Two documents arrived within a month of each other this summer, and together they raise the bar for what counts as an AI policy at a law firm.

The first came from the International Legal Technology Association and the Thomson Reuters Institute, which co-published the AI Guide for Legal Professionals: A Foundational Overview on June 29. The second came from the Alabama State Bar, whose Office of General Counsel issued Formal Opinion 2026-01, Artificial Intelligence Use: Best Practices Under Existing Professional Conduct Rules.

Both are addressed to attorneys and framed in terms of professional responsibility. Read the recommendations closely, though, and you will find that most of them describe technology that has to be evaluated, licensed, configured, documented, and monitored. That is systems work, and it tends to land on the firm administrator who is already carrying more than the job description covers.

You shouldn’t have to become an authority on state bar ethics opinions to keep your firm’s technology in good standing. Here is what the new guidance actually asks for, and how we handle it.

The guidance applies existing duties to new tools

The Alabama opinion makes a point worth understanding before anything else: artificial intelligence creates no new ethical duties. What it does is place familiar obligations — competence, confidentiality, supervision, candor, reasonable fees, and client communication — inside a technological environment where they behave differently than they used to.

That framing matters because it removes the option of waiting for a future rule. The duties already apply; they apply to every attorney using an AI tool on a client matter, and the opinion is explicit that they apply equally to solo practitioners, small firms, and large firms.

We walked through the underlying principles in A Practical Framework for Using AI Safely in Your Law Firm and in Turning AI Policies into Action. What the new guidance adds is detail, and the detail is operational.

What the guidance asks for, in operational terms

Tool selection is treated as a competence question. The opinion states that choosing an AI tool without evaluating its accuracy or its data-retention practices may itself fall short of the duty of competence. We perform and document that diligence on every tool before it touches a client matter, and we revisit it as products change, so your firm can show its work if the question is ever raised.

Enterprise and free consumer versions are not the same product. The guidance draws a clear line between them because enterprise agreements typically prohibit providers from training on your inputs, whereas free versions typically do not. Acting on that distinction takes licensing, provisioning, and visibility into what people are actually using. We manage all three, which means client information stays inside systems that are safe, secure, and reliable rather than flowing somewhere nobody intended.

Written policy must name specific tools and tasks. Approved tools, permitted uses, required verification steps. The opinion goes further, suggesting centralizing tool approval across the firm and designating a point person to vet tools and maintain usage records. We build the policy and take on the vetting and record-keeping behind it, so the approval process runs without adding another standing obligation to your week.

AI records may be discoverable, so retention has to account for them. Prompts, drafts, and interaction logs can be subject to production under some circumstances, and the opinion recommends documenting which tool was used on a matter, what it was asked to do, and what verification the supervising attorney performed. Most retention policies were written before any of this existed. We extend your existing policy to cover it, keeping one framework in place instead of two.

Agentic tools need a human checkpoint and an audit trail. This is where the guidance reaches furthest. For tools that plan and carry out multi-step tasks on their own — drafting a response, sending it, calendaring a deadline, updating the case management system — the recommendations include defining in writing what the tool may do unattended, requiring review before it acts, and regularly auditing its activity logs. The opinion also suggests asking vendors directly what safeguards and audit trails their agentic products include. We ask those questions during evaluation and set up the logging and review protocols, so autonomy stays within the boundaries your firm chose.

Every item on that list is technology work sitting inside an ethics document. Handling it is what we’re here for.

A good industry guide is still not your firm’s policy

The ILTA and Thomson Reuters guide is worth reading. It covers the current state of adoption, the categories of available tools, how they apply across research, drafting, document review, eDiscovery, and administrative workflows, and the accuracy and professional responsibility risks associated with each.

It also describes itself accurately. The announcement calls it a “primer, not a playbook.”

That distinction is worth sitting with. A primer explains the landscape. It cannot tell you which tools your firm has approved, which practice groups may use them and for what, where your client data travels when someone opens a chat window, who reviews agentic output before it leaves the building, or how long the logs are kept. Those answers depend on your matters, your clients, and your systems, and adopting someone else’s framework as your own policy leaves open exactly the gaps the guidance is warning about.

Closing those gaps is the work. We do it alongside your team.

A practical sequence for this quarter

  1. Find out what is already in use. Before any policy is written, we identify which AI tools attorneys and staff have adopted on their own and on which accounts, so the policy reflects how the firm actually operates.
  2. Sort the tools into approved, restricted, and prohibited. Then we make the approved path the easy one. Adoption follows convenience, so a well-provisioned, approved tier does more for compliance than a strongly worded memo.
  3. Set the verification and documentation standard. Who reviews AI-assisted work, what gets recorded on a matter, and how long those records are held. We fold this into your existing retention policy rather than standing up a parallel one.
  4. Treat agentic tools deliberately. We define in writing what any autonomous tool may do without a person in the loop, and confirm that its activity can be audited.

We’ve got your back on this

Firm administrators carry the weight of technology problems that are outside their expertise, and they are held responsible when something goes wrong, even when the cause lies elsewhere. That is a preventable problem, and you deserve better.

Innovative Computing Systems has worked exclusively with law firms and corporate legal departments since 1989, and today more than 100 firms nationwide rely on us. Managed Intelligence is the part of our work devoted to helping firms adopt and operationalize AI in a structured, secure, and practical way: tool evaluation, acceptable-use policy, approved-tool lists, data-handling rules, training, and the logging and review protocols that keep a policy working after the first month. Our support team is 100% U.S.-based and available 24/7/365, so when a question comes up about a tool, a log, or a policy exception, you reach someone who knows your firm.

More guidance is coming. Additional states will issue opinions, and existing ones will be revised as agentic tools mature. When your firm already has an inventory, a policy, and a review process running, each new opinion becomes a small adjustment we make on your behalf rather than a project that pulls you away from hiring, culture, and the work that actually moves the firm forward.

If you’d like to talk through where your firm stands today, request a consultation, and set up a conversation with our team.