Which AI tools is your firm actually using?

Staff paste client information into AI tools nobody approved — and nobody wrote down. Check where your firm stands in three steps, then publish an AI usage policy you can hand to a client, an insurer or a regulator.

Start the 8-question self-check See the AI tool list

  • Runs in your browser
  • Nothing installed on staff devices
  • No account, no client data uploaded
  • 8 questions
  • 20 tools rated
  • 3 steps to a policy

1. Which of these tools is your firm using?

Tick everything you have seen, heard about or simply are not sure about. Each entry shows why the typical setup is risky and what exactly to check. Tiers describe the usual configuration, not a verdict on the vendor.

Filter by category

0 tools selected

Ratings reflect the ordinary way small firms adopt these tools (personal accounts, default settings, no written rules). Move a tool to Medium or Lower risk by confirming the checklist item and recording it in the register.

2. Eight questions about how AI is used today

Answer as things are, not as they should be — the policy is only useful if it matches reality. Nothing is uploaded: answers stay in this browser.

0 answered

Do not collect device data to answer these questions. If you do not know, choose “I do not know” — that is an honest and useful answer.

3. Where your firm stands

4. Your policy, register and incident card

Generated from your answers and the tools you ticked. Edit anything before you publish it — it is your firm's document, and you can print it as a one-page A4.

You can edit the text below. Nothing is saved to a server.

AI usage register

One line per use of an AI tool on client work. Download the CSV, or copy the table into the spreadsheet you already use.

AI usage register

Example row — replace it with your own records.

First 72 hours: incident card

Print this and keep it with the policy. Do not wait to be sure — assess early and record the decision.

  1. Stop the leak: stop using the tool, remove the shared link, end the recording or revoke the account. Note the exact time.
  2. Write the timeline: what was entered, which client, which matter, by whom, when, and who else could have seen it.
  3. Tell the owner named in the policy the same day. Do not investigate alone.
  4. Assess the risk to the people whose data it is, and decide whether the supervisory authority must be notified. Record the decision either way.
  5. Tell the client if the data is theirs and the risk is real. Agree the wording with the owner first.
  6. Fix the cause the same week: update the approved list, the register and the training note.

General guidance, not legal advice. Reporting duties and deadlines depend on your jurisdiction and on the facts.

Sources and scope

The pain this tool answers was taken from a published survey of small-firm practice risks; the tool ratings describe configurations, not vendor policies.

  • Meeting recorders and transcription: voice fragments and transcripts of confidential meetings may be listened to manually by the provider's external staff; a personal-data leak involving AI must be assessed for reporting within a short statutory window. Source: derechoartificial.com (ES), recorded in the project pain-point research, item 282, 2026-09-25.
  • Professional secrecy and AI prompts: confidentiality protects lawyer–client communication, but does not automatically extend to prompts typed into an AI application. Source: ordevanvlaamsebalies.be (BE), items 274 and 277, 2026-09-25.
  • Generative AI and privileged material: do not share legally privileged or confidential information with a generative model until the data handling is clear. Source: barcouncilethics.co.uk (UK), item 275, 2026-09-25.
  • Breach notification: a personal data breach likely to result in a risk to people must be notified to the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Source: edpb.europa.eu (EU), item 273, 2026-09-25.

No vendor-specific claim is made anywhere in this tool. Ratings describe how small firms usually adopt a tool (personal account, default settings, no written rules). Always confirm the current terms and the data-processing agreement with the vendor before relying on them.