The firm AI policy: what the regulators expect in it.

The December 2024 joint statement contains the closest thing to a to-do item in all the guidance: firms using AI should implement clear, risk-based policies, and the regulators recommend making them available to clients on request. The Law Society of NSW guide adds the machinery around it: evaluate existing risk frameworks before adopting tools, educate staff, and keep human oversight present at every level of the organisation. This page turns those expectations into a working outline.

General information only. This guide summarises published regulatory guidance and is not legal advice. Read the primary sources linked throughout, and take professional advice on your firm’s specific position.

What the regulators say the policy must cover

The approved tool list

Which AI tools the practice has decided to use. Everything else is by implication unapproved, which is what makes the list enforceable.

Users, purposes, information

Who may use each tool, for which tasks, and with which categories of information. The confidentiality rules for client information go here, in plain words.

Risk tiers

The statement expects lower-risk, easily verified tasks to be permitted and higher-risk ones restricted or prohibited. Drafting a routine email sits at one end; analysing an unfamiliar legal concept or anything approaching a decision sits at the other.

Supervision

How junior and support staff use is continuously and actively supervised, and by whom. Our supervision guide covers what this means in practice.

Review and verification

How documents containing AI-generated content are reviewed for accuracy and verified before they are settled, and who signs off.

Records and client transparency

How AI use is recorded per matter, and the commitment to disclose it, and the policy itself, to clients on request.

Risk-based means written for your practice

The regulators asked for risk-based policies, which is a quiet warning against downloading a generic one. A conveyancing practice, a criminal firm and an in-house team have different high-risk tasks, different client sensitivities and different tools, and the policy the guidance contemplates is the one that describes your practice accurately. The fastest way to write a bad policy is to ban things staff demonstrably do; the supervision problem moves underground and the document becomes evidence of a rule the firm knew about and did not enforce.

Training belongs in the policy

The guide’s summary is blunt: educating employees on the risks and benefits of generative AI is essential, and gaps in understanding are where breaches start. A short session covering why public tools and client information cannot mix, what hallucinations are, and how verification works in your firm covers most of the regulatory surface. The guide also suggests prompt training for approved tools, which doubles as the positive half of the message.

Where deployment posture fits

Policy and architecture reinforce each other. A policy is easiest to follow when the approved path is also the convenient one, which is the practical case for an approved internal AI: the rule about public tools stops fighting convenience, and the review, supervision and record expectations attach to one visible system. The policy still has to exist in writing; the regulators asked for the document, and clients are entitled to ask for it too.

Common questions

Is a law firm AI policy mandatory in Australia?
The regulators' statement says firms using AI should implement clear, risk-based policies, framed as an expectation flowing from principals' supervision obligations rather than a standalone rule. A firm whose staff use AI without one is exposed on supervision grounds under rule 37 and s 34 if something goes wrong.
Should clients be able to see our AI policy?
The regulators recommend making the policy available to clients on request, as part of transparency about AI use. Several firms go further and summarise their approach in engagement materials, which tends to pre-empt the concern rather than invite it.
How often should the policy be reviewed?
The regulators have committed to updating their own guidance as AI evolves, and the NSW guide is already on a substantially updated version. Reviewing the firm policy on an annual cycle, and whenever tools change or new guidance lands, matches the pace the regulators themselves have set.

See Dominion answering from your own documents.

A demonstration takes 30 minutes, uses no client data, and comes with no obligation.

Book a demo