Back to blog

Legal

A UK Tribunal Treated Pasting Client Letters Into ChatGPT as a Data Breach

An Upper Tribunal ruling on an immigration adviser's ChatGPT use shows the real lesson is controls and evidence, not banning AI. Here's what actually failed.

NeutralAI Team2026-07-038 min read

17 November 2025, Upper Tribunal (Immigration and Asylum Chamber). In UK and R (on the application of Munir) v Secretary of State for the Home Department, Munir v SSHD, UKUT 81 (IAC), 2026, a level 3 IAA-accredited immigration adviser — who also held a solicitor's practising certificate — Mr Tahir Mohammed, uploaded Home Office decision letters into ChatGPT to generate client summaries, and separately pasted draft client emails into the tool to improve their wording. He accepted that this was a data breach, and undertook to notify the affected clients and self-report to his regulators, the IAA and the SRA. The tribunal went further than a general warning: it said that uploading confidential documents into a public AI tool such as ChatGPT places that information in the public domain, and so breaches client confidentiality and waives legal privilege. The ruling was heard on 15 October and 5 November 2025 and promulgated on 17 November 2025, then drew wide legal-press coverage from around February 2026 onward. The case is a useful, unglamorous example of how ordinary AI use — not a dramatic hack — becomes a reportable incident, and of what a firm needs in place before that happens.


Client letter passing through a masking control point before reaching a public AI tool
The tribunal's concern wasn't a hack — it was an ordinary upload with no control point between the letter and a public AI tool.

What happened

The facts are mundane, which is exactly why the case matters. An immigration adviser working on a client's case wanted help with two everyday tasks: summarising a Home Office decision letter, and tidying the language in a draft email to a client. He used ChatGPT for both. The letter and the email both contained information that identified the client and their case.

The adviser accepted before the tribunal that this amounted to a data breach. He committed to notifying the clients whose information had been exposed and to self-reporting to his professional regulators. The tribunal's own words were direct: uploading confidential documents into a public AI tool "is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege" — and it noted such conduct might itself warrant a referral to the regulator, and should in any event be referred to the Information Commissioner's Office.

There was no external attacker, no stolen laptop, no phishing email. The exposure happened through a normal browser tab, during normal casework, because a free consumer AI tool was the fastest way to get a summary and a cleaner sentence.

Why "we banned AI" wouldn't have saved this firm

The instinctive response to a story like this is to tighten the acceptable-use policy: no client data in ChatGPT, full stop. That instinct is understandable, but it doesn't hold up against how the incident actually occurred.

Policy alone doesn't inspect what goes into a prompt. A ban is only as good as everyone's memory of it, every time, under deadline pressure, across every browser tab. The adviser in this case was presumably subject to some version of a confidentiality obligation already — that's the baseline of professional legal practice, whether the representative is a solicitor or an accredited adviser. The gap wasn't a missing rule. It was the absence of anything sitting between "paste this letter into ChatGPT" and the letter actually leaving the firm's control.

Banning a tool changes what people are told to do. It does nothing to what happens when they don't, because there's no technical checkpoint to catch the letter before it leaves the browser. That's the distinction regulators and courts increasingly seem to be drawing: not whether firms permit AI, but whether they can show a control existed at the point sensitive data was about to leave.

What the guidance already requires

This isn't a novel expectation invented by one tribunal. The Law Society's "Generative AI — the essentials" practice guidance first went live on 20 May 2025 and is explicit on this point: firms should consider whether it's appropriate to put particular inputs into a generative AI tool at all, communicate their use of AI to clients, and not put confidential client data into free, public AI tools where they have no control over how that data is used — that's roughly six months before this ruling was promulgated, not the nine months a February 2026 reading of the dates might suggest. (The guidance page has since been revised and, as of this writing, shows a 1 October 2025 last-updated date — still before the ruling.) Either way, the tribunal wasn't setting new law; it was applying an obligation the profession's own representative body had already spelled out.

Regulators are also not waiting for AI-specific incidents to start enforcing data-protection basics in law firms. The ICO fined DPP Law Ltd £60,000 on 14 April 2025, after a cyber attack exfiltrated highly sensitive client data — a reminder that the regulator is actively scrutinising how firms handle client information, AI-related or not.

Courts are watching a related but distinct failure mode too. In Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank, EWHC 1383 (Admin), 2025, decided 6 June 2025, lawyers cited AI-hallucinated case authorities in court filings. The High Court held the conduct improper, unreasonable, and in one instance negligent, and referred the matter to the relevant regulators. Different failure — fabricated citations rather than a confidentiality breach — but the same underlying theme: courts and regulators are treating careless AI use as a conduct issue, not a technology footnote.

Put together, these three developments describe a profession where "we didn't have a policy" is no longer a plausible defence, and increasingly, neither is "we had a policy."

What good looks like: mask before send, and keep the evidence

Be precise about what the tribunal actually objected to before reaching for a fix. Its concern was not merely that names and case references were visible — it was that whole client letters and Home Office decision letters, as documents, were uploaded into an open, public AI system at all. On the tribunal's reasoning, that act placed the content "in the public domain" and was enough by itself to breach confidentiality and waive privilege, regardless of which words in the letter were identifying. Masking a person's name in a prompt does not undo that: it reduces identifiable data reaching the model, it does not stop privileged case material from being disclosed to a third-party AI provider in the first place.

So the practical answer sits between "ban AI" and "trust everyone to remember the rule every time," but it has to be honest about its limits. Two things need to be true at the point a prompt is about to leave a firm's control.

First, identifiable client data shouldn't reach a public AI tool in its raw form. A legal representative should still be able to ask for help summarising a decision letter or tightening a paragraph — that's genuinely useful work. What shouldn't happen is the client's name, case reference, and personal details travelling along with the request unmasked. Masking or tokenizing that data before it leaves the firm's environment reduces the personal-data exposure in the prompt. It is not a legal opinion on privilege or confidentiality, and on its own it does not make it safe to upload an entire privileged client letter to a public model — firms still need a policy decision about which documents and which tools are in scope, ideally backed by a data protection impact assessment, before deciding what should reach an AI system at all.

Second, when something needs checking later — by a partner, a regulator, or an insurer — a firm needs to show the control ran, without reconstructing events from memory or screenshots. That means evidence: a record that a request was screened and what categories of data were detected, not the raw client data itself sitting in a log, which would just recreate the original problem.

A useful way to frame the difference:

  • Policy only — relies on people remembering and following a rule under time pressure, with no record of whether they did.
  • Ban only — removes the fast path for genuinely useful work, without adding any technical checkpoint, and pushes usage into shadow workflows that are harder to see, not easier.
  • Mask before send + audit evidence + a documented policy on what may be uploaded — lets appropriate summarisation and drafting work continue, strips or tokenizes identifiable client data before it reaches the external tool, and leaves a record that the control operated — alongside, not instead of, a firm decision about which documents and tools are permitted.

This is the boundary NeutralAI is built to sit on: designed to reduce unnecessary exposure of client-identifiable data before a prompt reaches a public AI provider, and to help firms evidence that the control ran. That's a narrower claim than promising compliance, resolving privilege or confidentiality risk, or that any specific incident would have been prevented — no masking layer replaces professional judgment, a firm's own DPIA and policy work, or its regulatory advice.

The lesson

The Upper Tribunal case will likely be cited as a cautionary tale about AI in legal practice, and it is one. But the more durable lesson isn't "don't use ChatGPT." It's that useful, everyday AI tasks — summarising a letter, improving a sentence — will keep happening whether or not a policy exists, and firms that want to allow that work safely need a control point that acts before data leaves, plus evidence that it did. That combination is what turns "we have a policy" into something a regulator can actually verify.

Last reviewed: July 2026.

Sources

For a legal-sector walkthrough of how masking and audit evidence fit into existing workflows, see AI data protection for legal teams, or try the NeutralAI playground with a sample client letter.

Want to make AI safer for your team?

NeutralAI helps regulated teams mask sensitive prompt data before it reaches external model providers.