explainerAI GovernanceSRA & UK Regulation

Can lawyers put client data into AI tools?

The regulation map records 76 reviewed country answers on client data in AI tools: binding rules, guidance, proposals and gaps.

Edited and verified by Cognesio LLP

Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓

Sometimes, but the public rules rarely treat a prompt box as ordinary typing space. As of 16 September 2026, the editor-reviewed client-data category records seven binding country answers, 33 guidance answers, two proposals, 31 none answers and three unclear answers. The common line is confidentiality first, then contract, security and data-use controls.

How was the count made?

The count comes from every non-provisional country YAML file in src/content/countries/. The script read the confidentiality-client-data cell, grouped the status field, and counted each country once. Sub-national or professional-body rules support the country cell but do not create extra country counts.

That means the labels are not identical. Slovakia is binding because its bar resolution states conditions for entering confidential information or personal data into AI tools. The United Kingdom is guidance because the SRA and BSB documents apply existing duties to AI rather than making a new AI-specific rule. The United States is guidance at the country level, supported by the ABA Formal Opinion 512 record and state materials including California.

Where it is binding

The binding group is Austria, Colombia, Finland, Germany, the Philippines, Poland and Slovakia.

The sources differ by audience. Austria, Finland, Germany, Poland and Slovakia are lawyer-facing professional or data-security instruments. Colombia and the Philippines are judiciary-facing AI governance instruments that also cover court users, vendors or members of the Bar. The country page gives the limit for each cell.

Where it is guidance

Guidance answers are Argentina, Australia, Belgium, Brazil, Canada, Croatia, Czechia, Denmark, Estonia, the European Union, France, Hong Kong SAR, Indonesia, International bodies, Ireland, Israel, Italy, Japan, Luxembourg, Malaysia, the Netherlands, New Zealand, Nigeria, Norway, Singapore, Spain, Sweden, Switzerland, Türkiye, the United Arab Emirates, the United Kingdom, the United States and Vietnam.

Two reviewed country records sit outside those lists because the answer is proposed, not current law or guidance: Ecuador and South Africa.

Where nothing exists

The script counted 31 reviewed country records marked none and three marked unclear. None means the category was checked and no rule, guidance, proposal or case-law position was found in the recorded sources. Unclear means the source record does not yet support a reliable answer.

The none records are Bahrain, Bangladesh, Chile, China, Costa Rica, Cyprus, the Dominican Republic, Egypt, Ghana, Greece, Iceland, India, Kenya, Kuwait, Latvia, Lithuania, Malta, Mexico, Morocco, Nepal, Pakistan, Panama, Peru, Portugal, Qatar, Saudi Arabia, Slovenia, South Korea, Sri Lanka, Taiwan and Uruguay. The unclear records are Hungary, Romania and Thailand.

What the documents actually say

The sources use different legal forms, but the passages point in the same direction: client material is not to be entered into an AI system unless the confidentiality position has been dealt with first.

The Austrian Bar guide, §2, says: “Die Eingabe von mandatsbezogenen oder sonstigen vertraulichen Informationen in öffentliche oder ungesicherte KI-Systeme stellt einen Bruch der Verschwiegenheit dar und ist standesrechtlich unzulässig.”

The Slovak Bar resolution, Article 4, says: “Advokát nesmie zadávať do AI nástrojov informácie chránené mlčanlivosťou ani osobné údaje” unless one of the listed exceptions applies.

The SRA warning notice, under “Client confidentiality”, says: “Client information should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality.”

The Law Society of Singapore advisory says lawyers using public AI tools “must not upload or input … any data, document or information” that is privileged, proprietary, confidential or contains personal data.

What it does not cover

This category is not a general training-data rule. It records whether lawyer, court or data-protection sources say client information can be entered into AI tools, and on what confidentiality conditions. A vendor’s separate promise not to train on customer data belongs in the tools directory, not in the country map.

As of 16 September 2026, the tools directory has 53 verified independent tool records: 44 record noTrainingOnCustomerData: yes, five record no, and four record unknown. Those are vendor-documentation facts, not substitutes for a country rule. The same separation applies to client consent, disclosure to clients, procurement checks and data-protection law; those are separate tracker categories even when the same document covers them.

Sources