Not with identifiable client data in the clear. The Law Society’s guidance says confidential data should not go into free, public generative AI tools, and the Upper Tribunal accepted in Munir v SSHD that pasting client correspondence into ChatGPT was a data breach. Controls to evaluate include suitable provider terms and masking detected client identifiers on supported workflows to reduce identifiable data exposure. The remaining document content still needs review under the firm’s policies.
What the rules actually say
No UK rule bans law firms from using generative AI. The Law Society’s "Generative AI – the essentials" guide (first published November 2023, updated June 2026) permits use but is blunt about public tools: do not put confidential data into them, and use fictional data for testing. The SRA’s Risk Outlook report frames non-adoption as a risk in itself — the regulator’s concern is uncontrolled use, not use.
The case law made this concrete. In Munir v SSHD, an immigration adviser used ChatGPT to summarise Home Office decision letters and polish client emails — routine work, no bad intent. When it surfaced in a tribunal hearing, he accepted it amounted to a data breach and self-reported to his regulators. The tribunal characterised uploading client material to an open AI tool as placing it in the public domain.
Controls to evaluate together
Path one is contractual: ChatGPT Enterprise or an API agreement with no-training and retention commitments. Its protections depend on that contract and the approved workflow. It does nothing about staff using the free tier, other AI tools, or personal devices, and it still sends real client identifiers to the provider.
Path two is technical: mask detected client identifiers on supported inputs before model submission. Names, addresses, NI and NHS numbers, and case references become placeholders like <PERSON_7K9X>; the model works on text with detected identifiers replaced; restoration follows the configured local or gateway workflow. Remaining context may still be confidential; tool coverage, processing location, and audit behaviour depend on configuration.
The short version
- No ban exists — but identifiable client data in public AI tools is treated as a confidentiality breach.
- The Upper Tribunal has already accepted that pasting client letters into ChatGPT was a data breach.
- Combine approved provider agreements with masking controls on supported tools and workflows.
- Evidence matters: an audit trail of what was masked turns policy into something you can demonstrate.
Related questions
Is ChatGPT Enterprise enough on its own?
It covers the tool it contracts for. The gap is everything else: free-tier use, other AI tools, personal devices. Most firms combine an approved enterprise tool with technical controls on supported tools and workflows.
What happened to the adviser in the tribunal case?
He accepted the breach and self-reported to the SRA and the IAA; the tribunal said it would have referred him had he not. There was no fine in that case — the exposure is regulatory referral, potential unlimited fines or striking-off at the disciplinary stage, and UK GDPR liability.
Does masking client data change the legal position?
It changes what the AI provider receives: text with detected identifiers replaced; the remaining content may still be confidential. This can reduce identifiable data exposure, but it is not a legal guarantee, and firms still need policy and appropriate provider terms.
This page is general information, not legal advice. Where third-party guidance or law is summarised, read the originals via the source links before relying on them. Last reviewed: 17 July 2026.
This is the control in action
Identifiable data is masked in the browser before the prompt ever leaves — try it yourself with a sample prompt, or bring one low-risk workflow to a 20-minute review.
Advise Sarah Thompson, NI AB123456C, on the settlement offer.
Advise <PERSON_7K9X>, NI <NI_8W1R>, on the settlement offer.