The Percentage of Firms With No AI Data Security Policy Might Surprise You

43% of law firms have no formal AI policy, effectively offloading risk decisions onto individual lawyers and creating a governance gap that increasingly catches the eye of malpractice insurers

Share
The Percentage of Firms With No AI Data Security Policy Might Surprise You

43% of law firms have no formal AI policy. No plans to write one, either.

That's not a lag in paperwork. It's a governance decision the firm hasn't named as one yet. Every day without a policy is a day the firm has implicitly decided that individual lawyers, not the organization, own the risk decisions around what goes into an AI tool and what comes out of it.

For managing partners and boards, an AI policy belongs in the same category as a conflicts policy or a cybersecurity plan. Not because the technology is unusually dangerous. Because it's increasingly the first place a malpractice insurer looks. CNA, the largest legal malpractice carrier in the U.S., has already added supplemental AI-usage questionnaires to its renewal process. Firms that can't answer them are starting to see it show up in premiums and coverage terms.

The ordinary version of this gap looks like a mid-level associate summarizing a stack of discovery documents with AI on a Friday afternoon. No one at the firm has decided which tools are approved, whether the output needs a second reviewer, or who signs off before it reaches a filing. Nothing in writing says no. By default, everything is allowed.

The scale of the gap is the real story. Personal AI use among lawyers has more than doubled in a year, from 31% in 2025 to 69% in 2026. Formal firm-wide policy adoption hasn't kept pace: it sits around 21%, per the 2025 Legal Industry Report. Even among firms with a written policy, only 9% say it's enforced. More than half, 54%, offer no AI training at all.

What happens without a checkpoint in that gap is already on the record. In Akerlund v. Atlas Air, Inc. (11th Cir., July 2026), an appellate brief carried eight fabricated case citations. Eight, not one. That's the kind of volume a second reviewer catches on page one, if a second reviewer exists at all. The matter was referred to the bar.

The likely objection: our people are careful, we don't need a formal process. That confidence holds until a specific matter proves otherwise, and by then the question isn't whether your lawyers were careful. It's what your governance committee can point to when asked what controls existed at the time.

A useful policy doesn't need to be long. It needs to answer three questions clearly: which tools are approved, what output requires human verification before it leaves the building, and who owns enforcement. If your firm can't answer all three today, that's the gap a board should be asking about, before a claim forces the conversation.