In brief
- A solicitor came under regulatory investigation after uploading client documents into ChatGPT, a visible symptom of a wider control gap in regulated sectors.
- AI is already embedded in core legal work like case strategy, contract drafting, and client communications, so a single prompt can create confidentiality and regulatory exposure.
- Universal governance frameworks did not prevent shadow AI: half of legal respondents still reported it despite claiming full detection.
- The SRA judges conduct, not policy, so firms need AI security and governance that applies data-aware guardrails at the point of use and produces an audit trail.
A recent report of a solicitor facing regulatory investigation after uploading client documents into ChatGPT is not an isolated incident. It is a visible symptom of a broader structural issue unfolding across highly regulated industries.
Legal professionals operate under strict duties of confidentiality, and yet the tools reshaping their workflows are being adopted faster than governance and operational controls can keep pace.
The challenge is not whether AI should be used in legal practice. It already is.
The question is whether firms have meaningful control over how it is used, what data is being shared, and where exposure is being created.
AI Is Already Embedded in Core Legal Workflows
Our latest research, The State of Enterprise AI Usage: The Illusion of Control, confirms that AI adoption is no longer experimental. According to the survey of 300 senior technology and risk leaders, 67% of organisations report that AI is widely used across teams, and 91% expect usage to increase over the next 12 months.
This is not confined to low-risk functions. The highest concentration of AI usage sits within data analysis, software development, and customer-facing roles, all of which routinely handle sensitive, regulated, or commercially significant data.
In a legal context, this maps to case strategy, contract drafting, litigation preparation, and client communications.
When a solicitor uploads client material into an AI tool, the action often appears operationally normal. It is simply a prompt or a document upload in the course of drafting or analysis.
Yet that single action can create regulatory exposure, confidentiality breaches, and long-term data control risks that are difficult to reverse.
The Illusion of Control in the Legal Sector
Across the market, AI adoption is accelerating faster than enforcement. In sectors such as finance and IT, shadow AI levels exceed 70%, even where governance frameworks are in place.
The broader pattern is clear: policy maturity does not automatically translate into behavioural control.
In our survey with legal respondents:
- 100% reported high AI adoption
- 100% shared that they have formal governance frameworks
- 100% shared that they have AI detection capability
- 100% identified AI as a 2026 priority
Even acknowledging the small sample size, the signal is strong. Where confidentiality is existential and regulatory scrutiny is direct, AI governance maturity accelerates. Legal firms understand that AI risk is not theoretical. It is professional, contractual, and reputational.
Despite universal governance and detection claims, 50% of legal respondents still reported shadow AI.
This raises the question of whether, even in highly regulated professions with strong governance intent, AI usage still finds unmanaged paths.
Productivity pressure, embedded AI features in SaaS tools, personal accounts, and informal experimentation all create exposure outside approved channels.
Regulatory Accountability and the Shift from Policy to Proof
For solicitors in England and Wales, this is not merely an internal governance issue.
The Solicitors Regulation Authority holds both individual solicitors and firms accountable for maintaining client confidentiality, acting with integrity, and upholding proper standards of practice.
If sensitive client material is entered into an external AI system without appropriate safeguards, the regulatory exposure sits squarely with the firm and the individual practitioner.
The regulatory question will not be whether a firm has an AI framework or an AI committee in place. It will be whether the firm can demonstrate:
- What data was entered into AI systems
- By whom
- Under what guardrails
- With what evidence of enforcement
Policies describe intent. The SRA assesses conduct. This is where AI security and governance becomes operationally critical.
AI governance defines what should happen. Controls at the point of use ensure that behaviour at the moment of prompt or upload aligns with that policy.
It provides visibility into sanctioned and shadow AI usage, applies data-aware guardrails in real time, and generates the audit trail required to evidence compliance.
Legal firms are right to prioritise AI in 2026. The next step is ensuring that control is continuous, measurable, and operational, not assumed.
That is how the illusion of control becomes a defensible reality.
📖 Access the research
In March 2026, CultureAI releases new research: The State of Enterprise AI Usage: The Illusion of Control.
Based on insights from 300 senior leaders in regulated industries, this report explores enforcement maturity, sector-specific trends, and regulatory readiness in greater depth.