05/08/2026

The use of generative artificial intelligence (AI) tools is increasing rapidly across the private and public sectors. From drafting reports and summarising documents to supporting research and administrative tasks, AI presents significant opportunities to improve efficiency and reduce workloads.

However, organisations should be aware that the use of AI also creates legal and governance risks, especially in the context of litigation.

Recent examples

A recent decision of the Upper Tribunal (the “Tribunal”) in R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (“Munir”) provides an important reminder of the challenges associated with AI, particularly in relation to confidentiality, legal professional privilege and the reliability of AI-generated content.

The case arose during judicial review proceedings where the Tribunal identified a number of legal authorities cited in Court documents that could not be located and appeared to support legal propositions that were inaccurate. The Tribunal required the claimant’s solicitors to explain how those authorities had found their way into the claim.

Although the solicitors denied using ChatGPT and attributed the errors to inadequate checking of precedents and source materials, the Tribunal used the opportunity to reiterate the professional obligations that apply when preparing documents for Court. In particular, it emphasised the importance of verifying information and ensuring that all material relied upon is accurate.

Another recent example was how matters transpired in Anthony Malcolm Cork & Anor v Mark Smith [2026] EWHC 1199 (Ch). The underlying facts of the case were concerned with an application made in insolvency proceedings under a specific provision of the Insolvency (England and Wales) Rules 2016 to remove a person from office as an administrator or liquidator. 

A law firm was criticised for not accurately checking material produced by AI that was presented to the Court. Ultimately, the law firm had relied on inaccurate legislation cited by AI in an application made to the Court (in other words, the AI had produced a “hallucination”, which the Judge suspected). The legislation cited in that case was queried by the Judge, who sought clarification. At this point, the law firm relied on AI in an attempt to justify why the legislation cited was used in subsequent correspondence to the Court. The Judge listed a hearing to reach a conclusion on what exactly had happened. 

Witness statement for two senior fee earners (notably, not the junior fee earner who prepared the application and correspondence) were filed with the Court, along with the chat history between the junior fee earner and the AI. The Judge commented that “on a large number of occasions, [the AI] is plainly wrong or, at the very least, extremely misleading”. The Court considered the statements made in the application and correspondence to be misleading, albeit accepted on the evidence presented that there was no intention to mislead.

The law firm was also criticised by the Court for not adequately supervising the junior fee earner preparing the application and correspondence. The Judge’s view was that if adequate supervision had been implemented, the senior fee earner would have identified the error in the application and correspondence. 

This was understandably a professionally embarrassing series of events for the law firm, and these cases serve as a warning that organisations cannot rely on technology as a substitute for professional judgement and appropriate oversight.

The wider challenge: AI and confidentiality

A significant aspect of the Munir judgment is the Tribunal’s commentary on the use of AI systems and the treatment of confidential information.

The Tribunal drew a distinction between publicly available AI platforms and closed systems that operate within an organisation’s own secure environment. It warned that uploading confidential information into publicly accessible AI tools may result in that information entering the public domain, thereby losing its confidential nature.

Given that confidentiality is the foundation of legal privilege, this poses a real and obvious risk. In very simple terms, legal professional privilege protects confidential communications between lawyers and their clients. If confidentiality is lost, privilege may be lost as well.

Once privilege has been waived, it is often impossible to restore and this can be fatal in the event of litigation. During an inspection phase, parties may well look for evidence of the use of AI by clients to argue waiver of privilege and to strike a blow to the other party’s claim.

Parties to litigation therefore need to be aware of this risk and put in place appropriate internal measures to minimise this risk.

For organisations, this raises obvious concerns. Employees may be tempted to upload reports, correspondence, contracts, legal advice, investigation materials, procurement documents or other sensitive information into AI platforms in order to generate summaries or draft responses. In many cases, they may not appreciate the potential consequences of doing so. 

The risks are not limited to legal teams. Any member of staff using AI tools as part of their day-to-day role could inadvertently disclose confidential information or sensitive material and be entirely oblivious to the disclosure. Thomson Reuters’ “Future of Professionals Report 2026” found that 34% of professionals use AI tools that have not been sanctioned by their organisation yet – this creates an invisible risk that it is likely to be nearly impossible (if not impossible) for organisations to detect and mitigate.

Accuracy remains a significant concern

The case is also a reminder that generative AI tools are capable of producing convincing but inaccurate outputs.

AI-generated content may include incorrect factual statements, fabricated references, non-existent authorities or incomplete analysis. While these issues are particularly problematic in legal proceedings, the same risks arise in policy development, governance reports, committee papers, consultation responses and other public sector decision-making processes.

Decision-makers should therefore be cautious about relying on AI-generated content without appropriate verification and review.

The use of AI does not alter existing legal, regulatory or governance obligations. Organisations remain responsible for the accuracy of information they publish, rely upon or disclose. 

Practical steps for organisations

As AI adoption continues to grow, organisations should consider whether their existing governance arrangements adequately address these risks.

Key considerations include:

  • Implementing a clear AI usage policy that sets out what tools may be used and for what purposes, and what level of supervision is required, and how the policy is kept under review as tools and use cases evolve.
  • Prohibiting the input of confidential, privileged, personal or commercially sensitive information into public AI platforms, and making clear that anything entered into such tools should be treated as potentially disclosable and no longer secret.
  • Assessing whether any AI tools being used by staff are appropriately secured and supported by suitable contractual safeguards.
  • Providing ongoing training to staff on confidentiality, information governance, data protection and privilege risks associated with AI.
  • Establishing review and approval processes for AI-generated content, particularly where outputs may inform decisions, publications or legal proceedings, with a "human in the loop" verifying accuracy.
  • Maintaining appropriate records of when and how AI tools are used, so that the organisation can respond to disclosure and regulatory requests and demonstrate the integrity of its decision-making if challenged.
  • Ensuring that in-house legal teams are involved in the development of AI governance frameworks and policies, and that responsibility for approving new tools and use cases is clearly allocated.

 Looking ahead

Whilst the potential benefits of generative AI products are significant, these must be balanced against the legal and governance risks that accompany its use. The regulatory landscape is developing quickly: the UK is currently pursuing a principles-based, regulator-led approach, while organisations with an EU footprint will increasingly need to have regard to the EU AI Act and its extraterritorial reach. Professional and sector regulators, including the ICO and, for law firms, the SRA, continue to refine their expectations, and the case law in this area is still at an early stage.

The key lesson from Munir is that organisations should not view AI as a risk-free productivity enhancement tool. Whether preparing legal documents or correspondence, drafting reports or analysing information, users must remain alert to issues of accuracy, confidentiality and privilege, and to the prospect that their use of AI may itself come under scrutiny in litigation.

Organisations that adopt appropriate governance and supervision arrangements now (and, crucially, keep them under active review as the technology and the law evolve) will be better placed to realise the benefits of AI while minimising the risks, especially in the context of litigation.

If you need any support relating to issues in this article, please click for more information on our Technology and AI and Litigation and Dispute Resolution expertise, with details for contacting our expert lawyers. 

Stay informed across policy, practice, and delivery — follow our LinkedIn page.

Our use of cookies

We use necessary cookies to make our site work. We'd also like to set optional analytics cookies to help us improve it. We won't set optional cookies unless you enable them. Using this tool will set a cookie on your device to remember your preferences. For more detailed information about the cookies we use, see our Cookies page.

Necessary cookies

Necessary cookies enable core functionality such as security, network management, and accessibility. You may disable these by changing your browser settings, but this may affect how the website functions.

Analytics cookies

We'd like to set Google Analytics cookies to help us to improve our website by collection and reporting information on how you use it. The cookies collect information in a way that does not directly identify anyone.
For more information on how these cookies work, please see our Cookies page.