For law firms
69% of legal professionals used AI last year. 9% of firms enforce a written policy.
Individual use of AI among legal professionals went from 31% to 69% in a single year, while 43% of firms have no formal AI policy at all and only 9% have a written policy that is actually enforced (8am Legal Industry Report, March 5, 2026). Fifty-four percent report no training and no plans to add any.
You are not deciding whether your firm adopts AI. That decision was made incrementally, by people who did not think they were making it, and the decision actually in front of you is whether the use inside your firm is documented or undocumented.
The obligation to do something about that is not new and did not arrive with a carrier questionnaire. ABA Formal Opinion 512, issued July 29, 2024, holds that under Rules 5.1 and 5.3 firm leadership must establish written policies governing generative AI use and supervise both lawyers and non-lawyer staff in that use. That duty is yours today.
What changed, and when
Two measurements, taken a year apart, tell the same story from different directions.
The 8am Legal Industry Report of March 5, 2026 put individual use at 69% and firm-level implementation of general-purpose AI at 46%. Set those next to each other: 69% of people are using something, 46% of firms have deployed something, and the difference is use nobody authorized. Its barrier list reads data security 46%, ethics 42%, privilege and trust 39%, cost 24%.
Thomson Reuters found the same picture from another angle in its 2025 GenAI in Professional Services Report, published April 15, 2025: law firm generative AI use nearly doubled from 14% to 26%, and 48% of firms lacked a formal policy.
The ABA's own 2024 Legal Technology Survey Report, published March 7, 2025, put AI use at 30% of lawyers overall and 30% at firms with 10 to 49 lawyers, with 75% citing hallucination risk as the top hesitancy.
Different instruments, different years, one direction. The use is arriving faster than the governance.
The duty attached in July 2024, not this year
Opinion 512 created no new rules. It explained which existing ones already reach generative AI, and one holding lands directly on firm leadership: managerial authority carries a supervisory duty, and that duty extends to this. Not "should consider." Not "as a best practice."
The rest of 512 fills in the shape. Rule 1.1 requires that a lawyer understand a tool's risks before using it — hallucination, disclosure, retention. Rule 1.6 requires assessing disclosure risk before entering client information and obtaining informed client consent for self-learning tools. Rules 1.4 and 1.5 require disclosing AI use when the client asks or when it bears on the reasonableness of a fee. And a lawyer may not bill client time for their own learning curve on a tool.
The Mid-Atlantic bars said narrower versions of the same thing before that: joint PBA/Philadelphia Bar Formal Opinion 2024-200 on June 18, 2024, the New Jersey Supreme Court Committee on AI Preliminary Guidelines of January 25, 2024, and the NYSBA Task Force on AI report approved April 6, 2024. Verify output, protect confidentiality, supervise. Four bodies, three states, one message.
A memo is not a policy, and the difference is enforceability
Most of what circulates as a "law firm AI policy" is a memo saying exercise professional judgment and do not put confidential information into public chatbots. That is good advice with no owner, no scope, no enumerated tools and no way to tell whether anyone complied.
Take the enumerated tool list as the test case. "Public chatbots are discouraged" cannot be complied with or breached, because nobody can say which products it names. "Consumer ChatGPT and consumer Claude are prohibited for any client information; the firm's paid business accounts are approved for non-client research; anything else requires an exception from the named owner" can be. One of those sentences produces an answer on a questionnaire. The other produces a conversation with an underwriter.
A policy that answers a carrier supplemental has seven parts: scope and definitions including AI features embedded in software you already own; an enumerated tool list by named product and permission tier; permitted and prohibited uses by work type; the client consent rule; the verification requirement; a named owner with the authority to switch a tool off, and an exceptions process; and incident response. Underneath all seven sits the acknowledgement register — who signed, on what date, against which version. Without it you have a document. With it you have a control.
The ban is the worst available answer
The instinctive partner response to 69% is prohibition. It is worse than doing nothing deliberately, because it does not reduce use — it converts documented use into undocumented use, which is exactly the gap the numbers describe. A prohibition nobody can enforce produces the same behaviour with none of the record, and the firm loses the one thing it could otherwise have shown a carrier.
What to do Monday
- Pull the last 90 days of expense reports and search for AI subscriptions. Do this before you answer anything on an application.
- Open your practice management, email and PDF vendors' admin settings and list the AI features already switched on by default.
- Put both lists into one table with columns for vendor, training on inputs, retention and approver. That is the start of your inventory.
- Name one person with the authority to switch a tool off. One person, not a committee.
- Write the verification step for work product containing legal authority. One page. It can be improved later; it cannot be improved if it does not exist.
What we will not do
We will not write you a policy that describes a firm that does not exist. A generic document with your letterhead asserts practices you do not operate, and the gap becomes the story the moment a carrier or a client's general counsel compares the policy to the practice.
Signet, a division of Circle Square Consulting. AI that holds up. Radnor, Pennsylvania. The Renewal Dry Run is free and takes 30 minutes: /renewal-dry-run