All questions
Case lawReviewed 17 July 2026

What did the UK tribunal say about ChatGPT and client data?

The short answer

In Munir v SSHD [2026] UKUT 81 (IAC) — promulgated in November 2025 — the Upper Tribunal dealt with a legal representative who had used ChatGPT to summarise Home Office decision letters and improve client emails. Asked to explain his process at a hearing, he accepted it amounted to a data breach and undertook to notify his clients and regulators. The tribunal characterised uploading such material to an open AI tool as placing it in the public domain, breaching client confidentiality — and distinguished open tools from closed systems running inside a secure network.

What actually happened

The uses were mundane: polishing the wording of emails to clients, and uploading Home Office decision letters so the tool could summarise them. That ordinariness is the point — this was a busy professional using an available tool to work faster, which is precisely why it is predictable and repeatable in any firm.

The conduct surfaced during a tribunal hearing. The representative set out his process, accepted on the spot that it was a data breach, and said he would notify affected clients, the SRA, and the immigration regulator. The tribunal noted it would have referred him to both regulators had he not already self-reported.

Why the reasoning matters beyond this case

The tribunal’s framing — that placing client information into an open AI system puts it in the public domain — matches the judiciary’s own AI guidance, which tells judges to treat anything entered into a public AI chatbot as published to all the world. Two different judicial sources now describe the same act the same way.

The ruling also drew a line the industry should notice: it distinguished open tools from closed AI systems operating inside a secure network, which it accepted could summarise material without those risks. The safe path is not "no AI" — it is AI where confidential content never reaches the open tool. Masking identifiers before the prompt leaves achieves that boundary at the point of use.

What the exposure actually is

There was no fine in this case, because the representative self-reported. The exposure sits behind that: an SRA referral can end in unlimited fines, suspension, or striking off; a reportable breach engages UK GDPR, where penalties reach £17.5 million or 4% of turnover; and confidentiality, once lost to an open system, cannot be recalled.

The short version

  • Promulgated November 2025; press coverage followed in February 2026 — cite the case, not the news wave.
  • Routine use — email polish and letter summaries — was accepted to be a data breach.
  • The tribunal treats open-AI upload as publication to the public domain.
  • Closed systems in secure networks were explicitly distinguished — the control point is what reaches the open tool.

Related questions

Was the person involved fined or struck off?

No penalty was imposed in the ruling itself — he self-reported to the SRA and the IAA. The tribunal said it would have referred him had he not. The disciplinary and data protection processes carry the real exposure.

Does this ruling apply to all law firms?

It is an Upper Tribunal decision arising from immigration proceedings, but its reasoning about confidentiality and open AI tools is general — and it aligns with Law Society guidance and the judiciary’s own AI guidance. Prudent firms treat it as the current judicial view.

Would masking have changed this outcome?

The breach turned on client-identifiable material reaching an open tool. If the letters had been masked before upload — names, references, and identifying details replaced — the open tool would have received de-identified text. That is a materially different disclosure, though masking is a risk-reduction control, not a retroactive legal fix.

This page is general information, not legal advice. Where third-party guidance or law is summarised, read the originals via the source links before relying on them. Last reviewed: 17 July 2026.

This is the control in action

Identifiable data is masked in the browser before the prompt ever leaves — try it yourself with a sample prompt, or bring one low-risk workflow to a 20-minute review.

prompt → modelmasked before send
You type

Advise Sarah Thompson, NI AB123456C, on the settlement offer.

The model receives

Advise <PERSON_7K9X>, NI <NI_8W1R>, on the settlement offer.