Is it safe to use AI in a law firm?

2026-07-26 · 6 MIN READ · RISK & COMPLIANCE

Is it safe to use AI in a law firm?

Is it safe to use AI in a law firm?

It can be, but safety is a property of the arrangement rather than the tool. What matters is which information leaves the firm, whose account it lands in, what the provider is permitted to do with it, and whether a person reviews the output before it reaches a client or a court.

What actually creates the risk?

The risk is rarely that the software is "AI". It is that a confidential document has been copied into a system the firm does not control, under terms nobody has read.

That is not a new category of problem. Firms already reason about it when they send a brief to an overseas transcription service, or store matter files with an offshore host. The same questions apply: where does it go, who can read it, how long is it kept, and what can they do with it.

Generative tools add a second, separate problem. The output can be confidently wrong in a way that looks exactly like finished work. So there are two risks, not one:

  • An input risk. Confidential or personal information moving somewhere it should not.
  • An output risk. Plausible, well-formatted material that is inaccurate, invented, or subtly off.

They need different controls. Treating them as one problem is why blanket bans and blanket enthusiasm are both wrong.

What should never leave the firm?

A short, boring list, agreed once and written down. The test most firms find workable is this: would you be comfortable explaining this disclosure in a breach notification or a costs argument.

In most practices the list covers:

  • Client identities tied to matter detail, where the combination identifies someone
  • Privileged communications and advice
  • Settlement positions, instructions, and negotiation strategy
  • Trust account details, banking information and payment instructions
  • Sensitive personal information about clients or third parties, including health, criminal history, immigration status and family matters
  • Anything subject to a court order, undertaking, suppression order or confidentiality regime
  • Material produced under compulsion in litigation, where restrictions on use may apply

The list is not "never use AI on client work". It is "never paste this into a general-purpose tool the firm has no agreement with". The same content may be perfectly appropriate inside a system your firm has contracted for. The difference is the contract, not the category of software.

Does the account you use actually matter?

Yes, and it matters more than almost anything else on this page. The same underlying model can come with very different commitments depending on whether someone is signed in on a free consumer login, a personal paid plan, or a business tenancy the firm administers.

A firm-administered tenancy gives you things a personal login never will: user provisioning and offboarding, admin control over settings, audit visibility, and a contract in the firm's name. With personal logins, none of that exists. When a solicitor leaves, their history leaves with them, or stays somewhere you cannot reach.

The working rule is simple. No client information goes into any tool a partner cannot administer and cannot switch off.

How do you stop your work being used to train a model?

Check the setting, check the terms that apply to your plan, and keep dated evidence of both. Many providers offer a control over this, and business tiers commonly commit to not training on customer content, but the position varies by provider and by plan and it changes over time.

A practical sequence:

  1. List every tool actually in use, including ones staff signed up for themselves. Ask the question in a way that does not punish an honest answer.
  2. For each one, find the statement that applies to your plan about training on customer content, and save a dated copy as a PDF.
  3. Turn off chat history or model-improvement options that are on by default.
  4. Set the shortest retention period the tool allows.
  5. Re-check at renewal, and whenever a provider announces changes to terms.

That fifth step is the one firms skip. Terms are not a one-time reading exercise.

What does human review actually look like?

Proper review means a named person reads the entire output, checks every citation, figure, date and name against a primary source, and takes responsibility for it as their own work. Anything less is not review, it is a signature.

The failure mode that has embarrassed firms internationally is specific and worth naming: models produce citations that have the right shape, the right style of case name, the right reporting series, and do not exist. Others exist and say something different from what the summary claims. Because the format is right, skim-reading does not catch it.

Treat the output the way you would treat a first draft from a capable junior whose research you have never checked. Where a tool touches clients, courts or money, review should be a required step in the workflow rather than a habit you hope survives a deadline. A workflow that will not proceed until someone approves is worth more than a policy that says someone should.

What should the firm keep a record of?

Enough that you could reconstruct, months later, what was used, by whom, on what matter, and who checked it. Firms already have the habit from supervision and file notes. This is the same habit applied to a new tool.

At a minimum, keep:

  • A one-page policy: approved tools, prohibited information, the review requirement, and who to ask when unsure
  • A register of approved tools, the plan the firm is on, and the date the terms were last read
  • A file note where AI-assisted work materially informed advice, naming the reviewer
  • A record of who has access, reviewed when people join and leave

What to do next

Pick the smallest version of this that you can finish. Most firms get further with a two-week tidy-up than a six-month project.

  1. Find out what is actually being used today, without blame.
  2. Move anyone using a personal login onto a firm-administered account, or stop the practice.
  3. Write the prohibited-information list on one page and circulate it.
  4. Add a required review step anywhere output reaches a client, a court or a payment.
  5. Read the guidance your professional body publishes, and any practice notes or guidance issued by the courts you appear in.

If it helps to have someone map that with you and build the review step into the workflow itself, that is the kind of work Shift does. Either way, the sequence above is the sequence.

This article is general information only and is not legal advice. Obligations differ by jurisdiction, entity and matter, and they change. Confirm your position with your professional body and your own advisers before relying on any of it.

Common questions

Can lawyers in Australia use ChatGPT for client work?

There is no blanket yes or no. It depends on what information is entered, which account and plan is used, what the provider is contractually permitted to do with that information, and whether a person verifies the output. Many firms start with internal, non-client tasks while they settle those questions. Check your professional body's guidance and your own obligations before deciding.

Do I have to tell clients that my firm uses AI?

There is no single answer that fits every firm or every matter. Some Australian courts have published guidance about the use of generative AI in material filed with them, and some clients ask directly. Check the guidance for the jurisdictions you practise in, and consider how your engagement terms describe your use of software and third-party providers.

What is the safest way for a law firm to start with AI?

Start with work that contains no client information at all: internal summaries of public material, first drafts of marketing copy, or reformatting your own precedents. That lets the firm build judgement about where these tools are useful and where they are unreliable, before any confidential material is involved.

Next step

Work out what yours is costing.

The calculator on the home page takes about ten seconds, and the fit call is thirty minutes with no deck. If the honest answer is "not yet", you'll hear that.