An AI use policy for a Mauritian law firm: what belongs in it
Date
August 9 2026
Category
Legal
Date
August 9 2026
Category
LegalA firm-specific AI use policy is not a list of banned tools. It is a set of decisions about confidentiality, verification, privilege and liability that the partnership can defend to a client or a regulator.
Every law firm will need an AI use policy. The ones that fail will treat it as a technology policy, a list of approved software with footnotes about passwords. The ones that succeed will treat it as a professional-conduct document: who is responsible, what can leave the firm, and how output is checked before it reaches a client or a court.
This article sets out what belongs in a Mauritian law firm AI use policy. It is a starting point, not legal advice; review it with your own counsel before it is adopted.
1. Scope and purpose
State who the policy applies to: employees, pupils, interns, secondees, contractors and anyone else producing work under the firm’s direction. Explain that the policy is about professional obligations first and tools second. [DECISION, include retired partners, of-counsel and outsourced clerks.]
2. Confidentiality and professional secrecy
This is the heart of the document. It should be explicit about:
- what categories of client information may not be entered into any AI tool;
- that the firm’s normal confidentiality and privilege obligations apply to AI output as they do to any other work product;
- that using an AI tool does not remove the duty to keep client information confidential.
3. Approved and prohibited tools
List the tools the firm has reviewed and approved, with the person or body that approved them and the date. Prohibit staff from using unapproved consumer tools for firm work. Include a process for requesting a new tool: who assesses it, what data-protection and security questions must be answered, and who signs off.
4. Input rules
Be specific about what may be entered into an approved tool. For example:
- anonymised or hypothetical questions may be permitted;
- client names, file numbers, specific facts and internal strategy may not;
- pleadings, draft opinions and unredacted correspondence are restricted.
5. Output verification
Every AI-generated output used in firm work must be checked by a person with the competence to do so. The policy should require:
- verification of any cited authority against the original source;
- review by the supervising lawyer before the output is sent externally;
- a record that verification took place.
6. Logging and record-keeping
Firms should keep a register of AI use decisions, including approved tools, rejected requests, incidents and near-misses. This is evidence of reasonable steps if a regulator or client asks.
7. Training and breach
Set out how staff are trained on the policy and what happens if it is breached. The tone should be proportionate: the goal is compliance and understanding, not a culture of fear.
A starting template
We have prepared a draft AI use policy template for professional firms in Mauritius. It covers the sections above and includes notes for adapting it to your firm’s structure and obligations. [DECISION, finalise template after legal review.]
A policy is only useful once the partnership has discussed it, disagreed where necessary, and decided. The value is in the conversation, not the document.