The regulators have already written the rules for AI and client data
There is no single UK AI Act — instead, the Law Society, SRA, Bar Council, the judiciary, the ICO, the Data (Use and Access) Act 2025, and the FCA each set expectations for how regulated teams use AI with confidential data. This hub summarises each source with verbatim lines, links to the originals, and maps every expectation to a practical technical control. Each page carries the date it was last reviewed.
The seven sources that matter
Each page: what the guidance says (verbatim), what it means for your firm, and how it maps to technical controls.
Generative AI – the essentials
No confidential data into public generative AI tools; use fictional data for testing — the baseline for solicitors.
Read the summaryRisk Outlook report: the use of artificial intelligence in the legal market
The regulator frames AI adoption itself as expected — the risk is adopting it without controls, or not adopting it at all.
Read the summaryConsiderations when using ChatGPT and generative AI software based on large language models
Extreme vigilance with privileged or confidential information in LLMs; never input personal data into prompts.
Read the summaryArtificial Intelligence (AI) — Guidance for Judicial Office Holders
Anything entered into a public AI chatbot "should be seen as being published to all the world."
Read the summaryResponse to the consultation series on generative AI
The ICO has moved from consultation to enforcement posture on generative AI — with a statutory AI code in the pipeline.
Read the summaryData (Use and Access) Act 2025 (c. 18)
The UK’s data reform act: ADM rules relaxed but conditioned, complaints procedures mandatory, ICO AI code incoming.
Read the summaryAI and the FCA: our approach
No AI-specific rulebook: Consumer Duty and SM&CR already cover AI use — accountability sits with named senior managers.
Read the summaryUK guidance map
One table: every NeutralAI control mapped to the guidance lines it addresses, across all seven sources.
Open the mapAI Confidentiality Checklist for Law Firms
Thirty practical questions across usage discovery, client-data exposure, policy, technical controls, audit evidence, and incident readiness — with a scoring guide. Built for partners, COLPs, DPOs, and IT leads who need a structured 20-minute review, not a compliance lecture.
Not legal advice; the checklist is a practical starting point for reviewing AI confidentiality risk.
Common questions
Is there a single UK regulator for AI use in professional firms?
No. AI use is governed through existing regimes: the ICO for data protection, the SRA and Law Society for solicitors, the Bar Council and BSB for barristers, the FCA for financial services, and the courts through rulings and judicial guidance. This hub maps each source to the technical controls that address it.
Do these rules apply to a small firm without a security team?
Yes. Confidentiality, data protection, and accountability expectations apply at every firm size — none of the guidance carves out small firms. The practical difference is that small firms need controls that install in minutes rather than enterprise deployment projects.
Has anyone actually been sanctioned for pasting client data into AI?
The Upper Tribunal in Munir v SSHD ([2026] UKUT 81) accepted that a legal representative pasting Home Office letters into ChatGPT was a data breach, with self-reporting to regulators. There is not yet an ICO fine specifically for AI prompt leakage — the first law-firm fine (DPP Law, April 2025) was for basic security failures.
What is the fastest way to assess our exposure?
Work through the AI Confidentiality Checklist on this page — usage discovery, data exposure, policy, technical controls, audit evidence, and incident readiness in about 20 minutes. It is not a compliance assessment; it is a structured way to find the gaps.
Want to see the controls behind the mapping?
NeutralAI masks client-identifiable data in prompts and uploads before they reach AI tools, keeps a reversible vault with a 15-minute TTL, and logs audit-friendly evidence of every control. See the published accuracy benchmark, or bring one low-risk workflow to a 20-minute review.
This hub summarises third-party guidance for convenience and is not legal advice. Sources are linked on every page — read the originals before relying on them. Last reviewed: 17 July 2026.