The Upper Tribunal has now said it explicitly. Pasting client information into ChatGPT places that information in the public domain, breaches confidentiality, and waives legal privilege. What the ruling means and what firms should be doing this week.
Two weeks ago we wrote about the Pinsent Masons AI ruling and the wider judicial impatience with hallucinated case citations. The current regulatory direction goes further. The risk is not only that AI hallucinates. The risk is that the act of putting client information into a publicly accessible AI tool is itself a regulatory breach.
The most recent authority is R (Munir) v SSHD [2026] UKUT 81 (IAC), from a November 2025 hearing reported in early 2026 before an Upper Tribunal panel led by Judge Lindsley sitting with two others. The panel addressed publicly accessible AI in legal work directly. The principles it set out, more than the detail of the underlying cases, are the substance of this piece.
This piece sets out the three risks every claimant firm should now be designing against, the mitigation steps that apply regardless of which AI tools your firm uses, and what proper closed-source legal AI with human review looks like in practice.
The three risks of publicly accessible AI in legal work
Confidentiality breach
When you paste a client email, a witness statement, or a piece of disclosure into a publicly accessible AI tool, you are placing that information in the public domain. The data leaves the controlled environment of your firm. It is processed on servers you do not control, by a provider whose terms typically include using submitted data to train future models, and it sits in logs you cannot retrieve or audit.
The SRA Principles require solicitors to act in the best interests of clients and to maintain confidentiality. UK GDPR requires controllers to take appropriate technical and organisational measures to keep personal data secure. Putting client information into a publicly accessible chatbot fails both tests.
Privilege waiver
Legal professional privilege protects communications made for the purpose of obtaining or giving legal advice. The privilege depends on the communication being kept confidential. If you place a privileged document into a system that effectively makes it accessible beyond the client-solicitor relationship, the privilege risks being waived.
This is not a hypothetical risk. The current regulatory direction is unambiguous that this is the consequence of unrestricted use of publicly accessible AI tools.
Hallucinated citations and professional accountability
The third risk is the one most lawyers are now familiar with. Publicly accessible AI tools regularly produce confident-sounding but fabricated case citations, statutory references, and legal arguments. The professional accountability for what is filed in court or sent to a client rests with the qualified legal professional, regardless of how the document was drafted. A hallucinated citation in your name is your problem, not the tool's.
What firms should be doing to mitigate the risk
The mitigation framework is independent of which AI tools your firm chooses to use. Five steps every claimant firm should be taking this quarter, regardless of platform.
- Audit current AI use. Most firms underestimate how widely fee-earners are already using publicly accessible AI tools. Anyone with access to a Google search has access to AI. The audit needs to start from the assumption that AI is already in use, not from the assumption that it isn't.
- Set a clear written policy. Publicly accessible AI tools should not be used for any work involving client confidential information. Closed-source tools, with named approval and documented review processes, are the route for tasks like summarisation, drafting support, and research.
- Train every fee-earner who uses AI. The training needs to cover what publicly accessible AI does with the data, why that creates a confidentiality breach, what the self-reporting obligation looks like if a breach has occurred, and what the closed-source alternative looks like.
- Address historical exposure. If client information has already been put into publicly accessible AI tools, the regulatory route is the same. Self-report to the SRA. Take advice on whether to engage the ICO. Take advice on whether clients need to be informed. Self-reporting is meaningfully different from being caught.
- Build the audit trail. Every document an AI tool has touched should have a clear record of which tool, which fee-earner, what review was done, and what the outcome was. Without that trail, neither the firm nor its insurers can defend the position.
Where LegalDocs Assist fits, and why human-in-the-loop review matters
LegalDocs Assist was built around the four things publicly accessible AI tools cannot offer to a regulated law firm.
Closed-source environment. Client data is processed in a controlled environment, never used to train external models, never placed in the public domain. The confidentiality position is the same as your case management system, because LDA is closed by design.
Human review by default. No document LDA produces leaves the system without a named fee-earner having reviewed and approved it. The model drafts, the lawyer reviews, the lawyer signs. The accountability chain is unbroken and visible. This is what "human-in-the-loop" actually means in regulated practice. Not a tick-box, but a documented review step that sits between the model output and the client-facing document.
Audit trail per document. Every interaction, every prompt, every revision, every approval is captured. If your regulator, your insurer, or a court asks how a document was produced, the answer is in the file.
Specialist knowledge base, not general-purpose AI. LDA is built on verified case law and statutory references for the claimant practice areas it serves. There is no general-internet-scraped corpus to hallucinate from. The cited authorities are the cited authorities.
These four design choices are the floor that the current regulatory direction now treats as standard. The closed-source alternative is not a luxury. It is the default position a claimant firm should be assuming.
What firms should be doing this week
Three immediate actions, regardless of where your firm sits on the AI adoption curve.
- Audit who in your firm is using which AI tools for what tasks. Be honest about it. The audit needs partner-level visibility, not partner-level assumption.
- Set a written policy. One paragraph. Publicly accessible AI tools are not used for client work involving confidential information. Closed-source tools, with named approval, are the route.
- Identify your closed-source default. Pick the closed-source AI you are willing to put your firm's name behind. Train your fee-earners on it. Document the approval process. Then enforce it.
The AI conversation in claimant law is no longer about whether to use AI. It is about which AI you use, under what controls, with what review.
LegalDocs Assist is the closed-source AI document tool built for claimant law firms. Confidential by design, audit-grade by default. Book a demo at www.legaldocs-assist.co.uk.
© LegalDocs Assist — www.legaldocs-assist.co.uk