UK compliance hub

Law Society generative AI guidance, explained for busy firms

Generative AI – the essentials

Issued by
The Law Society of England and Wales
Published
17 November 2023
Updated
June 2026
We reviewed
17 July 2026
In one minute

The Law Society’s "Generative AI – the essentials" guide (first published November 2023, updated June 2026) tells solicitors they can use generative AI — but confidential data should not go into free, online generative AI services, and testing or template-building should always use fictional data rather than real client information. In practice that means firms need either an enterprise AI contract with retention guarantees, a technical control that removes client identifiers before prompts leave the firm, or both. The guide treats AI adoption as manageable risk — the emphasis is on confidentiality, competence, and supervision, not on avoiding AI.

What the guidance says

do not put any confidential data into the tool
The Law Society of England and WalesFor free, online generative AI services — where the firm has no operational relationship with the vendor — the instruction on confidential data is unambiguous.

Client confidential and personal data should not be used to test or build templates with generative AI — the guide says to create and use fictional data instead.

Firms should understand what the AI provider does with input data — training use, retention, and access — before approving a tool, and weigh any sharing of client data with an AI business carefully.

The June 2026 update added recent developments including a case in which two solicitors were referred to the SRA after AI-generated false information reached a court.

What this means for your firm

  • A written AI policy alone does not satisfy the guidance if staff can still paste client names into free chatbots — the control needs to reach the point of use.
  • Tool approval should be based on the provider’s data terms (retention, training, access), not on popularity.
  • If client identifiers are masked before a prompt leaves the firm, the confidentiality question changes materially: the public tool never receives the identifying content.
  • Consent conversations get easier when you can show clients exactly what does and does not reach an AI provider.

Guidance → control, line by line

How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.

No identifiable client data into public AI tools

Mask before send

Client names, addresses, NI/NHS numbers, and case references are detected and replaced with placeholders in the browser, before the prompt reaches the AI provider.

Understand and limit what the provider retains

Reversible vault (15-min TTL)

Real values never leave the firm; masked tokens are restored locally after the response returns, and vault entries expire in minutes by default.

Supervision and accountability for AI use

Audit trail

Every masking event is logged with policy, timestamp, and category counts — evidence of the control without storing raw client content.

Common questions

Does the Law Society ban solicitors from using ChatGPT?

No. The guidance permits generative AI use but expects firms to protect client confidentiality — identifiable client data should not go into public AI tools without safeguards and informed consent. The practical question is how the firm enforces that in daily work.

Is masking client data before AI use enough to satisfy the guidance?

Masking materially reduces what an AI provider receives, which is central to the confidentiality concern. It is a strong technical control, not a compliance guarantee — firms still need policy, training, and appropriate provider terms.

How current is this guidance?

It is actively maintained: first published in November 2023, with updates in 2024, May and October 2025, and June 2026. The June 2026 revision added recent regulatory developments and case references. The core position on confidential data and public AI tools has been consistent throughout — always check the original page for the current text.

This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.

See what this control looks like in practice

The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.

The control

detect → mask → send → restore → audit

Reversible vault, 15-minute TTL. The model only ever sees placeholders.