
An Iowa City law firm's guide to using AI without putting client information at risk
By Dan Roberts
AI is already finding its way into law firms.
Attorneys and staff may use it to summarize information, brainstorm ideas, draft emails, organize notes, research topics, or get a first draft started. AI features are also appearing inside software the firms already use, sometimes without employees even thinking of them as AI.
That creates an important question for Iowa City law firms:
Is AI actually safe to use in a law firm?
The short answer is AI can be used more safely in a law firm when the firm chooses appropriate tools, protects confidential information, establishes clear rules for employees, and requires people to review AI-generated work.
The bigger risk may be allowing employees to experiment with AI without knowing what tools they're using, what information they're entering, or what happens to that information afterward.
Why AI Requires Extra Caution In A Law Firm
Every business needs to think about data security when using AI.
Law firms have an additional concern: they routinely work with information clients expect them to protect.
Client communications, contracts, financial information, litigation documents, case strategies, personally identifiable information, internal correspondence, and other sensitive material can all find their way into everyday workflows.
That makes the question more complicated than, "Is ChatGPT safe?"
A better question is:
"Do we know how AI is being used inside our law firm, and have we established appropriate safeguards?"
The American Bar Association addressed generative AI in Formal Opinion 512. Its guidance makes clear that using AI doesn't eliminate a lawyer's existing professional responsibilities. Among the issues lawyers need to consider are competence, protecting client information, communication, supervision, and verifying work produced with AI.
For individual Iowa firms, specific ethical and legal requirements should be evaluated with appropriate legal or professional guidance. From an IT and cybersecurity perspective, however, there are several practical questions every firm can start asking.
Do You Know Which AI Tools Your Employees Are Using?
This is the place to start.
You can't create an effective AI strategy if you don't know how AI is already being used.
An employee may be using a public AI website to help write an email. An attorney might experiment with AI for research. Someone may have installed a browser extension. Your meeting platform may offer an AI transcription or summary feature.
Some of those uses may be appropriate.
Others may introduce risks the firm's leadership hasn't considered.
Our AI Readiness Guide asks this same question. Employees may already be using AI websites, apps, browser extensions, meeting recorders, and built-in AI features without formal approval.
Before deciding what employees should or shouldn't do with AI, find out what they're already doing.
What Information Do Employees Put Into AI?
This may be the most important question for a law firm.
An employee who copies information into an AI prompt may be sharing more than they realize.
That could include client information, internal documents, financial information, passwords, contracts, correspondence, or other sensitive material.
The ABA's AI guidance emphasizes lawyers' obligation to evaluate risks involving client information when using generative AI.
This is why "Don't put anything confidential into AI" is a useful starting point, but it isn't a complete AI policy.
Employees need to understand what your firm considers sensitive, which AI tools are approved, and what information can and cannot be used with those tools.
Are You Using Company-Approved AI Tools?
Not all AI tools work the same way.
They can have different privacy settings, security controls, data retention practices, administrative capabilities, integrations, and terms governing how information is handled.
A tool being popular doesn't automatically make it appropriate for firm data.
That's why RTS recommends establishing which AI tools, apps, extensions, meeting recorders, and integrations are approved rather than leaving each employee to make the decision independently.
The goal isn't necessarily to prohibit AI.
It's to make its use intentional.
Are Attorneys Checking What AI Produces?
AI can sound remarkably confident when it's wrong.
That's especially important in a law firm, where a polished answer isn't enough. Facts, citations, legal authorities, summaries, calculations, and other AI-generated information may still require verification.
The ABA's guidance says lawyers using generative AI need a reasonable understanding of its capabilities and limitations, and AI output must be appropriately reviewed for accuracy.
RTS takes a similar approach in its general AI safety guidance:
Verify before you trust.
And:
Never let AI make the final decision.
AI can assist the person doing the work.
It shouldn't remove that person's responsibility for the work.
What About AI Meeting Recorders And Browser Extensions?
This is an area businesses can easily overlook.
An AI meeting assistant may be able to hear conversations. A browser extension may interact with information displayed in a browser. An integration may have access to email, files, calendars, or other company systems.
The RTS AI Readiness Guide specifically calls attention to meeting recorders, browser extensions, and automation because seemingly harmless tools can potentially have extensive access to company information and systems.
For a law firm, those tools deserve the same scrutiny as the more obvious AI applications employees intentionally open and use.
Do Your Employees Know The Rules?
Telling employees to "be careful with AI" isn't much of a policy.
What does careful mean?
Can they use AI to rewrite an email?
Can they upload a document?
Can they summarize meeting notes?
Can they enter client information?
Can they use an AI meeting recorder?
Can they install an AI browser extension?
Which tools are approved?
Who should they ask when they're unsure?
If employees don't know the answers, they're left to make individual decisions about risk.
RTS recommends giving employees clear, consistent rules through a written AI Acceptable Use Policy and training.
Does Your Firm Have An AI Acceptable Use Policy
A written AI Acceptable Use Policy (AUP) helps turn vague guidance into practical expectations.
It can define which tools employees may use, what information must stay out of AI systems, when human review is required, what uses are prohibited, and what an employee should do when they're unsure.
For law firms, the policy should be developed with the firm's professional, contractual, privacy, cybersecurity, and other obligations in mind.
Technology policies also shouldn't be created once and forgotten.
AI tools are changing quickly. The way employees use them is changing just as quickly.
Your AI policy should be reviewed as your technology and business needs change.
Is Using AI Worth The Risk For A Law Firm?
The answer doesn't have to be either "Use AI everywhere" or "Ban AI completely."
AI can be useful.
The challenge is deciding where it belongs, which tools are appropriate, what information they can access, and where human judgment must remain in control.
A firm with clear rules and informed employees is in a very different position from a firm where everyone is experimenting independently.
The goal should be responsible adoption rather than adoption for its own sake.
Frequently Asked Questions
Is it safe for lawyers to use ChatGPT or other AI tools?
AI tools can be used more safely when firms understand the tools, protect confidential information, establish approved uses, and require human review. Lawyers should also consider their applicable professional and ethical obligations before using AI for client-related work.
Can attorneys put client information into AI?
Law firms should not assume client information is appropriate to enter into an AI system. The ABA has specifically identified confidentiality as an important ethical consideration when lawyers use generative AI. Firms should understand a tool's handling of data and their applicable obligations before using client information with it.
Can AI be used for legal research?
AI may assist with research, but attorneys remain responsible for verifying the accuracy of the resulting work. Generative AI can produce inaccurate information, including convincing-looking material that isn't reliable.
Should a law firm have an AI policy?
A written policy can help establish which AI tools are approved, what information employees may share, what uses are prohibited, and when human review is required. It also gives employees somewhere to turn instead of making individual decisions about AI risk.
Should law firms ban AI completely?
Not necessarily. The better question is whether the firm has evaluated where AI is appropriate and established safeguards for its use. A blanket ban may also fail to address AI features already built into software, browsers, meeting tools, and other applications employees use.
How can a law firm find out whether it's ready for AI?
Start by inventorying which AI tools employees use, determining what information can and cannot be shared, reviewing how AI output is verified, and establishing rules for approved use. RTS's AI Readiness Guide uses these questions to help businesses identify potential gaps in their current approach.
Start With Your Firm's AI Readiness
If you're an Iowa City law firm wondering whether employees are already using AI safely, you don't have to start by becoming an AI expert.
Start by asking better questions.
Do you know which AI tools employees are using?
Do you know what information they're putting into them?
Have you identified approved tools?
Are employees checking AI-generated work?
Do you have written rules?
Those answers can tell you a lot about your firm's AI readiness.
RTS Technology Solutions created a free AI Readiness Guide to help businesses evaluate those questions. The guide includes 10 AI safety rules, an AI readiness check, a scorecard, and practical next steps for establishing clearer AI rules.
Download the Free AI Readiness Guide at the top of the page.
If the assessment identifies gaps, RTS can also help businesses think through approved AI tools, data protection, employee expectations, and an AI Acceptable Use Policy.



