Two of this month's five free Independent AI Audits are still open — included when you start an AI health check.Check eligibility →
Legal

Nearly every lawyer uses AI. Half worry about what it leaks.

Research, summarisation, drafting and review are now routine — so are hallucinated authorities and client material pasted into public tools.

SECTOR SNAPSHOT Legal 94%
LegalGenWA · sector view
94%

of UK lawyers use AI; one in three daily (LexisNexis, 2026, vendor survey)

83%

worry about hallucinated content, up 26 points since early 2024 (LexisNexis, 2026, vendor survey)

53%

worry about confidentiality leaks (LexisNexis, 2026, vendor survey)

What your regulator has said

Accountability stays with a named person.

SRA warning notice, 17 August 2026: “AI has no separate legal personality; solicitors … remain accountable for their work and outputs, regardless of how that work has been prepared.” Putting client material into a public tool “is to place this information on the internet in the public domain”, and privilege may be lost for good. Professional indemnity insurers now ask for an AI policy, risk framework, training and monitoring evidence at renewal.

Regulator statements summarised from the published guidance; see the sources on the Problems page. This supports compliance; it is not legal advice.

Where AI is already used
  • Legal research and case summarisation
  • Contract review and clause extraction
  • Drafting and first-pass review
  • Client intake, AML and risk checks
What goes wrong
  • Client material in personal or public accounts
  • Fabricated citations reaching a client or a court
  • Partners buying tools per team with no register
What we do

Gateway with redaction and managed accounts for the tools fee-earners already use. Library so precedents and prompts are shared, not rebuilt. Usage Insight by practice group. Ledger as the record for the SRA and for clients.

Built in for this sector

The rules, as controls.

  • SRA Standards and Regulations
  • SRA warning notice on AI (Aug 2026)
  • Client confidentiality and privilege
  • Money Laundering Regulations 2017
  • UK GDPR and DUAA
The first ninety days
StartSet up with your teamRegister across managed accounts and the systems this sector runs on, set up by our team with your IT lead. Nothing for your people to install.
48 hFirst findingsEvery tool, account and pound. Personal accounts named. Sector rules checked.
Day 10Report and planAudit, evidence pack outline, 90-day plan, and the cost of doing it with us.
Day 90Under controlGateway live, rules enforced, first agent on a job with a named owner, value register running.
insight.genwa.co.uk/overview
Overview · September 2026example data · 310 people
Policy breaches · 30 days143 open · 11 resolved
Data stopped before leaving128items redacted or blocked
Personal AI accounts31 → 4migrating to managed
Spend vs budget£11,240of £14,000 · saved £4,870
Issues detected · needs attention first
Issue Rule Severity Owner Status
Payroll file uploaded to an external AI tool R-15 High HR Director Blocked · reviewed
31 personal AI accounts found in Sales R-02 High Head of Sales Migrating · 27 done
Customer data in a prompt without redaction R-01 High Ops lead Redacted · 0 left
Premium model used for internal drafts · 412 requests R-07 Medium Engineering lead Rerouted
CRM "AI assist" running without a DPIA Policy Medium Head of Sales DPIA in progress
Agent attempted an external email R-12 Low S. Reid Held · approved
Questions we are asked

From this sector.

Our professional indemnity insurer is asking about AI.

Evidence Packs give them the register, the controls and the exception log. Several insurers now ask for exactly that.

Where does our data go?

Nowhere new. Everything runs inside your own cloud account. Nothing routes through GenWA's infrastructure. Sensitive data is removed before a request leaves your environment.

Find out where your AI stands. Then decide.

Under a minute, an upload, or a visit. Something for the board either way.