Not with identifiable client data in the clear. The Law Society’s guidance says confidential data should not go into free, public generative AI tools, and the Upper Tribunal accepted in Munir v SSHD that pasting client correspondence into ChatGPT was a data breach. Law firms can still use ChatGPT productively in two ways: under an enterprise contract with retention and no-training guarantees, or — for any tool — by masking client-identifiable information before the prompt leaves the firm, so the model receives a de-identified version and confidentiality is never in question.
What the rules actually say
No UK rule bans law firms from using generative AI. The Law Society’s "Generative AI – the essentials" guide (first published November 2023, updated June 2026) permits use but is blunt about public tools: do not put confidential data into them, and use fictional data for testing. The SRA’s Risk Outlook report frames non-adoption as a risk in itself — the regulator’s concern is uncontrolled use, not use.
The case law made this concrete. In Munir v SSHD, an immigration adviser used ChatGPT to summarise Home Office decision letters and polish client emails — routine work, no bad intent. When it surfaced in a tribunal hearing, he accepted it amounted to a data breach and self-reported to his regulators. The tribunal characterised uploading client material to an open AI tool as placing it in the public domain.
The two compliant paths
Path one is contractual: ChatGPT Enterprise or an API agreement with no-training and retention commitments. It works — inside that one contract. It does nothing about staff using the free tier, other AI tools, or personal devices, and it still sends real client identifiers to the provider.
Path two is technical: mask client-identifiable information before the prompt leaves the browser. Names, addresses, NI and NHS numbers, and case references become placeholders like <PERSON_7K9X>; the model works on the de-identified text; the real values are restored locally when the answer returns. The confidential content never reaches the provider, whichever tool staff use — and an audit trail records that the control ran.
The short version
- No ban exists — but identifiable client data in public AI tools is treated as a confidentiality breach.
- The Upper Tribunal has already accepted that pasting client letters into ChatGPT was a data breach.
- Enterprise contracts protect one tool; masking protects the prompt on every tool.
- Evidence matters: an audit trail of what was masked turns policy into something you can demonstrate.
Related questions
Is ChatGPT Enterprise enough on its own?
It covers the tool it contracts for. The gap is everything else: free-tier use, other AI tools, personal devices. Most firms combine an approved enterprise tool with a technical control that applies to whatever staff actually use.
What happened to the adviser in the tribunal case?
He accepted the breach and self-reported to the SRA and the IAA; the tribunal said it would have referred him had he not. There was no fine in that case — the exposure is regulatory referral, potential unlimited fines or striking-off at the disciplinary stage, and UK GDPR liability.
Does masking client data change the legal position?
It changes what the AI provider receives: de-identified text instead of confidential client information. That materially reduces the disclosure — though it is a risk-reduction control, not a legal guarantee, and firms still need policy and appropriate provider terms.
This page is general information, not legal advice. Where third-party guidance or law is summarised, read the originals via the source links before relying on them. Last reviewed: 17 July 2026.
This is the control in action
Identifiable data is masked in the browser before the prompt ever leaves — try it yourself with a sample prompt, or bring one low-risk workflow to a 20-minute review.
Advise Sarah Thompson, NI AB123456C, on the settlement offer.
Advise <PERSON_7K9X>, NI <NI_8W1R>, on the settlement offer.