Earlier this year, the Upper Tribunal Immigration and Asylum Chamber published its judgment on the use of AI and potential waiver of confidentiality and legal privilege.
UK v Secretary of State for the Home Department (AI hallucinations; supervision; Hamid) [2026] UKUT 81 (IAC) concerned two joined cases that involved the use of AI by legal professionals as part of research and drafting, but it may well have broader implications beyond the legal profession.
Facts
In both cases, legal advisers used AI (whether directly or through the use of more junior members of staff) to assist with preparing judicial review documents and included citations to non-existent cases:
- In the first case, an immigration adviser included a non-existent case citation in the grounds of appeal it provided to the Upper Tribunal. The adviser stated that they had not used AI to draft the grounds of appeal (and was unsure about how the false citation made is way into the document), but admitted that they may have inadvertently used the ‘AI mode’ of a Google search, which may have led to the citation. The adviser also admitted that while they did not use AI to draft the grounds of appeal, they did use ChatGPT to summarise Home Office decision letters and to improve client emails by uploading the letters and draft emails onto ChatGPT.
- In the second case, an immigration solicitor included several non-existent case law citations in judicial review proceedings documents. The court suspected the potential use of AI, although this was not confirmed in the case, mainly due to the solicitor’s lack of understanding of AI usage in their firm and failure to provide a satisfactory explanation for the non-existent citations. The solicitor also admitted that a trainee lawyer had drafted the documents under their supervision, and that they had not properly checked the trainee lawyer’s work due to personal circumstances.
Judgment
Apart from the general warning against AI hallucination and the importance of carefully checking citations and other documents, the court concluded that: “Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place this information on the internet in the public domain, and thus to breach client confidentiality and waive legal privilege”, although “Closed source AI tools which do not place information in the public domain, such as Microsoft Copilot, are available for tasks such as summarising without these risks”. It also added that someone who has placed confidential information in an open-source AI tool is “advised to consult with the Information Commissioner’s Office”, which indicates that this could potentially amount to a personal data breach.
The court also highlighted the responsibilities of a supervising legal professional: “A solicitor or other legal professional who delegates their work to another fee-earner remains responsible for the supervision of their work and for ensuring its accuracy. Such supervisors must ensure that fee-earners under their supervision are aware of the dangers of using non-specialist AI for legal research and drafting. Failure to do so, or to undertake appropriate checks on the drafting of fee-earners, is likely to result in a referral to the Solicitors Regulation Authority or other regulatory body. A supervisor who fails to ensure that the work of a more junior fee-earner does not contain false cases or citations is likely to be more culpable than a lawyer who fails to ensure that his own work is free from such ‘hallucinations’”.
What are the implications?
Whilst the two cases concerned legal professionals (and serve as a timely reminder for those in the legal professional to continue to be careful when using AI tools), there are several learnings that can be applied more widely.
1. Uploading confidential information into open-source AI may waive confidentiality and legal privilege
With the use of AI becoming more prevalent, especially in a litigation context where organisations struggle to go through a high volume of lengthy documents, organisations should (1) only approve the use of ‘closed-source’ AI tools, (2) prepare an AI policy and train their staff members on that policy (including which AI tools can and can’t be used), and (3) ensure that staff do not upload any confidential information to non-approved open-source tools. Inadvertent use of an open-source AI may result in the waiver of legal privilege could have serious implications for the party who has “waived privilege” as they risk information they considered confidential and subject to legal privilege falling into the wrong hands and being exploited by third parties .
During his speech in April, the Chancellor of the High Court also reiterated the judgment in UK v Secretary of State for the Home Department by stating that legal privilege was unlikely to attach to exchanges with public AI models as they do not appear to be confidential, although the use of a secure (i.e. closed-source) AI model is unlikely to impact privilege.
2. Uploading personal data into open-source AI can be considered a data breach
The UK GDPR defines a personal data breach broadly as an incident involving the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. As the judgment suggests, uploading personal data onto an open-source AI tool places information in the public domain and can amount to a personal data breach (which would require notification to the ICO and – if the risk is sufficiently high – to any individuals affected).
Organisations should make this clear in their data protection and AI policies and train staff members so that they can identify when a data breach may have occurred. This will in turn ensure that organisations can comply with their obligations to report to the ICO and/or affected individuals as required. It is also important that staff know who to notify in the event of a breach and that they feel empowered to do so.
You can find more about what you need to do in the event of a personal data breach in ICO guidance here.
3. Charities should be mindful of serious incidents
Charities should be aware that if particularly sensitive confidential information, such as information about their beneficiaries or donors, is compromised by being placed into an open-source AI tool, this may not only lead to a potential personal data breach but may also amount to a serious incident that a charity must report to the Charity Commission by submitting a serious incident report. This will particularly be the case if the incident is likely to result in reputational damage or if the ICO (or another regulator) commences an investigation into the charity. You can find more about what the Charity Commission considers a reportable incident here.
4. Responsibility for misuse of AI remains with senior staff members
As the judgment in UK v Secretary of State for the Home Department makes clear, legal professionals who delegate work to more junior staff are still responsible for that work and its accuracy, including any misuse of AI. Similarly, a Charity Commission blog has warned “Trustees remain responsible for decision making…trustees may not be complying with their duties if a charity relied solely on AI generated advice to make a critical decision about their charity without undertaking reasonable independent checks to confirm its accuracy”. It is therefore essential that senior members of staff are up to speed with the types of AI permitted for use within their organisation, and what policies are in place to govern that use.
It’s clear that AI can be extremely useful for organisations of all types, particularly in the context of improving efficiency and the digestibility of large volumes of information. It is essential that all organisations consider the implications of using this technology, and do so without compromising the integrity and confidentiality of their information.
If you would like to discuss your organisation’s use of AI, including policies and training needed to protect confidential information and personal data, please get in touch with us. We regularly help clients who are facing data privacy and related challenges, both in the court and other forums.
The material in this article is provided for guidance and general information only and is not intended to constitute legal or other professional advice upon which you should rely. In particular, the information should not be used as a substitute for a full and proper consultation with a suitably qualified professional. Please do contact the Bates Wells team if you require advice.