9 min read · Updated August 2026
AI governance for a practice too small to have a committee
You don't need a governance committee, a risk framework binder, or a chief AI officer. You need about four rules, written down, that everyone actually follows.
Key takeaways
- Governance at a small practice fails when it's copied from a large firm's framework, because the overhead itself becomes the reason nobody follows it.
- The core question isn't 'do we allow AI,' it's 'which outputs require a named human to sign off before they leave the building.'
- Client confidentiality rules for AI tools need to be specific about what data goes where, not a general policy statement nobody rereads.
- A one-page policy that's actually followed beats a twenty-page policy that sits in a drawer.
- Governance has to include what happens when something goes wrong, not just rules for when things go right.
Why borrowed governance frameworks don't fit
I get asked fairly often by solo and small-firm lawyers to help them set up 'AI governance,' and what they usually mean is that they read an article describing a large firm's AI committee, use policy, and audit process, and they're worried they're supposed to have something similar. They're not, and trying to build a scaled-down version of a large firm's framework is usually worse than having no framework, because it creates paperwork with no enforcement behind it.
A large firm's AI governance exists to coordinate hundreds of lawyers who don't know each other, across dozens of practice areas, with a general counsel who needs a defensible answer if something goes wrong. A three-lawyer practice doesn't have that coordination problem. What it has is a much simpler, sharper problem: does everyone in the office actually know which uses of AI are fine, which need a second look, and which are off the table, and will they remember that under deadline pressure.
The four rules I actually recommend
1. Name what confidential data is allowed to touch which tools
Not a general statement about 'protecting client confidentiality.' A specific list: this tool is approved for drafting from public information, this tool is approved for client documents because we've confirmed it doesn't train on inputs and we've reviewed its terms, this tool is never to be used with client names or facts, full stop. Write the tool names down. Update the list when a tool changes its terms.
2. Define which outputs require sign-off before they leave the practice
I tell every small practice I work with: anything that goes to a client, a court, or opposing counsel needs a named human who reviewed it and is willing to put their name on having reviewed it. AI-assisted drafting is fine. AI-assisted drafting that skips a human read-through before it goes out the door is not, regardless of how good the tool has gotten.
3. Decide who can approve a new tool
In a small practice this is usually one person, often the person reading this. But it needs to be explicit, because otherwise every associate and paralegal independently decides which tools are fine to try, and you end up with client data scattered across services nobody vetted.
4. Write down what happens when something goes wrong
A tool hallucinates a citation, a draft goes out with an error, a piece of client information ends up somewhere it shouldn't. Decide now, calmly, what the response is: who gets told, how the client gets told if they need to be, how you figure out how far it spread. Practices that skip this step end up improvising during the worst possible moment to improvise.
What I've actually seen go wrong without this
In one small commercial litigation practice I advised, an associate had been using a general-purpose AI tool to summarize deposition transcripts, pasting full transcript text into the tool because it was fast and the output was genuinely useful. Nobody had told him not to, because nobody had written anything down at all. The practice had no idea this was happening until I asked, during an unrelated engagement, what tools people were using day to day.
Nothing had gone wrong yet in that case, which is exactly the point: the absence of an incident is not evidence that the practice was fine, it's evidence that nobody had looked. The fix took one afternoon: a short written policy naming the approved tools, the confidentiality line, and the sign-off rule, sent to everyone, discussed in a fifteen minute meeting. That's the whole governance program for a practice that size, and it's genuinely sufficient.
The right size test
If your governance document is longer than a page and a half for a practice under ten lawyers, ask honestly whether anyone will actually read it twice. A rule nobody remembers under deadline pressure isn't protecting you, it's just documentation that you thought about the problem once.
Keeping the policy alive instead of filed away
- Revisit it every time you adopt a new tool, not on a fixed annual schedule, because tool adoption is what actually changes your risk, not the calendar.
- Put the approved tool list somewhere people will actually see it day to day, not buried in an onboarding packet nobody rereads after week one.
- Ask new hires to read it in their first week and confirm they have, in writing, the same way you'd handle a conflicts check acknowledgment.
- When you catch a near miss, even a small one, treat it as a reason to tighten the specific rule that would have caught it, rather than a generic reminder to 'be careful.'
What changes as the practice grows
The four rules scale further than people expect. I've watched practices grow from three lawyers to fifteen without needing to add a committee, because the core structure, a named approver, a specific confidentiality list, a hard sign-off rule, and an incident plan, doesn't actually depend on headcount. What changes is enforcement mechanics: at three lawyers, enforcement is a conversation, at fifteen it's worth having someone spot-check occasionally that the approved tool list is actually what people are using.
The moment I do tell a client to build something closer to a real committee structure is when they're managing regulated data at real scale, multiple offices, or outside counsel guidelines from institutional clients that specifically require it. Short of that trigger, resist the pull toward heavier process. It's rarely the risk that justifies it, it's the discomfort of not having a formal-looking document to point to.
Questions
- Do I need a written AI policy if it's just me, solo, with no staff?
- Yes, briefly. Even solo, write down which tools you use for which categories of work and what your confidentiality line is. It forces a decision you'd otherwise make ad hoc under deadline pressure, and it gives you something concrete to point to if a client or bar inquiry ever asks.
- How do I evaluate whether a tool is safe for client data without a technical background?
- Read the terms of service section on data use and training, specifically, and if it's not clear within a few minutes of reading, that ambiguity is itself the answer: don't put client data in until you or someone you trust has gotten a straight answer from the vendor in writing.
- What's the single most common governance gap you find in small practices?
- No sign-off rule. People assume 'I'll obviously check it before it goes out' is enough, and it is, until a deadline crunch makes 'obviously' optional. Write the rule down so it survives the day everyone's exhausted.
- Should associates be allowed to pick their own AI tools?
- Not unilaterally for anything touching client data. Let them suggest tools, but route new tool adoption through the one named approver, so the practice always knows what's actually in use.
- Does malpractice insurance care about any of this?
- Increasingly yes, and it's worth asking your carrier directly what they expect. I've seen renewal questionnaires start asking about AI tool usage and safeguards, and having a short, real policy to point to is a much better position than having nothing written down at all.
Want this built for your practice, not just read about it?