Artificial intelligence is increasingly embedded in legal and commercial work. Documents can be summarised, analysed and compared in seconds, and large volumes of information can be processed far more efficiently than through traditional methods.
However, the convenience of AI creates a separate and potentially serious issue. What happens to confidentiality and legal professional privilege when sensitive material is uploaded to an AI tool?
Recent authority has brought that question into sharp focus.
AI and the loss of privilege
In UK and R (on the application of Munir) v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC), the Upper Tribunal considered two cases involving the misuse of artificial intelligence by legal representatives.
Much of the decision concerned the use of AI-generated authorities which did not exist or did not support the propositions for which they were cited. For further discussion of ‘AI hallucinations’, please see our previous article here. However, the Tribunal also addressed a different risk which may have even wider implications for legal practice – the effect of uploading confidential or privileged information to publicly available AI tools.
The Tribunal observed that putting client letters and Home Office decision letters into an open-source AI tool such as ChatGPT amounted to placing that information into the public domain, thereby breaching client confidentiality and waiving legal privilege.
That observation is significant because confidentiality lies at the heart of legal professional privilege. Privilege belongs to the client and protects certain confidential communications from disclosure without the client’s permission. Once confidentiality is lost, the protection afforded by privilege may also be lost.
This creates an obvious risk where AI is used to analyse material such as legal advice, witness evidence, expert reports, correspondence concerning litigation strategy, internal investigations or other documents created for the purpose of actual or contemplated proceedings.
Not all AI tools are the same
The Tribunal drew an important distinction between publicly available AI tools and closed systems which do not place information into the public domain.
That distinction should not, however, be treated simply as a question of which AI provider is being used. AI products are available in different configurations and subject to different contractual terms. The relevant questions include how information submitted to the system is processed and stored, whether it is used to train or improve the underlying model, who may have access to it, whether it is retained, and what contractual protections apply.
For lawyers, this means that using AI safely requires more than knowing the name of the product. Firms need to understand the particular system and configuration being used and the contractual and technical protections surrounding the information submitted to it.
This is consistent with guidance from the Law Society, which warns against entering confidential information into generative AI tools where there is insufficient control and oversight over how that information is processed.
The distinction is therefore between AI being used within an appropriately controlled environment and confidential information being provided to an external system without adequate safeguards.
Why privilege matters
Legal professional privilege is not simply another confidentiality obligation. It is a fundamental protection which allows clients to communicate candidly with their lawyers without those communications subsequently being disclosed to an opponent or the court.
There are two principal forms of legal professional privilege.
Legal advice privilege protects confidential communications between a lawyer and client for the purpose of giving or receiving legal advice. Litigation privilege can extend more widely to communications between lawyers, clients and third parties where litigation is in progress or reasonably contemplated and the communication is made for the dominant purpose of that litigation.
The material potentially affected by inappropriate AI use is therefore extensive. It may include legal opinions, advice on prospects and strategy, witness statements and proofs of evidence, expert instructions and reports, internal investigation material and correspondence analysing the strengths and weaknesses of a claim or defence.
The danger is particularly easy to overlook because uploading a document to an AI tool does not feel like conventional disclosure. There is no obvious recipient and the process may appear no different from using another piece of software. Legally, however, the relevant question is what happens to the information once it leaves the controlled environment in which its confidentiality was being maintained.
The risk does not end with the lawyer
There is also a wider commercial issue.
Businesses routinely disclose confidential information to prospective purchasers, investors, professional advisers, consultants, suppliers and commercial counterparties. Traditionally, an NDA would restrict the recipient from disclosing or using that information other than for an agreed purpose.
The increasing use of AI means that businesses should now also consider how recipients are permitted to process confidential information.
A recipient might comply with the conventional wording of an NDA in the sense that it has not deliberately sent confidential information to another individual but nevertheless upload that information to an external AI platform to summarise documents, analyse financial information, review a contract or prepare a report. Depending upon the system concerned and its terms of use, that may expose the information to processing, retention or use outside the parameters contemplated when the information was originally disclosed.
For that reason, AI-specific provisions are increasingly relevant when drafting and negotiating confidentiality arrangements.
An NDA may, for example, prohibit confidential information from being processed using machine learning or AI systems altogether. Alternatively, it may permit the use of approved AI systems subject to safeguards, including requirements that the confidential information is not used to train the model and is not made available or accessible to unauthorised persons.
The appropriate restriction will depend upon the transaction. An absolute prohibition may be appropriate where particularly sensitive information is being disclosed. In other circumstances, a controlled-use provision may provide a better balance between protecting confidentiality and allowing legitimate use of secure AI tools.
This is particularly important because contractual controls can address the risk before confidential information leaves the discloser’s control. Businesses should therefore consider not only their own internal AI policies but also whether their NDAs, confidentiality clauses and contractual arrangements adequately regulate the use of their information by others.
Practical protection
The implications extend beyond the wording of NDAs. Organisations using AI should understand which systems their employees and advisers are permitted to use, what information can be entered into them and what happens to that information afterwards.
For law firms, the issue also engages professional obligations concerning confidentiality and supervision. The SRA requires solicitors and firms to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. AI-assisted work also remains subject to appropriate human review and professional supervision.
The starting point should therefore be that confidential or privileged information is not uploaded to an AI system unless the user understands and is satisfied with the relevant data-processing arrangements and the use is consistent with the firm’s policies and professional obligations.
Businesses should adopt a similar approach. Internal AI policies, appropriate access controls, due diligence on AI providers and carefully drafted contractual restrictions can all reduce the risk of confidential information being used in ways that were never intended.
A new confidentiality risk
AI has considerable potential to improve the efficiency of legal and commercial work. The issue is not whether it should be used, but whether organisations understand what happens to their information when it is.
The decision in Munir is an important reminder that the consequences can extend beyond inaccurate AI output. Where confidential or privileged material is involved, inappropriate use of AI may compromise the confidentiality on which legal professional privilege depends.
The same issue increasingly arises outside legal practice. Businesses disclosing commercially sensitive information should consider whether traditional confidentiality provisions are sufficient in circumstances where the recipient may have immediate access to AI tools capable of processing that information.
As AI becomes part of ordinary working practice, confidentiality protections need to develop with it. That means considering not only who may receive confidential information, but also what technology they may use to process it.
Our firm can advise businesses on confidentiality, legal professional privilege and contractual protections concerning the use of artificial intelligence. Please do not hesitate to contact us if we can be of assistance.



