Ask a room of partners how many of their people use ChatGPT for work and you will get a number. Ask the associates and you will get a bigger one. Microsoft published a warning about shadow AI, meaning unsanctioned use of consumer AI tools at work, in October 2025, and the phenomenon it describes is not particular to law. What is particular to law is the cost of getting it wrong, because the material being pasted in is privileged.
Why fee-earners do it
Not recklessness. Speed, and a specific kind of speed. A trainee with a clause they do not understand at half past six has two options: work it out over forty minutes, or paste it into a chatbot and understand it in ninety seconds. The second option is available on the phone in their pocket, requires no approval, and produces an answer that is usually good enough to move forward with.
The economics of a billable hour push in exactly the same direction. Every minute spent understanding something is a minute not spent producing something. A firm that has never provided a fast, sanctioned route has, without deciding to, made the unsanctioned one the rational choice for anybody under time pressure. That is most people, most weeks.
What the regulator has actually said
The SRA warning notice 'Misuse of AI', published 17 August 2026, names confidentiality as one of its two concerns: client material put into public AI tools. It refers to UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC) on confidentiality and privilege. The Law Society's position is that sharing case details with tools like ChatGPT will likely breach client confidentiality, and that privilege may be permanently waived.
The SRA news release of the same date reports 42 reports of potential AI misuse between July 2025 and July 2026, covering inaccurate citations, supervision and confidentiality. Confidentiality is one of three named categories, which tells you this is not a hypothetical risk being raised for completeness.
Privilege is the part that does not heal
A confidentiality breach is serious and, depending on the facts, sometimes containable. The privilege point is different in kind. If privilege is waived, it is waived, and no amount of subsequent care puts it back. That is a loss the client suffers, in litigation, possibly years later, arising from ninety seconds somebody spent understanding a clause faster.
This is worth explaining to fee-earners in exactly those terms rather than as a policy line. People follow rules they understand the reason for and route around rules they do not. The reason here is concrete, and it takes one minute to explain in a team meeting.
Why a ban does not work
A prohibition changes where the behaviour happens, not whether it happens. Ban it on firm laptops and it moves to personal phones, where the firm has no visibility, no logs and no ability to tell a client what was disclosed and when. The firm has traded a supervisable problem for an invisible one and called it a policy.
The honest test for any firm is not whether shadow use is prohibited. It is whether anybody would report it. If a senior associate who pasted a clause into a consumer tool last month would not tell the COLP, the policy is producing silence rather than compliance, and silence is the thing that makes the regulator's questions hard to answer later.
The test a sanctioned route has to pass
Two conditions, and both are needed. It has to be at least as fast as the consumer tool for the small jobs, because that is where the volume is. Nobody opens a governed system to summarise a paragraph if the login takes ninety seconds. And it has to leave a record, because a sanctioned route that produces no evidence has solved the confidentiality problem and left the supervision one untouched.
Most internal AI policies fail the first condition and are then puzzled by their adoption figures. The tools people actually use at speed are the ones already open in a tab. If the sanctioned route is a form, an approval and a wait, the firm has built a process for the work that was never the risk in the first place.
What that looks like here
Before any model sees a prompt, the run screens it for personal and client data and redacts where needed, so a neutral citation number becomes a reference. The jurisdiction in scope is confirmed. For a research run, the plan is shown and paused for the user to Approve and run, Modify or Cancel. All of that is written into a 'How this was made' tab that stays with the output.
Data sits in the Microsoft Azure UK region, encrypted in transit and at rest, and is never used to train any model. Every run is recorded in the audit and compliance register with who authorised it, whether the checks passed and what it cost in credits. And the Free plan gives a firm two seats and 500 welcome credits, expiring after thirty days, with no card, which means the honest first step is not a procurement exercise. It is giving one team something better than the tab they already have open.
What this does not do
Nothing here stops anyone using a consumer chatbot on their own phone. There is no monitoring of firm devices, no browser extension watching what people paste, and no attempt to detect shadow use. Those are firm decisions about device management, not features of a research tool, and we would be overstating our position to suggest otherwise.
Screening before a prompt reaches a model reduces exposure without eliminating it. A user can describe a matter in enough detail to identify it without ever typing a name, and no screening layer reads intent. Training is the other half of this, and it is the half that belongs to the firm. CILEx launched an AI Academy in September 2025, and the Law Society updated 'Generative AI: the essentials' in June 2026, both of which are more useful starting points than another policy nobody reads.


