Insights
Updated September 2026

AI Governance for Law Firms and Professional Services

A practical AI governance framework for teams handling confidential work, regulated decisions, and professional accountability.

8 min read

General information, not legal advice. Legal position as of . Limitations in the Legal Notice

Review status: legal and language review by a named human reviewer is pending.

In this article

A lawyer pastes a confidential client memo into an unapproved AI service. This illustrative scenario raises questions about disclosure, access and professional secrecy. It does not establish a criminal offence without an assessment of the facts and the applicable law.

A useful governance framework makes those questions answerable before a tool is used. The approach below is designed for a small professional-services team. Its sequence is a planning aid, not a compliance certification or a measured implementation timetable.

Start with the Swiss professional duties

The Swiss Bar Association's AI guidance (in German), in its February 2025 version, recommends internal rules, careful assessment of input data and independent critical verification of results. It is guidance; the underlying legislation and applicable professional rules determine legal duties. The guidance deliberately avoids endorsing particular products.

It describes three possible arrangements: operation within the firm's own network without data leaving it; outsourcing assessed against the SAV's outsourcing and cloud guidance; or an informed client agreement and waiver where legally effective. None is an automatic exemption from data protection, confidentiality or other people's rights. Local deployment also needs access controls, secure operation and a check for external connections.

Two statutes anchor the duty. Article 13 of the Lawyers Act (BGFA) subjects lawyers within the Act's scope (Article 2), without time limit and towards everyone, to professional secrecy about everything clients entrust to them in their professional capacity, and requires them to ensure that their auxiliary staff also keep it. Article 321 of the Swiss Criminal Code protects professional secrets under its specific conditions. Neither provision makes every AI use an offence or a professional breach, and a general engagement-letter sentence does not authorise every disclosure. Identify the information, recipients, processing purpose and permissions needed for the proposed use.

The CCBE guide on the use of generative AI by lawyers, dated 2 October 2025 and published on the SAV's AI page, is also guidance rather than binding law. It recommends not entering personal, confidential or other client data into a generative AI tool unless appropriate safeguards are in place, verifying outputs where the use case requires it, and being transparent with a client where an informed client could reasonably be expected to object or have reservations.

Legal anchors (CH/EU)

Switzerland: Lawyers Act, Article 13 (professional confidentiality); Criminal Code, Article 321 (breach of professional secrecy); FADP, Article 7 (data protection by design and by default), Article 9 (processors), Article 16 (disclosure abroad), Article 21 (automated individual decisions) and Article 22 (data protection impact assessment).

EU, where the firm is within scope: GDPR, Article 22 (automated decisions) and Article 28 (processors); AI Act, Article 4 (AI literacy) and Article 26(2) (human oversight by deployers of high-risk systems, from 2 December 2027 for Annex III systems).

Assess each supplier and use case

Swiss hosting and a security certificate are useful evidence to examine. They do not establish that a particular processing operation is lawful. Apply the same assessment to a specialist Swiss product and to a general-purpose assistant.

Scroll horizontally to view all columns.

RecordQuestion to resolve
Purpose and ownerWhich task is approved, and who can stop it?
Data and accessWhich client, employee or third-party information reaches which recipients?
Processing chainWhere do inference, support, logs and backups run? Which subcontractors have access?
Contract and settingsAre training reuse, retention, deletion and changes in processing addressed?
Evidence and exitWhat can be tested or inspected, and how can work continue after termination?

Assess the actual processing chain rather than banning all subcontracting by default. Test it against professional secrecy, applicable data protection law and the contract. Unanswered material questions should restrict approval until resolved. A numerical procurement score cannot replace that assessment.

Research offers a useful structure, not a guarantee: Raji and colleagues' 2020 internal-auditing framework links lifecycle decisions to an audit trail. It proposes a method; it does not prove that a particular checklist prevents misconduct in law firms.

Build the operating rules

Keep an inventory of both firm-provided tools and individual work use. Ada Studio recommends approving one task and one data boundary at a time, with a named person who can stop it, rather than approving an entire product for any purpose. Use statuses such as approved with recorded conditions, awaiting evidence, and restricted pending review.

The acceptable-use policy should answer practical questions: which information may be entered, what output needs source verification, who handles an uncertain result, and how an incident is reported. Keep the main instructions readable and put detailed procedures where staff can find them. Page count alone does not establish that a policy will be understood or followed.

Qualified reviewers should verify material legal propositions and citations against the underlying authorities. Asking the same model whether its answer is correct is not independent verification. Test omissions and misleading agreement as well as visibly incorrect answers.

The SAV guidance identifies possible disclosure duties arising from supplier terms or a client's justified expectation of personal performance. Assess the mandate and applicable rules. A useful client explanation describes the actual role of AI and review arrangements; it is not a substitute for any specific consent or confidentiality permission required.

  1. Stage 1

    Inventory

    Record tools, tasks, data flows and a responsible owner.

  2. Stage 2

    Assessment

    Resolve confidentiality, supplier and legal questions before approving the use.

  3. Stage 3

    Policy and training

    Practise permitted tasks, source checks, escalation and fallback.

  4. Stage 4

    Review

    Use incidents, samples and changes in processing to reassess the controls.

Connect training to the work

Train staff on the approved tasks and give them a way to demonstrate the required checks. Attendance records document participation, not competence on their own. Assign enough time and authority to the person responsible for governance; a fixed quarterly time allowance is not supported by evidence.

Where the EU AI Act applies, Article 4 concerns AI literacy. From 2 February 2025 to 26 July 2026 it required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and of others operating or using AI systems on their behalf. Since 27 July 2026, as amended by Regulation (EU) 2026/1744, it requires measures to support the development of AI literacy and does not require anyone to guarantee a specific level for an individual. For high-risk systems, Article 26(2) will require deployers, from 2 December 2027 for Annex III systems, to assign human oversight to natural persons with the necessary competence, training and authority, as well as the necessary support. Territorial scope, intended use and operator role must be assessed separately.

Under the consolidated AI Act, Articles 111 and 113, the relevant Annex III high-risk duties apply from 2 December 2027, and corresponding product-related duties from 2 August 2028, subject to the relevant transitions. Article 50 transparency and AI literacy have separate timelines. A general governance policy does not automatically fulfil those specific duties.

Watch the Swiss regulatory path

On 12 February 2025 the Federal Council spoke out in favour of ratifying the Council of Europe's AI Convention, which mainly concerns state actors, and instructed the FDJP to prepare a consultation draft by the end of 2026 (Federal Council press release). Switzerland signed the Convention in March 2025. The Federal Office of Justice page (in German), read on 26 September 2026, still gives the end of 2026 as the deadline for the consultation draft. Until new rules are adopted, professional secrecy and the FADP remain the central Swiss rules for a firm's own AI use; the FDPIC confirms that the FADP applies directly to AI processing.

Keep evidence of decisions and changes

The NIST AI RMF can help organise responsibilities and risk review. Framework alignment or management-system certification does not establish compliance with every law. Reuse relevant privacy and security records, then identify the AI-specific gaps.

Governance discussion checklist

0/6

Key Takeaway

A useful framework connects an approved use to its data boundary, evidence, reviewer and escalation route. Documentation supports professional diligence; its legal significance depends on the facts and applicable duties.

Need a workable governance process? Get in touch to discuss your team's tools, responsibilities and review needs.

Clarify how AI decisions are made

Connect business, HR, IT and risk through clear ownership and review routines.

You might also like

Need clearer footing for an AI decision?

Start with a focused conversation about a live AI use case, workflow bottleneck, training need, or governance gap.