The direct answer
The Law Society of Ontario does not tell lawyers to avoid generative AI. Its guidance says the usual professional obligations continue when AI is used. In practice, that means a firm needs rules around the tool, account, information, task, review and person responsible before AI becomes routine.
For an Ontario law firm, the question is not simply whether someone has opened ChatGPT, Copilot, Claude, a research assistant, or another AI feature. The real question is whether the firm can explain which tools are allowed, what information may enter them, what work they may assist with, and how human responsibility remains in place.
That is governance. It is also where the Law Society of Ontario’s current direction is heading: artificial intelligence is part of legal practice, not a distant technology issue that can be deferred indefinitely.
The LSO has made AI guidance a standing practice resource
The Law Society’s Technology Resource Centre brings together the core resources lawyers should use when considering or using generative AI:
| LSO resource | Why it matters operationally |
|---|---|
| Licensee’s use of generative artificial intelligence | The white paper connects generative AI to professional duties and recommends an organizational policy, tool due diligence, training and verified output. |
| Generative AI: Your professional obligations | The practice note applies competence, confidentiality, candour, supervision, billing and tribunal duties to AI-assisted legal work. |
| Generative AI: Your quick-start checklist | A practical starting point for lawyers who need to identify the key questions before using a tool. |
| Building a generative AI policy: A checklist of key questions | A firm-level prompt to turn individual experimentation into clear, repeatable operating rules. |
The important distinction is that the LSO is not presenting AI as a separate shortcut around professional duties. The duties remain; the technology changes how a firm needs to meet them.
What the guidance requires a firm to manage
1. Human professional responsibility remains with the lawyer
AI can assist with work. It does not take responsibility for it. The LSO’s practice note says a licensee must independently verify AI-generated information they intend to rely on, and that the verification must be completed by a human being. A firm therefore needs a real review step before AI-assisted content is sent to a client, used in advice, entered in a file, or placed before a court or tribunal.
This is not solved by telling staff to “be careful.” The firm should decide which work can be AI-assisted, what review is required for each type of work, and who is accountable for the final output.
2. Confidentiality, privilege and privacy need tool-specific decisions
The LSO tells licensees to understand how a generative AI system uses inputs and to avoid entering confidential, privileged, proprietary or potentially identifying client information where the system lacks appropriate confidentiality, security and retention safeguards. That means the firm cannot judge a tool by its name, popularity, or a general statement that it is “secure.”
Before approving a tool for client-related work, a firm should understand the relevant account and settings, what prompt or upload data is retained, whether information may be used to improve the service, who can access the workspace, where the provider processes information, and what contractual protections apply.
If information cannot be adequately protected by anonymizing it, the LSO guidance says the licensee should consider the risks and informed consent before use. That is a legal and practice-management decision; the operational job is to make sure the firm knows what the tool actually does before information is entered.
3. Supervision includes staff use of AI
When students, clerks, assistants, junior licensees or other staff use AI, the firm still needs a controlled process. The LSO specifically recommends clear workplace guidelines, training on limitations and ethical risks, defined contexts for use, information restrictions, and regular review of AI-generated material used in employee work.
One person using an unapproved personal account to “clean up” a draft or summarize a document can create the same confidentiality, accuracy and supervision issue as a formal firm-wide rollout. A usable policy has to cover the work that is actually happening—not just the tools leadership intended to buy.
The firm questions that should be answered before AI becomes routine
A practical AI policy does not need to be a fifty-page document. It does need to produce clear answers that staff can follow.
| Governance question | What the firm should be able to answer |
|---|---|
| Which tools are approved? | The approved product, account type, owner, settings and intended users—not simply a brand name. |
| Who can add a new tool or feature? | The person or role that approves new AI products, extensions, integrations and paid subscriptions before client or firm information is used. |
| What information is restricted? | The categories that cannot be entered, uploaded, copied or connected without a documented review and applicable authority. |
| What tasks are allowed? | Permitted use cases, prohibited use cases, and tasks that require lawyer review before any result is used externally. |
| How does the provider handle information? | The relevant retention, training, security, access, location and contractual terms for the actual account and configuration. |
| How is work verified? | A human review requirement appropriate to the task, including checking legal authorities against trusted primary sources. |
| How are people trained? | Plain-language staff guidance on AI limits, data handling, approval routes and what to do when a situation is unclear. |
| What is recorded? | Approved tools, risk decisions, exceptions, vendor findings, policy changes and incidents or concerns requiring follow-up. |
Public AI and enterprise AI are not automatically the same—or automatically different
It is reasonable for a firm to distinguish between a public consumer account and a business tool used inside an existing productivity environment. It is not reasonable to assume that one is always acceptable and the other is always prohibited.
Microsoft Copilot, a public AI chat tool, a legal research feature, an AI-enabled document system and an AI browser extension can have different terms, configurations, prompt handling, permissions, retention rules and access paths. The firm should assess the actual deployment. In plain terms: which tool, which account, which settings, which information, which task, and which person is responsible?
That is why governance must come before general encouragement or prohibition. A simple rule that staff can understand is more useful than a vague warning about “being cautious with AI.”
This is no longer theoretical for Ontario law firms
Starting in 2026, Legal Aid Ontario requires roster lawyers to annually confirm through the Lawyer Self-Report that they have read and are complying with specified LSO AI guidance. Legal Aid Ontario also states that lawyers must not enter Legal Aid business information into AI platforms and remain responsible for privacy or data breaches arising from their AI use. Read Legal Aid Ontario’s 2026 update.
Ontario courts are moving in the same direction. The Superior Court of Justice now addresses responsible AI use in its civil, family and criminal practice directions. For example, its civil direction requires careful, informed and ongoing oversight where AI is used and requires legal information obtained with AI assistance to be verified against trusted and authoritative sources. Every firm should check the rules and directions of the specific court or tribunal where it appears. Read the Superior Court of Justice civil practice direction.
What an AI-ready firm should have in place
For a small or mid-sized law firm, the first useful deliverable is usually not a new AI subscription. It is a simple, current operating record that shows:
- the AI tools and AI-enabled features already in use;
- the accounts, owners, permissions and vendors connected to them;
- the information that can and cannot be entered;
- the permitted tasks and required human review;
- the approval process for a new tool, feature or integration;
- staff training and acknowledgement; and
- the person responsible for maintaining the policy and reviewing changes.
That record gives the lawyer and firm something much more useful than an informal promise that everyone uses AI carefully: a basis for supervision, consistent staff direction, vendor review and ongoing judgment.
Governance before AI
CyberTECT helps Ontario law firms map AI tools, information flows, access, vendors and operating responsibilities, then turn the findings into practical rules, review steps and records. CyberTECT does not provide legal advice, certify Law Society compliance, or approve the legal accuracy of AI-generated work.
Frequently asked questions
Does the Law Society of Ontario ban lawyers from using AI?
No. The Law Society’s guidance addresses how professional duties apply when legal services use generative AI. It emphasizes competence, confidentiality, supervision, professional judgment and independent verification rather than a blanket ban.
What should a law firm include in an AI policy?
A practical firm policy should identify approved tools and accounts, permitted tasks, restricted information, the approval process for new tools, required human review, staff training, vendor due diligence, and a way to record exceptions or concerns.
Can a law firm treat Microsoft Copilot and a public AI account the same way?
No. The firm should assess each tool and account on its own terms, including its settings, data handling, retention, access controls, contractual protections and intended use. A product name alone does not answer those governance questions.
Do lawyers need to verify AI-generated work?
Yes. The LSO’s practice note says information produced by generative AI that a licensee intends to rely on must be independently verified by a human being. Ontario court practice directions also require authoritative-source verification for legal information generated with AI in court proceedings.
General information only. This article summarizes public LSO, Legal Aid Ontario and court materials as reviewed on July 30, 2026. It is not legal advice, does not determine a firm’s professional obligations, and does not certify Law Society or court compliance. Firms should obtain advice appropriate to their practice, clients, tools and forum.
Related CyberTECT services and checks
Authoritative sources and further guidance
- Law Society of Ontario — Technology Resource Centre: Using technology
- Law Society of Ontario — Licensee’s use of generative artificial intelligence
- Law Society of Ontario — Generative AI: Your professional obligations
- Legal Aid Ontario — 2026 update to Lawyer Self-Report: AI compliance confirmation
- Ontario Superior Court of Justice — Consolidated Civil Provincial Practice Direction
CyberTECT resources provide general operational guidance. They do not replace advice specific to your legal, regulatory, contractual or technical circumstances.