For law firms

When a client's outside counsel guidelines arrive with an AI clause

It arrives as a routine email. Updated outside counsel guidelines, effective the first of next month, please confirm receipt. Attached is a 22-page document you have seen 19 pages of before. Section 11 is new: notice before generative AI is used on the client's matters, no entry of the client's confidential information into any tool that trains on inputs, a written AI governance policy, and the client's right to audit. Three weeks to confirm.

Treat that confirmation as what it is — a written representation to a party that has just reserved audit rights — and the work in front of you is not drafting an answer, it is assembling five artifacts you should hold anyway.

The same five artifacts answer the carrier supplemental and the client security questionnaire. You are not building three answer sets. You are building one and answering from it three times.

Why this is not an isolated event

The Association of Corporate Counsel publishes "Sample Artificial Intelligence (AI) Guidelines for Outside Counsel" in its resource library — a template for general counsel to insert AI clauses into outside counsel guidelines (acc.com, verified August 2026). The clause your client sent you is therefore likely to be substantially the clause your next four clients send you.

Nobody has counted how many firms have received one. No survey quantifies it, and we will not invent a number.

The mechanism is straightforward. Corporate legal departments are under their own AI governance pressure from their own boards and auditors, and the cheapest way for a general counsel to discharge it is to flow the obligation down to outside counsel. You are the supplier. Supplier requirements roll downhill and they do not roll back up.

Meanwhile, per a 2026 EPIC carrier survey reported in specialty insurance trade press, CNA has sent supplemental AI questionnaires to law firms since 2025 covering tools, governance policy, training, work-product verification and incident response, and more than 60% of LPL carriers now ask AI questions at renewal. Trade-press sourced; confirm with your broker. Open a client security questionnaire from a bank or a hospital system and you will find the same five categories in procurement vocabulary.

The five artifacts, and why they are not the policy

1. A tool-and-model inventory. One table. Every AI tool anyone at the firm can reach, including features embedded in software you already own. Vendor, model where disclosed, whether the terms permit training on your inputs, retention, what firm data it reaches, who approved it, date of last review. Almost every AI question on every questionnaire is answered from this table.

2. A written AI acceptable-use policy. Scope, permission tiers by named product, permitted and prohibited uses by work type, the client consent rule, the verification requirement, the named owner, the exceptions process, incident response — with a version number, an approval date and an acknowledgement register.

3. A verification record you can produce. Not the policy section describing verification. One completed record on a real matter, showing authority in an AI-assisted document pulled, read and signed off by a named person. General counsel have started asking for the artifact rather than the paragraph.

4. Training attendance records. Dated sessions, on your policy and your tools, with a sign-in sheet.

5. An incident response plan naming AI scenarios. Client information in an unapproved tool. A filing found to contain unverified authority. A vendor changing its data handling terms. Plus the date of your last tabletop.

With those five, the OCG clause is a confirmation email and a calendar entry. Without them it is three weeks of assembling documents while the client waits.

The crosswalk is the answer key

Every security questionnaire you will ever receive is a restatement of a control framework, usually at two removes. Two frameworks matter at your size. NIST Cybersecurity Framework 2.0, published February 2024: six functions — Govern, Identify, Protect, Detect, Respond, Recover. Govern is new in 2.0 and it carries policy, roles and oversight. There is no 3.0. And CIS Controls v8.1, released June 2024: eighteen controls broken into safeguards, ordered roughly by implementation priority. There is no v9, and CIS publishes an official crosswalk of v8.1 to NIST CSF 2.0.

A crosswalk is a mapping table. Left column, the control identifier. Right column, the policy section that satisfies it and the artifact that evidences it. When a questionnaire asks you to describe your process for inventorying software assets, you do not compose an answer — you look up CIS Control 2, read across to the policy section and the inventory, and copy what you already wrote.

For the AI-specific questions there is a third reference: the NIST AI Risk Management Framework 1.0, January 2023, with its Generative AI Profile, NIST AI 600-1. No 2.0 exists. And do not chase ISO/IEC 42001 because a questionnaire mentioned it once — it is an emerging procurement requirement, not settled practice, and the certification cost is not justified at your size this year.

The answer that gets you audited

One answer reads well and creates exposure. If you attest that the firm maintains a written AI governance policy, and the policy is a 2024 memo nobody acknowledged, you have made a representation about a control you do not operate — to a party with audit rights.

The precedent worth knowing sits on the insurance side. In 2022 Travelers and International Control Services jointly stipulated to void an active cyber policy from inception after ICS misrepresented its use of multi-factor authentication on its application (Insurance Journal, August 30, 2022). That was a stipulation between the parties, not a decision on the merits, and it was cyber rather than professional liability. There is no documented, named case of a claim denied specifically over an AI-related misstatement, and we will not imply there is.

The narrow lesson holds: the answer on the form is what the other side looks at later. If the honest answer is "not yet, and here is our timeline," most general counsel will take it. What they will not forgive is a confirmation that turns out to be untrue at the first audit.

What to do Monday

  1. Read Section 11 of the guidelines and mark each requirement as have / partly / do not have.
  2. Answer the "have" items with the artifact, not the policy paragraph.
  3. Reply to the general counsel this week with dates for the rest. Silence reads worse than a timeline.
  4. Start the inventory table. It is the single artifact that answers the most questions.
  5. File the completed answers where the next questionnaire can reuse them.

What we will not do

We will not sell you the crosswalk without the policies underneath it. A crosswalk is fast to produce and looks impressive, and on its own it is a map of an empty building — every row pointing at a policy section and an artifact, telling an auditor exactly where to look for the things you do not have.

Signet, a division of Circle Square Consulting. AI that holds up. Radnor, Pennsylvania. The Renewal Dry Run is free and takes 30 minutes — bring the clause: /renewal-dry-run

The Renewal Dry Run — free, 30 minutes Published August 29, 2026