DEV Community

Micky Irons
Micky Irons

Posted on

AI and Legal Privilege UK: Does Public AI Waive It?

Yes, if the tool is a public one. The Upper Tribunal has stated that uploading confidential documents into a public AI tool places them in the public domain, breaching client confidentiality and waiving legal professional privilege. Controlled tools are treated differently. Mickai runs the assistant offline on hardware the firm owns, so privileged files stay inside the firm.

Does uploading a document to a public AI tool waive privilege?

Yes, where the tool is a public one. A UK tribunal has now said plainly that putting confidential material into a public AI tool places it in the public domain, which breaches client confidentiality and waives legal professional privilege.

That is a harder line than most firms were working to. The common assumption was that an upload is a data protection question: a risk to be logged, reviewed, perhaps accepted. The tribunal treated it as something that changes the status of the document itself. Once privilege is waived, it is not a policy breach you can close out at the next risk meeting. It is a lost protection, and the client is the one who loses it.

I build software for organisations that cannot afford to lose that protection, so I read the judgment carefully. Below is what it says, what it does not say, and what a firm can do about it. This is general information, not legal advice.

What exactly did the Upper Tribunal say?

The case is UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC), handed down on 17 November 2025 and published at caselaw.nationalarchives.gov.uk. The passage that matters is paragraph 21, repeated at paragraph 60.

The tribunal was dealing with fabricated case citations in submissions, and with how they came to be there. In doing so it addressed the act of loading a client's papers into a public tool, and said that doing so would "breach client confidentiality and waive legal privilege". At paragraph 60 it went further: conduct of that kind might itself warrant referral to the professional regulator, and should in any event be referred to the Information Commissioner's Office.

Two details matter if you are the person who has to decide something. First, the tribunal distinguished between a public tool and a closed, controlled one. The point turns on which tool was used, not on AI as a category. Second, the referral to the data protection regulator is not framed as conditional. The tribunal said it should happen in any event.

Is client confidentiality lost as well as privilege?

Both go, and they go for different reasons. Privilege is the client's protection against disclosure. Confidentiality is your professional and statutory duty to the client, and it is engaged the moment the text leaves your control.

The data protection layer sits underneath. If the file contains personal data, and in litigation, employment or property work it almost always does, then sending it to a third party you have not assessed is a processing decision you have to justify under UK GDPR and the Data Protection Act 2018. The Information Commissioner's Office is the regulator for that (ico.org.uk). A referral of the kind the tribunal described starts that conversation from the worst available position: the regulator hears about it before your firm has decided anything.

Does a paid or enterprise AI licence change the answer?

Not by itself. The Solicitors Regulation Authority published a warning notice on the misuse of AI in August 2026 (sra.org.uk), and it is explicit that both free and paid AI systems can put client confidentiality at risk, because, depending on the provider's terms, settings and technical architecture, information entered into a system may be stored, retained or used to improve that tool. A subscription tier does not change where the data physically goes.

What an enterprise agreement gives you is a contractual promise. That has real value and I am not dismissing it. But a promise is a different kind of thing from a technical fact, and the questions in front of a firm are technical:

  • Where does the text go once it leaves the machine, and through which jurisdictions?
  • Who inside the provider can read it, and under what process?
  • Is it retained after the session ends, and for how long?
  • Is it used to train anything?
  • Can you prove the answers to a regulator without asking the provider for help?

If the last answer is no, your regulatory position rests on someone else's word. For non-regulated work that can be perfectly reasonable, and cloud services remain genuinely useful there. For privileged material it is a weak place to stand.

What counts as a controlled environment for privileged work?

The test I would apply is simple. The document never leaves hardware you control, and you can demonstrate that without relying on the vendor to confirm it.

That is how the Mickai Sovereign Intelligence Operating System is built. It runs on hardware the customer owns. It is capable of running fully offline, with no data egress. Knowledge bases are private and stay on the machine, so nothing has to cross the boundary for the assistant to be useful on a matter. Extraction and ingestion into those knowledge bases is still being completed, which I set out below. There are 63 studios in the system, 14 production-ready at launch and 49 in development, drawing on 50 specialised models we call brains.

Consequential actions wait for a named person to approve them. That is deliberate. Drafting assistance is one thing. Sending, filing or disclosing is another, and a named human signs for it.

One limitation stated plainly, because a buyer needs it. A local OCR runtime has read scanned PDFs in controlled tests, and the extraction and ingestion integration into SIOS is still being completed. If your bundles arrive as scans, ask where that work stands before you plan around it.

How does a firm prove which tool touched which document?

This is the part firms underestimate. A policy says what should have happened. Application logs say what your own software claims happened, in a format your own software produced. Neither carries much weight when a regulator is asking what was sent where.

Every consequential action in SIOS is sealed in an Open Audit Record. The seal uses ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024. An auditor can export a record and verify it offline, with a public key, using tools that are not ours. We are not in the verification path, which is the point.

The record is tamper-evident, not tamper-proof, and the difference is worth stating precisely. Tamper-proof would claim the record cannot be altered, and nobody should make that claim about bytes on a disk. Tamper-evident means that if a record is altered, verification fails. History cannot be changed quietly. That is the property an auditor actually needs, and it is the one that survives cross-examination.

What should a firm do this week?

Three things, in this order.

Find out what has already happened, by looking rather than by circulating a policy. Assume it has already happened somewhere in the past year, usually with good intentions and no malice at all. You cannot assess exposure you have not found.

Then decide where privileged work is allowed to run, and make that boundary technical rather than advisory. A rule staff have to remember will fail on a Friday afternoon with a deadline at five o'clock. A system that has no route offsite will not.

Then extend the boundary to the tools nobody logged. Meeting notetakers are the common gap: a client call transcribed by a public service is the same upload, performed automatically, often by whoever happened to book the room.

We have a closed beta running, with one regulated company onboarding as a design partner. The partner and its sector stay confidential. I am not setting this against the companies building the compute and cloud layer. They are doing necessary work and we work alongside them. What I dispute is the assumption that a regulated organisation must rent its intelligence, ship client material offsite, and then take a vendor's word for what happened to it.

Frequently asked questions

If I paste a client document into a public AI tool, is privilege gone?

Treat it as gone and act on that basis. The Upper Tribunal's position is that the material has entered the public domain, which waives privilege and breaches confidentiality at the same moment. Your immediate work is containment, an accurate record of what was uploaded and when, advice on telling the client, and a data protection assessment.

Does an enterprise AI subscription protect privilege?

Not by itself. The Solicitors Regulation Authority's warning notice on the misuse of AI states that both free and paid systems can put client confidentiality at risk, because, depending on the provider's terms, settings and architecture, material entered may be stored, retained or used to improve the tool. A contract gives you a promise about handling. It does not change where the data goes.

Can privilege be restored once it has been waived?

Assume not. Privilege protects material from disclosure, and once it is treated as being in the public domain that protection does not return because an account was deleted or a chat history cleared. Questions of scope and inadvertence are for a court on the facts. Plan on the basis that the waiver stands.

Should we report a staff member who uploaded a client file?

The judgment separates two referrals. Conduct of that kind might itself warrant referral to the professional regulator, and should in any event be referred to the Information Commissioner's Office. So the data protection referral is not discretionary in the tribunal's framing. Whether an individual faces internal action is a supervision and competence question for the firm.

Is a locally hosted AI assistant safe for privileged documents, including meeting notetakers?

A deployment on hardware you own, capable of running offline with no data egress, keeps the document inside the boundary, which is what the tribunal's distinction turns on. The same test applies to notetakers: a client call sent to a public transcription service is the same upload. Run transcription locally and keep a verifiable record.


Written by Micky Irons, founder and chief executive of Mickai LTD, which builds a sovereign AI operating system for regulated organisations. More at mickai.co.uk.

Top comments (0)