Sunday, 6 September 2026

AI in Legal Research: The Accuracy Problem and the Privacy Problem

AI in Legal Research: The Accuracy Problem and the Privacy Problem

Two strands of case law are converging on the same warning — check what the machine tells you, and watch what you tell the machine.

Source

This article is adapted from reporting and legal analysis originally published in Your Witness, the newsletter of the UK Register of Expert Witnesses, Issue 125 (September 2026), published by J S Publications.

Artificial intelligence has become impossible to avoid in litigation. Expert witnesses, solicitors, barristers and even judges are all reaching for AI tools in growing numbers. But a run of recent judgments shows that using AI carelessly creates two quite different problems: getting things flat-out wrong, and giving away information you never meant to share.

I.When AI Makes Things Up

Several recent cases have turned on what happens when AI-generated content reaches a court unchecked:

  • Harber v Revenue & Customs Commissioners[2023] UKFTT 01007 (TC) — AI had generated fictitious case law.
  • Zzaman v Revenue & Customs Commissioners[2025] UKFTT 539 (TC) — AI introduced citations that were inaccurate and didn't support the argument.
  • R (Ayinde) v Haringey LBC[2025] EWHC 1383 (Admin) — lawyers relied on AI-generated material without verifying it.

Following Ayinde, Dame Victoria Sharp, President of the King's Bench Division, issued guidance that was refreshingly blunt: generative AI tools can produce responses that look coherent and plausible but are, in fact, fictitious, inaccurate or misleading. They cannot be relied on to conduct legal research unsupervised. Anyone who uses them still carries the professional duty to check the results — and getting it wrong can mean contempt proceedings, wasted-costs orders, or a referral to a professional regulator.

None of this has slowed AI's spread through the justice system. Litigants in person use it extensively, often without the skill to check its output. Solicitors and barristers use it for research and drafting. And a number of judges have become cautious but genuine advocates for AI as a research aid in its own right.

The evidence itself can be the problem

A further judgment, David Abbott & Others v Ministry of Defence [2026] EWHC 941 (KB), added a different wrinkle. The court rejected AI-based evidence on hearing loss because the underlying method — built on deep neural networks and machine learning — couldn't be explained in a way the court could test. Such techniques, the judge held, cannot safely be deployed in litigation while nobody can say precisely how they reach their conclusions.

II.What Happens to the Data You Feed In

A second, equally serious risk has now been set out by the Upper Tribunal in R (Munir) v Secretary of State for the Home Department [2026] UKUT 81 (IAC).

The case again involved fabricated citations generated by AI, and Judge Blundell used the judgment to restate a principle that should be obvious but often isn't: the primary duty of any regulated lawyer is to the court and to the cause of truth and justice — not to whatever shortcut an AI tool offers. Anyone who knowingly or recklessly puts false information before a tribunal, or fails to supervise a junior who does, should expect serious consequences.

The judge went further still, adding a pointed warning about confidentiality: putting client letters and Home Office decision letters into a public AI tool such as ChatGPT effectively places that information on the open internet — breaching client confidentiality and waiving legal privilege.

Any regulated professional who does this should expect to answer to their regulator, and would be well advised to consult the Information Commissioner's Office.

“Do not input sensitive data into public AI tools.”

Most major AI tools use the text, documents and personal details users input to help train future versions of the model. Human reviewers can, in some cases, read chat transcripts, and stored data is always vulnerable to a breach. Feed a public tool your proprietary research, your strategy, your source code — and you risk that material being retained, reviewed, or resurfacing in someone else's query entirely. The same risk applies just as much to expert witnesses as it does to lawyers, especially where the material touches medical, financial or identity information.

III.What To Actually Do About It

The safest option is a closed system — one that keeps confidential information, personal data and client records out of the public domain. Judges increasingly rely on closed intranet tools, such as the judiciary's own ejudiciary.net, for exactly this reason. The trade-off is that closed systems tend to lag behind public ones in capability, given how fast the public tools are developing.

Where a public AI tool is genuinely unavoidable, treat it the way you'd treat social media — assume anything you type could become visible to someone else — and take these precautions:

  1. Redact your data. Strip names, identifiable personal details, addresses and passwords before you paste anything in.
  2. Check for opt-out settings. Where they exist, turn off model training and data-sharing.
  3. Use enterprise tiers. Paid accounts usually promise your data won't be used for training.
  4. Consider running models locally. It takes more technical know-how, but it hands you far greater control over your own data.

A platform's promise to "turn off" collateral training sounds reassuring — but the warning from the bench is not to rely on it. Treat anything typed into a public AI tool as though it were already public.

The Bottom Line

Between the accuracy failures in Harber, Zzaman, Ayinde and Abbott, and the privacy warning delivered in Munir, the message from the courts is now consistent. AI can be a genuinely useful research and drafting tool — but only when it's used with proper scrutiny of both the output it produces and the data you put into it. For anyone handling sensitive or identifiable material in litigation, the risks of a public AI tool are likely to outweigh the convenience. Specialist, closed systems remain the safer choice.

1 comment: