Key takeaways
- Lawyers remain responsible for all AI-assisted work.
- Client confidentiality, privacy and privilege must come first.
- Clear governance is more effective than a blanket ban.
Generative AI can help lawyers with research, drafting, document review, contract analysis and summarisation. However, the New Zealand Law Society’s guidance is clear that using AI does not reduce a lawyer’s professional obligations.
The technology may change how work is completed, but responsibility remains with the lawyer and the firm.
Lawyers remain accountable
AI tools can produce useful work quickly, but they can also generate inaccurate facts, invented authorities and misleading conclusions.
Lawyers must independently verify AI-generated content, particularly where it is used in legal advice, contracts, court documents or research. Staff using AI must also be properly supervised.
An incorrect result cannot be excused simply because it came from an AI tool.
Protect client information
The most immediate risk for many firms is the information entered into an AI system.
Prompts may contain:
- client names and identifying information;
- privileged communications;
- legal advice and litigation strategy;
- commercially sensitive documents; and
- personal information about third parties.
Firms should understand whether providers retain, reuse or transfer data overseas. The Law Society recommends using fictional data for testing and says personal or client information should not be used for testing or creating templates. Firms should also consider whether client consent is required before using client information with an AI tool.
Removing a client’s name may not be enough if the surrounding facts still identify the person or matter.
Governance should enable responsible use
A blanket ban may encourage staff to use AI without approval or supervision. A better approach is to provide clear boundaries, approved tools and appropriate oversight.
AI governance should cover:
- approved and prohibited uses;
- rules for entering client information;
- vendor security and privacy assessments;
- human review requirements;
- staff training;
- incident reporting;
- insurance and business continuity; and
- regular review of tools and policies.
AI implementation is not simply an IT project. It can affect privacy, professional obligations, client service, billing and organisational risk.
Example: AI document summarisation
A firm considering an AI summarisation tool should first review the provider’s security, retention practices and overseas data processing.
It should then define which documents may be used, how outputs must be checked and when client approval is required.
The issue is not whether AI is used. It is whether the firm remains in control of its use.
Client communication and billing
Clients may expect to know when AI is used to process their information or complete important parts of their legal work.
Firms should be able to explain:
- why the tool is being used;
- what information it processes;
- what safeguards apply;
- how the output is reviewed; and
- who remains accountable.
Firms should also review whether existing billing practices remain appropriate where AI significantly reduces the time required to complete a task.
What this means for your organisation
New Zealand law firms should take five practical steps:
- Identify current AI use across the firm, including tools embedded in existing software.
- Approve suitable tools and define what information may be entered.
- Set human review requirements based on the risk of the task.
- Assess vendors for security, privacy, retention and overseas processing.
- Update policies and training, including client communication and incident reporting.
Conclusion
The Law Society’s guidance does not discourage AI adoption. It encourages firms to use it carefully and deliberately.
Law firms should know which tools are being used, understand how information is handled and maintain meaningful human oversight. Good governance allows firms to benefit from AI without compromising professional duties or client trust.
Sources
Qualification
This article provides general information about AI governance. It is not legal or technical security advice.

