This guide is written for solicitors, trainees and law students in England and Wales.
What should happen before client material touches an AI tool?
Before anything from a client file goes into an AI tool, a firm needs to know where the data travels: whether the provider retains inputs, trains on them, or can access them. The Upper Tribunal observed in Munir [2026] UKUT 81 (IAC) at [60] that uploading confidential documents into an open-source tool such as ChatGPT places the information in the public domain, breaching confidentiality and waiving privilege. This checklist turns that warning into something a firm can act on.
The scale of the exposure is not hypothetical. Shadow use of consumer AI tools inside firms, the subject of the figures we reported on 3 August, means the question for most compliance officers is no longer whether client material has touched such a tool but how recently, and the answer determines whether the remaining task is prevention or notification.
A fee earner pasting a draft letter into a free chatbot to tidy the wording is not making a technology decision; they are making a disclosure decision, and on the tribunal’s reasoning it may be an irreversible one. The protective steps are cheap and the remedial ones are not, so the time to draw the line between controlled and uncontrolled environments is before the first upload, in writing, for everyone who touches a file.
Who this checklist is for
This checklist is for compliance officers for legal practice, managing partners setting firm AI policy, and any solicitor supervising fee earners who draft with these tools, which after the past year of adoption is close to all of them. It assumes no technical background, and it treats the question as one of professional conduct and information governance rather than of software preference.
What does Munir decide, and what does it not?
Precision matters here, because several summaries in circulation overstate the decision. Munir v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC) was a decision of a three-judge panel of the Upper Tribunal, promulgated on 17 November 2025 and published on 19 February 2026, exercising the Hamid jurisdiction over the professional conduct of representatives in two joined immigration matters where filed documents cited authorities that did not exist. In the first, an accredited adviser admitted using ChatGPT in his work, including putting draft client emails and Home Office decision letters into the tool; in the second, a firm attributed judicial review grounds containing fabricated citations to a junior fee earner, and the tribunal’s concern was the supervisory failure that let them reach the court under a statement of truth.
The confidentiality passage is an observation made in that conduct context. The tribunal was not asked to decide whether privilege had in fact been lost on the facts of either case, and a decision of the Upper Tribunal does not bind the High Court, so the proposition that uploading equals waiver remains persuasive guidance rather than settled law. It is nonetheless the clearest English statement available, it points firms towards their regulator and the Information Commissioner’s Office where confidential material has been uploaded, and no sensible policy waits for a High Court judgment before treating it as the working assumption.
What the decision line does settle beyond argument is the citation point. From the earlier Hamid case law through Munir itself, a representative who files authority they have not verified answers for it personally, whatever tool produced the text, and the tribunal referred conduct in both joined cases to the relevant regulators.
Why “controlled” and “uncontrolled” beats “open” and “closed”
The open and closed labels obscure more than they reveal, because a nominally closed enterprise deployment can still retain prompts for abuse monitoring, and a consumer product can offer settings that disable training. What determines the confidentiality analysis is the data journey: where an input goes, who at the provider can see it, how long it is kept, and whether it feeds model training. Commentary since Munir, including the analysis published by 4 New Square, has converged on that framing, and it is the one this checklist adopts. A firm that can answer those four questions for a given tool, in writing, from the provider’s terms rather than from marketing copy, knows whether the environment is controlled; a firm that cannot answer them should treat the tool as uncontrolled regardless of what the label says.
| Question | Controlled environment | Uncontrolled environment |
|---|---|---|
| Are inputs used to train models? | Contractually excluded | Permitted by default, or unclear |
| Are inputs retained? | Defined retention period, deletable on request | Indefinite or unstated retention |
| Who can access inputs? | The firm, under an enterprise agreement with confidentiality terms | The provider, on consumer terms the fee earner accepted personally |
| Where does the data sit? | Known jurisdiction, covered by the firm’s UK GDPR arrangements | Unknown, outside any processor agreement |
| Who agreed the terms? | The firm, after review | An individual clicking through a sign-up screen |
The checklist
- Inventory every AI tool in actual use across the firm, including personal accounts on work devices, because policy written for the tools the firm bought does nothing about the tools the fee earners found.
- Classify each tool as controlled or uncontrolled against the table above, using the provider’s current terms, and record the classification with a review date, since providers change retention and training terms without ceremony.
- Prohibit client-identifying or privileged material in uncontrolled environments outright, in a written policy that names examples a busy fee earner will recognise: draft letters, attendance notes, decision letters, medical records, anything from the file.
- For controlled tools, define what may be entered and by whom, and keep the enterprise terms, the data processing agreement and the training exclusion where the COLP can produce them.
- Map the obligations engaged, which for solicitors include the duty of confidentiality in paragraph 6.3 of the Code of Conduct, the competence and supervision requirements the tribunal pressed on in Munir, and UK GDPR duties where inputs contain personal data.
- Require human verification of every authority, quotation and factual assertion in AI-assisted drafting before it is filed or sent, and make the supervisor signing a statement of truth confirm that the check happened.
- Decide the incident route now: who assesses whether an upload has occurred, who considers notification to the client, to the SRA and to the ICO (the two bodies Munir itself points towards), and who assesses whether a personal data breach is reportable within 72 hours.
- Train on the reasoning, not just the rule, because a fee earner who understands that a free chatbot may retain and learn from what they paste will hold the line when the policy document is not in front of them.
- Revisit the classification whenever a tool is updated, an account tier changes, or guidance lands from the SRA, the judiciary or the courts, all three of which are moving.
What if confidential material has already been entered?
Establish exactly what went in, into which tool, on which account tier and under which settings, because the analysis differs sharply between an enterprise deployment with training excluded and a personal free account. Then take the provider’s routes for deletion where they exist, assess the personal data breach question against the 72-hour clock, and confront the harder judgment calls: whether the client must be told, whether the matter is notifiable to the SRA, and whether a report to the ICO is prudent, which is the course Munir commends for regulated professionals. Whatever is decided, record the reasoning at the time. A firm that discovers historic uploads and responds with a documented assessment is in a defensible position; a firm that decides not to look is not.
Common mistakes
- Reading Munir as a binding rule that any AI use waives privilege, when the tribunal did not decide privilege on the facts and does not bind the High Court; the overstatement leads firms to ban useful controlled tools while the uncontrolled ones stay in quiet use.
- Trusting the open or closed label instead of the provider’s actual retention and training terms.
- Writing a policy that covers the firm’s procured tools and says nothing about personal accounts, which is where the shadow use lives.
- Treating verification of citations as a junior task, when the statement of truth belongs to the person who signs it.
- Handling a discovered upload as an IT matter rather than a conduct and data protection matter with a clock running.
Official sources
The decision is published on the tribunal decisions service: UK and R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC). The professional obligations engaged are in the SRA Standards and Regulations, and data protection guidance for organisations is at the Information Commissioner’s Office. Our short report of the decision appears in this week’s roundup, the privilege boundary in litigation is covered in our Bourlakova analysis, and adjacent information governance questions are addressed in our guide to message retention and disclosure.
Date last updated: 10 August 2026.