New managing partners at Canadian law and IP firms

New managing partner: a 90-day AI risk checklist

Sources verified Sanitized Ai Team

The short answer

Spend days 1 to 30 finding out how AI is actually used across the firm, days 31 to 60 deciding on a policy, approved tools, and rules for client data, and days 61 to 90 putting controls and training in place and collecting evidence that they work. Anchor each step in the guidance your law society has already published, and in what clients and insurers are starting to ask.

The situation

You took over as managing partner this month. In your first two weeks, a financial institution client sent an updated set of outside counsel guidelines with a new section on AI, the firm's cyber insurance renewal arrived with questions about AI use, and an associate asked whether they can use ChatGPT for a first draft. The firm has a two-paragraph AI memo from last year. Nobody is sure who wrote it.

AI risk at a law firm is not mainly a technology question. It is a question of confidentiality, privilege, supervision, and competence, carried out by people who already use AI every day. A 90-day plan gives you a defensible answer for clients, insurers, and your own partners.

What the rules actually say

No Canadian law society we reviewed has created a separate AI rule. The binding duties are the existing ones in each code of conduct. What regulators have published is guidance on how those duties apply.

  • Ontario. The Law Society of Ontario's resource on generative AI and professional obligations walks through competence, confidentiality, honesty and candour, supervision, fees, and duties to tribunals. It advises firms with employees to develop policies on appropriate use, and its policy checklist lists the questions a policy should answer: which tools, which settings, what information may be entered, whether personal accounts are allowed, and when clients are told.
  • British Columbia. The Law Society of BC's guidance on generative AI suggests that client confidential information, including anything identifying the client, ideally be left out of what is supplied to a generative AI tool, with fully informed client consent as the fallback. It also reminds lawyers that fees must stay fair and reasonable when AI saves time, and that records security rules still apply.
  • Quebec. The Barreau du Québec's practical guide takes a firm line on professional secrecy. It states that entering information covered by professional secrecy into an open, publicly accessible system is itself a violation, even without any actual reproduction or disclosure. It recommends anonymizing data before use, not using the tool when that is impossible, documenting prompts and results in the client file, and keeping internal policies current.

Confirm how these apply to your firm with your law society's practice advisors.

Why policies and bans fall short

Most firms start and stop at a policy memo. A memo sets expectations, but it cannot tell you whether anyone follows it, and it does nothing at the moment an associate pastes a client document into a personal account. A ban tends to push use onto personal phones, where the firm sees nothing.

When a client or insurer asks how AI risk is managed, a policy on its own is a thin answer. A 90-day plan should end with something you can show, not only something you wrote.

What a practical control looks like

Days 1 to 30: discover

  1. Name an owner. Pick one person with the authority to change the policy and the knowledge to answer questions about it.
  2. Inventory the tools. List approved AI tools, AI features switched on inside existing software, and the consumer assistants people actually use. Ask your IT provider what they can see.
  3. Ask people directly. A short, no-blame survey: which tools, for which tasks, on which accounts and devices.
  4. Collect external demands. Gather AI clauses in client outside counsel guidelines, recent security questionnaires, and insurer renewal questions. See how to comply with AI clauses in outside counsel guidelines.
  5. Check for past incidents. Has client information already been entered into an unapproved tool? If so, follow the 48-hour incident playbook.

Days 31 to 60: decide

  1. Write or rewrite the policy using the Ontario checklist questions as a structure, whatever your province.
  2. Choose approved tools and settings. Record which privacy, retention, and training settings must be on.
  3. Set the personal account rule in one clear sentence.
  4. Define restricted data: client names and identifiers, personal information, privileged advice, deal terms, and unfiled invention details.
  5. Decide on client disclosure and billing. When will clients be told, when is consent needed, and how will AI-assisted time be billed?
  6. Adopt an incident process with named contacts for your practice advisor, insurer, and privacy officer.

Days 61 to 90: deploy and prove

  1. Train everyone, including assistants and students, on the policy and the restricted data categories.
  2. Put a control at the prompt so the policy operates when people are busy, not only when they remember.
  3. Measure. Track flagged events, incidents, and training completion.
  4. Report to the partnership and prepare a standard answer for client questionnaires, drawing on how outside counsel answer the client AI security questionnaire.

Sanitized Ai is a browser extension that supports step 13. When someone is about to submit client identifiers, personal information, or deal terms to one of the major AI assistants, it redacts or blocks that content before submission and explains in plain language what was flagged and why, so training happens in the moment.

Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when), never prompt content. By day 90, that gives you the evidence for steps 14 and 15: a record of risky submissions caught before they left the firm, which can support your answer to a client or insurer that reasonable safeguards are in place. See how it fits law firms.

Frequently asked questions

Is there a law society rule that requires an AI policy?

We are not aware of a Canadian law society rule that requires a written AI policy by name. The Law Society of Ontario, the Law Society of BC, and the Barreau du Québec have each published guidance that ties AI use to existing duties such as confidentiality, competence, and supervision, and the Ontario and Quebec guidance both encourage firms to adopt internal policies.

Who should own AI risk at a mid-sized firm?

One named person with enough authority to change the policy and enough knowledge to answer questions about it. The Law Society of Ontario's policy checklist suggests designating an overseer who answers questions, keeps the policy current, and reviews it at regular intervals. In many firms that is a partner working with the director of operations and the outsourced IT provider.

Do we need client consent before using AI on a file?

It depends on the tool, the data, and the jurisdiction. Ontario's guidance ties disclosure to factors such as how the tool is used and whether it affects the client's interests or costs. The Barreau du Québec's guide recommends informed, written consent where client files are processed with generative AI. Decide your approach in days 31 to 60 and apply it consistently.

What evidence will clients and insurers want to see?

Usually a written policy, a list of approved tools and how they are configured, proof of training, an incident process, and some record showing the policy is followed in practice. A record of events caught before submission is more persuasive than a policy alone.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Related guides

Further reading