How to Design Your Firm's AI Usage Policy

Tyra Delos Reyes

Your firm doesn’t need to formally adopt AI before setting expectations around its use.

Cruz Marcelo & Tenefrancia (CMT) developed its AI governance policy while still evaluating different tools, recognizing that lawyers may already be experimenting with AI as regulation continues to evolve.

So what should responsible AI use actually look like inside a law firm?

We asked Atty. Rogelio Torres Jr. and Atty. Jerome Canlas how CMT approached that question. Their experience offers a practical blueprint for firms that want to start now.

Before writing the policy, decide what your firm wants from AI

Before writing rules, decide what role AI should play in your practice. For Atty. Canlas, that starts with the partners:

“The partner should know what you want to achieve. The partner should know what you want to avoid.”

At CMT, the answer was rooted in the kind of firm they wanted to remain. 

Their policy commits to the “responsible adoption of appropriate technologies to enhance the efficiency and quality of its legal services,” while preserving professional competence, fidelity, and confidentiality.

That gives the rest of the policy a north star. Approved tools, prohibited uses, and data rules can all flow from a clearer question: What should AI help us do better, and what should it never compromise?

The two partners describe a culture of partner ownership at CMT, where direction starts with firm leadership. That opens up a wider conversation: how can partners help their teams use AI responsibly?

Atty. Torres also recommends speaking with associates about what they’re already using, where AI is entering their work, and where they still have questions.

How to build your firm’s AI policy

Based on CMT’s approach, a workable AI policy can be built around eight core sections:

1. Define the purpose and scope of AI use

Start with why the firm is using AI and who the policy covers.

Atty. Torres said CMT’s policy applies not only to lawyers, but also to legal and non-legal personnel, such as contractors, consultants, and others involved in the firm’s operations.

The policy should make clear what AI is expected to help with, whether it’s research, drafting, efficiency, or other work.

2. Incorporate your core professional obligations

Atty. Torres identified principles in CMT’s policy including human sovereignty and oversight, fidelity, strict confidentiality, transparency, and fairness.

“It has to be clear that we’re not entirely foregoing any intervention by lawyers in the use of AI.”

These principles give lawyers something to fall back on when the policy doesn’t address a specific situation.

3. Create a whitelist of approved AI tools

CMT recommends identifying which AI tools lawyers are actually allowed to use. For Atty. Canlas, the first criterion should be data security.

“The principal and primary consideration [is] that our information and our data is safe if we use this AI.”

Before approving a tool, firms should ask: 

  • What happens to our prompts and uploads? 

  • Who can access them? 

  • Are they used to train AI models? 

  • How are they stored and deleted?

Vendors should be able to answer those questions clearly. Anycase, for example, is explicit about how customer data is handled, including its policy of not using customer data to train AI models. That kind of transparency gives firms something concrete to evaluate when deciding which tools they’re comfortable approving.

Ease of use matters too, but Atty. Canlas recommends treating it as secondary to whether the firm’s information stays safe.

4. Define what lawyers can and cannot do instead of policing prompts

Atty. Canlas described the basic approach as telling lawyers what they can do and what they cannot do: 

  • what AI may be used for

  • what uses are prohibited

  • what information can be uploaded

  • when human review or additional approval is required.

CMT deliberately doesn’t regulate every possible prompt.

“We don’t have specific and strict guidelines as to prompts, but we have strict guidelines on the use of and uploading of information on the AI tool.”

5. Set clear rules for confidential information

Confidentiality should have its own section. Atty. Torres recommends understanding a tool’s policies around areas such as data retention and deletion before uploading sensitive information. 

If there’s still doubt, take the conservative route.

“Our obligation to be competent doesn’t outweigh our obligation to hold client confidences.”

He also emphasized that lawyers should ask whether the AI needs the information at all:

“Don’t be lazy. Don’t just upload without thinking.”

As he put it, “There’s a way to pose the query and still maintain confidentiality.”

6. Make human review and lawyer responsibility explicit

Using an approved tool doesn’t transfer responsibility to the AI. Lawyers still need to verify authorities, check the facts, review drafts, and decide whether the output is appropriate for the client.

Atty. Torres put it plainly: “It’s always the responsibility of the lawyer. It’s never the AI.”

7. Set out enforcement and sanctions

CMT’s policy also addresses unauthorized use and sanctions. But Atty. Canlas acknowledged that firms can’t monitor every interaction with AI.

He described enforcement as “more of an honor code”, supported by clear rules, lawyers’ professional obligations, and disciplinary consequences when improper use is discovered.

The policy should therefore make clear what counts as non-compliance, how exceptions are approved, and what happens when the rules are breached.

8. Build the policy to change

Cruz Marcelo & Tenefrancia intentionally designed its policy to evolve alongside future Supreme Court guidance.

Atty. Canlas said it needed to remain flexible enough to change, while still providing clarity on what associates can and can’t do with their AI tools. 

AI policies don’t have to be complicated: even a three-lawyer firm should have one

When we asked Atty. Torres whether even a three-lawyer practice should establish an AI policy, his answer was: “With more reason.”

His reasoning was practical:

“If you have limited resources, you have to make use of what’s available… small firms really do have a tendency to use AI more.”

At the very least, the core of an AI policy should give everyone in the firm the same answers to a few basic questions:

  • Which AI tools are approved?

  • What information can and cannot be uploaded?

  • What uses of AI are allowed?

  • What level of human review is required?

  • Who remains responsible for the final work?

Those rules can evolve as the tools and Supreme Court guidance do. The important starting point is giving lawyers a shared standard for how AI should be used inside the firm today.

Level 21, 8 Rockwell, Hidalgo Dr., Rockwell Center, Makati City, Metro Manila, Philippines

Level 21, 8 Rockwell, Hidalgo Dr., Rockwell Center, Makati City, Metro Manila, Philippines

Level 21, 8 Rockwell, Hidalgo Dr., Rockwell Center, Makati City, Metro Manila, Philippines

Level 21, 8 Rockwell, Hidalgo Dr., Rockwell Center, Makati City, Metro Manila, Philippines