The situation
A long-standing corporate client sends its annual outside counsel guidelines update. Buried after the billing rules is a new section on artificial intelligence. The firm must not use generative AI on the client's matters without prior written approval, must not enter the client's confidential information into any publicly available AI tool, must ensure no provider trains on the client's data, and must identify any AI tools used in delivering the work. The relationship partner signs the acknowledgement. Nobody tells the associates.
The pattern is easy to recognize. The clause is easy to sign and hard to comply with, because AI use happens one prompt at a time, on many devices, by people who never read the guidelines.
What these clauses typically require
Wording varies, but AI sections tend to be built from the same parts:
- Notice or prior consent before AI is used on the client's matters, sometimes by matter, sometimes by tool.
- No confidential information in public tools: no client data in consumer AI assistants or any tool without enterprise terms.
- No training on client data, and sometimes limits on retention by the AI provider.
- Approved tools only, often with a requirement to list the tools and their providers.
- Human review of AI output by a responsible lawyer.
- Billing rules: no charging for time the tool saved, no charging for learning a tool, or AI costs treated as overhead unless agreed.
- Disclosure and cooperation: tell the client which tools were used, report incidents promptly, and answer audit or questionnaire requests.
- Flow-down: the same obligations apply to contract lawyers, agents, and other service providers the firm engages.
What the rules actually say
The client's guidelines are a contractual layer on top of your professional duties, and they can be stricter than your law society. Canadian regulators have published guidance, not AI-specific rules, and the guidance lines up with most of these clauses.
The Law Society of Ontario's resource on generative AI and professional obligations advises against entering confidential or identifying client information into tools without appropriate confidentiality, security, and retention safeguards. It ties disclosure to clients to the duty of honesty and candour, and says any AI cost passed on as a disbursement must be fair, reasonable, disclosed in a timely way, and billed at actual cost.
The Law Society of BC's guidance suggests leaving client-identifying information out of AI tools and, where that is not possible, considering fully informed client consent. It also asks firms to reflect on how billing should change when AI saves time. The Barreau du Québec's practical guide recommends informed consent, formalized in writing, when generative AI is used on client files.
Clients with US operations may draft their guidelines with US ethics guidance in mind. The American Bar Association's Formal Opinion 512, issued July 29, 2024, applies the model rules on competence, confidentiality, communication, and fees to generative AI. It takes the view that lawyers may bill for time spent entering information into a tool and reviewing the output, but in most circumstances not for learning how to use it. For Canadian firms, it is context, not a binding rule.
None of this is legal advice. Read each client's actual wording and confirm your approach with your practice advisors and, where needed, the client.
Why policies and bans fall short
A firm-wide AI policy rarely matches every client's clause. One client allows approved enterprise tools, another requires written consent per matter, and a third bans generative AI outright. Associates cannot hold that matrix in their heads while drafting at midnight.
The harder problem is evidence. When the client's questionnaire or audit asks whether its information has ever been entered into a public AI tool, a policy lets you say what should have happened. It does not let you say what did. We cover what a credible answer looks like in answering the client AI security questionnaire.
What a practical control looks like
- Build a clause register. For each client with AI terms, record what is allowed, what needs consent, which tools are approved, and the billing rule. Attach it to the client record in your practice management system.
- Map every obligation to a control and evidence. For example, "no confidential information in public tools" maps to a technical control at the prompt and a record of what it caught.
- Flag restricted matters at file opening, so everyone on the team knows the client's rule on day one.
- Keep a tool inventory with each provider's data terms, retention, and training settings, ready for disclosure requests.
- Set billing codes for AI-assisted work that follow each client's terms.
- Train the team on data categories rather than brands: client names and identifiers, personal information, deal terms, and privileged advice.
- Report incidents on the client's timetable. Guidelines may set their own notice periods. Align your incident process with them, and see the managing partner's 90-day checklist for building that process.
Sanitized Ai is a browser extension that gives a core clause, no client confidential information in public AI tools, a working control. When someone is about to submit client names, identifiers, personal information, or deal terms to one of the major AI assistants, it redacts or blocks that content before submission and explains in plain language what was flagged and why.
Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never see prompt content. That gives the firm audit-ready records to support its answers when a client asks how its guidelines are followed in practice. See how it fits law firms.