The regulatory landscape for AI in UK law firms has shifted significantly in 2026. The SRA has issued multiple Warning Notices, the ICO has published detailed AI guidance, and the EU AI Act โ despite Brexit โ has extraterritorial reach affecting many UK practices. This guide sets out exactly where things stand and what your firm must do.
Key takeaway: UK solicitors face a patchwork of obligations โ SRA Code of Conduct, UK GDPR, ICO AI guidance, and in some cases the EU AI Act. The common thread: you remain personally responsible for any AI output used in client work, and client data uploaded to cloud AI is almost certainly a breach of your professional duties.
1. The SRA's position on AI in 2026
The Solicitors Regulation Authority has been clear since its first Shadow AI Warning Notice: using unsanctioned AI tools with client data is a disciplinary risk. In 2026, the SRA's position has hardened.
The key provisions of the SRA Code of Conduct for Solicitors engaged by AI use are:
- Paragraph 6.3 โ you must keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.
- Paragraph 6.4 โ you must not use or attempt to use confidential information for the benefit of anyone other than the client.
- Paragraph 4.2 โ you must not abuse your position by taking unfair advantage of clients or others.
- Paragraph 3.3 โ you must ensure that work is competently carried out โ which includes understanding the limitations of any AI tool used.
The SRA has confirmed that uploading client files to a cloud-based AI without explicit client consent is likely to breach paragraph 6.3. The fact that the provider claims "we don't train on your data" is not sufficient โ the data still leaves your control.
โ ๏ธ Shadow AI: The SRA defines "Shadow AI" as AI tools used by staff without firm-level approval or governance. Firms are expected to have a written AI policy covering which tools are approved, how they may be used, and how outputs must be reviewed before being relied upon.
2. Legal Professional Privilege and AI
This is the most serious risk for litigators and those advising on contentious matters. Legal Professional Privilege (LPP) โ whether litigation privilege or legal advice privilege โ can be waived irreversibly if privileged communications are disclosed to a third party without necessity.
When you upload a client's privileged documents to a cloud AI service, you are disclosing them to a third party: the AI provider. Even if the provider's terms state they do not access or store the data, courts have taken a strict view of LPP waiver. The risk is not theoretical โ it is structural.
The only way to guarantee that LPP is maintained is to ensure that privileged communications are processed only within systems entirely under your control. A self-hosted AI solution โ one installed physically within your firm's network โ achieves this. A cloud service, however well-intentioned, cannot.
3. UK GDPR and the DPA 2018
As a law firm, you are a data controller under the UK GDPR. Your clients' personal data โ names, addresses, financial details, health information โ must be processed in accordance with the six lawful bases, and you must ensure appropriate technical and organisational measures to protect it.
When you use a cloud AI tool, you are engaging a data processor (the AI provider). Under Article 28 UK GDPR, you must have a written Data Processing Agreement (DPA) with that processor before any processing occurs. Many solicitors using ChatGPT, Copilot or similar tools have no such agreement in place.
Furthermore, if the AI provider is based outside the UK (as most are โ US-based), you must ensure an appropriate transfer mechanism is in place under UK GDPR Chapter V. The ICO's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs are the main options. Again, most solicitors using consumer-grade AI tools have not put these in place.
4. ICO AI Guidance 2026
The Information Commissioner's Office published updated AI guidance in early 2026. The key points for law firms:
- AI systems must be explainable โ you must be able to explain to clients how decisions affecting them were made, if AI was involved.
- Data minimisation applies โ you should not feed an AI more personal data than is necessary for the task.
- Accuracy obligations are heightened โ AI outputs must be checked for accuracy before being relied upon, especially in legal contexts where errors can have serious consequences.
- Automated decision-making provisions (Article 22 UK GDPR) apply where AI makes decisions with significant effects on individuals โ which may include AI-generated risk assessments or predictive litigation analysis.
5. The EU AI Act โ does it apply to UK firms?
Strictly speaking, the EU AI Act does not apply in the UK post-Brexit. However, it has extraterritorial effect in two situations relevant to UK law firms:
- If you advise EU clients โ if the output of your AI is used to provide services to individuals in the EU, the AI Act's provisions on high-risk AI systems may apply.
- If you use EU-based AI providers โ providers established in the EU must comply with the AI Act, and those obligations flow downstream to users.
Legal AI tools are classified under the AI Act's high-risk category (Annex III, point 6 โ administration of justice). This means providers must register their systems, conduct conformity assessments, and maintain technical documentation. As a deployer, you should verify that any AI tool you use has complied with these requirements if it falls within scope.
6. What your firm must do in 2026
Based on the current regulatory position, every UK law firm using or considering AI should take the following steps:
- Write a firm AI policy โ covering which tools are approved, permissible use cases, mandatory human review of outputs, and confidentiality obligations.
- Audit existing AI use โ identify any Shadow AI being used by staff without firm approval.
- Review your data processor agreements โ ensure DPAs are in place with any AI provider processing personal data.
- Check international transfer mechanisms โ ensure IDTA or UK Addendum SCCs are in place for any US-based provider.
- Consider self-hosted alternatives โ for any work involving privileged communications or sensitive personal data, a self-hosted AI that processes data entirely within your firm's network is the only way to eliminate LPP and UK GDPR risk structurally.
- Train your staff โ ensure all fee-earners understand the LPP and UK GDPR implications of AI use. This training is also eligible for SRA CPD points.
LegisBox eliminates these risks by design
Installed physically in your firm. No data ever leaves your network. No DPA required for client files. LPP maintained absolutely. SRA compliant.
Book a demo โ