TL;DR
Ask a professional services firm to justify its AI use and many will reach for a log of individual prompts. New guidance for conveyancers calls that misdirected effort. Under UK data protection law the legal footing is decided once for a given purpose, not renewed at every interaction — and the thing firms genuinely cannot evidence is something else entirely.
Start with the scenario
A fee-earner is up against a deadline. A client’s file goes into a consumer chatbot, on a personal login. Nobody vetted the supplier, no contract governs the arrangement, and nothing anywhere records that it happened.
So what precisely has been breached? If the firm settled its footing for handling client information when it took the retainer on, and if supplier terms get agreed once per vendor at onboarding, then neither of those duties has failed.
The failure is evidential. Nobody can say whose material went to which provider, or show it stayed among the tools the firm had actually checked. This processing may have been entirely lawful. Demonstrating as much is now impossible.
Why the original footing holds
Ed Molyneux, writing the second part of a series on adopting the technology safely, traces the confusion to reasoning that is half sound. Personal data is involved, and there must be a legal footing for handling it: both true. That each separate use demands its own fresh justification does not follow.
The determination gets made before any processing starts, entered in the record of processing activities and disclosed in the privacy notice. Filing material in a spreadsheet, corresponding about it and drafting from it with a model all serve a single purpose, under one standing determination. Nothing about a tool being AI resets that.
Contract performance or legitimate interests are the workable options for a retainer. Consent is a poor fit, since a client may pull it tomorrow and delivery cannot depend on that.
Looking forward
The redirect is the valuable part. Logging a justification per interaction merely re-records a choice already properly made. A register of what went where does real work: it evidences accountability, shows usage kept within sanctioned limits, and answers the awkward questions that surface months afterwards: who exactly held this person’s information, when a subject access request lands; whose records were sitting with a supplier, when that supplier gets breached.
No policy document supplies any of that. It complements last week’s warning that public AI tools may waive privilege: the exposure lives in unrecorded usage, not in paperwork.