The situation
A managing partner at a 40-person Toronto firm gets a question from a client's general counsel: "What is your policy on generative AI, and how does it line up with Law Society of Ontario guidance?" The partner knows associates use ChatGPT and Microsoft Copilot. She suspects an articling student has pasted part of a draft agreement into a personal account. What she lacks is a clear picture of what the Law Society says, which parts are binding, and what a reasonable firm should do.
The short version: the Law Society treats generative AI as a new way to meet old duties. There is no separate AI rule, but its guidance on how the existing Rules of Professional Conduct apply is specific enough to build a firm policy around.
What the rules actually say
The guidance documents
In April 2024 the Law Society published a white paper, Licensee use of generative artificial intelligence, prepared by its Futures Committee. It encourages licensees to try generative AI while taking reasonable steps to mitigate the risks. Its Technology Resource Centre adds a practice resource, Generative AI: Your professional obligations, a quick-start checklist, eight best practice tips, and a later checklist of questions for building a firm AI policy.
Competence (rule 3.1-2)
Rule 3.1-2 requires a lawyer to perform legal services to the standard of a competent lawyer. Commentary [4A] and [4B] in Chapter 3 say that competence includes understanding the benefits and risks of relevant technology, tied directly to the duty to protect confidential information. The white paper applies this to generative AI: learn a tool's terms, data handling and limits before using it, and verify its output.
Confidentiality (rule 3.3-1)
Rule 3.3-1 requires a lawyer to hold all information about a client's business and affairs in strict confidence. The white paper notes that some AI providers use inputs to train their tools or otherwise store them, and it recommends that licensees not input confidential or privileged information without adequate security measures. It also warns that anonymized facts can sometimes be pieced back together. The professional obligations resource goes further: where a tool lacks appropriate safeguards, do not enter identifying client information at all, and where anonymizing is not enough, explain the risks to the client and obtain informed consent.
Supervision (rule 6.1-1)
Rule 6.1-1 in Chapter 6 makes a lawyer fully responsible for their practice and requires direct supervision of non-lawyers. The practice resource compares using generative AI to getting help from a non-licensee employee, and it recommends clear firm guidelines, training, and rules about what information may and may not be entered into an AI system.
Clients, fees and tribunals
The guidance also covers candour with clients (rule 3.2-2), fair fees and disbursements, and the duty not to mislead a tribunal. For factums, Ontario's Rules of Civil Procedure now require a signed statement, under rule 4.06.1(2.1), certifying that every cited authority is authentic and every quotation accurately reproduces the authority. That is a citation-checking duty with its own review process.
Why policies and bans fall short
The Law Society's policy checklist asks firms to decide whether staff may use personal AI accounts for work, and suggests limiting use to accounts tied to the firm's credentials. That is the right question, and it is where written policy runs out. A personal account in a browser tab looks like any other website, and the firm cannot see what was pasted. Gartner reported in 2026 that 88% of employees with enterprise AI access also use personal AI tools for work.
A ban does not change that behaviour. It moves it out of view, which makes supervision under rule 6.1-1 harder, not easier. The timing problem is structural: once client information is submitted to a public AI tool, it cannot be recalled. It becomes subject to the provider's terms, which can permit retention, sub-processing and, in some cases, training. A policy that is only reviewed after the fact cannot prevent that disclosure. The partner owes a supervisory duty over the method, as our post on what a partner owes when a student pastes a client file into AI explains, not only over the finished memo.
What a practical control looks like
The Law Society's checklists map onto a short program a firm can start this quarter:
- Name a policy owner. The policy checklist suggests one person with authority to answer questions and revise the policy as tools change.
- Approve tools and settings. List the sanctioned tools, require firm accounts, and set privacy and training options before anyone uses them.
- Define what may never be entered. Client names and identifiers, privileged communications, deal terms, and personal information, unless the tool has been vetted and the client has consented where needed.
- Train everyone who touches a file. The guidance recommends training for licensees and non-licensees alike, covering how the tools process sensitive information.
- Set a client communication protocol. Use the white paper's disclosure factors to decide when to tell clients and when to seek informed consent.
- Create an incident path. Decide who is told, how the client is informed, and how the event is documented if confidential information reaches an unapproved tool.
- Keep verification separate. Factum certification under rule 4.06.1(2.1) and output review are human tasks with their own checklist.
For the technological competence side of this, see our post on the duty of technological competence and ChatGPT. Firms with lawyers in more than one province can compare this guidance with the Law Society of BC's approach.
Sanitized Ai is a browser extension that supports steps 3, 4 and 6 at the moment they matter. When someone pastes or uploads client identifiers, personal information, or deal terms into an AI assistant, it detects that data and redacts or blocks it before submission, and it tells the person in plain language what was flagged and why. Coverage spans the major AI assistants and keeps growing.
Administrators see a dashboard of flagged events (which tool, what type of data, which policy, when) without ever seeing prompt content. The quick-start checklist suggests keeping an audit trail and monitoring AI use; an audit-ready record of events caught before submission can support that and serve as evidence of reasonable safeguards, without collecting privileged material. It does not check citations or legal accuracy, so steps 5 and 7 stay with your lawyers. Confirm your approach with the Law Society's Practice Management Helpline or your own counsel, and see how the extension fits a firm's workflow on our law firms page.