A paralegal is behind on a client reply. She pastes the client's email into ChatGPT, asks it to draft a response, cleans it up, and sends it. It takes four minutes. Nobody else in the firm knows this happened. That's the starting point for why every firm needs an AI use audit law firm-wide, not just a policy nobody reads: staff are already using AI on client work, right now, without anyone tracking it.
This isn't a story about one careless paralegal. It's a story about what happens in every firm where AI tools are easy to sign up for and nobody has asked who's using what. The tool itself usually isn't the problem. The problem is that nobody owns the answer to a very simple question: which AI tools touch our client data, and does anyone know it's happening.
The Problem: Unowned AI Use Spreads Quietly
Consumer AI tools don't require IT approval, a training session, or a line item in the budget. Anyone with a laptop and a free account can start using one today. That's exactly why they spread the way they do: one at a time, person by person, with no visibility at the firm level.
A paralegal uses AI to summarize a long deposition. An associate uses it to draft a first-pass memo. An office manager uses it to write a client email faster. Each decision feels small and reasonable in the moment. None of them get reported anywhere, because there's nothing to report to. Six months later, the firm has five different AI tools quietly touching client information, and not one person, including the partners, could name all five if asked.
This is an AI use audit law firm problem before it's an AI risk problem. You can't secure what you don't know is happening, and you can't fix a workflow gap you haven't named yet. It sits right alongside the broader question of where AI helps and where it breaks the workflow: the firms getting burned aren't usually the ones using AI deliberately, they're the ones where it spread without anyone tracking where.
Why This Keeps Happening
Firm governance is built top-down: a policy gets written, distributed, maybe reviewed once a year. AI adoption happens bottom-up: someone finds a tool that saves them twenty minutes and starts using it that afternoon. Those two speeds don't match, and the gap between them is where shadow AI use lives.
Office managers, who are usually the ones who'd catch this, are often the last to know. They're not sitting next to every paralegal watching what tab is open, and most office managers are already stretched across billing, scheduling, and a dozen other operational threads. The only way to close that gap is to stop waiting to notice it by accident and go ask directly.
This Isn't Just Internal Housekeeping
It's tempting to treat an AI use audit as a nice-to-have, something to get to once the busier items on the list clear out. That's a mistake. In July 2024, the ABA issued Formal Opinion 512 on generative AI tools, and it puts this squarely inside a lawyer's existing professional responsibility duties, not a new, optional category of concern.
The opinion is direct about it: lawyers have a duty of competence that includes understanding the AI tools being used on client matters, a duty of confidentiality that applies fully to what gets typed into a chatbot, and a duty to supervise staff, including paralegals and non-lawyer assistants, on how those tools get used. A firm that can't answer which AI tools touch client data isn't just missing a nice internal process. It can't currently demonstrate it's meeting duties that already exist on paper.
This is exactly why the audit has to come before the policy, not after. You can't supervise what you haven't identified.
The Fix: A Lightweight AI Use Audit
An AI use audit law firm teams can actually complete doesn't need to be complicated. It needs five columns and an owner. For every AI tool in active use across the firm, track:
- Tool name. ChatGPT, Copilot, a drafting assistant, a legal research tool, anything.
- Use case. What it's actually being used for, in plain language, not a category label.
- Touches client data? (yes/no). Does anyone ever paste, upload, or reference client information in it.
- Owner. The person responsible for knowing how this tool is used and flagging changes.
- Review date. When this line gets checked again, not "whenever," an actual date.
That's the whole audit. It's not about banning AI or building a thirty-page policy nobody will read. It's about knowing which of the tools people already use touch client data, and making sure one person is accountable for the answer. This is a smaller, sharper version of the same discipline behind workflow automation generally: a step that isn't tracked and owned isn't really under control, no matter how well-intentioned everyone involved is.
How to Start This Week
Don't send a firm-wide email asking people to self-report. Most people won't respond, and the ones who do will underreport, not because they're hiding anything, but because "I use AI sometimes" doesn't feel worth mentioning until someone asks specifically.
Instead, ask directly, one conversation at a time: what AI tools are you using, and for what. Start with the roles most likely to touch client-facing work first: paralegals, associates, anyone doing intake or drafting. Build the list as you go. You'll have gaps in the first week. That's fine. The point isn't a perfect audit on day one, it's a list that exists and grows, instead of no list at all.
Once the list exists, the review date column does the real work. An AI use audit law firm teams build once and never revisit is just a policy document again. Put a date on every line and actually look at it when that date comes. The same way a firm needs operational visibility into where every matter stands instead of finding out at the last minute, it needs visibility into where AI is already embedded in daily work, instead of finding out when something goes wrong.
This connects directly to what to check before adopting legal software, because you can't evaluate a new AI tool's risk against tools you don't know are already there. An audit of what's already in use is the baseline every future software decision should be checked against.
Frequently asked questions
Do we need a formal AI policy before doing this audit?
No. The audit comes first. You can't write a meaningful policy about tools you don't know are in use, and ABA Formal Opinion 512 is clear that supervision obligations only work once the underlying use is actually identified. Build the list, see what's actually happening, then write a policy that addresses the real picture instead of a hypothetical one.
Who should own the AI use audit at a small firm?
Usually the office manager, since they already track firm operations and compliance details. At a smaller firm, it can be whoever handles IT decisions or vendor relationships. The important part is that one person owns it, not that it's the "right" title.
What if someone is already using AI in a way that's risky?
Address it directly and calmly, not punitively. Most risky AI use isn't malicious, it's someone trying to save time without realizing the data implications. Once you know it's happening, you can fix it: switch to a compliant tool, add a data-handling step, or stop that specific use case.
How often should the audit be reviewed?
At minimum quarterly, and any time a new AI tool starts getting used firm-wide. The review date column on each line should reflect how sensitive that tool's use case is: a tool touching client financials needs more frequent review than one used for internal scheduling notes.
Isn't this the same as a security audit?
It's a starting point for one, not a replacement. This audit tells you what's happening. A full security and compliance review, which what to check before adopting legal software walks through, tells you whether what's happening is actually safe.
Does this apply to non-lawyer staff too, or just attorneys?
It applies to everyone touching client matters. ABA Formal Opinion 512 is explicit that a lawyer's supervisory duty extends to paralegals and other non-lawyer assistants using AI tools on firm work, not just to attorneys using them directly. An audit that only covers attorney AI use is missing most of where this actually happens day to day.
---
The firms that get burned by AI aren't usually the ones that adopted it deliberately. They're the ones where it spread quietly and nobody was tracking where. If you want a hand building this out for your firm, book a demo with Legalboards and we'll walk through it with you.