Does ChatGPT Waive Legal Privilege? UK Ruling Explained
A 2026 Upper Tribunal ruling found uploading client documents to ChatGPT can waive legal privilege. What the Munir case means for UK lawyers.
A 2026 Upper Tribunal decision found that uploading client documents into public AI tools can permanently destroy confidentiality — and with it, legal professional privilege. Here’s what actually happened, what it does and doesn’t mean, and what to change in your practice this week.
In short: In UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 00081 (IAC), the Upper Tribunal (Immigration and Asylum Chamber) held that uploading client letters and case documents into an open-source AI tool such as ChatGPT places that information “in the public domain,” breaching client confidentiality and waiving legal professional privilege — regardless of the user’s intentions. Closed, enterprise-contracted tools such as Microsoft Copilot were treated differently, because the data does not enter the public domain in the same way. The tribunal’s comments are persuasive rather than binding, but they are the first explicit English judicial statement on AI and privilege, and firms are already being asked about it at audit and renewal.
What actually happened in Munir
UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 00081 (IAC) was handed down by the Upper Tribunal (Immigration and Asylum Chamber) on 17 November 2025, exercising the tribunal’s Hamid jurisdiction — the mechanism it uses to scrutinise poor professional conduct by legal representatives in immigration and asylum cases and, where necessary, refer them to their regulator.
The tribunal dealt with two linked cases in one judgment. In the first, an immigration adviser had drafted grounds of appeal that cited a case which did not exist; when challenged, the adviser eventually admitted the citation was “an AI creation,” and confirmed that client emails and Home Office decision letters had been uploaded into ChatGPT for summarising and redrafting. In the second, a trainee had drafted judicial review grounds containing multiple fabricated citations, which the supervising solicitor signed off under a statement of truth without independently checking them.
The tribunal’s remarks on citation-checking and supervision were the central holding. But it went further, and it is this second part of the judgment that has since dominated the legal press:
Uploading confidential documents into “an open-source AI tool such as ChatGPT placed this information in the public domain,” constituting a breach of client confidentiality and a waiver of legal professional privilege.
Why uploading a document to ChatGPT can waive privilege
Legal professional privilege exists to protect confidential communications between a lawyer and client. It depends entirely on that confidentiality being maintained — privilege is lost the moment a document is knowingly disclosed to a third party outside the protected relationship, whether that disclosure is deliberate or careless.
The tribunal’s reasoning treats a free-tier, public generative AI tool as exactly that kind of third-party disclosure. The logic runs like this:
- Free and consumer-tier AI tools are, contractually, a disclosure to the provider. Their terms of use typically allow the provider to retain prompts, use them to train or improve models, and grant staff or systems access to that data.
- Once information leaves the lawyer-client relationship on those terms, it has left the zone of confidentiality that privilege protects — the tribunal characterised this as functionally equivalent to publishing the information.
- Waiver happens at the point of upload, not at the point anything goes wrong. It doesn’t matter whether the model “leaks” the specific document, whether anyone else ever sees it, or whether the lawyer believed the tool was private. The act of upload is the disclosure.
This is a stricter reading than many firms had assumed. A lawyer pasting a client’s Home Office decision letter into ChatGPT to get a faster summary is not “using a research tool” in the tribunal’s framing — they are handing a confidential document to a third party on terms that let that third party keep and reuse it.
Open-source AI vs closed, enterprise tools: the distinction that matters
The tribunal did not treat all AI tools the same way. It explicitly distinguished:
- Open-source / public tools (its own example: ChatGPT, free tier) — carry the confidentiality and privilege risk described above.
- Closed-source tools that do not place information in the public domain (its own example: Microsoft Copilot) — recognised as usable for tasks like summarising without the same risk.
The tribunal also noted, separately, that “use of legal AI programmes by properly trained professionals was a step forward” for focused legal research and disclosure work — this is not a ruling against AI use in legal practice. It is a ruling about which tools, on what contractual terms, for which categories of document.
In practice, the label on the tool matters less than three underlying questions, which is where firms should focus policy attention rather than on brand names:
- Where does the data go? Is it processed within a contracted, audited environment, or sent to a general consumer product?
- Is it retained or used for training? Enterprise agreements typically disable training on your inputs by contract; free consumer tools typically do not.
- Who can access it, and under what safeguards? Does the provider’s contract give you audit rights, data residency commitments, and deletion guarantees?
A tool can move between these categories depending on whether you’re on the free consumer product or a paid enterprise agreement with the same vendor — “is it ChatGPT” is the wrong question; “what does our contract with the provider say” is the right one.
Is this binding on solicitors and barristers generally?
Some important limits on how far Munir reaches:
- It is an Upper Tribunal (Immigration and Asylum Chamber) decision. It does not bind the High Court, and its privilege observations were not strictly necessary to decide the appeal in front of it — meaning they carry real persuasive weight but remain, formally, obiter.
- It is, as far as the legal commentary tracking this area has identified, the first explicit English judicial statement addressing AI tools and privilege directly. Expect further case law to refine, and possibly qualify, the bright-line approach taken here.
- The tribunal did not set out a comprehensive test for what makes a system “safe” — its comments describe a principle, not a checklist.
None of that is a reason to treat the ruling as low-risk. It is precisely the kind of reasoning that the SRA, the Bar Standards Board, opposing counsel, insurers, and — per the tribunal’s own suggestion — the Information Commissioner’s Office are now positioned to rely on. The Bar Standards Board’s own AI guidance, issued shortly after Munir attracted attention, separately warns that free generative AI tools are “unlikely” to meet the standard required when outsourcing legal work, for closely related reasons: providers can claim rights over input data and store prompts indefinitely.
What to do about it: a practical checklist
- Stop treating “AI tool” as one category in your policies. Separate approved enterprise tools (with a signed data processing agreement, training disabled, and defined retention) from free consumer tools, and name them specifically.
- Ban free-tier consumer AI tools for anything containing client, case, or personal data — not just obviously sensitive material. Summarising a decision letter counts.
- Update supervision, not just tooling. Munir held supervisors more culpable than the fee-earners who made the original error, for failing to check. A tool policy without a verification step doesn’t fix the underlying problem.
- Build in an incident path. If confidential material has already gone into an unapproved tool, the tribunal’s own suggestion was that the Information Commissioner’s Office may need to be notified — know who in your firm makes that call, and how fast.
- Document the policy, and the reason for it, so that if a fee-earner is asked at audit or in litigation why a particular tool was or wasn’t approved, there’s a documented answer rather than an improvised one.
Frequently asked questions
Does uploading a document to ChatGPT always waive privilege? Under the reasoning in UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 00081 (IAC), uploading confidential material into an open-source, public AI tool was treated as placing it in the public domain, which the tribunal held breaches confidentiality and waives privilege. The tribunal’s own example of a lower-risk alternative was a closed, enterprise-contracted tool such as Microsoft Copilot.
Is Microsoft Copilot definitely safe to use with client data? The tribunal referenced Copilot as an example of a closed-source tool that doesn’t place data in the public domain in the same way as free ChatGPT — but this isn’t a blanket approval. What matters is the specific contract and tier you’re on: enterprise agreements with training disabled and defined data handling terms are the relevant safeguard, not the product name.
Is the Munir ruling legally binding on solicitors? No. It’s an Upper Tribunal (Immigration and Asylum Chamber) decision, so it doesn’t bind the High Court, and the tribunal’s remarks on privilege were not essential to its decision on the appeal itself. It is, however, the first explicit English judicial statement on the issue and is already being treated as highly persuasive by commentators, insurers, and regulators.
What should I do if I’ve already uploaded client documents to ChatGPT? Stop further uploads immediately, tell your supervisor or COLP, and check your firm’s incident response process. The tribunal’s own observations suggest that in some circumstances the Information Commissioner’s Office may need to be notified. Document what was uploaded and when, so the firm can assess the scope of any breach.
Does this mean lawyers shouldn’t use AI tools at all? No — the tribunal itself said that AI tools used by properly trained professionals were “a step forward” for legal research and similar tasks. The ruling is about which tools, under what contractual terms, and for what categories of information — not a rejection of AI use in legal practice generally.
This article summarises publicly reported commentary on UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 00081 (IAC) and related regulatory guidance as of August 2026; it is not legal advice, and firms should check their own policies against current SRA and BSB guidance. For more on the conduct standards this ruling sits alongside, see AI Ethics for Lawyers: What the Rules Require and What the Courts Are Punishing and 10 Questions to Ask Before Your Firm Buys an AI Tool. For a structured walkthrough of AI governance and ethics for legal practice, see The AI Bar’s AI Foundations for Lawyers module.