AI usage policy that fee earners will actually follow
Short, specific and written for practitioners rather than for a compliance file: what may be used, on what matters, with what data, and what must never leave the firm.
Professional services
Your people are already using AI on client work. The question is not whether to allow it — that decision was made for you — but whether you can evidence how it is being used when a client, a regulator or your insurer asks.
The day-to-day
Where the money goes
Client-privileged material pasted into a consumer AI tool is a disclosure. The firm's difficulty is not usually the exposure itself — it is being unable to say what has been exposed, which makes every question unanswerable.
Without a review standard, AI-assisted work varies enormously by who produced it. The failure mode is not obviously wrong output; it is plausible output that nobody checked.
Client due diligence questionnaires and PI insurers now ask about AI governance directly. "We are looking into it" is an increasingly expensive answer.
Individuals get faster; the firm does not. Without changing how work is scoped, reviewed and billed, personal productivity gains stay personal.
What we would build
Short, specific and written for practitioners rather than for a compliance file: what may be used, on what matters, with what data, and what must never leave the firm.
A reviewed shortlist of tools with acceptable data handling, configured with the right retention and training settings, and least-privilege access to matter data.
A defined review step for AI-assisted work product, proportionate to matter risk, so the firm can evidence human oversight rather than assert it.
Language for engagement letters, DDQ responses and insurer questionnaires that describes your controls accurately — which is only possible once the controls exist.
What we design around
These are the things that make a generic build fail here. We treat them as hard requirements from day one, not as issues discovered in testing.
Every design decision starts from what may cross the firm boundary. Where a use case cannot be made safe, the answer is no, and we will say so rather than engineer around it.
A prohibition with no approved alternative produces shadow usage, which is worse than the original problem. Every restriction we recommend comes with a sanctioned route to do the same work.
Policies that were not built with the people who will be governed by them do not last. We run this with partners in the room, not as a document delivered to them.
A realistic first quarter
Indicative, and it changes with your systems — but this is the shape, and the ordering is deliberate: lowest risk first, so the evidence arrives before the exposure does.
Discover what is actually in use. Anonymous, non-punitive, and consistently more extensive than management expects.
Draft the policy and the approved-tool list with a working group of partners and senior associates.
Configure the approved tools properly — retention, training opt-out, access scope — and roll out with practical training.
Add the review standard, then look at where AI genuinely changes the economics of a matter type.
How we would engage
Start here
A short, evidence-led engagement that maps where AI will actually reduce cost or recover time in your business, ranks the options by return and risk, and gives you a sequenced plan you can budget against.
Read moreControl the risk
Your team is already pasting client data into public AI tools. We put the policy, access controls and vendor review in place that let you say yes to AI safely — sized for a mid-sized business, not an enterprise compliance department.
Read moreFAQ
No. Bans do not work; they produce undocumented usage on personal devices. The objective is a sanctioned route that is good enough that nobody needs the unsanctioned one.
Honestly. We help you establish scope, assess materiality, and decide what needs disclosing. Most firms find the exposure is narrower than feared but broader than assumed.
We work to your regulator's requirements and your professional obligations as the constraints on the design. We are technologists, not your legal advisers — where a question is legal rather than technical, we will say so and work alongside whoever advises you.
A firm with nothing in place today can have a written policy, a reviewed tool list and configured access inside four weeks. The harder part — changing habits — takes a quarter.
Bring us a month of call logs or enquiry data and we will tell you, specifically, where it is leaking and what it is worth fixing.
Altus AI concierge
Answers about our work — and books your call
Hello — I'm the Altus concierge. Ask me anything about AI adoption, governance, or the agents we build. If it's a fit, I'll set up a call with the team.
AI-generated. We store what you send so we can follow up. Privacy