
The ungoverned AI problem hiding in plain sight
Andrew Stevens, general manager at Access Legal, highlights the prevalence of shadow AI use and practical measures for creating an effective strategy for responsible AI use
A landmark ruling from the Upper Tribunal earlier this year sparked a much-needed conversation about the use of AI tools in law firms. In Munir v Secretary of State [2026] UKUT 81 (IAC), the court made clear that uploading client materials to open-source AI tools puts that information into the public domain, breaching confidentiality, extinguishing legal professional privilege, and triggering mandatory reporting obligations to the ICO and the SRA.
It has prompted firms to take a harder look at the tools their people are using, and rightly so. But the conversation that follows matters just as much as the one that started it.
The problem isn’t AI. It’s the wrong AI.
There is a meaningful difference between open-source consumer tools, ChatGPT, free browser extensions, public-facing models, and closed, enterprise-grade environments where data never leaves a contractually controlled space. The Munir ruling drew exactly this distinction. Microsoft Copilot, for example, was cited as a low-risk option for tasks like summarising notes. The court wasn’t condemning AI. It was condemning ungoverned AI.
This distinction matters enormously, because the data on how fee earners are actually using AI tells a story that firm leaders need to hear.
Our research found that 59% of fee earners admit to using tools like ChatGPT. Not because they’re reckless, but because their firm’s existing software is old, slow and doesn’t give them what they need to do their job well. Poor technology contributes to a loss of 4.16 billable hours per fee earner every week. At a typical rate, that’s more than £36,000 in unbilled work per lawyer per year. This is as much a revenue problem as a compliance one.
Meanwhile, 68% of firm leaders say they’re confident there’s no risk of unauthorised AI use in their firm. A further 21% actively disagree that they have full visibility. The gap between what leaders believe and what is actually happening on the ground is significant, and it’s widening.
Who is actually using it, and why
The pattern of shadow AI use is telling. It’s highest among paralegals (71%) and solicitors (57%): the people closest to client work, managing the heaviest caseloads. These aren’t junior staff cutting corners. They’re professionals trying to maintain quality under pressure, often at the start of careers where expectations are high and support is thin.
Shadow AI use is also significantly higher in firms with 250 to 500 employees. Scale and complexity, not naivety, appear to be the real drivers. The bigger the firm, the harder it is to keep oversight tight, and the more likely it is that people will find their own solutions when the approved ones fall short.
Client expectations are adding pressure from the other direction. Separate research we conducted found that half of clients expect AI to be involved in at least some elements of their legal work, in much the same way they expect it from their bank or insurer. There are no prizes for doing things the slow way. Clients want good outcomes, delivered efficiently.
Why restriction makes the problem worse
Here’s what the data shows about mandated tools: three-quarters of firm leaders already struggle to get fee earners to consistently use separate digital tools, tools they’ve invested in and required people to use. If approved AI is hard to adopt, banned AI is even harder to avoid.
Restriction also creates a different kind of risk. Under the SRA’s competence framework, withholding tools that would allow fee earners to do their job effectively and efficiently isn’t a neutral act. It has professional implications of its own.
The starting point for any firm’s AI strategy should be what people can use safely and responsibly, not what they can’t. When the safe option is also the easy option, the workaround disappears.
What responsible AI actually looks like in practice
Enterprise-grade AI environments operate on a fundamentally different basis to consumer tools. At Access Legal, our AI operates within a private, secure environment: no customer data is used in open AI systems for training purposes, user role-specific permissions are replicated within the AI layer, and each individual’s use remains personally confidential. That’s not a marketing position; it’s a structural one, underpinned by ISO 42001 accreditation, the first international standard for AI management systems.
The principles that should govern any firm’s AI adoption are the same ones that govern responsible technology use more broadly: transparency about how decisions are made, accountability for outcomes, and security that doesn’t compromise when it’s inconvenient.
What to do now
Whatever the extent of unauthorised AI use in your firm, the first step is an honest audit of what’s actually being used. The compliance exposure extends beyond confidentiality. More than half of legal leaders in our research cited AML failures and regulatory breaches as a direct risk of fragmented, ungoverned systems. Any audit of AI tools must also assess whether compliance and AML workflows sit within the same governed environment, not bolted on separately.
The professionals using unapproved AI aren’t doing so carelessly. They’re trying to do their job well. The Munir ruling makes clear that good intentions aren’t a defence, but the answer isn’t to make their lives harder. It’s to close the gap between what they need to work effectively and what their firm can safely allow them to use.
When those two things are the same thing, the choice disappears.


