Generative AI can help solicitors organise and complete their work more quickly. But it also brings significant professional and regulatory risks.
AI systems cannot substitute the role of the solicitor. Legal practice depends on far more than the processing of data. It requires human reasoning, judgement, empathy and the ability to navigate complex factual and commercial circumstances.
The corollary of this is that the skills which technology cannot replicate become essential when using AI tools. Lawyers must be able to evaluate outputs and determine whether the results are appropriate in the context of the matter at hand.
In this regard, law firms should treat generative AI as they would any other new technology — useful, but only within a controlled framework. That means understanding the ABCs of AI risk: accuracy, bias and client confidentiality.
A is for accuracy
The reality is that generative AI tools can produce confident, polished answers that may look correct, even when they are not. AI systems may invent legal authorities, misstate legislation or apply law from the wrong jurisdiction. These risks are now well documented. There have been cases where lawyers relied on AI-generated research without properly checking sources. In Ayinde v London Borough of Haringey, the claimant’s barrister submitted grounds with citations which did not exist and a summary of legislation which was not correct. Similarly, in Al-Haroun v Qatar National Bank which involved damages for an alleged breach of a financing agreement, a schedule of authorities filed for the claimant was found to contain numerous case authorities that did not exist. These cases were referred to the Divisional Court (England and Wales) and listed together under the court's "inherent power to regulate its own procedures and to enforce duties that lawyers owe to the court" (known as the Hamid jurisdiction) - ref (2025) EWHC 1383 (Admin).
These cases are important reminders that AI can produce content that can appear accurate and convincing while still being completely wrong (referred to as hallucinations). It’s therefore essential that lawyers always check their AI results against authoritative sources before using them in client advice, documents or correspondence.
AI output should always be treated as a starting point, never a finished product. Solicitors remain responsible for the advice given, the documents issued and the submissions made. Every AI-assisted output should be checked and revised very carefully. In other words, treat AI output as a very rough, initial draft. Check all citations, law, facts, dates, assumptions and the client’s instructions before relying on it.
B is for bias
AI systems learn from data. If that data reflects historic assumptions, gaps or unfairness, the output may reproduce those problems. In other words, an AI tool that has learned from biased information is likely to produce biased results. Such biases are often subtle (the tone of client communications or assumptions about the parties) but they can be deeply embedded and can result in unfair or incorrect outcomes.
In legal practice, biased output can affect decision-making, client care and the fairness of advice. Or, an AI system might apply statistics that are not necessarily relevant or that solicitors need to look behind to see the full picture. Practitioners should be trained to challenge AI content, especially in sensitive matters or where vulnerable clients may be affected.
C is for client confidentiality
Client confidentiality is one of the clearest risk areas. Law firms handle large amounts of confidential information and it’s crucial that this information is protected.
It’s essential that the use of any private AI systems aligns with data protection legislation, such as the GDPR, and adheres to the Law Society’s rules. Additionally, entering any client information into a public AI tool amounts to disclosure to a third party. Even where names are removed, the remaining information may still be identifiable when combined with context. As such, as stated in the Law Society’s guidance, lawyers must never share confidential or privileged information with any public generative AI tool, under any circumstances.
What about the DEFs?
D is for due diligence on AI providers
Before adopting any AI product, firms should scrutinise their providers. It’s important that firms read the terms of use for these products and consider their implications.
The Law Society of Scotland has two guides:
• Guide to IT Procurement (opens a new window)
• Guide to Generative AI (opens a new window)
These documents have lists of questions that firms can put to third-party providers before using them.
E is for every result must be checked
As discussed above, AI can be persuasive even when it’s wrong. That creates a risk of automation bias: the tendency to trust a machine-generated answer because it appears authoritative. AI output must be reviewed by a suitably competent person before it’s relied on, sent to a client, filed in court or used to support advice.
A practical review process should be implemented, and firms should consider the use of checklists to ensure that critical details have been verified against outputs and to weed out potential biases or factually inaccurate information. Where the task is high risk, novel or contentious, consideration should be given to an even more stringent supervision and approval process before results are incorporated into correspondence or documents.
F is for firm-wide policies and training
Every firm should have a clear AI policy to mitigate against the risk of AI misuse. With this in mind, Lockton have a template AI Usage Policy (opens a new window), which can be downloaded for completion and use within your own organisation. The template is intended as a starting point for firms to adapt as they wish and should be tailored so that it’s specific to the organisation and to align with the organisation’s other policies and procedures.
Training should be practical: when AI may help, when it must not be used, what information is off limits, how to prompt safely, how to spot errors or bias, and when to escalate questions to a supervisor or partner.
Law Society of Scotland guidance
The Law Society of Scotland’s Guide to Generative AI (opens a new window) is an important starting point for firms considering whether and how to use these tools. The guide is designed to help members make informed decisions about how to safely incorporate the use of generative AI products into their legal practice.
Firms should review the guide before adopting AI and revisit it as tools, regulation and professional expectations develop.
Risk management takeaway
Generative AI is not something firms need to fear, but it is something they need to govern. The safest approach is to remember the ABCs: check for Accuracy, challenge Bias and protect Client confidentiality. Add the DEFs: provider Due diligence, ensure Everything is checked and have robust Firm-wide policies and training and AI becomes a managed tool rather than an unmanaged risk.
In short: use AI with curiosity, but not complacency. The solicitor’s professional obligations remain the same, even when the technology changes.
