What is this course about?
Firm AI governance has to survive three audiences: partners who resent process, clients whose outside counsel guidelines already restrict AI, and a malpractice carrier that will ask what controls exist. This course builds a governance structure addressing all three, including stopping shadow AI use without driving it further underground.
Who is this course for?
- Firm general counsel and risk partners
- Managing partners and executive committee members
- Firm CIOs and innovation officers
- Professional responsibility committee members
What do I need before starting?
- Firm leadership or risk responsibility
- Access to client outside counsel guidelines
What will I be able to do afterwards?
- Establish an AI committee with authority partners will accept
- Maintain an approved tool list and stop shadow AI use
- Deliver mandatory training and document competence
- Meet client disclosure and outside counsel guideline requirements
- Produce the audit trail a malpractice carrier expects
What does each module cover?
Who sits on the AI committee?
40 minComposition and authority that a partnership will actually respect.
Objectives
- Define committee composition and authority
- Secure partnership buy-in for the authority
- Design a decision process that is fast enough
Topics
Activity. Draft the committee charter and test it against three real decisions.
How do you stop shadow AI without driving it underground?
45 minApproved tool lists that work because the approved tools are good enough.
Objectives
- Build and maintain an approved tool list
- Make approval fast enough that people wait for it
- Detect unapproved use without surveillance
Topics
Activity. Survey actual tool use anonymously and compare against the approved list.
What training is mandatory, and how do you prove it?
45 minTraining that discharges the competence duty and produces evidence it happened.
Objectives
- Define mandatory training by role
- Document competence for each attorney
- Refresh training as tools and rules change
Topics
Activity. Design the mandatory training program with competence documentation.
What do client outside counsel guidelines already say?
45 minThe AI restrictions clients have already imposed, which most firms have not audited.
Objectives
- Audit client guidelines for AI restrictions
- Track restrictions per client and matter
- Enforce restrictions technically where possible
Topics
Activity. Audit your top ten clients' guidelines for AI restrictions.
How do you obtain client consent?
45 minEngagement letter language and the conversation with a client who asks hard questions.
Objectives
- Draft engagement letter AI provisions
- Handle the client conversation
- Manage clients who decline
Topics
Activity. Draft the engagement letter provision and rehearse the client conversation.
What does your malpractice carrier want to see?
40 minCarrier expectations, and the controls that affect coverage and premium.
Objectives
- Identify carrier expectations around AI
- Document controls in the form carriers request
- Understand coverage implications
Topics
Activity. Complete a carrier AI questionnaire honestly and identify the gaps.
What does the audit trail need to contain?
40 minLogging that supports a later inquiry without creating a discoverable liability.
Objectives
- Specify audit trail contents
- Balance evidentiary value against discoverability
- Set retention appropriately
Topics
Activity. Specify the audit trail and review it with litigation counsel for discoverability.
Assembling the governance package
50 minThe workshop module: policy, consent, training, and audit assembled for adoption.
Objectives
- Assemble the complete governance package
- Plan the partnership adoption path
- Set the review cadence
Topics
Activity. Assemble the package and plan the partnership meeting that adopts it.
What is the capstone project?
Firm AI governance package
Produce the complete package: committee charter, approved tool list with a fast approval path, mandatory training with competence documentation, a client guideline audit, engagement letter provisions, carrier-ready control documentation, and an audit trail specification.
Deliverable: A governance package ready for partnership adoption.
How are learners assessed?
- Anonymous tool survey completed and compared against the approved list
- Client guideline audit covering the firm's largest clients
- Audit trail specification reviewed by litigation counsel for discoverability
What ships with the course?
Facilitator guide
Session-by-session running order, discussion prompts, and the questions that reliably derail a room.
Learner workbook
Exercises, checklists, and the templates each module's activity produces.
Hands-on lab environment
A sandboxed ibl.ai deployment so exercises run against real agents, not screenshots.
Assessment bank
Scenario questions and rubric criteria mapped to each stated learning outcome.
Source bibliography
Every primary regulation and standard cited on this page, linked and dated.
Which AI agents does this course use?
The hands-on modules run against agents already deployable on the ibl.ai platform for legal.
Where does the course material come from?
Every module is grounded in primary sources — the regulation, standard, or research itself, not a summary of it. Each was resolved at authoring time.
- Model Rules of Professional Conduct
American Bar Association
The duties the governance package must discharge.
- AI Risk Management Framework
NIST
Control framework the governance package maps to.
- ISO/IEC 42001, AI management systems
ISO
Management system structure for firms seeking formal certification.
- OWASP Top 10 for LLM Applications
OWASP
Technical control requirements informing the approved tool criteria.
Delivery notes
Binding guidance for anyone preparing and delivering this course.
- Module 2's approval speed is the whole shadow-AI strategy. If approval takes six weeks, partners will use unapproved tools regardless of policy, and the governance is theatre.
- The anonymous survey must be genuinely anonymous and non-punitive. Attorneys will not disclose unapproved use to a process that could sanction them.
- Module 7's discoverability question is real and under-considered. An audit trail built for governance can become a plaintiff's exhibit, and litigation counsel should shape it.
- Module 4 will surprise most firms. Many large clients already restrict AI in their guidelines and firms have been non-compliant without knowing it.
- Coordinate with LEG-6 — the policy content comes from there, and this course is about the governance structure that operates it.
Why run AI training on a platform you own?
You own the course, not a licence to it
Course content, learner data, and the platform run inside your perimeter — you own all the code and the data.
Model-agnostic delivery
Run the course's AI components on any LLM — Claude, GPT, Llama, Gemini, Command — and switch anytime.
No per-seat training licences
Usage-based or self-hosted, so cost tracks actual use rather than headcount.
Deploy anywhere
Cloud, private VPC, on-premise, or fully air-gapped — including for cohorts that cannot use public AI tools.
Frequently asked questions
What does the Law Firm AI Governance: Policy, Training, and Client Consent course cover?
Firm AI governance has to survive three audiences: partners who resent process, clients whose outside counsel guidelines already restrict AI, and a malpractice carrier that will ask what controls exist. This course builds a governance structure addressing all three, including stopping shadow AI use without driving it further underground. It runs 5 hours across 8 modules across 8 modules, at intermediate level, and closes with a capstone: Firm AI governance package.
Who should take Law Firm AI Governance: Policy, Training, and Client Consent?
It is written for Firm general counsel and risk partners, Managing partners and executive committee members, Firm CIOs and innovation officers, Professional responsibility committee members. Prerequisites: Firm leadership or risk responsibility; Access to client outside counsel guidelines.
Can we run this course on our own infrastructure?
Yes. ibl.ai is model-agnostic and deploy-anywhere — cloud, private VPC, on-premise, or fully air-gapped — and you own all the code and the data. Cohort data, submissions, and any material learners upload stay inside your perimeter, which matters for legal teams that cannot send work to a public AI tool.
How do we get access to Law Firm AI Governance: Policy, Training, and Client Consent?
Request access and we will set it up for your cohort — hosted by ibl.ai, or running against your own deployment. Tell us the group size and timing you need, and whether it should run inside your own perimeter.
How much does AI training for legal cost on ibl.ai?
There is no per-seat pricing — you pay for usage or self-host and pay only for the infrastructure, so a 5,000-person rollout does not cost 5,000 licences. 1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.