The situation
A 45-person firm has no IT department. A managed service provider handles laptops, Microsoft 365, backups, and the firewall under a monthly contract. A client's procurement team sends a questionnaire asking how the firm controls the use of generative AI. The managing partner forwards it to the MSP, and the MSP replies that it can block websites but that deciding what lawyers may do with client information is a firm decision.
Both answers are reasonable, and that is the gap. The MSP has the technical access but not the professional duties. The firm has the duties but no one whose job is AI. Meanwhile, associates, clerks, and assistants are already using AI tools, some on firm accounts and some on personal ones.
What the rules actually say
In Ontario, the duties that apply are the general ones in the Law Society's Rules of Professional Conduct, and the Law Society has published guidance on how they apply to generative AI. Other provinces have similar competence and confidentiality rules; confirm the specifics with your own law society.
Technological competence. The commentary to rule 3.1-2 says a lawyer should understand and be able to use technology relevant to their practice, including its benefits and risks, with the duty to protect confidential information in mind. Commentary is interpretive guidance attached to the rule, not a separate rule, but it sets the expectation. The technological competence article explores what that means for ChatGPT.
Confidentiality. Rule 3.3-1 requires a lawyer to hold client information in strict confidence unless an exception applies. The Law Society's practice note, Generative AI: Your professional obligations, suggests reviewing a tool's terms of use, not entering confidential or identifying client information into tools without adequate safeguards, and redacting where possible.
Supervision. Rule 6.1-1 makes the lawyer responsible for their practice and for directly supervising non-lawyers. The same practice note suggests giving all employees clear guidelines on how generative AI may be used.
Policy. The Law Society's policy checklist suggests naming a person with the knowledge and authority to oversee the policy, specifying which tools are allowed and with which settings, and considering whether to allow only accounts created with firm credentials. None of this guidance assigns the work to an IT provider.
Why policies and bans fall short
A small firm usually starts by circulating a memo. That is necessary, but IBM's 2025 Cost of a Data Breach Report found that 63% of organizations have no AI governance policy at all. Even where one exists, a memo does not reach the moment someone pastes a document into a chatbot at 10 p.m. Asking the MSP to block AI sites tends to fail too: staff move to phones and personal laptops, and the firm loses what little visibility it had. The article on why AI policies stall covers this pattern.
The other trap is treating AI as a purely technical problem. An MSP can configure a browser, but it cannot decide whether a draft factum may go into a given tool, and it should not be the one reading about client matters.
What a practical control looks like
- Assign ownership. The managing partner owns AI governance and reports on it to the partnership. An operations lead or office manager runs it day to day and is the contact for questions, as the Law Society checklist suggests.
- Write a short policy. One or two pages: the approved tool, the information that must not go into any other tool (client names and identifiers, privileged communications, financial and personal information), whether personal accounts are allowed, and who to call after a mistake.
- Sanction one tool. Pick an enterprise AI tool, review its terms on retention and training, configure its settings, and provision firm accounts. People use what is easy, so make the approved option easy.
- Ask the MSP specific questions. Which browsers and profiles are managed? Can extensions be force-installed so users cannot remove them? What do the policies not cover, such as private browsing windows, unmanaged browsers, and personal devices? How will the MSP report on deployment coverage each month?
- Deploy browser-level controls through existing management. Most MSPs already manage Chrome and Edge through Intune, Group Policy, or Google Admin. Browser policies such as Microsoft's ExtensionInstallForcelist let an administrator install an extension silently so users cannot turn it off. That makes the MSP's part a configuration task, not a new project.
- Review a monthly report. The operations lead reviews flagged events and deployment coverage and raises patterns, not individuals, with the managing partner. Record decisions so the firm can answer the next client questionnaire.
- Keep an incident path. If client information reaches an unapproved tool, the responsible lawyer should know the same day. The 48-hour response guide sets out the steps.
Sanitized Ai is a browser extension for Chrome, Edge, and Firefox that fits this model. The MSP deploys it through the browser management it already runs. When someone is about to submit client names, personal information, financial data, or other sensitive content to an AI tool, it redacts or blocks it before submission and explains in plain language what was flagged and why, which is the training the policy promises delivered at the moment it matters.
The operations lead and managing partner see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never the prompt content. That gives the firm audit-ready records of reasonable safeguards to show clients and insurers without anyone reading what lawyers typed. See how this fits a firm's duties on the law firms page.