In conversations about AI, firms often frame the decision as adopt or wait. That framing is already out of date. In most practices, staff are using consumer AI tools today - for drafting, for summarising, occasionally with client material in the prompt. The real choice is not whether AI is in the practice. It is whether it operates under the firm's governance or around it.
Why “wait” is the riskiest option
A firm that has not provided a governed alternative has not avoided AI risk; it has outsourced its AI policy to whichever tool each employee prefers. Client confidentiality then depends on individual judgement about what is safe to paste into a public tool - a standard no firm would accept for physical files. The uncomfortable conclusion: doing nothing is the permissive option.
What governed looks like
A governed deployment differs from consumer usage on five specifics:
- Approved sources only. The assistant indexes the firm's SOPs, templates, precedents, circulars and internal guidance - nothing else. It answers from the firm's knowledge, not the open internet's confidence.
- Role-based access. Engagement teams see only their own client material. The partner's boundary questions - who can see what - are answered by the access model, not by trust.
- Source-linked answers. Every draft cites the document and section it came from, so review means checking a reference, not fact-checking a black box.
- Audit logging. Every query and retrieval is recorded. When someone asks “has client data been put into AI?”, the firm has a log, not a hope.
- A data boundary. The environment is approved, and client data never trains a public model.
The line that does not move
One rule sits above the architecture: the assistant produces assistance and first drafts - it never produces a professional opinion. Anything that becomes advice, a filing or a client communication is approved by a qualified person. This is not a limitation to apologise for; it is the design principle that makes the rest acceptable. Technology adoption should strengthen professional responsibility, never weaken it.
Where to start if the firm is uneasy
Governance can precede any assistant. An AI acceptable-use policy, an access model and a data-handling standard are a complete, standalone piece of work - no assistant, no client data, just the guardrails. Firms that start there make the eventual deployment decision from a position of control rather than anxiety. And if the answer is still “not yet”, the policy alone has closed the ungoverned gap that existed before.
The firms that navigate this well will not be the ones that adopted fastest or resisted longest. They will be the ones that made the choice deliberately, wrote the rules down, and could evidence both.