Skip to content
Back to Guides
workflowintermediate

AI Browser Extensions and Client Confidentiality

What an AI browser extension can read, what to check in its terms, and why your firm's policy decides whether you install one

The Problem

An AI browser extension puts an assistant in a sidebar or behind a button on every page you open. If you read client email, view documents or use your firm's practice management system in the browser, those are pages too. An extension that can read the page can read a client's email.

Installing one takes a click. Nothing in that click asks whether your firm has approved the vendor.

The Solution

Treat an AI browser extension as an outside supplier that may receive what is on your screen. Before you install one, check three things, in this order:

  1. Your firm's policy
  2. The permissions the extension asks for
  3. The vendor's terms

This guide recommends no extension and names none.

What an Extension Can See

The facts in this section were checked on 29 September 2026 against the pages listed under "Sources". Those from Google describe Chrome. If your firm uses another browser, read that browser's own pages.

  • The National Cyber Security Centre says: "Extensions typically have permissions to read or change the data on any websites a user visits." It adds: "This could include sensitive or personal data."
  • Google's help page for the Chrome Web Store describes the permission "Your data on all the websites you visit" as access to read, request or modify data from every page you visit.
  • The same page says of a permission warning: "The warning doesn't mean that the app is dangerous, just that it can be."

What that means for you depends on what you open in the browser. If you read client email in a browser tab, an extension with that permission can read it. The same goes for a document you view in a tab, a client portal, and your firm's practice management system if it runs in the browser.

The permission tells you what the extension can reach. The vendor's terms tell you what the vendor does with it. You need both.

Check 1: Your Firm's Policy

Your firm's policy decides whether you may install an extension at all. Ask before you install:

  • Does the firm keep a list of approved extensions, and is this one on it?
  • Is the extension covered by an agreement between the firm and the vendor, or would you be accepting the vendor's terms on your own?
  • Who in the firm approves a new tool?

The National Cyber Security Centre's advice to organisations is: "Develop a policy around the installation of third-party extensions on your browser." Google's documentation for administrators says that an organisation can allow or block extensions, and can block them by the permissions they ask for.

If your firm has no policy on extensions, ask for a decision. Silence is not permission.

Check 2: The Permissions It Asks For

When an extension asks for a permission that carries a warning, Chrome shows the warning and you choose whether to accept it. Read it before you accept.

Chrome also lets you narrow when an extension can read a page. Under "Let extensions read and change site data", Google lists three settings:

  • When you select the extension: the extension can access the current site only when you select it
  • On [current site]: the extension can read and change data on the current site automatically
  • On all sites: the extension can read and change data on all sites automatically

Choose the first unless your firm has approved something wider. Google's steps are in Install and manage extensions.

Narrowing the setting limits when the extension can read a page. It does not change what the vendor does with the text once the extension has sent it.

Check 3: The Vendor's Terms

Read the vendor's terms of service, its privacy policy and, if it offers one, its data processing agreement. Look for the answer to each of these questions:

  • What leaves your device? The text you select, the whole page, or the page without your asking?
  • Who receives it? The vendor alone, or also another company whose AI model the extension uses? On what terms?
  • Is it used to train a model? Is that on by default, and can your firm switch it off?
  • How long is it kept, and can it be deleted?
  • Where is it stored? A transfer outside the UK is a question for your firm's data protection lead under UK GDPR.
  • Which plan do the answers apply to? The terms for a business plan and the terms for a free or personal plan can differ. Claude Projects for Client Matters shows how far they differ for one vendor.

If the terms do not answer a question, treat the answer as unknown. Do not assume the answer you would like.

On the Chrome Web Store, Google asks the developer of an extension to disclose what types of data it collects, and says that those disclosures are displayed to Chrome users. Read them on the extension's listing. They are the developer's own statement, so read them alongside the terms and not in place of them.

What the Terms Do Not Decide

The permissions and the terms are the least you need to know. They do not answer these questions, which are for your firm:

  • Does your firm's policy allow client information to reach this vendor at all?
  • Has the client agreed, in the engagement terms or otherwise, to its information being handled this way?
  • Is any of the material privileged, and what does your firm's policy say about putting privileged material into an outside tool?

Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. This guide explains what to check. It does not advise on how that duty applies to your matter: ask your firm's compliance officer before you install anything.

If an Extension Is Already Installed

  1. Open the list of extensions in your browser and read it. Google's steps are in Install and manage extensions.
  2. For each extension, look at which sites it can read.
  3. Remove any extension your firm has not approved.
  4. If you think client information has reached a vendor your firm has not approved, tell your firm's compliance officer or data protection lead. Do not decide on your own whether it matters.

Trying One Without Client Material

If your firm allows you to try an extension:

  • Set its site access to "When you select the extension"
  • Select it only on a public page, such as a statute on legislation.gov.uk or a judgment on Find Case Law
  • Do not select it on a page that shows client information
  • Check what it tells you as you would check any AI output: see The Citation Verification Rule

Common Mistakes

❌ Installing first and reading the terms later: the extension can read pages from the moment it has permission

❌ Treating a well-known name as approval: your firm's policy decides, not the brand

❌ Leaving site access on "On all sites": choose "When you select the extension"

❌ Relying on a setting inside the extension to make client material safe: confidentiality comes from your firm's agreement with the vendor and your firm's policy

✅ Firm policy first, then the permissions, then the terms

Quick Reference

Before you install an AI browser extension:

  1. Firm policy: is the extension approved, and under whose agreement with the vendor?
  2. Permissions: what can it read, and on which sites?
  3. Terms: what leaves your device, who receives it, is it used for training, how long is it kept, where is it stored?
  4. Your firm's questions: the client's agreement, privileged material, paragraph 6.3 of the SRA Code of Conduct

If any answer is unknown: do not use the extension on a page that shows client information.

Sources

All checked on 29 September 2026.

National Cyber Security Centre:

Google:

Solicitors Regulation Authority:

Related Topics

workflowbrowserconfidentiality