TL;DR: This is a working AI use policy for an Indian law firm, not an essay about needing one. Twelve clauses cover permitted and prohibited uses, client confidentiality, tool approval, mandatory human verification before filing, disclosure to courts and clients, record-keeping, personal-account use, training, and sanctions. Each clause carries the rule it is built on. A full copy-pasteable version sits in a single code block partway through.
On this page
- Why the policy has to be a document, not a memo
- Clause 1: purpose and scope
- Clause 2: permitted uses
- Clause 3: prohibited uses
- Permitted versus prohibited, at a glance
- Clause 4: client confidentiality and data handling
- Clause 5: approved tools and who approves them
- Clause 6: mandatory human verification before filing
- Clause 7: disclosure to courts
- Clause 8: disclosure to clients
- Clause 9: record-keeping
- Clause 10: shadow AI and personal accounts
- Clause 11: training
- Clause 12: sanction for breach
- The full policy, ready to copy
- How a filing moves through the approval gate
- Rolling this out in a firm that has never had one
- Frequently asked questions
Why the policy has to be a document, not a memo
A partner telling associates to “be careful with AI” is not a policy. It has no scope, no named approver, no verification step a junior can point to when a senior asks why a citation made it into a filing, and nothing to show a client, an opposing counsel, or a disciplinary committee if the question ever comes up. The Supreme Court has already held, in Pooja Ramesh Singh v. Jammu and Kashmir Bank Ltd. & Anr., 2026 INSC 668, decided 2 July 2026 by Justice Pamidighantam Sri Narasimha and Justice Alok Aradhe, that citing an AI-generated precedent without verification is misconduct on the part of an advocate, and that a decision built on even a fragment of fake or hallucinated material is no decision in the eyes of the law. That is a standard a firm has to be able to demonstrate it meets, not just believe it meets. Our earlier coverage of that judgment, AI-generated case law and the Supreme Court’s 2026 rule, the draft disclosure duty in regulation 19 and the AI disclosure requirement, the underlying obligation described in a lawyer’s duty to verify AI legal output in India, and the wider framework in the Supreme Court’s AI rules for courts are the four sources this policy is built on. Read them for the reasoning. This piece is the document that operationalises it.
What follows is twelve clauses in the order a firm would actually adopt them: scope first, then what is allowed and what is not, then the two clauses that carry the real risk (confidentiality and verification), then disclosure, records, the personal-account problem, training, and finally what happens on breach. Each clause states the rule and then the reasoning immediately below it, so a partner adapting this for their own firm can see why a line is drawn where it is drawn.
Clause 1: purpose and scope
Clause text. This policy governs the use of artificial intelligence tools, including generative AI, legal research AI, and AI-assisted drafting and translation tools, by every partner, associate, trainee, paralegal, and administrative staff member of the firm, in connection with any client matter, internal work product, or firm business. It applies regardless of whether the tool is provided by the firm or accessed independently, and regardless of whether the output is used in a filing, an opinion, an email, or internal research.
Why it is written this way. A scope clause that only covers “AI used in court filings” misses most of the actual exposure. An associate who pastes client facts into a free chatbot to draft an email is inside the confidentiality risk long before anything reaches a court. The clause deliberately covers every person and every use, not just litigation staff and filed documents, because the duty of confidentiality attaches to the advocate-client relationship itself, not to the document type.
Clause 2: permitted uses
Clause text. Subject to the confidentiality, tool-approval, and verification clauses below, AI tools may be used for: first-pass legal research to locate candidate authorities for human verification; summarising publicly available judgments, statutes, or non-privileged documents; drafting first drafts of contracts, notices, and pleadings that will undergo full human review before use; translation and language support for client communication; transcription of hearings, depositions, or client meetings where consent has been obtained; internal knowledge management, including tagging and indexing of the firm’s own precedent bank; and administrative tasks such as scheduling, billing narrative drafts, and internal memo formatting.
Why it is written this way. The permitted list is framed around AI as a first-pass tool, not a final one. Every item produces something a human still has to check, translate, or approve before it leaves the firm, which is the same distinction the Supreme Court drew in Pooja Ramesh Singh: the judgment has no bearing on the rightful use of AI, only on presenting unverified output as though it were law. A clause that stops at “AI may assist with research and drafting” without tying every item back to a human check would license the exact conduct the Court condemned.
Clause 3: prohibited uses
Clause text. AI tools must not be used to: generate case citations, statutory references, or quotations, which risk hallucinated citations, that are then filed, emailed to a client, or relied on in advice without independent verification against a primary source; input client-identifying information, privileged communications, or confidential case facts into any tool that is not on the approved list under clause 5; draft or finalise any document for filing without the human verification step under clause 6; make or simulate a legal judgment, sentencing recommendation, or determination of guilt or liability presented as the firm’s considered position; generate content for a court filing without applying the disclosure clause under clause 7 where a court or tribunal requires it; or substitute for the exercise of independent professional judgment on strategy, settlement, or advice to a client.
Why it is written this way. Each prohibition maps to a documented failure mode, not a hypothetical one. The fabricated-citation prohibition maps to Pooja Ramesh Singh. The confidential-input prohibition maps to the advocate’s obligation under Section 132 of the Bharatiya Sakshya Adhiniyam, 2023, covered in clause 4 below. The judgment-simulation prohibition maps to the assistive-versus-decisional distinction the Supreme Court’s AI Committee has drawn for AI inside the judicial process, described in the Supreme Court’s AI rules for courts. A clause that just says “do not misuse AI” gives a disciplinary committee nothing to test compliance against. This one gives a checklist.
Permitted versus prohibited, at a glance
| Use | Permitted | Prohibited |
|---|---|---|
| First-pass research to find candidate authorities | ✓ | |
| Filing a citation without independently checking it against the primary source | ✗ | |
| Drafting a first draft of a notice or pleading for human review | ✓ | |
| Filing an AI-drafted document without the verification step in clause 6 | ✗ | |
| Pasting client facts into an approved, firm-controlled tool under an enterprise agreement | ✓ | |
| Pasting client facts into a free consumer chatbot or personal account | ✗ | |
| Using AI to summarise a public judgment | ✓ | |
| Using AI to generate a simulated finding of fact or liability presented as the firm’s advice | ✗ | |
| Using AI transcription for a meeting where consent was obtained | ✓ | |
| Recording or transcribing a privileged conversation without the client’s knowledge | ✗ | |
| Disclosing AI use to a court that requires it under its own rules or practice directions | ✓ | |
| Concealing AI use from a court that has asked directly | ✗ |
Clause 4: client confidentiality and data handling
Clause text. No partner, associate, trainee, or staff member may input any information that could identify a client, a matter, or a privileged communication into an AI tool unless that tool appears on the firm’s approved list under clause 5 and has been confirmed, in writing by the approving partner, to meet the firm’s data-handling standard. Public, free-tier, or consumer versions of AI tools must never be used for any client-identifying input, regardless of the tool’s own privacy claims. Where personal data of a client, witness, or opposing party is processed through an approved AI tool, that processing must comply with the firm’s obligations as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, including the security safeguards required under Rules 5 to 9 and the breach-notification obligations that follow.
Why it is written this way. This clause rests on two legal foundations, kept separate because they carry different consequences. The first is the advocate’s own duty of confidentiality. Section 132 of the Bharatiya Sakshya Adhiniyam, 2023, the current law of evidence that replaced the Indian Evidence Act, 1872 with effect from 1 July 2024, protects professional communications between an advocate and client from disclosure without the client’s express consent, subject only to the illegal-purpose and crime-or-fraud exceptions in the section itself. Bar Council of India Rules, Chapter II, Part VI, Section II, Rule 17, made under the rule-making power in Section 49(1)(c) of the Advocates Act, 1961, separately requires that an advocate shall not, directly or indirectly, commit a breach of this obligation. The Rule’s text still points to the old Section 126 of the Indian Evidence Act, since the Bar Council has not amended the wording since the recodification, but the obligation it enforces is now carried by Section 132 of the BSA. Feeding client facts into a third-party AI tool without knowing where that data is processed or retained is a live risk of exactly the disclosure the Rule prohibits.
The second foundation is statutory. If the input includes personal data of an identifiable individual, the firm is a Data Fiduciary under the Digital Personal Data Protection Act, 2023, and the DPDP Rules, 2025 require the security safeguards and breach-notification steps our DPDP Rules 2025 guide sets out in full. An AI vendor that retains inputs for training, or processes data outside the terms the firm agreed to, can turn a routine research query into a reportable personal data breach, which is why clause 5 exists: nobody in the firm should decide alone whether a tool’s data practices are acceptable.
Clause 5: approved tools and who approves them
Clause text. The firm maintains a written list of approved AI tools, reviewed at least every six months and whenever a new tool is proposed for use. A tool is added to the list only after the managing partner, or a partner designated in writing for this purpose, has reviewed the vendor’s data-processing terms, confirmed whether client data is used to train the vendor’s models, confirmed the data-retention period, and confirmed where the data is stored and processed. No associate, trainee, or staff member may adopt a new AI tool for any client-related work without this approval, regardless of the tool’s reputation or use at other firms.
Why it is written this way. Part of that review, especially for a tool that will touch client facts, is whether it is a legal-specific product or a generic AI product repurposed for legal work, since that affects both the training-data question and the accuracy of Indian citations. A platform built specifically for Indian legal work, such as Niyam, states as a design principle that client documents are not used to train or fine-tune its models, which is the kind of written commitment clause 5 asks the approving partner to confirm before adding any tool to the list. Centralising approval in one named role is what makes clause 4 enforceable. A confidentiality rule that says “only use approved tools” without saying who approves them, and what they check for, is not actually a control. The six-monthly cycle exists because vendor terms change; an approval given a year ago on the vendor’s old privacy policy is not evidence of a current one.
Clause 6: mandatory human verification before filing
Clause text. No document containing AI-generated or AI-assisted content, including case citations, statutory references, quoted passages, or factual summaries, may be filed with any court, tribunal, or authority, or sent to a client as final advice, until every citation, quotation, and factual claim in it has been independently checked by a human lawyer against the primary source. Primary-source verification means locating and reading the actual judgment, statute, or document, not accepting the AI tool’s own summary or citation of it as sufficient. The lawyer performing the verification must be identified, and the verification must be recorded under clause 9 before the document leaves the firm.
Why it is written this way. This is the clause that answers Pooja Ramesh Singh directly. In that case, senior counsel for the appellant pointed out that the citations relied on by the National Company Law Tribunal were fake and non-existent, probably AI-generated, and that even where a citation was accurate, the paragraph excerpted from it could not be traced in the law reports. The Supreme Court held at paragraph 7 that courts must adopt a zero-tolerance mode for producing, citing, or using AI-generated precedents without verification, that citing such judgments without verification is misconduct on the part of an advocate, and that a decision built on fake or hallucinated material is no decision in the eyes of the law even if only an iota of it entered the reasoning. Paragraph 17 goes further: such a decision is no decision at all, and amounts to subversion of the rule of law. The full account of how that fake precedent moved from an AI tool into a tribunal order, and the five-step check that catches it, is in a lawyer’s duty to verify AI legal output in India and AI-generated case law and the Supreme Court’s 2026 rule.
“Independently checked against the primary source” is deliberately narrow. An AI tool that summarises its own citation correctly is not a verification; the check has to reach the actual reported judgment or the bare Act, along the lines set out in our guide to vetting legal AI citation accuracy. A citator that flags whether a judgment has been affirmed, distinguished, or overruled, and links straight to the reported text so the check takes minutes rather than an afternoon in the library, is what turns this clause from a compliance burden into something a busy associate will actually do every time. That is the specific gap Niyam’s good-law checking is built to close.
Clause 7: disclosure to courts
Clause text. Where a court, tribunal, or its practice directions require disclosure of AI use in the preparation of a filing, that disclosure must be made accurately and completely, stating which AI tool was used, the extent of its contribution, and the verification steps taken. Where no binding disclosure requirement exists, the firm’s default position is not to volunteer disclosure of routine, verified AI-assisted drafting, but never to give a false or misleading answer if a court asks directly.
Why it is written this way. The Supreme Court’s AI Committee released the Draft Regulations for Use of Artificial Intelligence in Courts, 2026 on 3 June 2026 for public comment. Regulation 42 requires a party or counsel who used AI in preparing a document to disclose that at filing, and lets the court ask which system was used and what verification was performed; Regulation 43 puts responsibility for fabricated content on the filer regardless of the AI’s role. These are draft, unnotified provisions, so the clause cannot treat them as binding today. The full clause-by-clause reading is in the duty to declare AI use in pleadings. The default separates what is legally required now from what a firm should do anyway once a court asks directly: answer truthfully every time.
Clause 8: disclosure to clients
Clause text. Clients must be told, in the engagement letter or a written update, that the firm may use AI tools as part of its research, drafting, or administrative process, subject to the safeguards in this policy, and that all substantive advice and every filed document is reviewed and approved by a named human lawyer before it reaches the client or the court. A client may request, at any time, that no AI tool be used on their specific matter, and that request must be honoured and recorded.
Why it is written this way. Client trust in the firm’s output does not survive a client discovering AI involvement they were never told about, even where the work was accurate. Framing the disclosure around the human review step, rather than the AI tool’s capabilities, keeps the client’s actual concern in view: they are asking whether a person stands behind the advice, not whether the firm uses software. The opt-out exists because some clients, particularly on especially sensitive facts, will reasonably want a stricter standard than the default.
Clause 9: record-keeping
Clause text. For every matter where AI tools were used in research, drafting, or document preparation, the firm must maintain a record identifying the tool used, the task it was used for, the lawyer who performed the human verification under clause 6, and the date of that verification. These records must be retained for the life of the matter file and produced on request to a client, a court, or a disciplinary body investigating a complaint.
Why it is written this way. A verification clause without a record-keeping clause is unenforceable after the fact. If a citation error surfaces months later, the firm needs to show who checked it and when, not reconstruct the answer from memory. This is also the record that would satisfy Regulation 42’s disclosure question once it is notified, so the firm is not building a new process from scratch at that point.
Clause 10: shadow AI and personal accounts
Clause text. Use of personal AI accounts, whether free or individually subscribed, for any client-related work is prohibited, regardless of whether the associate believes the tool to be more capable than the firm’s approved list. Any staff member who has used a personal AI account on client work before this policy took effect must disclose that use to the approving partner under clause 5, without disciplinary consequence for the disclosure itself, so the firm can assess whether any client data was exposed.
Why it is written this way. Shadow AI, meaning tools adopted by individual staff outside any firm process, is the most common way client data ends up outside the firm’s control, precisely because it happens quietly and with good intentions. A policy that only punishes shadow AI, without an amnesty for disclosing past use, guarantees nobody discloses it, which leaves the firm blind to its actual exposure. The amnesty exists so the confidentiality risk gets found and contained rather than hidden.
Clause 11: training
Clause text. Every partner, associate, trainee, and relevant staff member must complete AI use policy training before being granted access to any approved tool, and refresher training at least annually or whenever this policy is materially revised. Training must cover the approved tool list, the verification requirement, the confidentiality rule, and at least one worked example of an AI hallucination in an Indian legal context.
Why it is written this way. A policy that exists only as a document nobody has read produces the same failures as no policy at all. Requiring at least one worked hallucination example ties the training to something concrete rather than an abstract warning; Pooja Ramesh Singh itself, where fake citations reached a tribunal order because nobody checked them against the primary source, is the kind of example that makes the verification clause feel necessary rather than bureaucratic.
Clause 12: sanction for breach
Clause text. A breach of this policy, including filing an unverified AI-generated citation, using an unapproved tool for client data, or failing to disclose AI use when a court has required it, is treated as a disciplinary matter within the firm and, where the conduct amounts to professional misconduct, will be referred in accordance with the firm’s obligations under the Advocates Act, 1961. Internal sanctions range from a formal warning and mandatory retraining for a first, promptly self-reported breach, to suspension of AI tool access, and, for deliberate concealment or repeated breaches, to referral for disciplinary proceedings.
Why it is written this way. Section 35 of the Advocates Act, 1961 gives the State Bar Council’s disciplinary committee jurisdiction where an advocate is believed guilty of professional or other misconduct, and Pooja Ramesh Singh has confirmed that citing an unverified AI-generated precedent falls within that category. The clause grades its response because treating a promptly disclosed, honest mistake the same as deliberate concealment discourages the self-reporting clauses 9 and 10 depend on. It is also explicit that internal discipline does not substitute for the firm’s external obligations.
The full policy, ready to copy
The block below is the complete policy in one document. Replace the bracketed placeholders with the firm’s own names and dates before circulating it.
[FIRM NAME] ARTIFICIAL INTELLIGENCE USE POLICY
Effective date: [DATE]
Approving partner: [NAME]
1. PURPOSE AND SCOPE
This policy governs the use of artificial intelligence tools, including generative
AI, legal research AI, and AI-assisted drafting and translation tools, by every
partner, associate, trainee, paralegal, and administrative staff member of the
firm, in connection with any client matter, internal work product, or firm
business. It applies regardless of whether the tool is provided by the firm or
accessed independently, and regardless of whether the output is used in a
filing, an opinion, an email, or internal research.
2. PERMITTED USES
Subject to clauses 4, 5, and 6, AI tools may be used for:
(a) first-pass legal research to locate candidate authorities for human
verification;
(b) summarising publicly available judgments, statutes, or non-privileged
documents;
(c) drafting first drafts of contracts, notices, and pleadings that will undergo
full human review before use;
(d) translation and language support for client communication;
(e) transcription of hearings, depositions, or client meetings where consent
has been obtained;
(f) internal knowledge management, including tagging and indexing of the
firm's own precedent bank; and
(g) administrative tasks such as scheduling, billing narrative drafts, and
internal memo formatting.
3. PROHIBITED USES
AI tools must not be used to:
(a) generate case citations, statutory references, or quotations that are then
filed, emailed to a client, or relied on in advice without independent
verification against a primary source;
(b) input client-identifying information, privileged communications, or
confidential case facts into any tool not on the approved list under
clause 5;
(c) draft or finalise any document for filing without the human verification
step under clause 6;
(d) make or simulate a legal judgment, sentencing recommendation, or
determination of guilt or liability presented as the firm's considered
position;
(e) generate content for a court filing without applying clause 7 where a
court or tribunal requires disclosure; or
(f) substitute for the exercise of independent professional judgment on
strategy, settlement, or advice to a client.
4. CLIENT CONFIDENTIALITY AND DATA HANDLING
No staff member may input client-identifying or privileged information into an
AI tool unless that tool is on the approved list under clause 5 and has been
confirmed in writing by the approving partner to meet the firm's data-handling
standard. Free-tier or consumer AI tools must never be used for client-
identifying input. Processing of personal data through an approved tool must
comply with the firm's obligations as a Data Fiduciary under the Digital
Personal Data Protection Act, 2023 and the DPDP Rules, 2025.
5. APPROVED TOOLS AND APPROVAL AUTHORITY
The firm maintains a written approved-tools list, reviewed at least every six
months and whenever a new tool is proposed. A tool is added only after the
approving partner has reviewed the vendor's data-processing terms, training-
data use, retention period, and processing location. No staff member may adopt
a new tool for client-related work without this approval.
6. MANDATORY HUMAN VERIFICATION BEFORE FILING
No document containing AI-generated or AI-assisted content may be filed with
any court, tribunal, or authority, or sent to a client as final advice, until every
citation, quotation, and factual claim has been independently checked by a
named human lawyer against the primary source. The verifying lawyer and the
date of verification must be recorded under clause 9 before the document
leaves the firm.
7. DISCLOSURE TO COURTS
Where a court or its practice directions require disclosure of AI use in a
filing, that disclosure must state which tool was used, the extent of its
contribution, and the verification performed. Where no binding requirement
exists, the firm does not volunteer disclosure of routine, verified AI-assisted
drafting, but gives a truthful and complete answer if a court asks directly.
8. DISCLOSURE TO CLIENTS
Clients are told, in the engagement letter or a written update, that the firm
may use AI tools in its process, subject to this policy, and that all advice and
filings are reviewed and approved by a named human lawyer. A client may
request that no AI tool be used on their matter, and that request is honoured
and recorded.
9. RECORD-KEEPING
For every matter where AI tools were used, the firm maintains a record of the
tool, the task, the verifying lawyer, and the date of verification. Records are
retained for the life of the matter file and produced on request to a client,
court, or disciplinary body.
10. SHADOW AI AND PERSONAL ACCOUNTS
Personal AI accounts must not be used for client-related work. Staff who used a
personal account before this policy took effect must disclose that use to the
approving partner without disciplinary consequence for the disclosure, so the
firm can assess any client-data exposure.
11. TRAINING
All staff complete AI use policy training before gaining access to any approved
tool, and refresher training at least annually. Training covers the approved
tool list, verification, confidentiality, and a worked hallucination example.
12. SANCTION FOR BREACH
A breach, including an unverified AI citation reaching a filing, unapproved-tool
use with client data, or failure to disclose AI use where required, is a
disciplinary matter within the firm and, where it amounts to professional
misconduct, is handled in accordance with the firm's obligations under the
Advocates Act, 1961. Sanctions range from a warning and retraining for a
promptly self-reported first breach to referral for disciplinary proceedings for
deliberate concealment or repeated breaches.
Acknowledged and agreed:
[NAME] [SIGNATURE] [DATE]
How a filing moves through the approval gate
flowchart TD
A[Lawyer drafts using an AI tool] --> B{Tool on approved list, clause 5?}
B -- No --> C[Stop. Route through tool approval first]
B -- Yes --> D[Draft with citations produced]
D --> E{Every citation checked against primary source, clause 6?}
E -- Not yet --> F[Return to draft. No filing]
E -- Checked --> G{Client-identifying data involved?}
G -- Unapproved handling --> C
G -- Handled per clause 4 --> H[Named lawyer records verification, clause 9]
H --> I{Court requires AI disclosure, clause 7?}
I -- Yes --> J[File disclosure statement with the document]
I -- No --> K[File the document]
J --> L[Document filed]
K --> L
Rolling this out in a firm that has never had one
Two points matter for firms with existing AI use that predates any written rule. First, clause 10’s amnesty has to run before clause 5’s approval process starts, or nobody will disclose what they have already been doing. Second, the six-month tool review is a floor, not a target: a tool approved on today’s vendor terms is not automatically approved after the vendor’s next terms-of-service update. Firms spanning litigation and unfiled transactional work may want to tier the approved-tools list by sensitivity rather than run one list for everything, which is a variation on clause 5, not a departure from it.
The verification clause is where firms underestimate the time cost until they measure it. Pulling a reported judgment and checking subsequent treatment takes ten minutes to an hour depending on how well-indexed the source is, and a primary versus secondary legal sources discipline only shortens that if the associate already knows which reporter to check first. Firms deciding whether to add a dedicated legal AI tool to the approved list will find the trade-offs in choosing an Indian case law search engine, the best AI legal drafting tools in India, and legal AI for small law firms in India. Where a client asks where their matter data is stored, that belongs in clause 4’s approval record; our explainer on AI data residency requirements for Indian legal work covers what to check before a tool goes on the list.
Frequently asked questions
Does a small law firm actually need a written AI use policy, or is this only for large firms?
Yes, regardless of size. The professional conduct obligations under the Advocates Act, 1961 and the confidentiality duty under Section 132 of the Bharatiya Sakshya Adhiniyam, 2023 apply to every advocate individually, not only to firms above a certain size. A solo practitioner using AI without any written process carries the same verification and confidentiality exposure as a large firm, with fewer people to catch a mistake before it reaches a client or a court.
Who should be the “approving partner” in clause 5 at a small firm?
At a firm too small to have a dedicated compliance role, the managing partner or the most senior partner typically holds this responsibility directly. What matters is that one named person, not a rotating or informal arrangement, reviews vendor terms and signs off on each tool, so there is a clear answer if a client or disciplinary body later asks who approved a specific tool’s use.
Can a firm rely on the AI tool’s own claim that it does not train on user data?
No, not without independent confirmation in writing. Vendor marketing claims and a vendor’s actual data-processing terms sometimes diverge, and terms change without individual notice to every user. Clause 5 requires the approving partner to review the written data-processing terms directly, not rely on a summary, before any tool goes on the approved list.
What happens if an associate used an unapproved tool before the policy existed?
Clause 10’s amnesty is designed for exactly this situation. The associate discloses the prior use to the approving partner without facing discipline for the disclosure itself, so the firm can assess whether client data was exposed and take any necessary steps, such as notifying the client or reviewing the vendor’s retention practices. Discipline attaches to concealment after the policy takes effect, not to honest disclosure of past conduct.
Does the mandatory verification clause apply to internal memos, or only to court filings?
The clause as drafted applies to anything filed with a court or tribunal and to final advice sent to a client. A firm can extend it to internal memos if it wants a single standard across all work product, but the drafting above keeps the mandatory gate at the two points where an error has external consequences, since requiring full primary-source verification on every internal draft would slow down legitimate first-pass research without adding real protection.
How does this policy relate to the Supreme Court’s draft AI regulations for courts?
The Draft Regulations for Use of Artificial Intelligence in Courts, 2026 are not yet notified, so they do not bind a firm today. This policy’s disclosure clause is written to work under the current position and to convert cleanly into compliance with Regulation 42’s disclosure duty once the draft is notified, because the record-keeping clause already captures the information Regulation 42 would require a court to be able to ask for.
Is using AI to draft a first version of a contract itself a professional conduct violation?
No. The Supreme Court said explicitly in Pooja Ramesh Singh that its ruling has no bearing on the rightful use of AI, only on presenting unverified or fabricated material as though it were law. Drafting a first version with AI assistance and then having a qualified lawyer review, correct, and take responsibility for the final version is exactly the workflow the permitted-uses clause describes.
What counts as “client-identifying information” for the confidentiality clause?
It includes the client’s name, the names of parties or witnesses, specific facts unique to the matter, document contents, and any detail that would let a third party identify who the matter concerns even without the client’s name being used directly. A hypothetical fact pattern stripped of all identifying details is generally outside this restriction, but the safer practice is to route anything drawn from an actual client matter through an approved tool rather than judge the anonymisation case by case.
Does the firm need separate consent from the client to use AI on their matter?
Not as a matter of professional conduct rules, provided the client has been told in the engagement letter or a written update under clause 8 that the firm may use AI tools subject to its safeguards. What the client is entitled to, and what clause 8 preserves, is the right to opt out and request that no AI tool be used on their specific matter.
Who is responsible if an AI hallucination reaches a filing despite the policy?
The lawyer who signed and filed the document, not the AI tool and not the firm’s policy in the abstract. This is the position the Supreme Court took in Pooja Ramesh Singh: the advocate who cites an AI-generated precedent without verification has committed misconduct, and a well-drafted policy that was not actually followed on that filing does not change that. The policy reduces the chance of this happening; it does not shift the underlying duty.
How often should the approved-tools list actually be reviewed in practice?
The policy sets a floor of six months, and that floor should be treated as a maximum interval, not a target. A material change to a vendor’s terms of service, a new AI feature added to an existing approved tool, or a client raising a specific data-residency question are all events that should trigger an out-of-cycle review rather than waiting for the next scheduled one.
What is the difference between disclosure to a court and disclosure to a client under this policy?
Disclosure to a court, under clause 7, is conditional on what that specific court or tribunal’s rules require, and the default is not to volunteer it for routine, verified drafting. Disclosure to a client, under clause 8, is unconditional and happens at the start of the engagement, because the client relationship is ongoing and the client’s right to know how their matter is being handled does not depend on whether a particular filing happens to trigger a court disclosure rule.
Adopting a written policy is the first step. The verification clause in it only holds if the underlying check is fast enough that a busy associate actually runs it on every filing, not just the ones that feel risky. A citator that surfaces the reported judgment and its subsequent treatment in one lookup, rather than requiring a separate search for each, is what makes clause 6 practical rather than aspirational; see how that check works in practice in Niyam’s good-law checking.