Lawyer's Learning Center with DHIA

AI in Law Firms: Risks, Rewards, and Responsibility – Part 2

Daniels-Head Insurance Episode 121

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 24:56

Artificial intelligence is quickly seeping into daily law firm workflows. While AI helps attorneys save time, boost efficiency, and improve client interactions, it also poses significant risks if not properly managed. 

In this episode, we cover 8 practical strategies to implement AI use responsibly, share a simple framework to build a strong AI policy, and discuss warning signs that it may be time to reevaluate your AI policy.

Whether your firm is already using AI or just beginning to explore it, this episode will help you responsibly use AI, protect client data, create internal AI policies, train your team, and minimize risk.

 

════════════════════

More Resources:

What can lawyers gAIn from Artificial Intelligence?

FAQs on ChatGPT for Solo and Small Law Firms

Balancing Legal Technology & Human Connection Guide

A Quarterly Mental Reset Guide for Lawyers

 
 
════════════════════

Join 5,700+ attorneys receiving exclusive tools, checklists, and practical legal risk management resources every month. Join Now & Stay Ahead: www.DHIA.com/Newsletter 

Stay connected with DHIA for updates on webinars, tools, and resources! https://linktr.ee/danielshead 

SPEAKER_00

Welcome to Lawyers Learning Center with DHIA, where we share practical attorney-focused insights to help law firms strengthen their practices, manage risk, and make more informed decisions about professional liability insurance. You'll find related resources in the show notes to help you stay informed in a changing legal and insurance landscape. Now let's dive into today's episode. Welcome to part two of AI in law firms, the risks, rewards, and responsibilities. Last week, we discussed why AI is becoming so difficult to ignore in law firms. The practical benefits of AI in a law practice, the biggest mindset shift that AI is an assistant, not the attorney. We also shared seven key liability risks related to AI in law firms. Today we are sharing eight practical strategies for implementing AI responsibly in your law practice, as well as a simple AI risk management framework and also some signs that your law firm may need a stronger AI policy. So let's dive in. The first strategy is to create a written AI use policy. Even a simple policy is better than silent, informal, inconsistent use. An AI policy could include approved AI tools, prohibited AI tools, allowed and prohibited use cases, confidentiality rules, human review requirements, including when and what requires attorney review, citations and research verification requirements, client disclosure guidelines, billing guidelines, documentation requirements, staff training expectations, and consequences for improper use? The policy should be clear enough that attorneys and staff know what to do in real situations. For example, questions like: Can staff use AI to draft a client email? Can an attorney paste deposition excerpts into an AI tool? Can AI be used to summarize discovery? Can AI access the firm's document system? Or what must be reviewed before anything leaves the firm? All these questions should not be answered casually, in the moment. They should be answered intentionally and built into your AI policy to avoid inconsistent AI usage and problems leading to liability risks. Strategy two is to classify AI tasks by risk level. Not all AI use carries the same risk. A low risk use would be things like brainstorming better workflow ideas, creating an internal meeting agenda, or improving the clarity of non-confidential administrative text. Moderate risk uses would be drafting general client education materials, creating intake templates, or summarizing non-confidential internal processes. A higher risk use might include legal research, contract drafting, case strategy, document review, discovery analysis, client-specific advice, or anything involving confidential information. And a very high-risk use case would be things like court filings, legal opinions, settlement strategy, privileged information, or autonomous communication with clients, courts, opposing counsel, or third parties. The higher the risk, the stronger the safeguards should be. Some measures to consider adding to an AI policy are no confidential information in public tools, independent legal research verification, client consent where appropriate, vendor security review, documentation of AI use, and final approval by the responsible attorney. These considerations give the firm a practical framework. So instead of asking, can we use AI every time? The question becomes, what is the risk level of this use and what safeguards are required? Which can be answered by simply checking the AI policy. The third strategy is simple but critical. Verify everything that matters. If the output includes law, facts, citations, analysis, deadlines, client information, risk assessments, or recommendations, it needs review. That means don't just accept the AI's answer because it sounds polished or correct. Check the citations in trusted legal research tools. Read the actual cases, confirm the statutes, rules, jurisdiction, and deadlines, and compare any summaries against the original documents. Then look at the final language through your own professional lens and ask whether anything is missing, inaccurate, out of context, or simply not the right fit for the client or matter. Human review is especially important because AI can sound confident even when it's wrong. So don't ask, does this sound good? Ask, is it accurate, complete, current, and appropriate for this client and this matter? That is a much stronger standard that supports risk management and loss prevention. The fourth strategy is to protect confidential information by default. A strong rule and best practice is to not enter confidential client information into an AI system unless the firm has approved that tool for that use and the attorney understands the confidentiality and security implications. That includes client names, case facts, privileged communication, medical and financial information, legal strategy and settlement discussions, draft pleadings, discovery materials, contracts, internal firm documents, or any information that could identify the client or matter. If a firm wants to use AI with client confidential information, it should evaluate the tool carefully. Thoroughly review the vendor, security and privacy controls, data retention, and where appropriate, client consent requirements and best practices. This review is important to avoid accidentally exposing client information and ultimately exposing yourself and your law firm to liability claims or reputational damage. Strategy number five is training. A policy is only useful if people understand it. AI training should cover what AI can and cannot do, common risks, including hallucinations and outdated information, confidentiality rules, approved tools, prohibited uses, how to verify outputs, when attorney review is required, how to document AI use, and what to do when someone is unsure. Training should also be repeated regularly because AI tools change so quickly. A policy written and trained on once can become outdated fast, even by the next year. Make AI training part of the firm's ongoing risk management process and make it practical. Use real examples like can I paste this client email into AI? Can I ask AI to summarize this deposition? Can I use AI to draft a motion? Or what if the client asks whether we use AI? The goal with creating an AI policy and training the team on it is not to make everyone afraid or make it feel overwhelming. The goal is to help everyone make better decisions and protect the firm and their clients. Strategy six is to think intentionally about disclosure. This will depend on the matter, the client, the tool, the jurisdiction, the type of work, and the level of AI involvement. But firms should consider whether engagement letters or client communications should address AI use. A simple AI provision might say that the firm may use technology tools to support efficiency and quality, but the attorney remains responsible for all legal advice and final work product. It should also reassure clients that confidential information will be handled in line with professional obligations. AI will not replace attorney judgment, and any client-specific AI costs will be disclosed when required. The wording should be tailored to the firm's actual practices. Don't promise safeguards the firm does not have or vaguely disclose something without understanding it. And do not assume that clients won't ever ask about your firm's use of AI. Clients are also becoming more aware of AI and more curious about where their personal data is. A clear explanation can build trust and also make the client feel like they have an option when it comes to their personal information being put into an AI tool. A vague or defensive answer about AI use can create distrust and cost a client. Practical strategy number seven is to use AI where it strengthens systems, not where it replaces judgment. Some of the best AI use cases may not be the flashiest. They're often focused on operational efficiency. Things like creating intake checklists, drafting internal workflow process templates, summarizing firm policies, creating client education outlines, improving plain language explanations, building FAQ documents, standardizing status update templates, organizing marketing content ideas, reviewing internal processes for gaps, or helping create task checklists for repeatable work. These uses can support consistency without handing over legal judgment. That is a powerful place to start. A firm doesn't need to use AI for the highest risk legal work first to be efficient or considered technologically advanced. In fact, it's smarter to start with lower-risk, high-friction workflows. Think about workflows that are repeated often or take extra time, but don't require legal judgment, or where clients need clearer explanations. Consider workflows where staff recreate the same language or documents, where templates could improve consistency and efficiency, or where AI could help create a better first draft faster for attorney review. This approach offers a more strategic way to implement AI, reducing risks and saving even more time. Start where the benefits are real, but the risk is manageable. The eighth and final strategy is documentation. If your firm uses AI, document the governance around that use. It's important. This might include the firm's AI policy, approved tools, vendor assessments, training materials, client disclosure language, billing guidance, verification procedures, and updates to policies over time. Documentation matters because it shows the firm is not using AI casually or carelessly. It shows intention. It shows supervision. It shows that the firm thought through confidentiality, accuracy, client communication, and professional responsibility. And if a question ever arises later, documentation can help demonstrate that the firm had reasonable safeguards in place. Documenting your firm's AI governance thoroughly may be the safety net needed to protect your practice. So if we had to simplify this into one practical framework, here it is. Before using AI in a law practice, ask these seven questions. One, what tasks are we using AI for? Is it administrative, marketing, drafting, research, client communication, analysis, or legal strategy? Question two, what information are we putting into the tool? Is it confidential, privileged, sensitive, client identifying, or is it public information? Three, what tool are we using? Is it approved by the firm? Do we understand its terms, privacy, security, and data practices? Four, what can go wrong if the output is inaccurate? Could it affect advice, deadlines, filings, client expectations, billing, or professional duties? Question five, who will review and verify the output? Six, does the client need to know? Would AI use materially affect the representation, costs, confidentiality, or decision making? Question seven, how will we document the process? Is there a policy, checklist, a disclosure, or review step? These questions can help move from casual to responsible AI use. And that's what this conversation is really about. Not fear, not hype, responsible, intentional AI adoption. Before we wrap up, let's quickly go over a few warning signs that your firm may need a stronger AI policy. Your firm may need more structure or clarity if attorneys and staff are using different AI tools without approval. If people are unsure whether they can enter client information into AI, if AI-generated content is being used without review, no one is checking citations or legal authority, staff are using AI for client communications without clear guidelines or review. If the firm has not addressed AI in billing practices, if no one has reviewed vendor privacy or data security terms, or if it's been a while, if the firm has no training on AI risks or recent trainings, or if leadership doesn't know how AI is currently being used across the practice. If any of these sound familiar, it's time to evaluate and develop a safer, clearer system. Like many risk management challenges, the aim isn't perfection, it's awareness, it's structure, and consistent follow-through. To recap both parts one and two of AI and law firms, AI can be a valuable tool for law firms. It can help reduce administrative burden, improve communication, support drafting, organize workflows, and create better systems. But AI also carries real risks, both obvious and hidden risks. The biggest risks include inaccurate or fabricated information, confidentiality and data security concerns, over reliance on AI output, loss of professional judgment, lack of client communication or consent, inadequate supervision, billing and fee issues, bias, incomplete context, and poor fit, and inconsistent use across the firm. The key takeaway is that AI does not change the attorney's professional responsibilities. It increases the need to manage them intentionally. At the end of the day, AI doesn't take away the attorney's core responsibilities around competence, confidentiality, candor, reasonable fees, supervision, clear communication, and independent professional judgment. It may help a firm work faster, but that speed only matters if the work still remains accurate, ethical, confidential, and client-centered. So if your firm is using AI or just thinking about it, start with structure. Create a policy, train your team, protect client information, verify legal outputs, review billing practices, disclose thoughtfully when appropriate, and keep the attorney, not the technology, in control of the final work. That is how law firms can use AI, not as a shortcut, but as a responsible tool for stronger service, better systems, and smarter risk management. Thank you for listening to Lawyers Learning Center with DHIA. We hope today's episode provided you with useful ideas and insights to strengthen your practice, serve your clients effectively, and manage risks with greater confidence. If you found this episode helpful, subscribe, share it with a colleague, or leave a review so more legal professionals can find the show. For more resources related to today's topic, visit the links in the show notes or go to dhia.com slash podcast. Until next time, keep learning, keep growing, and keep moving your practice forward.