top of page
web banner Fika Friday.png

Article 2.4 · Client Data Is Not Training Material

  • Writer: Will Whawell
    Will Whawell
  • 4 days ago
  • 6 min read

T3PS Legal Dynamics · Series 2: AI Readiness — It’s Not a Technology Question ·


Written by Will Whawell. Human intelligence throughout; AI assisted with the drafting.


Fact-verified June 2026


A managing partner told me, not long ago and with some pride, that his firm had “gone all in on AI.” I asked which tools, and on what data. There was a pause. It turned out the fee earners were pasting client documents — witness statements, heads of terms, a settlement position or two — into a free public chatbot, because it was quick and nobody had told them not to. He had not deployed AI. He had exposed his clients’ confidential information to a third party he had never assessed, and called it innovation. He is not unusual. He is the median.


The Series 2 argument has been that AI readiness is not really a technology question. It is a data question and a governance question wearing a technology costume. Nowhere is that clearer than here. The missing question for most firms is not whether AI can produce useful work. It plainly can. The question is what the firm had to expose to the system to get that work — and whether it had any right to.


A law firm’s data is not an undifferentiated productivity asset

It is tempting to treat the firm’s documents as raw fuel for efficiency. They are nothing of the sort. They include client confidential information, privileged material, special-category data, commercially sensitive documents, litigation strategy, settlement positions, medical records, employment records, financial information, and personal data belonging to third parties who have never heard of the AI provider being used and never consented to it. Feeding that into an AI system is not a technical decision. It is a data-protection, confidentiality, privilege and professional-conduct decision, all at once — and most firms have been making it implicitly, at the level of the individual fee earner under time pressure, which is the worst possible place for it to be made.


There is hard evidence this is happening at scale. Research cited across the sector has found a large majority of corporate legal teams using unapproved AI tools, with a substantial minority admitting that sensitive or private data has been put into unvetted systems. “Shadow AI” — unsanctioned tools used quietly by individuals — is not a fringe risk. For many firms it is the actual operating model, just one nobody has written down.


The regulator is not ambiguous about this

The SRA’s developing approach is consistent and, on the central point, blunt. Firms are expected to be transparent about AI use, to understand what data is used, to maintain oversight, and not to put identifiable client data into AI tools without informed consent. On public tools the guidance reported from the SRA’s February 2026 webinar on AI policy and regulation is especially direct: raw client data should not be placed into public AI systems. That is not a style preference. It follows straight from the existing duties of confidentiality, competence and supervision — none of which the arrival of a clever tool suspends.


And the client at the other end of the matter is increasingly informed. The same SRA-commissioned research found that roughly a third of the public has already used generative AI to help identify legal issues, often alongside a solicitor. The client may be AI-literate enough to ask, pointedly, what the firm does with their data — and a firm that cannot answer has a problem that is now commercial as well as regulatory.

The questions that are no longer optional

For any firm using AI on client work, a defined set of questions has stopped being good practice and become baseline diligence:


—   Which AI tools are approved for client work — and which are banned?

—   Does the provider train its model on client inputs?

—   Where is the data processed and stored?

—   Is there a UK GDPR Article 28-compliant data-processing agreement in place?

—   Can client data be segregated, deleted, exported and audited?

—   Are prompts and outputs retained — and if so, by whom, and for how long?

—   Has the client been told how AI may be used on the matter?

—   Is the firm’s confidentiality obligation actually preserved end to end?

—   Has the COLP signed off the risk assessment?


If a firm cannot answer those questions, it has not deployed AI. It has outsourced risk and renamed it innovation. The distinction matters most at exactly the moment it is most tempting to ignore — when a tool is fast, free and already in the building.


Why “does it train on my data?” is the load-bearing question

Of all those questions, one carries more weight than the rest: does the provider use client inputs to train its model? Because if it does, the firm is not merely sending confidential material to a processor under controlled terms. It is potentially contributing that material to a system whose future outputs are, by design, shaped by what it has absorbed — a system other people, including opponents, will use. That is the precise sense in which client data must never be training material. The phrase is not a slogan. It is the bright line. A firm can use AI extensively and responsibly while holding that line; it cannot cross it and still claim to have protected privilege and confidentiality.


This is also where the firm’s answer to a sophisticated client’s procurement questions is won or lost. “We use approved tools that do not train on your data, under a compliant processing agreement, with named human review and an audit trail” is a sentence that closes business. “We’re very excited about AI” is a sentence that invites a follow-up the firm cannot survive.


Where ISO 42001 earns its place

This is the point at which a governance standard stops being a compliance overhead and becomes a commercial asset. ISO 42001 — the AI management-system standard — forces AI governance out of informal enthusiasm and into auditable controls: approved-tool registers, risk assessments, defined responsibilities, monitoring, review. It links naturally to ISO 27001 information-security controls and to UK GDPR accountability, so the three reinforce each other rather than sitting in separate binders. A firm that holds, or is working towards, that kind of management system can answer every question in the list above without flinching — not because it is virtuous, but because it built the machinery to know.


That is the readiness Series 2 has been describing throughout. Not the firm with the most tools, or the loudest AI strategy slide. The firm that can say, precisely and on demand, what data goes where, under what terms, with whose sign-off, and with what record. In BREW terms this is Business Intelligence and Workflow Excellence doing quiet, unglamorous work — the foundations that let everything built on top of them be trusted.


Readiness is a decision, not a purchase

The firm that pastes client documents into a public chatbot and the firm that runs an approved, audited, contractually-bound AI workflow may be using technology that looks similar from the outside. They are not in the same business. One has made a decision about its clients’ data and can defend it. The other has let a thousand individual decisions be made for it, under time pressure, by people who were never told the stakes. AI readiness is the act of replacing the second state with the first. It is governance, not gadgetry — and it is entirely within a firm’s control, whatever its size.

Three questions to take back to your desk

—   Right now, today, do you know which AI tools your fee earners are actually using on client work — including the ones nobody approved?


—   For each approved tool, can you state plainly whether it trains on client inputs, and where the data is processed?


—   If a major client’s procurement team asked how you protect their data in AI tools, would your answer win the panel place or lose it?


Most firms discover their real AI-data position is messier than the one on the strategy slide. Finding that out over a coffee is a great deal more comfortable than finding it out in a breach notification or a panel review. A Fika is a sensible place to map what you are actually running.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page