Blog
How do we stop staff using unapproved AI tools at work?
A ban on its own rarely holds. Give people an approved tool that does the job, write one short rule about what must never be pasted anywhere else, and make it easy to ask before trying something new.
Alesis · · 5 min read
You stop it by removing the reason for it. People use their own accounts because they have work to do and no approved way to do it faster, so the answer is an approved tool that covers the common jobs, one short rule about what may never leave the firm's systems, and a named person who can say yes or no quickly. A ban with nothing behind it just moves the activity out of sight.
Why people reach for whatever is on their phone
Nobody in your firm is trying to breach confidentiality. The pattern is almost always the same: a fee earner is under pressure, there is a summary to write or a clause to untangle, and a free tool is thirty seconds away on a personal device.
The same goes for note taking apps in meetings, transcription tools for attendance notes, and browser add-ins that appeared without anyone deciding to install them. Each one felt like a small practical shortcut at the time.
If your firm has no approved option, you are not choosing between AI and no AI. You are choosing between AI you can see and AI you cannot.
What the actual risk is
Be precise about what worries you, because vague warnings do not change behaviour.
- Client information leaving your control. Once a passage from a client's papers is pasted into a consumer account, the firm cannot say where it is held, who can reach it, or whether it is retained. That sits badly with your confidentiality duty and with UK GDPR obligations you hold as controller.
- No record. Work done on a personal account leaves nothing on the matter file. If a decision is later questioned, there is no way to reconstruct what was asked or what came back.
- Unchecked output reaching a client or a court. The problem is not the tool producing something wrong. It is the absence of any supervision step before that output travels.
- No supplier relationship. With a personal account there is no contract, no route to raise a problem and nobody to answer questions from a client or an insurer.
Write the risk down in those terms. Staff respond to concrete consequences far better than to a general instruction to be careful.
What works better than a ban
- Approve something. Pick one tool that handles the ordinary work: reading a file, checking a source, drafting a first version. If the approved route is genuinely quicker than the shortcut, most of the problem disappears.
- Say what is allowed by name. A policy that says "use only approved tools" without listing them leaves everyone guessing. List the tools that are in, and say plainly that anything not listed needs a decision from the person who owns this.
- Give a fast route to ask. If a request to try something takes three weeks to answer, people stop asking. A same week answer, even a no, keeps the conversation inside the firm.
- Separate personal use from firm use. Nobody needs to police what staff do at home. The rule is about client information and firm information, not about the technology itself.
- Check in on the tools that arrive quietly. Browser extensions, meeting assistants and features that appear inside software you already licence deserve the same question as anything else: where does the information go.
Wording the rule so people remember it
One sentence people can repeat beats three pages nobody reads. Something along these lines:
"Client information, matter documents and firm confidential information go into approved systems only. If you want to use anything else, ask first."
Then add two lines of detail. First, what counts as client information, including names, addresses, sums, medical detail and anything that identifies a matter even where the name is removed. Second, who to ask, by name, with an email address.
Put it in the induction pack, mention it at a team meeting once a quarter, and let supervisors raise it in file reviews. Repetition matters more than length.
When you find it has already happened
Assume it has, at least once. The response sets the tone for whether anyone tells you next time.
Find out what was entered and when. Work out whether identifiable client information was involved, and if so treat it as you would any other possible data incident: assess it, record it, and take advice on whether it needs reporting to the Information Commissioner's Office or telling the client. Check whether any output reached a client or a court unchecked, and review that work.
Then deal with the cause. If the shortcut existed because the approved route was slow or missing, fixing the tooling will do more than a warning. Save formal action for people who were told clearly and carried on anyway.
Keep a note of what happened and what changed. A firm that can show it spotted an issue, dealt with it and adjusted its practice is in a far stronger position than one that never looked.
Where Alesis fits
Alesis is an AI assistant for UK law firms, made by L25 Limited, used through the web browser, with one conversation for a matter. Your information is held in the UK and processed only in the UK and the EU, kept apart from every other firm, and never used to train anything for anyone else; inside a firm, people see only the matters they are on, and seniority alone grants no view. Every account proves its email address, and can add two-factor authentication and passkeys. Alesis assists qualified professionals and does not replace them, and it does not provide legal advice.