Most law firm AI policies cover case documents and stop there — and leave out the firm’s own financial data. Billing records, trust balances, realization figures, and client payment histories are confidential client information too, and they’re exactly the data operators now want to query with AI. A complete policy needs a section that names who can use AI on financial data, which tools are allowed, and what’s off-limits. This is the piece most policies skip.
This is a companion to our full law firm AI policy template and guide. Start there for the base policy; use this to add the financial-data section.
Why financial data is the blind spot
Most firm AI policies were written in reaction to one fear: an associate pasting a case file into ChatGPT. That’s the right instinct, aimed at the wrong-sized target. The duty of confidentiality under ABA Model Rule 1.6 covers all information relating to a client’s representation — which includes the numbers: what you billed, what you wrote off, what a client still owes, what sits in trust. As firms start asking AI questions about their own revenue, that data starts moving into tools, and the policy has to keep up.
What the financial-data section should specify
- Data classification. Name which financial data is sensitive (trust balances, client payment history, matter-level billing and write-offs) and treat it with the same care as case files.
- Approved tools only. Financial data goes into tools that contractually don’t train on your inputs, isolate your data, and support role-based access — never a public chatbot.
- Who can query it. Set access by role. Not everyone who can run a report should be able to ask an AI tool about another attorney’s realization or a client’s payment behavior.
- What’s prohibited. Be explicit: no firm financial data in public, consumer AI tools, full stop.
Keep it enforceable
A policy is only as good as the systems behind it. If financial data lives in a dozen exports and spreadsheets, no policy can govern where it goes. When that data sits in one connected system with role-based access, the policy has something to attach to — the rules hold because the system enforces them, not because everyone remembers to. That’s what makes a financial-data policy real rather than aspirational.
Frequently asked questions
Is billing and trust data really covered by confidentiality rules? Yes. Model Rule 1.6 covers all information relating to a client’s representation, which includes financial details — not just case strategy.
Can we let staff ask AI about our firm’s revenue numbers? Only in a governed tool with role-based access, so the right people see the numbers and no one else does. Never in a public tool.
Where does this fit in our existing AI policy? As a data-classification and approved-tools subsection. If you don’t have a base policy yet, start with our policy template and add this section.
Published by
The LeanLaw Team
The LeanLaw Team is the legal-finance content team behind LeanLaw — the billing, trust accounting, and revenue-reporting platform built natively on QuickBooks Online. Drawing on years of work alongside law firms and the accountants who serve them, the team writes about trust accounting, IOLTA compliance, legal billing, and law-firm financial operations. LeanLaw is a QuickBooks Online Premium App Partner.
Related articles