AI for small accounting and law firms: what is safe, what is not, and a one-page policy
Where AI is safe for a small accounting or law firm, where it is not, and a copyable one-page AI policy: allowed tools, a never-paste list, a review rule.
By Levi Johnson, founder
Small accounting and law firms are using AI whether or not anyone decided to. Someone on staff is already pasting something into a chatbot. The question is not whether to allow it. It is whether the firm has drawn the line between what is safe and what is not, and written it down.
Where things stand
Two figures, both attributed so you can check them.
Clio’s 2025 Legal Trends Report found that about 75% of legal professionals at small firms reported using AI in some form, though only around 10% of small firms said they use it extensively (Clio press release, reported as of September 2026). The ABA’s 2024 Legal Technology Survey Report, which asks a narrower question about AI-based tools used for work, found 30% of lawyers using them, up from 11% the year before, with solo practitioners at 18%.
Read the two together and the picture is clear: most people have tried it, few firms have built it into how they work, and the gap is where both the value and the risk sit. Accounting firms do not have an equivalent survey we could confirm, but what we have watched in small practices matches: the tax team has a favorite tool, the admin has a different one, and nobody has compared notes.
What is safe
Safe means three things at once: a mistake is cheap to catch, a person reviews the output before it leaves the firm, and no client data goes somewhere it should not. These four uses clear that bar in most small firms.
Drafting. Engagement letters, client update emails, first drafts of memos, routine correspondence, responses to common questions. The tool gets you from blank page to rough draft. The professional turns the rough draft into the real thing. Nothing goes out without that second step.
Summarizing. Long email threads, a 60-page contract where you need the termination and indemnity clauses, a year of bank statements where you want the unusual transactions flagged, a new regulation you have to read but do not want to. “Tell me what matters in here” is something these tools do well, as long as you treat the summary as a map and still read the parts that matter.
Intake triage. A new inquiry comes in through the web form or the general inbox. The tool reads it, pulls out the matter type, the parties, the urgency, and the conflict-check names, and drops a structured summary into your intake system for a person to act on. It does not respond to the prospect. It does not decide whether to take the case.
Deadline extraction. Reading a court order, an engagement agreement, or a notice from a tax authority and pulling out every date and what is due on it, into a list a person checks against the calendar. The tool catches the date buried on page eleven. The person confirms it. Both steps stay.
We covered the general version of this in where AI saves a small business time, and the rule there holds here: predictable input, useful rough draft, cheap to check.
What is never safe
Client data in consumer tools. A personal ChatGPT, Gemini, or Claude login, a free tier, any account the firm did not set up and does not control. The problem is not the model. It is that you do not know where the data goes, whether it trains the next version, or who can see the conversation history. Client names, financials, case facts, tax identification numbers, and anything from a privileged communication do not go into a tool the firm has not vetted. No exceptions for “I removed the name.”
Anything filed, sent, or signed without review. A brief with an invented citation. A tax return with a number the tool guessed. A client letter that states the law confidently and wrongly. Every one of these has happened somewhere, and the common thread is that a person did not read it before it left. The review rule is not bureaucracy. It is the whole safety system.
Judgment calls. Whether to take the matter. How aggressive a position to take. Whether a client’s explanation holds up. The tool will produce an answer. It will not have the context, and it will not be liable.
Legal or tax conclusions presented to a client as advice. Drafting the explanation is fine. The conclusion is the professional’s, reviewed and owned.
A one-page AI policy you can copy
Most firms do not have a policy because they imagine it needs to be twelve pages from outside counsel. It does not. It needs four parts, one page, and a partner’s signature. Here is a version to start from. Replace the bracketed parts, take out what does not fit, and have whoever handles your professional responsibility questions read it before you adopt it.
[Firm name] AI use policy, adopted [date]
1. Allowed tools. Staff may use only the following AI tools for firm work, on firm-managed accounts: [list, e.g. the assistant built into our Microsoft 365 or Google Workspace tenant; a named business or enterprise plan with data training turned off; a named practice-management feature]. Personal accounts, free tiers, and any tool not on this list may not be used for firm work, even for tasks that seem harmless. Requests to add a tool go to [name].
2. The never-paste list. The following may not be entered into any AI tool, including the allowed ones, unless [name] has confirmed in writing that the specific tool is approved for it: client names alongside matter facts; Social Security, EIN, or other government identification numbers; bank, card, or account numbers; financial statements or tax returns; privileged communications; anything under a protective order or NDA; personnel or health information. When in doubt, it is on the list.
3. The review rule. Nothing produced with AI assistance leaves the firm, is filed, or is relied on for a client decision until a qualified person has read it in full and takes responsibility for it as their own work. Every citation, figure, date, and statement of law is checked against the source. AI-generated work is held to the same standard as work by a new hire: useful, never final.
4. Who to ask. Questions about whether a tool or a use is allowed go to [name] before the tool is used, not after. Mistakes, including accidental pastes, are reported to [name] the same day, without penalty for reporting. This policy is reviewed [every six months] and the allowed-tools list is updated as tools change.
Signed: [managing partner], [date]
That is the whole thing. A firm that adopts this and actually enforces part two has removed most of the real risk. The rest is training.
Getting from policy to practice
A policy nobody has been trained on is a document in a drawer. The same week you adopt it, sit the team down for an hour and show them, on their own screens, which tool to open, where it lives, and what a safe drafting or summarizing task looks like start to finish. Then pick one use per person and name it: the paralegal does intake triage, the senior accountant does engagement letter drafts, the admin does the deadline list. Usage that is attached to a named task survives. Usage that is “try it and see” is gone by week three, for reasons we wrote up in why your team stopped using AI tools.
That hour is what our team training session is built for, and it works best after a half-day assessment has found which two or three tasks in your firm are actually worth the effort. Some firms find the answer is intake triage. Some find it is the recurring client update nobody enjoys writing. A few find the honest answer is that a cleaner intake form would save more time than any AI tool, and we tell them so.
The firms that get this right are not the ones with the most tools. They are the ones where everyone knows the line, the line is written down, and a person still reads everything before it goes out the door.
Common questions
Can our staff use ChatGPT for client work?
Not the free consumer version with client data in it. The line is not the brand, it is the account: a business plan with data controls and no training on your inputs, approved by the firm, is a different product than a personal login. The policy below draws that line in one sentence.
Do we need a policy if only two people use AI?
Yes, and especially then, because those two people are making the firm's data decisions alone. A one-page policy takes an hour to adopt and turns 'I assumed it was fine' into a rule everyone can point to.
Is AI output privileged or confidential?
That is a question for your bar or your professional liability carrier, not for us. What we can say is that the practical risk is the tool's data handling, which is why the never-paste list is the most important part of the policy.
What is the first thing a small firm should automate?
Usually intake triage or deadline extraction, because both are tedious, both have a clear review step, and a mistake is caught before it costs anything. Drafting comes next once people trust the tool.
Found this useful? Share it on LinkedIn.