The National Association of Criminal Defense Lawyers this week told its members that adopting AI isn’t optional anymore—it’s an ethical imperative. But the association’s new report, titled Parity in Practice: The Defender’s Duty to Ethically Use AI, draws a hard line: defense lawyers must not touch public AI tools with client data, and any enterprise solution they pick—including Microsoft Copilot—needs a formal, written governance policy before a single prompt gets written.

The report, authored by St. Mary’s University School of Law assistant professor Mason Clark, lands as prosecutors and law-enforcement agencies increasingly use AI for investigations, charging decisions, and evidence review. For overburdened public defender offices and smaller Windows-centric criminal-defense firms, the message is both an opportunity and a warning. You can use AI to level the playing field, but only if you treat it as a regulated instrument, not a productivity gadget.

Consumer AI tools are off the table—here’s why

The report explicitly calls out commercial generative-AI services—OpenAI’s ChatGPT, Google Gemini, and Anthropic Claude—as unacceptable for case-related work when lawyers use consumer-facing accounts or don’t understand data handling. The risk isn’t theoretical: upload a police report to a free chatbot, and you may lose attorney-client privilege, violate confidentiality rules, or expose sensitive information to model training pipelines that you don’t control.

For Windows-based firms, that warning hits close to home. Many attorneys already use these tools informally on personal devices. The NACDL report makes clear that such shadow IT is a serious professional liability. Instead, the report steers defenders toward enterprise AI offerings—including Microsoft Copilot obtained through an organizational Microsoft 365 license, as well as legal-specific platforms like Harvey and Thomson Reuters CoCounsel.

But the shift to “enterprise” doesn’t automatically solve the problem. As the report notes, AI platforms carry materially different policies and data paths depending on how they’re licensed and configured.

Microsoft Copilot’s identity crisis: Which one are you even using?

The word “Copilot” covers a lot of ground. There’s the consumer version that’s free with a Microsoft account, the Copilot baked into the Edge browser, the Microsoft 365 Copilot that integrates with Word and Outlook under a commercial license, and a growing family of domain-specific Copilots for security, sales, and more. Each has its own data-use terms, tenant boundaries, and retention practices.

For an IT administrator supporting a criminal-defense practice, that fragmentation is the first governance hurdle. If a public defender pastes a discovery document into a consumer Copilot session, the data isn’t protected by the firm’s Microsoft 365 tenant safeguards. Even within a properly licensed tenant, administrators must confirm that Copilot for Microsoft 365 is activated only for authorized users, that confidential material is classified and restricted from being fed into prompts, and that logging and eDiscovery controls are in place to track what staff are doing.

The NACDL report doesn’t prescribe specific Copilot settings, but its model AI-use policy makes the implications clear. Firms need to document which Copilot experiences are approved, who gets access, and what data can and cannot leave the firm’s existing legal systems. Get that wrong, and what looks like an innocent productivity shortcut becomes a breach waiting to happen.

The practical to-do list for law firm IT admins

For Windows-centric offices that already run on Microsoft 365, the report’s recommendations translate into a concrete checklist. Here’s what IT teams should tackle now:

  • Provision AI through managed organizational accounts. No one in the firm should use a personal Microsoft account, Google account, or free-tier AI service for client matters. All approved tools should be tied to the firm’s identity provider, with conditional access policies and multi-factor authentication enforced.
  • Classify and label sensitive data before it touches an AI workflow. Microsoft Purview sensitivity labels can automatically restrict documents from being shared with external services. If a lawyer tries to feed a labeled transcript into an unapproved AI tool, the system should block it or flag it for review.
  • Maintain an audit trail for AI-generated output. Any AI output used in research, discovery summaries, or drafted filings must have a named review owner and a documented approval step. That creates accountability and aligns with the report’s emphasis that attorneys—not machines—are answerable for court submissions.
  • Train staff on prompt hygiene and model limitations. Attorneys and paralegals need to understand that AI can invent facts, misstate holdings, and sound authoritative while being completely wrong. The report stresses that overreliance erodes core lawyering skills. Training should cover how to craft prompts that minimize hallucination risk, how to spot bogus citations, and why every factual assertion must be verified against primary sources.

The verification obligation: You can’t blame the bot

One of the report’s sharpest points is that verification isn’t a feature request—it’s a legal duty. Even enterprise AI tools that operate within a secure tenant can produce plausible-sounding errors. The report recounts well-publicized incidents where lawyers submitted AI-generated briefs containing fictitious case law, and it warns that criminal-defense work carries even higher stakes: a hallucinated precedent can cost someone their liberty.

The proposed model policy therefore requires mandatory human review of all AI-generated material before it’s used in any legal context. For a firm’s IT leadership, that means building review workflows into the tools themselves. For example, if Microsoft 365 Copilot drafts a motion, the document management system should track that it was AI-assisted, record who reviewed it, and lock it from filing until that review is complete.

This isn’t about slowing down the practice of law—it’s about ensuring that the technology actually helps. The report makes clear that responsible AI adoption can help overworked defenders analyze massive discovery sets, spot patterns, and prepare cases more efficiently. But the productivity gains are only realized when the guardrails are in place.

What the NACDL report means for the next 12 months

The report recommends that defense organizations create and implement formal AI-use policies within the next year. For firms that already started rolling out Microsoft 365 Copilot or piloting legal-specific AI tools, that timeline turns governance from a long-term aspiration into an immediate operational priority.

Over the coming months, expect to see:

  • More detailed ethics opinions from state bar associations, which may impose stricter rules on AI use than the NACDL’s baseline.
  • Vendor accountability pressure. Law firms will increasingly demand that Microsoft and other AI providers offer transparent documentation about how data is handled, logged, and retained within their enterprise tenants.
  • An uptick in discovery disputes where the use of AI for evidence review becomes a point of contention, making it essential for defense teams to have a documented, defensible AI workflow.

For Windows-focused IT teams in the criminal-defense world, the takeaway is straightforward: the tools exist, the licenses can be bought, but the risk of deploying them without a policy now has a name and a formal report behind it. The NACDL just gave every defender’s office a blueprint. Ignoring it isn’t just poor IT practice—it’s an ethical gamble.