Independent analysis of artificial intelligence in business
Efficiency Innovations
Home / AI in Law
AI in Law

Implementing AI in the Small and Midsize Law Firm

How to use ChatGPT, Claude, and Gemini without purchasing a large-firm AI platform or losing control of client information.

The first mistake a small law firm makes with AI is assuming it has only two choices: purchase an expensive legal AI platform or prohibit AI entirely. Neither choice reflects what is happening inside most firms. Attorneys and staff already have access to ChatGPT, Claude, Gemini, and AI features embedded in software they use every day. The real question is whether the firm will manage that use or allow each employee to make independent decisions about confidentiality, accuracy, and client risk.

The economics have settled the affordability question. A firm doesn't need the six-figure enterprise platforms examined in this publication's survey of legal AI products to begin using AI productively. ChatGPT Business starts at $20 per user per month with annual billing and a two-user minimum. Claude Team Standard seats also run $20 per user per month billed annually, with a five-seat minimum. Google includes varying levels of Gemini functionality within its Workspace business plans, which may make it the lowest-friction option for a firm already operating in Gmail, Drive, and Docs. All three providers state that data submitted through their business or commercial environments isn't used to train their general models by default.

What the subscription cannot buy is the part that determines whether the implementation is useful or reckless: a firm-managed business account, approved use cases, clear rules for client information, mandatory human review, and someone responsible for the deployment. The software is affordable. The control structure is the work.

Pick One Platform, Not Three

The article-length comparisons matter less than the deployment decision, which should usually be to select one approved primary platform and manage it at the firm level. Giving employees ChatGPT, Claude, and Gemini simultaneously increases cost, training demands, account sprawl, and uncertainty over where client information has been placed. A small firm doesn't need three AI strategies.

The selection logic is straightforward. A firm heavily invested in Google Workspace may start with Gemini because it's already integrated into Gmail, Docs, Drive, and Meet. A firm seeking a general-purpose standalone assistant may evaluate ChatGPT Business. A firm particularly interested in document-intensive analysis may evaluate Claude Team, but should test its own documents and workflows rather than rely on vendor claims or general opinions. The test is the same regardless of shortlist: run identical controlled tasks through each candidate using public, synthetic, or properly sanitized information, then compare output quality, administrative control, usability, integration, and cost.

Step One: Find the AI Already Inside the Firm

Before purchasing anything, management should determine what attorneys and staff are already using. The inventory typically includes personal ChatGPT, Claude, and Gemini accounts; AI features in Microsoft 365 or Google Workspace; transcription and meeting-note tools; legal research products with AI functionality; browser extensions; document summarizers; email-writing tools; client intake chatbots; and practice-management software with embedded AI. This is the firm's actual AI footprint, and a policy written without it is mostly theoretical.

Prohibiting AI doesn't remove it from the firm. It usually removes it from management's visibility.

The professional responsibility stakes are explicit. The ABA has warned that when a firm permits AI without defining its parameters, it effectively delegates risk assessment to individual lawyers, which is inconsistent with the supervisory responsibilities of firm leadership under the rules ABA Formal Opinion 512 applies to generative AI.

Step Two: Choose a Firm-Owned Business Environment

Client work shouldn't be conducted through an employee's personal AI account, and the reason is more than administrative tidiness. Free and consumer AI accounts may use conversations to train the provider's models, depending on the product and settings, which means client facts typed into a public chatbot can leave the firm's control entirely. The training protections the vendors advertise apply to their business and commercial environments, not automatically to whatever account an employee happens to have. The firm should own the workspace, control membership, require multifactor authentication, remove access when an employee leaves, and maintain authority over configuration. The billing account, administrative credentials, and recovery information belong to the firm.

The distinction that smaller firms most often miss is between individual and organizational subscriptions: ChatGPT Plus versus ChatGPT Business, Claude Pro versus Claude Team, personal Gemini versus Gemini within Google Workspace. Paying $20 for an individual subscription doesn't create a managed organizational environment. It creates a personal account that happens to be paid, with no firm administration, no centralized offboarding, and no organizational control over where client information goes when the employee who opened it departs.

Step Three: Review the Provider Before Uploading Client Information

"Not used for training" is an important control, but it isn't a complete vendor-risk assessment. Before client information touches the platform, the firm should document: whether prompts and outputs are used for model training; how long conversations and uploaded files are retained; whether administrators can delete user data; whether the firm can export its records; what third-party applications or connectors can access the workspace; whether data is encrypted; what audit or activity information is available; how terminated-user data is handled; whether the provider offers appropriate contractual terms; and whether the provider will notify the firm of a security incident.

This isn't gold-plating. Florida Ethics Opinion 24-1 specifically directs lawyers to investigate AI providers' policies on data retention, data sharing, and self-learning, and confirms that lawyers remain responsible for accuracy, competence, confidentiality, billing, and supervision when AI is involved.

Step Four: Lock Down Integrations and Connected Applications

An approved AI platform may connect to email, cloud storage, calendars, customer-management systems, practice-management applications, and outside plugins, and every connector expands the amount of information the platform can reach. The defaults deserve attention: OpenAI's current documentation indicates apps and connected plugins are enabled by default in ChatGPT Business, although administrators can manage them, while Google provides granular controls, activity logging, and the ability to determine which users can access Gemini features in specific Workspace applications.

The practical recommendation is to begin with external applications and connectors disabled, enabling each connection only after the firm understands what data it can access and what operational purpose it serves. A small firm doesn't need an AI assistant reading every mailbox and every client folder on the first day.

Step Five: Define Three Levels of Permitted Use

The firm needs a use-case classification rather than a vague instruction to use AI responsibly.

Generally permitted

Lower-risk activities that don't involve client confidential information: creating internal checklists, drafting generic administrative correspondence, developing training materials, brainstorming article or seminar topics, summarizing public documents, improving the readability of nonconfidential text, drafting generic interview questions, preparing internal meeting agendas, and creating first drafts of office procedures.

Permitted under controls

Activities that may involve client or matter information, requiring the approved business workspace, applicable client consent, jurisdictional review, and attorney supervision: summarizing case documents, creating factual chronologies, comparing contracts, drafting deposition outlines, organizing discovery material, preparing first drafts of client correspondence, identifying issues in agreements, reviewing large document sets for themes or inconsistencies, and producing an initial draft of a pleading or memorandum.

Prohibited

At least initially, the firm should prohibit: entering client information into personal or unapproved AI accounts; allowing AI to send communications directly to a client; filing AI-generated material without attorney review; relying on AI-generated citations without checking the original authority; allowing AI to make final legal judgments; giving an AI system unrestricted access to the document-management system; using public custom bots or third-party plugins for confidential matters; allowing an AI-generated answer to become the only record of legal research; and concealing AI use when a court rule, client requirement, or engagement condition requires disclosure.

AI can participate in legal work. It cannot accept professional responsibility for the result.

Define What Human Review Actually Means

Almost every AI policy says output must be reviewed by a human, and the instruction is too vague to supervise. In a law firm, verification means: every case citation is opened and checked in an authoritative legal research source. Every quotation is compared with the original document. Every statutory and regulatory reference is checked for current applicability. Jurisdiction, procedural posture, and effective dates are confirmed. Factual summaries are compared with the underlying record. Privilege and confidentiality issues are reviewed before the output is shared. The responsible attorney determines whether the result reflects the client's objectives and legal strategy. And no AI-generated document goes directly from the model to a client, opposing counsel, or court.

This is not an invented standard. ABA Formal Opinion 512 applies the existing duties of competence, confidentiality, client communication, supervision, candor, and reasonable billing to generative AI, and places responsibility on lawyers to understand how the technology uses data and to establish adequate safeguards.

Client Consent Deserves Careful Treatment

Not every use of AI requires client consent, and a policy that claims otherwise won't survive contact with practice. The obligation varies with the information involved, the manner of use, the provider, and the controlling jurisdiction. The defensible formulation: before submitting information relating to a representation, the firm must determine whether its confidentiality safeguards are reasonable and whether the applicable professional rules require client consultation or informed consent.

ABA Formal Opinion 512 recommends informed consent before client confidences are placed into certain generative AI systems and indicates that generic boilerplate in an engagement agreement may be insufficient. Florida's guidance similarly calls for informed consent when using a third-party generative AI program would disclose confidential information. Firms should review the rules of every jurisdiction in which they practice; the ABA opinion is a useful baseline, not the only controlling authority.

Privilege Is a Separate Question From Confidentiality

Confidentiality is a duty the firm owes the client. Privilege is a protection the client can lose, and AI creates two distinct ways to put it at risk. The first is waiver: privilege generally depends on the communication remaining confidential, and no court has yet definitively resolved whether processing privileged material through a third-party AI vendor is more like using a cloud storage provider, which courts have generally accepted under proper controls, or more like a disclosure that undermines the protection. Until that law develops, the conservative position is to keep genuinely privileged communications and litigation strategy out of AI systems whose retention and access the firm doesn't control, and to paper the vendor relationship with confidentiality obligations the way the firm would for any other service provider handling client material.

The second risk is the record itself. AI conversations aren't ephemeral. In 2025, the federal court in the New York Times copyright litigation ordered OpenAI to preserve ChatGPT conversation logs, including chats users had deleted, a widely reported reminder that prompts and outputs can become preserved, discoverable records in litigation the firm isn't even a party to. OpenAI's own chief executive publicly cautioned the same year that conversations with ChatGPT carry no legal privilege of their own. A lawyer's prompt describing case strategy is a written record of that strategy, held by a third party, on retention terms the firm chose when it configured the account. That's the practical reason the retention and deletion questions in the vendor review above aren't paperwork; they determine what exists to be demanded later.

The privilege problem also walks in the door with the client. Many clients and prospective clients have already run their case facts through a public AI tool before ever contacting a lawyer, and those conversations were never privileged: the protection attaches to confidential communications with counsel, and a chat with a consumer chatbot involves no lawyer at all. Retaining the firm afterward doesn't retroactively protect what was already shared with a third party, and the client's own prompts can surface later as discoverable records or admissions. Intake procedure should therefore ask specifically whether the client has discussed the matter with any AI tool, instruct the client to stop, and direct that existing conversations be preserved rather than deleted, since deletion after litigation is anticipated creates a spoliation problem on top of the original one. The exposure belongs in the case assessment the same way a client's social media history does.

Start With One Controlled Workflow

The first pilot shouldn't be giving everyone AI to see what happens. A better pilot involves three attorneys or staff members and one repeatable workflow: creating a chronology from a controlled set of documents, comparing two versions of an agreement, producing a first draft of a routine client-status letter, summarizing publicly filed pleadings, converting a firm procedure into a checklist, or creating an intake summary for attorney review within the approved environment.

Measure the current process first: time required, labor cost, error rate, amount of attorney review, turnaround time, and rework. Then compare the AI-assisted process against that baseline. The objective isn't simply safe AI use. It's safe AI use that produces measurable business value, the same discipline this publication applies to every AI investment decision.

A 30-Day Implementation Model

Week 1

Discovery

Inventory existing AI use across the firm, identify one candidate workflow, review the applicable ethics rules, and classify the information the workflow involves.

Week 2

Platform and controls

Evaluate the shortlisted platforms on controlled tasks, select the business environment, configure accounts under firm ownership, require multifactor authentication, restrict connectors, and create the initial permitted-use policy.

Week 3

Training and testing

Train the limited pilot group on synthetic, public, redacted, or otherwise approved material. Teach users how to verify citations, factual summaries, quotations, and legal conclusions.

Week 4

Controlled pilot

Run the selected workflow against the documented baseline, record errors and time savings, and decide whether to expand, modify, or terminate the use case. Expansion should depend on evidence, not on whether users enjoyed the tool.

Billing Is Part of the Implementation

AI can reduce the time required to produce legal work, which raises billing questions most implementation guides ignore. A lawyer can't bill three hours merely because the task historically took three hours if AI reduced the actual attorney time to forty-five minutes. The firm can charge for time actually spent prompting, reviewing, correcting, and validating the work. Costs associated with a specialized AI product may sometimes be passed through when properly disclosed and agreed, but ordinary subscription costs may be treated as overhead. ABA Formal Opinion 512 addresses both reasonable fees and the need for transparency, and a firm that resolves the billing question before the pilot avoids resolving it in a fee dispute afterward.

The Choice Facing the Small Firm

The choice facing a small law firm isn't between purchasing an expensive legal AI platform and avoiding AI entirely. Affordable business versions of ChatGPT, Claude, and Gemini can support useful legal and administrative workflows. The firm must still decide what information those systems may receive, how their output will be checked, who is responsible for their use, and what measurable result justifies the expense.

The technology is already inexpensive enough for a small firm to obtain. What can't be purchased with a subscription is the management discipline required to use it properly.

Sources and Notes

  • Vendor pricing per published pricing pages retrieved August 2026: ChatGPT Business $20 per user per month billed annually with a two-user minimum; Claude Team Standard seats $20 per user per month billed annually with a five-seat minimum; Gemini functionality included at varying levels within Google Workspace business plans. All three providers state business or commercial customer data isn't used to train their general models by default. Pricing and terms change frequently; confirm before purchase.
  • ABA Formal Opinion 512 (2024): application of the duties of competence, confidentiality, client communication, supervision, candor, and reasonable fees to generative AI; informed consent recommended before client confidences enter certain generative AI systems; guidance on billing for AI-assisted work.
  • Florida Bar Ethics Opinion 24-1 (2024): direction to investigate AI providers' policies on data retention, data sharing, and self-learning; informed consent where use of a third-party generative AI program would disclose confidential information; continuing lawyer responsibility for accuracy, competence, confidentiality, billing, and supervision.
  • Connector defaults per OpenAI and Google Workspace administrative documentation reviewed August 2026; verify current defaults in the admin console during configuration.
  • Privilege discussion: preservation order regarding ChatGPT conversation logs, including deleted chats, entered in the New York Times v. OpenAI copyright litigation (S.D.N.Y., 2025), as widely reported; public statements by OpenAI's chief executive in 2025 that ChatGPT conversations carry no legal privilege. Whether third-party AI processing waives attorney-client privilege remains unresolved in the case law; the discussion above describes the open question rather than settled doctrine.
  • Related analysis: AI Tools for Law Firms: What Practices Are Actually Buying, the LinkedIn AI eDiscovery decision, and ChatGPT Business vs Claude Enterprise.