Joshua Lenon from the legal software provider Clio explores the “disclosure disconnect” and explains why legal AI governance must be built on trust.
The legal sector has traditionally been characterised as cautious with technology. Slow to change. Traditional. But that view is clearly outdated. As a recent report by Clio found, 89% of UK legal professionals are now using AI in some capacity.
As integration deepens, numerous challenges will emerge. One that’s already showing up in Clio’s research is around governance. In the same report, 81% of firms say they disclose their use of AI to clients, yet only seven per cent of clients recall their lawyers proactively telling them AI had been involved.
If we dig deeper into these findings, a further ten per cent of clients say disclosure came only when they asked, and the remaining 83% either don’t know whether AI was used or believe it wasn’t used at all.
It’s clear there is a gap between what firms believe they are doing and what clients actually experience. I’m calling this the disclosure disconnect. It raises questions around why AI disclosure is failing and how clients can feel better informed by their law firms.
Why the message isn’t landing
The disclosure disconnect is typically an issue of communication and process. When most clients come to solicitors, their focus is on the “what” and the “how much” rather than the “how” – the technology the firm uses to work on the case.
While detail-oriented disclosures may exist, they tend to slip into the same category as the fine print on a user agreement. They’re acknowledged, at best, but rarely absorbed.
There is no clear line on when AI use must be disclosed and when client consent may be required.
There is also a lack of clarity around when AI disclosure or consent is actually required. This technology is still new and developing.
There is no clear line on when AI use must be disclosed and when client consent may be required, in the way there are established frameworks for processing personal data under data protection law. These two issues can create a situation where what one firm deems an appropriate level of disclosure is seen as insufficient to the client.
A practical solution
Here’s one way to start addressing the disconnect: disclose AI use in a client care letter.
The client care letter is a natural home for clear and concise disclosures. It marks the beginning of the professional engagement, and includes essential information. In addition to the standard contents, such as scope of work, fees, timelines, and responsibilities, lawyers can describe the firm’s AI use in the letter.
To give that disclosure structure, firms should follow the Information Commissioner’s Office’s four principles for explaining AI: transparency, accountability, context, and impact on the client.
Targeting these four points helps a firm convey what tools it is using, how it maintains control over confidential client data, where its own professional judgement sits above whatever the AI tool produces, and how the tool ultimately benefits the client.
Used well, the client care letter bridges the gap between disclosure made and disclosure remembered.
Beyond the disclosure baseline
After the client care letter, firms don’t need to seek client consent for every specific use of AI. Instead, they should evaluate the need for disclosure as a risk-based decision, shaped by three key questions.
First, is there a real risk of disclosing personal or private information? This should also determine which AI solution is appropriate. Firms should consider how a provider processes and retains data.
They should also consider whether contractual and technical safeguards are in place, and whether lawyers have been trained to use the tool correctly. As matters evolve, firms should continue to assess whether particularly sensitive information should be redacted before it is processed.
Firms should continue to assess whether particularly sensitive information should be redacted before it is processed.
Second, does another legal or professional obligation apply? Some types of legal work, such as credit history or anti-money laundering checks, already carry their own disclosure or regulatory requirements.
Introducing AI into that workflow creates a new form of data processing, so firms should consider whether using a particular tool changes their obligations around confidentiality, transparency, or consent.
Third, did the client ask? Within the current disconnect, I encourage clients to raise any concerns they have about AI use. Clients can have legitimate anxieties, such as consumer AI products using their confidential data for LLM training.
Building trust
Firms should be ready to answer client questions honestly, in line with professional duties around transparency. Although it is unlikely for a client to go into such granular details about a firm’s AI usage, these conversations build trust and establish long-term business relationships.
Right now, AI disclosure may feel novel. However, it is unlikely to feel that way for long. We rarely see client complaints about which video-conferencing platforms a firm uses, or which legal research tool has supported the advice given by the lawyer.
Those technologies have become part of the legal landscape. AI is likely to follow a similar journey. Firms should focus today on updating their client care letters and implementing clear policies that ensure disclosure is both meaningful and understood.
Visit
Connect with Joshua Lenon via Linkedin