DEV Community

Cover image for The SRA Is Watching AI in 2026: How UK Law Firms Review Contracts Without Sending Client Data to the Cloud
Micky Irons
Micky Irons

Posted on • Originally published at mickai.co.uk

The SRA Is Watching AI in 2026: How UK Law Firms Review Contracts Without Sending Client Data to the Cloud

UK law firms can do legal AI contract review without sending a single client document to the cloud: run the redlining, due diligence extraction and clause drafting on the firm's own hardware, and the client data never leaves the building. That is the saving. You stop paying per seat for cloud legal AI and per matter for cloud processing, you remove the confidentiality exposure the SRA has put firms on notice about, and the money moves into one system you own rather than a stack of subscriptions you rent.

Why legal AI contract review confidentiality is the risk the SRA is watching in 2026

The regulator has already spelled out where this goes wrong. Industry reporting on the SRA's risk outlook for AI in the legal market flagged confidentiality, competence and supervision as the live concerns, and it treats putting confidential client information into a public AI tool as a likely breach of the duty of confidentiality, one that can also risk waiving legal professional privilege. A May 2026 survey found that most UK legal professionals had already used unauthorised AI tools for client work, which means the exposure is not theoretical, it is happening quietly on personal accounts.

The uncomfortable part is that the cheapest tools are the ones most likely to breach. A free public chatbot has no contractual wall around your client's data, and the paid cloud suites still move that data off your infrastructure to a vendor you do not control. The way to close the risk is not another policy memo, it is to make the sanctioned tool the one that keeps the data on site.

What cloud legal AI costs a firm today

Two bills sit on top of each other. First is the licence: contract review and due diligence platforms are quoted per seat, and for a mid market firm putting a tool in front of every fee earner, that number scales with headcount whether or not a given seat is busy that month. Second is the processing: documents uploaded for review carry cloud fees, often billed per matter, so a heavy diligence exercise on a transaction becomes its own line item.

Then there is the cost that never appears on an invoice. Every matter run through an external cloud tool is a matter whose confidentiality now depends on someone else's security and someone else's training practices. The SRA has made clear the accountability stays with the solicitor. A breach or a privilege waiver is not a software refund, it is a professional and reputational cost that dwarfs the subscription.

How Astraea reviews contracts on the firm's own hardware

Astraea is our contracts studio, and a studio is a ready made application for one business function that runs inside a single system. Astraea redlines contracts, extracts due diligence points and drafts clauses, and it does all of it offline on the firm's own hardware. It is built to replace Harvey, Luminance, Kira and Ironclad, but the difference that matters is where the work happens: nothing leaves the machine.

The Assistant that drives Astraea runs on the firm's own brain, a model built on the firm's own data and precedent rather than a shared cloud service. Privilege is preserved because the document, the prompt and the output all stay on infrastructure the firm controls, and no client data enters an external training set. When a partner asks the hard question, whether a diligence exercise put client data at risk, the honest answer is that it never left the room.

What you replace, and what you save

| What you run today | What it costs you | With Mickai |

| --- | --- | --- |

| Harvey, a generative legal assistant | Per seat licence, and prompts leave the firm | Astraea drafts and researches offline, no per seat meter and no data egress |

| Luminance or Kira for contract review and due diligence extraction | Per seat or per matter, with documents uploaded to a vendor cloud | Extraction runs on the firm's own hardware, the per matter cloud fee disappears |

| Ironclad for redlining and contract lifecycle | Per seat subscription plus cloud storage | Redlining on owned hardware, each run sealed to the Open Audit Record |

| Free public chatbots used off the books for client work | Confidentiality breach and privilege waiver exposure | A sanctioned offline system where no prompt leaves the machine |

| Outside review or offshore extraction hours | Hourly labour billed per matter | The Assistant runs on the firm's own brain, the labour stays in house |

The audit trail that answers a supervision question

Supervision is the third thing the SRA named, and it is the one AI makes harder, because a system can produce far more output than a partner can read line by line. Astraea seals every run under post-quantum cryptography into the Open Audit Record, a signed, tamper evident log of who ran what, on which document, and when. That is not a compliance certificate, it is the evidence a supervising solicitor needs to show the work was overseen, and it is produced as a by product of doing the job rather than assembled after the fact.

It also changes the shape of a regulatory or client query. Instead of reconstructing what a cloud vendor did with a matter, the firm holds a local, verifiable record on its own hardware. The evidence supports the confidentiality and supervision standards the SRA examines, without claiming any certification the firm has not earned.

How a matter runs end to end, offline

In practice a matter moves through Astraea like this, and every step stays on the firm's own hardware:

  • Load the contract set and the matter's data room into Astraea on the firm's own hardware, with no upload to any external cloud.
  • The Assistant, running on the firm's own brain, redlines against your house positions and playbook and flags the clauses that fall outside them.
  • Due diligence points and risk items are extracted with a citation back to the source document, so a fee earner can verify each one against the paper.
  • A fee earner reviews and approves; the model drafts and marks up but does not send, file or complete anything irreversible on its own.
  • Each run is sealed under post-quantum cryptography into the Open Audit Record, so who ran what, when, and on which document is answerable later.

What specifically leaves the software budget

Fold it up and three recurring lines come off. The per seat legal AI licence stops, because the owned system carries no seat meter. The per matter cloud processing fee stops, because the processing happens on hardware the firm already runs. And the shadow spend on personal chatbot subscriptions has a sanctioned home to move to, which removes both the cost and the breach exposure that came with it. What replaces them is a one off owned capability, paid for once and kept, on infrastructure the firm controls.

Frequently asked questions

Does using AI for contract review breach SRA confidentiality rules?

It can, if the tool sends client data off your infrastructure. Industry reporting on the SRA's AI risk outlook treats putting confidential client information into a public AI tool as a likely breach of confidentiality, and warns it can waive privilege. Running the review offline on the firm's own hardware, as Astraea does, keeps the data in the building and closes that specific exposure.

What tools does Astraea replace?

Astraea is built to replace per seat cloud tools such as Harvey, Luminance, Kira and Ironclad for redlining, due diligence extraction and clause drafting. The saving is that the per seat licence and the per matter cloud processing fee both disappear, and the work moves onto hardware the firm owns.

Does the model send client data anywhere for training?

No. Astraea runs offline on the firm's own hardware and the Assistant runs on the firm's own brain, a model built on the firm's own data. The document, the prompt and the output stay on infrastructure the firm controls, so no client data enters an external training set.

How does a firm evidence supervision of the AI?

Every run is sealed under post-quantum cryptography into the Open Audit Record, a signed, tamper evident log of who ran what, on which document, and when. That gives a supervising solicitor a local, verifiable record of oversight, produced as a by product of the work rather than reconstructed later.

Top comments (0)