AI usage policy for law firms and dental offices
A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.
Read articleCompliance
A three-attorney cost example, ABA duties, provider questions and the evidence a small law firm should ask for.
For a law firm with three attorneys and no other counted people or unassigned shared computers, Obsidian Ridge costs $75 per month for Ridge Core or $150 per month for Ridge Plus, with business onboarding separate. Obsidian Ridge's Ridge Core includes endpoint MDR and Microsoft 365 or Google Workspace ITDR at $25 per person per month, month-to-month with no minimum and business onboarding separate. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Ridge Plus costs $50 per person per month on an annual term, billed monthly, with no minimum. It adds staff training, email-security configuration and a secure browser to Ridge Core; business onboarding is separate.
This is an example for three counted people, not a promise that a three-attorney firm has only three users. Include paralegals, assistants and other staff. A shared computer with no named user counts as one person. Business setup is $500 for up to 25 machines, or $1,000 for 26 to 100. See current pricing and the law-firm service scope.
Model Rule 1.1 Comment 8 includes keeping up with the benefits and risks of relevant technology as part of competence. Rule 1.6(c) requires reasonable efforts to prevent unauthorized access to or disclosure of information relating to representation.
These are model provisions. Check your jurisdiction's adopted rules and the demands of particular matters or client agreements. Neither is a certification that a law firm becomes compliant by buying a named security product.
| ABA source | What it addresses | A practical provider question |
|---|---|---|
| 477R: securing communications | Reasonable precautions for transmitting client information; some information or agreements call for additional protection | How do we select and configure an appropriate client communication route? |
| 483: electronic breaches | Monitoring, responding to a breach, restoring systems and communicating with affected clients | Who preserves the facts and supports the firm's notification decisions? |
| 512: generative AI | Competence, confidentiality, communication and other professional duties in AI use | Which AI tools and data uses are approved, and who reviews the output? |
Use these to assign work and ask better questions. They do not replace jurisdiction-specific advice or matter-specific judgment.
Ask for a written inventory and a responsibility table before choosing the lowest price:
Our MDR service covers endpoint detection and response; ITDR covers the account layer. Compare supported identity platforms in the ITDR provider comparison. A case-management application is not automatically within every integration or response permission.
Keep an approved access list, evidence of MFA and device coverage, a training roster, backup and restore-test records, and a short incident contact sheet. For each record, retain the date and system scope so it answers a concrete question later. This is a practical evidence list, not an exhaustive statement of legal retention duties.
Obsidian Ridge's Ridge Log managed SIEM add-on costs $8 per data source per month, with no minimum. The add-on contract term is not published; confirm it, source coverage and retention in the quote. Huntress's SOC monitors and acts 24/7; Obsidian Ridge provides CISSP-led follow-through within one business day, serving the Research Triangle and businesses across the United States. Use managed SIEM when separately scoped logging addresses a defined risk or evidence requirement. Agree record access and confidentiality before collection.
Ridge Reserve costs $70 per person per month on an annual term, billed monthly, with no minimum and onboarding separate. It adds an incident-response plan and annual tabletop, quarterly admin-access review, monthly patch reporting and an annual questionnaire refresh to Ridge Plus. The monthly service is still different from legal review, forensic investigation or unlimited recovery work.
Adopt a written approval process before staff paste client information into personal accounts. Check the tool's terms, data flows, access and retention; decide whether informed consent or additional safeguards are required. A lawyer remains responsible for reviewing work used in a representation. ABA Formal Opinion 512.
The copyable AI policy supplies a starting point for firm approval. Technical controls help apply it, but do not make the professional judgment for the lawyer.
Start with the inventory and the unanswered responsibility questions. If a client or insurer has sent a form, use free application help and the questionnaire worksheet. The Readiness Sprint costs $1,500 to $3,500 once for a 7-business-day engagement. The deliverable is the same at each scope: a signed evidence pack and a record of controls and gaps. The Readiness Sprint is separately scoped around the evidence work. Talk with us when the firm knows which systems and people the proposal must cover.
Fetched October 2, 2026.
Last updated
October 2, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
For a law firm with three attorneys and no other counted people or unassigned shared computers, Obsidian Ridge costs $75 per month for Ridge Core or $150 per month for Ridge Plus, with business onboarding separate.
Add staff and any shared computers without named users to the count. Core is month-to-month; Plus is annual, billed monthly.
The cited Model Rules and opinions address competence, confidentiality, reasonable safeguards and responsibilities after an incident. They do not certify one vendor or make purchasing a particular product the test. Check the rules adopted in your jurisdiction.
Ask which endpoints and cloud accounts are covered, who can contain a threat, who handles follow-through, how records are exported and what is excluded. Put after-hours responsibilities and restore ownership in writing.
Do not assume every tool or account is approved. Evaluate confidentiality, access and retention, the task and any required informed consent. ABA Formal Opinion 512 addresses competence, confidentiality, communication and other duties when using generative AI.
Related reading
A copyable staff AI policy, plus browser and device controls to manage client data, approved tools and incident reporting.
Read articleCompare five SIEM options on evidence, retention, response, pricing, contract terms and minimums for a small practice.
Read articleConfidentiality is a bar duty before it is an IT one. What your IT provider owns, what a security operation owns, and how MR 5.3 applies to the vendor.
Read article