About Newsletter Contact
Checklist

AI tools, confidentiality and privilege: a checklist before anything touches a client file

Before client material touches an AI tool, firms need to know where the data goes. A checklist built on Munir: controlled environments, verification duties, and what to do after upload.

Last UpdatedAugust 2026
6 min read Professional Conduct
Who This Guide Is For

This guide is written for solicitors, trainees and law students in England and Wales.

Solicitors Trainees Law Students Professional Conduct

What should happen before client material touches an AI tool?

Before anything from a client file goes into an AI tool, a firm needs to know where the data travels: whether the provider retains inputs, trains on them, or can access them. The Upper Tribunal observed in Munir [2026] UKUT 81 (IAC) at [60] that uploading confidential documents into an open-source tool such as ChatGPT places the information in the public domain, breaching confidentiality and waiving privilege. This checklist turns that warning into something a firm can act on.

The scale of the exposure is not hypothetical. Shadow use of consumer AI tools inside firms, the subject of the figures we reported on 3 August, means the question for most compliance officers is no longer whether client material has touched such a tool but how recently, and the answer determines whether the remaining task is prevention or notification.

Why it matters

A fee earner pasting a draft letter into a free chatbot to tidy the wording is not making a technology decision; they are making a disclosure decision, and on the tribunal’s reasoning it may be an irreversible one. The protective steps are cheap and the remedial ones are not, so the time to draw the line between controlled and uncontrolled environments is before the first upload, in writing, for everyone who touches a file.

Who this checklist is for

This checklist is for compliance officers for legal practice, managing partners setting firm AI policy, and any solicitor supervising fee earners who draft with these tools, which after the past year of adoption is close to all of them. It assumes no technical background, and it treats the question as one of professional conduct and information governance rather than of software preference.

What does Munir decide, and what does it not?

Precision matters here, because several summaries in circulation overstate the decision. Munir v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC) was a decision of a three-judge panel of the Upper Tribunal, promulgated on 17 November 2025 and published on 19 February 2026, exercising the Hamid jurisdiction over the professional conduct of representatives in two joined immigration matters where filed documents cited authorities that did not exist. In the first, an accredited adviser admitted using ChatGPT in his work, including putting draft client emails and Home Office decision letters into the tool; in the second, a firm attributed judicial review grounds containing fabricated citations to a junior fee earner, and the tribunal’s concern was the supervisory failure that let them reach the court under a statement of truth.

The confidentiality passage is an observation made in that conduct context. The tribunal was not asked to decide whether privilege had in fact been lost on the facts of either case, and a decision of the Upper Tribunal does not bind the High Court, so the proposition that uploading equals waiver remains persuasive guidance rather than settled law. It is nonetheless the clearest English statement available, it points firms towards their regulator and the Information Commissioner’s Office where confidential material has been uploaded, and no sensible policy waits for a High Court judgment before treating it as the working assumption.

What the decision line does settle beyond argument is the citation point. From the earlier Hamid case law through Munir itself, a representative who files authority they have not verified answers for it personally, whatever tool produced the text, and the tribunal referred conduct in both joined cases to the relevant regulators.

Why “controlled” and “uncontrolled” beats “open” and “closed”

The open and closed labels obscure more than they reveal, because a nominally closed enterprise deployment can still retain prompts for abuse monitoring, and a consumer product can offer settings that disable training. What determines the confidentiality analysis is the data journey: where an input goes, who at the provider can see it, how long it is kept, and whether it feeds model training. Commentary since Munir, including the analysis published by 4 New Square, has converged on that framing, and it is the one this checklist adopts. A firm that can answer those four questions for a given tool, in writing, from the provider’s terms rather than from marketing copy, knows whether the environment is controlled; a firm that cannot answer them should treat the tool as uncontrolled regardless of what the label says.

Question Controlled environment Uncontrolled environment
Are inputs used to train models? Contractually excluded Permitted by default, or unclear
Are inputs retained? Defined retention period, deletable on request Indefinite or unstated retention
Who can access inputs? The firm, under an enterprise agreement with confidentiality terms The provider, on consumer terms the fee earner accepted personally
Where does the data sit? Known jurisdiction, covered by the firm’s UK GDPR arrangements Unknown, outside any processor agreement
Who agreed the terms? The firm, after review An individual clicking through a sign-up screen

The checklist

What if confidential material has already been entered?

Establish exactly what went in, into which tool, on which account tier and under which settings, because the analysis differs sharply between an enterprise deployment with training excluded and a personal free account. Then take the provider’s routes for deletion where they exist, assess the personal data breach question against the 72-hour clock, and confront the harder judgment calls: whether the client must be told, whether the matter is notifiable to the SRA, and whether a report to the ICO is prudent, which is the course Munir commends for regulated professionals. Whatever is decided, record the reasoning at the time. A firm that discovers historic uploads and responds with a documented assessment is in a defensible position; a firm that decides not to look is not.

Common mistakes

Official sources

The decision is published on the tribunal decisions service: UK and R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC). The professional obligations engaged are in the SRA Standards and Regulations, and data protection guidance for organisations is at the Information Commissioner’s Office. Our short report of the decision appears in this week’s roundup, the privilege boundary in litigation is covered in our Bourlakova analysis, and adjacent information governance questions are addressed in our guide to message retention and disclosure.

Date last updated: 10 August 2026.