What Fee Earners Need to Know Before Putting Anything
into an AI Tool
Whether an AI tool is safe for client work comes down to one distinction – and getting it wrong can waive privilege for good.
Is it safe to put client information into an AI tool?
That responsibility point is the one the regulator keeps returning to. The SRA’s position is that whatever the technology, the lawyer remains the person making the decision and carrying professional responsibility for it and has to be able to explain and justify their own work. Governance is how a firm makes that real rather than aspirational.
You might know that consumer ChatGPT lets you switch model training off in its settings and assume that makes it safe for client work. It doesn’t.
Turning training off is a single toggle that can be reset or changed, but more to the point, your information has still gone to a third party you have no agreement with, still sits on their systems, and is still outside the firm’s control. The training setting deals with one symptom. It doesn’t put the information back inside the building. So, the safe line isn’t “a tool with training switched off”, it’s “a tool the firm has under contract.”
Why confidentiality bites earlier than you'd think
The risk isn't the document you upload. It's the prompt you dash off without thinking.
The line the courts have now drawn
In Munir v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the Upper Tribunal held that uploading confidential documents into an open-source AI tool such as ChatGPT is to place that information in the public domain, breaching client confidentiality and waiving legal professional privilege. The Tribunal added that such conduct might itself warrant referral to the SRA and should in any event be reported to the Information Commissioner’s Office.
Once privilege is waived, it's gone. There is no putting it back.
The consequence is the part to hold onto. Once privilege is waived, it’s lost. It cannot be recovered, and there’s no mechanism to claw it back once the material has entered the public domain. This isn’t a fine you pay and move on from. The protection is simply gone, for that material, permanently.
None of this, however, means AI is off-limits. The same courts have been clear that, used properly, these tools are a genuine step forward. It means the choice of which tool, for which information, is now a decision with real weight behind it.
How to tell which kind of tool you're using
SIGN UP
If you signed up for it yourself, it's free or on a personal subscription, and there's no arrangement between your firm and the provider behind it, treat it as open, and off-limits for client information. Consumer chatbots are the obvious case.
ACCESS
If the firm gave you access to it, there's an IT or procurement process behind it, and it sits under a business or enterprise agreement, then it's likely closed, and safe to use as intended.
UNCERTAINTY
If you're not certain which you're dealing with, that uncertainty is itself the answer: don't put client information in until someone can confirm it. The firm's list of approved tools exists precisely so you're not making that call alone under deadline.
A few habits that cover the rest
Before you send a prompt to anything you’re not certain about, read it back as though it were going to be published – because with an open tool, it effectively is. Names, figures, positions and the shape of a matter all count, not just the documents you attach.
And check what comes back. AI tools can produce citations, authorities and facts that look entirely right and aren’t, so verifying against the original source before you rely on it is your responsibility, not the tool’s.
One more, easily forgotten in the confidentiality conversation: the SRA expects firms to be clear with clients about where AI is used on their matter. How that’s handled is a firm decision, so it’s worth a word with whoever owns it if you’re unsure of the position.
Using AI safely as an individual is one half of the picture.
The other is the firm having the governance around it – approved tools, clear policies, the controls that mean you’re not left guessing at your desk in the first place. If you’re looking at that wider side, our guide to AI governance for law firms covers what a firm needs in place before any tool goes live.
We’ve put them into a single guide built for exactly that – the decision flowchart, a few worked examples, and the what-to-do-if steps – so the safe choice is the easy one, even on a deadline.