Posted by Clare Bonsall, head of product at Legal Futures Associate Access Legal [1]

Bonsall: Time to act quickly on shadow AI
It’s difficult to remember a time when AI didn’t dominate conversations at work.
But while we can assume that most people are using it at least to some degree, it remains an elephant in the room. Just how much are fee-earners relying on it to get through the workloads? Are they using it responsibly? Does it make a material difference to client outcomes and commercial goals?
These are questions that every firm leader must be able to answer. Earlier this year, in the case of Munir, the Upper Tribunal issued a stark warning [2] about the use of free open-source AI tools like ChatGPT or Google AI search. Inputting client data into these tools effectively puts it into the public domain, making it an automatic breach of legal professional privilege.
Using these tools also violates SRA principle 2 (integrity) and 7 (competence), and regulated professionals who do so must contact the regulator and consult with the Information Commissioner’s Office.
Scale of shadow AI
The problem of shadow AI (and lack of senior oversight) is evident from our own research.
Nearly 60% of fee-earners in small and mid-sized firms admit to using unapproved tools (like free versions of ChatGPT). Yet 68% of firm leaders are confident they have full visibility and zero risk of unapproved AI being used for client work.
Unless this gap is addressed, we’re likely to see more cases like Munir and the erosion of public trust in the sector.
It’s worth noting that our study, published in May, doesn’t suggest that fee-earners are using unapproved AI tools because they lack integrity – far from it.
In a sector famous for processing large amounts of information, AI is an obvious solution, allowing teams to work more efficiently, gain deeper insights and deliver a better service with higher commercial returns.
To limit AI’s use (or outright ban it) could therefore be just as damaging as giving it free rein.
Firstly, it can push fee-earners further towards shadow AI tools, creating a patchwork of unaccounted-for applications and compliance and data risks across the firm.
Secondly, it stifles innovation and competitiveness, since the most forward-thinking firms are already embracing trusted AI to drastically reduce the time it takes to resolve a case, protect their margins and improve client experiences.
Half of clients [3] expect AI involvement in legal work, according to a consumer poll we ran in 2025.
Last year, Garfield AI hit the headlines when it was authorised by the Solicitors Regulation Authority and promised it could issue business debt recovery with letters starting at just £2.
Then last month, we saw what has been described as a ‘landmark moment’ when a claimant received £7,000 in unpaid debt [4] after paying Garfield AI £400. The claimant used Garfield AI to prepare the papers, including witness statements, before the company instructed a barrister for the trial.
It’s clear that AI is already fundamentally shifting client expectations around delivery (including a move to self-service) and traditional pricing models. Fee-earners also expect to be able to use intuitive tools and find the answers they need quickly.
So, while AI is a hot topic, there are wider debates about the adoption and effectiveness of technology in general in law firms today.
According to our research [5], each fee-earner loses well over half a day (4.16 billable hours) every week due to ill-functioning technology. If firm-sanctioned applications don’t meet users’ needs because the outputs are poor, or they have to switch between screens, they won’t engage with them, or they’ll create their own workarounds.
This equates to every firm losing, on average, £2m in lost billable hours, based on 50 fee-earners working 48 weeks at £194 per hour.
Appetite for trusted AI
The Munir ruling removed ambiguity about the type of AI suitable for legal work: it must be enterprise-grade, closed-source and well-governed.
Despite the pervasiveness of shadow AI, fee-earners themselves recognise the need for trusted tools. Half of the professionals we surveyed said they would welcome AI tools, built natively into their case management system, yet only 25% of firms currently have it.
For firm leaders, now is the time to draw a line in the sand. Open and honest dialogue, avoiding a culture of blame, can highlight where AI is being used, including the applications and innovations that might be confined to one department or individual.
Alongside this, an anonymous survey could capture more candid answers from the team.
Anything free AI tools can do, enterprise-grade ones can usually do much better. Not only do they support regulatory compliance, but they also help to standardise processes and ensure equitable access across the firm, so the benefits of AI aren’t siloed.
It’s also important to audit the AI tools approved for use in the firms. Check whether the software you use to manage client data includes AI features and quiz your vendor on whether they meet the standard for data privacy (e.g. GDPR and ISO 27001), and responsible AI (ISO 42001).
Role-based permissions are also critical, since the Munir ruling highlights the responsibility supervisors have for AI-assisted outputs from their teams.
As well as limiting access and editing rights to only those who need them, these permissions also create a strong and transparent audit trail so supervisors have full oversight of decisions.
Check too whether your supervision and review processes include the use of AI because this safeguard to be built into the framework.
No matter whether you suspect the use of shadow AI in your firm, it is the time to act quickly. The Munir ruling provided clear and practical advice on the applications that can help you stay compliant and protect your reputation, while enabling you to innovate at pace.