Australian legal practice is at a crossroads. Artificial intelligence tools have never been more accessible, and the pressure on fee earners to work faster, bill more, and do it all with fewer resources has never been greater. The result? Solicitors and paralegals across the country are quietly reaching for consumer AI tools, personal ChatGPT accounts, free-tier generative AI platforms, and browser-based assistants to get client work done faster. No IT approval. No oversight. No policy. This is shadow AI in legal practice, and it represents one of the most pressing AI risk issues facing the Australian legal profession right now.
What Is Shadow AI and Why Is It Growing in Legal Practices?
Shadow AI refers to the use of artificial intelligence tools by employees without formal organisational approval or governance. In law firms, this typically means a fee earner using a personal or consumer AI account to draft client correspondence, conduct legal research, summarise documents, or generate advice letters, outside of any firm-sanctioned AI framework.
The numbers are sobering. In 2024, a staggering 80% of Australian workers were using personal generative AI accounts at work. And the legal profession is not exempt. According to the Thomson Reuters Tech, AI and the Law 2024 Australian edition, one in three law firm professionals (31%) said they are using unofficial generative AI systems to support their work.
What’s driving this? A few things:
- Billable hour pressure. Using an AI tool to draft or summarise cuts hours off routine tasks.
- Tool accessibility. Consumer AI platforms are free, intuitive, and available on any device.
- Policy gaps. The Thomson Reuters 2025 Generative AI in Professional Services report found that only 30% of law firms currently have a specific AI policy in place. When firms fail to provide a clear structure for AI adoption, practitioners naturally turn to whatever tools are most accessible.
- Visibility failures. According to the 2025 Shadow AI Report by Josys, which surveyed 500 Australian technology decision makers, 70% of organisations have moderate to no visibility into what AI tools are being used within their operations.
This is how unsanctioned AI use quietly becomes embedded in legal work, not through deliberate misconduct, but through convenience.
The ASCR Confidentiality Problem
This is where shadow AI in law firms moves from an IT governance issue to a serious professional conduct matter.
The joint statement on the use of AI in Australian legal practice, issued by the Law Society of New South Wales, the Legal Practice Board of Western Australia, and the Victorian Legal Services Board and Commissioner, is unequivocal: lawyers cannot safely enter confidential, sensitive, or privileged client information into public AI chatbots or copilots like ChatGPT, or any other public tools.
The obligations trace directly to the Australian Solicitors’ Conduct Rules. Rule 9 of the ASCR requires solicitors to maintain the confidentiality of client information at all times, including after the retainer ends. The obligation applies to all information a solicitor obtains during a retainer, not just formally privileged communications.
When a practitioner pastes client matter content into a consumer AI tool, several things can happen to that data:
- It may be stored on offshore servers (typically in the United States) under US law.
- It may be used to train the AI model unless the user has actively opted out.
- It may be accessible to the AI provider’s staff.
- It may be surfaced in responses to other users.
Reasonable steps in 2025 include selecting AI tools with Australian data residency or verifiable data isolation, executing data processing agreements with AI vendors, implementing access controls preventing AI tools from accessing matter files without appropriate authorisation, and training staff on the confidentiality implications of AI use.
The use of AI in legal research carries additional risk. Several cases have emerged where practitioners relied on AI-generated case law that later proved to be fictitious, so-called “hallucinations.” In Luck v Secretary, Services Australia [2025] FCAFC 26, the Full Court identified a fictitious case in a litigant’s application, noting they apprehended it was a product of hallucination by a large language model.
The use of consumer AI is not just a data risk. It can also compromise legal privilege itself. The Supreme Court of Queensland has directed in its 2025 guidelines that any information inputted into a public generative AI chatbot should be treated as published to all the world, since public AI chatbots can remember every question asked of them and could use that information to respond to queries from other users.
Other Regulatory Considerations
Beyond the ASCR, law firms face a broader set of compliance obligations when it comes to AI use across their practice.
- Privacy Act obligations. The Australian Privacy Act 1988 and the Australian Privacy Principles apply to the collection, use, and disclosure of personal information. When client data is transmitted to a third-party AI provider without a proper data processing agreement, firms may be in breach of their Privacy Act obligations, particularly if that data is processed or stored outside Australia.
- Uniform Law jurisdictions. Under the Legal Profession Uniform Law, lawyers using AI should implement clear, risk-based policies to minimise data and security breaches, setting out what AI tools they have decided to use in their practice, who can use those tools, for what purposes, and with what information. This applies in the legal profession uniform law jurisdictions of New South Wales, Victoria, and Western Australia.
Law Society and regulatory body guidance. Multiple bodies have issued specific statements:
- The Law Society of New South Wales and the Legal Practice Board of Western Australia co-issued the December 2024 joint statement on AI use.
- The Victorian Legal Services Board and Commissioner has published guidance on confidentiality and AI.
- The Law Society of the Australian Capital Territory has reminded practitioners that the use of generative AI tools must be consistent with their professional obligations, and that practitioners must not input confidential, sensitive, or privileged information into public generative AI tools.
- In June 2024, the Queensland Law Society issued Guidance Statement No. 37 on artificial intelligence in legal practice.
- The Law Council of Australia’s Technology and the Law Committee has stated that competence in 2025 includes understanding the capabilities and limitations of AI tools used in practice.
PI insurance implications. A shadow AI incident, where unsanctioned AI use leads to a confidentiality breach or an erroneous AI output submitted to a court, could trigger a professional indemnity insurance claim and raise questions about whether the firm’s coverage applies, given the absence of a documented AI policy.
What a Shadow AI Incident Actually Looks Like
Consider this scenario, which is far from hypothetical in the current environment.
A junior solicitor at a mid-sized Australian law firm is under pressure to turn around a client advice letter by end of day. She opens a personal ChatGPT account on her work laptop. She pastes in the client’s name, the relevant matter details, their instructions, and key background facts. She asks the tool to draft the letter.
In seconds, she has a draft. She edits it, sends it to the partner for review, and the letter goes out. The partner has no idea the draft originated in a consumer AI tool.
What has just happened?
- The client’s confidential information, name, instructions, and matter details has been transmitted to a US-based AI model operating under standard consumer data retention terms.
- The firm has no record of the AI tool use, no consent from the client, and no policy that covers the scenario.
- The firm is potentially in breach of ASCR Rule 9.
- Depending on the AI provider’s terms, that data may have entered the model’s training dataset.
- The firm’s PI insurer would likely not have been informed of this AI tool use.
This is what shadow AI risk looks like in Australian law firms, not a dramatic data breach, but a quiet, well-intentioned decision that creates serious exposure. The cybersecurity best practices guide for Australian businesses from Telco ICT outlines how shadow IT monitoring, including unsanctioned AI tools, is now a core element of endpoint security for professional services firms.
Building an AI Acceptable Use Policy for Your Firm: Key AI Governance for Law Firms
A documented AI policy is no longer optional for Australian legal practices. It is the baseline expectation from regulators, law societies, and PI insurers.
Here is what a legally sound AI usage policy for an Australian law firm should cover:
- Approved AI tools list. Name the specific AI tools that have been reviewed and approved for use with client matter data, and those that are prohibited.
- Data classification rules. Specify what categories of information (client-identifiable, privileged, commercially sensitive) may never be entered into any AI tool without explicit authorisation.
- Matter-specific prohibitions. Define which matter types, litigation, sensitive transactions, and regulatory investigations carry higher restrictions on AI tool use.
- Training obligations. Require all fee earners and support staff to complete training on the confidentiality implications of using AI tools and the limitations of AI output.
- AI output verification. All AI-generated content must be reviewed and verified by a qualified practitioner before use in any client-facing document or court filing.
- Breach reporting. Establish a clear process for staff to report suspected AI policy breaches, including inadvertent disclosure of client data to an unapproved AI provider.
- Billing transparency. Lawyers who use AI should ensure that it does not unnecessarily increase costs for their client above traditional methods, and that billing accurately represents the legal work done.
Telco ICT supports law firms in developing and implementing AI governance frameworks as part of a broader managed IT and compliance engagement. This includes endpoint management, data loss prevention configuration, and Microsoft 365 governance that prevents unsanctioned AI tool use at the network and device level. See how Telco ICT’s managed IT services are already supporting professional services firms across Australia.
Approved vs. Unapproved AI Tools: A Simple Framework
Use this table to assess whether an AI tool is appropriate for use with client matter data in an Australian legal practice.
| Feature | Approved Enterprise AI Tool | Unapproved Consumer AI Tool |
| Data residency | Australian or contractually specified | Unknown, typically US-based |
| Training data use | Contractually prohibited | Default opt-in (unless manually disabled) |
| Data processing agreement | Yes, with firm | No |
| Audit trail | Full logging within firm systems | None |
| Access controls | Role-based, matter-level | None |
| Regulatory alignment | ASCR, Privacy Act, Uniform Law | Not assessed |
| AI output verification | Policy-enforced | Ad hoc |
| Approved AI access | Controlled by IT policy | Personal account, unmonitored |
Examples of enterprise AI tools that can be configured for legal practice in Australia include Microsoft 365 Copilot (with appropriate data governance), Harvey AI, and LexisNexis AI under a formal enterprise agreement. Microsoft made in-country data processing available for Microsoft 365 Copilot interactions in Australia by late 2025, meaning Copilot interactions can be processed and stored within Australian borders, a significant step toward meeting the data residency requirements relevant to Australian legal practice.
By contrast, free-tier ChatGPT, personal Claude accounts, Google Gemini, and similar consumer AI applications are unapproved AI tools for client matter use unless operating under an enterprise contract with appropriate data protections.
How Telco ICT Supports Law Firm IT Governance
Telco ICT Group provides managed IT services for professional services firms, including law practices that need to govern AI use across their workforce without blocking the productivity benefits that secure AI can deliver.
Our work in this area includes:
- Microsoft 365 and Copilot deployment with appropriate data residency configuration, sensitivity labelling, and data loss prevention policies. Read more about integrating Microsoft 365 Copilot into your business with proper governance in place.
- Endpoint management to detect and block unapproved AI tool access at the device level, including shadow IT monitoring for unsanctioned AI applications.
- AI policy support as part of a broader IT governance engagement, including acceptable use frameworks aligned with ASCR obligations and law society guidance.
- Data governance reviews to ensure your firm’s Microsoft 365 environment is configured to support Copilot deployment safely, without over-permissioned SharePoint environments surfacing matter data inappropriately.
If your firm is exploring how to enable secure AI adoption while maintaining compliance, talk to the Telco ICT team about a professional services IT governance engagement. You may also find our posts on cybersecurity trends for 2026 and whether your IT provider is really using AI useful context for this conversation.
Ready to get your firm’s AI governance in order?
Talk to Telco ICT Group about managed IT and AI governance for professional services firms. We help law practices across Australia implement the policies, tools, and controls needed to use AI safely and stay on the right side of their ASCR obligations.
FAQs
Is it against the ASCR to use ChatGPT for client work?
Yes, it can be. The joint statement from the Law Society of NSW, the Legal Practice Board of Western Australia, and the Victorian Legal Services Board and Commissioner makes clear that lawyers cannot safely enter confidential, sensitive, or privileged client information into public AI chatbots like ChatGPT. Doing so without an enterprise agreement and data processing safeguards in place risks breaching ASCR Rule 9.1.
What AI tools are considered safe for Australian law firms?
Tools with Australian data residency, zero training data retention, an enterprise data processing agreement, and full audit trail capability. Microsoft 365 Copilot (correctly configured), Harvey AI, and LexisNexis AI under enterprise contracts are frequently cited examples. Consumer or free-tier versions of any AI tool are not appropriate for client matter work.
Does Microsoft Copilot comply with Australian data residency requirements?
Microsoft announced in late 2025 that it would offer customers in Australia the option to have Microsoft 365 Copilot interactions processed in-country, meaning within Australian data centres. However, this requires deliberate configuration by your IT provider, and data governance controls, including permission management and sensitivity labelling, remain the firm’s responsibility.
How do I detect if fee earners are using unapproved AI tools?
This requires active endpoint monitoring and network-level visibility. A managed IT provider can configure tools to flag or block access to consumer AI platforms on firm devices and networks. Regular IT audits, acceptable use policy acknowledgements, and staff training are also essential components of a documented AI governance framework.
What should a law firm’s AI policy include?
At minimum: a list of approved and prohibited AI tools, data classification rules, matter-specific restrictions, AI output verification requirements, staff training obligations, breach reporting procedures, and billing transparency guidance aligned with the Legal Profession Uniform Law.
Table of contents
Related Posts
We’ll handle the tech
so you can get on with
running your business.