Managing partners, general counsel, and risk leads at law firms

Outside counsel guidelines with AI clauses: how to comply

Sources verified Sanitized Ai Team

The short answer

AI clauses in outside counsel guidelines tend to ask for the same things: notice or consent before AI is used on the client's matters, no client confidential information in public AI tools, no training on client data, fair billing for AI-assisted work, and disclosure of which tools the firm uses. Comply by recording each client's terms, mapping every obligation to a control and a piece of evidence, and making sure the rule operates at the prompt, not only in a memo.

The situation

A long-standing corporate client sends its annual outside counsel guidelines update. Buried after the billing rules is a new section on artificial intelligence. The firm must not use generative AI on the client's matters without prior written approval, must not enter the client's confidential information into any publicly available AI tool, must ensure no provider trains on the client's data, and must identify any AI tools used in delivering the work. The relationship partner signs the acknowledgement. Nobody tells the associates.

The pattern is easy to recognize. The clause is easy to sign and hard to comply with, because AI use happens one prompt at a time, on many devices, by people who never read the guidelines.

What these clauses typically require

Wording varies, but AI sections tend to be built from the same parts:

  • Notice or prior consent before AI is used on the client's matters, sometimes by matter, sometimes by tool.
  • No confidential information in public tools: no client data in consumer AI assistants or any tool without enterprise terms.
  • No training on client data, and sometimes limits on retention by the AI provider.
  • Approved tools only, often with a requirement to list the tools and their providers.
  • Human review of AI output by a responsible lawyer.
  • Billing rules: no charging for time the tool saved, no charging for learning a tool, or AI costs treated as overhead unless agreed.
  • Disclosure and cooperation: tell the client which tools were used, report incidents promptly, and answer audit or questionnaire requests.
  • Flow-down: the same obligations apply to contract lawyers, agents, and other service providers the firm engages.

What the rules actually say

The client's guidelines are a contractual layer on top of your professional duties, and they can be stricter than your law society. Canadian regulators have published guidance, not AI-specific rules, and the guidance lines up with most of these clauses.

The Law Society of Ontario's resource on generative AI and professional obligations advises against entering confidential or identifying client information into tools without appropriate confidentiality, security, and retention safeguards. It ties disclosure to clients to the duty of honesty and candour, and says any AI cost passed on as a disbursement must be fair, reasonable, disclosed in a timely way, and billed at actual cost.

The Law Society of BC's guidance suggests leaving client-identifying information out of AI tools and, where that is not possible, considering fully informed client consent. It also asks firms to reflect on how billing should change when AI saves time. The Barreau du Québec's practical guide recommends informed consent, formalized in writing, when generative AI is used on client files.

Clients with US operations may draft their guidelines with US ethics guidance in mind. The American Bar Association's Formal Opinion 512, issued July 29, 2024, applies the model rules on competence, confidentiality, communication, and fees to generative AI. It takes the view that lawyers may bill for time spent entering information into a tool and reviewing the output, but in most circumstances not for learning how to use it. For Canadian firms, it is context, not a binding rule.

None of this is legal advice. Read each client's actual wording and confirm your approach with your practice advisors and, where needed, the client.

Why policies and bans fall short

A firm-wide AI policy rarely matches every client's clause. One client allows approved enterprise tools, another requires written consent per matter, and a third bans generative AI outright. Associates cannot hold that matrix in their heads while drafting at midnight.

The harder problem is evidence. When the client's questionnaire or audit asks whether its information has ever been entered into a public AI tool, a policy lets you say what should have happened. It does not let you say what did. We cover what a credible answer looks like in answering the client AI security questionnaire.

What a practical control looks like

  1. Build a clause register. For each client with AI terms, record what is allowed, what needs consent, which tools are approved, and the billing rule. Attach it to the client record in your practice management system.
  2. Map every obligation to a control and evidence. For example, "no confidential information in public tools" maps to a technical control at the prompt and a record of what it caught.
  3. Flag restricted matters at file opening, so everyone on the team knows the client's rule on day one.
  4. Keep a tool inventory with each provider's data terms, retention, and training settings, ready for disclosure requests.
  5. Set billing codes for AI-assisted work that follow each client's terms.
  6. Train the team on data categories rather than brands: client names and identifiers, personal information, deal terms, and privileged advice.
  7. Report incidents on the client's timetable. Guidelines may set their own notice periods. Align your incident process with them, and see the managing partner's 90-day checklist for building that process.

Sanitized Ai is a browser extension that gives a core clause, no client confidential information in public AI tools, a working control. When someone is about to submit client names, identifiers, personal information, or deal terms to one of the major AI assistants, it redacts or blocks that content before submission and explains in plain language what was flagged and why.

Administrators get a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) and never see prompt content. That gives the firm audit-ready records to support its answers when a client asks how its guidelines are followed in practice. See how it fits law firms.

Frequently asked questions

Can we agree to a clause that bans all generative AI on the client's matters?

You can, but only if you can actually comply. That means knowing which of your approved tools include AI features, telling everyone on the matter, and having some way to catch use of AI assistants on that client's information. If you cannot meet a blanket ban, negotiate for notice and consent instead of signing and hoping.

Is a vendor promise not to train on our data enough to satisfy a no-training clause?

It covers the approved tool, under the contract you signed. It does not cover a personal account someone opens in another browser tab. Clients usually care about where their information went, not only which tool the firm licensed.

How should we bill for AI-assisted work under these guidelines?

Follow the client's terms first. The Law Society of Ontario's guidance says any AI cost passed on as a disbursement must be fair, reasonable, disclosed in a timely way, and billed at actual cost. In the United States, ABA Formal Opinion 512 takes the view that lawyers may bill for time spent using and reviewing an AI tool but, in most circumstances, not for learning how to use it.

Do Canadian law societies require client consent before using AI?

Not as a blanket rule. Ontario's guidance ties disclosure to factors such as how the tool is used and whether it affects the client's interests or costs, BC's guidance treats consent as the route when client information cannot be removed, and the Barreau du Québec's guide recommends informed written consent. A client's guidelines can require more than your law society does.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

For your industry

Related guides

Further reading