Regulatory Notice: UtterConnection is an independent operations consultancy, not an SRA or CLC regulated law firm.Read compliance info
Security & Confidentiality

Your clients' data
is non-negotiable.

AI is powerful, but in the wrong hands, it's a data breach waiting to happen. Here's how to get it right.

It's already happening

In late 2025, the Upper Tribunal's Immigration and Asylum Chamber published a landmark ruling that every solicitor in the UK should read.

An adviser who is also a solicitor on the roll admitted putting client emails he had drafted into ChatGPT to improve them, and uploading Home Office decision letters to the same platform to summarise them for clients.

"Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and any such conduct might itself warrant referral to the SRA and should, in any event, be referred to the Information Commissioner's Office."
UK and R (on the application of Munir) v SSHD (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC), headnote 4. Promulgated 17 November 2025, published 19 February 2026. Upper Tribunal Judges Lindsley, Keith and Blundell.

He had already self-reported to the SRA and to the Immigration Advice Authority, so the tribunal made no referral of its own. It said plainly that had he not self-reported, it would have referred him. He accepted at the hearing that what he had done was a data breach, and that he would have to tell his clients.

In the second case in the same judgment, a firm submitted judicial review grounds citing four authorities that did not exist, drafted by a very junior caseworker. The citations sent the judge on a "fool's errand." The supervising solicitor, who was also the firm's COLP, was referred to the SRA. The tribunal recorded a "considerable increase" in fictitious authorities cited in the latter half of 2025.

The finding that matters most to a firm principal is at paragraph 38. A supervisor who fails to catch a junior's hallucinated citations is "likely to be more culpable" than a lawyer who fails to catch their own. Supervision is where the liability lands, not the tool.

The key takeaway

The judge was blunt: "Whether [citation errors] are inserted by a hapless trainee or by ChatGPT is really neither here nor there; the point is that the qualified legal professional with conduct of the matter is expected to ensure that such documents are checked."

The responsibility stays with the supervising solicitor. Always.

The tribunal did not say stop using AI

It said the opposite, twice, and this is the part most summaries leave out.

At paragraph 18: "We do not suggest for a moment that the use of legal AI programmes by properly trained professionals is anything other than a step forward in legal practice. The software which is currently available is of enormous benefit in properly focused legal research."

And at paragraph 21, immediately after the confidentiality finding, the tribunal drew the line exactly where a governed firm would want it drawn:

"Closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks."
UK and R (on the application of Munir) v SSHD [2026] UKUT 81 (IAC) at [21].

That is a UK tribunal naming the distinction that governance turns on. Not AI versus no AI. Open tools on client data versus a closed tenant with a named person accountable for the output. Most conveyancing firms already pay for the second one and use the first one anyway, because nobody ever told them which was which.

Open vs closed AI tools

Not all AI tools are created equal. The critical difference for law firms is where your data goes:

Open AI (HIGH RISK for client work)

  • ChatGPT free tier, Google Bard, Perplexity free
  • Your input is sent to external servers
  • Data may be used to train future models
  • No guarantee of deletion or confidentiality
  • Putting client documents into these tools is a data breach

Closed / Enterprise AI (LOWER RISK)

  • Microsoft Copilot for Business, Azure OpenAI, private deployments
  • Data stays within your organisation's tenant
  • Not used to train external models
  • Contractual data protection agreements available
  • Still requires policies, training, and oversight

The judge in the Upper Tribunal case specifically noted that "closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks."

We help firms evaluate exactly which tools sit in which category, and establish policies accordingly.

GDPR and data protection

When you send client data to an AI tool, you need to ask:

  • Where is the data processed? (UK, EU, US, or unknown?)
  • Is it encrypted in transit and at rest?
  • Does the provider retain your input data?
  • Is there a Data Processing Agreement (DPA) in place?
  • Can you fulfil Subject Access Requests if data is held by the AI provider?
  • Have you updated your privacy notice to cover AI processing?

If you can't answer these questions confidently for every AI tool your firm uses, you have a gap. We help you close it.

How we help

  • AI Tool Assessment, We evaluate every tool your firm uses or is considering, and categorise them by risk level
  • Policy Development, We help you create clear, practical AI usage policies that your team will actually follow
  • Staff Training, We train your solicitors and support staff on what's safe, what's not, and what to do when they're unsure
  • Incident Preparedness, If a breach occurs, we help you respond correctly, including SRA/CLC notification requirements
  • Ongoing Review, AI tools change constantly. We help you stay current without the anxiety

Don't wait for an incident.

Book your 30-minute Diagnostic and find out exactly where your firm stands on AI security.

Start AI Reality Check →