What risks do solicitors firms face when using AI with client data, and how do you use it with confidence?
By Andrew Isaacs, CIMA Member in Practice ·
The three real risks are confidentiality leakage into public AI models, hallucinated outputs that get relied on without checking, and supervision gaps where staff use tools the firm has not approved. UK solicitors can adopt AI with confidence by using enterprise grade tools with zero data retention, documented governance under the COLP, and a rule that no raw client data ever touches a consumer chatbot.
Why this matters right now
The Solicitors Regulation Authority is not banning AI. It is watching how firms use it. In its risk outlook on AI in the legal market the SRA named three concerns it expects firms to manage. Confidentiality breaches when client data leaks into AI training sets. Competence failures from over reliance on outputs that nobody verified. Supervision gaps where junior staff use AI tools with no qualified oversight.
Further SRA material on generative AI and on AI use with client data has been signalled for 2026. The regulator has also now authorised an AI driven law firm under strict conditions covering confidentiality, conflicts, user approval at every stage, and a bar on the AI proposing case law. That authorisation tells you the direction of travel. AI in legal practice is an operational standard the SRA expects firms to meet, not a novelty to experiment with informally.
Industry survey work points the same way. The Clio Legal Trends reporting for 2026 puts AI tool use among legal professionals at around seventy nine per cent, with something close to forty four per cent of firms having no formal governance policy in place. That gap is where the regulatory risk sits.
The actual risks to client data
Five risks worth naming specifically. Each has a different mitigation.
- Client data used to train a public model. The free tier of most public chatbots, and the consumer subscription tiers too, may use your prompts as training data unless you have switched that off or signed the right agreement. A paragraph of a client's witness statement pasted into a consumer tool has in effect been disclosed to the provider. Once a model has trained on that text you cannot pull it back.
- Privilege loss. A United States court ruled in early 2026 that a set of documents generated through a consumer AI tool were not protected by attorney client privilege, and the judgment noted that enterprise grade tools with zero data retention could support a materially different analysis. The UK courts have not ruled on this directly. The logic still travels. If the tool uses your inputs for training, or retains them somewhere a third party could reach them, you have weakened the confidentiality that privilege depends on.
- Hallucinated outputs treated as fact. In Ayinde v London Borough of Haringey the court considered referring a barrister to the Bar Standards Board after fabricated case citations appeared in submissions. In a separate reported case a wasted costs order was made against a firm whose administrative staff had filed pleadings containing fictitious cases generated by AI. These are not edge cases. They are what happens when AI output reaches a court without a qualified solicitor verifying every citation.
- Shadow AI. When a firm bans AI outright, fee earners under pressure find workarounds on personal devices, and the firm loses all visibility of where client data is going. A blanket ban is usually worse than controlled adoption, because you still get the leakage and you no longer know about it.
- Supervision gaps. A junior lawyer running a contract through an AI tool without partner review is a regulatory problem even if the tool is enterprise grade. The SRA expects the Compliance Officer for Legal Practice to be responsible for AI governance in the same way as for any other new technology, which means the COLP is briefed before a tool goes into use.
What safe adoption actually looks like
Four layers. None of them are complex. They are just rarely all done at once.
Layer 1, the tool itself. Use enterprise or API access rather than a consumer account. Commercial terms of service mean your data is not used for training. Consumer terms, by default, mean it can be.
Layer 2, zero data retention. For the most sensitive matters, ask for a zero data retention arrangement, under which prompts and responses are not stored beyond the immediate processing window except where the law requires it. This normally sits on API and enterprise tiers and needs a signed agreement.
Layer 3, governance and policy. Classify use cases by sensitivity.
- Green. Internal drafting, marketing copy, research with no client specifics in it.
- Amber. Redacted client context, with review.
- Red. Raw client identifiable data into any public tool, case law work without human verification, and automated decisions affecting client outcomes.
Put that on one page, have the COLP sign it off, and review it every six months.
Layer 4, supervision and audit. Keep a register of which tools are approved, which matters use them, and who reviewed each assisted output. Audit it regularly. If a judge asks how AI generated citations reached a bundle, no one checked is not a defence.
What to check in an enterprise AI tool
The controls below are the ones that map onto what the SRA expects a firm to demonstrate. Claude is used as the worked example because it is the tool we see most often in firms, and because the tier distinctions are a useful illustration of a general point. The same questions apply to any vendor.
| Concern | Control | Tier required |
|---|---|---|
| Data not used for training | Commercial terms of service explicitly prohibit training on inputs | Claude for Work, Enterprise, API |
| Short retention | Seven day default on the API | API |
| Zero data retention | Prompts and responses not stored after processing | Enterprise, or API with a zero retention agreement |
| UK GDPR compliance | Data processing addendum available | All commercial tiers |
| Security certification | SOC 2 Type II | All commercial tiers |
| Regional processing | Available through major cloud platforms | Platform dependent |
| Audit logs | Immutable access logs | Enterprise |
| Admin controls | Single sign on, role based access, usage monitoring | Team, Enterprise |
Two things to flag. First, a paid consumer tier can sound like a business product without being one. A fifty person firm that equips its fee earners with personal paid subscriptions is still on consumer terms, and client data going through those accounts is by default eligible for training retention unless every user has manually opted out. Second, zero data retention does not override every feature. Some capabilities that depend on storing prompts, long term memory among them, are switched off under it. For a regulated firm that is the right trade.
What to do this week
Four steps, in order.
- Audit what is already in use. Ask every fee earner and support staff member what AI tools they use for client work, on which devices, and on which account type. You will find more than you expect. This is an inventory exercise, not a disciplinary one.
- Close the consumer tool gap. If anyone is using a free or personal paid tier with client data, stop it this week. Move them to an approved enterprise tier, or back to manual until you have one.
- Write the one page policy. Green, amber and red use cases. Name the approved tools. Name the COLP as accountable owner. Circulate it, have every fee earner confirm they have read it, and keep the record.
- Build the audit trail. Any assisted output that leaves the firm, especially anything going to court or to a client, needs a verification step by a qualified solicitor. Document it. A tick box on the matter management system is enough, provided it is actually used.
None of this needs a large budget. It needs a decision at partner level that AI governance is a real operational responsibility, and a compliance officer with the authority to enforce it.
Common questions
Is Claude safe for UK law firms? On the right tier, yes. On a commercial tier with appropriate settings, client data is not used for training, retention is short and a UK GDPR compliant data processing addendum is available. On consumer tiers it is not suitable for confidential client data without further configuration.
Does the SRA allow solicitors to use AI? Yes, provided the firm meets the existing regulatory framework. Principle 7 on acting in the best interests of each client applies, as does the confidentiality duty in the Code of Conduct and the requirements on compliance and business systems. Further SRA guidance on AI and client data has been signalled.
What is zero data retention and do we need it? It is an arrangement where prompts and responses are not stored after processing, except where the law requires it. Not every matter needs it. If you act for regulated clients or handle sensitive commercial data, it is worth agreeing with your provider.
Who is accountable for AI governance? The Compliance Officer for Legal Practice. Brief the COLP before a tool is adopted, not after a complaint arises.
Do we need to tell clients we are using AI? The position is still developing. Good practice is to update engagement letters to say that the firm uses AI tools to support efficiency while keeping human oversight and confidentiality intact. The ICO has emphasised transparency about how personal data is processed. Staying silent when AI has materially shaped advice is a risk not worth taking.
What about hallucinations in legal research? Treat any AI generated case citation, statutory reference or authority as unverified until a qualified solicitor has checked it against the primary source. That is the single most important rule in this whole article.
Is a firm wide ban safer? Usually not. Bans push usage underground onto personal devices and consumer accounts, and you lose sight of what is happening with client data. Controlled adoption gives you the efficiency and the regulatory cover.
How we help
We give solicitors firms with turnover between £500k and £5m a finance function that enables the business rather than just recording it, and that the firm keeps control of. Qualified people do the thinking and sign every output, whatever tooling sits underneath.
If you run a firm and want to talk through what good finance support looks like when AI is part of the toolkit rather than the point of it, we should talk. We work with firms across Surrey, Kent and the wider South East.
Andrew Isaacs is a CIMA Member in Practice and Practising Certificate Holder, and the founder of AI Finance Partners, the outsourced finance function for professional services firms turning over £500k to £5m across the South East. Legal cashiering is not part of what we do.