The firm AI policy: what the regulators expect in it.
The December 2024 joint statement contains the closest thing to a to-do item in all the guidance: firms using AI should implement clear, risk-based policies, and the regulators recommend making them available to clients on request. The Law Society of NSW guide adds the machinery around it: evaluate existing risk frameworks before adopting tools, educate staff, and keep human oversight present at every level of the organisation. This page turns those expectations into a working outline.
General information only. This guide summarises published regulatory guidance and is not legal advice. Read the primary sources linked throughout, and take professional advice on your firm’s specific position.
What the regulators say the policy must cover
Which AI tools the practice has decided to use. Everything else is by implication unapproved, which is what makes the list enforceable.
Who may use each tool, for which tasks, and with which categories of information. The confidentiality rules for client information go here, in plain words.
The statement expects lower-risk, easily verified tasks to be permitted and higher-risk ones restricted or prohibited. Drafting a routine email sits at one end; analysing an unfamiliar legal concept or anything approaching a decision sits at the other.
How junior and support staff use is continuously and actively supervised, and by whom. Our supervision guide covers what this means in practice.
How documents containing AI-generated content are reviewed for accuracy and verified before they are settled, and who signs off.
How AI use is recorded per matter, and the commitment to disclose it, and the policy itself, to clients on request.
Risk-based means written for your practice
The regulators asked for risk-based policies, which is a quiet warning against downloading a generic one. A conveyancing practice, a criminal firm and an in-house team have different high-risk tasks, different client sensitivities and different tools, and the policy the guidance contemplates is the one that describes your practice accurately. The fastest way to write a bad policy is to ban things staff demonstrably do; the supervision problem moves underground and the document becomes evidence of a rule the firm knew about and did not enforce.
Training belongs in the policy
The guide’s summary is blunt: educating employees on the risks and benefits of generative AI is essential, and gaps in understanding are where breaches start. A short session covering why public tools and client information cannot mix, what hallucinations are, and how verification works in your firm covers most of the regulatory surface. The guide also suggests prompt training for approved tools, which doubles as the positive half of the message.
Where deployment posture fits
Policy and architecture reinforce each other. A policy is easiest to follow when the approved path is also the convenient one, which is the practical case for an approved internal AI: the rule about public tools stops fighting convenience, and the review, supervision and record expectations attach to one visible system. The policy still has to exist in writing; the regulators asked for the document, and clients are entitled to ask for it too.
Common questions
Is a law firm AI policy mandatory in Australia?
Should clients be able to see our AI policy?
How often should the policy be reviewed?
See Dominion answering from your own documents.
A demonstration takes 30 minutes, uses no client data, and comes with no obligation.
Book a demo