The Solicitors Regulation Authority has issued formal Warning Notices on the use of AI tools in legal practice โ specifically on what the SRA calls "Shadow AI": the use of unapproved, personal or consumer-grade AI tools in professional contexts. This guide explains what the notices say, which Code of Conduct obligations are engaged, and what your firm needs to do.
Shadow AI refers to the use of AI tools that have not been formally approved or procured by the firm โ typically consumer-grade tools like ChatGPT, Claude, Gemini or Copilot used through personal accounts, or business accounts that have not been vetted for data protection compliance in a legal context.
It is called "shadow" because it often happens without the firm's management or compliance officers knowing โ individual fee earners using tools they find helpful without realising the professional and regulatory implications.
The SRA Warning Notices identify several specific obligations in the SRA Code of Conduct 2019 that Shadow AI puts at risk:
You must keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. Uploading client files to a cloud AI constitutes disclosure to a third party โ the AI provider โ without client consent. This is a direct breach of 6.3.
You must not use confidential information for the benefit of anyone other than the client. If a cloud AI provider uses client data to improve its models, that is precisely what happens โ the client's confidential information benefits the AI provider's product development.
You must ensure that the work you and your firm carry out is competent and delivered in a timely manner. The SRA has indicated that using AI tools without understanding their limitations, verifying their outputs, or ensuring they are appropriate for the task may itself be a competence issue.
Managers of firms must have effective governance arrangements and clear accountability. Failing to have an AI policy that addresses Shadow AI risks โ or having a policy but failing to enforce it โ can engage the firm-level obligations under Paragraph 7.
One of the most important points in the SRA's guidance is that a cloud provider claiming to host data in the UK does not eliminate the risks. The SRA specifically notes that:
The SRA's guidance sets out clear expectations for compliant AI use:
With a cloud AI tool, achieving SRA compliance requires managing a complex web of DPAs, DPIAs, sub-processor agreements and ongoing monitoring. Each new tool version or sub-processor change may require a new assessment.
With a self-hosted solution like LegisBox, the compliance picture is fundamentally simpler. Because client data never leaves the firm's network, the DPIA for client matter processing concludes with a straightforward finding: no third-party processing, no transfer risks, no sub-processor concerns. The SRA's requirements on confidentiality and data security are met by the architecture itself.
No Shadow AI risk. No DPA required for client data. Legal Professional Privilege and UK GDPR protected by architecture.
Book a demo โ