
Yes. Your firm should use AI. But probably not for the thing the vendor demo showed you, and never in the places where a mistake lands on a client.
We’ve done legal AI consulting work, and the question we get first is almost always the same one. Is this safe? The honest answer is that AI is as safe as the rules you put around it. Most of the risk comes from firms that skipped the rules, not from the technology.
Where AI actually helps a small firm
The best uses are the unglamorous ones. Work that eats hours, follows a pattern, and gets checked by a lawyer anyway.
First drafts of routine documents
Engagement letters, standard correspondence, intake summaries, status updates to clients. AI produces a solid first draft in seconds. A lawyer reviews and edits it, which is what happens with a paralegal’s draft today. The draft just shows up faster.
Summarizing what’s already in the file
Long email chains, deposition transcripts, a stack of records from a new client. AI is good at reading a lot and telling you what’s there. It’s a starting map, not a finding, and it gets verified against the source.
Intake and the front office
Sorting inquiries, drafting responses to the routine questions, getting the right information from a prospective client before anyone schedules a call. This is ordinary office automation, and a law firm’s front desk has as much of it as anyone’s.
Marketing and the website
Practice area pages, a blog that actually gets written, a newsletter. Held to the same standard as any other public statement by the firm, and reviewed like one.
Where AI must never go unsupervised
This part is not negotiable.
Legal research you don’t verify. AI models can produce case citations that look perfect and do not exist. Lawyers have been sanctioned for filing briefs with invented cases in them. Every citation, every quote, every holding gets checked against the actual source. Every time.
Legal judgment. Whether to settle. How to advise a client. What a clause really means for this deal. AI can lay out considerations. It can’t carry the responsibility, and it shouldn’t pretend to.
Anything sent to a client without a lawyer reading it. Not an email, not a letter, not a summary. The firm’s name is on it and so is the lawyer’s license.
We write more about this in What AI Can’t Do. The short version: AI does the work, a person signs off, and in a law firm that person needs to be a lawyer.
Confidentiality is the real question
Most firms worry about AI getting the law wrong. The bigger risk is where client information goes.
When someone pastes a client’s file into a free consumer chatbot, that information may be stored, reviewed, or used to train the model, depending on the product and the settings. That’s a confidentiality problem before anyone reads the output.
The questions to answer before any tool touches client data:
- Where does the data go, and who can see it?
- Is it used for training? Business and enterprise tiers of the major tools often let you turn this off or exclude it by default. Consumer tiers often don’t. Read the actual terms.
- Is there a written agreement covering it? Treat an AI vendor the way you’d treat any other vendor handling client files.
- Do your clients need to know? Bar guidance on AI generally touches on communication with clients. The ABA has issued formal guidance on generative AI, and many state bars have followed. Check what applies in your jurisdiction.
We’re not your ethics counsel, and this isn’t legal advice. But in our consulting work, sorting out data handling came before any tool got chosen. It should for you too.
How to start without risking anything
Here’s the order we’d recommend for most small firms.
- Write a one-page AI policy. Which tools are approved. What data can and cannot go into them. Who reviews output. Keep it short enough that people actually read it.
- Pick one internal, low-risk task. Summarizing internal meeting notes, drafting marketing content, cleaning up intake forms. Nothing that touches privileged material yet.
- Use a business-grade tool with training turned off. Pay for it. Free tools are paid for some other way.
- Review everything for a month. Learn where it’s reliable and where it drifts.
- Then expand, one task at a time.
That’s slower than a vendor would like. It’s the pace that doesn’t end with a malpractice call.
If you want a broader starting point that isn’t legal-specific, our Small Business AI Readiness check walks through ten questions any office can answer in an afternoon.
What we do for firms
We assess the workflow first. Where the hours actually go, which tasks follow a pattern, and where confidential data lives. Then we map which pieces AI can handle safely and which stay with people. Sometimes the answer is a handful of automations and a policy document. Sometimes it’s a new website and an intake process that stops losing leads. Sometimes the right advice is to wait on a tool until it’s ready.
We run our own studio on AI, directed by a human principal who reviews every output. That’s the same model we’d put in place at a firm, with a lawyer in the reviewer’s chair. You can see how the whole process works on our How It Works page.
The straight answer
Use AI for drafting, summarizing, intake, and marketing. Verify everything. Keep client data out of consumer tools. Keep legal judgment with lawyers. Start small and write the rules down before you start.
Firms that do that will get real hours back. Firms that skip it will end up in the news for the wrong reason.
If you’d like a clear-eyed read on where AI fits in your practice, start the conversation here.
