The judiciary’s AI guidance: the clearest line in UK legal AI
Artificial Intelligence (AI) — Guidance for Judicial Office Holders
- Issued by
- Courts and Tribunals Judiciary
- Published
- 12 December 2023
- Updated
- 31 October 2025
- We reviewed
- 17 July 2026
The judiciary’s AI guidance for judicial office holders (December 2023, updated October 2025) contains the single clearest sentence in UK legal AI: any information you input into a public AI chatbot "should be seen as being published to all the world." Judges are told not to enter anything that is not already public. The October 2025 update also added warnings about white text and hidden prompts embedded in documents. If that is the standard the bench applies to itself, it is a reasonable benchmark for anyone handling confidential material.
What the guidance says
“Do not enter any information into a public AI chatbot that is not already in the public domain.”
“Any information that you input into a public AI chatbot should be seen as being published to all the world.”
The October 2025 version added a glossary entry for "white text" and warns about hidden prompts concealed in documents — visible to the system but not the human reader.
Coverage is broad: all judicial office holders plus clerks, judicial assistants, and legal advisers under the Lady Chief Justice and Senior President of Tribunals.
What this means for your firm
- The "published to all the world" framing is the same reasoning the Upper Tribunal applied in Munir v SSHD when a representative pasted client letters into ChatGPT — this is now a consistent judicial position.
- If a matter may end up before a judge, assume the judge holds this view of what pasting into a chatbot means.
- The white-text warning matters for document uploads: what a human reviewer sees is not necessarily what the model receives.
- The operational answer is the same as everywhere else in this hub: make sure non-public information physically cannot reach the public tool.
Guidance → control, line by line
How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.
Nothing non-public into public AI chatbots
Client-identifiable and confidential specifics are replaced before submission, so the public tool receives only de-identified content.
Treat inputs as irreversible publication
Because real values never leave the firm, there is nothing to "recall" from the provider — restoration happens locally, and vault entries expire by default.
Beware hidden content in documents
Uploads are scanned before submission, on the same masked path as typed prompts — reducing the gap between what a human sees and what the model receives.
Common questions
Does the judiciary’s guidance apply to law firms?
Not directly — it binds judicial office holders and their support staff. Its wider value is as a benchmark: it shows how the bench itself characterises entering information into public AI tools, which informed the Upper Tribunal’s reasoning in Munir v SSHD.
What is the "white text" warning about?
Hidden prompts or concealed text can be embedded in a document so the system reads instructions a human reviewer cannot see. The October 2025 update added this to the guidance glossary — it is a document-upload risk, not just a chat risk.
What changed between the 2023 and 2025 versions?
The core confidentiality position is unchanged. The chain is December 2023 → April 2025 → October 2025, with the latest version adding the white-text/hidden-prompt warnings and updated definitions. Read the current version at the source link.
This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.
See what this control looks like in practice
The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.
The control
detect → mask → send → restore → audit
Reversible vault, 15-minute TTL. The model only ever sees placeholders.