Ask a two-to-twenty-five person firm which AI tools are permitted and you will usually get a product name. Ask who decided, and the answer is almost never a lawyer.
It is the licence bundle. Somebody sells the firm a productivity suite, an AI assistant is included or costs a little extra, and that becomes the answer to a question nobody asked out loud. Which is fine, right up until you notice what that decision quietly settled.
The duty does not move with the invoice
Model Rule 1.6(c) puts the obligation to make reasonable efforts on the lawyer. Not the vendor, not the provider who set up the tenant. Your IT company can be excellent — many are — and it still cannot hold a duty that the rule assigns to you.
Formal Opinion 512 goes further and names who inside the firm owns it:
Managerial lawyers must establish clear policies regarding the law firm's permissible use of GAI, and supervisory lawyers must make reasonable efforts to ensure that the firm's lawyers and nonlawyers comply
ABA Formal Opinion 512, July 2024, as quoted in The Bar Examiner. The opinion itself is here.
"Managerial lawyers must establish clear policies" is not a recommendation to consider a framework. It names a person and a document. A licence bundle is neither.
A worked example, using a good product
We went and read Microsoft's own documentation on enterprise data protection for Copilot, because it is one of the few vendor pages in this whole area that is dated in the page itself and that we could read end to end without being blocked. It is here, and as of 19 August 2026 it carried an update stamp of 18 August 2026.
The headline is exactly what people believe it is:
the prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models
Microsoft Learn, Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat
That is a real commitment and it is worth having. Now here are three more things on the same page, none of them hidden, all of them things the person who sold the licences is unlikely to have mentioned.
- Web searches leave the protection. When Copilot goes to the web, the query goes to Bing, and the page says the Bing service "operates separately from Microsoft 365 and has different data-handling practices covered by the Microsoft Services Agreement between each user and Microsoft", with Microsoft acting as "an independent data controller". Two footnotes make the edge sharper still: HIPAA compliance "doesn't apply to web search queries as they aren't covered by the DPA and Business Associate Agreement (BAA)", and the EU Data Boundary "doesn't apply to web search queries."
- Add-on agents have their own terms. In Microsoft's own words: "When you're using agents in Microsoft Copilot, check the privacy statement and terms of use of the agents to determine how they'll handle your organization's data." Which is to say the protections you just read about are not automatically inherited by everything that appears inside the same window.
- The protections vary by plan. A footnote: "The specific controls will vary depending on a customer's Microsoft subscription plans." So "we're covered, we have Microsoft" is not an answer to anything until somebody names the plan.
To be clear about what that adds up to: Microsoft wrote all of that down, publicly, and dated it. That is better disclosure than most of this industry manages. The problem is not the disclosure. It is that nobody whose duty this is has read it.
What we did not check
We read Microsoft's documentation. We did not verify the equivalent statements from Google or OpenAI — OpenAI's pages we could not read at all — and we are not going to summarise a document we have not seen.
So take the Microsoft section as a worked example of how to read a vendor page, not as a comparison. The pattern generalises. The specific footnotes do not.
What to do
Send your provider four questions and ask for the answers in writing. Which plan are we on, exactly. Does that plan's documentation say our inputs are excluded from model training. Which parts of the product fall outside that — searches, add-ons, anything a user can switch on themselves. And where is the page that says so, so we can read it ourselves.
That is one email, and it can go out this afternoon without a meeting first. Whoever manages the relationship with the provider is the right person to send it.
A good provider will answer inside a day and will not mind being asked. A provider who cannot name your plan, or who answers with reassurance instead of a link, has told you something useful too.
The cost of not asking is not a bill. It is the difference between "we are covered, we have Microsoft" and a plan name with a page behind it. One of those is an answer and the other is an assumption, and at the moment you may not know which one you are holding.
The answers go in the policy, which is the next post.
If you would rather have someone sit on that call with you and read the answers properly, the consulting page is the way in. Send the email either way — it costs nothing and it is yours to keep.