Safe AI and AI governance

Your people are using AI. Has anyone told them what is safe?

Tier 1 helps law firms and high-trust consultancies find the AI already in use, set a clear line around sensitive information and build oversight that people can follow.

Scroll to explore
02Tier 1

Section 02

Confidentiality duties still apply when AI is used

Client material entered into an unapproved tool may be processed outside the firm's approved systems under terms the firm has not assessed. AI output can also be wrong while sounding convincing. Both issues need practical controls.

A glowing glass form contained within frosted screens in a dark room.
03Tier 1

Section 03

A practical governance baseline

The goal is safe, useful adoption with named accountability, not a large policy exercise.

Map actual use

Record approved, trial and prohibited tools, their owners, purposes, users and information.

Set data rules

Define what may and may not enter each tool, including client, personal, privileged and security information.

Review suppliers

Assess terms, locations, retention, training use, subcontractors, deletion, incidents and administration.

Require human review

Define which output needs checking, who is qualified and what evidence should be retained.

Train the firm

Use examples from real legal and advisory work so staff understand the line and how to report a mistake.

Use ISO 42001 where it fits

Build a formal AI management system when risk, clients, tenders or strategic goals justify it.

04Tier 1

Section 04

Move from unknown use to controlled use

The work can begin as a focused baseline and grow only where the firm's use and obligations require it. The immediate aim is to give staff a safe route to use useful tools and a clear way to ask before crossing the line.

Discover

Speak with the people doing the work and record existing tools, experiments, embedded features and intended use cases.

Decide

Classify uses, approve suitable tools and set the information, review and recordkeeping rules that apply to each category.

Enable

Train staff with relevant examples, publish a simple approval path and make reporting a mistake easier than hiding it.

Review

Recheck approved tools, exceptions and higher-risk uses when suppliers, terms, models or business processes change.

05Questions

Straight answers

Common questions

Do we need to ban public AI tools?

Not necessarily. A practical starting point is to identify real use, decide which information cannot enter a tool and approve suitable services for defined tasks. Some uses may need to remain prohibited when the confidentiality or reliability risk cannot be controlled.

Is a paid or enterprise AI account automatically safe?

No. Contract terms, data use, retention, location, access controls, deletion and administration still need review. The right answer depends on the tool, configuration, information and proposed use.

Do we need ISO 42001 certification?

Most small firms do not need certification to begin governing AI. An inventory, data rules, supplier checks, human review and named ownership usually come first. Formal alignment becomes more useful when clients, tenders, higher-risk systems or strategy justify it.

Can our legal, privacy and IT advisers be involved?

Yes. AI governance crosses contractual, privacy, security, technology and professional duties. Tier 1 can coordinate the control work while the appropriate adviser remains responsible for advice in their field.

A quiet first step

Book a confidential call

Talk directly with Michael about what your firm needs to protect and the practical next step.

Book a confidential call