Your staff already use AI. The question is whose rules they follow
In almost every firm, someone has already summarised a contract in ChatGPT or drafted a letter with Claude, usually on a personal account because the firm offers no official route. This is shadow AI: AI used for firm work that the firm neither sees nor governs.
Banning it rarely works; people carry on, just more quietly. Ignoring it is no safer. The middle path is a short written policy that is actually enforced. Call it an AI acceptable use policy or a law firm AI policy; either way it says who may use which tools, on what data, and who answers for the result.
Below is a policy you can copy, a two-week rollout plan and a short checklist. This guide is general information, not legal advice.
Why it has to be written down
Professional firms handle clients' personal data every day, and for most of that work your firm is the controller under Indonesia's PDP Law. Several of a controller's duties bear directly on AI use:
- Article 31: the controller must record all personal data processing. A document pasted into a personal account never reaches the firm's records.
- Articles 35 and 36: the controller must put protective technical and operational measures in place and keep the data confidential. A written policy is among the easiest measures to evidence.
- Article 37: the controller must oversee everyone involved in processing under its control, including staff and the services they use.
- Article 34: an impact assessment is required for high-risk processing, including new technology and specific personal data.
- Article 46: if personal data protection fails, the controller must notify the individuals and the supervisory authority in writing within 3 x 24 hours. Without an internal reporting route, that deadline is nearly impossible to meet.
Article 4(2) classes health data, criminal records, children's data and personal financial data as specific personal data, and Article 25 requires a parent's or guardian's consent to process a child's data. Probate, divorce and family tax work are full of it.
A written policy does not remove the risk, but it gives you something to show when a client, auditor or regulator asks.
Indonesia's AI rules as of September 2026
The official reference in force is Minister of Communication and Informatics Circular No. 9 of 2023 on Artificial Intelligence Ethics, signed on 19 December 2023. It sets out ethical values for developing and using AI, including transparency, credibility and accountability, personal data protection and intellectual property. It is addressed to AI businesses and electronic system operators, and it is guidance only, but its values make a sound frame for an internal policy.
The government is also drafting a Presidential Regulation on a National AI Roadmap and another on AI Ethics (Komdigi legal information network, February 2026). When this guide was reviewed, we could not find either as an enacted regulation. For client data, the PDP Law remains your main reference.
An AI use policy template for your firm
Copy the text below, fill in the square brackets and delete what does not apply. Two pages everyone reads beat twenty in a drawer.
ARTIFICIAL INTELLIGENCE (AI) USE POLICY [Firm name], effective from [date]
1. Purpose and scope
- 1.1 This policy governs the use of generative AI, such as ChatGPT, Claude, Microsoft Copilot, Gemini and AI features in other applications, for the work of [Firm name].
- 1.2 It applies to all partners, employees, trainees and contractors, on any device.
- 1.3 [Name and role] oversees this policy and is referred to below as the AI Lead.
2. Approved tools and account types
- 2.1 Firm work may only use the AI services on this list: [for example ChatGPT Business, Claude Team, or Microsoft Copilot with a firm work account]. The AI Lead maintains the list.
- 2.2 AI accounts are created and paid for by the firm, using firm email addresses. Personal accounts, including paid ones, may not be used for client data.
- 2.3 New services, including browser extensions and meeting note-takers, need the AI Lead's approval first.
- 2.4 Web search and third-party app connections inside an AI service are switched on only after the AI Lead has reviewed them.
3. What may never be entered into AI
- 3.1 Without exception: passwords, one-time codes and access keys.
- 3.2 Unless masked: NIK (national identity numbers), NPWP (tax numbers), passport numbers and bank account numbers.
- 3.3 Unless the responsible partner has approved it in writing: health data and medical records, children's data, criminal records and detailed personal financial data.
- 3.4 Unless the partner and the client have approved it: material covered by professional confidentiality or privilege, such as litigation strategy, internal memos on a client's position and confidential client correspondence.
- 3.5 If in doubt, do not send it. Ask the AI Lead first.
4. Clients
- 4.1 Engagement letters state that the firm uses approved AI services under this policy.
- 4.2 Where a client prohibits or limits AI use, this is recorded in the client's folder and followed by the whole team.
- 4.3 Children's data is processed with AI only where a parent's or guardian's consent is in place, as required by Article 25 of the PDP Law.
5. Human review
- 5.1 AI output is a draft. Every document that leaves the firm is reviewed and approved by the professional whose name is on it.
- 5.2 AI is not used to make a final decision with legal effect on a client or anyone else without human judgement.
- 5.3 Responsibility for the content lies with the reviewer, not the AI.
6. Citations
- 6.1 Every article, regulation, judgment, standard or tax rate an AI mentions must be checked against the official source before it is used.
- 6.2 A citation that cannot be found in the official source is treated as wrong and removed.
- 6.3 AI output may not be cited as a source.
7. Record-keeping
- 7.1 AI use on client documents is recorded: who, which tool, which document, why and when. An automatic system record is preferred to a manual log.
- 7.2 Records are kept for [period, for example the same as matter files].
- 7.3 Significant drafts produced with AI are saved to the client's folder, not left only in a chat history.
8. Incident reporting
- 8.1 If data barred under section 3 is sent to an AI, or a firm AI account may have been used by someone else, report it to the AI Lead the same day.
- 8.2 Nobody is penalised for promptly reporting their own mistake.
- 8.3 The AI Lead decides whether the incident is a failure of personal data protection that must be notified within 3 x 24 hours under Article 46 of the PDP Law.
9. Training
- 9.1 Everyone is introduced to this policy before receiving a firm AI account, and signs to confirm they have read and understood it.
- 9.2 A short refresher is held every [six] months, or whenever the list of tools changes.
10. Breaches
- 10.1 Breaches are handled under the firm's disciplinary rules. A self-reported mistake is treated differently from a concealed one.
11. Review
- 11.1 This policy is reviewed no later than [date] and every six months after that, or sooner if new regulation appears or an AI provider changes its terms.
Approved by [managing partner], [date].
Before you fill in the list in section 2
The biggest difference is the account type. According to each provider's official pages when this guide was reviewed:
- OpenAI states that data from ChatGPT Business, Enterprise, Edu and the API is not used to train its models by default.
- Anthropic states that it does not train on inputs or outputs from its commercial products by default, and that it acts as processor for Team and Enterprise plans.
- Microsoft states that Copilot used by organisations is covered by its Data Protection Addendum with Microsoft as processor, and that prompts and responses are not used to train foundation models. One caveat: web search queries Copilot sends to Bing are handled separately, with Microsoft acting as an independent controller. That is why clause 2.4 exists.
A business plan settles the training question, not where data is processed. If that is outside Indonesia, the transfer conditions in Article 56 of the PDP Law apply. Terms change often, so check again before you buy.
Rolling it out in two weeks
This suits a firm of 5 to 50 people; a larger one may need a lead in each team.
Week one: decide
- Day 1. Appoint the AI Lead, usually the managing partner or office manager.
- Days 1–2. Run a short anonymous survey: which AI tools, for what work, on whose account. The aim is to map usage, not to find culprits.
- Day 3. Choose one or two tools and buy business seats for those who need them.
- Day 4. Fill in the template and allow the partners one round of comments.
- Day 5. Partners approve it. Update your engagement letter template to match section 4.
Week two: run it
- Day 6. Set up firm accounts, with web search and app connections off until reviewed.
- Day 7. Hold a 60-minute session: the policy, real examples of what is and is not allowed, how to mask a NIK and how to report.
- Day 8. Everyone signs. Drafts in personal accounts move to firm folders, and the personal history is deleted.
- Day 9. Drill the reporting route: someone "accidentally" pastes a NIK. Time how long before the AI Lead hears.
- Day 10. Diary the first review and start checking usage records weekly.
A short checklist
- An AI Lead appointed in writing.
- A list of approved tools, all on business plans paid for by the firm.
- The data rules in section 3 explained with real examples from your own work.
- Engagement letters that mention AI use.
- Every outgoing document reviewed by the person whose name is on it.
- Every legal or tax citation checked against the official source.
- AI use on client documents recorded.
- A tested reporting route, and people who know about the 3 x 24 hour deadline.
- Everyone trained and signed.
- A review date in the calendar.
Tools that help the policy work
Sections 3 and 7 are the hardest to run by hand: masking every NIK is tedious, and manual logs are soon abandoned. In folders.id you choose which folders each AI connection may read, every search, document read and refused request is recorded in the activity log, and NIK, NPWP, passport and bank account numbers are masked before they reach any AI. The policy and the training are still yours; a tool only makes them easier to follow.