Artificial Intelligence Governance Policy
1. Purpose and Scope
Ramsay & Partners (“the Firm”) recognises that artificial intelligence (AI) and generative AI tools offer significant opportunities to enhance the quality, speed, and efficiency of legal services. This Policy establishes the principles, responsibilities, and procedures governing the development, evaluation, approval, and use of AI technologies within the Firm. It applies to all partners, lawyers, paralegals, trainees, professional support staff, contractors, and any third parties acting on the Firm’s behalf.
2. Core Principles
The Firm will only use AI in a manner that is:
- Accurate and Reliable – using only tools that have been appropriately vetted and monitored for bias, hallucination, and error rates.
- Ethical – consistent with the rules of professional conduct and our duties to the court, clients, and the administration of justice.
- Secure – protecting client confidentiality, privilege, and personal data.
- Transparent – ensuring clients are informed when AI plays a material role in their matter and obtaining consent where required.
- Accountable – maintaining meaningful human oversight and responsibility for all work product.
3. Governance Structure
3.1. AI Oversight Committee
- Chaired by the Managing Partner or delegate.
- Membership: Chief Operating Officer, and at least one practicing partner from litigation and transactional practices.
- Meets quarterly or as required.
3.2 Responsibilities of the Committee
- Maintain and update the Approved AI Tools Register.
- Conduct or commission risk assessments of new tools.
- Review incidents and near-misses.
- Recommend training and policy updates.
4. Approval Process for AI Tools
No AI tool may be used for client-related work until it appears on the Approved AI Tools Register.
4.1. Responsibilities of the Committee
- Tier 1 (Low Risk) – Internal tools with no external data transmission (e.g., on-premise models or Firm-developed automation).
- Tier 2 (Moderate Risk) – Cloud-based enterprise or business-level tools with contractual no-training clauses, enterprise-grade security, and controlled data residency.
- Tier 3 (High Risk) – Public, free, or consumer-grade tools, or tools that train on user inputs. Use of Tier 3 tools for any client-related or confidential matter is strictly prohibited.
4.2. Mandatory Evaluation Criteria for Tier 2 Approval (all must be satisfied)
- Vendor confirms that inputs and outputs are not used to train models.
- Data residency in jurisdictions with adequate protection (e.g., Jamaica, Australia, EU/EEA, UK, Canada, US with appropriate safeguards).
- Recent independent security attestation (e.g., SOC 2 Type II or equivalent).
- Encryption in transit and at rest (AES-256 or better).
- Documented testing for accuracy, bias, and hallucination risks.
- Ability to audit logs and delete data on demand.
- Appropriate contractual indemnity and liability coverage.
5. Current Approved AI Tools Register (as at 30 April 2025)
| Tool | Vendor | Tier | Permitted Uses | Special Conditions / Limitations |
| Grammarly Business | Grammarly, Inc. | 2 | Writing assistance, grammar, tone, plagiarism check | Enterprise plan required; suitable for processing draft documents |
| vLex AI; Vincent | vLex | 2 | Legal research, case analysis, summarisation | Paid subscription with AI features enabled |
| Google Gemini | Google LLC | 2 | Research, summarisation, brainstorming | Workspace/Enterprise plan only; no direct input of confidential or personal data |
| Microsoft Copilot | Microsoft Corporation | 2 | Productivity in Office apps, research, drafting | Microsoft 365 Copilot license; integrated use allowed |
| ChatGPT | OpenAI | 2 | General research, brainstorming, drafting support | Enterprise or Team plan only; strictly no confidential, privileged, or personal data input |
| Clio AI (including Duo) | Clio | 2 | Practice management, document insights, automation | Standard Clio subscription; use within platform only |
| Grok | xAI | 2 | General research, reasoning, idea generation | Paid subscription required; strictly no confidential, privileged, or personal data input |
| Todoist AI | Doist, Inc. | 2 | Task prioritisation, smart suggestions | Business plan; primarily internal productivity use |
| Reclaim.ai | Reclaim | 2 | Intelligent scheduling and time protection | Business plan; internal productivity use |
| Serif.ai | Serif.ai | 2 | AI-assisted tasks (as licensed) | Enterprise/business plan; use in accordance with vendor terms |
| Repriced.ai | Repriced.ai | 2 | Travel booking monitoring, price drop detection and refunds | Subscription plan; internal firm travel and expense management only; no input of confidential, privileged, or client data |
| Loom | Loom (Atlassian) | 2 | Asynchronous video messaging, screen recording with AI transcription, summaries, and editing | Business/Enterprise plan; primarily internal use or with client consent; no sharing of confidential materials without safeguards |
| Fireflies.ai | Fireflies.ai | 2 | Meeting recording, transcription, summarisation, action items | Enterprise plan required; obtain all necessary recording consents; avoid or anonymise highly sensitive client discussions |
Additional similar enterprise or business-level tools meeting the Tier 2 criteria may be proposed to the AI Oversight Committee for evaluation and potential addition to this register.
6. Prohibited Practices
The following are strictly forbidden:
- Entering any confidential, privileged, personal, or sensitive data into Tier 3 or unapproved tools.
- Using AI to generate advice or work product without meaningful human review and verification.
- Representing AI output as independent lawyer work without disclosure where material.
- Circumventing technical controls or using personal accounts for Firm work.
- Using AI for automated decision-making in high-risk areas (e.g., conflicts, sanctions) without Committee approval.
- Failure to comply with Practice Direction No. 1 of 2025 – Use of Generative Artificial Intelligence in Court Proceedings (Supreme Court of Jamaica)
7. Client Confidentiality & Data Protection
- All client data processed by AI tools remains subject to legal professional privilege and applicable privacy laws (including the Data Protection Act).
- Where practicable, lawyers must anonymise or redact identifying information before input.
8. Client Notification and Consent
8.1 Standard engagement letters and General Terms of Engagement include disclosure and consent provisions for AI use.
8.2 For highly sensitive matters (e.g., involving special categories of personal data, national security, or public interest litigation), specific written client consent identifying the tool(s) and use case is recommended.
9. Human Oversight and Quality Control
- All AI-generated output must be independently reviewed, verified, and citation-checked by a qualified lawyer.
- The responsible lawyer remains fully accountable for accuracy and appropriateness.
10. Training and Competence
- All fee-earners and relevant staff must complete annual AI ethics and secure-use training.
- New joiners receive training within 30 days.
11. Incident Reporting
Any suspected or actual breach (e.g., accidental data exposure, material hallucination) must be reported immediately to the AI Oversight Committee.
12. Review and Updates
This Policy and the Approved AI Tools Register will be reviewed at least annually or upon material changes in technology, regulation, or case law.