AI policy

Law firms trust us with confidential and often privileged client data. This is a summary of the rules our team follows when using AI.

Last updated 25 September 2026

In short

We use AI to help our team work more efficiently, under a written internal policy. We never put your firm’s data into free or consumer AI tools, we treat matter files as privileged unless you tell us otherwise, and we don’t use AI on your data without your informed agreement. A qualified person reviews anything AI helps produce, and every migration is proved by reconciliation, not by AI.

Our approach

Our internal AI Usage Policy applies to every director, employee and contractor. It follows Australia’s AI Ethics Principles, the National AI Centre’s Guidance for AI Adoption, and the Australian Signals Directorate’s guidance on AI for small business, alongside our obligations under the Privacy Act 1988 and the confidentiality duties our law firm clients owe their own clients.

  • Accountability. Our Managing Director owns the policy and approves every AI tool we use.
  • Approved tools only. We keep a register of approved tools, recording where each one stores data and confirming that training on our data is switched off. Tools that aren’t on the register can’t be used for client work.
  • Risk-based rules. Low-risk tasks, like drafting internal notes, need little more than an approved tool. Anything involving client data is high risk and needs your agreement, an enterprise-grade tool and sign-off by a person.
  • Training. Staff complete AI training, including how to spot inaccurate output and manipulated content, before they get access to any AI tool.

On your project

  • We check your engagement terms first. Where they are stricter than our policy, your terms apply.
  • We tell you which AI tools, if any, we plan to use on your project, and get your written agreement where your contract requires it or where privileged or sensitive material could be involved.
  • We assume law firm matter files may contain privileged material, and never process them with AI without your informed consent.
  • Where AI helps analyse or test data structures, we use sample, synthetic or de-identified data wherever we can, rather than your full data set.
  • We prefer AI features already built into platforms you use and have approved, such as Microsoft 365, over introducing new tools. Any new tool is checked first, including confirming where your data would be processed and whether it would leave Australia.
  • Any AI-assisted mapping or transformation logic is reviewed and signed off by a qualified team member before it runs against your live data, and significant AI-assisted actions are logged in the project file.
  • Your data is removed from any AI workspace when the task or project ends, in line with our privacy policy.

What we never do

  • Upload client documents, matter details or personal information to free or consumer AI tools, even briefly.
  • Allow your data to be used to train AI models.
  • Use AI to make final decisions about your matters without review by a person.
  • Present AI-generated analysis as verified when it hasn’t been checked.

If something goes wrong

Staff must report any suspected AI-related incident straight away. If client or personal information is affected, we notify you, and the Office of the Australian Information Commissioner and affected individuals where the Notifiable Data Breaches scheme requires it.

Questions

If you would like to know how AI was or wasn’t used on your project, or would prefer we don’t use AI at all, tell us at the start and we’ll agree it in writing. Email info@entasker.com. We review this policy at least once a year and whenever the tools or the rules change.