Law Society of Ontario AI Policy Template: A 2026 Governance Framework for Ontario Law Firms

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

Fusion recommends four controls as a practical way to operationalize existing LSO duties. The LSO does not prescribe this policy structure. It names the rules of professional conduct it operationalizes (LSO Rule 3.1-2 on competence, Rule 3.3-1 on confidentiality, Rule 6.1-1 on supervision). It lists approved and prohibited AI tools by product name. It requires citation verification before any AI-assisted filing leaves the office.

It closes with annual partner sign-off. This guide turns those requirements into a clause-by-clause template Ontario firms can adapt, and reads alongside our AI deployment guide for Canadian law firms.

Key takeaways

  • Fusion recommends mapping each clause to a named LSO rule (3.1-2 competence, 3.3-1 confidentiality, 6.1-1 supervision), the three the Law Society works through in its April 2024 generative-AI white paper.
  • The Law Society publishes the questions, not the answers. Its checklist Building a generative AI policy asks what tools are covered and who is bound, and supplies no clause wording, no cadence, no training minimum.
  • In Zhang v Chen, 2024 BCSC 285, a lawyer was ordered to pay wasted costs personally after two ChatGPT-invented cases reached a notice of application.
  • Consumer ChatGPT, Claude.ai, and Gemini cannot appear on the approved-tools list. The data processing agreement (DPA) gap and training-data exposure can create confidentiality, contractual and privilege risk.
  • Supervision is a recurring gap in the law-firm policies Fusion reviewed in 2025 and 2026. Rule 6.1-1 requires direct supervision and review at frequent intervals. Fusion recommends documenting supervisory standards that name AI use, not generic delegation language.

Book a 30-minute AI policy review

What goes in a law-firm AI policy for Ontario? The duties explained

A law-firm AI policy is a firm-level governance document that turns the Law Society of Ontario’s existing Rules of Professional Conduct into desk-level generative AI practice. The LSO does not certify or approve policies, so treat the structure below as Fusion’s recommendation rather than a compliance standard. It anchors three duties: competence (3.1-2), confidentiality (3.3-1), supervision (6.1-1). Chapter 3 of the Rules carries the first two and chapter 6 carries the third. Neither mentions AI. The policy is the artifact that proves your firm applied duties it already carried.

Why Ontario law firms need a written AI policy in 2026


Neither the LSO Rules of Professional Conduct nor the Federation Model Code has been rewritten for generative AI, and both already govern how an Ontario lawyer uses one. The compliance gap is not a missing rulebook. It is the missing firm policy that turns Rules 3.1-2, 3.3-1 and 6.1-1 into desk-level practice.

Firms without a written policy face two risks. The first is regulatory. If the LSO investigates an AI-related complaint, it may request information or documents relevant to the allegations. A written policy, tool register, supervision records and training records can help the firm explain its governance when those materials are relevant. A firm that produces none of those looks ungoverned.

The second risk is insurance. In the Ontario cyber-rider renewal conversations Fusion Computing has sat in on through the 2026 cycle, the questionnaire asked whether a written AI policy was in force and who owned it. A firm with nothing on file answers both badly.

The Law Society reached the same place in its April 2024 white paper on licensee use of generative artificial intelligence. The first best practice it lists is to create an organizational policy. This template is that artifact.

The LSO regulatory anchors Fusion recommends citing


Fusion recommends mapping each policy clause to a named rule so the firm can explain which duty the clause supports. The LSO does not prescribe that document structure. Three carry most of the weight, and the FLSC Model Code is the national frame the provincial codes rest on. Naming the rule beside the clause is what makes the policy auditable.

Rule What it requires How AI engages the rule
LSO Rule 3.1-2 A lawyer shall perform legal services to the standard of a competent lawyer. Technology competence is a component. A lawyer using AI without understanding its limits, training data, or output reliability fails this standard.
LSO Rule 3.3-1 A lawyer shall hold in strict confidence all information concerning the business and affairs of the client. A consumer AI tool that may train on input or store data in unknown jurisdictions puts confidential and potentially privileged content outside the firm’s control, which can breach Rule 3.3-1 depending on the content and the terms that applied.
LSO Rule 6.1-1 A lawyer shall, in accordance with the by-laws, assume complete professional responsibility for their practice of law and directly supervise non-lawyers to whom particular tasks and functions are assigned. Clerk and student AI use counts as delegated work, and the supervising lawyer owns any error. Licensed paralegals are separately regulated and hold their own obligations under the Paralegal Rules of Conduct, so the policy should address both routes.
FLSC Model Code National harmonizing framework adopted by most provinces with local variations. Use the FLSC Model Code as the reference for any clause that needs to read consistently across provinces if the firm has multi-jurisdictional matters.

“To maintain the required level of competence, a lawyer should develop an understanding of, and ability to use, technology relevant to the nature and area of the lawyer’s practice and responsibilities. A lawyer should understand the benefits and risks associated with relevant technology, recognizing the lawyer’s duty to protect confidential information set out in section 3.3”.

Federation of Law Societies of Canada, Model Code of Professional Conduct, Rule 3.1-2 commentary [4A], 2024 consolidation.

Section 1 of the template: Scope and purpose


The scope clause defines what the policy covers, who it binds, and what counts as “use of AI”. The LSO checklist opens with those same three questions. The mistake most Ontario firms make is a scope that only covers lawyers, when the policy must bind everyone who touches firm systems.

Recommended wording. “This policy governs the use of generative artificial intelligence tools by all personnel of [Firm Name]. Bound personnel include lawyers, paralegals, articling students, support staff, contract personnel, and authorized third-party vendors with access to firm systems”.

“‘Generative AI tool’ means any software system that produces text, images, code, audio, or video output in response to user prompts, including large language models, retrieval-augmented systems, and agent frameworks. This policy operationalizes the firm’s obligations under Rules 3.1-2, 3.3-1, and 6.1-1 of the Rules of Professional Conduct of the Law Society of Ontario”.

If you want a starting frame that is not LSO-specific, the general AI acceptable-use policy framework is the parent document. The Ontario clauses below build on it.

The Federation of Law Societies of Canada Model Code added its technological-competence commentary in 2019, and Ontario and British Columbia both carry it. The rule prescribes no tools. It prescribes the duty to know enough about a tool to use it safely, which is the duty a policy documents.

Section 2: Approved AI tools and prohibited tools


The approved-tools list is the spine of the policy. It must name specific products, not categories. “Enterprise AI tools” is unenforceable. “Microsoft 365 Copilot deployed inside the firm tenant” is enforceable. The list goes in the policy itself, not in a supplementary document, so the firm can produce it from one document rather than assembling it later.

Tier Tools Permitted use
Candidate tools – firm approval required Microsoft 365 Copilot inside the firm tenant, plus the specific Canadian legal-research AI products named in your own subscription (for example Lexis+ AI or vLex Vincent AI). Use the exact product and feature name shown in the firm’s contract or admin console. Candidates the firm may approve, after its own review, for client matter work and citation-grade legal research. Approval is the firm’s decision, not a Fusion or LSO designation.
Candidate tools – limited use, firm approval required ChatGPT Enterprise or Claude for Work, where the firm has confirmed the exact service and workspace, its storage and processing locations, its training terms and a signed DPA. Residency is a configuration to verify in the contract and admin console, not a product attribute. If the firm approves the exact service and workspace, permitted uses are non-privileged research, internal training material and non-client work product. Never for client data or matter content.
Prohibited Consumer ChatGPT, Claude.ai consumer, Google Gemini consumer, Perplexity consumer, any tool without an enforceable DPA. Cannot touch firm devices, firm accounts, or any client-matter content under any circumstance.

Our Copilot vs CoCounsel vs Harvey comparison for Canadian law firms covers the tool-selection logic; the policy itself carries only the list.

Section 3: Confidentiality and solicitor-client privilege protections


Rule 3.3-1 is the binding constraint, and the clause must close three gaps ordinary IT policies miss. It must prohibit consumer AI tools from touching firm devices regardless of whether client content is involved, because once the tool is on the device the policy depends on user discipline alone.

It must require Microsoft Purview sensitivity labels on every matter folder before any AI tool is enabled, and state that the lawyer carries the burden of proving privilege was not waived.

Recommended wording. “All client communications and work product are treated as confidential, and potentially privileged or otherwise protected pending legal classification. Personnel shall not input client content, matter content, or any data that could identify a client into any AI tool the firm has not approved in writing for client content under this policy”.

“Tools approved for limited use may be used only for content that has been confirmed in writing to be non-privileged and non-confidential. The use of any consumer-grade AI tool on a firm device, or via a firm account, is prohibited regardless of the content involved. Microsoft 365 Copilot deployments shall apply Microsoft Purview sensitivity labels to every client matter folder before the tool is enabled for the user”.

Section 4: Citation verification (the Zhang v Chen lesson)

Citation verification is where AI-specific risk meets traditional advocacy. The Law Society of Ontario names Mata v Avianca in its own white paper as the illustration of the risk, and adds that similar occurrences have been reported in Canadian litigation.

They have. In Zhang v Chen, 2024 BCSC 285, two ChatGPT-invented cases reached a notice of application. Justice Masuhara declined special costs, then ordered the lawyer personally liable for the costs her mistake wasted and directed her to review every file she had before the court within thirty days.

The duty arrived before the tools did.2019.2023.2024.2026.FLSC tech competence.Mata v Avianca (SDNY).Zhang v Chen; LSO paper.IPC and OHRC principles.Every milestone here is a rule or a ruling you can open and read.
Sources: FLSC Model Code commentary 4A, CourtListener, British Columbia Courts, IPC Ontario.

Recommended wording. This clause serves the Rule 3.1-2 competence duty. “No filing, memorandum, factum, or written communication leaves the firm with an AI-assisted citation that has not been independently verified against CanLII, Westlaw, Lexis, or the original reporter”.

“The drafting lawyer signs a one-page certification stating: authorities verified against the source, parallel citations confirmed, direct quotations checked against the source text, and no AI-generated authority appears in the document without independent verification. The certification is filed with the matter file and retained under the firm’s documented file-retention policy, taking account of applicable discovery and ultimate limitation periods, LSO guidance, client obligations and insurer requirements”.

“As this case has unfortunately made clear, generative AI is still no substitute for the professional expertise that the justice system requires of lawyers. Competence in the selection and use of any technology tools, including those powered by AI, is critical. The integrity of the justice system requires no less”.

Justice D.M. Masuhara, Zhang v. Chen, 2024 BCSC 285, at paragraph 46.

Section 5: Client-facing disclosure

The LSO’s 2024 white paper stops short of mandating client disclosure for all AI use. It sets out factors for considering disclosure, including whether AI use is material to the engagement, whether the client’s retainer agreement contemplates it, and whether the work product is substantially shaped by AI. Fusion’s recommended approach is to draft a disclosure clause that defaults to transparency without over-disclosing routine internal use.

Recommended wording. “The firm will disclose AI use to clients in three circumstances:

  • (a) where AI tools materially shape the legal advice provided.
  • (b) where the engagement letter requires disclosure of technology use.
  • (c) where AI use exceeds routine internal drafting or summarization”.

“Routine internal use (transcript summarization, internal memo drafting, document review for relevance) does not require client-by-client disclosure but is described in the firm’s general technology disclosure included with every engagement letter. Where disclosure is made, it shall be in writing and shall identify the category of AI tool used and the verification controls applied”. That default tracks the 2024 white paper’s materiality line.

Section 6: Training and competence requirements

Rule 3.1-2 makes technology competence part of professional competence. Fusion recommends the training clause name a minimum cadence, a documented curriculum and a verification mechanism. “The firm will provide AI training as needed” produces no record; naming the hours, the topics and the sign-off does. Rule 3.1-2 does not itself set a cadence.

Recommended wording. “Every lawyer, paralegal, and student handling client matters shall complete a minimum of four (4) hours of AI competence training annually, documented in the firm training register”.

“Required topics include: the firm’s approved-tools list and prohibited-tools list, citation verification protocol, privilege protection in AI workflows, recognition of AI hallucinations and confabulations, and the supervision standard under LSO Rule 6.1-1. New hires complete the training within thirty (30) days of start date. Training completion is verified by a signed acknowledgement filed with the personnel record”.

Fusion Computing runs this training rollout for Ontario firms under CISSP-led leadership.

Book a 30-minute AI policy review

Section 7: Incident response and the LawPRO escalation

An AI-related incident can fall under three escalation paths at once. Notify LAWPRO or another insurer when that policy’s trigger is met. Report to the LSO only when Rule 7.1-3 or another reporting duty applies. Tell the client when the retainer, client instructions, law or court rules require it. The incident response clause must name all three and the trigger conditions for each.

Recommended wording. “An ‘AI-related incident’ includes any event where:

  • (a) privileged or confidential information may have been disclosed to an unapproved AI tool.
  • (b) an AI-generated authority or fact appears in a filed document or external communication without verification.
  • (c) an unauthorized AI tool is detected on a firm device.
  • (d) a client raises a concern about firm AI use”.

“Upon detection: the partner-in-charge is notified within twenty-four (24) hours. LawPRO is notified where a claim or a circumstance that may give rise to a claim arises, within the timeline its policy requires; any separate cyber policy has its own notice terms. The firm assesses whether Rule 7.1-3 or another actual reporting duty is triggered before reporting to the LSO. A written incident report is filed with the firm risk register, recording the tool involved, content exposed, lawyer of record, client affected, remediation steps, and lessons learned”.

The LawPRO escalation specifics, including disclosure obligations under the Rules of Professional Conduct when an AI error has produced a foreseeable harm to the client, are covered in our LawPRO AI errors disclosure guide.

In our practice a documented incident-response artifact is the record a firm most often needs to produce, and it is more useful than the policy text alone. A clause that names trigger conditions and notification timelines beats one that defers the response to judgement at the moment of the incident, because the second produces no record.

Section 8: Annual review and partner sign-off

The annual review clause is what turns the policy from a document into a governance artifact. Fusion recommends a documented annual review, and an out-of-cycle review whenever approved tools, vendors or regulator guidance change. A policy the firm cannot show it revisited is harder to rely on later. The review must produce a record: who reviewed, what changed, and who signed.

Recommended wording. “This policy is reviewed at least once every twelve (12) months by the firm’s managing partner or designated equivalent, in consultation with the firm’s IT advisor and, where applicable, outside counsel on professional conduct matters”.

“The review produces a written record covering: tools added to the approved list, tools removed, incidents recorded in the prior year, training completion rates, and any updates to LSO or FLSC guidance. The reviewed policy is re-circulated to all personnel and re-acknowledged in writing within thirty (30) days of the review date. An interim review tracks supervision records under Rule 6.1-1” (Fusion suggests quarterly).

The clause-by-clause comparison table

FREE DOWNLOAD

The LSO AI Policy Template for Canadian Law Firms (2026)

The clause-by-clause template Ontario firms can adapt, mapped to LSO Rule 3.1-2 on competence, Rule 3.3-1 on confidentiality and Rule 6.1-1 on supervision. Ships as an editable Word edition alongside the PDF.


Written by Mike Pearlstein, CISSP. No sales call required.

This is the spine readers will print. Each row maps a clause to the LSO rule it serves, the wording fragment, and the failure mode Ontario firms hit when they shortcut it.

LSO AI policy clauses, mapped to rules and common failure modes.
Template clause LSO rule Recommended wording fragment Common pitfall
Scope 3.1-2; 6.1-1 “Governs all personnel, including paralegals, students, support, and vendors”. Scope limited to lawyers; leaves paralegal AI use uncovered.
Approved tools 3.1-2; 3.3-1 “Tools the firm has approved in writing for client matter work: Microsoft 365 Copilot inside the firm tenant, plus the exact legal-research AI products named in the firm’s subscription…”. Categories instead of named products; unenforceable.
Prohibited tools 3.3-1 “Consumer ChatGPT, Claude.ai consumer, Gemini consumer, no DPA tools”. Allowing consumer tools for “internal-only” tasks; one paste exposes privilege.
Confidentiality 3.3-1 “Apply Purview sensitivity labels to every matter folder before enabling Copilot”. Copilot enabled before labels deployed; oversharing risk.
Citation verification 3.1-2 “Drafting lawyer signs a one-page verification certificate per filing”. No documented certification; Zhang v Chen pattern.
Client disclosure 3.1-2; 3.3-1 “Material AI use disclosed in writing; general use covered in engagement letter”. No disclosure protocol; client surprise becomes complaint.
Training 3.1-2 “Four hours annual, signed acknowledgement, new hires within thirty days”. “Training as needed” language; no completion records.
Supervision 6.1-1 “Written supervision review per supervised person, filed” (Fusion suggests quarterly; Rule 6.1-1 sets no cadence). No written record; partner cannot prove supervision occurred.
Incident response 3.3-1; 6.1-1 “Twenty-four-hour partner notification, LawPRO and LSO triage paths”. No defined trigger; incidents go unreported.
Annual review 3.1-2 “Annual full review, interim review, partner sign-off, re-acknowledgement” (cadence is the firm’s choice). One-time policy; goes stale within twelve months.

The 7-step rollout plan

The policy is the artifact. The rollout is what makes it stick. The steps below sequence the work in the order Ontario firms actually execute it.

  1. Draft. Adapt the template clauses to firm specifics, name the actual approved tools, and identify the partner-in-charge for AI.
  2. Review. Have outside ethics counsel or the firm’s practice-management advisor check the draft against current LSO and FLSC guidance.
  3. Train. Run the four-hour competence training for every bound person, support staff included, before the policy takes effect.
  4. Sign-off. Every bound person signs an acknowledgement. Acknowledgements filed with personnel records. Partner sign-off recorded on the policy itself.
  5. Publish. Policy posted to firm intranet, included in the new-hire onboarding pack, and named in the engagement-letter technology disclosure.
  6. Audit. A recurring supervision review under Rule 6.1-1 documents what was supervised, by whom, and what was flagged. Filed. Fusion suggests quarterly; the rule requires frequent review, not a set interval.
  7. Annual review. Full review at twelve months. Update approved-tools list, add lessons-learned from any incidents, re-sign, re-acknowledge.

FIELD NOTE FROM MIKE

Across the law-firm AI policies I reviewed in 2025 and 2026, supervision under Rule 6.1-1 was a recurring shortcut. Firms write “partners supervise paralegal AI use” and stop there. That is not what the rule requires.

Rule 6.1-1 requires the lawyer to assume complete professional responsibility and directly supervise the person doing the work. A clause that names neither a cadence nor an artifact leaves nothing to produce when someone asks.

In our practice the fix is usually the same: name a cadence (we suggest quarterly), name the artifact (a one-page written review per supervised person), and file it. Fusion has reviewed draft Ontario firm policies that had no supervision artifact before the engagement.

If you want a draft policy that already addresses the supervision gap and the citation-verification gap for your Ontario firm, download the LSO AI policy template →.

Common policy mistakes Canadian firms make

Mistake 1: Permitting consumer AI for “internal-only” tasks

The most common drafting error is a carve-out letting staff use consumer ChatGPT for “internal-only” work. The problem is enforcement. Once the tool sits on a firm device, the policy depends on user discipline alone, and one paste of a privileged document turns the carve-out into a discipline file.

Mistake 2: Skipping the citation-verification certification

Firms treat verification as a soft expectation until they see an incident. In Zhang v Chen the two invented cases would have failed a basic CanLII verification check, and the costs landed on the lawyer personally. The certification makes that check non-negotiable.

Mistake 3: Treating supervision as an informal practice

Rule 6.1-1 requires direct supervision and review at frequent intervals; written records are Fusion’s recommended way to evidence it. If the firm is asked to evidence supervision and the answer is “we discuss it at the weekly meeting,” there is no record to point to.

Mistake 4: Letting the policy go stale

Approved tools change and vendors change DPAs. A policy written in early 2025 and not reviewed by mid-2026 is unlikely to reflect current tools or guidance, and the annual-review clause is what keeps it defensible.

The firms most exposed in an LSO complaint are rarely the ones that ban AI outright. In our experience the exposed Ontario firm allows consumer ChatGPT on firm devices with no Purview label and no written policy behind it. The problem is informal use, not deliberate non-compliance.

The security layer underneath the policy

A policy needs technical controls behind it. They are what stop the prohibited-tools clause from being theatre. Microsoft Purview sensitivity labels and permissions shape what Copilot can surface, so label and permission hygiene at the matter level is what limits exposure. Blocking unsanctioned consumer AI is normally done with web/content filtering or app-control tooling; Conditional Access governs access to your own tenant rather than to third-party consumer services.

Data loss prevention rules block matter numbers and client identifiers from being pasted into unapproved tools, and audit logging retains the activity record for the retention period the firm configures, which is bounded by the plan’s retention limits. Where the firm runs a document management system, the same controls have to reach it: see our guide to NetDocuments and iManage Copilot integration for Canadian law firms.

Our cybersecurity services for Canadian businesses deploy these controls for law firms as part of the AI rollout, not after. The policy and the controls go in together or the policy is unenforced.

Further reading and primary sources

How this guidance was assembled

This article is written from first-person field observation in Fusion Computing’s work with Ontario and British Columbia law firms in 2025 and 2026, including Copilot, Purview and Entra ID rollouts inside privilege-sensitive practices.

What a policy has to contain reflects draft policies we read before firms adopted them, and what we observed about rollout order. These are field observations, not a measured benchmark or a survey.

Source review updated August 2026. Firms should re-check regulator, court, insurer and vendor requirements before adopting the policy. Over that sits first-person field observation from CEO Mike Pearlstein’s practice supporting regulated Canadian SMBs since 2012.

Where this usually goes next

A signed policy is the start, not the finish. Section 6 of this template requires training and competence, and that is the part firms skip. We run role-based AI training for Ontario firms and check that the technical controls underneath match what the policy promises.

How we run AI enablement and training
Book a 20-minute call

Senior engineer, not sales. If there is nothing worth doing we will tell you.

Frequently asked questions

Does the Law Society of Ontario require law firms to have a written AI policy?

The LSO has not amended the Rules of Professional Conduct to mandate a written AI policy. Its 2024 white paper on licensee use of generative AI makes clear that existing rules apply: 3.1-2 competence, 3.3-1 confidentiality, and 6.1-1 supervision. A written policy, tool register, training records and supervision records can help a firm explain its governance if the LSO later reviews an AI-related matter. The records requested will depend on the facts.

Which LSO rules govern lawyer use of generative AI?

Three rules carry most of the weight. Rule 3.1-2 sets the competence standard, which includes technology competence. Rule 3.3-1 sets the confidentiality obligation, which governs what data can be input into AI tools. Rule 6.1-1 sets the supervision standard for non-lawyers doing delegated work. Licensed paralegals are separately regulated under the Paralegal Rules of Conduct and carry their own professional obligations. The Federation of Law Societies Model Code provides the harmonizing reference across provinces.

Can an Ontario lawyer use ChatGPT for client matters?

Not the consumer version. Consumer ChatGPT may train on input and stores data in unknown jurisdictions, which can create a confidentiality problem under Rule 3.3-1 depending on the content entered and the terms that applied at the time. ChatGPT Enterprise may be usable for non-privileged research and internal work product where the firm has confirmed the exact service, its storage and processing locations, its training terms and a signed DPA. Firms commonly consider Microsoft 365 Copilot inside the firm tenant and Canadian legal research tools first; confirm the exact licensed product and feature name against your own contract.

What happened in Zhang v Chen and why does it matter for the policy?

In Zhang v. Chen, 2024 BCSC 285, a lawyer put two ChatGPT-invented cases into a notice of application. Justice Masuhara dismissed the request for special costs, held her personally liable under Rule 16-1(30) for the costs her mistake wasted, and ordered her to review every file she had before the court within thirty days. The policy lesson: verification cannot be informal. The drafting lawyer signs a per-filing certification.

How often should a law-firm AI policy be reviewed?

The Rules set no review interval. Fusion recommends a full review annually, plus an interim review focused on the supervision clause under Rule 6.1-1 and an out-of-cycle review whenever tools, vendors or guidance change. The annual review produces a written record covering tools added or removed, incidents recorded, training completion rates, and updates to LSO or FLSC guidance. The reviewed policy is re-circulated and re-acknowledged in writing within thirty days; interim reviews keep the supervision record current.

Do paralegals and clerks need to be bound by the AI policy?

Yes. Rule 6.1-1 requires lawyers to directly supervise non-lawyers to whom particular tasks are delegated, and AI use by clerks and articling students falls inside that supervisory obligation. Licensed paralegals are separately regulated and hold their own obligations under the Paralegal Rules of Conduct, so bind both. A policy that binds only lawyers leaves the largest risk surface uncovered; the scope clause should name every role with firm-system access.

Does the firm have to disclose AI use to clients?

Not for every use. The Law Society sets out the disclosure factors at page 17 of its April 2024 white paper, and its policy checklist asks firms to decide in advance whether client approval is needed. Fusion recommends a general technology-use clause in every engagement letter plus written disclosure when AI use is material. Routine internal use such as transcript summarization does not require client-by-client disclosure.

What is the training requirement under the policy?

Fusion recommends the policy name a minimum cadence (we suggest four hours annually), a documented curriculum and a sign-off mechanism. The Rules set no fixed number of hours. Required topics include the approved-tools and prohibited-tools lists, citation verification, privilege protection, recognition of AI hallucinations, and the Rule 6.1-1 supervision standard. New hires complete it within thirty days; completion is verified by a signed acknowledgement filed with personnel records.

What triggers a LawPRO notification under an AI incident?

Notify LAWPRO promptly when an actual or alleged error, or another circumstance, may give rise to a claim. Detection of an unauthorized AI tool or a client concern is an internal incident trigger; notify LAWPRO if the facts may give rise to a claim. Assess any separate cyber-insurance notice obligation under that policy. See our LawPRO AI errors disclosure guide for the broader picture.

Does the policy need to address Microsoft 365 Copilot specifically?

Yes if the firm uses Microsoft 365. The confidentiality clause should require Purview sensitivity labels on every matter folder before Copilot is enabled. The supervision clause should specify that Copilot output is draft work product under the same review standard as paralegal work. Our Microsoft 365 Copilot guidance for Canadian businesses covers the deployment specifics.

Does this template apply outside Ontario?

The clauses align with the FLSC Model Code, whose technological-competence commentary the provinces adopted from 2019 onward, so the structure transfers with local rule swaps. British Columbia firms should cross-check the current Law Society of British Columbia guidance. Quebec firms should review the Barreau du Québec’s current guidance plus Quebec’s private-sector privacy Act, which requires a privacy impact assessment and adequate protection, evidenced in a written agreement, before communicating personal information outside Quebec. It does not impose blanket Quebec residency. Firms with multi-province matters should adopt the strictest applicable standard.

How does this policy interact with the firm’s cyber insurance underwriting?

Some Canadian cyber insurance applications now ask whether a written AI policy is in force. Underwriting varies by carrier, limits and risk, so check the actual questionnaire rather than assuming a market-wide standard. A documented policy with named approved tools, supervision records, training logs and incident-response paths is the evidence such a question asks for. Some carriers apply AI-specific exclusions; sequence the annual policy review with the underwriting cycle.

Bottom line

A law-firm AI policy is short. Fusion’s template maps each clause to a named rule, names approved tools by product, requires per-filing citation verification, documents Rule 6.1-1 supervision on a cadence the firm sets, and gets partner sign-off.

The Law Society supplies the questions. This page supplies the wording, from Fusion Computing’s CISSP-led practice. The playbook is in our AI deployment guide for Canadian law firms.

Book a 30-minute AI policy review

Licence and permitted use

This is a field guide with sample clauses, free to download and adapt inside your own firm. Do not adopt it unchanged: every clause needs review against your practice, your regulator obligations and your insurer’s terms before you issue it. That review includes rewriting clauses, deleting sections that do not apply, and taking your own advice on the result.

Two restrictions apply. No resale: you may not sell this template, or a derivative of it, as a standalone product or as a paid deliverable in a template pack. Keep the attribution: the attribution to Fusion Computing stays on the title page of any copy you circulate outside your own firm. Purely internal copies issued to your own personnel do not need it.

Professional advisers may adapt this template for a client engagement provided the attribution is retained and the template itself is not billed as a separately priced product.

Last updated August 2026.

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611