The numbers tell a clear story. AI is embedded in day-to-day legal work, but, in many firms, its use isn’t documented or controlled. Such governance gaps in legal practices have consequences. Each of the following risks has generated UK case law, regulatory guidance, or professional indemnity implications:
Hallucinations
AI tools can produce citations to cases that do not exist, stated with complete assurance. As Gareth Parker, Head of Operational Compliance, explained on our recent AI governance webinar: “AI can be confidently wrong.”
By the end of 2025, the UK had recorded 24 confirmed hallucination incidents in courts and tribunals; internationally, the number exceeded 600, according to Natural and Artificial Intelligence in Law.
As just one example, in Choksi v IPS Law LLP, a witness statement from a managing partner of a solicitor’s firm contained fabricated cases produced with the assistance of AI. The references had been used without any verification system in place.
Confidentiality and legal privilege
Uploading any client documents to an open-source AI tool may constitute a breach of client confidentiality and a waiver of legal privilege.
This risk was addressed directly in UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC). According to sources, the judgement drew a clear distinction between open-source tools (which place information in the public domain) and closed enterprise tools with appropriate data safeguards:
“Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege.
Closed-source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks.”
Many staff members are making tool choices without understanding these implications, but it is clear that the distinction matters.
Supervision gaps and partner-level liability
Courts and regulators are increasingly treating AI misuse as a systems failure, not a personal one.
In Ndaryiyumvire v Birmingham City University, two fake AI-generated cases appeared in an application. The court regarded this a failure of management at the firm rather than the named solicitor’s individual conduct, according to reports.
If staff are using AI tools without a supervision framework in place, the risk sits with the organisation – regardless of who did the work.
Data protection and automated decision-making
The Data (Use and Access) Act 2025, in force from February 2026, amended the UK GDPR’s approach to automated decisions. Under the old rules, using AI to make decisions that legally or significantly affected individuals was largely prohibited unless specific conditions were met.
The new rules are more permissive, but they come with mandatory safeguards. If AI is making or significantly contributing to a decision that affects a client, firms must tell the client that automated processing was involved and they are able to both challenge it and request a human review.
The risk for law firms isn’t that AI can’t be used in client-facing work. Rather, if AI is being used without a documented process showing safeguards are in place, legal firms could be potentially in breach without realising it.