UK compliance hub

The judiciary’s AI guidance: the clearest line in UK legal AI

Artificial Intelligence (AI) — Guidance for Judicial Office Holders

Issued by
Courts and Tribunals Judiciary
Published
12 December 2023
Updated
31 October 2025
We reviewed
17 July 2026
In one minute

The judiciary’s AI guidance for judicial office holders (December 2023, updated October 2025) contains the single clearest sentence in UK legal AI: any information you input into a public AI chatbot "should be seen as being published to all the world." Judges are told not to enter anything that is not already public. The October 2025 update also added warnings about white text and hidden prompts embedded in documents. If that is the standard the bench applies to itself, it is a reasonable benchmark for anyone handling confidential material.

What the guidance says

Do not enter any information into a public AI chatbot that is not already in the public domain.
Courts and Tribunals JudiciaryThe confidentiality rule is absolute for public chatbots.
Any information that you input into a public AI chatbot should be seen as being published to all the world.
Courts and Tribunals JudiciaryInputs are treated as irreversible publication.

The October 2025 version added a glossary entry for "white text" and warns about hidden prompts concealed in documents — visible to the system but not the human reader.

Coverage is broad: all judicial office holders plus clerks, judicial assistants, and legal advisers under the Lady Chief Justice and Senior President of Tribunals.

What this means for your firm

  • The "published to all the world" framing is the same reasoning the Upper Tribunal applied in Munir v SSHD when a representative pasted client letters into ChatGPT — this is now a consistent judicial position.
  • If a matter may end up before a judge, assume the judge holds this view of what pasting into a chatbot means.
  • The white-text warning matters for document uploads: what a human reviewer sees is not necessarily what the model receives.
  • The operational answer is the same as everywhere else in this hub: make sure non-public information physically cannot reach the public tool.

Guidance → control, line by line

How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.

Nothing non-public into public AI chatbots

Mask before send

Client-identifiable and confidential specifics are replaced before submission, so the public tool receives only de-identified content.

Treat inputs as irreversible publication

Reversible vault (15-min TTL)

Because real values never leave the firm, there is nothing to "recall" from the provider — restoration happens locally, and vault entries expire by default.

Beware hidden content in documents

Document scan gate

Uploads are scanned before submission, on the same masked path as typed prompts — reducing the gap between what a human sees and what the model receives.

Common questions

Does the judiciary’s guidance apply to law firms?

Not directly — it binds judicial office holders and their support staff. Its wider value is as a benchmark: it shows how the bench itself characterises entering information into public AI tools, which informed the Upper Tribunal’s reasoning in Munir v SSHD.

What is the "white text" warning about?

Hidden prompts or concealed text can be embedded in a document so the system reads instructions a human reviewer cannot see. The October 2025 update added this to the guidance glossary — it is a document-upload risk, not just a chat risk.

What changed between the 2023 and 2025 versions?

The core confidentiality position is unchanged. The chain is December 2023 → April 2025 → October 2025, with the latest version adding the white-text/hidden-prompt warnings and updated definitions. Read the current version at the source link.

This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.

See what this control looks like in practice

The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.

The control

detect → mask → send → restore → audit

Reversible vault, 15-minute TTL. The model only ever sees placeholders.