Laptops and screens: client confidentiality and privilege when using AI

Insights

The SRA on AI, part two: confidentiality and privilege

Part one dealt with supervision, which is where most of the coverage of the SRA's warning notice will settle, because false citations make headlines and there are judgments to point at. The other half of the notice will do more damage in practice, and it will do it quietly.

Picture what actually happens in a firm like ours. A suspension letter arrives for a sponsor client, twenty pages of it, setting out what the compliance officer found on the visit and what the Home Office proposes to do about it. Twenty sponsored workers are downstream of the answer and the client is already on the phone. The fee earner pastes the letter into a chatbot and asks it to pull out the allegations so they can start the response. It works. It saves an hour. Nobody sees it happen, no judge is embarrassed in open court, and there is a fair chance nobody in the firm ever finds out.

I have felt the pull of that myself, which is the only reason I can describe it so precisely. The tool is open, the deadline is real, and the thing it does takes four seconds.

The notice cites the Upper Tribunal's observation that to put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place that information on the internet in the public domain. That is the sentence I would put in front of every fee earner in the country. It is not a warning about a risk that might crystallise later. It is a description of what has already happened at the moment the paste completes.

What the notice requires

Client data should enter an AI system only where appropriate contractual, technical and organisational safeguards are in place. Beyond that, the notice sets out what you have to satisfy yourself about: that the data stays secure, that unauthorised third parties cannot reach it, that models are trained on it only with explicit authorisation, and that it is not retained longer than necessary.

Note the phrase satisfy yourself. Not assume, not take on trust because the vendor is large and the interface is polished. The duty is on the firm, under paragraph 6.3 of both the Code for Solicitors and the Code for Firms, and it does not soften because the tool is expensive. The notice is explicit that free and paid systems alike may retain, store or use what you give them in order to improve the product.

There is also a point for those working in-house, who are told to consider whether their organisation's interest in AI conflicts with their professional obligations. If the business wants everything fed into a model and you are the person on the roll, that tension is yours to resolve, and the notice now says so.

Privilege

So far this reads as a data protection problem. It is not only that.

I was raised Catholic, and the first thing you learn about the confessional is that the seal is absolute. The priest does not get to weigh whether your sin is interesting enough to keep to himself. Legal professional privilege is a cousin of that idea. It exists so a person can tell their lawyer the worst version of the truth, and it only functions while the person believes it holds.

Legal professional privilege protects communications that are confidential. Confidentiality is a condition of privilege rather than a by-product of it. Where material has been published to the world and is no longer confidential, the protection built on that confidence is in serious doubt, and you may be arguing about it in circumstances where you have no good facts and an unsympathetic tribunal.

I would not state that flatly as settled law in every case, and if it happens on one of your files you should take proper advice rather than rely on a blog. But the direction of travel in the notice is unmistakable, and it is not a direction anyone wants to be travelling in while explaining to a client why their account is now recoverable by someone else.

Find out what is actually being used

If you do one thing after reading the notice, find out which tools your people are using, rather than which tools your policy permits. Those two lists are rarely the same, and the gap between them is the whole exposure.

The gap is not usually the product of recklessness. It is the product of deadlines. The person pasting the refusal letter is not trying to breach confidence; they are trying to get the grounds out before the time limit, using whatever is fastest and already open in another tab. They are under pressure and reaching for the thing that works now, and I understand that impulse better than I would like to. Policies that consist of a prohibition and nothing else lose to that pressure every time, because they take something away and put nothing in its place. If you want the behaviour to change, you have to give people a permitted route that is no slower than the one they are using now.

How do you satisfy yourself?

The notice uses that phrase and then leaves it there, which is fair enough; a regulator setting out a method would be writing your risk policy for you. But it does mean the work falls to firms, and I think most will start in the wrong place by looking for a standard to adopt.

Start with the law you already owe. Most immigration work involves special category data under Article 9 of the UK GDPR, because we handle material about health, sexuality, religious belief and racial or ethnic origin as a matter of course, and often criminal offence data under Article 10 as well. Running that through a new technology, systematically, is about as clear a case as you will find for a mandatory data protection impact assessment under Article 35. So for many firms the honest answer to whether there is a risk assessment available is that you already owe one, and the conduct questions in the notice can hang off it.

Then borrow the questions. ISO/IEC 42001:2023 is the international standard for AI management systems, and I am not suggesting anyone certify against it; the SRA does not ask you to, and for a firm our size the badge would cost more attention than it returned. What the standard contains is the most carefully worked out set of questions anyone has yet written about putting an AI system into an organisation, and questions are free.

Three of its ideas transfer straight across. The first is the separation it draws between risk assessment, which asks what could go wrong for the organisation, and impact assessment, which asks what could go wrong for the people affected. When legal AI fails, the damage is rarely to the firm. It is to the client, who did not choose the tool and may never be told it was used, so for us the second question is the more important one and it is the one most firms will not ask.

The second is the insistence on intended use and reasonably foreseeable misuse as two separate questions. The product your supplier demonstrates on a Tuesday and the product your fee earner reaches for at half past five with a deadline running are not reliably the same product, and a policy that only contemplates the first is not a control.

The third is the idea of interested parties and what each of them is entitled to know. For a law firm that list is the client, the court, the insurer and the regulator, and the honest answer is different for each of them. Working out what you would tell a judge about how a document was produced is a good way of discovering what you are not comfortable with.

The standard's catalogue of risk sources is a serviceable prompt sheet on top of that: data quality and provenance, transparency, robustness, the level of automation, the precise step at which a human decides something rather than confirms it, and how a system is validated before deployment and monitored afterwards. I am describing the standard from knowledge rather than with it open in front of me, so treat that as the shape of the thing rather than a citation.

What none of it does is ask what a law firm specifically needs to know, because it was not written for people who owe duties to a court and hold other people's confidences. So we built our own out of three sources: the structure of the standard, the requirements of the notice, and the questions that only occur to you after running this in a practice for a while. It is published alongside this piece for anyone who wants to take it apart and improve it: read it here or download the PDF. It tiers tools by the material they will actually see, from published sources at one end to a sponsor's compliance file or a trafficking client's account at the other.

What to ask a vendor

Ask in writing and keep the answers on file, because paragraph 7.2 requires you to be able to justify your decisions and a screenshot of a sales page is not a justification.

Does the model train on our content, and if the default is yes, how is that turned off and who can turn it back on. Who are the sub-processors and where is the data held. How long is content retained after a session ends, and can we require deletion, and how quickly. Is there a data processing agreement and what does it say about onward transfer. What happens to our data when we stop paying. If a supplier cannot answer those in writing within a week, you have your answer. Remember which of you is regulated in that relationship. The vendor carries no professional duty at all.

The same questions apply, with more force rather than less, where the supplier is connected to the firm. We build our own tooling, which means the person answering the questionnaire and the person asking it know each other well. That is a reason to document the arrangement as though a stranger were reading it, not a reason to skip it.

None of this displaces the data protection regime. UK GDPR obligations sit alongside the conduct rules and the ICO takes its own view of them; the warning notice is not a substitute for that analysis and does not pretend to be.

Why this one matters more in our work

I did not come to this work from a neutral position. I am half Indian and half English, my wife is Filipino, and my children are the result of a good deal of movement across borders. When I sit with a client and explain what happens to the things they are about to tell me, I am not reciting a rule at them.

We do business immigration and personal immigration, with family and employment work alongside. That means the material divides into two kinds, and both are the sort you do not want loose.

On my side of the practice it is commercial. A sponsor licence file holds an employer's entire sponsored workforce, the salaries, the gaps in their right to work checks, the things the compliance visit found. It often holds what the business has not announced yet: the restructuring, the change of ownership, the expansion that depends on the licence surviving. Lose that and you have not only breached a confidence, you have handed somebody a competitor's payroll and a list of its regulatory failures, and possibly moved a share price.

On Crystal's side it is safety. She acts in modern slavery and trafficking matters, in domestic violence cases, and for nurses facing fitness to practise proceedings that will end their careers if they go the wrong way. In those files the material is the identity of the person who exploited someone, the address that must not be found, the account of what was done to a client who has spent years not saying it out loud. For clients applying on the basis of a relationship that is not safe to disclose where their family lives, the confidence is the case.

None of those people chose the tool. Most of them have already had the experience of information about them being held by an authority and used against them, which is precisely why they hesitate before telling us anything at all. The undertaking we give when somebody sits down and starts talking is the reason they talk.

It does not survive being pasted into a text box because the deadline was tight. Worth making sure everyone in the building understands that before somebody has to explain it to a client.

The SRA's warning notice on the misuse of AI was published on 17 August 2026. Quotations and paragraph references are taken from the notice as published on that date; guidance changes, so check the current version before relying on it. The Upper Tribunal decision referred to is cited in the notice, and I have taken it from there rather than from my own reading. Nothing here is legal advice.

Part one: supervision → The risk assessment template ← All insights