ResourcesFree-to-use template
AI use policy

A template for your AI use policy

This is a complete AI use policy template, written for professional firms in Mexico: law, accounting, architecture, medical, engineering, real estate and marketing agencies. It is meant to be read and applied in daily work. It is free to use: copy it, change what you need and adopt it in your firm.

See the governance practice

How to use the template

Before adopting it
01

The bracketed fields are yours. Replace [Firm name], [responsible area or person], [incident contact or person] and the marked lists with what applies to your real operation. Before adopting it, run it past your legal area or a lawyer you trust so it fits your contracts, your privacy notice and your sector duties.

02

Treat it as a living document. Give it a version number and a date ([version], [date]), name an owner who maintains it, and set how often it is reviewed. When your tools or the law change, update the template and tell your team; a policy nobody reads again stops protecting anyone.

The policy

10 sections

01 Purpose and scope

This policy defines how [Firm name] uses artificial intelligence tools in its work. The goal is simple: let your team benefit from AI without putting client information, professional secrecy or the firm's legal compliance at risk.

It applies to everyone working for [Firm name], whether partners, associates, administrative staff, interns or outside providers with access to firm information. It applies to any AI tool, whether or not it is on the approved-tools list.

When this policy and a client contract say different things, the stricter one wins. If you are unsure about a specific case, [responsible area or person] decides before you act.

02 Definitions

So the rules below apply the same way for everyone, these terms mean the same thing throughout the document.

  • AI tool: any service that generates or processes text, images, audio or code with artificial intelligence models, whether a public chatbot, an enterprise version or a model on the firm's own servers.
  • Public tool: an open service anyone reaches with a standard account, where by default what you type may be retained or used to improve the model.
  • Enterprise tool: a version contracted under an agreement that fixes retention, deletion and a ban on training the model with your data.
  • Own servers: a model running on infrastructure the firm controls, where the data never leaves your hands.
  • Personal data: any information that identifies or can identify a person. The law gives reinforced protection to sensitive data, such as health, and treats financial or asset data separately, which also requires express consent.
  • AI output: any text, analysis, image or code produced with the help of an AI tool.

03 Approved tools and usage tiers

The firm sorts its information into four tiers and maps each tier to a type of tool. The base rule: the more sensitive the data, the more closed the tool.

The concrete list of approved tools lives in an annex, [approved-tools list], kept current by [responsible area or person]. Using a tool outside that list for firm work requires prior authorization.

  • Public (already published or non-sensitive): marketing material, public documents, generic templates. May be used in approved public tools.
  • Internal (firm operations, non-sensitive): general drafts, notes, internal communication with no client data. Approved public tools, with human review.
  • Confidential (work product, matter facts, professional secrecy, NDA): only in enterprise tools or on the firm's own servers, never in public tools.
  • Restricted (personal data, identity documents, sensitive data): only on own servers or under a documented exception approved by [responsible area or person].

04 Data that never enters public tools

This is the line that is not crossed under any deadline. None of the following is pasted into a public AI tool, even when the output is needed in minutes.

If you need a public tool's help with a sensitive document, strip the data that identifies people first and leave only the shape of the problem. When the data cannot be separated from the identity, use an enterprise tool or your own servers.

  • Client names tied to the facts of their matter.
  • Official IDs, tax IDs and contact details of identified persons.
  • Financial statements or economic information before they are public.
  • Sensitive personal data, such as health, and detailed financial or asset data of identified persons.
  • Passwords, access keys or credentials for any system.
  • Any information a client has asked in writing to keep off third-party systems.

05 Confidentiality and professional secrecy

The firm's duty of confidentiality does not change because an AI model is involved. Anything covered by professional secrecy or a confidentiality agreement stays just as protected inside and outside an AI tool.

Before entering client information into any tool, confirm two things: that the information's tier allows that tool under section 03, and that the client contract does not forbid using third parties to process their data.

If a client requires that their information never touch AI tools, that instruction overrides this policy. Record it in the file and communicate it to everyone assigned to the matter.

06 Personal data and the LFPDPPP

When the firm decides what is done with personal data, the law treats it as the data controller, and that role is not transferred by hiring a tool. Mexico's Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) still applies to any processing done with AI.

The firm's privacy notice must cover the purposes of processing and, where applicable, transfers to third parties; when a provider processes data on the firm's behalf, that is a remission to a processor, governed by contract. It is also good practice for the notice to state clearly that AI tools are used. You do not quietly add a new purpose after collecting the data. Review it before bringing AI into the workflow.

Every person keeps their ARCO rights, access, rectification, cancellation and objection, and, where the applicable law provides for it, may object to decisions made solely by automated means. The firm must be able to honor those requests even when data has passed through an AI tool.

  • A provider that processes data on the firm's behalf is a processor and must be bound by contract to the same confidentiality and security.
  • Personal data is processed only for the purposes stated in the privacy notice.
  • For sensitive data the consent standard is higher; process it only on own servers or under an approved exception.

07 Human review and responsibility for the output

No AI output leaves the firm without a person reviewing it and owning it. The tool assists; responsibility for the final content always belongs to whoever signs the work.

Review is more than a quick skim. Verify the facts, the citations and any figures the model generated, because a model can state something false with full confidence. What you cannot verify does not go out.

The more the output matters, the stricter the review. An internal draft tolerates a glance; a document going to a client, a counterparty or an authority demands full review by the person responsible for the matter.

08 Logging and traceability of use

The firm keeps a reasonable record of how AI is used in the work, enough to answer clearly if a client or an authority asks. It is enough to be able to show who may use which tool, for which tasks, and with which tier of data.

[responsible area or person] keeps that record and the approved-tools list. For confidential or restricted work, it is worth noting the tool used and the human review performed.

  • Which tools are approved and at which data tier.
  • Who has access to each enterprise or own-server tool.
  • Authorized exceptions, with date, reason and approver.

09 Incidents and who to tell

If confidential information or personal data reaches somewhere it should not, for example a document pasted into a public tool by mistake, the goal is to contain it fast.

The sequence is short on purpose, so it can be followed under stress: stop, save evidence of what happened, and immediately notify [incident contact or person].

[responsible area or person] assesses whether the incident involves personal data and triggers whatever the LFPDPPP requires in that case. That decision is made by the right person, with the full picture in view.

10 Training and keeping the policy current

A policy nobody read or practiced protects nobody. Everyone covered gets training on these rules applied to their real work before using AI for the firm, and that training is recorded.

The policy has an owner, [policy owner], and a fixed review date: at least [frequency, for example every 6 or 12 months], and also whenever the approved tools or the applicable law change.

Each version carries a number and a date. When it is updated, the change is communicated to the team. Version [version], in force since [date], owner [policy owner].

Questions about the template

FAQ
Can I copy the template as is?

Yes, it is free to use. But copying it without adjusting leaves gaps: the bracketed fields, the approved-tools list and the data tiers depend on your operation. Change them for what you actually use before adopting it, or you will be signing rules that do not describe your firm.

Do I need a lawyer to adopt it?

To use the template, no. To adopt it seriously, it helps: a lawyer checks that it fits your contracts, your privacy notice and your sector duties. If you do not have that in-house, the legal half of our AI governance practice is handled by Alarcón Law, our allied firm.

How often should an AI use policy be reviewed?

At least once or twice a year, and also whenever your approved tools or the applicable law change. Give it a version number and a date so you know which one is in force. A policy with no review date ages without anyone noticing.

Does it work for agencies and real estate, not only law firms?

Yes. The structure works for any firm or company that handles client information: accounting, architecture, medical, engineering, real estate and marketing agencies. Swap the data examples for your sector's; the logic of tiers and human review is the same.

Governance and training

Adopt the policy and train your team

We can help you adapt this template, review the legal side with Alarcón Law and train your team so they actually follow it. The technical and training side is ours; the legal side is our allied firm.

AI use policy template · Lizardi Consulting · living version at https://www.lizardi.mx/en/recursos/politica-de-uso-de-ia