How to Draft an AI Governance Policy for New York Law Firms Under NYC Local Law 144 and the SHIELD Act
NYC Local Law 144 requires New York City employers using automated employment decision tools to conduct an annual bias audit and provide notices before use. For New York law firms, that obligation intersects with the SHIELD Act’s data security requirements and broader professional responsibility duties when AI touches applicant, employee, client, or matter data. This article explains how to draft an AI governance policy tailored to New York law firms, with practical clauses, controls, and implementation steps.
Why New York law firms need an AI governance policy now
New York law firms are adopting AI across recruiting, HR, marketing, e-discovery, knowledge management, billing review, and client-facing workflows. The risk profile is different from many industries because a firm holds sensitive personal data (applicants, employees, vendors) and highly confidential client information, often subject to privilege and contractual security obligations.
A written AI governance policy is the control document that ties together: (1) when the firm may use AI; (2) who can approve, buy, and configure tools; (3) how the firm tests for bias and accuracy; (4) what data can be input; (5) what security and retention rules apply; and (6) how the firm documents compliance. In New York City, that governance must explicitly address NYC Local Law 144 when AI is used in employment decisions, and statewide it must align with the SHIELD Act’s data security program requirements.
Key legal frameworks to map into your policy
NYC Local Law 144 (Automated Employment Decision Tools)
NYC Local Law 144 regulates the use of “automated employment decision tools” (AEDTs) by employers and employment agencies in New York City. In practical terms, if a law firm uses a tool that substantially assists in making employment decisions—such as screening resumes, scoring applicants, ranking candidates, or making promotion decisions—it may fall within the AEDT definition.
Your policy should assume Local Law 144 is triggered whenever a system produces a score, classification, recommendation, or ranking that is relied on to make hiring or promotion decisions for roles in NYC, unless counsel determines a clear exemption applies. The compliance backbone generally includes:
• Annual independent bias audit of the AEDT before use.
• Candidate/employee notices regarding AEDT use and how individuals may request information.
• Public posting of bias audit summaries and distribution date (commonly on a website page accessible to applicants).
• Recordkeeping sufficient to demonstrate what tools were used, when, and under what audit/notice posture.
New York SHIELD Act (data security safeguards)
The SHIELD Act expanded New York’s data breach notification law and, critically for governance, requires businesses that own or license “private information” of New York residents to implement “reasonable safeguards” to protect the security, confidentiality, and integrity of that information. For law firms, this typically includes applicant and employee data (e.g., Social Security numbers, driver’s license numbers), financial account data, and certain account credentials.
Even when a firm is already operating a written information security program, AI tools change the data-flow. A governance policy must address whether AI vendors receive private information, whether data is used for training, where data is stored, and which teams can approve transfers.
Professional responsibility and confidentiality duties
Independent of employment and privacy statutes, law firms must manage confidentiality and competence obligations when using technology. An AI governance policy should expressly confirm that confidential client information may not be input into public or unapproved AI systems, and that lawyers remain responsible for supervising AI outputs used in legal work product.
Define the scope: what your AI governance policy covers
Start with clear definitions, because Local Law 144 compliance depends on how tools are described and used. Include definitions for:
“Artificial intelligence tool” (broad: machine learning, generative AI, statistical models, vendor platforms with AI features).
“AEDT” (narrow: AI that substantially assists in employment decisions in NYC).
“High-risk use” (employment decisions; access to private information; client confidential data; automated communications to clients; legal research or drafting that could be filed).
“Private information” (track SHIELD Act categories and any firm-specific additions like passport numbers or background check data).
“Sensitive client information” (client secrets, privileged communications, litigation strategy, deal terms, nonpublic client data).
The scope section should state the policy applies to all personnel (partners, associates, staff, contractors) and all AI tools used on firm devices, firm accounts, or to process firm data—even if accessed from personal devices.
Governance structure: roles, approvals, and accountability
Local Law 144 compliance can fail because nobody “owns” the AEDT decision. A New York law firm policy should name specific roles and assign decision rights.
Suggested roles
AI Governance Committee (cross-functional: HR, General Counsel/Risk, IT/Security, Privacy, DEI, and a practice leader). Owns policy updates, tool approvals, and exceptions.
AEDT Owner (HR) for each employment tool. Responsible for notices, coordinating audits, documenting configurations, and ensuring the tool is not used outside approved parameters.
Information Security Officer responsible for SHIELD-aligned safeguards, vendor security review, and incident response integration.
Procurement/Vendor Manager ensures contracts include AI and data protection clauses (see below).
Practice/Client Data Steward for any tool that touches client/matter data, ensuring confidentiality controls and client contract requirements are met.
Approval workflow
Build a simple but enforceable intake and approval process:
1) Intake questionnaire: What is the tool? What decisions does it influence? Does it score/rank applicants? What data fields are ingested? Where are users located (NYC)?
2) Risk tiering: High risk (AEDT or private/client data) vs. standard risk (no sensitive data, no employment decisions).
3) Legal + security review: Local Law 144 applicability determination, SHIELD safeguards check, ethics/confidentiality check.
4) Configuration controls: Turn off vendor data retention/training where possible; restrict access; define permitted inputs.
5) Final written approval: Tool added to an AI registry with an owner, renewal date, and audit cadence.
Local Law 144 compliance clauses to include
1) AEDT identification and use limitations
Your policy should prohibit “shadow AEDTs”—tools used informally by recruiters or partners. Include language such as:
Policy rule: “No AI tool may be used to screen, rank, recommend, or otherwise substantially assist employment decisions for NYC roles unless the tool is listed in the Firm’s AEDT Registry and is covered by a current bias audit and required notices.”
Also address internal mobility and promotion decisions, which can be overlooked.
2) Bias audit management (annual, independent)
Operationalize the annual audit requirement by defining:
• Independence: the auditor must be an external party or otherwise meet the independence criteria your counsel recommends.
• Audit inputs: datasets used, protected categories analyzed, selection rates and impact ratios, and how the tool’s output is used in decisions.
• Change management: if the vendor updates the model, scoring rubric, or features, require an impact review and consider whether an updated audit is needed before continued use.
• Documentation: store audit reports, configurations, and the precise “distribution date” required for public posting.
3) Notice delivery and applicant communications
Build a notice protocol into your governance policy so HR is not improvising. At minimum, the policy should require:
• Pre-use notice to candidates/employees that an AEDT will be used.
• Instructions on how to request an alternative selection process or accommodation (coordinate with employment counsel on how to frame this).
• Process transparency on job postings or career pages directing individuals to the firm’s AEDT disclosure page.
Example: If the firm uses a resume-screening platform that ranks applicants, the policy should require that the job posting links to a page stating the tool category, the bias audit summary, and a contact method for inquiries.
SHIELD Act alignment: “reasonable safeguards” for AI tools
The SHIELD Act does not mandate a single security framework, but it expects administrative, technical, and physical safeguards appropriate to the size and complexity of the business and the sensitivity of the data. Your AI governance policy should map directly to those safeguard categories.
Administrative safeguards
• Data inventory and classification for AI use cases (applicant data, background checks, payroll-related identifiers).
• Access controls (role-based permissions; HR-only for AEDT admin panels; least privilege).
• Training (annual training plus point-of-use guidance: “Do not paste SSNs into chat tools.”)
• Vendor management requiring due diligence and contractual protections (below).
Technical safeguards
• MFA and SSO for AI tools, especially HR platforms and any tool containing private information.
• Encryption in transit and at rest where available.
• Logging and monitoring for access to private information and exports.
• Data loss prevention (DLP) rules to reduce copying private information into unapproved AI.
Physical safeguards
For most firms, this is handled via existing facility controls and secure device policies. Still, your AI policy should cross-reference device management and secure disposal when AI datasets are stored locally or exported for audits.





















