Managing partners and operations leads at small and mid-sized law firms

How does a law firm with outsourced IT and no security team govern AI?

Sources verified Sanitized Ai Team

The short answer

Give ownership to the managing partner and an operations lead, not to the MSP. Adopt a short policy and one sanctioned AI tool, then ask the MSP to deploy browser-level controls through the browser management it already runs, and review a simple monthly report. The professional duties stay with the firm; the MSP carries out the technical pieces.

The situation

A 45-person firm has no IT department. A managed service provider handles laptops, Microsoft 365, backups, and the firewall under a monthly contract. A client's procurement team sends a questionnaire asking how the firm controls the use of generative AI. The managing partner forwards it to the MSP, and the MSP replies that it can block websites but that deciding what lawyers may do with client information is a firm decision.

Both answers are reasonable, and that is the gap. The MSP has the technical access but not the professional duties. The firm has the duties but no one whose job is AI. Meanwhile, associates, clerks, and assistants are already using AI tools, some on firm accounts and some on personal ones.

What the rules actually say

In Ontario, the duties that apply are the general ones in the Law Society's Rules of Professional Conduct, and the Law Society has published guidance on how they apply to generative AI. Other provinces have similar competence and confidentiality rules; confirm the specifics with your own law society.

Technological competence. The commentary to rule 3.1-2 says a lawyer should understand and be able to use technology relevant to their practice, including its benefits and risks, with the duty to protect confidential information in mind. Commentary is interpretive guidance attached to the rule, not a separate rule, but it sets the expectation. The technological competence article explores what that means for ChatGPT.

Confidentiality. Rule 3.3-1 requires a lawyer to hold client information in strict confidence unless an exception applies. The Law Society's practice note, Generative AI: Your professional obligations, suggests reviewing a tool's terms of use, not entering confidential or identifying client information into tools without adequate safeguards, and redacting where possible.

Supervision. Rule 6.1-1 makes the lawyer responsible for their practice and for directly supervising non-lawyers. The same practice note suggests giving all employees clear guidelines on how generative AI may be used.

Policy. The Law Society's policy checklist suggests naming a person with the knowledge and authority to oversee the policy, specifying which tools are allowed and with which settings, and considering whether to allow only accounts created with firm credentials. None of this guidance assigns the work to an IT provider.

Why policies and bans fall short

A small firm usually starts by circulating a memo. That is necessary, but IBM's 2025 Cost of a Data Breach Report found that 63% of organizations have no AI governance policy at all. Even where one exists, a memo does not reach the moment someone pastes a document into a chatbot at 10 p.m. Asking the MSP to block AI sites tends to fail too: staff move to phones and personal laptops, and the firm loses what little visibility it had. The article on why AI policies stall covers this pattern.

The other trap is treating AI as a purely technical problem. An MSP can configure a browser, but it cannot decide whether a draft factum may go into a given tool, and it should not be the one reading about client matters.

What a practical control looks like

  1. Assign ownership. The managing partner owns AI governance and reports on it to the partnership. An operations lead or office manager runs it day to day and is the contact for questions, as the Law Society checklist suggests.
  2. Write a short policy. One or two pages: the approved tool, the information that must not go into any other tool (client names and identifiers, privileged communications, financial and personal information), whether personal accounts are allowed, and who to call after a mistake.
  3. Sanction one tool. Pick an enterprise AI tool, review its terms on retention and training, configure its settings, and provision firm accounts. People use what is easy, so make the approved option easy.
  4. Ask the MSP specific questions. Which browsers and profiles are managed? Can extensions be force-installed so users cannot remove them? What do the policies not cover, such as private browsing windows, unmanaged browsers, and personal devices? How will the MSP report on deployment coverage each month?
  5. Deploy browser-level controls through existing management. Most MSPs already manage Chrome and Edge through Intune, Group Policy, or Google Admin. Browser policies such as Microsoft's ExtensionInstallForcelist let an administrator install an extension silently so users cannot turn it off. That makes the MSP's part a configuration task, not a new project.
  6. Review a monthly report. The operations lead reviews flagged events and deployment coverage and raises patterns, not individuals, with the managing partner. Record decisions so the firm can answer the next client questionnaire.
  7. Keep an incident path. If client information reaches an unapproved tool, the responsible lawyer should know the same day. The 48-hour response guide sets out the steps.

Sanitized Ai is a browser extension for Chrome, Edge, and Firefox that fits this model. The MSP deploys it through the browser management it already runs. When someone is about to submit client names, personal information, financial data, or other sensitive content to an AI tool, it redacts or blocks it before submission and explains in plain language what was flagged and why, which is the training the policy promises delivered at the moment it matters.

The operations lead and managing partner see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never the prompt content. That gives the firm audit-ready records of reasonable safeguards to show clients and insurers without anyone reading what lawyers typed. See how this fits a firm's duties on the law firms page.

Frequently asked questions

Can we make AI governance our MSP's responsibility?

The MSP can deploy and maintain controls, but it does not carry the firm's professional obligations. Confidentiality and supervision duties sit with the lawyers, so ownership should sit with a partner, with the MSP accountable for the technical tasks it agrees to.

Do we need a long AI policy?

No. A policy of one or two pages that names the approved tool, the information that must not go into other tools, and who to call after a mistake is more likely to be read and followed. The Law Society of Ontario has published a checklist of questions that helps firms build one.

Will browser controls let partners read what staff type into AI tools?

It depends on the tool. Sanitized Ai reports only metadata about flagged events, such as which tool, what type of data, which policy, and when, and never shows prompt content. Firms should decide deliberately how much monitoring they want and tell staff what is collected.

What if staff use personal devices?

Browser management covers managed devices and managed browser profiles. The policy should require client work on managed devices only, and the MSP should explain what its browser policies do and do not reach, including private browsing windows.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Standards that apply

Related guides

Further reading