The situation
You took over as managing partner this month. In your first two weeks, a financial institution client sent an updated set of outside counsel guidelines with a new section on AI, the firm's cyber insurance renewal arrived with questions about AI use, and an associate asked whether they can use ChatGPT for a first draft. The firm has a two-paragraph AI memo from last year. Nobody is sure who wrote it.
AI risk at a law firm is not mainly a technology question. It is a question of confidentiality, privilege, supervision, and competence, carried out by people who already use AI every day. A 90-day plan gives you a defensible answer for clients, insurers, and your own partners.
What the rules actually say
No Canadian law society we reviewed has created a separate AI rule. The binding duties are the existing ones in each code of conduct. What regulators have published is guidance on how those duties apply.
- Ontario. The Law Society of Ontario's resource on generative AI and professional obligations walks through competence, confidentiality, honesty and candour, supervision, fees, and duties to tribunals. It advises firms with employees to develop policies on appropriate use, and its policy checklist lists the questions a policy should answer: which tools, which settings, what information may be entered, whether personal accounts are allowed, and when clients are told.
- British Columbia. The Law Society of BC's guidance on generative AI suggests that client confidential information, including anything identifying the client, ideally be left out of what is supplied to a generative AI tool, with fully informed client consent as the fallback. It also reminds lawyers that fees must stay fair and reasonable when AI saves time, and that records security rules still apply.
- Quebec. The Barreau du Québec's practical guide takes a firm line on professional secrecy. It states that entering information covered by professional secrecy into an open, publicly accessible system is itself a violation, even without any actual reproduction or disclosure. It recommends anonymizing data before use, not using the tool when that is impossible, documenting prompts and results in the client file, and keeping internal policies current.
Confirm how these apply to your firm with your law society's practice advisors.
Why policies and bans fall short
Most firms start and stop at a policy memo. A memo sets expectations, but it cannot tell you whether anyone follows it, and it does nothing at the moment an associate pastes a client document into a personal account. A ban tends to push use onto personal phones, where the firm sees nothing.
When a client or insurer asks how AI risk is managed, a policy on its own is a thin answer. A 90-day plan should end with something you can show, not only something you wrote.
What a practical control looks like
Days 1 to 30: discover
- Name an owner. Pick one person with the authority to change the policy and the knowledge to answer questions about it.
- Inventory the tools. List approved AI tools, AI features switched on inside existing software, and the consumer assistants people actually use. Ask your IT provider what they can see.
- Ask people directly. A short, no-blame survey: which tools, for which tasks, on which accounts and devices.
- Collect external demands. Gather AI clauses in client outside counsel guidelines, recent security questionnaires, and insurer renewal questions. See how to comply with AI clauses in outside counsel guidelines.
- Check for past incidents. Has client information already been entered into an unapproved tool? If so, follow the 48-hour incident playbook.
Days 31 to 60: decide
- Write or rewrite the policy using the Ontario checklist questions as a structure, whatever your province.
- Choose approved tools and settings. Record which privacy, retention, and training settings must be on.
- Set the personal account rule in one clear sentence.
- Define restricted data: client names and identifiers, personal information, privileged advice, deal terms, and unfiled invention details.
- Decide on client disclosure and billing. When will clients be told, when is consent needed, and how will AI-assisted time be billed?
- Adopt an incident process with named contacts for your practice advisor, insurer, and privacy officer.
Days 61 to 90: deploy and prove
- Train everyone, including assistants and students, on the policy and the restricted data categories.
- Put a control at the prompt so the policy operates when people are busy, not only when they remember.
- Measure. Track flagged events, incidents, and training completion.
- Report to the partnership and prepare a standard answer for client questionnaires, drawing on how outside counsel answer the client AI security questionnaire.
Sanitized Ai is a browser extension that supports step 13. When someone is about to submit client identifiers, personal information, or deal terms to one of the major AI assistants, it redacts or blocks that content before submission and explains in plain language what was flagged and why, so training happens in the moment.
Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never prompt content. By day 90, that gives you the evidence for steps 14 and 15: a record of risky submissions caught before they left the firm, which can support your answer to a client or insurer that reasonable safeguards are in place. See how it fits law firms.