Confidentiality and data.
Confidentiality and data protection for firms using AI, with the questions to put to any supplier before client information goes anywhere near a model. These pieces show where data leaves a firm without anyone deciding that it should, and how to keep it under your control.
Back to all insights, or start with the complete guide to AI for law firms.
Articles
That lets you tell the difference between a rule you have to work to soon and a document that arrives in eighteen months.
The ICO AI guidance timetable to plan around
The regulator has published what it is drafting and when it expects to finish. Two of the entries carry dates inside the next six months.

Analysing case data lawfully after Kul v DWF
The Court of Appeal upheld a firm's analysis of 372 claim files naming people who were not its clients. The same test meets any tool reading your caseload.

NCSC advice on agentic AI, read for a law firm
The National Cyber Security Centre published interim advice on autonomous tools on 20 August 2026. Its controls turn into the questions you put to a supplier.

AI memory and your firm's ethical walls
A legal AI platform relaunched with memory at its centre. The conflicts question it raises reaches every firm using an assistant that learns.

AI agent handoffs between your suppliers
Two suppliers have agreed a way to pass half-finished work between them. The consent point lands on your fee earner, so the rule has to reach them first.

Your duty when a new AI model handles client data
Kimi K3 has arrived from abroad and ranks near the top. The confidentiality duty a firm owes before it lets any new model near client data.

Multi-model legal AI, what your firm should ask
The larger legal AI platforms now run on several models at once and route work between them. That shifts your due diligence from which model to how the platform handles your data.

Client confidentiality when using AI tools
How to keep client data inside the firm, choose tools that respect it, and prove that you did.

UK GDPR when client data meets AI
Lawful basis, data minimisation and the question every small firm should ask a vendor: where does our client data go, and who can read it.

Moving client data across borders with AI
Many AI tools process data outside the United Kingdom. When client data crosses a border, the UK GDPR has something to say about it.

The confidentiality trap in AI note-takers
AI meeting assistants are everywhere, and they quietly record and send client conversations to a third party. That is the trap.

Cyber security when you adopt AI
Every new tool is a new door into the firm. AI tools are no different, and a few basics keep them from becoming a way in.

Retention and deletion when AI holds your records
If an AI tool holds copies of client data, your retention and deletion duties follow the data into the tool.
The list
Stay in touch.
The writing connects to one email list, so readers hear when something useful goes out. No noise, one clear next step each time.
One email when a new piece goes out, nothing else, and a reply takes you off the list. See the privacy policy.