A meeting table in a modern law firm, a closed laptop and a chair behind a glass partition

Solicitors

What an AI policy for a law firm actually needs to cover

A policy is not a document about technology. It is a record of five decisions the firm has taken about client information, supervision and accountability, and the reason firms write one is almost always that somebody is already using a tool nobody approved.

Last checked 20 September 2026

Start from what is already happening #

Most firms come to this after the fact. A paralegal has been summarising documents with a free tool for three months because it works, a fee earner has drafted a first attempt at a letter the same way, and nobody has ever been told whether either is permitted. The policy is then written to close a gap rather than to open a door, which is the wrong order but the normal one.

That matters for what the document has to do. A policy that describes an intended future does nothing about the tools in use today.

What the regulator has actually said #

The SRA published a Risk Outlook report on the use of artificial intelligence in the legal market on 20 November 2023. It is worth reading in full, and three of its points do most of the work.

On accountability it is unambiguous.

As with any other technology or system in your firm, you will remain responsible and accountable for the outputs from AI you are using.
SRA, Risk Outlook report on the use of artificial intelligence in the legal market, 20 November 2023

On reliability it explains why these tools fail in a particular way, describing systems that work "by anticipating the text that should follow the input they are given" without "a concept of 'reality'", producing what it calls hallucination, "where a system produces highly plausible but incorrect results".

On confidentiality it names specific mechanisms rather than a general worry.

  • A staff member using an online tool to answer a question on a client’s case

  • “Confidential data being revealed when it is transferred to an AI provider for training”

  • “The output from an AI system replicating confidential details from one case in its response to another”

Those are three different failures with three different controls, and a policy that treats them as one covers none of them properly.

What the Law Society has said #

Law Society guidance for solicitors on generative AI is blunter about free tools than most firms expect.

If you are using a free, online generative AI service where you have no operational relationship with the vendor other than use, do not put any confidential data into the tool.
Law Society, Generative AI: the essentials

More generally it advises against feeding confidential information into these tools "especially if you lack direct control and oversight over the tool's development and deployment".

On supervision it removes a common escape route. A solicitor's professional duties, in particular the duties to the court and to the client, apply to work carried out by the solicitor regardless of whether AI was used to assist with it, and they apply "whether AI was used by the solicitor personally or by anyone under that solicitor's supervision".

The guidance also separates two kinds of training that firms routinely conflate, noting that technical training in using a tool is distinct from training in the ethical use of it and that both matter.

Confidentiality and privilege are two questions, not one #

Paragraph 6.3 of the Code of Conduct for Solicitors is a professional obligation: "You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents." It is owed by the solicitor, and it is the duty most AI policies address.

Legal professional privilege is a different thing. It belongs to the client, not to the firm, and whether a particular disclosure to a third party service affects it is a legal question that depends on the facts. This page will not answer it and no supplier should offer to.

Data protection runs on a separate track #

If client information identifies a living individual, UK GDPR applies and the firm is accountable for how it is processed, independently of anything the SRA says.

The ICO publishes guidance and resources on artificial intelligence, including detailed guidance on applying UK GDPR principles to AI systems, guidance on explaining decisions made with AI, and an AI and data protection risk toolkit for assessing risks to individual rights and freedoms. Those are the documents an assessment should be built on.

An accountancy practice faces the same three-way split, set out on the client data in AI tools page, and the general version is on whether ChatGPT is GDPR compliant.

The five decisions a policy is really recording #

Strip the boilerplate out and a usable policy settles five things. Not how to do any of them, which depends entirely on the firm, but that a decision was taken and by whom.

  1. Which tools

    Named, with a route for asking about a new one, because an unanswerable request turns into quiet use.

  2. What may go in

    By category of information, not by good intentions. This is where confidentiality, privilege and personal data all land.

  3. Who is accountable

    A named person, consistent with paragraph 2.1 of the Code of Conduct for Firms on governance structures and 2.5 on managing material risks.

  4. What happens to output before it leaves the firm

    Given what the SRA said about non-existent cases, this is a supervision question under paragraph 4.4, not a preference.

  5. What is recorded

    Paragraph 2.2 requires records to demonstrate compliance, and a decision nobody wrote down is hard to evidence later.

What runs on rules, and what does not #

Runs on rules

  • Knowing which systems hold client information, though most firms have never written the list down
  • Knowing who has access to what
  • Recording that a decision was taken, and when
  • Evidencing that training happened

Needs a person

  • Deciding whether a category of information may be used at all
  • Deciding whether a disclosure affects privilege
  • Reviewing output before it reaches a client or a court

The first belongs to the firm, the second is a legal question, and the third is judgement, always.

What this consultancy will not do #

  • Tell you that a tool is safe for client matters
  • Tell you that a configuration is compliant
  • Tell you that a supplier's assurances are enough

Those conclusions are the firm's to reach, and automating a step has never made anybody compliant with anything.

What is useful to say is that a surprising amount of the admin load in a firm never needs to touch privileged material at all. Knowing which files have gone quiet, which letters have not come back, which matters are waiting on the same third party: those are questions about the state of the firm rather than about the substance of a case, and that distinction is where the safe ground is.

It runs through the update nobody has time for, and the task sorter is a quick way to see which of your own jobs fall on which side.

Questions people ask

Does a law firm have to have an AI policy?
The SRA does not publish a rule requiring a document with that name. It does require, at paragraph 2.1 of the Code of Conduct for Firms, "effective governance structures, arrangements, systems and controls", at 2.5 that a firm identifies, monitors and manages all material risks to its business, and at 2.2 that it keeps records to demonstrate compliance. A firm whose staff are already using these tools has to be able to show how that is governed.
Who is responsible if an AI tool gets something wrong?
The firm and the individual. The SRA Risk Outlook report on artificial intelligence in the legal market, published 20 November 2023, states that "you will remain responsible and accountable for the outputs from AI you are using". Law Society guidance makes the same point about supervision: the duties of a solicitor apply whether the tool was used by them personally or by anyone under their supervision.
Can we put client information into a free online AI tool?
Law Society guidance is direct on this: if you are using a free online generative AI service where you have no operational relationship with the vendor other than use, do not put any confidential data into the tool. Whether a given disclosure also affects privilege is a legal question for the firm, and it is the question most policies never ask.
What is the most common failure in practice?
Not a breach. A governance gap. Somebody finds a tool useful, uses it on real work because it saves an hour, and nobody has ever said whether that was allowed. The policy usually gets written after the firm discovers this, which is why the first job is finding out what is already in use.
Does a policy make the firm compliant?
No. A document is evidence of a decision, not a substitute for one, and it protects nobody if the underlying judgements were poor or the policy is not followed. Your obligations remain yours, and the SRA supervises the firm rather than its suppliers.

Where these numbers come from

  1. SRA, Risk Outlook report: the use of artificial intelligence in the legal market, 20 November 2023 , read 20 September 2026
  2. Law Society, Generative AI: the essentials , read 20 September 2026
  3. SRA Code of Conduct for Firms, paragraphs 2.1, 2.2, 2.5, 4.3 and 4.4 , read 20 September 2026
  4. SRA Code of Conduct for Solicitors, RELs and RFLs, paragraph 6.3 , read 20 September 2026
  5. ICO, Artificial intelligence guidance and resources , read 20 September 2026

Last checked 20 September 2026.

Our workings are on the methodology page .

Free audit

A free audit for law firms

One call, walking through a normal week. You get the tracker of every repeated job ranked by hours, a map of the top five, and the number of hours a month they could give back. Yours to keep either way.

Solicitors

Client onboarding, file opening, forms and the updates clients ring about.

All of solicitors

Read next