Law firms have strong reasons to approach new technology carefully. Duties to clients, the courts and third parties continue when a process is digital or an AI system contributes to the work. Confidentiality, privilege, competence, supervision, data protection and the accuracy of legal material are substantive obligations.
Care can still turn into avoidance. A proposal is labelled a compliance concern before the applicable rule, risk and possible control have been identified. The initiative stalls while individual employees find their own tools or old processes create risks of a different kind.
The useful distinction is between a requirement and the organisation’s chosen response to it. Both matter. They should not be allowed to merge into a vague claim that “compliance will not allow it”.
This article is an operating argument rather than legal advice. The applicable requirements depend on the firm, jurisdiction, service, client, data and technology. Decisions should be led by appropriately qualified legal, compliance, data protection and security specialists.
Regulation is a design constraint, not a slogan
The current SRA Code of Conduct for Firms includes duties concerning conflicts and the confidentiality of current and former clients. Those duties do not disappear because a supplier describes a product as secure or an employee uses a publicly available tool.
The SRA’s August 2026 warning notice on misuse of AI is particularly direct. It identifies inaccurate information and client confidentiality as areas of concern, reminds firms that SRA standards still apply, and says client information should enter AI systems only where appropriate contractual, technical and organisational safeguards are in place. The notice also explains the SRA’s outcomes-focused approach: firms have freedom to use AI and new ways of working provided they meet the required standards.
That combination matters. “AI is permitted” is too broad to guide a firm. “AI is prohibited” is equally unhelpful. A proposed use needs its own assessment of purpose, information, professional consequence, supplier terms, technical controls, human oversight and accountability.
Data protection adds another layer. The ICO’s AI and data protection guidance covers lawfulness, fairness, transparency, security, data minimisation, accuracy, governance and individual rights when personal data is processed. At the time of writing, parts of that guidance are under review following legislative change. A project should therefore check the current position rather than rely on a checklist copied from an earlier programme.
Separate four different statements
When somebody says compliance blocks an initiative, ask which of these they mean:
- A rule or legal duty prevents the proposed activity. The team should cite the relevant requirement and explain its application.
- The activity could proceed only with controls the firm cannot currently provide. This is a capability and investment decision.
- The residual risk exceeds the firm’s approved appetite. That is a governance decision which should name the accountable authority.
- The position is uncertain and requires specialist interpretation or regulator guidance. Uncertainty is real, and it should lead to a defined route for resolving it.
This separation protects the compliance function as much as the innovation team. It prevents an individual compliance partner from being made personally responsible for a loosely framed yes-or-no decision. It also prevents advocates from treating a difficult control as evidence that compliance is merely obstructive.
The source article used two useful examples. A duty to protect client information does not, by itself, establish that every cloud service is unacceptable. Equally, the existence of other law firms using cloud systems does not establish that a particular service, contract or configuration is suitable. The decision sits in the missing detail.
Likewise, a conflicts process may need to change before a new CRM can be introduced. That need is neither automatic grounds for rejection nor a minor implementation task. It is part of the service and control design.
The comfort zone has risks of its own
A restrictive default may reduce one visible risk while increasing others.
Unapproved use
If employees believe the formal route cannot produce a timely answer, some may use consumer tools without approval. The gap between official policy and actual behaviour can create confidentiality, privilege, accuracy, supervision and data-protection risks. A policy that exists only on paper offers limited protection.
Firms need a current inventory of approved tools and credible ways to identify unapproved use. Employees also need a route to propose a use case without committing the firm to it.
Operational decay
Old systems and manual workarounds can carry security, resilience, error and continuity risks. Continuing with them is still a decision. It deserves evidence and ownership rather than the presumption that unchanged means safe.
Client friction
Clients may reasonably expect secure, accessible and timely ways to exchange information and understand progress. A firm should test those expectations with its own clients instead of assuming either that digital service is decisive or that legal quality makes the surrounding experience irrelevant.
Capability and retention
People who repeatedly encounter unexplained rejection may stop suggesting improvements or develop skills elsewhere. That does not prove a direct retention effect. It is still a leadership risk worth investigating through employee research, tool requests and exit evidence.
These are not arguments for lowering professional standards. They are reasons to evaluate the whole risk position, including the consequences of delay and informal behaviour.
Move compliance into the design
Late approval creates poor conditions for everyone. The delivery team has already committed to an approach, so material concerns feel like obstruction. Compliance sees a near-finished solution and is asked to carry the risk. Changes are expensive, and the conversation becomes positional.
Involve the relevant specialists while the service, workflow and supplier requirements can still change. For an AI-assisted legal task, that group may need to address:
- the intended purpose and whether AI use is appropriate for it;
- the categories and sensitivity of information involved;
- confidentiality and privilege;
- the lawful basis and data-protection implications;
- accuracy, source checking and required human review;
- competence, training and supervision;
- supplier access, retention, model training and subprocessors;
- security, access control, logs and incident response;
- transparency to clients or affected people;
- contractual allocation of responsibility; and
- the circumstances in which use must stop.
Compliance by design should not become a marketing label. Its value lies in decisions and evidence: requirements recorded, controls tested, residual risks accepted by the right person and operational monitoring assigned.
Use a bounded pilot only when it is safe to do so
A pilot can reduce uncertainty. It is not an exemption from professional or legal obligations.
Start with a use case whose possible harm can be controlled. Define users, matters, data, duration and expected benefit. Set prohibited inputs, oversight requirements, success measures, stop conditions and an incident route. Where realistic client information is unnecessary, use suitable synthetic or otherwise safely prepared data. Obtain specialist advice on whether that treatment is sufficient.
Test the control system as well as the product. Can users recognise an unreliable output? Are reviews recorded? Do permissions work? Does the supplier behave as the contract states? Can the firm investigate an incident and remove data according to its obligations?
At the end, make an explicit decision to expand, revise, stop or gather further evidence. A permanent pilot with ambiguous status can create its own governance gap.
For genuinely uncertain regulatory questions, use current official guidance and the regulator’s available channels. The SRA provides a Professional Ethics Guidance helpline for conduct queries and publishes resources on innovation and technology. A firm should obtain advice suited to the issue rather than assume that a general conversation amounts to approval.
Reframe the leadership question
“Does compliance allow this?” forces a complex decision into permission or refusal. A stronger brief is:
What obligations, harms and uncertainties apply to this use, and what service design and controls would be required to proceed responsibly?
The answer may still be no. The necessary safeguards may be unavailable, disproportionate or inconsistent with the firm’s obligations and risk appetite. That is a defensible conclusion when the reasoning, evidence and authority are clear.
Choose one stalled initiative and reconstruct its decision trail. Identify the actual requirement, the assumed restriction, the missing evidence, the possible controls and the person authorised to accept residual risk. If the initiative remains unsuitable, the firm will have a stronger reason for stopping. If a compliant route exists, the team will have a brief for designing it.
If the argument in this piece is resonating and you want a framework for shifting the firm's performance conversation away from inputs toward outcomes - which is what makes innovation investable - I've written a follow-up piece on moving from billable hours to business value that picks up where this one leaves off.



