AI and Legal Privilege: A Practical Framework for UK Firms
A practical framework for UK lawyers assessing whether an AI tool threatens legal professional privilege, covering the legal test, the questions, the checklist.
Whether an AI tool puts privilege at risk was never really about the tool’s name. It’s about confidentiality law, what your contract with the provider actually says, and where the data goes. Here’s the framework to run before you approve, or keep using, any AI tool with client material.
In short: Legal professional privilege depends on confidentiality being maintained. Under the long-standing “limited waiver” principle, sharing privileged material with a third party does not waive privilege if that sharing happens on confidential terms, for a limited purpose. Free, consumer-tier AI tools typically fail this test because their terms let the provider retain and reuse your input. Enterprise-contracted tools with a data processing agreement, a no-training commitment, and a defined retention policy can pass it, provided you’ve also checked where the data is processed and that any transfer outside the UK has a lawful basis. This article sets out the questions to ask and a checklist to apply, tool by tool.
The legal test everyone skips: it’s not “is it AI”, it’s “was there a confidential disclosure”
Most internal debates about AI and privilege start in the wrong place, arguing about a specific product rather than applying the doctrine that has governed disclosure to third parties for decades.
Legal professional privilege protects confidential communications between lawyer and client. Privilege is capable of being waived where privileged material is voluntarily disclosed to a third party outside that relationship. But English law has never treated all third-party disclosure as fatal to privilege. Where privileged material is shared with someone, such as an agent, an expert, or a service provider, on confidential terms, for a defined purpose, privilege is generally preserved as against the rest of the world. This is known as the principle of limited waiver, and it is the reason law firms have been able to use translators, external counsel, e-discovery vendors, and cloud storage providers for years without automatically destroying privilege.
The practical guidance on this principle is consistent on two points that matter directly for AI tools:
- It is best practice to put an express confidentiality or non-waiver agreement in place, setting out the purpose of disclosure and restricting further use.
- Disclosure in one jurisdiction can cause loss of privilege in another — if disclosure genuinely destroys confidentiality more broadly, rather than being confined to a limited, protected purpose, privilege can be lost even where the discloser didn’t intend that result.
Once you frame it this way, the question an AI tool actually has to answer is not “is this a reputable product,” it’s “does using this tool amount to disclosure on confidential terms, for a limited purpose, or does it amount to giving the information away”. That is precisely the reasoning the Upper Tribunal applied in Munir v Secretary of State for the Home Department [2026] UKUT 00081 (IAC), the first explicit English judicial statement on AI and privilege, treating uploading documents to a free, public AI tool as placing them “in the public domain” (destroying confidentiality outright), while treating a closed, enterprise-contracted tool as capable of being used without the same risk. We’ve covered that case in detail separately; this article is about the general framework it sits inside, which applies well beyond that one case and will keep applying as new tools and new rulings arrive.
Your SRA and BSB obligations sit on top of this
The privilege analysis runs alongside, not instead of, your regulatory duties.
Solicitors must, under paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs and RFLs (mirrored for firms), “keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.” The SRA’s own guidance on outsourcing goes further, warning that “clients may not have agreed or understood that their confidential information may be considered by an unregulated third party and that in certain cases, information will be considered in a foreign jurisdiction,” and that firms “will need to consider the arrangements they have in place to ensure adequate protection of clients’ confidential information.” The SRA guidance treats this as applying to outsourcing generally, expressly including “any arrangements for storing data with a third party via the cloud,” and for cloud storage specifically, the SRA points firms toward National Cyber Security Centre guidance on choosing secure providers.
The Bar Standards Board’s AI guidance (published May 2026) takes a correspondingly firm line on free tools specifically. It has been reported as warning that such tools’ terms typically let the provider claim rights over input data, store prompts indefinitely, and use them for model training, and that free tools are “unlikely” to meet the standard required when a barrister outsources any part of their work. Firms and chambers should check the BSB’s published guidance directly for the exact wording before relying on it in a policy document.
Neither regulator has published an exhaustive list of approved or banned tools, and that’s unlikely to change — the assessment has to be done tool by tool, and revisited as contracts and products change.
The three questions that actually determine your exposure
Strip away the marketing and every AI tool your firm considers reduces to three questions.
1. Does the provider’s contract let it train on, or reuse, your input? If the answer is yes, as it typically is for free, consumer-facing products, you are not disclosing on “confidential terms.” You’re granting the provider a licence to use the material for its own purposes. That is very hard to square with limited waiver.
2. Is there an actual signed agreement with your organisation, not just an individual’s account? A fee-earner signing up for a personal paid subscription is not the same as your firm holding an enterprise agreement and data processing addendum (DPA) with the vendor. Confidentiality protections that flow from a business contract generally don’t extend to a staff member’s individual consumer sign-up, even on a “Plus” or “Pro” tier.
3. Where is the data processed and stored, and does it leave the UK/EEA? Even a fully enterprise-contracted, no-training tool can raise a separate compliance question if it processes data outside the UK, which is covered next.
Data residency and international transfers: the layer most firms miss
This is a distinct legal question from privilege, and it’s easy to assume a good DPA settles it. It doesn’t, on its own.
Under UK GDPR, sending personal data to a recipient outside the UK can be a “restricted transfer”, which needs its own lawful basis. The ICO’s current test for whether a transfer is restricted asks, in substance: does UK GDPR apply to the processing; are you (or your processor) the one initiating a transfer of that data to a separate organisation; and is the overseas recipient a distinct legal entity from the one sending it? Where a transfer is restricted, firms need one of:
- Adequacy regulations — the UK has recognised the destination country’s data protection as adequate. For US-based providers, the relevant mechanism is the UK-US Data Bridge (the UK’s extension of the EU-US Data Privacy Framework), which a receiving US entity must actively be certified under, and it is not automatic just because the vendor is American.
- Appropriate safeguards — most commonly the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or Binding Corporate Rules for large groups.
- A specific derogation — a narrow, exception-based route not designed for routine, repeated business transfers.
The practical point for AI procurement: most large AI vendors process data in the United States (sometimes with regional or EU/UK-hosted options at extra cost). Ask the vendor which mechanism their DPA actually relies on for UK customer data, and check whether the specific product tier you’re buying, and the specific data centre region, is the one the certification or clauses actually cover. Marketing claims about “GDPR compliance” are not a substitute for identifying the mechanism.
What the major vendors say they commit to (snapshot, verify before relying on it)
AI vendor terms change frequently, and the difference between a free consumer tier and a paid enterprise tier is usually the whole ballgame. As of August 2026, based on each vendor’s own published documentation:
| Vendor / product | Training on your data | Retention | Free vs enterprise distinction |
|---|---|---|---|
| Microsoft 365 Copilot (commercial) | Not used to train foundation models (prompts, responses, and Microsoft Graph data are excluded by design) | Governed by your organisation’s own retention policies and the Microsoft Products and Services DPA | Applies to commercial/tenant-licensed use under your Microsoft 365 agreement, not a personal Microsoft account |
| OpenAI (ChatGPT Business/Enterprise, API) | Not used to train models by default | Enterprise/Business: admin-controlled; API: up to 30 days by default, zero data retention available for eligible endpoints | Explicitly different from the free consumer ChatGPT product, where input may be used to improve models unless the user opts out |
| Anthropic Claude (Claude for Work, API) | Not used to train models by default on commercial products | Standard commercial retention terms apply; explicit user feedback (e.g. thumbs up/down) is a separate, opt-in exception | Explicitly different from free/Pro/Max consumer Claude.ai accounts, which are covered by separate consumer terms |
Treat this table as a starting point for the conversation with your vendor and your firm’s data protection lead, not as a substitute for reading the current DPA yourself. Commitments, product names, and tiers are all liable to change, and “enterprise” branding on a page doesn’t guarantee your specific contract includes every protection listed above.
The decision tree
Run any AI tool through this sequence before it touches client material:
- Is this a free or personal-tier product? If yes, stop. Do not use it for anything containing client-identifiable, confidential, or privileged information, regardless of how the individual account is configured.
- Does your firm hold a signed enterprise agreement and DPA with the provider? If it’s an individual’s personal paid subscription rather than a firm-level contract, treat it as though it were free tier.
- Does that agreement confirm, in writing, no training on your inputs and a defined retention/deletion period? If this isn’t clearly stated, get it confirmed in writing before uploading anything privileged — don’t rely on a sales conversation or a marketing page.
- Where is the data processed, and does it leave the UK or EEA? If it does, identify the specific transfer mechanism relied on (adequacy regulation, IDTA, SCCs addendum, BCRs) and confirm it actually covers the product tier and region you’re using.
- Even where 1-4 are satisfied, is this a matter where any disclosure beyond the firm should be avoided regardless of contract terms — for example highly sensitive litigation strategy, national-security-adjacent material, or anything subject to a specific client instruction restricting onward disclosure? Some matters warrant a blanket “no external AI tool” rule irrespective of how strong the vendor paperwork is.
- Document the decision. Keep a record of which tools are approved, for what categories of work, and the vendor terms reviewed at the time. This is what you’ll need at audit, at PII renewal, or if a client or regulator asks why a particular tool was approved.
Frequently asked questions
Does using any AI tool automatically waive legal privilege? No. The relevant test is whether disclosure to the AI provider happens on confidential terms for a limited purpose (in which case privilege is generally preserved under the limited waiver principle) or whether it amounts to placing the information beyond the protected relationship, which is what the Upper Tribunal found had happened with a free, public AI tool in Munir v Secretary of State for the Home Department [2026] UKUT 00081 (IAC).
Is a paid personal subscription (e.g. ChatGPT Plus) the same as an enterprise agreement for privilege purposes? No. Confidentiality protections generally flow from the contract your firm signs with the provider, not from an individual paying for a personal account. Treat personal subscriptions as though they carry the same risk as free tools unless your firm holds its own enterprise agreement covering that use.
If a vendor’s data processing agreement says “no training on your data,” is that enough? It’s necessary but not sufficient on its own. You also need to check data retention and deletion terms, where the data is processed, and, if it leaves the UK or EEA, that a lawful international transfer mechanism actually applies to the product tier and region you’re using.
Do I need a separate international data transfer assessment even if the AI vendor has a strong confidentiality contract? Yes. Privilege/confidentiality and UK GDPR international transfer rules are separate legal questions. A strong DPA can protect confidentiality while the underlying personal data transfer still needs its own lawful basis, such as the UK-US Data Bridge, the UK IDTA, or the UK Addendum to the EU Standard Contractual Clauses.
Has the SRA published a list of approved AI tools? No. The SRA’s confidentiality and outsourcing guidance sets out principles, such as adequate protection of confidential information and awareness of unregulated third parties and foreign jurisdictions, rather than naming approved products. Firms are expected to apply that guidance to each tool individually and keep the assessment under review.
This article summarises general principles of English law on privilege and confidentiality, current SRA and BSB guidance, and publicly available vendor documentation as of August 2026. It is not legal advice, and vendor terms in particular change frequently. Always check the current contract before relying on any commitment described here. For the case law behind this framework, see Does Using ChatGPT Waive Legal Privilege? What the Munir Ruling Means for UK Lawyers, and for a structured walkthrough of AI governance for legal practice, see AI Foundations for Lawyers.