TL;DR
Research by Access Legal, published in May, found that nearly 60% of fee-earners at small and mid-sized firms admit using unapproved AI tools such as free ChatGPT, while 68% of firm leaders are confident they have full visibility and zero risk of unapproved AI touching client work. Writing for Legal Futures, Access Legal’s head of product Clare Bonsall argues that gap is what produces cases like Munir.
In Munir, the Upper Tribunal warned against free open-source AI tools, on the basis that entering client data into them effectively puts it into the public domain — an automatic breach of legal professional privilege. Doing so also breaches SRA principles 2 and 7, integrity and competence, and obliges the regulated professional to contact the regulator and consult the Information Commissioner’s Office.
The figures come from a vendor selling enterprise legal AI, and the piece concludes that firms should buy governed tooling, so they warrant the usual discount. The underlying gap is harder to dismiss, because both halves are self-reported by the same sector: practitioners describing what they do, and leaders describing what they think is happening.
Bonsall’s argument against simply banning AI is the more interesting one. Prohibition pushes fee-earners further towards unmonitored tools, and firms are not standing still — Garfield AI, authorised by the SRA last year, recently helped a claimant recover £7,000 in unpaid debt for a £400 fee, preparing papers and witness statements before instructing a barrister for trial.
Looking Forward
Munir did narrow the question: AI used on client matters needs to be enterprise-grade, closed-source and governed. What it did not do is tell supervisors how to know what their teams are running, and the ruling puts responsibility for AI-assisted output squarely on them. The practical controls Bonsall names — auditing which approved tools already embed AI features, checking vendors against GDPR, ISO 27001 and ISO 42001, and role-based permissions producing an audit trail — are unremarkable information-governance practice applied to a new input. The pattern generalises well beyond law. Half of UK founders fed sensitive data into public AI tools in a single month, on separate research published this week, and the Court of Appeal has already ruled that AI trial preparation can amount to witness coaching. Any regulated UK profession where individuals face personal sanctions has the same exposure, and the same reason to prefer an honest internal count to a confident assumption.