All resources

Law-firm AI workflow

AI for Law Firms: A Safe Workflow Checklist

A practical workflow for using generative AI in a law firm with approved tools, protected inputs, source verification, human review, and lawyer approval.

12-minute readPublished October 3, 2026Reviewed October 3, 2026

Prepared and reviewed by the Law Firm Training Manual Editorial Team. Read our editorial and correction standards or report a correction.

Update note: Initial publication. Florida Ethics Opinion 24-1, current Florida Bar rules, ABA Formal Opinion 512, NIST AI risk guidance, and FTC privacy guidance were checked on October 3, 2026.

On this page

Start with permission, purpose, and destination

Do not begin by pasting a document into the first available chatbot. Start with the matter, client or prospective-client status, assigned task, responsible lawyer, operator, intended recipient, delivery channel, and protected workspace. The lawyer or firm must identify whether AI is permitted for this task, which tool and account may be used, what information may be submitted, what review is required, and which uses are prohibited.

Florida Ethics Opinion 24-1 is an advisory opinion, not a binding court rule, but it identifies core professional concerns for Florida lawyers using generative AI: competence, confidentiality, oversight, fees and costs, and advertising. ABA Formal Opinion 512 is supplementary national ethics guidance and is not binding Florida authority; the NIST AI Risk Management Framework is voluntary risk guidance rather than a Florida legal rule. Opinion 24-1 emphasizes that lawyers remain responsible for their work product and professional judgment. Staff therefore uses AI only inside an approved human-controlled workflow, never as an independent decision-maker or final reviewer.

  • Record the approved task, purpose, tool, account, input class, sources, reviewer, destination, and prohibited uses.
  • Check current firm policy, engagement terms, client instructions, protective orders, court or judge requirements, and vendor conditions.
  • Stop when authorization, confidentiality, consent, disclosure, court treatment, or billing remains unresolved.

Verify the tool environment before exposing information

A product name alone does not describe the environment that will receive the data. Verify the exact account and workspace, plan or contract, administrator controls, retention, provider access, model-training or improvement settings, sharing, integrations, connected storage, export, deletion, incident notice, and access conditions relevant to the approved task. A firm account and a personal or public account may have different controls even when the interface looks the same.

The FTC has warned AI providers to honor privacy and confidentiality commitments, but a provider’s marketing statement does not replace the firm’s review. Save the applicable terms, settings, approval, and review date rather than assuming that a familiar tool is approved for every client, data type, or use.

  • Use only the firm-approved account and workspace for the assigned use.
  • Treat plugins, browser extensions, connectors, shared links, synchronized folders, and retrieval features as additional disclosure paths.
  • Recheck material vendor, model, retention, sharing, or integration changes before relying on an earlier approval.

Classify and minimize every proposed input

Before prompting, classify each proposed input under the firm’s approved scheme: public, firm-internal, client confidential, privileged or work product, personal or sensitive, court-restricted, or prohibited. Remove information that is unnecessary for the task, use neutral labels or synthetic examples when authorized, and obtain the required lawyer approval before protected information is entered, attached, pasted, linked, synchronized, or exposed through an integration.

Florida Ethics Opinion 24-1 explains that the confidentiality duty is broad and recommends obtaining the affected client’s informed consent before using a third-party generative-AI program when the use would disclose confidential information. The responsible lawyer decides whether disclosure is permitted, whether consent is required or appropriate, and what safeguards are sufficient. Staff does not infer consent from the client’s use of email, a general technology clause, or the fact that a tool offers a delete button.

  • Build an input manifest showing each file or field, its classification, necessity, approval, and transformation.
  • Do not submit one client’s material to improve work for another client or a general firm template without authorization.
  • Never rely on deletion after submission as the primary confidentiality safeguard.

Build the source set before writing the prompt

AI cannot verify a matter from sources it was never given, and access to a source does not make the model’s use of it reliable. Assemble the lawyer-approved source set first and distinguish matter records, primary authority, official instructions, firm-approved references, and background material from AI-generated text. Preserve original documents separately from converted, OCR, excerpted, or annotated working copies.

Give the tool a bounded task, named source limits, required output structure, uncertainty instruction, citation format, and an express prohibition against inventing missing facts, quotations, authorities, page references, dates, amounts, people, or actions. Prompt wording is a control, not a guarantee; every output remains unverified.

  • Identify the exact question and the facts or fields the tool may extract, compare, organize, or draft.
  • Require unknown, conflicting, ambiguous, and source-missing items to remain visible.
  • Keep outside knowledge or web material out unless the lawyer approved the source and research method.

Preserve a reproducible AI work record

A useful control record lets another qualified reviewer reconstruct what was evaluated without duplicating protected content into an insecure log. Record the matter and task, authorization, tool environment, operator, source-set version, materially relevant prompt and attachments, output, model or product identifier when available, date, reviewers, flags, disposition, and approval evidence.

Preserve iterations when a changed prompt, source, model, or output affects the work product. Subject to the approved firm and client retention or deletion policy, do not overwrite the rejected output that explains why a correction was needed, and do not treat a polished final document as proof that the underlying AI output was accurate or appropriately reviewed.

  • Separate preserved source records, AI inputs, raw outputs, human corrections, lawyer decisions, and the approved final version.
  • Use stable source identifiers so every extracted statement or drafted proposition can be traced.
  • Record retention or deletion only after the approved evidence and final work product are safely preserved.

Verify every material proposition against the exact source

Treat the output as a candidate work product. Compare every material name, date, amount, quotation, citation, document reference, page or line, defined term, event, status, and requested action with the exact approved source. Check for omissions, changed meanings, contradictory records, unsupported inferences, fabricated detail, hidden instructions, bias, confidentiality leakage, and content outside the assigned scope.

For legal research, open each cited authority from an authoritative source and verify its identity, status, proposition, quotation, context, and later treatment as directed. The responsible lawyer must verify the accuracy and sufficiency of all legal research performed by generative AI; staff source-checking or another AI review does not replace that duty. For records and drafting, maintain source-to-output traceability. A second AI pass, automated score, citation-looking link, or confident explanation is not human verification.

  • Mark each proposition verified, corrected, excluded, unresolved, or lawyer-decision-required with its source citation.
  • Do not convert an AI inference, summary, suggested deadline, or probable match into a matter fact.
  • Reverify downstream work when a source, output, fact, authority, or approved version changes.

Match the control to the legal workflow

The same safety sequence supports different tasks, but each workflow needs its own exact-set and decision boundaries. Intake summaries must preserve the prospective client’s words and leave conflict identity and representation decisions to qualified humans. Inbox and court-filing triage must preserve messages and attachments while humans control matter matching, deadlines, filing status, and every consequential action.

Chronologies, deposition indexes, discovery matrices, medical-record timelines, billing ledgers, and personal-injury demand materials require stable source citations and neutral treatment of conflicting evidence. Lawyers and qualified professionals control legal significance, testimony use, discovery sufficiency, privilege, medical interpretation, causation, damages, coverage, liens, valuation, strategy, and outgoing advocacy.

  • Use the task-specific lesson and checklist rather than treating one general AI prompt as a universal workflow.
  • Preserve the exact source set and page, line, request, response, record, bill, or exhibit reference required by that task.
  • Prevent AI from sending, filing, calendaring, accepting, rejecting, negotiating, or updating a system of record without approved human action.

Require human review and lawyer-controlled release

Route legal judgment, privilege, disclosure, consent, advice, strategy, filings, communications, advertising, fees, and remediation to the responsible lawyer. Obtain documented human review appropriate to the risk and final lawyer approval when the work product or action requires it. The reviewer must have the source set, not merely the AI output and a statement that it was checked.

Before release, freeze the approved version and inspect the exact outgoing file, message, filing set, or system entry. Remove comments, hidden prompts, tracked changes, metadata, or unnecessary AI artifacts as directed; verify recipient, channel, attachments, permissions, confidentiality, and status evidence; and preserve the approval and delivery record.

  • An AI confidence statement or second model is not a substitute for qualified human review.
  • Never allow the drafting tool to become the final sender, filer, deadline calculator, conflict resolver, or legal approver.
  • Record the reviewer, approval scope, exact approved version, release result, and any limitation carried forward.

Control billing, disclosure, corrections, and closure

Florida Ethics Opinion 24-1 warns against duplicative or falsely inflated billing and addresses actual AI costs, overhead, and client communication. When a lawyer intends to charge an actual client-specific AI cost, the opinion says the lawyer should inform the client, preferably in writing. If the actual AI cost attributable to a particular client matter cannot be determined, periodic or subscription charges may not be prorated to the client and must be treated as overhead. ABA Formal Opinion 512 also discusses reasonable fees and communication duties. Staff records actual work and client-specific costs; the lawyer controls fee treatment, engagement terms, communication, and whether AI use must or should be disclosed in the circumstances.

Client-facing or third-party chatbots create additional intake and advertising risks. Opinion 24-1 says they must identify themselves as AI rather than a lawyer or law-firm employee and comply with advertising restrictions. An overly welcoming intake experience can also create prospective-client or relationship risk, so lawyer-approved warnings and limitations must be clear and understandable. More broadly, the lawyer controls all disclosures about AI assistance, limitations, incidents, corrected work, or affected recipients.

Close the AI work record only after delivery, approved retention or deletion, open limitations, downstream dependencies, corrections, and incidents are resolved or assigned. Reopen it if a source, fact, authority, output, vendor condition, or recipient action changes the reliability or permitted use of the work.

  • Do not bill estimated manual time when AI made the task faster, duplicate charges, or prorate periodic or subscription AI charges when the actual client-specific cost cannot be determined.
  • Escalate a suspected confidentiality leak, fabricated authority, wrong-matter output, misleading communication, or released error immediately.
  • Preserve the corrected version, affected downstream work, notification decision, remediation, owner, and closure evidence.

Continue with the related workflow

Use these guides when the next step moves from general verification into a specific filing or scheduling workflow.

Safe law-firm AI workflow checklist

Use this as a conversation starter with the person responsible for the work. Replace general language with the firm’s actual systems, owners, and procedures.

  • The matter, client or prospective-client status, task, responsible lawyer, operator, destination, and protected workspace are verified.
  • The exact tool, account, workspace, purpose, input class, reviewer, and prohibited uses are currently approved.
  • Firm policy, engagement terms, client instructions, protective orders, and court or judge requirements were checked.
  • Retention, sharing, training or improvement, integrations, export, deletion, access, and incident conditions were reviewed for the exact environment.
  • Every input is classified, minimized, necessary, approved, and entered only through the permitted route.
  • The lawyer resolved confidentiality, consent, disclosure, privilege, work-product, court-restriction, and sensitive-data questions.
  • The approved source set is frozen, originals are preserved, and the bounded prompt forbids invented content.
  • The prompt, attachments, output, product or model identifier when available, date, versions, and reviewers are recorded securely.
  • Every material name, date, amount, quotation, citation, document reference, event, and action was verified against the exact source.
  • Unknowns, conflicts, omissions, unsupported inferences, confidentiality issues, and legal decisions remain visible and escalated.
  • The task-specific workflow preserves its own exact-set, source-citation, and lawyer-decision boundaries.
  • Qualified human review and required lawyer approval cover the exact final version and intended destination.
  • The outgoing file, message, filing, or system action passed recipient, channel, attachment, permission, metadata, and status checks.
  • Actual time, approved costs, billing treatment, and any required communication or disclosure were handled under lawyer direction.
  • Delivery, retention or deletion, corrections, incidents, downstream effects, limitations, ownership, and closure are documented.

Official references

These primary sources support the general operational controls discussed above. Check their current versions and follow the governing court, judge, clerk, software, and firm procedures for the actual work.

Related lesson previews

Practice one workflow at a time

Responsible AI Operations

Use Generative AI Safely in a Florida Law Firm

Use an approved generative-AI tool through controlled inputs, exact source verification, human review, lawyer approval, and documented release.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Summarize New-Client Intake and Prepare Conflict-Check Inputs

Turn an approved intake submission into a source-linked summary and candidate conflict-search input set while qualified humans control every legal and representation decision.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Triage a Law-Firm Inbox and Build a Daily Action Queue

Use approved AI to summarize email and propose matter matches, action items, dates, priorities, and drafts while humans control every consequential action.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Triage Florida Court-Filing Emails and File Pleadings

Preserve court-filing email and attachments, use approved AI to propose exact matter and document matches, and file only after qualified human review.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Build a Verified Matter Chronology from Pleadings, Orders, Correspondence, and Records

Use approved AI to propose a source-linked matter chronology while humans verify every event and lawyers control legal significance, deadlines, and strategy.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Summarize a Deposition Transcript and Build a Verified Testimony Index

Use approved AI to create a source-linked deposition summary and testimony index while humans verify every page-line citation and lawyers control legal use.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Compare Discovery Requests and Responses and Build a Verified Response Matrix

Use approved AI to align discovery requests with exact responses, objections, verifications, productions, and amendments while humans verify every source and lawyers control legal conclusions.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Build a Verified Medical-Record Chronology and Treatment Index

Use approved AI to organize medical records into a source-linked chronology and treatment index while humans verify every citation and lawyers control medical and legal conclusions.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Build a Verified Medical-Billing and Payment Ledger

Use approved AI to organize bills, ledgers, EOBs, payments, adjustments, and balances into a source-linked ledger while humans verify every entry and lawyers control medical and legal conclusions.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Build a Verified Personal-Injury Demand Package Index

Use approved AI to organize a personal-injury demand package into a source-linked index while humans verify every citation and the lawyer controls liability, causation, damages, coverage, liens, value, and strategy.

Preview lesson

AI-Assisted Law-Firm Workflows

Use AI to Prepare a Source-Verified Personal-Injury Demand Letter Draft

Draft a personal-injury demand letter from a lawyer-approved proposition matrix while humans verify every source and the lawyer controls all substantive positions, terms, and transmission.

Preview lesson