AI Governance for Law Firms — NJ & NY

Your attorneys are
already using AI.
The only question is
whether it's governed.

Copilot, CoCounsel, ChatGPT — they're inside your firm today, approved or not. ABA Formal Opinion 512 says your existing duties of competence, confidentiality, and supervision follow them. In seven days, we make sure your firm can prove it.

Book the 15-minute call No pitch deck · Read-only methodology
Why listen to me

I vet AI platforms for one of the
largest law firms in the world.

My day job is cybersecurity governance at an Am Law 100 firm — running vendor security reviews on the AI tools attorneys ask to use, access governance across enterprise systems, and Microsoft 365 security operations. Before an AI platform touches privileged material there, it goes through the kind of review most small firms have never seen.

Small firms face the same ethics rules, the same client security questionnaires, and the same insurance underwriters — with none of that machinery. Attorneys and staff adopt tools on their own, client information follows, and nobody is accountable for where it goes.

Watusoft exists to close that gap: the same review discipline, scoped and priced for firms that will never hire a security team.

Vendor review methodology applied at Am Law 100 scale

What's actually at stake

Three facts most firms
haven't priced in.

01

Shadow AI is the default

If your firm has no approved tools, it doesn't mean AI isn't used — it means it's used invisibly. Client facts pasted into free consumer chatbots are retained, and you have no record of what left the building.

02

The duty is already yours

ABA Formal Opinion 512 places generative AI squarely under Rules 1.1, 1.6, and 5.3 — competence, confidentiality, and supervision. Having no policy isn't a defense. It's the finding.

03

The questions are coming

Corporate clients now send security questionnaires that ask about AI use. Cyber insurers are following. "We're working on it" reads very differently than a signed policy and a trained staff.

The engagement

AI Governance Readiness
Everything, in seven days.

  • Firm-wide AI tool inventory — approved, unapproved & shadow use
  • Vendor risk review of each tool's data handling & retention
  • Generative AI Acceptable Use Policy tailored to your practice areas
  • Confidentiality mapping to ABA Model Rules 1.1, 1.6 & 5.3
  • Staff briefing — what's allowed, what's not, and why
  • 30-day post-implementation check-in
Day 1Inventory
Day 3Policy draft
Day 5Staff briefing
Day 7Handoff
+30Check-in
Fair questions

Asked on almost
every call.

We barely use AI — do we actually need this?

Firms that "barely use AI" are usually the ones using it invisibly. The inventory step exists precisely to answer this question with facts instead of assumptions — and if it genuinely turns up nothing, the policy and training make sure it stays governed when adoption arrives, which it will.

Will you need access to client files?

No. The engagement works at the inventory and configuration level — which tools are in use, what their data terms say, how access is set up. It follows the same read-only discipline as every Watusoft engagement: no shared admin passwords, nothing touched without documentation.

What happens after the 15-minute call?

If it's a fit, you get a one-page proposal the same day and we typically start within a week. If your firm is already covered — it happens — I'll tell you that on the call and you'll have lost fifteen minutes.

The investment

Flat. Published.
The way fees should work.

One engagement, one fee, everything above included. Pair it with the Microsoft 365 Audit + Hardening engagement and cover the two exposures insurers and bar counsel ask about most — $6,500 bundled.
$4,500
One-time · 7 days · No hourly billing
The first step

Fifteen minutes.
Then you'll know.

Tell me where your firm is with AI — even if the answer is "no idea." I'll tell you what the exposure looks like and whether this engagement fits. No deck, no follow-up sequence of sales calls.