The full template. Highlighted blanks fill in when you
Personalize; whatever's left stays a [bracket] for you to complete.
Purpose
Generative AI tools can help [Short Name] draft communications, summarize documents, research issues, and work more efficiently. They also create real risks: confidential client information can be exposed, outputs can be inaccurate, and misuse can violate professional and regulatory obligations. This policy sets clear rules so staff can use these tools productively while protecting our clients and the firm.
Scope
This policy applies to all partners, employees, contractors, and temporary staff of [Organization Name] who use any generative AI tool for firm work. "Generative AI" means any system that produces text, code, images, audio, or analysis from prompts — including chatbots, writing assistants, and AI features built into other software. It applies whether the tool is accessed on firm devices, personal devices, or through another application.
Approved Tools
Staff may only use generative AI tools that the firm has reviewed and approved. Currently approved tools are: [Approved AI Tools].
- Do not use unapproved consumer AI tools for firm work, even free ones you already have accounts on.
- Before using a new AI tool, or a new AI feature inside existing software, get written approval from [AI Tool Approval Contact].
- Prefer firm-licensed or enterprise versions that contractually agree not to train on our data and offer appropriate security controls.
Protecting Client and Firm Information
This is the most important rule in this policy. Never enter confidential client information or sensitive firm data into a public or unapproved AI tool. Content submitted to consumer AI services may be stored, reviewed by the vendor's staff, or used to train future models — placing it outside our control.
Do not paste or upload the following into any AI tool unless it is a firm-approved tool with a signed data-protection agreement:
- Client names tied to financial details, Social Security numbers, EINs, or account numbers
- Tax returns, working papers, financial statements, or source documents
- Any personally identifiable information (PII) or nonpublic personal information
- Passwords, credentials, or firm-internal confidential materials
When in doubt, treat information as confidential and leave it out. If you need AI help with client-specific work, de-identify the material first or use only an approved tool cleared for that data.
Prohibited Uses
Generative AI must not be used to:
- Make final professional judgments — such as signing positions, audit conclusions, or advice — without qualified human review.
- Generate work you present as your own analysis without verifying it.
- Create misleading, deceptive, or fabricated content, including fake citations or authorities.
- Circumvent confidentiality, security, or licensing obligations.
- Produce content that is discriminatory, harassing, or otherwise violates firm conduct standards.
Human Review and Accuracy
Generative AI can produce fluent output that is wrong, outdated, or invented. The staff member using the tool is fully responsible for the accuracy and quality of any work product, regardless of AI involvement.
- Independently verify all facts, calculations, citations, and tax or accounting positions before relying on them.
- Treat AI output as a first draft or research aid, never as an authoritative answer.
- Apply the same professional standards, due care, and skepticism you would to your own work.
Disclosure
Be transparent about material AI use consistent with our professional obligations and client expectations. [Client Disclosure Standard] When a client asks whether AI was used in their work, answer honestly.
Roles and Responsibilities
- [Policy Owner] ([Owner's Title]) owns this policy, maintains the approved-tools list, and answers questions.
- Supervisors ensure their teams follow this policy and review AI-assisted work product.
- All staff protect client data, verify AI output, and use only approved tools.
Direct questions to [Policy Owner] at [Contact Email].
Employee Acknowledgment
By using generative AI tools for firm work, staff acknowledge they have read, understood, and agree to follow this policy. A signed acknowledgment may be required as a condition of access.
Enforcement
Violations may result in loss of AI tool access and disciplinary action up to and including termination. Exposing client data may also trigger breach-response and regulatory obligations.
Review and Revision
Given how fast AI technology changes, [Policy Owner] will review this policy at least annually, and sooner if tools or regulations change. This policy is effective [Effective Date] and is scheduled for review by [Firm's Next Review Date]. This template is a starting point; adapt it to your firm's tools, clients, and legal requirements.