Risk

Shadow AI in law firms: the tools nobody approved

By Michael Nadalin, Founder, Market Lead · 29 July 2026 · 7 min read

A junior solicitor has forty pages of witness statements to summarise before a 5pm conference. The firm has no AI tool, no AI policy, and no one to ask. She opens ChatGPT on her phone, pastes in the statements, and has a serviceable summary in ninety seconds. Nobody will ever know, and that is exactly the problem.

This is shadow AI: unapproved tools used for real client work, invisible to the people who carry the professional risk. It is not a hypothetical from a vendor deck. It is the predictable result of giving people impossible deadlines and no sanctioned way to move faster.

The firms handling this badly are the ones still deciding whether AI is a fad. The firms handling it well started from a less comfortable question: what is already happening in this office, and what would we find if we looked?

How shadow AI actually gets into a firm

Nobody makes a decision to introduce unapproved AI. It arrives sideways, usually through the people under the most time pressure and with the least authority to ask permission.

The pattern is consistent across firms of every size. One person tries a tool on something low stakes, it works, the use creeps up the risk curve, and by the time a partner hears about it the practice is months old and quietly embedded in how a team works.

The usual path
Week 1
A paralegal uses a free chatbot to tidy the grammar in a file note. Harmless, and it saves twenty minutes.
Month 2
The same tool gets used to summarise a lengthy affidavit. Client names and dates go in with the text.
Month 4
A solicitor asks it to draft a letter of advice on an unfamiliar area, then edits the output rather than checking the law.
Month 6
Three teams have their own tools, each on a personal account, none visible to IT or the practice manager.
The bad day
A citation in a submission does not exist, or a client asks in writing whether their file has been put through an AI system.
No single step looks unreasonable. The endpoint is a firm with no idea what its confidential material has been fed into.

Why banning it does not work

The instinct is to send a firm wide email prohibiting AI tools. It feels decisive and it costs nothing. It also fails, because a ban does not remove the pressure that created the behaviour. It only removes your visibility of it.

Worse, a ban converts a manageable governance problem into a disciplinary one. Staff who were previously willing to tell you what they were using now have a reason not to. The use continues on personal devices and personal accounts, which is the one configuration you can neither audit nor control.

What firms assume versus what is happening
We have not adopted AI, so we do not have an AI risk
You have unmanaged AI use, which is the higher risk version
We sent an email banning it
You made it invisible, not absent
Only the juniors would do this
Time poor senior practitioners are heavy users, often on their own devices
It is only used for drafting emails
Drafting creeps into summarising evidence and researching unfamiliar law
IT would see it in the logs
Personal phones and personal accounts do not touch firm infrastructure
Most AI governance failures are failures of assumption, not failures of technology.

The exposures that actually matter

Not every use of an unapproved tool is equally serious. Treating them as one undifferentiated risk makes it harder to have a sensible conversation with your team, and harder to work out where to spend your governance effort.

Rank them honestly. The confidentiality exposure is a duty question and, depending on what was disclosed, potentially a notifiable data breach question under the Privacy Act. The fabricated authority exposure is a candour to the court question, and Australian courts have made their expectations about verifying AI assisted material increasingly explicit through practice notes and guidance.

Shadow AI exposures, worst first
Fabricated citations reaching a court
An invented case or a misquoted provision in a submission is a candour problem, not a typo. It attracts costs consequences and referrals, and it is the single fastest way to damage a practitioner's standing with a judge.
Severe
Confidential client material entering a consumer tool
Client information disclosed to a third party system without consent engages the confidentiality duty in the solicitors' conduct rules and, if the material is personal information, the Privacy Act and the notifiable data breach regime.
Severe
Legally wrong advice built on unverified output
A chatbot trained largely on overseas material will confidently describe American or English positions as though they were Australian law. The error is invisible unless someone checks the primary source.
High
Privilege and conflict contamination
Material from multiple matters pasted into the same account or thread creates a record you cannot easily discover, delete or explain if it is ever asked about.
High
No record of how work product was produced
If a client or an insurer asks how a document was prepared, the honest answer is that nobody knows. That is uncomfortable rather than fatal, but it undermines every other assurance you give.
Moderate
Inconsistent output quality
Different tools, different prompts, different people. Work leaving the firm varies in a way partners cannot see until a client complains.
Moderate
The bottom two are annoying. The top two end up in front of a costs judge, a regulator or your insurer.

Finding out what is actually happening

Before writing a policy, find out what you are writing it about. A policy drafted against an imagined problem gets ignored by people dealing with the real one.

The goal of this exercise is information, not discipline, and you have to say so out loud or you will get nothing useful. An amnesty framing works: tell people you want to know what they use and why, and that no one is in trouble for answering honestly.

A two week audit any practice manager can run
1
1. Declare the amnesty
One short message from a partner, not from IT. State plainly that the firm wants to know what tools are in use, that there are no consequences for telling the truth, and that the aim is to give people something better.
2
2. Ask about tasks, not tools
Ask what people wish they could hand off: summarising long documents, first draft correspondence, getting oriented in an unfamiliar area of law. The answers tell you what to sanction.
3
3. Check the browser and app landscape
For firm managed devices, look at what has been installed and what domains are being reached. This is not surveillance theatre, it is scope. Be transparent that you are doing it.
4
4. Sample the work product
Pick a handful of recent internal memos and research notes and check the authorities cited. If anything does not resolve to a real decision on AustLII or a court's own site, you have a live problem, not a theoretical one.
5
5. Write down the top five use cases
By the end you should have a short list of jobs people are doing with AI. That list is the specification for whatever you approve next.
You are looking for the tasks people are trying to solve, not a list of offenders.

A policy people will actually follow

A policy that says only be careful gives nobody a decision rule. A policy that says never gets ignored. What works is a short document that draws a hard line around confidential material, sets a verification standard for anything leaving the firm, and names an approved tool for the tasks people were already doing.

Keep it to two pages. Every clause a busy solicitor will not read is a clause that will not be complied with.

Ninety days to something workable
Days 1 to 30
Scope and stop the bleeding
  • Run the amnesty audit and write down the real use cases
  • Issue one immediate rule: no client identifying material into any consumer tool, effective now
  • Sample recent work for unverified citations and fix anything already filed
  • Tell the team a sanctioned option is coming and give them a date
Days 31 to 60
Approve something real
  • Assess tools against where data is stored, whether inputs train the model, and whether outputs cite verifiable Australian sources
  • Check the vendor's data residency and retention terms in writing, not from the marketing page
  • Run a pilot with the two teams that reported the heaviest shadow use
  • Write the two page policy: what is allowed, what is prohibited, who to ask
Days 61 to 90
Make verification routine
  • Require every authority in outgoing work to be checked against the primary source, regardless of how the draft was produced
  • Add an AI use question to the file opening and matter closing checklists
  • Train on prompting and on failure modes, especially confident output on overseas law
  • Review the policy against current court practice notes and guidance each quarter
The sequence matters. Approve a usable tool before you enforce a restriction, or you are back to a ban.

The version of this that ends well

Firms that come out of this in good shape are not the ones with the strictest rules. They are the ones where a solicitor with a deadline has an obvious, approved, reasonably good option, so there is no reason to reach for a personal account.

That means the sanctioned tool has to be genuinely useful for legal work rather than a generic assistant with a compliance wrapper. Practically, it needs to keep matter material inside a system you have assessed, answer against Australian legislation and Australian judgments, and show you the source so verification takes seconds rather than an hour. Purpose built Australian legal research tools, Legal Brain among them, exist for that reason, and the question to ask any vendor is the same one you would ask a new graduate: show me where you got that.

Shadow AI is not a technology problem. It is a signal that your people found a way to work faster and did not think the firm would let them say so. Fix that, and the governance follows.

Frequently asked questions

Is it a breach of confidentiality to put client information into ChatGPT?

Disclosing client information to a third party system without informed consent engages the confidentiality duty in the Australian Solicitors' Conduct Rules, and consumer AI services are third parties. If the material is personal information, the Privacy Act obligations and the notifiable data breach scheme may also be in play. The safe working rule is that no client identifying material goes into any tool the firm has not assessed and approved.

Do Australian courts require disclosure of AI use in court documents?

Expectations vary by jurisdiction and change as courts update their guidance. Several Australian courts have issued practice notes and guidelines dealing with generative AI in the preparation of court documents, including requirements around verification and, in some cases, disclosure. Check the current practice note for the specific court and division before filing, and treat every authority as unverified until you have read the primary source.

How do I find out if my staff are using AI without approval?

Ask, under a stated amnesty, with the message coming from a partner rather than IT. Pair that with a look at installed applications on firm managed devices and a sample check of citations in recent internal research memos. If an authority does not resolve on AustLII or the relevant court's website, you have found active shadow AI use.

Should a small firm ban AI until it can afford a proper tool?

A ban without an alternative pushes use onto personal devices where you cannot see it, which is worse than the position you started from. A more workable interim step is one hard rule, no client identifying material into unapproved tools, plus a verification requirement for every authority in outgoing work. That controls the two serious exposures while you assess options.

Check your understanding

Two quick questions

No score is stored. Pick an answer to see why it is right.

  1. 1A firm sends a all staff email prohibiting the use of ChatGPT and similar tools. What is the most likely result?

  2. 2Which shadow AI exposure carries the most serious professional consequences for an Australian solicitor?

Research Australian law without handing over client data

Legal Brain searches Australian legislation and case law, shows you the source behind every answer, and anonymises client-identifying detail before anything reaches a model.

Request early access