Client Confidentiality & AI:

What Fee Earners Need to Know Before Putting Anything 
into an AI Tool 

Whether an AI tool is safe for client work comes down to one distinction – and getting it wrong can waive privilege for good. 

Client Confidentiality
Most confidentiality problems with AI don’t start with a dramatic breach.
They start with an ordinary prompt, typed on deadline, by someone trying to get the work done faster. 
A fee earner drops a paragraph of a draft into a chatbot to tighten the wording. Someone pastes a Home Office letter in to summarise it. A paralegal uses a free tool to clean up a client email. None of it feels reckless. All of it can put confidential client information somewhere it should never be.  This page is about where that line sits, why it’s closer than most people think, and how to stay the right side of it without giving up the tools that genuinely help. 

Is it safe to put client information into an AI tool? 

It comes down to one question: is the tool inside your firm’s control, or has your information left the building? 

That responsibility point is the one the regulator keeps returning to. The SRA’s position is that whatever the technology, the lawyer remains the person making the decision and carrying professional responsibility for it and has to be able to explain and justify their own work. Governance is how a firm makes that real rather than aspirational.

Closed Tool
A closed tool is one your firm has put under contract – a business or enterprise arrangement where the provider is contractually bound over how your data is handled, doesn’t use it to train its models, and keeps it in a defined environment the firm can account for. Your information stays within reach of the firm’s obligations. 
Open Tool
An open tool is a public, consumer product you’ve signed up to yourself – a free or personal chatbot account, with no agreement between it and your firm. Whatever you enter is sent to a third party you have no contract with, held on their systems, and, by default, used to help train their models. 
That's the distinction that matters and it's worth being precise about why, because there's a common misconception in the way. 

You might know that consumer ChatGPT lets you switch model training off in its settings and assume that makes it safe for client work. It doesn’t.

Turning training off is a single toggle that can be reset or changed, but more to the point, your information has still gone to a third party you have no agreement with, still sits on their systems, and is still outside the firm’s control. The training setting deals with one symptom. It doesn’t put the information back inside the building. So, the safe line isn’t “a tool with training switched off”, it’s “a tool the firm has under contract.”

Why confidentiality bites earlier than you'd think

It’s tempting to think you’re safe as long as you don’t upload an actual document. In reality, you’re not. 
The duty of confidentiality covers all information relating to a client’s matter, not just privileged documents – litigation strategy, draft terms, financial details, the shape of a negotiation. And it’s triggered far earlier than a file upload. A prompt that names the parties, describes the dispute, or summarises a position can reveal enough to identify the matter on its own.  So “revise this indemnity clause for our client’s £20m acquisition of a regional manufacturer” isn’t a neutral request. In a single line it’s given away the deal type, the value, the client’s position and enough to identify who’s involved. The document never had to leave your screen for the confidential information to.  That’s the part worth sitting with: the risk isn’t only in the obvious upload. More often than not, it’s in the routine, hurried prompt. 

The risk isn't the document you upload. It's the prompt you dash off without thinking.

The line the courts have now drawn
This all stopped being theoretical in 2026. 

In Munir v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the Upper Tribunal held that uploading confidential documents into an open-source AI tool such as ChatGPT is to place that information in the public domain, breaching client confidentiality and waiving legal professional privilege. The Tribunal added that such conduct might itself warrant referral to the SRA and should in any event be reported to the Information Commissioner’s Office. 

Once privilege is waived, it's gone. There is no putting it back.

The consequence is the part to hold onto. Once privilege is waived, it’s lost. It cannot be recovered, and there’s no mechanism to claw it back once the material has entered the public domain. This isn’t a fine you pay and move on from. The protection is simply gone, for that material, permanently. 

None of this, however, means AI is off-limits. The same courts have been clear that, used properly, these tools are a genuine step forward. It means the choice of which tool, for which information, is now a decision with real weight behind it. 

How to tell which kind of tool you're using 
You don’t need to read anyone’s terms of service. A few practical signals do the job. 

SIGN UP

If you signed up for it yourself, it's free or on a personal subscription, and there's no arrangement between your firm and the provider behind it, treat it as open, and off-limits for client information. Consumer chatbots are the obvious case. 

ACCESS

If the firm gave you access to it, there's an IT or procurement process behind it, and it sits under a business or enterprise agreement, then it's likely closed, and safe to use as intended. 

UNCERTAINTY

If you're not certain which you're dealing with, that uncertainty is itself the answer: don't put client information in until someone can confirm it. The firm's list of approved tools exists precisely so you're not making that call alone under deadline. 

A few habits that cover the rest
Beyond choosing the right tool, two things are worth making automatic. 

Before you send a prompt to anything you’re not certain about, read it back as though it were going to be published – because with an open tool, it effectively is. Names, figures, positions and the shape of a matter all count, not just the documents you attach. 

And check what comes back. AI tools can produce citations, authorities and facts that look entirely right and aren’t, so verifying against the original source before you rely on it is your responsibility, not the tool’s.  

One more, easily forgotten in the confidentiality conversation: the SRA expects firms to be clear with clients about where AI is used on their matter. How that’s handled is a firm decision, so it’s worth a word with whoever owns it if you’re unsure of the position. 

Where this fits

Using AI safely as an individual is one half of the picture.

The other is the firm having the governance around it – approved tools, clear policies, the controls that mean you’re not left guessing at your desk in the first place. If you’re looking at that wider side, our guide to AI governance for law firms covers what a firm needs in place before any tool goes live.

The Short Version, for Your Desk
The rules here come down to a handful of judgements you can make in seconds, once you know what to look for.

We’ve put them into a single guide built for exactly that – the decision flowchart, a few worked examples, and the what-to-do-if steps – so the safe choice is the easy one, even on a deadline. 

Rising Tide AI
Where Rising Tide AI Fits
We build AI tools for UK law firms – the contained, properly governed kind that fee earners can actually use on client work without this being a worry. If your firm is working out which tools are safe to put in front of people, we’re happy to help.
FAQs
Governing AI in Your Firm
Can I use ChatGPT for client work?
Not the free or personal version, and not even with model training switched off. It’s a consumer tool with no contract between it and your firm, so your information still goes to a third party outside the firm’s control. A closed, firm-provided tool under a business or enterprise agreement is a different matter. Check which your firm has approved before using anything for client work.
Less risky, but not as safe as it feels. The duty of confidentiality isn’t limited to names – a matter can be identifiable from the deal type, the sums involved, the jurisdiction, or the shape of a dispute, even with the obvious identifiers stripped out. Anonymising a prompt is a sensible instinct, but it isn’t a reliable way to make an open tool safe for client information. The tool question comes first.
The confidentiality risk drops away when there’s no client information involved, but a second risk doesn’t. AI tools can produce citations, authorities and facts that look right and aren’t, so anything you rely on has to be checked against the original source, whether or not client details were ever in the prompt.
It depends on the terms your firm holds it under, not the brand. The same AI feature can be inside your firm’s contracted business or enterprise agreement or accessed through a personal account with no such protection, and only the first keeps your information within the firm’s control. The question to ask isn’t “which product is it” but “is this instance covered by our firm’s agreement”, which is something your IT team can confirm.
Raise it with your supervisor or COLP straight away. There may be steps to take, including assessing what was disclosed and whether it needs reporting to the ICO, and these are far easier dealt with early than late.