One in three legal professionals now uses AI tools their firm hasn't approved, according to Thomson Reuters research. For conveyancers processing transaction data, client funds and identity documents under SRA and CQS oversight, that shadow usage creates compliance exposure most practices haven't assessed.
The 34 per cent figure, drawn from Thomson Reuters' 'Future of Professionals' report, points to a governance gap between individual adoption and institutional control. When unapproved AI processes case files, firms face questions about professional indemnity notifications, GDPR processor agreements, cyber insurance validity and audit trail integrity. The risk sits with practices that lack the technical capacity to assess what their own staff are already using.
What conveyancing practices face that general law firms don't
The compliance burden differs by work type. A conveyancer using unapproved AI to generate contract summaries or draft TR1 forms handles different risk than a litigator summarising case law.
Property transactions involve client money, anti-money laundering checks, title examination and regulated deadlines. If AI processes that data, several standards apply. SRA Code of Conduct 8.5 requires confidentiality protections proportionate to the information handled. CQS accreditation expects documented systems for data security and quality control. GDPR Article 28 requires written processor agreements before third parties handle personal data.
A conveyancer pasting transaction details into ChatGPT or a standalone summarisation tool bypasses all three. No processor contract exists. No firm-level security assessment has occurred. The cyber insurance policy likely assumes approved systems only.
Professional indemnity insurers ask whether technology usage falls within disclosed systems and controls. If a claim arises from AI-generated advice or a data breach through an unapproved tool, notification obligations and coverage questions follow. Most firms haven't updated their PII applications to reflect AI usage because they don't know what staff are using.
The case management integration argument
Redbrick Solutions, whose promotional content prompted this analysis, positions integrated AI as a governance solution. The commercial logic is straightforward: bundling AI into existing case management creates a controlled environment with defined data hosting, security standards and approval by default.
The pitch carries weight for firms that lack technical due diligence resource. A standalone AI tool requires the practice to assess data residency, encryption standards, processor agreements and usage logging independently. An integrated offering transfers some of that assessment burden to the case management vendor relationship the firm already manages.
But integration doesn't eliminate governance requirements. Firms still need defined use cases, human oversight rules and staff training on where AI output requires checking. The Thomson Reuters statistic suggests the problem isn't just tool selection but usage discipline. If one-third of staff use unapproved tools despite firm policies, the issue is compliance culture as much as vendor choice.
UK data hosting, emphasised in Redbrick's positioning, matters less than contractual safeguards. GDPR adequacy depends on processor obligations, not server location. A UK-hosted system without proper data processing agreements offers no more compliance protection than an adequately contracted EU or US provider. Conveyancers evaluating AI vendors should prioritise processor contract terms, security certifications and audit rights over hosting geography.
What matters more than the technology
No AI tool solves the precedent risk that matters most in conveyancing. If AI drafts a lease clause incorrectly, cites an outdated statute or misreads a title restriction, the professional liability sits with the conveyancer who relied on it without verification.
The efficiency case for AI summarisation and drafting assistance is real. A 50-page lease report condensed to key issues saves fee-earner time. But the output requires checking by someone qualified to spot errors. That means firms need use-case definitions: AI may summarise documents but a qualified conveyancer reviews the summary before advice is given. AI may draft standard letters but a supervisor approves client-facing content.
Those rules need documenting before individual adoption creates inconsistent practice. The governance framework should cover:
- Which AI tools are approved and for what tasks
- What information may and may not be input
- What level of review AI output requires before use
- How usage is logged for audit and insurance purposes
- Who is responsible for vendor due diligence and contract terms
Firms without this framework should assume staff are already using consumer AI and work backwards to establish control.
