Why rollouts stall after everyone has agreed
The familiar pattern is not disagreement. Leadership accepts that AI use needs structure, someone drafts a policy, it goes to a committee, and then little operational happens while people carry on using whatever they were using.
Two things account for much of it, and neither is fixed by writing a better document.
The first is structural. In a partnership the people who would have to comply are the people who own the firm. An associate can be told; an equity partner is being asked. A rollout designed as an instruction meets a governance structure that does not take instructions, which is why a sensible sequence produces something partners find useful before it produces something that constrains them.
The second is that a policy which only restricts arrives as a tax. If several things are now forbidden and nothing is now available, what tends to follow is not compliance but the same use, less visible. That is worse than the starting position, because the firm has lost sight of where client information is going while believing it has addressed the problem.
There is also a question of whose job this is. ABA Formal Opinion 512 reads Model Rules 5.1 and 5.3 to mean that “[m]anagerial lawyers must establish clear policies regarding the law firm’s permissible use of GAI, and supervisory lawyers must make reasonable efforts to ensure that the firm’s lawyers and nonlawyers comply with their professional obligations when using GAI tools.” Model Rule 5.1(a) itself reaches a partner in a law firm and any lawyer who possesses comparable managerial authority. Whatever else that duty is, it is not one the IT director can discharge, because the questions it turns on are confidentiality and supervision questions rather than technical ones.
On where firms actually are, the survey evidence is softer than it is usually presented, and it is worth showing rather than picking from. Clio’s 2026 report on mid-sized firms found that 86% report using AI and 60% report having formal policies guiding AI use. The 8am 2026 report found that 43% of respondents said their firm has no formal AI policy and no plans to create one, 24% are developing one, and 9% have one in place and actively enforce it. Those three add to 76, and 8am does not break out the remaining quarter in its public release. One plausible reading of the remainder is firms with a policy they do not actively enforce, which if right is the group this article is about, but the release does not say and it could as easily be non-response.
Sources: Clio 2026 Legal Trends Report for Mid-Sized Law Firms. Clio’s figures come from a survey of more than one thousand US legal professionals, including lawyers, paralegals and administrative staff, drawn from both an independent market panel and Clio’s own customers. Its mid-sized report series defines mid-sized law firms as those with 21 or more employees, compared to smaller firms of 20 or fewer, and states no upper bound. 8am 2026 Legal Industry Report, conducted online September to October 2025, more than 1,300 responses across a broad range of roles, firm sizes and practice areas, respondents primarily based in North America.
Two instruments, different populations, different questions, and neither is a number to plan around. What survives the comparison is the distance both describe: between a policy existing and a policy operating. An AI policy is not AI governance.
First, which rules actually bind your firm
Opinion 512 is advisory, and the ABA Model Rules bind no lawyer until a jurisdiction adopts them. What a rollout is measured against comes from three places, and they should be established before the policy is drafted.
Your state’s rules of professional conduct, which may differ structurally and not only in numbering. Texas is the clean example: its Professional Ethics Committee analyzed generative AI in Opinion 705 in February 2025 under the Texas Disciplinary Rules, where the confidentiality provision is Rule 1.05 rather than Model Rule 1.6.
Your state or city bar’s ethics opinions, which are moving faster than the ABA. Opinion 512 itself relies on Florida’s Opinion 24-1 from January 2024 and on the Pennsylvania and Philadelphia joint opinion of the same year. Since then the New York City Bar has issued two opinions on recording, transcribing and summarizing conversations: one covering clients in December 2025, and a companion in August 2026 covering non-clients, which reaches co-counsel, prospective clients, opposing counsel, witnesses, and the attorney’s own employees and agents such as investigators. Prospective clients is the one to notice, because it lands on intake.
In California, the State Bar’s professional responsibility committee approved proposed amendments to six rules on March 13, 2026: 1.1, 1.4, 1.6, 3.3, 5.1 and 5.3. Two of the six matter here. A proposed comment to rule 1.1 would state that a lawyer “must independently review, verify, and exercise professional judgment regarding any output generated by the technology that is used in connection with representing a client.” And a proposed comment to rule 5.1 would address managerial lawyers’ obligation to make reasonable efforts to establish internal policies and procedures governing AI use, which moves that duty from an advisory opinion into a state rule’s official commentary. Status as of this writing: approved for comment, comment period closed, package pending.
The courts you appear in. This is the one most firms miss, because it is not an ethics question. New York’s Unified Court System added 22 NYCRR Part 161 effective June 1, 2026. Its statewide policy is that AI use in preparing papers “should not be prohibited,” so long as the use accords with the duties and responsibilities that already apply to anyone submitting papers to a court, and that attorneys and parties “should not be required, upon submitting papers, to disclose to the court that they have used AI in the preparation of such papers.” It then leaves it to each court, “in its discretion,” to adopt a part rule, and encourages courts that do to use the model rule in Appendix A, under which the signature on a filing certifies that the filer independently reviewed it for fabricated or fictitious material. So the operative standard varies from court to court within one state, and tracking it is somebody’s job.
None of that is a reason to wait. It is a reason to know, before drafting, which text the policy has to satisfy.
The order is forced, and it is not a calendar
Rollout guidance is usually organized as thirty, sixty, and ninety days. That is a convenient shape and the wrong one, because it implies the steps are independent and can be scheduled. Most of them consume the output of the step before.
The chain runs like this. The inventory tells you which tools exist. The facts about each tool, principally whether it trains on inputs, determine which confidentiality analysis applies. That determines what the rule about inputs can say. The rule about inputs, plus the tool list, is what makes risk tiers assignable rather than theoretical. Tiers determine what the approval route has to handle and who signs off at each level. Only then is there anything specific enough to train people on, or to show a client.
Run it in a different order and the work is redone. A confidentiality rule written before anyone has read the vendor terms will say something like “do not enter confidential information into unapproved tools,” which resolves nothing for the person deciding at five in the afternoon. Training delivered before the register exists teaches principles with nothing to attach to.
So what follows is an order of operations, not a schedule.
Step one: find out what is in use, and settle the amnesty question first
Every rollout begins with an inventory, and this is where many stall, for a reason that is rarely stated.
The answer may include things the firm would rather not know. Where a firm has not governed this yet, it is reasonable to expect that some client material has gone into a consumer tool. Asking converts a suspicion into a record, and a record has consequences.
So the firm has to decide, before it asks, what happens to what it finds. If the exercise is a look-back with consequences attached, people answer narrowly and the inventory comes back wrong, which is the worst outcome available: the political capital is spent and the firm still cannot see where its information went. If the exercise is explicitly a line-drawing, the answers come back usable. That decision belongs to the managing partner, should be made once, and should be communicated in a sentence. Something close to: We are documenting what is in use so we can govern it. Tell us what you have used. From the date the policy takes effect, the rules apply.
Two cautions on that sentence, and they are the reason it should be cleared with the firm’s own counsel before it is circulated rather than drafted from an article. First, an amnesty the firm offers its own people cannot displace duties that run elsewhere: client communication obligations if something disclosed amounts to a confidentiality incident, breach-notification clauses in a client’s outside counsel guidelines, any applicable data-breach statute, and reporting duties under the state’s analogue to Rule 8.3. Second, the firm should decide in advance how it will handle a disclosure serious enough to trigger any of those, because discovering that mid-exercise is the worst possible moment.
There is a related question the inventory raises and Opinion 512 does not answer. The opinion requires informed consent prior to inputting information relating to a representation into a self-learning tool. It says nothing about what a firm owes a client whose information already went in before any of this existed. That is a real question with client-relationship and professional-responsibility dimensions, it is jurisdiction-specific, and it is one to put to counsel and to the firm’s carrier rather than to resolve internally.
Two practical points on the asking. Ask about tasks, not tools, because people do not think of the summarize button in the meeting platform, the drafting assistance in the word processor, or the AI features in the research subscription as AI tools. They think of ChatGPT. Those embedded features carry volume the firm has already paid for. And ask by practice group, because the pattern of use in a transactional group looks nothing like litigation.
Step two: the facts about each tool, and the register they become
Four questions determine what the firm can do with any given tool. The first comes from Opinion 512’s confidentiality analysis. The other three are among the four diligence items the opinion relays from earlier cloud computing and outsourcing opinions, introduced with the phrasing that those opinions “suggest that lawyers should”.
Does it train on inputs? This is the fork. Opinion 512 states that “because many of today’s self-learning GAI tools are designed so that their output could lead directly or indirectly to the disclosure of information relating to the representation of a client, a client’s informed consent is required prior to inputting information relating to the representation into such a GAI tool.”
An important limit on that fork, because it is easy to over-read. It governs the Rule 1.6 informed-consent question and nothing else. Opinion 512 still requires a risk analysis for every tool before information relating to a representation goes into it, and Rule 1.4 imposes separate client-communication duties that attach regardless of whether the tool learns: if the client asks, if the engagement agreement or the client’s outside counsel guidelines require it, if the use is relevant to the basis or reasonableness of the fee, and where output “will influence a significant decision in the representation,” such as reliance on the tool to evaluate potential litigation outcomes or jury selection. A firm that concludes “not self-learning, therefore no client conversation” has skipped five separate questions.
What happens to the data, and when? The suggestion is to “determine whether the [GAI tool] retains information submitted by the lawyer before and after the discontinuation of services or asserts proprietary rights to the information.”
What is the notice obligation? To “ensure that the [GAI tool] is configured to preserve the confidentiality and security of information, that the obligation is enforceable, and that the lawyer will be notified in the event of a breach or service of process regarding production of client information.” A vendor that receives a subpoena for material the firm put into it, and is not obliged to tell the firm, is a specific and checkable problem.
What are the limits on liability, and where would you sue? To “investigate the [GAI tool’s] reliability, security measures, and policies, including limitations on the [the tool’s] liability,” and, from the outsourcing opinions carried forward, “the availability and accessibility of a legal forum for legal relief for violations of the vendor agreement.” The fourth diligence item is a posture rather than a question: understand that provider servers “are subject to their own failures and may be an attractive target of cyber-attacks.”
These are contract questions with factual answers, and they take longer than firms expect because they depend on vendors and on careful reading. Opinion 512’s instruction is that “[a]s a baseline, all lawyers should read and understand the Terms of Use, privacy policy, and related contractual terms and policies of any GAI tool they use to learn who has access to the information that the lawyer inputs into the tool or consult with a colleague or external expert who has read and analyzed those terms and policies.” The Committee adds that lawyers “may need to consult with IT professionals or cyber security experts” to understand them. So the reading can be delegated to a competent reader, but the baseline expectation is that lawyers understand what they are using.
The register is what those answers become. It is the artifact that turns policy into something usable, and the fields follow from the above.
| Field | Why it is there |
|---|---|
| Tool name and edition | Terms differ between the free and enterprise editions of the same product |
| Vendor and contracting entity | The party the confidentiality obligation actually runs against |
| Approved uses, by task | Approval is per purpose, not per product |
| Trains on inputs: yes / no / unresolved | Determines which confidentiality path applies. “Unresolved” is a legitimate and important status |
| Data retention during and after termination | Opinion 512’s diligence item |
| Proprietary rights asserted over inputs | Same item, second half, and the one most often missed |
| Breach and service-of-process notice: yes / no | Whether the firm learns if its material is subpoenaed from the vendor |
| Liability limits and governing forum | What recourse exists, and where |
| Risk tier | Routine, Standard, Elevated, or Prohibited |
| Client consent required, and the script reference | Follows from the self-learning answer |
| Status | Approved, Conditional, Under review, or Prohibited |
| Conditions attached | The half of “conditionally approved” that otherwise lives in someone’s memory |
| Approver and date | Who decided, and when |
| Next review date or trigger | Without this the register decays silently |
| Register owner | The person accountable for keeping it true |
A register with the first three fields is a list. A register with all fifteen is a control.
Step three: who decides, in a firm without a security officer
A firm of 20 to 100 attorneys typically has a managing partner, an executive or management committee, a firm administrator, and an IT lead who may be a vendor. It may not have a chief information security officer, an innovation department, or anyone whose day job is this.
That is workable without a committee. It requires three assignments with names attached.
One lawyer accountable. In most firms of this size that will be a partner, though the rule reaches any lawyer with comparable managerial authority. One person rather than a committee, because committees meet quarterly while tools change under their own names.
There is an objection to this and it deserves a straight answer. Making one partner accountable hands that partner responsibility for firmwide conduct without authority over the equity partners whose behavior creates most of the exposure. That is a real problem and it is not solved by an org chart. What solves it, to the extent anything does, is that the accountable partner owns the process and the management committee owns the consequences: the register, the criteria and the record sit with one named person, and the decision to act when a partner works outside them sits where every other partner-conduct decision at the firm already sits. A firm that cannot say where that is has a governance problem that predates AI.
One person who maintains the register. Usually the firm administrator or practice manager. This is the job that determines whether governance is still true a year in, because a register nobody owns is accurate the day it is written and misleading thereafter.
Named reviewers for the two questions that recur. The technical and security question, usually the IT lead. The confidentiality and professional responsibility question, which has to be a lawyer. Both need to be reachable in days.
Ownership that is assumed rather than assigned is the failure that stays invisible until the first request arrives and nobody moves.
Step four: the approval route, and what the form asks
If there is no practical way to ask, people decide for themselves. The route matters more than the policy language around it, and using it has to be easier than not using it.
Nine questions do the work.
- What is the task, and in what practice area?
- Will any information relating to a client representation be entered? This is the Rule 1.6 test, and it is deliberately broader than “confidential” or “client identifying.” Opinion 512 describes the duty as covering information relating to the representation regardless of its source.
- Which tool and which edition, and does it train on inputs?
- Do this matter’s outside counsel guidelines or engagement terms restrict AI use?
- Does any court in this matter have a part rule or standing order on AI?
- What review does the output get before it leaves the firm?
- Does anything about this affect what the client is billed?
- Has client consent been obtained where required, and where is it recorded?
- Does this raise an ethical wall or conflicts issue? Opinion 512 specifically flags that a self-learning tool may disclose information to people in the firm “who either are prohibited from access to said information because of an ethical wall” or who “could inadvertently use the information from one client to help another client, not understanding that the lawyer is revealing client confidences.”
Every approval should carry an expiration or review trigger, because a tool approved in March on terms that changed in July is a stale approval.
Questions 4, 5 and 7 are the ones firms leave off, and they are the ones an outside party reaches first, because that is where AI use becomes visible to someone who is not in the firm.
One design point, which is an inference rather than something the opinion prescribes. There should be a lighter route for uses that involve no information relating to a representation, because a single heavyweight process for both an experiment and a client-data workflow means the experiment goes unreported. The opinion gives that lane a boundary: it identifies uses where consent is not required “because the lawyer will not be inputting information relating to the representation,” offering idea generation as an example, expressly qualified as being “in a manner that does not require inputting information relating to the representation.”
Step five: tiers people can apply, and who approves each one
Classification works only if the person doing the work can determine the tier quickly and reach the same answer as a colleague. Four tiers, separated by one variable: what enters the tool.
| Tier | Test | Approval |
|---|---|---|
| Routine | No information relating to a client representation enters the tool. Administrative drafting, personal productivity, idea generation on a hypothetical | Self-serve from the approved list, no submission |
| Standard | Information relating to a representation enters an approved tool that does not train on inputs. Attorney verification mandatory | Reviewer sign-off, recorded in the register |
| Elevated | Matter-specific work, client sensitive material, regulated data, or any self-learning tool | Accountable lawyer, with the client consent position resolved before use |
| Prohibited | Uses the firm has closed. Worth naming explicitly: consumer accounts holding matter facts, tools with no enterprise agreement, tools whose terms assert proprietary rights over inputs | No route |
Two notes on Prohibited, because a rule a firm immediately breaks is worse than no rule.
The first is that a tool the firm cannot get an answer about is not automatically prohibited; it is unresolved, which is why that status exists in the register. On day one a firm will have embedded features in software it already licenses whose training behavior nobody has confirmed. The honest handling is to record them as unresolved, cap their permitted use at Routine while the question is open, and give the resolution a name and a date. Prohibiting them on day one means prohibiting the word processor, which nobody will comply with.
The second is that Prohibited should list actual uses, not a definition. A tier defined as “uses the firm has determined are unacceptable” tells no one anything.
The design test is whether an associate can place a task in a tier without calling anyone and get the same answer a colleague would. Keep one vocabulary: if the policy says Elevated, the register, the form and the training all say Elevated.
Step six: the four rules that have to be specific
Everything else in the policy can be general. These four get tested from outside the firm.
Inputs. Which categories of information may go into which tools, mapped to the actual tool list, with the no-input uses named so people know what is freely available.
Consent. For self-learning tools, what the client is actually told, drafted in advance rather than improvised per matter. Opinion 512 sets a demanding standard and closes the shortcut: “merely adding general, boiler-plate provisions to engagement letters purporting to authorize the lawyer to use GAI is not sufficient.” For consent to be informed, the opinion says the client must have the lawyer’s best judgment about why the tool is being used, “the extent of and specific information about the risk, including particulars about the kinds of client information that will be disclosed, the ways in which others might use the information against the client’s interests, and a clear explanation of the GAI tool’s benefits to the representation.” It adds an element specific to these tools and easily missed: “Part of informed consent requires the lawyer to explain the extent of the risk that later users or beneficiaries of the GAI tool will have access to information relating to the representation.”
Verification. By task type, not as a single standard. The opinion is explicit that the required amount “will necessarily depend on the GAI tool and the specific task that it performs as part of the lawyer’s representation of a client,” and it works an example: a lawyer using a tool to summarize numerous lengthy contracts “would not necessarily have to manually review the entire set of documents to verify the results if the lawyer had previously tested the accuracy of the tool on a smaller subset of documents by manually reviewing those documents,” comparing them to the summaries and finding them accurate. Sample testing can carry the weight. Recording that the testing happened is not in the opinion, but it is the difference between a standard the firm can evidence later and one it can only assert.
Billing. Opinion 512 covers time actually spent, flat and contingent arrangements, learning time, and whether tool cost is overhead or an expense. The operative sentence for a policy is procedural: “before charging the client for the use of the GAI tools or services, the lawyer must explain the basis for the charge, preferably in writing.” For in-house tools the opinion adds that the lawyer “must ensure that the amount charged is not duplicative of other charges to this or other clients.” A firm without a written position produces a different answer from every partner asked.
Step seven: training by role, and the records that outlast it
An all-hands announcement is not training, because different roles face different decisions. Attorneys need the input rules, the verification standard, and when a client conversation is required. Practice group leaders need supervisory expectations, since Rule 5.1 reaches lawyers with comparable managerial authority and 5.1(b) reaches direct supervision. Administrative staff need tool boundaries and data handling. Reviewers and approvers need the criteria and the tier definitions.
Opinion 512 treats training as part of the supervisory duty and says it “could include the basics of GAI technology, the capabilities and limitations of the tools, ethical issues in use of GAI and best practices for secure data handling, privacy, and confidentiality.”
Two artifacts are worth producing here because they are what the firm can show afterward. An acknowledgment record, so the firm can demonstrate who was trained and when. And a storage convention the opinion suggests in a footnote: that material produced by these tools be marked as such “when stored in any client or firm file so future users understand potential fallibility of the work.”
One question to raise with the firm’s own counsel rather than settle internally: whether prompts, outputs and register entries are discoverable, and how they interact with litigation holds. Opinion 512 does not address it, and a firm is better off having asked before the first preservation letter than after.
Step eight: staying current, because the guidance says it will not stay current
Opinion 512 says so twice. Its opening section describes generative AI as a rapidly moving target and anticipates updated guidance from the Committee and from state and local bar committees. And footnote 34, attached to the informed-consent conclusion itself, begins: “This conclusion is based on the risks and capabilities of GAI tools as of the publication of this opinion. As the technology develops, the risks may change in ways that would alter our conclusion.”
The Committee treated its own conclusion as provisional. A firm’s answers are provisional too, and the governance that matters is the mechanism for asking again.
Calendar reviews are the weak version. Event triggers are better, and four are worth writing down: a vendor changes its terms or ships a feature, someone requests a tool that is not on the register, a court the firm appears in adopts an AI rule, or a client sends a questionnaire.
Where rollouts fail
Ownership assigned to IT. The technical questions are real and IT can answer them. The confidentiality and supervision questions are neither technical nor theirs.
A policy that only restricts. If nothing is approved on the day the restrictions land, use moves out of sight. Publish the permitted path at the same time.
AI arriving inside software already purchased. No procurement decision, so nobody coded it as adoption. This is a common route for an ungoverned tool to enter a firm and it is invisible to any process that starts at “who wants to buy something.”
Personal accounts and personal devices. A partner using a personal subscription is outside the controls the firm has built and outside its enterprise agreement, so the vendor terms the register records will usually not apply to that use.
Client questionnaires answered by business development. The AI section of an RFP or client audit gets completed by whoever owns the response, and commits the firm to a description of its governance that nobody in the register’s chain has seen.
Laterals arriving with their own tools and habits. Onboarding rarely asks.
The register nobody owns. Correct when written and increasingly wrong afterward, which is worse than absent because people rely on it.
Practice group carve-outs. Flexible in appearance, and they tend to produce several incompatible standards, none documented, and no ability to answer a client question at the firm level. If the litigation group’s position on a tool differs from the transactional group’s, that is a register entry with conditions, not a separate regime.
Treating circulation as completion. Acknowledgment is not implementation.
What to tell a client who asks in the middle of it
Firms are being asked before they are finished. Corporate legal departments now have a published question list for evaluating outside counsel’s AI use, covering policies, accountability, data handling, quality control and billing. The Association of Corporate Counsel’s framing is public; the full list requires an ACC login. Outside counsel guidelines usually arrive earlier than any questionnaire, because they arrive as contract terms, and they tend to cover the same ground: whether the firm has a written policy, whether client data is excluded from model training, who is accountable, what quality control applies, and how AI-assisted time is billed. And AI governance is increasingly part of professional-risk and insurer conversations.
“We are implementing” is a legitimate answer when it is true, dated and specific. What a client is testing is whether anyone at the firm owns this and whether there is a plan with a name and a date attached.
What this actually costs
Not in days, because that depends on a firm’s attention rather than on the work. In units the firm can count before it starts.
The vendor contracts to be read equals the number of distinct tools on the inventory, which for a firm of this size is usually more than the partners expect once embedded features are counted. Each one needs a named contact at the vendor and, where the published terms do not answer the training question, one written exchange. Beyond that: one decision from the managing partner on amnesty, four rules to draft, one register to populate, one form to build, one training session per role group, and one review of each of the above before anything is circulated.
The slowest link is almost always waiting on vendors. The second constraint is attention, because this competes with billable hours and is nobody’s day job at this size. Firms running it internally should protect the first two steps in particular, since everything downstream waits on them.
What is worth resisting is starting at step six. Writing the policy first feels like progress because it produces a document, and it is the step most likely to be discarded, because a policy written before the tool facts are known cannot say anything specific enough to be used.
If you want to see which of these steps your firm has completed, the AI Governance Readiness Assessment takes about three minutes.
CounselRisk builds and operates governance machinery for law firms. This article is general information and not legal advice. Formal Opinion 512 is advisory, and the ABA Model Rules are not binding until adopted by a jurisdiction, so jurisdiction-specific conclusions belong to the firm and its counsel. CounselRisk is operated by QbitBrains LLC.