Artificial Intelligence Governance Policy


1.  Purpose and Scope

Ramsay & Partners (“the Firm”) recognises that artificial intelligence (AI) and generative AI tools offer significant opportunities to enhance the quality, speed, and efficiency of legal services. This Policy establishes the principles, responsibilities, and procedures governing the development, evaluation, approval, and use of AI technologies within the Firm. It applies to all partners, lawyers, paralegals, trainees, professional support staff, contractors, and any third parties acting on the Firm’s behalf.


2. Core Principles

The Firm will only use AI in a manner that is:

  • Accurate and Reliable – using only tools that have been appropriately vetted and monitored for bias, hallucination, and error rates.
  • Ethical – consistent with the rules of professional conduct and our duties to the court, clients, and the administration of justice.
  • Secure – protecting client confidentiality, privilege, and personal data.
  • Transparent – ensuring clients are informed when AI plays a material role in their matter and obtaining consent where required.
  • Accountable – maintaining meaningful human oversight and responsibility for all work product.

3.  Governance Structure


3.1. AI Oversight Committee

  • Chaired by the Managing Partner or delegate.
  • Membership: Chief Operating Officer, and at least one practicing partner from litigation and transactional practices.
  • Meets quarterly or as required.


3.2  Responsibilities of the Committee

  • Maintain and update the Approved AI Tools Register.
  • Conduct or commission risk assessments of new tools.
  • Review incidents and near-misses.
  • Recommend training and policy updates.

4. Approval Process for AI Tools


No AI tool may be used for client-related work until it appears on the Approved AI Tools Register.


4.1.  Responsibilities of the Committee

  • Tier 1 (Low Risk) – Internal tools with no external data transmission (e.g., on-premise models or Firm-developed automation).
  • Tier 2 (Moderate Risk) – Cloud-based enterprise or business-level tools with contractual no-training clauses, enterprise-grade security, and controlled data residency.
  • Tier 3 (High Risk) – Public, free, or consumer-grade tools, or tools that train on user inputs. Use of Tier 3 tools for any client-related or confidential matter is strictly prohibited.


4.2. Mandatory Evaluation Criteria for Tier 2 Approval (all must be satisfied)

  • Vendor confirms that inputs and outputs are not used to train models.
  • Data residency in jurisdictions with adequate protection (e.g., Jamaica, Australia, EU/EEA, UK, Canada, US with appropriate safeguards).
  • Recent independent security attestation (e.g., SOC 2 Type II or equivalent).
  • Encryption in transit and at rest (AES-256 or better).
  • Documented testing for accuracy, bias, and hallucination risks.
  • Ability to audit logs and delete data on demand.
  • Appropriate contractual indemnity and liability coverage.

5. Current Approved AI Tools Register (as at 30 April 2025)

ToolVendorTierPermitted UsesSpecial Conditions / Limitations
Grammarly BusinessGrammarly, Inc.2Writing assistance, grammar, tone, plagiarism checkEnterprise plan required; suitable for processing draft documents
vLex AI; VincentvLex2Legal research, case analysis, summarisationPaid subscription with AI features enabled
Google GeminiGoogle LLC2Research, summarisation, brainstormingWorkspace/Enterprise plan only; no direct input of confidential or personal data
Microsoft CopilotMicrosoft Corporation2Productivity in Office apps, research, draftingMicrosoft 365 Copilot license; integrated use allowed
ChatGPTOpenAI2General research, brainstorming, drafting supportEnterprise or Team plan only; strictly no confidential, privileged, or personal data input
Clio AI (including Duo)Clio2Practice management, document insights, automationStandard Clio subscription; use within platform only
GrokxAI2General research, reasoning, idea generationPaid subscription required; strictly no confidential, privileged, or personal data input
Todoist AIDoist, Inc.2Task prioritisation, smart suggestionsBusiness plan; primarily internal productivity use
Reclaim.aiReclaim2Intelligent scheduling and time protectionBusiness plan; internal productivity use
Serif.aiSerif.ai2AI-assisted tasks (as licensed)Enterprise/business plan; use in accordance with vendor terms
Repriced.aiRepriced.ai2Travel booking monitoring, price drop detection and refundsSubscription plan; internal firm travel and expense management only; no input of confidential, privileged, or client data
LoomLoom (Atlassian)2Asynchronous video messaging, screen recording with AI transcription, summaries, and editingBusiness/Enterprise plan; primarily internal use or with client consent; no sharing of confidential materials without safeguards
Fireflies.aiFireflies.ai2Meeting recording, transcription, summarisation, action itemsEnterprise plan required; obtain all necessary recording consents; avoid or anonymise highly sensitive client discussions


Additional similar enterprise or business-level tools meeting the Tier 2 criteria may be proposed to the AI Oversight Committee for evaluation and potential addition to this register.



6. Prohibited Practices


The following are strictly forbidden:

  • Entering any confidential, privileged, personal, or sensitive data into Tier 3 or unapproved tools.
  • Using AI to generate advice or work product without meaningful human review and verification.
  • Representing AI output as independent lawyer work without disclosure where material.
  • Circumventing technical controls or using personal accounts for Firm work.
  • Using AI for automated decision-making in high-risk areas (e.g., conflicts, sanctions) without Committee approval.
  • Failure to comply with Practice Direction No. 1 of 2025 – Use of Generative Artificial Intelligence in Court Proceedings (Supreme Court of Jamaica)

7.  Client Confidentiality & Data Protection

  • All client data processed by AI tools remains subject to legal professional privilege and applicable privacy laws (including the Data Protection Act).
  • Where practicable, lawyers must anonymise or redact identifying information before input.

8. Client Notification and Consent


8.1  Standard engagement letters and General Terms of Engagement include disclosure and consent provisions for AI use.


8.2 For highly sensitive matters (e.g., involving special categories of personal data, national security, or public interest litigation), specific written client consent identifying the tool(s) and use case is recommended.


9. Human Oversight and Quality Control

  • All AI-generated output must be independently reviewed, verified, and citation-checked by a qualified lawyer.
  • The responsible lawyer remains fully accountable for accuracy and appropriateness.

10. Training and Competence 

  • All fee-earners and relevant staff must complete annual AI ethics and secure-use training.
  • New joiners receive training within 30 days.

11. Incident Reporting


Any suspected or actual breach (e.g., accidental data exposure, material hallucination) must be reported immediately to the AI Oversight Committee.


12. Review and Updates


This Policy and the Approved AI Tools Register will be reviewed at least annually or upon material changes in technology, regulation, or case law.