed?

At least every twelve months, and sooner if the firm adopts a new class of tool, has an incident, or the regulatory position moves. Keep old versions dated rather than overwriting them; the version history is itself evidence of governance.