Public AI tools can destroy legal privilege. Shadow AI just became a litigation risk
A UK Upper Tribunal warning on AI use in legal work cuts through the hype: uploading confidential documents into open, public AI tools can waive privilege and breach confidentiality.
That is not a futuristic risk. It is ordinary workflow. A junior staff member pastes a draft, a case summary, or an attachment into a chatbot to "tidy it up", and the organisation quietly crosses a line it cannot uncross.
The uncomfortable point is that many governance programmes are aimed at accuracy and bias. The immediate failure mode is procedural: evidence handling, disclosure duties, and professional obligations. Once privilege is compromised, there is no clever model card that fixes it.
This should force a rethink on Shadow AI. The question is not whether staff should use AI. It is whether the firm can prove where sensitive material went, which tools touched it, and what controls existed at the time. If the answer is "nobody knows", the risk is already live.
The same applies beyond law firms. Accountants, consultants, insurers, and in-house teams all handle sensitive documents that can end up in disputes later. A casual paste today can become an expensive disclosure problem tomorrow.
Questions for comment:
- Are organisations treating public AI tools as safe because nobody has been caught yet?
- What should be the default rule for staff: never paste client data, or use only approved closed systems?
- Should regulators require audit logs for AI use in legal and professional services?
- How should liability be handled if an AI workflow compromises privilege in a live case?
- What practical training actually changes behaviour, beyond policy PDFs?

