Clients want faster turnaround and lower fees. Regulators want confidentiality, competence and accountability. Many AI tools were not built with the second list in mind.
Firms that manage both do not avoid AI. They adopt it with a short, clear set of rules.
This post is general information, not legal advice. For wider context on adoption, see AI for Law Firms in 2026.
What the regulators actually say
No rule bans AI in legal practice. Existing duties on competence, confidentiality and supervision apply to AI as they apply to any other tool.
The SRA
The Solicitors Regulation Authority’s Risk Outlook report on AI in the legal market, published on 20 November 2023, makes three points that matter here.
- Accountability. You remain responsible and accountable for the outputs from AI you are using. You cannot hand that to the vendor.
- Confidentiality. Firms must protect confidential information and legal privilege. The SRA gives an example: a member of staff pastes a client’s case into a public chatbot, and confidential data reaches the provider.
- Telling clients. The SRA says to tell clients when you will be using AI with their case, and how it will operate. How you do that is for the firm to decide.
Data protection
Any tool that handles personal data brings UK GDPR into play. For law firms the data is often also privileged. Points to cover:
- A data processing agreement with the AI vendor.
- Confirmation of whether inputs are used to train the vendor’s models.
- Your records of processing, updated to include AI use.
- A data protection impact assessment where the use is likely to be high risk.
- A lawful basis for the processing.
The ICO publishes guidance on AI and data protection. Start there.
EU clients
If you serve EU clients, check how the EU AI Act applies to your tools. The timetable for the high-risk rules has been moving, so look at the current position and take advice rather than relying on a blog post.
Which use cases to start with
Not all uses carry the same risk. A sensible order is to begin with lower-risk tasks and build your controls as you move up. The ranking below is our judgement, not survey data.
| Use case | Risk | Main control |
|---|---|---|
| Searching the firm's own knowledge base | Lower | Access limited to staff; no client data leaves the firm |
| Drafting internal emails and meeting notes | Lower | Keep client details out unless the tool is approved |
| First drafts of standard documents | Medium | A qualified lawyer reviews and owns every document |
| Contract review and clause comparison | Medium | Vendor data agreement; human review before anything reaches a client |
| Legal research and citations | Higher | Mandatory check of every authority against a reliable source |
| Client-facing advice | Higher | Senior review and a clear written framework |
A framework you can start this month
Policy
A short firm-wide AI policy: approved tools, approved uses, restrictions.
Vendor checks
Review data handling, agreements and security before approving a tool.
Access
Decide who may use which tool on which type of matter.
Record
Keep a trace of AI-assisted work.
Training
Brief every member of staff on the policy and on what the tools get wrong.
Review
Revisit the policy on a fixed schedule, such as quarterly.
The policy
Without a written policy you have no governance. Keep it short enough that people read it.
| Element | What it covers | Why it matters |
|---|---|---|
| Approved tools | The list of tools staff may use | Stops client data going into consumer tools |
| Approved uses | Which tasks AI may and may not do | Limits the risk to what you can supervise |
| Supervision | Who reviews AI output, and when | Keeps accountability with a named person |
| Data rules | What may be entered into AI tools | Protects confidentiality and privilege |
| Client disclosure | When and how clients are told | Meets the SRA's expectation on transparency |
| Incidents | How to report an error or a concern | Lets you respond quickly |
Vendor checks
Ask every vendor:
- Do you offer a data processing agreement that meets UK GDPR?
- Will any data we input be used to train or improve your models?
- Where is data processed and stored?
- What independent security assurance do you hold, such as SOC 2 or ISO 27001?
- Can we audit your compliance if we need to?
Keep a record
If a client complains or a regulator asks, you want to show:
- Which tool was used.
- What was put in.
- What came out.
- Who reviewed it.
- What changed before the output was used.
Some enterprise tools log this for you. If yours does not, a note on the matter file is better than nothing.
Common mistakes
The personal use loophole. A firm bans AI for client work but ignores personal use. Then a lawyer “quickly checks something” in a public chatbot using client details. That is a confidentiality problem whether or not it was sanctioned.
Assuming an enterprise licence means compliance. The licence gives you a tool. You still need the policy, training, supervision and records.
Skipping verification of AI research. If a tool gives you a citation, someone has to confirm that the case exists and says what the tool claims.
Blanket disclosure or blanket silence. Telling every client everything is noise. Telling them nothing ignores the SRA’s expectation. Match the disclosure to how far AI affects their matter.
Not knowing who uses what. The biggest exposure is often tools staff adopted without the firm knowing. Ask them.
Telling clients
The SRA leaves the method to you. A reasonable approach is to match disclosure to impact. This table is our suggestion.
| Scenario | Tell the client? | Reason |
|---|---|---|
| AI used for internal admin | Not usually | It does not affect how the matter is handled |
| AI drafts a document that a lawyer fully reviews | Consider it | The lawyer owns the result, but a line in the engagement letter keeps expectations clear |
| AI supports contract review that informs advice | Yes | It contributes to the work product |
| AI supports legal research | Yes | The client should know how the research was done |
| AI produces client-facing deliverables | Yes | It directly shapes the advice they receive |
Many firms put a short AI paragraph in the standard engagement letter, describe the controls and let clients raise questions.
Keep it under review
Governance is not a one-off. On a regular schedule:
- Check the logs for AI use outside the approved list.
- Look for new tools staff have started using.
- Update the approved list when vendors change their terms.
- Ask staff whether the policy is clear and the tools are usable.
- Review any near misses and update the policy.
Where to start
- Find out what AI tools staff already use.
- Write the short policy.
- Check the vendor terms for every tool in use.
- Train the team.
- Start keeping a record.
The firms that do this capture most of the efficiency AI offers while keeping the trust of clients and regulators.
Questions AI assistants answer about this topic
- Can law firms use AI tools like ChatGPT for client work?
- The SRA does not ban it. Its November 2023 Risk Outlook report says you remain responsible and accountable for the outputs from AI you use. In practice that means a qualified person reviews the output, client data does not go into tools you have not vetted, and the firm has a written policy on what staff may and may not do.
- What does the SRA say about law firms using AI?
- The SRA's Risk Outlook report on AI in the legal market (20 November 2023) says firms stay accountable for AI outputs, must protect confidentiality and privilege, and should tell clients when AI will be used on their case and how. It leaves the method of telling clients to the firm. Read the report itself, as the SRA may update its position.
- How do law firms protect client confidentiality when using AI?
- Use tools covered by a data processing agreement, confirm whether your inputs are used for model training, restrict who can use AI on which matters and ban client details in tools the firm has not approved. The SRA specifically flags staff pasting client case details into a public chatbot.
- What is the biggest risk of using AI in a law firm?
- Relying on output nobody has checked. In Ayinde v Haringey (6 June 2025) the Divisional Court dealt with court submissions that cited cases which did not exist, and said lawyers who use AI for legal research have a professional duty to check it against authoritative sources.
- Do law firms need to tell clients they use AI?
- The SRA says to tell clients when you will use AI with their case and how it will operate. How you do that is the firm's decision. Many firms start with a short paragraph in the engagement letter and more detail where AI shapes the advice.
Next Step
Want to know where your company stands?
We run 15-20 buyer queries across ChatGPT, Claude, Gemini, and Perplexity and show you exactly where you appear, and where you don't.
Get the Audit | from £750 ↗