Skip to content
Back to Errors

Privileged, until pasted

Client facts, or privileged material, pasted into a consumer chatbot whose terms let the provider train on the input or let staff read it.

  • First recorded: November 2023
  • Where it shows up: consumer chatbots · personal phones · free accounts · browser extensions
  • Status: recurring

The short version

A client's facts, or a privileged document, typed or pasted into a free chatbot on its default settings. The duty of confidentiality under the SRA Code does not depend on whether anyone ever finds out.

What it is

Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs reads: "You keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents." The error is treating a chatbot's text box as private because nobody else is in the room. What happens to the text afterwards is set by the provider's terms and the account's settings, and on a consumer account those can allow the text to be used to train models or to be read by people working for the provider.

What that means for privilege on particular facts is a question for advice on the matter, not for this page. What the regulators and professional bodies have said is on the record:

  • The SRA's Risk Outlook report on AI, of 20 November 2023, lists among the threats to confidentiality "A staff member using an online AI, such as ChatGPT, to answer a question on a client's case" (SRA).
  • The Bar Council tells barristers to "Be extremely vigilant about sharing with a generative LLM system any legally privileged or confidential information", because the input "may be used to generate future outputs and could therefore be publicly shared with other users", and says such sharing "is likely to be a breach of Core Duty 6 and rule rC15.5 of the Code of Conduct" (Bar Council guidance, last reviewed 25 November 2025, paragraph 28).
  • The Law Society publishes its own guidance for solicitors, Generative AI – the essentials. An article of 20 May 2025 on the Law Society's Risk and Compliance community site says it may be "of particular interest to small and medium firms, and in-house practitioners" (Compliance and the use of AI in law firms).
  • Judges are told: "Any information that you input into a public AI chatbot should be seen as being published to all the world" (Guidance for Judicial Office Holders, 31 October 2025, section 3, part II).

A sighting

The SRA's example is the sighting: a question on a client's case, put to an online chatbot. The terms decide where it goes next. Two consumer services, as their own pages described them on 1 October 2026:

  • Google Gemini (personal accounts). The Gemini Apps Privacy Hub says that human reviewers look at some of the data collected, asks users "Please don't enter confidential information that you wouldn't want a reviewer to see", and says that chats reviewed by human reviewers are not deleted when the user deletes their activity but "are retained for up to three years".
  • Anthropic Claude (Free, Pro and Max plans). Anthropic's page Is my data used for model training? (updated 16 March 2026) says that consumer chats are used to improve its models when the user allows it in the Model Improvement setting, when a conversation is flagged for safety review, when the user opts in to a programme such as its trusted testers, and, for the conversation concerned, when the user gives feedback with the thumbs up or down.

Business and enterprise plans are covered by other pages and other terms. The site's setup guides set out the settings tool by tool; they change, so the dates matter.

Why it happens

The free tool is on the phone and opens in a second. The firm's approved tool, where there is one, may be slower to reach. The settings that decide what happens to the text sit in an account menu, and it is easy to start typing without opening it.

What to say back

"Which account was that pasted into, and what do its settings say about training and human review? If nobody can say, who in the firm decides whether this is a data incident?"

Origin

  • 20 November 2023. The SRA's Risk Outlook report names a staff member using ChatGPT on a client's case as a confidentiality risk.
  • December 2023. The first judicial guidance on AI is issued (as recorded in R (Ayinde) v London Borough of Haringey [2025] EWHC 1383 (Admin), paragraph 15, on the National Archives). The version of 31 October 2025 tells judges not to enter private or confidential information into a public AI chatbot.
  • 30 January 2024. The Bar Council issues its guidance for barristers. The version last reviewed on 25 November 2025 links confidential input to Core Duty 6 (paragraph 28).
  • Now. On 1 October 2026, Google's and Anthropic's consumer pages both described uses of chat content beyond answering the question: human review in one case, model training with the user's permission in the other.

Sources

  1. SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs, paragraph 6.3
  2. SRA, Risk Outlook report: the use of artificial intelligence in the legal market,
  3. Bar Council, Considerations when using ChatGPT and generative artificial intelligence software based on large language models (issued 30 January 2024, last reviewed 25 November 2025),
  4. Natalie Cooksey and Karim Nasser (Travers Smith), Compliance and the use of AI in law firms, the Law Society Risk and Compliance community,
  5. Courts and Tribunals Judiciary, Artificial Intelligence (AI): Guidance for Judicial Office Holders,
  6. Google, Gemini Apps Privacy Hub (checked 1 October 2026),
  7. Anthropic, Is my data used for model training? (checked 1 October 2026),