In one week in early 2025, a UK law firm’s monitoring logged more than 32,000 hits on ChatGPT, over 3,000 on DeepSeek and around 50,000 on Grammarly. Hill Dickinson blocked general access and replaced it with a request process. The Information Commissioner’s Office replied in public: “the answer cannot be for organisations to outlaw the use of AI and drive staff to use it under the radar” (BBC).
That exchange is the whole debate about shadow AI in law firms: the firm saw usage it had not approved and reached for the block; the regulator pointed out where blocked usage goes. Here is the evidence that shadow AI is the normal state, why a ban makes the risk worse, and a 30-day programme that works better.
The numbers: shadow AI is the default
| Figure | What it measures | Source |
|---|---|---|
| 34% (41% where organisational progress is slow) | Professionals using AI tools their organisation has not sanctioned | Thomson Reuters, Future of Professionals 2026 (1,816 respondents, 62 countries) |
| 69% | Legal professionals personally using general-purpose AI for work, up from 31% in 2025 | 8am 2026 Legal Industry Report (1,300+) |
| 9% | Work at a firm with a written, enforced AI policy; 43% have no policy and no plans | 8am 2026 |
The Thomson Reuters figure is the one for the management committee (Thomson Reuters); the 8am pairing of 69% use against 9% enforced policy explains it (LawNext). Nicole Black’s summary: lawyers use generative AI “off the books”. The State Bar of Texas adds that 50% of its lawyers report no firm policy, only 5% a firm that discourages AI, and 63% of users are on ChatGPT; ILTA’s 2025 Technology Survey found a third of small firms using public ChatGPT. The what lawyers really think guide has the sentiment behind the numbers.
Hill Dickinson’s 32,000 hits and the ICO’s line
Hill Dickinson was not wrong to look; looking is the first step. The lesson is in the ICO’s phrase, “under the radar”. A block does not reduce the 32,000 hits. It removes them from the log.
Why bans fail: personal phones, consumer defaults
The North Carolina Bar put the mechanism plainly in January 2026: “When firms ban AI without providing approved alternatives, they inadvertently create ‘Shadow AI’”, as lawyers “may turn to free, consumer-grade tools (like the free version of ChatGPT) on personal devices” (NC Bar).
The personal phone is the worst tier. Consumer ChatGPT trains on conversations unless “Improve the model for everyone” is switched off. Consumer Claude has trained by default since 28 August 2025, with five-year retention for users who allow it (Anthropic). Consumer Gemini, personal Copilot and Perplexity do the same; the business tiers do not. A ban moves the same client letter from a logged firm account with no-training terms to an unlogged personal one with training on, behind toggles nobody in the firm can check.
The real risks: training, privilege, holds, note-takers
Training and leakage. The archetype is Samsung, which banned ChatGPT in May 2023 after an engineer uploaded sensitive source code (Forbes); substitute a share purchase agreement. The SRA’s warning notice of 17 August 2026, issued after 42 reports of potential misuse, adds that “Both paid for and free-to-use AI tools may not provide the contractual, and technical safeguards needed to maintain client confidentiality” (SRA; see the SRA notice guide).
Privilege. In United States v. Heppner (S.D.N.Y., bench ruling 10 February 2026, memorandum 17 February), Judge Rakoff held that a defendant’s roughly 31 self-initiated exchanges with consumer Claude were protected by neither privilege nor work product: “Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege” (Orrick). Counsel-directed use, the court added, “might arguably” have been different: the same task on an unapproved consumer account is the version a court will not protect (the privilege guide has the case in full).
Litigation holds. Under the New York Times preservation order (13 May to 26 September 2025) OpenAI had to keep even deleted chats for Free, Plus, Pro and Team users; only Enterprise, Edu and zero-data-retention API customers were excluded, and 20 million de-identified logs were later ordered produced (OpenAI). “Deleted” on a personal account is conditional on someone else’s litigation.
Note-takers. The New York City Bar’s Formal Opinion 2025-6 requires client consent before recording and warns that transcripts “could effectively formalize everything that was said, including informal legal advice”. A free note-taker on a client call is shadow AI with a verbatim record.
Detection without a surveillance culture
Network logs give volume, not use case, and a firm that hunts individuals gets fewer disclosures next time. Use three sources: an anonymous census framed as an amnesty (people admit to an anonymous survey what they will never admit to a supervising partner); network logs in aggregate; and, once approved tools exist, their admin logs. Insurers now ask at renewal, “Do you police it?”, and want a policy, training records and a usage log, none of which a ban produces.
You are helping a [40-lawyer] firm run an anonymous survey of AI use before it chooses approved tools. Draft twelve questions answerable in three minutes, with no free-text field that could identify a person. Cover: which tools (name the common ones); which device and account (firm, personal); which tasks (eight options, research to note-taking); what client information has gone in (none / anonymised / identifiable); what would let the person stop using unapproved tools; what training they want. Add a two-sentence preamble stating the amnesty.The amnesty-plus-alternative programme
One promise, one deadline. Nobody is disciplined for disclosing what they already use, and every disclosure becomes a use case for the approved tool. The alternative is live within 30 days, because an amnesty with nothing to migrate to is a survey.
| Week | Action | Output |
|---|---|---|
| 1 | Announce the amnesty; run the census; publish interim traffic-light rules | Census results; interim rules on one page |
| 2 | Switch on the approved tool on a business tier for everyone; set retention; turn the top five census use cases into saved prompts | Approved tool live, not a pilot |
| 3 | Hands-on training in small groups on the census use cases, with anonymised real documents | Training records; a seeded prompt library |
| 4 | Policy version one, built from what people actually do; first metrics | Policy, acknowledgement, baseline numbers |
Two design choices matter. Everyone, not a pilot group: Richard Susskind warns that pilot groups create “two classes of lawyer”. And hands-on, not a webinar: Paul Weiss found its first PowerPoint session “ineffective” and moved to a prompting workshop; Ashurst found leaderboards drove engagement. The training guide has the formats.
Draft a 250-word all-staff message from the managing partner of a [jurisdiction] law firm announcing an AI amnesty. It must: state that a third of professionals use unapproved AI tools and that this firm assumes the same; promise that nobody will be disciplined for disclosing current use in the anonymous census; explain in one sentence why consumer tools on personal devices are the real risk (training defaults, no logs, privilege); commit to an approved tool within 30 days; give the three interim rules (public information: any tool; anonymised client material: approved tool only; identifiable client data: nowhere else); name a contact. Plain, warm, no threats.Week four comes last for a reason. Butler Snow had a written AI policy from June 2023 and an AI committee; in July 2025 three of its partners were still disqualified and referred to the Alabama bar after one used ChatGPT to add five fabricated citations. A policy is not a control; it works only once weeks one to three have made the approved path the easy one. And say the numbers out loud: a firm that opens with “we assume we are no different” gets disclosures; one that opens with “a disciplinary matter” gets silence and the same 32,000 hits.
Choosing the approved alternative fast
Do not run a six-month selection. Choose the business tier of what the census says people already use; the tool they know is the tool they will migrate to. ChatGPT Business is $20 a seat billed annually or $25 monthly; Claude Team is $20 to $25 a seat; Microsoft Copilot lists at $30 a user a month for enterprise and $21 for the Copilot Business add-on. None trains on your data by default. The ChatGPT confidentiality guide and the policy template cover settings and rules; a legal-specific platform can follow later.
Clifford Chance is the counter-example. It never blocked generative AI, its risk chief’s rule was “If it’s green, knock yourself out”, and its Copilot business case fitted on a napkin: “if we save 15 minutes per lawyer per week it will pay for itself. And we are saving more than that” (Legal IT Insider). Fifteen minutes a week is a low bar; your shadow users already clear it on their phones.
Draft a one-page interim AI use rule for a [jurisdiction] law firm during a 30-day transition. Three tiers: GREEN (public information, general legal concepts, marketing drafts: any tool); AMBER (anonymised client material, first drafts, summaries: approved business-tier tool only, with placeholders for names, amounts and dates); RED (identifiable client information, privileged strategy, anything filed with a court, recordings of client calls: never on an unapproved or consumer tool). Add the verification rule for anything sent or filed, who to ask when unsure, and that the rule replaces no professional duty. Plain English, under 400 words.Measuring the shift
Three numbers, monthly, from week four:
- Share of AI use on approved tools: admin-log active users divided by the census estimate; the target is the census number, not headcount.
- Usage growth on the approved tool: Freshfields reported roughly 500% growth in Claude usage in its first six weeks; flat usage after launch means the shadow tools are still winning.
- Training and acknowledgement records: what insurers and, in the EU, Article 4 supervisors ask for.
Thomson Reuters found that 66% of professionals at organisations with an active AI strategy say AI meets expectations, against 22% without one. The amnesty programme is the cheapest strategy you can have by next month; the implementation playbook and the firm implementation hub cover what follows.
Where to go next: the prompts above are in the prompt library. Send the disclosed shadow users to AI Lab for Lawyers first: four live, hands-on sessions on browser tools, after which they come back as the people who run week three.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools that the organisation has not approved, cannot see and cannot monitor: a lawyer running a client's letter through consumer ChatGPT on a personal phone, a paralegal using a free note-taker on a client call. It is the AI version of shadow IT. Thomson Reuters' 2026 Future of Professionals report found 34% of professionals doing it, rising to 41% where the organisation's own AI progress is slow.
How many lawyers use unapproved AI tools?
Roughly a third. Thomson Reuters' 2026 survey of 1,816 professionals in 62 countries found 34% using unsanctioned AI tools. The 8am 2026 Legal Industry Report found 69% of legal professionals personally using general-purpose AI for work while only 9% had a written, enforced firm policy, which is why Nicole Black describes much of that use as happening "off the books". Texas Bar data shows 50% of lawyers report no official firm policy at all.
Should law firms ban ChatGPT?
No. A ban does not stop use; it moves it. Hill Dickinson blocked access after 32,000 ChatGPT hits in a week, and the UK Information Commissioner's Office replied that outlawing AI drives staff to use it under the radar. The NC Bar says the same: bans without approved alternatives create shadow AI on personal devices. Approve a business-tier tool, publish a traffic-light rule for what may go into it, and train people hands-on.
What happened at Hill Dickinson?
In February 2025 the BBC reported that the UK firm had detected more than 32,000 hits on ChatGPT, over 3,000 on DeepSeek and around 50,000 on Grammarly in a single seven-day period. It restricted general access and replaced it with a request process. The ICO responded publicly that "the answer cannot be for organisations to outlaw the use of AI and drive staff to use it under the radar".
How do you bring shadow AI use into compliance?
Announce an amnesty: nobody is disciplined for disclosing what they already use, and every disclosure becomes a use case. Run an anonymous census in week one, switch on an approved business-tier tool in week two, train hands-on in week three, and publish policy version one in week four. Then measure the share of users on approved tools, usage growth, and training records. Send the shadow users to training first; they become the champions.