Departments across all areas of the business are adopting AI at fast rates – in fact, 80% of organizations are now using it in some form, including legal teams.
But quick and informal adoption can have negative results – inconsistent practices, unclear accountability and growing risks around data, accuracy and compliance – so much so that only around a third of organizations adopting AI have established policies or ethics guidelines in place to control those risks.
With regulatory scrutiny increasing globally through legislation like the EU AI Act, and expectations around responsible AI use becoming more concrete, legal teams are being pulled into a more central role in shaping how AI is deployed through the use of AI mandates. But how do you get started with creating one? Read on to find out.
An AI policy typically sets out principles – high-level guidance on responsible use, ethics and risk. An AI mandate goes a step further, translating those principles into clear rules, guardrails and operational expectations. It answers practical questions like:
There are three main pressures converging here:
{{quote 1}}
In-house teams are often brought in once AI usage is already widespread. At that point, the instinct can be to react quickly, but it can lead to a few common mistakes:
And vitally, this isn’t just a business issue – it can exist within legal teams too. You might be using AI securely in your own workflows, but what about the rest of the legal function? Without shared standards and visibility, usage can quickly become inconsistently, even among colleagues in the same team.
These challenges all point to the same underlying issue: a lack of practical structure.
Your goal shouldn’t be to create a perfect framework immediately, but to establish clear, usable guardrails that can evolve over time. Here are a few core areas to focus on:
Be explicit about:
Being clear here reduces ambiguity across the business.
This is often the most critical area. Start by asking if your data can be used for training and if it should be. Crucially, not all “training” is the same – there’s an important distinction between:
For legal teams, this distinction is often one of the most significant from a risk and confidentiality perspective – and one that isn’t always understood across the business.
From there, your AI mandate should define:
“The question isn’t just ‘can we use AI?’. It’s ‘what happens to the data once we do?’ That’s where a lot of organizations still don’t have clear answers.”
– Richard Somerfield, Chief Technology Officer, Summize
AI outputs aren’t always accurate, and treating them like they are introduces risk. An AI mandate should set expectations around:
This is especially important for legal and customer-facing work.
For organizations operating across borders, AI governance isn’t one-size-fits-all. Legal teams should consider:
This doesn’t need to be overly complicated, but it does need to be considered early.
An area a lot of organizations overlook is whether employees should be using personal AI tools at all. Your AI mandate needs to clarify:
Without this, enforcement can become difficult.
Even the most well-considered AI mandate won’t be effective if it isn’t adopted in the first place. Success with an AI mandate isn’t just about defining rules, but about embedding them into how people actually work. That means:
{{quote 2}}
In other words, an AI mandate shouldn’t be a static, one-and-done document. It needs to be visible, usable and reinforced over time. For legal teams, that often means shifting from a purely advisory role to a more embedded, operational one that works closely with the business to make responsible AI use the default rather than the exception.
If you’re starting to formalize your approach, our full guide to AI and CLM explores how legal teams can apply these principles in practice – bridging the gap between policy and day-to-day contract workflows.
“From a legal perspective, the risk isn’t that AI is being used – it’s that it’s being used inconsistently, often without visibility into what tools are in play, what data is being shared, or who is accountable when something goes wrong. That’s where exposure quietly builds.”
“Use your leadership team to champion your AI mandate. The organizations getting it right aren’t the ones with the longest policies, but the ones that make it easier for their teams to do the right thing by default.”
