
Keeping client confidentiality when you use AI
Client information may only leave the firm if the law allows it or the client agrees. An AI tool is run by another company, so that agreement belongs in your engagement letter.
In the last week of July 2026, shared conversations with AI assistants started turning up in Google's search results. The people who made those links had chosen to share them. Few would have expected the pages to become searchable.
That is the confidentiality problem as it now stands. You cannot give a client's information to anyone outside the firm unless the law allows it or the client agrees, and an AI tool is run by another company.
Two things follow. Get the client's agreement in writing, in the engagement letter. Then hold everyone to one rule: client information goes only into the AI accounts the firm has approved, never into anyone's personal account.
Paying for a plan is not the same as having checked it.
This is general information, not legal advice. It is written for firms that hold confidential client information, and it draws on the rules for solicitors and for accountants and tax advisers. If your profession has its own code, apply that one.
What changed this year
Until recently the risk was that someone would paste client information into a chat box. The rule you needed was about what staff typed, and we have written that one up as a one-page yes or no policy.
Take the shared conversations. Pressing the share button in an AI assistant creates a web page anyone holding the link can open, and those pages carried no instruction telling search engines to leave them alone. Anthropic added the instruction within about two days, and the same failure had already happened to other assistants.
The assistant does keep a log of what each person has shared, which is what makes the fix below possible. What no firm has is an approval step before a link is created, or anything that prompts someone to take one down afterwards. The pages stay live until the person who made them unshares them.
A connector gives an assistant access to far more than a pasted document does. When you connect an assistant to a drive, a mailbox or a document system, it reads with the permissions of the person who connected it. Anthropic states this plainly in its own documentation: "When you connect a tool, Claude inherits your permissions in that tool and can only see and do what you can already see and do."
That is deliberate, and reasonable. But in a small firm a senior user often has access to a large share of the client files, and a connector inherits that reach unless the permissions and the sources are deliberately restricted.
Then there are notetakers, which join a call, transcribe it and keep the transcript, often on the provider's own systems. When the client hosts the meeting, their settings decide whether a notetaker can join, not yours. We have written separately about notetakers in client meetings.
None of that involves anyone deciding to disclose anything. That is why a rule about what staff type is no longer enough.
Why a breach does not need a leak
In November 2025 the Upper Tribunal considered the conduct of a solicitor who had put client emails and official decision letters into ChatGPT, to improve his drafting and to summarise documents for clients. He had recognised it as a data breach himself, and told the Tribunal he would inform the clients and his regulators.
The judgment does not record an identified external leak, or a complaint from any client.
The Tribunal's observation now appears in the headnote of the published judgment, at paragraph 4 of UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC):
"Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege, and any such conduct might itself warrant referral to the SRA and should, in any event, be referred to the Information Commissioner's Office."
It is an observation, not a finding that this solicitor breached the SRA Code, and no sanction followed on the confidentiality point.
The case had reached the Tribunal over a different fault, a fabricated case citation. The confidentiality question only emerged when the Tribunal asked him how he had used the tool. The "public domain" wording is the Tribunal's own, a statement of principle rather than a technical account of how any product handles data.
The Tribunal's "open-source" is loose too: it means a publicly available tool, not what the software industry means by open source.
The Tribunal was describing an uncontrolled upload to a public tool, and that language does not settle what happens with a service your firm has contracted for. Whether privilege survives a disclosure depends on the facts, including whether confidentiality was preserved and how limited and well documented the purpose was. A business contract does not automatically settle it either.
Even with those limits, a UK judge reached for that public-domain framing without being asked to.
We searched the ICO's enforcement database for artificial intelligence, ChatGPT, generative, chatbot, machine learning and Copilot. The search returned nothing.
As at the end of July 2026 there is no ICO enforcement action arising from a UK professional-services firm putting client information into an AI tool. We could locate no published tribunal finding on it either. Our search covered case summaries rather than the full text of judgments.
That is an absence of a close precedent, not an absence of regulatory exposure. The Information Commissioner's powers are unchanged.
A fine is not the likeliest outcome. You are more likely to spend time putting it right, tell the client, report it to your professional body, answer your insurer, or face a contractual claim. Our post on professional indemnity cover and AI goes further on the insurance side.
You already trust suppliers with client files, so why is AI different?
That is a fair objection. Your practice management system holds every client file you have. Your email sits on somebody else's servers. Your accounts software holds your clients' financial details.
Nobody calls any of that a breach of confidence.
The distinction turns on whether the use is authorised. In the formulation the courts use, the wrong is the "unauthorised use of the information to the detriment of the party communicating it". The Court of Appeal has confirmed that the use must also be "without lawful excuse" (The Racing Partnership Ltd v Sports Information Services Ltd [2020] EWCA Civ 1300, at paragraphs 44 to 45).
A supplier arrangement the client has authorised, and the firm controls, does not breach the duty. That is usually why using your document system, your email and your practice management system is not a breach: the client's authority for the ordinary conduct of their matter covers the suppliers you need to do the work.
The case does not decide that any particular supplier disclosure is authorised. The supplier contract is one part of the arrangement, and it does not supply the client authority your own professional rules ask for.
A personal AI account is a different arrangement. There is no contract between the firm and the provider, no agreed purpose, no instructions the provider is bound to follow, and no right for the firm to have anything deleted. The provider may also use the material for its own purposes.
So the line does not fall between AI and other software. It falls between an account the firm has contracted for and an account somebody signed up for on their own.
There is one weakness in that argument. The SRA frames disclosure to third parties more strictly than the general law does. Its guidance on confidentiality says "Information should not be passed to third parties without the client's consent". That consent "must be clear, so that the client knows to whom their information should be made available, when and for what purpose".
It is better to get the client's consent than to rely on an argument you would have to make later.
The confidentiality duty, and the rule it produces
The duty is short. SRA Code of Conduct paragraph 6.3, in effect since 11 April 2025, says:
"You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents."
It covers former clients too. That catches more AI use than firms expect, because old matters are exactly what people feed to a tool when they want a precedent or a template.
Paragraph 6.3 binds solicitors. Other codes use different words and come to the same thing: client confidentiality is a duty, and the client's authorisation is one of the few ways out of it.
On AI specifically, the accountancy and tax bodies have been more direct than the SRA or the Law Society. The bodies behind Professional Conduct in Relation to Taxation, including the Institute of Chartered Accountants in England and Wales, published joint guidance on 19 January 2026. Paragraph 4.2 puts it in one sentence:
"The input of client data into publicly available AI tools is likely to constitute a breach of client confidentiality, unless the client has consented to this."
Keep both qualifications when you quote that to your team: "likely to", and "unless the client has consented". It turns on consent, and it is not a ban on AI.
The same guidance explains what you give up: "When information is entered into publicly available AI tools, control over that data is relinquished."
It is also explicit about what authority means. At paragraph 4.1: "Members may only disclose information to third parties with proper and specific authority from clients, unless there is a legal or professional right or duty to disclose." Proper and specific is the standard, and a line saying you may use AI tools is neither.
The Law Society's test is what kind of account you have. Its guidance for solicitors is blunt: "If you are using a free, online generative AI service where you have no operational relationship with the vendor other than use, do not put any confidential data into the tool."
That is where the rule for your staff comes from. A business account the firm holds comes with a contract, and under that contract the provider usually agrees not to train its models on what your people type.
Three things have to be true before client information goes into an AI tool. The client's authority has to cover the disclosure and its purpose. The firm has to have approved that provider, product and plan on suitable contract and data-protection terms. And the use itself has to be limited to what the matter needs.
Paying for a subscription only helps with the firm's approval of the provider.
Consumer tiers often do offer a no-training setting. Anthropic's own privacy pages describe a model-improvement control a user can switch off, and say a user can change those settings at any time.
The difference is who holds the control. On a personal account the individual holds that control, not the firm. The same goes for the retention setting, the decision to delete anything, and the ability to switch any of it back next week.
A business contract usually stops the provider training on your information, but it does not always stop the provider storing it. Our post on what data protection law actually asks of your firm explains the difference.
What counts as a business account, then? It is not simply one the firm pays for. The test is whether the firm has approved that provider, that product, that plan and its settings for the use you have in mind.
Start with the licences the firm holds. They include the AI features inside business software you already license, such as an assistant bundled into your Microsoft or Google subscription, or the AI built into your practice management system. A free tier does not count, and neither does an individual subscription somebody bought on their own card.
Paying is not the same as approving. The checklist below is what approving means.
What the regulator has not said
Regulator guidance is thinner than you might hope. The ICO's guidance on AI and data protection is still stamped "This guidance was updated on 15 March 2023". It now carries a banner saying it "is under review and may be subject to change" following the Data (Use and Access) Act.
Two obligations have not changed: UK GDPR Article 5(1)(f) requires appropriate security for personal data, and Article 5(2) requires you to be able to demonstrate that you comply.
Where firms actually are
The government's UK Business Data Survey 2026 asked 1,870 UK businesses that use AI whether they had a policy about it. It was published on 18 June 2026, with fieldwork by Ipsos from October 2025 to January 2026.
Section 3.4 reports that 17% did: 5% with a formal written policy, and 12% with informal guidance. Of those that had anything, 62% said it covered AI access to their business's data and files, with no measurable variation by size or sector.
Put the 17% and the 62% together and roughly one in ten AI-using businesses has a policy or informal guidance covering what its AI tools may reach. That is our arithmetic, not a published figure, so treat it as an indication of scale.
Closing that gap is a short checklist for each tool you use, one paragraph in your engagement letter template, and an afternoon on the three jobs below. Nothing in it asks you to use AI less.
Firms that finish this can use these tools on client work without reopening the question every time.
Before you approve a tool: the supplier checklist
Approving a supplier is a separate job from paying for one, and it is the job that produces the schedule your engagement letter points at. Work through it once per product, write down the answers, and date them.
- The exact product and plan you are approving, not the vendor's name in general.
- Whether inputs and outputs are used to train models, and whether that is a setting or a contractual commitment.
- How long information is kept, and what you can delete on request.
- Whether there is a data-processing agreement, and who is controller and who is processor.
- Which subprocessors are involved, and whether you are told when they change.
- Where information is processed, in the United Kingdom or overseas, and what safeguards cover any transfer.
- Encryption, access controls, multi-factor authentication and whether there is an audit trail.
- What an administrator can control centrally: sharing, connectors, retention, and removing someone who leaves.
- What the provider will tell you, and do, if something goes wrong at their end.
If a provider processes personal data on your behalf, data protection law requires a written contract, not just good practice. It has to cover documented instructions, confidentiality, security, subprocessors, help with individual rights, deletion and audit rights. Overseas access can also count as a restricted transfer needing its own safeguard.
Two answers change what you tell clients: where information is processed, and which providers and subprocessors you will have to name in your schedule.
Telling a client is not the same as asking them
This is where the paperwork usually falls short. The accountancy guidance suggests a line in the engagement letter, and says at paragraph 1.3 that such a statement "can help support transparency with the client". The same document makes the breach turn on whether the client "has consented". Those are two different jobs, and a letter that only announces you use AI has done the first one.
Consent has a narrow meaning here. It is the client agreeing to a disclosure that would otherwise breach your professional duty. It is not the same as choosing consent as your lawful basis under data protection law, which is a separate question under a different rulebook. Only the professional duty is the subject of this post.
There is no published wording for that consent. The Law Society's own page records that "Currently, the SRA does not have specific guidance on generative AI related to use or disclosure of use for client care." We have written it below.
The wording to put in your engagement letter
This is drafted to do three things at once: obtain the client's authority for the disclosure and its purpose, point at a schedule that names who actually receives the information, and keep a person answerable for the output. Copy it, put it in your engagement letter under its own heading, and have your own adviser check it against your own code, your services and the rest of your terms.
Use of artificial intelligence tools
We may use artificial intelligence tools the firm has approved to help
us summarise documents, draft correspondence, analyse information and
review work. These tools may process information about you and your
matter, including confidential information.
We use only business services the firm has approved, under contracts
and data-protection terms the firm has reviewed. The providers we
currently use, what we use them for, where information is processed
and how long it is kept are set out in our AI supplier schedule,
which forms part of these terms. We do not put your information into
free or personal accounts.
By agreeing these terms you authorise us to disclose information to
those providers for the purposes described. We remain responsible for
the work we provide to you, and AI-assisted material in our advice or
deliverables is reviewed by a suitably qualified person.
Please tell us before work begins if you need restrictions on the use
of these tools. We may ask for your separate agreement before using
one on exceptionally sensitive or privileged material, or for a
purpose these terms do not cover.
The schedule is the part that makes this work, and it is why the clause does not name products. Your terms should not have to be reissued every time a provider changes, but the client does need to be able to find out who holds their information.
So keep a short schedule listing the actual providers, and treat a material change of provider, purpose or data handling as something that may need notice or fresh authority.
Check four things before you use any of it.
First, only keep the review sentence if you can do it on every job. A client can hold you to what your terms say.
Second, a signed engagement letter can evidence the client's agreement. You do not need a tick box on every matter.
Where material is unusually sensitive or privileged, or a client may reasonably object, a tick box or a matter-specific agreement is the prudent course: "Please tick one: the firm may use artificial intelligence tools as described above, or the firm may not." An unticked box gives you no evidence at all, and the SRA's standard is that consent must be clear.
Third, be realistic about what you can switch off. If an assistant is built into a system you cannot disable matter by matter, say so when you agree the alternative approach, rather than promising a clean exclusion you cannot deliver.
Fourth, a template only applies to new engagements.
For clients already on letters signed years ago, start by reading what you have. Read the engagement letter, any outsourcing clause and any data-handling terms already agreed. If those do not clearly cover this disclosure and its purpose, get a written variation or a matter-specific agreement before identifiable client information goes into the tool. Until then, use genuinely anonymised material on those matters, or keep the tool off them.
A provider contract cannot fill that gap. It governs the provider. It does not give you authority to disclose.
If a client declines, record it in the matter file. A single line is enough: "AI tools not to be used on this matter. Client's instruction, [date]." Then tell the people doing the work, or they will use AI on the matter anyway.
The same task, done two ways
| The task | The way that risks a breach | The better-controlled way |
|---|---|---|
| Summarising a client's letter | Uploading the letter, with the client's name, address and matter details in it, to a free account someone signed up for | Working in the firm's business account, with the engagement-letter agreement in place, and removing identifying details where the summary does not need them |
| Drafting advice for a client | Pasting the client's full instructions and figures into a personal assistant to get a first draft | Drafting in the firm's account, then reviewing and signing the output yourself, so a person is answerable for the advice |
| Preparing a brief before a client call | Letting a connector or agent read across every folder it can reach to assemble background | Pointing the tool at the single matter folder, and keeping notetakers off the call unless the client has agreed to one |
The pattern is the same in each row. The better-controlled version uses an approved account, has a stated purpose, has a named person who signs off, and puts in no more information than the task needs. None of them is risk-free, which is why the approval step matters.
Three jobs that matter more than the policy
Keep the written rule. These three jobs are the ones that change what a tool can actually reach.
First, clear the shared links. Ask everyone who uses an AI assistant to open their sharing log and unshare anything containing client material. In Claude that is Settings, then Privacy, then Shared chats. Then make it a standing rule that people move AI output by copying the text into the systems you already control, instead of sending a link.
Second, check the connectors. List what each assistant is connected to and whose permissions it inherited, then scope each one down to the folders the work actually needs.
Third, settle the notetaker question. Decide whether they are allowed on client calls at all. If they are, ask before you bring one, because on a client-hosted call it is the client's settings that decide.
If it has already happened
If you look, you will probably find something. Our AI incident plan sets out the full procedure. Work in this order:
- Stop the use, and disable any public link or connector involved.
- Preserve the facts: the account, the prompts, the files, the dates, the settings and who was involved.
- Work out which clients and what information are affected.
- Use the unshare and delete controls you have, and ask the provider where you need more.
- Decide whether personal data is involved and what could follow for the people affected.
- Write the assessment down even if you conclude it is not reportable.
On reporting, UK GDPR Article 33 requires a controller to notify the Information Commissioner of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it". That duty does not apply where the breach is unlikely to result in a risk to people's rights and freedoms.
Deciding whether that applies is a judgement, so write down how you reached it. For regulated work, take your own advice early on what you owe the client, your professional body and your insurer.
What to do this month
Take four steps, in this order.
- Run the supplier checklist on the tools you already use, and write down the answers. That gives you your approved list and your schedule.
- Add the wording to your engagement letter template, and to the next letter that goes out. Then decide how you will reach the clients already on old letters.
- Stop client information going into personal and free accounts, and make sure everyone who needs an approved account has one. A rule that leaves someone without a tool they need is a rule people work around.
- Do the three jobs above: shared links, connectors and notetakers, and write the result into your AI policy.
If you would rather not do this in-house, book a short call and we will map where AI touches client information in your firm, and what each use needs before it is approved.
Common questions
Do you have to get client consent before using AI on a matter?
For a solicitor, paragraph 6.3 gives you two routes: disclosure required or permitted by law, or the client's consent. Some firms argue that using a contracted supplier for the purpose the client engaged them for needs no separate consent.
We would not rely on that. The SRA's guidance frames third-party disclosure as consent-based and says consent must be clear enough that the client knows to whom, when and for what purpose. The accountancy and tax guidance asks for authority that is "proper and specific". Both are easier to satisfy in the engagement letter than to argue after the event.
Is it a breach if nothing ever leaks?
Possibly, yes. The duty is about disclosure without permission. Harm is a separate question, and in the case above the Tribunal treated the upload itself as the problem, without any finding that the information had been seen by anyone else.
Does using ChatGPT or Claude at work breach confidentiality by itself?
No, and two things have to be in place. The client's agreement has to cover the disclosure and its purpose, and the account has to be one the firm holds and has approved on reviewed contract and data-protection terms. Together those give you the same kind of supplier arrangement as your other software.
A free or personal account fails the second test, because the settings and the contract stay in one person's hands. That is why the rule turns on the account rather than the product.
What about former clients?
The duty covers them in the same words it uses for current clients. A ten-year-old matter file is still confidential, and those are the files people upload when they need a template to work from.
Your staff are already using their own accounts. What now?
Give them a business account first, then set the rule, then ask them to clear their sharing logs. In that order people have a working tool before you tell them to stop using their own account, so they are more likely to follow the rule.
This is general information, not legal advice. Where a matter is sensitive, where a client has given specific instructions, or where you are unsure what your own professional code requires, take advice from a specialist in your own field.