Using AI Safely in Regulated Professions
IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.
Solicitors and other regulated professionals may use AI to support tasks such as summarisation, document preparation, research planning and administrative checking. The professional remains responsible for confidentiality, accuracy, legal and factual verification, client interests and anything submitted in their name. Sensitive information should enter only approved systems, critical sources and deadlines must be checked independently, and AI should not file, send or make rights-affecting decisions without authorised human approval.
Professional regulation exists because clients, courts, markets and the public place trust in the people and organisations whose work can directly affect rights, money, freedom, property, employment and health. AI does not inherit that trust. It does not accept a professional duty. It does not carry professional indemnity insurance. It cannot appear before a court to explain itself.
That does not mean regulated professionals should avoid AI. It means they should use it in a way that keeps professional responsibility where it legally and professionally belongs — with the qualified person who has accepted it.
AI may assist professional work. It does not inherit the professional's duty, judgement or accountability.
This guide uses solicitors in England and Wales as the clearest detailed example, because their regulatory framework, court obligations and professional duties are well documented and publicly stated. Similar principles apply, in ways specific to each sector's rules, to accountants, financial advisers, insurance professionals, surveyors, architects, HR professionals, healthcare organisations, regulated consultants, public bodies and compliance teams. This guide does not apply any profession's rules identically to another.
The Quick Answer
Regulated professionals may use AI to assist with preparation, document drafting, research planning and administrative tasks. Responsibilities that remain with the professional include:
- Confidentiality and privilege
- Accuracy and factual verification
- Checking legal sources and authorities
- Independent calculation of critical dates
- Assessment of client interests
- Final judgement on advice, strategy and recommendations
- Approval of anything submitted, filed, signed or sent externally
Your signature, submission or advice remains your responsibility — even when software prepared the first version.
Last checked: 6 August 2026. Verify all regulatory, SRA, Law Society and judiciary guidance against current official sources before acting on it.
Solicitors in England and Wales — current position
Solicitors in England and Wales are not generally prohibited from using generative AI or other legal technology. The Solicitors Regulation Authority does not ban the use of particular AI tools by name. What the SRA's regulatory framework requires is that solicitors meet professional obligations regardless of the tools they use.
Current SRA regulatory expectations relevant to AI include: maintaining competence, including understanding the technology used; protecting client confidentiality; maintaining legal professional privilege where it applies; complying with data protection law; ensuring that suppliers used to assist with client work are appropriate and that risks are managed; supervising work carried out under the firm's authority; providing accurate and non-misleading advice and court material; considering equality and bias where AI is used in decisions; keeping appropriate records; and maintaining adequate insurance.
The Law Society has issued practice notes and guidance on AI, covering areas including legal professional privilege, confidentiality and human oversight. The position is developing as AI capabilities, case law and regulatory guidance evolve. Verify the current SRA and Law Society positions using their official sources before acting.
The tool can produce the draft. The solicitor remains responsible for what is advised, signed, filed or submitted.
A solicitor remains responsible for work performed in their name, including work assisted by junior staff, contractors, outsourced providers, software or AI systems. Delegation does not transfer professional responsibility.
Other regulated professions
Similar principles apply across regulated sectors, though the specific rules, regulators and requirements differ. Accountants and auditors operate under ICAEW, ACCA and FRC standards and must maintain professional scepticism, audit quality and client confidentiality. Financial advisers and wealth managers operate under FCA rules requiring advice to be suitable, accurate and demonstrably in the client's interest. Insurance professionals have duties of accuracy and fair dealing. Surveyors, architects and engineers carry professional responsibility for advice, calculations and signed documents. HR professionals and employers face obligations around fairness, discrimination and employment law. Healthcare organisations are subject to clinical governance, patient confidentiality, CQC requirements and NHS data standards.
In each case, the question is not simply whether AI may be used. It is whether AI is being used in a way that is consistent with the specific obligations of the regulated sector, the professional's duty to clients or patients, data protection law and the standards the regulator enforces.
Court documents and AI
The judiciary in England and Wales has issued guidance for legal professionals using AI for court work. The Courts and Tribunals Judiciary issued interim guidance in 2023 and has consulted further on AI in the courts. Verify the current status of any guidance, consultation or formal procedural rule against official judiciary sources before acting.
It is important to distinguish between the categories of material that may affect practice in this area:
- Current professional duty: the existing responsibility to provide accurate, non-misleading material to the court — which applies regardless of whether AI was used
- Guidance: advice issued by regulators or the judiciary about how duties apply to AI-assisted work
- Consultation: a proposal being considered — not yet a binding requirement
- Formal rule: a binding procedural or regulatory requirement once adopted
Never present a consultation proposal as though it is already a binding court rule.
Cases in multiple jurisdictions have resulted in professional consequences where AI-generated legal citations that did not exist were submitted to courts without verification. In England and Wales, the existing duty of candour to the court applies fully to AI-assisted work. Submitting fabricated or unverified material to a court, regardless of how it was generated, is a serious professional matter. Check current SRA and judiciary sources for any specific guidance or requirements that have been adopted since this guide was last reviewed.
Legal research and hallucinated authorities
Generative AI systems may produce plausible but entirely invented legal citations. This is not a rare edge case — it has been observed across multiple platforms and has resulted in disciplinary and court proceedings when fabricated citations were submitted without verification.
AI may invent cases, citations, judges, quotations, legislation, procedural rules, dates, links and legal propositions. Each may appear entirely credible. The output may contain accurate references alongside invented ones, making selective checking insufficient.
A plausible citation is not a legal authority until somebody has opened and checked the source.
For every legal authority used in professional work, verify through an authoritative legal database or primary source: that the case exists; that the neutral citation is correct; that the court is correctly identified; that any quoted passage appears in the actual judgment; that the legal proposition it supports is genuinely what the case decides; that the decision has not been overruled, distinguished or reversed; that subsequent treatment has been considered; and that the jurisdiction is relevant to the matter.
AI-generated legal summaries are a starting point for research, not a substitute for it. Professional reliance on AI output without independent verification is a professional responsibility question, not a technology question.
Confidentiality and privilege
Professional information may include client identity, case facts, legal advice, litigation strategy, privileged communications, medical information, financial information, employee records, commercial negotiations, witness statements, settlement positions and security information. The appropriate AI tool, account type and contractual arrangements depend on the specific nature of that information.
Consumer AI tools operate under general consumer terms with limited organisational control. Business or enterprise AI services are contracted services with additional administration, security and data commitments that vary by supplier and agreement. Private or controlled deployments operate within a defined technical and contractual environment. These are meaningfully different categories — the question is not simply which product name appears on the login screen.
A secure product may still be used insecurely, unlawfully or outside the client's reasonable expectations.
Enterprise branding alone does not make every use lawful or professionally appropriate. The relevant questions are: what data enters the system; under what contractual terms; with what retention, training and subprocessor arrangements; and is the organisation authorised to disclose and process that information through that service given its professional obligations.
Personal data
UK data protection law applies to personal data — information relating to identifiable individuals — which includes most client, patient, counterparty and employee data that professional-services organisations handle. Entering personal data into an AI service is a disclosure and a processing activity. It requires the same legal analysis as any other disclosure.
The question is not simply whether the provider trains on the information. It is whether the organisation is authorised to disclose and process that information through the service.
Data protection obligations relevant to AI use include: identifying the correct controller and processor roles for each arrangement; establishing a lawful basis for the processing; considering transparency obligations to data subjects; applying data minimisation — providing only the information the AI task actually requires; ensuring appropriate security; understanding data retention and deletion arrangements; considering international transfers where data is processed outside the UK; addressing individual rights including subject access; assessing special-category data where relevant; and conducting data protection impact assessments where the processing involves high risk.
Consent is not automatically required — other lawful bases may apply depending on the use case. But the correct approach depends on the use case, the data, the people affected, the platform, the contract, the risk, the available safeguards and any applicable professional requirements. Removing a name does not automatically anonymise a document. The ICO has published detailed guidance on AI and data protection that should be reviewed when assessing any AI deployment involving personal data.
Professional privilege
Legal professional privilege protects confidential communications between a lawyer and client for the purpose of legal advice, and communications prepared for the dominant purpose of litigation. Privilege belongs to the client. Its protection and potential loss are matters of legal complexity.
Entering privileged or confidential information into a third-party AI service may create confidentiality risk, contractual risk, privilege concerns, disclosure risk, access by subprocessors, retention issues, data-location issues and evidential complications. This guide does not give a universal conclusion that privilege is automatically lost by using any particular service — the answer depends on specific facts, service terms and applicable case law.
Do not use uncertainty about privilege as a reason to experiment with privileged information.
Where sensitive or privileged information is involved, obtain appropriate specialist advice before proceeding. The Law Society and specialist commentators have published analysis on AI and privilege that should be consulted and verified against current authority.
First-draft use and the safe drafting sequence
AI may appropriately assist with document outlines, issue lists, chronology preparation, first-draft correspondence, document comparison, approved document summaries, internal checklists, question preparation, non-confidential research planning and formatting. These tasks involve preparation and organisation rather than the application of professional judgement.
AI should not be treated as a substitute for legal analysis, professional advice, evidential judgement, strategic decisions, final court drafting, client-specific recommendations, conflict checks or ethical decisions.
Good first-draft use saves preparation time. It does not transfer authorship responsibility.
A safer drafting sequence: define the permitted task and the approved information to be used; ask for an outline and review it before proceeding; require uncertainty to be identified explicitly; produce the first draft from approved information; verify every source and authority against primary sources; apply professional judgement; obtain final human approval before the document leaves the firm.
Deadlines and calculations
AI may assist with extracting dates from documents, identifying relevant events, preparing a draft chronology, proposing reminders and highlighting missing information. These are useful preparation tasks.
Critical deadline calculations may depend on court rules, working days, bank holidays, service methods, time zones, jurisdiction, extensions, contractual wording, event timing, exceptions and rule changes. Each of these can affect whether a deadline is correct. A draft date produced by an AI system is a suggestion, not a verified calculation.
A deadline entered into the diary is a professional commitment, not an AI suggestion.
Independent verification through authoritative rules — court practice directions, limitation statutes, contractual provisions — and approved case management systems is required for every critical date. Professional diary management systems exist precisely because the consequences of a missed deadline can be catastrophic for clients and serious for the professional.
Prompt injection and hostile documents
Documents and external material may contain instructions intended to influence an AI system — a risk described as prompt injection. Instructions can be concealed in white text within a document, in comments or metadata, in hidden spreadsheet cells, in PDFs, in email content, in websites, in document management systems or in embedded content.
A document is evidence or information. It should not gain authority merely because an AI system can read it.
Prompt injection in a professional context could cause an AI system to produce misleading output, take unexpected actions, reveal information from other parts of the context, generate content serving the interests of an adversary rather than the professional's client, or trigger tool use without human authorisation.
Controls include: treating documents as untrusted data and separating source content from system instructions; limiting the tools available to the AI to those actually needed for the task; reviewing all output rather than accepting it automatically; using secure document viewers and content inspection where appropriate; prohibiting automatic external action based solely on document content; logging AI interactions with external documents; and testing workflows against adversarial document examples.
Automated external access
AI or browser automation may be used to access court portals, regulator portals, client systems, land registries, financial platforms, government services and document portals. Each carries obligations beyond technical capability.
Professional urgency does not create permission to bypass a system owner's access controls.
Before automating access to any external system, consider: whether the organisation holds authorised access; what the system's terms of service permit; whether an official API exists and should be used instead; who owns the credentials used; what audit logs are maintained; what rate limits apply; how service availability affects workflow reliability; what data protection obligations apply to data collected; what professional obligations apply; and what happens if the automation fails.
Client communication and transparency
Whether and when to disclose AI use depends on professional rules, contractual commitments, client instructions, the materiality of the AI's contribution, data handling, service descriptions, automated decisions affecting clients and sector-specific requirements.
Situations where transparency may be particularly important include where AI materially shapes advice; where personal data enters an external service; where automated decisions affect a person; where the engagement letter restricts outsourcing or data sharing; where client instructions expressly prohibit AI use; where a regulator requires disclosure; or where the service description would otherwise be misleading.
Clients do not need a list of every software feature used, but they should not be misled about how sensitive or material work is performed.
Supplier due diligence
A professional AI supplier assessment should address: the legal entity providing the service; the specific product purpose and what the organisation intends to use it for; the account type and available organisational controls; the contract and its key terms; data ownership and what happens to inputs and outputs; whether inputs are used to train models; retention and deletion of data; the data locations used; subprocessor arrangements; encryption in transit and at rest; access controls and authentication requirements including MFA and single sign-on; audit logging capability; administrative and user-management controls; incident notification obligations and timescales; service availability and SLA arrangements; data export and portability; exit arrangements; any professional-sector-specific claims; stated accuracy limitations; model-change notification practices; insurance and liability limits; and the level of support provided.
A well-known AI brand is not a substitute for professional due diligence.
Human review levels
Not every AI-assisted task requires the same level of professional review. A proportionate model for regulated work:
Level 1 — Low-risk administration: formatting, meeting notes, non-sensitive categorisation. Routine review is appropriate. The work does not leave the firm and does not create professional records.
Level 2 — Internal professional support: issue identification, chronology drafts, internal summaries, research plans. Qualified review before any reliance is placed on the output.
Level 3 — Client-facing professional work: advice drafts, reports, client correspondence, calculations. Detailed professional review and approval before the output is sent to the client.
Level 4 — Court, regulatory or rights-affecting work: court documents, regulatory submissions, expert reports, financial recommendations, disciplinary decisions, regulated advice. Explicit qualified approval and independent verification of critical facts, law, sources and calculations.
The higher the consequence, the less acceptable it is to treat human review as a quick proofreading exercise.
Audit trail
Regulated organisations may need records demonstrating that AI-assisted work was properly controlled. Records may need to show: the approved tool used; the user; the purpose; the source material; the model or service version; the instructions provided; the output; corrections made; which sources were checked; who carried out the review; who gave approval; the date; the final version; and any incident or exception.
Proportionality applies. Records should not retain unnecessary personal data merely to create an audit trail — retention periods and data minimisation requirements apply to records as they do to other processing. The obligation is to be able to demonstrate appropriate professional accountability, not to create comprehensive surveillance of every AI interaction.
Staff competence
Professional competence now includes understanding the AI tools in use: what they can and cannot do, where they are known to fail, what information may enter them, how confidentiality and privilege apply, what security controls are required, how data protection obligations apply, where bias may arise, how to verify output, when to escalate a concern, which tools are approved and which uses are prohibited.
Training should teach staff when to stop using the AI, not merely how to obtain a better answer.
Effective training for regulated work should include realistic exercises rather than theoretical descriptions. Exercises should involve invented legal sources that look plausible, missing information that should be noticed, confidential documents that should not enter the tool, prompt injection examples, proposed deadlines that require independent checking, ambiguous instructions, and persuasive but incorrect output. The objective is professional judgement about when not to trust the AI, not just technical skill in using it.
AI use policy for regulated work
A professional firm's AI policy should address: which tools are approved and for which uses; which account types are permitted; what information is prohibited from any AI tool; what uses are permitted; which uses are high-risk and require senior review; what level of human review is required for different task types; how sources must be verified; how client instructions about AI use are recorded and followed; what approval is required before court or regulator submissions; which AI supplier arrangements have been approved; what browser automation is permitted; what records must be kept; how incidents are reported; what training is required; what disciplinary or contractor consequences apply; and who owns policy review.
Formal policies for regulated organisations should receive appropriate legal and regulatory review before adoption. This guide does not provide employment-law or contractual wording.
Regulated AI use checklist
Before using AI for regulated or professional work, work through these questions:
Purpose: Is the task suitable for AI assistance? Is an accountable professional assigned? Is the risk level defined?
Tool: Is the tool approved? Is the account appropriate for this information? Have supplier terms been reviewed? Are security controls — MFA, SSO, audit logging — enabled?
Information: Is personal data involved? Is confidential or privileged information involved? Can the information be minimised? Are the client's restrictions on data sharing known?
Output: Could it affect rights, money, liberty or legal obligations? Are facts independently checked? Are all legal authorities opened and verified against primary sources? Are calculations checked separately?
Action: Will the output be sent externally? Will it be filed with a court or regulator? Will it trigger an automated action? Is explicit approval by a qualified person required?
Record: Is the final version retained? Is the reviewer recorded? Are the sources checked recorded? Are incidents and exceptions documented?
Warning signs
Stop or escalate where any of these apply:
- Public consumer tools receive client files
- The user cannot explain the supplier terms
- AI-generated legal authorities are not checked against primary sources
- A court or limitation deadline relies solely on AI output
- A document may contain hidden instructions
- A workflow can file or send without human approval
- Client restrictions on AI use are ignored
- The output affects a person automatically without human review
- Professional privilege has not been considered before entering information
- Personal data is excessive given the task
- AI output is treated as legal research evidence rather than a starting point
- Audit records do not exist for significant AI-assisted work
- Staff use personal AI accounts for professional work
- The business has no approved-tool list
- Senior professionals delegate review entirely to junior staff
- Polished wording is mistaken for professional competence
- The organisation cannot withdraw AI access quickly if needed
When the professional cannot explain or verify the output, the output is not ready for professional use.
Practical business implications
- AI use is not generally prohibited — but professional duties still apply fully
- The professional remains responsible — software does not sign away accountability
- Confidentiality requires platform assessment — consumer and controlled business systems are not equivalent
- Legal authorities must be opened — a citation is not verified because it looks convincing
- Deadlines require independent checking — calendar errors can cause serious client harm
- Prompt injection is a document risk — files may contain hostile instructions for AI systems
- Automation needs authorisation — external systems and portals have access rules
- Client expectations matter — AI use should not make service descriptions misleading
- Audit trails support accountability — regulated work should remain explainable
- Human review must be meaningful — proofreading is not enough where judgement is required
The IT Club view
Regulated professionals should not reject useful AI merely because it creates risk. They should also not treat professional status as protection from poor technology decisions.
AI can assist with preparation, extraction, organisation, first drafts, comparison and controlled research support. It cannot accept professional responsibility.
Your signature, submission or advice remains your responsibility — even when software prepared the first version.
IT Club recommends: using only approved tools for client-related work; establishing clear data boundaries that reflect confidentiality and privilege; requiring qualified human review proportionate to the consequence of error; verifying every legal authority and calculation independently; controlling automation and requiring approval before external action; assessing AI suppliers as carefully as any other professional service provider; training staff to recognise hallucinations, prompt injection and when to stop; maintaining audit trails that support professional accountability; reporting incidents and learning from them; and reviewing AI use through an Operational Heartbeat as regulatory guidance develops.
The right goal is not to keep AI out of professional work. It is to make every material use controlled, reviewable and accountable.
Operational Heartbeat
Professional AI risk changes as staff adopt new tools, suppliers change terms, models change, integrations expand, client instructions change, court guidance develops, regulators issue new material, personal data enters workflows, audits identify gaps, incidents occur, staff leave and approved uses expand without corresponding controls.
A recurring review of professional AI use should check: which tools are approved and for which purposes; who is using each tool and which accounts are in use; what client restrictions on AI use have been recorded and followed; what data types are entering AI tools; how professional use cases have changed; whether supplier terms remain acceptable; whether models have changed in ways that affect reliability or compliance; whether court and regulator guidance has changed; whether human-review controls are being followed; whether authority-verification procedures are working; what automation is in operation; incidents and near-misses; training records; audit records; business value delivered; corrective actions taken; and the date of the next review.
AI use in regulated work needs an Operational Heartbeat: tools, data, professional duties, human review, regulatory guidance, incidents and supplier changes should be reviewed rather than assumed to remain acceptable.
Related Business Questions
Can solicitors in England and Wales use AI?
Yes. Solicitors are not generally prohibited from using AI. The SRA's regulatory framework requires that professional obligations — including competence, confidentiality and accuracy — are met regardless of the tools used. Verify the current SRA position using SRA official sources.
Does the SRA ban ChatGPT?
The SRA does not ban specific AI products by name. It requires solicitors to comply with professional obligations when using any tool. The question is whether the tool is used in a way consistent with those obligations, not whether the tool is named in a prohibited list. Verify the current SRA guidance.
Can a solicitor use AI to draft a letter?
Yes, with appropriate review. AI can assist with drafting. The solicitor remains responsible for the accuracy, appropriateness and professional quality of any letter sent to a client, court or other party. The draft requires qualified review and approval before it is sent.
Can AI prepare a court document?
AI can assist with drafting a court document. The solicitor or barrister signing, filing or presenting the document remains fully responsible for its accuracy, its compliance with court rules, the verification of every legal authority cited and its conformity with duties to the court. AI-generated court documents must receive detailed professional review before filing.
Must AI use be disclosed to the court?
Verify the current position against judicial guidance and any procedural rules in force. The duty not to mislead the court applies fully to AI-assisted work. If guidance or rules require disclosure, comply with them. If not, consider whether transparency is appropriate given the nature and extent of AI use.
Are new court rules on AI already in force?
Judicial guidance and consultation documents on AI in the courts have been issued. Whether any formal procedural rules have been adopted, and what they require, must be verified against current official judiciary sources. Consultation proposals are not binding rules until formally adopted.
Who is responsible for an AI-generated court filing?
The professional who signs and files the document. Software does not carry professional responsibility. If an AI-generated document contains an error, a fabricated authority or misleading content, the professional who filed it bears the consequences.
Can solicitors rely on AI-generated case citations?
No without verification. Every citation must be opened and checked against an authoritative legal database: the case must exist, the neutral citation must be correct, the quotation must appear in the actual judgment, and the legal proposition must be supported by the decision. Cases in multiple jurisdictions have resulted in serious professional consequences for submitting AI-generated citations that did not exist.
How should legal authorities be checked?
Open the case directly using an authoritative legal database. Check the neutral citation, the court, any quoted passage and whether the case supports the proposition for which it is cited. Check whether the decision has been appealed, distinguished, overruled or otherwise affected. Do not rely on an AI summary of a case without checking the primary source.
Can client information be entered into AI?
Entering client information into an AI service is a disclosure and a data processing activity. It requires analysis of confidentiality obligations, data protection law, supplier terms, data locations, subprocessor arrangements, retention settings and any client instructions about data sharing. The answer depends on the specific information, service, terms and obligations involved.
Can privileged information be entered into AI?
This requires careful analysis of the specific service, its terms, data handling arrangements and applicable law. The risk of confidentiality loss, privilege concerns and evidential complications should be considered before entering privileged material into any third-party service. Obtain specialist advice for sensitive use cases rather than experimenting.
Does an enterprise AI account protect confidentiality?
Enterprise accounts typically provide stronger organisational controls than consumer accounts, but enterprise branding does not automatically make any use lawful or professionally appropriate. The specific contract, data-processing agreement, retention settings, subprocessor arrangements and security controls must be reviewed. A secure product can still be used insecurely.
What is legal professional privilege?
Legal professional privilege protects confidential communications between a lawyer and client made for the purpose of legal advice, and communications prepared for the dominant purpose of actual or contemplated litigation. Privilege belongs to the client. Its scope and any risk of loss require analysis of specific facts and applicable law — consult specialist sources and, where uncertain, specialist advice.
Can AI calculate court deadlines?
AI can assist with extracting and organising dates. It cannot reliably replace the professional analysis needed to calculate a court deadline, which may depend on court rules, working days, bank holidays, service methods, extensions, jurisdiction and rule changes. Every critical deadline requires independent verification through authoritative rules and approved case management systems.
Can AI check court portals?
Accessing court portals requires authorised access, compliance with the portal's terms and consideration of data protection obligations. Whether automation of portal access is permitted depends on the specific system's terms and any applicable rules. Do not use automation to bypass access controls.
What is prompt injection in a legal document?
Prompt injection is an attempt to embed instructions in content that an AI system will process, with the aim of influencing the AI's output or actions in ways the operator has not authorised. In a legal context, this could affect AI-generated summaries, produce misleading analysis, reveal information or trigger unintended tool use.
Can hidden text manipulate an AI system?
Yes. White text, concealed comments, metadata, hidden spreadsheet cells and embedded content can all contain instructions that an AI system may act on when processing a document. Treat documents from untrusted sources as untrusted data and review AI output carefully when working with opponent, third-party or external documents.
Should solicitors use personal AI accounts?
No, for professional work. Personal accounts do not provide the organisational controls, audit logging, data processing agreements or administrative oversight required for professional use. Client and matter information should enter only approved business accounts with appropriate contractual and technical protections.
What should an AI supplier assessment include?
Data ownership, input use and training, retention and deletion, data locations, subprocessors, encryption, access controls, MFA, SSO, audit logging, incident notification, exit arrangements, accuracy limitations, model-change notifications, liability limits and insurance. See the AI supplier assessment guide for the full framework.
Do clients need to be told about AI use?
It depends on professional rules, engagement terms, client instructions, the materiality of AI use and sector requirements. Clients do not need a list of every software feature, but they should not be misled about how sensitive or material work is performed. Where client instructions restrict AI use, those restrictions must be followed.
What should a law firm AI policy cover?
Approved tools, approved account types, prohibited information, permitted and high-risk uses, human review requirements, source verification, client instructions about AI, court and regulator submission controls, supplier approval, browser automation rules, record keeping, incident reporting, training and review ownership. The policy should receive appropriate legal and regulatory review.
What records should be kept?
Records sufficient to demonstrate that AI-assisted work was properly controlled: the tool used, the user, the purpose, the source material, the output, what was checked, who reviewed, who approved, the date and any exceptions. Apply data minimisation and retention rules — records should not retain unnecessary personal data.
How should staff be trained?
Training should cover approved tools, prohibited uses, confidentiality and privilege, verification of legal authorities, deadline handling, prompt injection awareness and escalation procedures. Practical exercises with invented sources, misleading output and confidentiality scenarios are more effective than theoretical presentations alone.
Can AI make regulated decisions?
No without human oversight and, where required, authorisation. Decisions that affect rights, create obligations, determine professional advice or result in regulatory submissions require qualified human approval. AI may support the analysis — it cannot accept the professional responsibility.
Can accountants and surveyors use AI?
Yes, subject to their professional obligations. Each regulated sector has its own standards, and the analysis for accountants, surveyors, financial advisers and other regulated professionals follows the same framework: approved tools, data protection compliance, professional responsibility for output, qualified review and appropriate client transparency. Check the requirements of the specific professional body.
What should require partner or director approval?
New AI tool approvals, changes to AI supplier arrangements, use of AI for court or regulatory submissions, any AI use involving privileged information, exceptions to the AI policy and any incident affecting client data or professional obligations. The specific level of seniority required should be defined in the AI policy.
Can IT Club help assess professional AI use?
Yes — for technology governance questions. IT Club provides practical technology-governance guidance, not legal or regulatory advice. For questions about professional obligations, SRA requirements or legal privilege, obtain guidance from the appropriate regulator, professional body or qualified adviser. Submit a technology governance question through Ask the Advisor.
Plain-English Takeaway
Solicitors and other regulated professionals may use AI to support tasks such as summarisation, document preparation, research planning and administrative checking. The professional remains responsible for confidentiality, accuracy, legal and factual verification, client interests and anything submitted in their name. Sensitive information should enter only approved systems, critical sources and deadlines must be checked independently, and AI should not file, send or make rights-affecting decisions without authorised human approval.
Sources and further reading
- Solicitors Regulation Authority — Technology and AI guidance
- The Law Society — Technology and the law
- Courts and Tribunals Judiciary — AI guidance for legal professionals
- ICO — Artificial intelligence guidance and resources
- NCSC — AI and cyber security: what you need to know
- ICO — Anonymisation and pseudonymisation guidance
External guidance changes. Check the source itself for the current position before acting on it.