AI in practice · 16 September 2026
AI Governance for a Small Practice: What Actually Matters
Governance does not require a committee. It requires four decisions written down, and most small practices can make all four in one sitting.
"Governance" is a word that sounds like it belongs to a large firm with a risk committee and a policy manual nobody reads past page two. That reputation is exactly why most small practices skip it entirely when adopting AI, treating governance as bureaucracy scaled for an institution they are not. I have watched that skip happen repeatedly, and the actual cost of it rarely shows up as a dramatic failure. It shows up as a confidentiality problem or a bad output that reaches a client, discovered as a surprise instead of managed as a known, bounded risk.
Governance is four decisions, not a department
Strip away the large-firm apparatus and AI governance for a small practice comes down to four specific decisions, written down once, revisited occasionally, not reinvented for every new tool. None of the four require a committee. All four can be decided by the person who actually runs the practice, in one sitting, if they sit down and actually answer them rather than deferring the question indefinitely.
Decision one: what confidential data can touch which tools
Not every AI tool handles data the same way, and a small practice needs one clear rule, not a case-by-case judgment call made fresh every time a new matter comes in. The question to answer once: which categories of client information, names, case facts, privileged communications, are permitted in which tools, and which categories are never permitted outside a small, named set of tools the practice has actually vetted. This does not require a technical audit of every vendor's data policy in exhaustive detail. It requires a plain decision, written down, that a busy associate or paralegal can actually follow without having to ask each time.
Decision two: which outputs need sign-off before leaving the practice
Not every AI-assisted output carries the same risk. A first-pass internal summary of a long document, used only to speed up a lawyer's own reading, carries a different risk profile than a client-facing letter or a court filing. The decision here is which categories of output require a named human review step before they leave the practice, and which do not. This is exactly the evidence-anchoring reviewer discipline, applied at the governance level rather than the document level: name the checkpoint, name who owns it, before the first output of that kind is ever produced, not after something has already gone out that should have been checked.
Decision three: who can approve a new tool
Small practices accumulate AI tools the same way they accumulate software generally, one person tries something, likes it, starts using it, and six months later three different tools are handling client data with nobody having made a deliberate decision about any of them. The fix is not a procurement process, it is a single named person, even in a practice of one, whose approval is required before a new AI tool touches real client data. In a solo practice this decision is trivially easy, it is simply a discipline: pause before adopting a new tool for real matters, and actually think through decisions one and two against it, rather than adopting first and thinking later.
Decision four: what happens when something goes wrong
This is the decision practices skip most often, because it requires imagining a failure before one has happened, which feels unnecessary right up until it is not. What happens if an AI tool produces a fabricated citation that makes it into a filing. What happens if client data gets pasted into a tool that should not have received it. The answer does not need to be elaborate: who gets told immediately, what gets checked, whether a client needs to be notified. A practice with this decision made in advance responds to an actual incident in minutes. A practice without it spends the first hours of a real incident deciding how to decide, which is exactly the wrong moment to be improvising a process.
Why four sentences is enough, and why that is not a compromise
I want to be direct about something: four sentences of governance is not a scaled-down, lesser version of what a large firm needs. It is the right size for the actual risk surface of a small practice, which handles fewer matters, fewer tools and fewer people than a large firm's governance apparatus is built to manage. Over-building governance for a small practice, importing a large firm's committee structure wholesale, is its own failure mode, because a process too heavy to actually follow gets skipped exactly like no process at all, just with more meetings first.
What this looks like written down
In practice, this is a single page, not a manual: which data goes in which tools, which outputs need a named reviewer before they leave, who approves a new tool, and what the first hour of an incident response actually looks like. It gets written once, revisited when a genuinely new category of tool or task shows up, not rewritten from scratch every quarter out of habit.
The connection to being AI-native, not just AI-augmented
Governance is what makes the difference between AI running systematically, on every matter, safely, and AI running incidentally, wherever someone happened to reach for it, with no shared understanding across the practice of what is and is not permitted. A practice that has not made these four decisions cannot actually be AI-native no matter how sophisticated its tools are, because AI-native requires AI to run by policy, and policy is exactly what these four decisions are. I laid out the full governance sequence alongside the broader ninety-day move off the billable hour in the AI-Native Practice Field Guide.
ai governance · legal ai · risk management · practice management