All posts

Blog

Is ChatGPT safe for legal work?

For drafting a first paragraph, often. For anything involving a client's information or a point of law you will rely on, only with rules the firm has actually written down. The tool matters less than what goes into it and what is done with what comes out.

Alesis · · 5 min read

It depends less on the tool than on two things the firm controls: what goes into it, and what is done with what comes out. ChatGPT is the best-known consumer AI assistant, and the question is really about consumer assistants generally. Used for the right tasks under rules the firm has actually written down, they can be safe. Used the way most people first try them, by pasting in whatever is to hand and copying out whatever comes back, they are not.

Here is how to think about it without either banning the tools or pretending the risk is not there.

What goes in

The first risk is disclosure. Anything typed or pasted into an assistant has been sent to the company that runs it, under that service's terms. Consumer and business tiers of the same product can differ sharply on how content is stored, who can see it and whether it is used to improve the service. Most people using a free account have not read those terms, and a firm cannot describe a disclosure it has not read the terms of.

For a law firm this is not an abstract point. Client names, matter details, documents, correspondence: all of it is confidential, and much of it is personal data. The practical rule most firms land on is simple. Nothing that identifies a client, a matter or a person goes into a consumer tool. If a task needs the papers, it needs a tool the firm has assessed for exactly that, with terms it has read and answers about data it has in writing.

What comes out

The second risk is reliance. Consumer assistants write fluent, confident prose whether or not it is right, and they do not, by default, show where a proposition came from. For a paragraph of plain-English explanation to a colleague, that is a small risk. For a statement of the law that will go into advice, a letter or a document before a court, it is a serious one. The courts in England and Wales have already had to deal with filings that cited cases which did not exist, and the responsibility sat with the lawyer, not the tool.

The rule that follows is as simple as the first. Nothing an assistant says about the law is relied on until a qualified person has opened the source and checked it. If the assistant cannot show a source, the checking starts from scratch, and the time saved is smaller than it looked.

The problem nobody planned for

Most firms did not decide to use consumer AI tools. Individuals started using them, quietly, because they were useful. That is understandable and it is also the risk: the firm has an AI practice it did not design, cannot see and has not told its clients or its insurers about.

The answer is not a ban, which pushes the use further out of sight. It is a policy short enough to be read and specific enough to be followed.

A one-page policy that works

Four questions cover most of it.

  1. What may go into a consumer tool? Nothing that identifies a client, matter or person. Anonymised or hypothetical questions are fine; the papers are not.
  2. What must be checked before it is relied on? Any statement of law, any date, any figure, and anything that will leave the firm. Checked means the source opened and read by a qualified person, not the assistant asked whether it is sure.
  3. Who is accountable? The person who signs the work, as always. Supervision applies to AI-assisted work exactly as it applies to a trainee's.
  4. What tools does the firm provide for work involving client information? Name them, so people are not left to improvise. A tool built for firms will answer from the matter's own papers and official sources, keep the information in the UK, keep firms and matters apart, and show its sources; that is the standard to hold any candidate to.

Write the policy down, tell everyone, and revisit it in six months. It will be out of date, and that is fine; a policy that is revised is one that is being used.

What the regulator and the profession say

The Solicitors Regulation Authority and the Law Society have both published guidance on generative AI in practice. The themes are consistent: know what the tool does with your information, remain competent and responsible for the work, supervise its use, and be open with clients where the way you work affects them. None of that prohibits consumer tools. All of it argues for deciding, in writing, where they may and may not be used.

Where Alesis fits

Alesis exists for the work that consumer tools are not built for: questions about a firm's own matters, answered from the matter's own papers and from official sources, with every point naming where it came from. Your firm's information is held and processed in the UK, kept apart from every other firm, and never used to train anything for anyone else. It says when it cannot find support for a point rather than guessing, and it sends nothing itself; a qualified person reviews and signs off before anything leaves. It is one conversation, in the shape people already know, with the rules of a law firm underneath.

Alesis assists qualified professionals and does not replace them; nothing here is legal advice. If a point above is wrong or out of date, write to us and we will correct it in writing.

Put a real matter to it

Create an account, open a matter and upload the papers. Every point it makes names where it came from.

Get started