Most government legal departments now have an AI use policy in place or in progress — however, some are leaving the door open to risk that a little change in structure could close
Key insights:
- Adoption has outpaced governance — Government legal departments are using AI faster than ever, but policy and oversight are still catching up with the technology.
- An unwritten policy is a policy of risk — Without clear guardrails, staff will use AI inconsistently, and sometimes unsafely, at their own discretion.
- Governance is also a retention strategy — Structured training and clear standards can help government legal departments keep the talent they've worked so hard to attract.
The numbers tell the story — nearly two-thirds of government legal professionals surveyed say their agencies either have an AI use policy in place or are actively developing one, with adoption running notably higher among federal and state agencies compared to county and city offices, according to the Thomson Reuters Institute's 2026 Government Legal Department Report.
That's real progress, especially compared to past adoption levels. It still means, hoever, that roughly 1-in-5 respondents say their agency has no AI policy at all. And every day without one is a day that legal staff may be using AI tools with no guardrails, no documentation, and no consistent standard for what's acceptable.
This isn't a government-only problem, either. The Thomson Reuters2026 Future of Professionals Report found that roughly one-third of professionals across legal, corporate, and tax industries admit to using AI tools that their organization hasn't sanctioned, a worrisome practice sometimes called shadow AI, which can quietly expose organizations to data, quality, and compliance risks they never agreed to take on.
Critically, government legal departments carry an added burden here because the data they handle is often more sensitive, the stakes of a bad output are often higher, and the public accountability is unlike anything in the private sector.
Why the gap matters now
The Government Legal Department Report is clear about what's at stake when AI governance lags behind adoption: Those agencies without an AI policy leave the door open to confidential information getting exposed, to staff trusting AI output that was never checked, and to different teams handling the same kind of matter in inconsistent ways.
The lesson, as the report explains, isn't to slow down. It's to build a process of governance that lets agencies move fast responsibly, protecting the people they serve while actually gaining the productivity that AI promises.
5 steps toward a governance framework that actually works
Here's what building that kind of governance looks like in practice:
1. Define the problem before exploring the solution
It's tempting to start with the tool — such as a new AI product or a flashy demo — and work backward to a use case; but that's how departments end up with mismatched technology and frustrated staff. Start instead by naming the actual bottleneck: Is document review taking too long? Is inconsistent research quality across a large team the problem? Can we be on-boarding new attorneys faster? A clearly defined problem makes every decision after it easier, from vendor selection to training design.
2. Work with AI solutions that are built for the problem you've named
Not every AI tool is designed with government legal work in mind, and general-purpose tools often lack the guardrails, citation standards, or data handling needed for stringent legal and regulatory environments. Government legal departments get the best results when they match the tool to the specific workflow — research, drafting, case management, etc. — rather than adopting a broad platform and hoping it fits.
3. Properly enact know-your-vendor standards
Government agencies already apply rigorous vetting to outside counsel and contractors, but AI vendors don't often receive the same scrutiny. Departments need to understand how a vendor trains its AI models, where its data is stored and for how long, who has access to it, and what happens in the event of a breach or subpoena. Know-your-vendor practices aren't a one-time checkbox; rather, it's an ongoing relationship that should be revisited as vendors update their products and practices.
4. Set appropriate security standards
Security standards should cover data classification, output verification requirements, and access controls, with clear consequences for noncompliance. This is also where legal departments can partner with IT and records teams that may be already managing similar risks elsewhere in the agency.
5. Implement proper training standards
A policy that no one understands isn't a governance framework, it's a document. Training should be role-specific, recurring, and tied to real workflows rather than a single on-boarding session. It should also be treated as a retention tool, because professionals, especially those early in their careers, increasingly expect their employer to help them build AI fluency. The government legal departments that deliver on that expectation are better positioned to keep their top talent in a competitive hiring market.
Why this is about more than a policy document
Building AI governance isn't simply about avoiding risk. It's about giving staff the confidence to use powerful tools well and giving the public confidence that the agency serving them is doing so carefully.
For example, the U.S. Patent and Trademark Office (USPTO) offers a good working example of what disciplined AI adoption can look like. The agency rolled out a suite of AI tools aimed at specific bottlenecks in its process, including a new trademark classification tool that automates portions of application pre-processing that once was measured in months. The USPTO also created an internal generative AI assistant, known as SCOUT, for use by its examining attorneys only after governance guardrails were established. The agency is also developing chatbot capabilities that are intended to speed up both internal research and communication with applicants. None of this happened by accident; rather, it followed the same sequence outlined above — problem first, then a matched tool, then guardrails, then rollout.
Today, AI is no longer changing on an annual cycle, or even a monthly one. It's changing weekly, sometimes daily. Government legal departments have a well-earned reputation for caution, and that caution still has its place, but it can't extend to training and governance.
Those government agencies that treat AI literacy as core infrastructure, not an occasional workshop, will be the ones that are best able to keep pace and serve the public as they were designed to do.

