Generative AI is becoming increasingly embedded in legal practice. From reviewing lengthy documents and summarising case material to assisting with research, drafting correspondence and identifying information within large datasets, AI can offer considerable efficiencies to solicitors and law firms.

Yet the adoption of these technologies raises an important question: how can lawyers benefit from AI without compromising the confidentiality of their clients?

Confidentiality has always been central to the solicitor-client relationship. Clients must be able to provide their lawyers with sensitive information on the understanding that it will be handled appropriately and protected from unauthorised disclosure. The arrival of generative AI does not alter that professional obligation. Instead, it introduces another layer of risk which firms must understand and manage.

AI and the Changing Nature of Legal Work

Generative AI systems can produce new text, summaries, drafts and research outputs in response to a user’s instructions. Their apparent ability to understand questions and respond in natural language makes them particularly attractive within professional environments.

For lawyers, however, fluency should not be confused with reliability.

The SRA has warned that AI can generate fictitious cases, references and apparently factual assertions which may nevertheless have no basis in fact. It has identified both inaccurate AI-generated legal material and the entry of confidential client information into public AI systems as areas of concern.

This creates two distinct but connected professional risks. The first concerns accuracy: an AI system may produce material which appears authoritative but is wrong. The second concerns confidentiality: information supplied to an AI system may be processed, retained or otherwise handled outside the solicitor’s direct control.

Both require active human oversight.

The Confidentiality Problem

A solicitor might, for example, wish to upload a lengthy contract to an AI platform and ask it to identify unusual clauses, prepare a summary or compare provisions. From a productivity perspective, the attraction is obvious.

The professional question is rather different: what happens to the information once it has been uploaded?

The answer depends upon the particular AI product, its contractual terms, technical architecture, security arrangements, retention policies and configuration. The fact that a platform is paid for does not, in itself, establish that confidential client information is adequately protected.

The SRA specifically warns that both free and paid-for AI systems may lack the contractual and technical safeguards necessary to preserve client confidentiality. Firms are expected to understand what safeguards apply and whether those safeguards are appropriate to the nature and sensitivity of the information being processed.

This is particularly important because legal documents can contain considerably more sensitive information than a simple question typed into a chatbot. A solicitor may upload correspondence, contracts, witness material, financial information, personal data, litigation documents or other material which is subject to professional confidentiality and potentially legal professional privilege.

Once such information is placed into an external system, the solicitor needs to know precisely how it will be handled.

Legal Professional Privilege and AI

Confidentiality and legal professional privilege are closely related but distinct concepts, and the use of AI can create concerns in relation to both.

In UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the Upper Tribunal considered the implications of using public AI tools in case preparation. The Tribunal raised concerns about confidential case material being entered into an open-source AI system and the potential consequences for confidentiality and legal professional privilege.

The SRA has subsequently emphasised that confidential or client-sensitive information entered into AI systems may create significant risks to confidentiality, privilege and data protection compliance, particularly where the solicitor no longer has complete control over how the information is processed or used.

This is why firms should resist the temptation to regard AI as simply another piece of office software. The technology may be accessed through a familiar interface, but its underlying data-processing arrangements can be considerably more complicated.

AI Hallucinations and the Duty to the Court

Confidentiality is not the only professional concern.

Generative AI can produce what are commonly described as “hallucinations” — fabricated or inaccurate information presented in a convincing manner. In legal practice, the consequences can be particularly serious where an AI system invents a case, produces an incorrect citation or attributes a legal proposition to an authority which does not support it.

The SRA has identified cases in which AI-generated inaccuracies have found their way into legal work and court submissions. It has also stressed that solicitors remain accountable for their work irrespective of whether AI was involved in producing it.

The judgment in R (on the application of Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin) provides an important illustration. The case involved false authorities being placed before the court following the use of AI. The SRA notes that reliance upon an AI output does not provide an adequate defence: lawyers remain responsible for verifying the accuracy of material contained in legal submissions.

The lesson is straightforward. AI may assist with research, but it cannot take responsibility for the research.

Every authority, quotation, factual assertion and legal proposition must be checked against an authoritative source before it is relied upon.

Human Supervision Remains Essential

The growing use of AI also raises questions about supervision within law firms.

A junior member of staff may use an AI system to produce a first draft. Another employee may use AI to summarise a bundle. A solicitor may then review the final document before it reaches a client or the court.

That process does not necessarily remove the firm’s professional responsibilities.

The SRA’s Code of Conduct places obligations upon solicitors who supervise or manage others providing legal services. The regulator has made clear that solicitors remain accountable for work carried out through those whom they supervise and must ensure that work is effectively supervised.

This becomes particularly important where AI is used informally or without a firm’s knowledge. Unmanaged experimentation can result in staff entering confidential information into tools which have never been approved by the organisation.

For that reason, firms need to know how AI is actually being used, rather than simply assuming that employees will use it responsibly.

Establishing an AI Policy

A sensible starting point for a law firm is a clear internal AI policy.

Such a policy should establish which AI systems have been approved, what information can be entered into them and what categories of client information must never be uploaded without appropriate safeguards.

Firms should also consider:

  • how AI providers store and process information;
  • whether information is retained after a session;
  • whether customer data can be used for model training;
  • where data is stored;
  • what encryption and access controls are available;
  • whether third parties can access the information;
  • how long information is retained;
  • whether the firm’s insurers are aware of the proposed use of AI; and
  • what level of human review is required before AI-generated material is used.

The SRA expects firms to maintain effective governance structures, systems and controls for managing risks arising from AI.

Should Client Information Ever Be Entered Into AI?

There is no universal answer which applies to every AI system.

The important issue is whether the particular system has appropriate safeguards for the particular information being processed.

The SRA’s guidance indicates that client information should only be entered into AI systems where suitable contractual, technical and organisational safeguards are in place. Firms should satisfy themselves that client data remains in a secure environment, cannot be accessed by unauthorised third parties, is not used to train AI models except where expressly authorised and appropriate, and is not retained for longer than necessary.

In practice, this means that firms should carry out proper due diligence before approving an AI platform for legal work.

A public chatbot and a properly configured enterprise system should not automatically be treated as presenting identical risks.

Anonymisation Can Reduce Risk — But It Is Not a Complete Solution

One practical precaution is to remove identifying information wherever possible.

Instead of entering the name of an actual client, for example, a solicitor may be able to use terms such as “Client A”, “Company B” or “Party C”. Monetary figures and other identifying details may also be capable of being removed where they are unnecessary for the particular task.

However, anonymisation should not be regarded as a universal solution.

A document can contain enough contextual information to identify a client even when names have been removed. Firms therefore need to consider whether information is genuinely anonymised rather than simply stripped of obvious identifiers.

AI Should Assist Rather Than Replace Professional Judgement

The attraction of AI is understandable. Legal professionals spend significant amounts of time on work which is repetitive, document-heavy or administrative.

AI can potentially help with document review, summarisation, chronology preparation, initial drafting and other tasks. Used appropriately, it may allow lawyers to devote more time to matters requiring experience, judgement and strategic thinking.

The difficulty arises when efficiency begins to replace professional scrutiny.

An AI-generated document may look polished. It may use appropriate legal terminology. It may even contain apparently convincing citations. None of those characteristics establish that it is correct.

The SRA’s position is that AI does not diminish or transfer professional responsibility. Solicitors remain accountable for work and advice provided to clients regardless of whether AI has been used in its preparation.

The Future of AI in Legal Practice

It is unlikely that the answer to the risks presented by AI will be to prohibit lawyers from using the technology altogether. The more realistic approach is controlled, informed and proportionate adoption.

Firms will need to understand the systems they use, train their people, establish appropriate policies and continually reassess the risks as the technology develops.

There is also an important cultural issue. Lawyers must remain sufficiently sceptical of AI-generated material to question it rather than simply accept it because it sounds authoritative.

That principle is particularly important when dealing with courts. A solicitor’s professional obligations do not disappear because a piece of work was initially prepared by a machine.

Conclusion

Generative AI presents genuine opportunities for the legal profession, but its use introduces responsibilities which cannot simply be delegated to a technology provider.

Confidentiality remains a fundamental professional obligation. Client information must be protected, legal research must be verified and documents must receive appropriate human scrutiny before they are relied upon. Firms must also ensure that their governance and supervision arrangements keep pace with the way AI is actually being used.

The SRA’s message is clear: AI can support the delivery of legal services, but it does not assume the solicitor’s professional responsibilities. Appropriate human oversight, informed judgement and a proportionate, risk-based approach remain essential to compliance.

For law firms, therefore, the real challenge is not simply learning how to use artificial intelligence. It is learning how to use it without allowing speed and convenience to undermine confidentiality, accuracy, professional judgement or public confidence in the legal profession.

Leave a Reply

Trending

Discover more from Adviser Society

Subscribe now to keep reading and get access to the full archive.

Continue reading