TL;DR

Most discussion of AI in legal practice asks whether solicitors are using it competently. A Legal Futures analysis by Eleonora Dimitrova argues that is the wrong end of the problem: by the time anyone types a prompt, the firm’s regulatory exposure was settled when it signed the vendor contract. The test she proposes is uncomfortably simple, and many UK firms would fail it today.

The question a firm should be able to answer

Could your firm demonstrate, with evidence, where a privileged document travels once an AI system processes it, who can reach it, and what remains afterwards?

For plenty of firms the honest answer is no. Dimitrova’s point is that this is not a supervision or training gap. It is a buying decision made without the people who understand the consequences, and regulators have historically treated that class of failure as systemic.

Under the SRA’s outcomes-focused approach, firms answer for the systems delivering their legal services. Competence, due diligence and confidentiality cannot be contracted out to a supplier. Each assumes the firm knows how its own tooling behaves.

Why the usual buying process breaks

Legal-sector procurement typically rests on assumptions that generative AI invalidates: that the seller knows the product best, that warranties and indemnities absorb the downside, and that architecture is a technical detail with no bearing on professional duties.

None survives contact. Vendors often cannot articulate model behaviour in legally sensitive conditions. An indemnity does not restore waived privilege or repair a regulatory finding. And where data is processed now determines whether compliance is achievable at all.

The structural failure is ordinary: IT reviews security, innovation teams assess capability, partners judge usefulness, and risk and compliance arrive late or not at all.

What buyers should insist on

Dimitrova sets out five baseline demands. Documented data flows, covering ingestion through to deletion, rather than a blanket assurance about training. Enforceable contract terms on secondary use, subcontractors, cross-border transfer and retention, backed by audit rights. Clarity on processing jurisdiction. Intelligible explanations of how outputs arise, how errors occur and how updates are controlled. And a clean exit, with extraction and deletion that can be independently confirmed.

Looking forward

This lands the same week Deloitte found UK staff buying AI tools with their own money, 31% of them without telling their employer — procurement discipline is moot if the software arrives on a personal card. Conveyancers, meanwhile, have been logging AI use as though each prompt needed consent. The SRA has so far offered principles rather than operational expectations, and the gap is where divergence grows.