The AI Governance Gap in UK Law Firms, And Why It Matters Now.

In AspiraCloud’s early survey of UK law firms, 33% are already using AI tools with no formal policy in place to govern how AI gets used, what data goes into it, or who’s accountable when something goes wrong1. A further 44% are exploring AI but haven’t adopted it yet. 

That’s the finding at the centre of AspiraCloud’s ongoing research into IT priorities across the legal sector, and it’s the one that should give every managing partner and IT decision-maker pause. 

Much of this adoption is happening informally, through individual fee earners trying a tool that saves them an hour on a first draft, well ahead of any firm-wide decision to adopt AI at all. 

Governance is playing catch-up, and the gap between what’s actually happening on the ground and what firms can formally account for is widening every month. 

AI Adoption Is Moving Faster Than the Policies Meant to Manage It 

This isn’t a hypothetical risk. Across the firms we surveyed, and the wider conversations we’ve had with managing partners and IT decision-makers, the same pattern keeps showing up: 

  • Fee earners using generative AI on personal devices or accounts for research, drafting, or correspondence 
  • Client documents pasted into public AI tools with no assessment of where that data goes 
  • AI-assisted content reaching clients without a consistent review step 
  • No firm-wide record of which tools are in use, or by whom 
  • Copilot switched on without reviewing who can see what across SharePoint and Teams 

None of this makes a firm reckless. It’s simply what happens when useful tools arrive faster than the policies meant to sit around them. The SRA doesn’t see it that way, though. 

Existing obligations don’t disappear just because a task involves AI rather than a person, so firms are expected to know where AI sits in their workflows and keep client information secure, with a suitably qualified person reviewing output before it reaches a client. 

Using AI without a policy may not put a firm in breach of a specific rule on its own. Where the exposure lies is in being unable to show, if asked, that any of this has been properly thought through. 

Why the Timing Matters 

Adoption is accelerating because the tools are inexpensive and useful for everyday work, such as summarising bundles or drafting first-pass correspondence. Every month that passes, more firms end up in the same position as the third of firms in our survey who are already using AI with no formal policy to govern it. 

Regulators are paying closer attention at the same time. The SRA’s recent guidance on supervision makes clear that firms need to show active oversight of how work gets delegated and reviewed, whether that work goes to a junior colleague or an AI tool2. A missing policy is now a visible gap in a firm’s compliance story. 

Clients are asking similar questions before handing over sensitive matters, and fee earners increasingly expect these tools to be available and properly managed. A firm is already sitting in this gap if any of the following sound familiar: 

  • Fee earners have mentioned using tools like ChatGPT or Copilot without being asked 
  • There’s no written answer to the question of which AI tools the firm allows 
  • Nobody could confidently say who last reviewed a piece of AI-assisted client work 
  • Decisions about AI tools have been made ad hoc rather than as a single policy 

Where Copilot Changes the Picture 

Copilot’s growing presence in Microsoft 365 environments makes the governance gap harder to ignore for any firm already running that stack. Copilot works from the same permissions structure a firm already has across Microsoft 365, so it can only see what a user could already access before it arrived. Any risk it surfaces was already sitting inside the firm’s access model. 

These risks build up over time and stay easy to miss until something starts summarising across all of it at speed. Copilot is that something. 

Ask any managing partner whether they’d be comfortable if Copilot summarised everything an employee could currently access across the firm today. Most won’t have an answer, because nobody’s tested it. 

This is where AI governance and Microsoft 365 security become the same conversation. A policy on approved tools means little if nobody’s checked the access model underneath it. Before rolling out Copilot, firms need visibility over a few things. 

  • Who has access to what across SharePoint and Teams 
  • Whether multi-factor authentication (MFA) and conditional access are enforced properly 
  • Whether devices connecting to the tenant meet a minimum security standard 
  • Whether data loss prevention controls and an audit trail are in place 

None of this is a reason to hold off on Copilot, since it removes a lot of the administrative load around client work when it’s used well. The permissions work simply needs to happen alongside the rollout, because Copilot will surface whatever’s there regardless.  

What a Workable AI Governance Policy Covers 

Closing the gap doesn’t require months of consultancy or a document nobody reads. A proportionate policy for a small or mid-sized enterprise (SME) or mid-sized firm typically covers the following:  

  • Which tools are approved for use, and which aren’t 
  • What client data can and can’t be entered into an AI system 
  • Who reviews AI-assisted output before it reaches a client, and how 
  • How AI-assisted time gets recorded and billed 
  • What training staff need before they’re allowed to use approved tools 
  • Which permissions and access controls get reviewed before Copilot or similar tools go live 

None of this is complicated in isolation. The challenge is finding time to work through it properly and knowing which parts matter most for a legal practice specifically, instead of adapting generic corporate guidance that doesn’t reflect how fee earners work. 

A policy that sits in a drawer unread does as little good as no policy at all, so the training and review steps matter just as much as the document itself. 

Where an Informed Partner Helps 

This is exactly where a technology partner who understands legal practice earns their place. AspiraCloud brings direct experience of the legal sector to this kind of policy work, including the following: 

  • Worked alongside law firms and legal aid organisations across the UK, including presenting at Law Society events on legal technology and compliance 
  • Holds Microsoft’s Change Management and User Adoption competency, one of only two UK partners with that specialism 
  • Built a training and adoption approach specifically to make sure new tools and policies get used, instead of just switching on 
  • Understands that a workable policy for a 30-person practice looks different to generic corporate guidance 

What sets firms managing this well apart is having a partner who can translate SRA expectations into a policy that fits how their practice operates day to day and who’s there to update it as the tools and the guidance keep moving. 

Join the Conversation This October 

AspiraCloud is bringing these findings, and the wider picture from its full legal sector survey, to three roundtable events this October in London, Birmingham, and Manchester. 

Each session brings managing partners and IT decision-makers together to discuss AI, compliance, and data management in UK law firms, with AspiraCloud facilitating and the research setting the agenda. 

Delivered in partnership with Microsoft, each event includes a live session on where Copilot changes the risk picture for firms already running Microsoft 365, built around the same access and permissions questions raised in this piece. 

Register your interest to secure a place at the event nearest you: https://visit-our.link/9StRVFm

FAQs 

  1. What is AI governance for a law firm? 
    AI governance is the policy and oversight a firm puts in place to control how AI tools get used and who checks the output before it reaches a client. It sits alongside a firm’s existing compliance framework, supported by staff training. 
  2. Does the SRA require law firms to have a formal AI policy? 
    There’s no single rule that says every firm must hold a document titled AI policy. What the SRA does expect is that firms can demonstrate oversight of AI use, in line with existing obligations around competence and confidentiality. In practice, a documented policy is the clearest way to show that. 
  3. How many UK law firms have a formal AI policy in place? 
    In AspiraCloud’s early survey of UK law firms, 33% of respondents are already using AI tools with no formal policy in place, and a further 44% are exploring AI but haven’t adopted it yet. 
  4. What should a law firm’s AI policy cover? 
    A proportionate policy typically sets out approved tools, rules on client data, a review process for AI-assisted work, guidance on recording AI-assisted time, and minimum training before staff use approved tools. 
  5. Where can I find out more about the AI governance gap in UK law firms? 
    AspiraCloud’s full benchmark report on IT in UK law firms publishes later this year, and the findings will also be discussed at AspiraCloud’s roundtable events in London, Birmingham, and Manchester this October.