This article is general information, not legal advice. Applicable court directions, professional rules, client requirements and provider terms should be checked for the particular matter and use.
Start with the act of disclosure
“Using AI” describes too many different things. Asking a public service to summarise a witness statement, running a model entirely on a device, searching a database that has no generative component, and using a court-approved transcription system do not create the same risks.
For a barrister holding a brief, the first question is concrete: what information will leave my control, to whom, for what purpose, and on what terms? A prompt may disclose names, instructions, litigation strategy or the substance of privileged communications even when no document is uploaded. Pasting an apparently innocuous extract can reveal its context through the question asked about it.
Confidentiality and privilege overlap, but they are not identical. Material can be confidential without being privileged. Privilege may belong to the client, not counsel, and careless third-party disclosure can create arguments that should never have arisen. The practical response is to analyse the proposed transmission before treating vendor assurances as the answer.
Identify the service, not just the product name
A polished legal interface may still send text to another company's model. A desktop application may operate locally for one feature and use a cloud endpoint for another. “Enterprise”, “private” and “not used for training” each address only part of the picture.
Before sending matter material, establish:
- the entity receiving the prompt, attachments, metadata and output;
- where processing occurs and whether subprocessors are involved;
- whether inputs or outputs are retained, logged, reviewed by humans, or used to improve models;
- what settings alter those defaults and who controls them;
- how deletion, security incidents and compelled disclosure are handled; and
- whether the client's or chambers' requirements permit the proposed use.
Terms and settings change. Record the basis for an important decision rather than relying on a remembered marketing statement. If the answer cannot be established, that uncertainty is itself part of the risk assessment.
Data minimisation is useful, not magical
Removing direct identifiers can materially reduce exposure. It does not necessarily anonymise a case. A distinctive factual pattern, occupation, location, transaction value or procedural history may identify a person when combined. Nor does pseudonymisation change the character of legal advice or litigation strategy contained in the text.
Use the least material required for the task. Replace identifying details where appropriate, remove irrelevant passages and inspect the exact payload. But do not reason backwards from “names removed” to “privilege protected”. The relevant question remains whether this disclosure, in this form, to this service, is proper.
Consent should be specific and informed
Client consent is not a universal cure, but a client should not discover after the event that their material was sent to a generative AI provider. Where consent is relied upon, it should concern an intelligible proposed use: the service, the kind of material, the purpose, the safeguards and the material risks. A broad engagement-letter reference to technology may not answer the practical or professional question.
Instructions from a solicitor do not remove counsel's independent obligations. Equally, a client or institutional solicitor may impose stricter controls than a provider technically requires. Matter-level consent is preferable to a global setting because sensitivity and authority differ between briefs and can change as the proceeding develops.
Responsibility for the output stays with counsel
Generative systems produce plausible language, not verified propositions. They can invent authorities, misstate holdings, merge factual accounts, omit qualifications and express uncertain conclusions with confidence. Confidentiality controls do not address those failures.
Verification must return to primary material:
- open and read every authority relied upon, including subsequent treatment and the precise passage said to support the proposition;
- trace factual statements to the evidence and check the permissible use of that evidence;
- check quotations word for word and in context;
- review calculations, dates, names and procedural references independently; and
- ensure the final work reflects counsel's own analysis and complies with any disclosure obligation about AI use.
“Human in the loop” means more than reading polished output and agreeing with its tone. The reviewer needs enough command of the brief and law to detect what is missing or subtly wrong. If the task is one counsel cannot independently verify, delegating it to a model does not solve the problem.
Privilege is one risk among several
A sound decision also accounts for privacy law, suppression and non-publication orders, implied undertakings, secrecy provisions, contractual controls, cybersecurity, Indigenous data considerations where relevant, and the court's directions about generative AI. The strictest applicable constraint may come from somewhere other than privilege.
There is also a forensic risk in creating new records. Prompts and generated drafts may expose strategy, contain inaccurate assertions, or become relevant to a later dispute about the work performed. Know what the tool and the local workspace retain. Keep an appropriate audit trail without casually multiplying sensitive copies.
A practical decision framework
Before using generative AI on matter-related work, work through five steps:
- Define the task. What useful outcome is sought, and can it be achieved without matter content or with a local tool?
- Classify the material. Identify confidentiality, privilege, personal information, court restrictions and client controls.
- Map the transmission. Determine exactly what leaves the device, who receives it, retention and training settings, and relevant contractual terms.
- Reduce and authorise. Minimise the payload, pseudonymise where useful, obtain any required approval or consent, and preserve a record proportionate to the decision.
- Verify and own the result. Check against sources, exercise independent judgment, comply with court requirements, and treat the output as untrusted until that work is complete.
This framework may lead to different answers for different tasks in the same matter. Brainstorming generic headings without disclosing case facts is not the same as uploading the brief. Running a model locally is not the same as sending text to a cloud provider—though a locally installed interface configured to call a remote machine is not truly local merely because it appears on the desktop.
Why local-first changes the default
A local-first workspace reduces the number of disclosure decisions hidden inside ordinary work. Reading, searching, organising documents, maintaining a chronology and drafting notes need not require a third-party copy of the matter. That is a structural safeguard: there is no provider term to interpret for data that was never sent.
It does not make every optional AI use safe, and it does not replace professional judgment. If a cloud model is deliberately enabled, the same analysis applies. Lexware keeps cloud AI consent at the matter level and uses the barrister's own supported provider access; local processing remains available by default. Pseudonymisation and payload review can reduce risk on supported cloud paths, but they are aids rather than guarantees.
The most durable reading of the guidance is therefore neither panic nor permission. Know the information, know the system, minimise disclosure, obtain proper authority, verify everything material, and remain responsible for the work put forward in your name.