Engagement letter AI clause in England and Wales, ready to copy
· Updated · Written and maintained by Joaquín Trapero, Nonimo
No rule in England and Wales tells a solicitor or an accountant, in so many words, to tell clients that the firm uses AI. The SRA Code of Conduct is silent on it. The Law Society says the SRA has issued no specific guidance about it. And ICAEW calls its own template wording best practice, not a professional standard.
An engagement letter AI clause earns its place all the same, because three duties reach the letter by other routes. Confidentiality means some uses need the client’s agreement before anything goes into a tool. The UK GDPR makes a provider that receives client data a recipient the client must be told about. And for tax work, the bodies behind PCRT now recommend a statement in the letter of engagement.
This guide reads each source for what it actually says, first for solicitors and then for accountants and tax advisers. The wording comes last: a numbered clause for your terms of business, with two versions of the sub-clause on client data. One version is for firms that strip identifying details before using a tool; the other is for firms whose tool receives them. For the wider picture, see our page for solicitors or the one for accountants.
Why an engagement letter AI clause, when no rule demands one
There is no general duty, but there are several particular ones. They come from bodies of very different weight, so it helps to see them side by side. The list runs from a regulator’s code and its research report to a representative body’s guide, a joint ethical standard for tax advisers, and statute.
| Source | Status | On telling the client |
|---|---|---|
| SRA Code of Conduct, 6.3 and 8.6 | binding on solicitors | confidentiality unless the client consents; informed decisions |
| SRA Risk Outlook on AI, November 2023 | research report | tip: tell clients when AI is used on their case |
| SRA warning notice on AI, August 2026 | the SRA will have regard to it | silent on telling; strict on safeguards |
| Law Society, Generative AI: the essentials | guidance | decide with clients whether and how AI is used |
| PCRT topical guidance on AI, January 2026 | ethical guidance for tax work | a line in the letter of engagement supports transparency |
| ICAEW engagement letter helpsheet, March 2026 | best practice, not a standard | example terms of business now mention AI |
| UK GDPR, article 13(1)(e) | law | recipients of personal data, or their categories |
Source: the documents listed under Sources below.
Read down the last column and a pattern appears. Nothing makes a firm announce AI for its own sake. What the rules watch is the client’s information: who gets to see it, and whether the client can choose sensibly without knowing. The engagement letter is the cheapest place to settle both, before the first document arrives.
Three nearby questions are left out on purpose. Whether to tell a judge is covered in the court documents guide. Rules for your own staff belong in an AI acceptable use policy. And what to say once a file has already gone where it should not is a separate conversation, linked in the section on paragraph 6.3.
Telling clients about AI: the SRA’s tip and the Law Society’s advice
The closest the SRA has come to saying “tell them” is a research report. Its Risk Outlook on artificial intelligence in the legal market, dated 20 November 2023, groups its tips under transparency and explainability. One of them is to let clients know when AI will be used on their case, and how it will work.
The next line hands the method back to the firm, to decide in its own circumstances. A Risk Outlook tip is advice, not a rule. Under accountability, the same report asks firms to settle what clients need to hear about AI in their cases. So the decision is yours; the regulator has not written you a script.
What the August 2026 warning notice added
The SRA issued its warning notice on AI on 17 August 2026. The regulator says it will have regard to the notice when exercising its functions. It covers two worries: invented citations and client confidentiality. On telling clients that AI is in use, it says nothing. What it says on confidentiality does change how the clause must be drafted, and we come back to it under paragraph 6.3.
One older SRA page is firmer, on a narrower point. Its compliance tips on AI and technology, updated on 9 February 2026, say it should always be clear to clients when they are interfacing with AI. That means technology the client touches directly: a chatbot on your website, or an intake form that replies. If a client ever deals with software rather than a person at the firm, that line applies to you as written.
The Law Society leaves the choice to you and the client
The Law Society’s guide, Generative AI: the essentials, is candid about the gap. The version online as we wrote is dated 1 October 2025. It says the SRA “does not have specific guidance” on generative AI for use or disclosure in client care. It suggests that firm and client decide together whether and how such tools are used, and its checklist for smaller firms says the same.
Paragraph 8.6 of the Code, by contrast, is binding. You give clients information in a way they can understand. You also make sure they can make informed decisions about the services they need and how their matter will be handled. Whether a tool is part of how a matter is handled is a judgement call. A chronology drafted by a model and checked by a trainee sits nearer that line than a spellchecker does.
Add the rules later in this guide, and telling the client comes down to six triggers. More than one can apply to the same matter.
Will the client deal with AI software directly, such as a chatbot on your website?
YesMake it clear to them that they are dealing with AI, as the SRA's compliance tips say.
NoGo to the next question.
Is the tool part of how the matter will be handled?
YesParagraph 8.6 of the Code expects the client to decide with that knowledge. Say it in the letter.
Could the provider read, keep or learn from the client's matter?
YesTelling is not enough. Ask for the client's consent before anything goes in (paragraph 6.3). Accountants need the client's authorisation.
Will personal data from the file reach the provider?
YesAdd the provider, or its category, to the recipients in your privacy notice (UK GDPR article 13).
Are you the client's processor, as when you run their payroll?
YesThe client must authorise the tool in writing, in advance (article 28(2)).
Tax work: is AI fundamental to what the client will receive?
YesConsider telling the client directly before you start, as the PCRT guidance on AI asks.
None of them: no rule makes you say it, but the SRA's Risk Outlook tip and the Law Society's advice both point to telling the client, and the letter is the place.
Paragraphs 8.1 to 8.11 apply only when you provide services to the public or a section of it. So they do not reach a solicitor advising their own employer. For a high street or regional practice, our page for solicitors covers what the warning notice means in daily work.
Paragraph 6.3: when telling the client becomes asking
Confidentiality is where a notice can stop being enough. Paragraph 6.3 of the Code lets you disclose a client’s affairs in three situations: where the law requires it, where the law permits it, or where the client consents.
The warning notice explains why this bites. It cites the Upper Tribunal in UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC). The tribunal said that to put client letters “into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain”. The SRA concludes that such use will likely breach confidentiality, and that privilege may be lost for good.
It then warns that paying for a tool is no cure. Free and paid systems alike may lack the contractual and technical safeguards that confidentiality requires.
Our reading: safeguards first, then consent
The notice expects safeguards in every case. It wants client information in AI systems only where contractual, technical and organisational protection exists. It also asks firms to be satisfied of three things: the data remains “within a secure environment”, it is kept out of model training unless explicitly authorised, and it is held no longer than needed.
Our reading of the notice and the Code together is this. If the safeguards still leave the provider able to read, keep or learn from the matter, that is a disclosure, and paragraph 6.3 then needs the client’s consent. If they are complete, or the tool never receives anything that identifies the client, a clear notice is what the client is owed. The wording further down supports either position.
Consent in the Code, and consent in the UK GDPR
Notice what paragraph 6.3 leaves out. Where the Code wants a particular kind of consent, it says so: paragraphs 6.4(b) and 6.5(b) ask for “informed consent, given or evidenced in writing”. Paragraph 6.3 says only that the client consents. A signed page is still the natural proof, because paragraph 7.2 wants you to be “able to justify your decisions and actions”.
Keep that apart from consent as a lawful basis under the UK GDPR. A client agreeing that their matter may pass through a tool answers a confidentiality question. If your processing also rested on data protection consent, article 13(2)(c) would require you to tell the client they can withdraw it at any time. Unless your data protection adviser chose that basis on purpose, the clause should not read as though it did.
Side by side, the two positions look like this.
| Telling the client | Asking the client | |
|---|---|---|
| When | safeguards complete, or nothing identifying reaches the tool | the provider can still read, keep or learn from the matter |
| The rule | Code paragraph 8.6: informed decisions | Code paragraph 6.3: disclosure with the client’s consent |
| What is enough | a clear notice | the client’s consent, in no set form |
| Proof | the letter and terms you sent | a page the client signs (paragraph 7.2) |
| Where in the wording | sub-clauses 12.1 and 12.2, and option 1 of 12.3 | option 2 of 12.3, on a signed page |
| Accountants and tax advisers | a statement in the letter of engagement (PCRT) | disclosure the client has authorised (ICAEW Code R114.3(b)) |
Source: SRA Code of Conduct for Solicitors; SRA warning notice on AI, August 2026; PCRT guidance on AI; ICAEW Code of Ethics 2026.
If a file has already been pasted into a public chatbot, the question is no longer what the letter says. Our guide to that situation picks it up.
The privacy notice: your AI provider is a recipient of client data
The plainest duty on this page comes from data protection law, and AI plays no special part in it. When a controller obtains personal data from someone, UK GDPR article 13(1)(e) requires it to give that person “the recipients or categories of recipients”. A provider whose system takes in text from a client file is one of them, even when it acts only as your processor.
The ICO’s guidance on the right to be informed says recipients include anyone who processes data on your behalf. You may give names or categories, keeping categories as specific as you can. “Our IT suppliers” will not tell a client that their divorce papers may be summarised by a language model. “Providers of artificial intelligence tools that process data on our behalf” will.
Transfers, retention and a new right to complain
Since 5 February 2026, article 13(1)(f) has referred to regulations under article 45A, in wording substituted by the 2025 Data (Use and Access) Act. Where client data will be processed abroad, the notice names the regulations or the safeguard relied on, and says how the client can see it. The big assistants are mostly American. Their position under the UK Extension to the Data Privacy Framework is set out in our comparison of assistants under UK GDPR.
Article 13(2) covers how long data is kept. From 19 June 2026 it also covers the right to complain to the controller itself, under section 164A, which the same Act inserted. Retention matters because it shifts between plans, as ChatGPT’s own periods show.
| Article 13 point | What the notice gives | What it means once AI is in use |
|---|---|---|
| 13(1)(e) recipients | the recipients, or their categories | the AI provider, or a specific category |
| 13(1)(f) transfers | the regulations or safeguard relied on (since 5 February 2026) | needed where client data is processed abroad |
| 13(2) retention | how long data is kept | check the plan: periods differ |
| 13(2)(ca) complaints | the right to complain to the controller (from 19 June 2026) | a general duty, not specific to AI |
| 13(2)(c) consent | the right to withdraw consent at any time | only if consent is your lawful basis |
Source: UK GDPR article 13, as in force on 24 September 2026; ICO, the right to be informed.
None of this has to sit in the engagement letter itself. The letter can simply point to the notice.
Accountants and tax advisers: PCRT and the ICAEW terms of business
For accountants, the written expectation is sharper than anything the SRA has put out. The seven bodies behind Professional Conduct in Relation to Taxation, ICAEW among them, issued topical guidance on AI on 19 January 2026. Under integrity, paragraph 1.3 says a suitable statement in the letter of engagement can support transparency with the client. Its example is a statement that software with AI features may be used.
The guidance also reaches past the letter. Members are asked to consider telling the client about actual use of AI when the work is handed over. Where AI is fundamental to the work, they are asked to consider telling the client directly before starting. The reasoning is PCRT paragraph 2.4: disclosure keeps a member from misleading a client by omission.
Confidentiality under PCRT and the ICAEW Code
On confidentiality the guidance does not hedge. Paragraph 4.2 says that putting client data into publicly available AI tools is likely to breach confidentiality unless the client has consented. Paragraph 4.4 wants anything entered into such a model to be generic enough that the client cannot be identified. The risk table beside it warns that a client may still be recognised from associated details, such as an unusual service they are known for.
| PCRT guidance on AI | What it asks of members |
|---|---|
| paragraphs 1.2 and 1.3 | a statement in the letter of engagement that AI may be used |
| paragraphs 1.2 and 1.3 | consider disclosing actual use at delivery, and telling the client first where AI is fundamental |
| PCRT 2.4 | do not mislead a client by omission |
| paragraph 4.1 | proper and specific authority from clients |
| paragraph 4.2 | no client data in public AI tools without the client’s consent |
| paragraph 4.4 and its risk table | generic input only; a client can be recognised from associated details |
Source: PCRT bodies, topical guidance on the ethical use of AI tools, 19 January 2026.
The ICAEW Code of Ethics 2026, which applies from 1 July 2026, frames the same duty. R114.3(b) permits disclosure that the client has authorised. R114.1(d) makes you responsible for reasonable steps so that the people you manage keep your confidences. ICAEW’s July 2026 regulatory news carried that into AI, and our page for accountants sets out what it means for a practice.
ICAEW’s March 2026 template, and what we could not read
ICAEW’s engagement letter helpsheet had a full review on 10 March 2026, and the example terms of business in its Part 4 now refer to AI. ICAEW’s own summary says the new guidance covers three points. The first is whether AI or other software tools will be used to deliver the service. The second is their limitations and effect on outputs. The third is who is responsible for data protection, confidentiality and due diligence on technology providers.
That wording sits behind the member login. We have not read it, so nothing below quotes or copies it. Members can start from Part 4 and use this page to check how it deals with client data. The helpsheet calls itself best practice, not a professional standard.
Payroll: when the client has to authorise the tool
One case is different in kind. Running a client’s payroll usually means handling their employees’ data on the client’s behalf, as a processor. Article 28(2) then bars you from bringing in another processor without the client’s “prior specific or general written authorisation”. Under the general form, any new or replaced provider has to be flagged in advance, which gives the client its chance to object. Payslips raise the stakes: a union deduction is special category data on the payroll.
A tool that reads payslips is another processor. A notice will not do here: the letter needs the authorisation. Article 28(4) also obliges you to pass your own data protection obligations down to the provider by contract. Which tools staff may use at all is a matter for your AI policy, and stays out of the client’s letter.
Clause 12: the AI wording for your terms of business, ready to paste
This wording is a numbered clause for the terms of business that sit behind a client care letter or a letter of engagement. Most firms in England and Wales keep their standing terms there. The SRA’s guidance on client care letters allows for that split: generic terms need not sit in the letter, and may be easier to enclose. Renumber the clause to fit your document; the square brackets are yours to fill.
The skeleton follows the three topics ICAEW says its March 2026 guidance covers: whether AI is used, what its limits are, and who answers for data protection and confidentiality. Sub-clause 12.3, on the client’s information, comes in two options. Sub-clauses 12.4 and 12.5 add what paragraph 8.6 and PCRT suggest. We have not seen ICAEW’s own wording, so none of this is taken from it.
The text of clause 12
12. Artificial intelligence
12.1 Where we use it. Some of the software we use includes artificial intelligence. We use it for [first drafts of routine letters, summaries of documents you send us, legal or tax research, and notes of meetings]. We do not use it to decide how your matter should be run or what advice to give you.
12.2 Its limits. Artificial intelligence can produce material that is inaccurate, incomplete or out of date, and can present it with confidence. Anything produced with it is reviewed by [a solicitor or a qualified member of our staff] before we rely on it or send it to you. Our responsibility for our work is the same whether or not artificial intelligence helped to prepare it.
12.3 Your information. [Option 1 or option 2, below.]
12.4 Your choice. If you would prefer us not to use artificial intelligence on your matter, or on a particular document, tell [the person handling your matter]. We will confirm in writing whether that changes our estimate of cost or timescale.
12.5 [Tax work only.] When we send you [a tax return, a computation or written tax advice] and an artificial intelligence tool played a significant part in preparing it, we will say so when we send it.
Sub-clauses 12.1 and 12.2 give paragraph 8.6 some content. The client learns what the software touches and what it never decides. The last sentence of 12.2 is there because the SRA’s notice and the PCRT guidance make the same point in nearly the same words: responsibility stays with the professional.
Sub-clause 12.4 is ours, not any regulator’s. The Law Society’s advice is that firm and client decide together, and a clause inviting the client to opt out is the plainest record that they could. The estimate sentence ties it to paragraph 8.7, because declining a tool can make a job longer. Sub-clause 12.5 applies the PCRT suggestion about disclosure at delivery; solicitors may keep it or drop it.
Sub-clause 12.3: option 1 or option 2
Choose one version of 12.3. Option 1 is for firms that replace identifying details on their own systems before a tool sees the text. Option 2 is for firms whose tool receives client information as it stands.
12.3 Your information. Before text from your file is put into an artificial intelligence tool, we remove the details that identify you or anyone else in it and put codes in their place. These include names, dates of birth, National Insurance numbers, addresses, account numbers and case references. We do this using software that runs on our own computers. We also check the text for other details that could point to a person. The list matching each code to the original detail is kept only on our systems.
12.3 Your information. We use [name of tool and plan], provided by [provider name and address]. It processes information from your file, including personal data about you and others, on our behalf under a written contract. Under that contract the provider [does not use it to train its models] and deletes it after [period]. [It may be processed in [country], relying on [UK adequacy regulations or the safeguard used]. You can ask us for a copy.]
Because this means sharing confidential information with another organisation, we will only use the tool on your matter with your agreement. You give it by signing [this letter or the enclosed form].
What option 1 commits you to
The phrase “on our own computers” carries the weight. The SRA wants client data to remain “within a secure environment”, and stripping details out after they have reached another company’s server would not meet that. The sentence about other details answers PCRT’s warning that a client can be recognised from associated details once the name has gone. That is also why the ICO declines to call such a file anonymous.
Option 1 does not take the provider off your list of recipients. What leaves the firm is still information about the client’s affairs. For the firm, which holds the codes, it remains personal data within UK GDPR article 4(1)(5). Our pseudonymisation guide walks through which details to strip from a British file, and why a page can still identify someone after that.
What option 2 needs from your contract
Each bracket answers a condition in the SRA’s warning notice. Provider and contract answer the secure environment. The training bracket answers no training unless explicitly authorised, and the deletion bracket answers no retention beyond need. If your contract will not let you fill one in truthfully, the safeguards are incomplete, and the agreement sentence carries the whole load. For PCRT members, that sentence is the proper and specific authority that paragraph 4.1 speaks of.
Check the plan before you fill in the brackets. Training and retention differ between business and consumer versions of Claude and of Copilot. And keep the agreement sentence on a page the client signs, not in terms they are merely sent.
The privacy notice line and the payroll schedule
Two more pieces of wording sit outside clause 12. One is a line for your privacy notice; the other goes in the payroll schedule of the letter.
Who we share your personal data with: [your existing list]. We also use providers of artificial intelligence software, who process personal data for us on our instructions and under contract. [Their names are listed at [web address].]
Other processors. For the payroll services in this schedule we process your employees' personal data as your processor. You give us general written authorisation to use other processors, including providers of artificial intelligence software, as long as they are bound by written terms that give the data at least the protection our terms with you do. We publish the current list at [web address] and will give you [30] days' notice of any addition or change. If you object, we will [not use that processor for your data] [or discuss with you whether the service can continue].
Most practices already publish a privacy notice with a section on who receives data. It is often adapted from a professional body template, such as the privacy notice in Part 5 of ICAEW’s helpsheet. What matters is that the category is as specific as the ICO asks, and that the notice is published before the first file goes in.
The payroll wording belongs in the payroll schedule, which in ICAEW’s helpsheet means the Part 2 J schedules, not in the general terms. It applies only where you are the processor. Article 28 sets no notice period, so the [30] days is a placeholder: pick a period you can keep.
The last sentence is the practical one. Article 28(2) gives the client a right to object, and a clause that says nothing about what follows an objection leaves room for a dispute.
Phrases to keep out of your terms of business
Some AI wording arrives in templates bought online or carried over from American precedents. It reads badly against the rules in England and Wales. Here are five phrases to leave out, and what the clause above says instead.
| Phrase to leave out | The problem | Say instead | |
|---|---|---|---|
| 1 | “Our AI tools are approved by the SRA.” | the SRA does not approve tools | describe your own practice |
| 2 | “We will never use AI without your consent.” | few firms can keep it: AI is built into email, word processing and Microsoft 365 through Copilot | describe your use, as 12.1 does; ask for agreement where option 2 needs it |
| 3 | “Your data is anonymised.” | codes you can reverse make it pseudonymised, not anonymous | say what is replaced, as option 1 does |
| 4 | “We accept no liability for errors in AI output.” | it contradicts the SRA and PCRT on responsibility | keep your responsibility, as 12.2 does |
| 5 | “Every AI output is reviewed by a partner.” | unless that is really so, a supervision promise you will break within the week | name a reviewer you can deliver, as 12.2 does |
Source: SRA warning notice on AI, August 2026; PCRT guidance on AI; our pseudonymisation guide.
The SRA’s warning notice describes an outcomes focused approach: it sets standards and leaves the method to firms. On liability, it says the use of AI “does not diminish or transfer” your responsibilities. PCRT likewise holds members responsible for their work, whatever helped produce it, and suggests treating AI output like a less experienced colleague’s work. On anonymisation, the ICO does not treat a file with reversible codes as anonymous, and our guide explains the ICO’s reasoning.
What the five have in common is that each promises something about a tool, a regulator or the future. The clause is safer describing the firm’s own practice today, because that is the one thing the firm can check.
Clients already on your terms: sending the AI notice
We found no provision that says to send a fresh letter when AI arrives. Yet the duties above do not wait for the next new instruction. Your privacy notice’s list of recipients has to be right for every client whose data now reaches a tool. And a client taken on before the change has made no choice about it.
ICAEW’s line on existing clients is practical. Its note of 13 March 2026 on the updated templates quotes a senior consultant in its Technical Advisory Services: adopting new digital tools should prompt an update to the terms agreed with the client. The same note recommends getting updated letters signed and returned, and keeping a record of what went out. Nothing in the SRA material points solicitors elsewhere.
A short covering letter does the job
For most firms, the simplest route is a one page letter to clients with open matters. It carries clause 12 as you have adopted it, the updated privacy notice, and the client’s right to decline under 12.4. Send it before data from those matters goes into the tool. Give staff a start date too, since your staff policy and the client letter must agree on when the change takes effect.
If people at the firm have already been running client work through a tool, first check what that provider has retained. That way the letter describes what actually happens, not what you mean to do next.
Keeping option 1 of sub-clause 12.3 true, with Nonimo
Option 1 only holds if the replacing happens every time, on the firm’s own machines, before anything is pasted. Nonimo is a desktop app, for Mac and for Windows, that does exactly this. A fee earner highlights the passage and presses its key. Names, dates of birth, National Insurance numbers, and a UTR or NHS number shown with its label, are swapped for tags like [PERSON_1]. The passage is then ready to paste.
The reply comes back carrying the tags, and the app restores the originals on screen for whoever reads it. The table linking each tag to its original is stored encrypted on that computer, and none of the matter’s text is sent to us. What the app does send, once a day, is a usage count with no words from your documents in it. Our security page has the technical detail.
It cannot tell that the only female partner at a Truro practice is a person anyone would recognise. That second read belongs to the fee earner.
Our page for organisations covers deployment across a practice, and the licence page sets out the terms.
Treat clause 12 as a first draft for your COLP, your compliance principal or whoever leads on data protection to adapt. It is not advice on any particular matter.
Sources
Each entry with the fact it supports.
- SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs, version in effect from 11 April 2025. sra.org.uk. Paragraph 6.3 (confidentiality unless disclosure is required or permitted by law or the client consents); 6.4(b) and 6.5(b) (informed consent, given or evidenced in writing); 7.2 (justify decisions and actions); 8.6 and 8.7 (informed decisions about how the matter is handled; information on cost); paragraphs 8.1 to 8.11 apply only to services to the public or a section of it.
- SRA, Misuse of AI: warning notice, published 17 August 2026. sra.org.uk. The two concerns (hallucinations and confidentiality); the Upper Tribunal’s observation in UK v SSHD [2026] UKUT 81 (IAC) at paragraph 21; paid and free tools alike may lack safeguards; client information only where contractual, technical and organisational safeguards are in place, no training unless explicitly authorised, no longer retention than necessary; the use of AI does not diminish or transfer professional responsibilities. The notice says nothing about telling clients that AI is used.
- SRA, Risk Outlook report: the use of artificial intelligence in the legal market, 20 November 2023. sra.org.uk. The tip to tell clients when AI will be used with their case and how it will operate; how to do it is a decision for the firm; deciding what information clients need.
- SRA, Compliance tips for solicitors regarding the use of AI and technology, updated 9 February 2026. sra.org.uk. It should always be made clear to clients where they are interfacing with AI.
- SRA, Client care letters guidance, updated 25 November 2019. sra.org.uk. Generic information such as terms of business can be enclosed separately from the letter.
- The Law Society, Generative AI: the essentials, dated 1 October 2025 in the version read on 24 September 2026. lawsociety.org.uk. The SRA has no specific guidance on generative AI related to use or disclosure of use for client care; advisable that firm and client decide whether and how the tools are used; communicate to clients when and how AI is used, where appropriate.
- PCRT bodies, topical guidance on the application of PCRT to the ethical use of artificial intelligence tools, 19 January 2026, published by ICAEW. icaew.com. Paragraphs 1.2 and 1.3 (transparency; a statement in the engagement letter; disclosure of actual use at delivery; telling the client first where AI is fundamental; PCRT 2.4); 4.1, 4.2 and 4.4 (proper and specific authority; public AI tools and consent; generic input) and the risk table on identification from associated details.
- ICAEW, Engagement letters and privacy notices helpsheet, updated 10 March 2026. icaew.com. Full review; Part 4 terms of business section on AI updated; best practice guidance, not a professional standard. The sample wording is available to members only and was not read for this guide.
- ICAEW, Engagement letter updates: key changes and guidance for firms, 13 March 2026. icaew.com. The three points the AI guidance covers; new digital tools should prompt an update to terms agreed with the client; ask clients to sign and return updated letters.
- ICAEW Code of Ethics 2026, applying from 1 July 2026. icaew.com, PDF. R114.1(d) (reasonable steps so that personnel comply with the duty of confidentiality) and R114.3(b) (disclosure authorised by the client).
- ICAEW, Protecting client confidentiality: internal controls and the ICAEW Code of Ethics, 28 July 2026. icaew.com. Due diligence, contractual protections and internal approval before confidential information goes into AI systems; knowing where data is stored and whether it may be used to train models.
- UK GDPR, articles 4(1)(5), 13 and 28, as in force on 24 September 2026. legislation.gov.uk, article 13 and article 28. Pseudonymisation defined; recipients or categories of recipients (13(1)(e)); transfers (13(1)(f)); withdrawal of consent (13(2)(c)); complaint to the controller under section 164A of the Data Protection Act 2018, inserted from 19 June 2026 (13(2)(ca)); prior specific or general written authorisation for another processor (28(2)) and obligations passed down (28(4)).
- ICO, What privacy information should we provide? ico.org.uk. Recipients include anyone processing data on your behalf; names or categories; be as specific as possible with categories.
- Nonimo, security page and release 0.2.8. nonimo.ai/security. Local processing on Mac and Windows, encrypted mapping on the computer, daily usage count without text; the screenshots were taken with release 0.2.8 for Mac.
Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.
Common questions
Is a solicitor obliged to tell a client that the firm uses AI?
Not as such. The SRA Code of Conduct has no rule on it, and the Law Society notes that the SRA has issued no specific guidance on disclosure in client care. Paragraph 8.6 still expects clients to make informed decisions about how their matter is handled. Paragraph 6.3 may also call for consent before client information reaches a tool. An engagement letter AI clause deals with both early, and Nonimo can help keep its sub-clause on client data true.
Is a line in our terms of business enough to count as consent?
It is thin evidence. Paragraph 6.3 of the SRA Code prescribes no form of consent, but paragraph 7.2 expects you to justify what you did. A sentence lost in standard terms does not show that the client understood it. For tax work, the PCRT guidance speaks of proper and specific authority from clients. Give the AI section its own heading in the letter itself, and have the client sign that page.
Does the AI provider have to be named in our privacy notice?
Not necessarily: the ICO's guidance lets you choose. You can name each organisation, or give the category it falls in, as specific as you can make it. A line such as providers of artificial intelligence software that process data for us on our instructions meets that. A generic reference to IT suppliers does not. Listing the names on a web page you keep current also helps when clients or insurers ask who sees their data.
Does PCRT expect tax clients to be told about AI?
It recommends it rather than requiring it. The seven PCRT bodies issued topical guidance on AI on 19 January 2026. It says a statement in the letter of engagement, saying that AI tools may be used, can support transparency. It also asks members to consider two further steps: disclosing actual use when the work is delivered, and telling the client beforehand where AI is fundamental to what they will receive.
We run payroll for clients. Do they have to authorise the AI tool?
Yes, where you handle their employees' data on their behalf. Under UK GDPR article 28(2), a processor needs the controller's written permission in advance before bringing in another processor. That permission can name the provider or be given in general terms. Under a general one, every new or replaced provider must be flagged first, so the client can object. A tool that reads payslips is another processor, so the payroll letter needs the authorisation, not just a notice.
Do clients already on our terms need a new letter?
In ICAEW's view, yes. Its March 2026 note on the updated templates says that adopting new digital tools should prompt an update to the terms agreed with clients, signed and returned. The UK GDPR adds a practical reason: your privacy notice must identify who receives client data, and a new AI provider is one of them. A single page to clients with open matters, sent before their files go into the tool, usually covers both.
May a client opt out of AI on their matter?
Yes, and the clause should tell them so. If you rely on consent under paragraph 6.3 of the SRA Code, or on authorisation under R114.3 of the ICAEW Code, the client is free to withhold it. Even where you do not, a client may still ask. It is better to have agreed in advance what that does to cost and timing. Sub-clause 12.4 of the wording on this page gives clients that option in writing.
Is there an SRA, Law Society or ICAEW model clause?
ICAEW has something close. Since its review of 10 March 2026, the example terms of business in its engagement letter helpsheet refer to AI. That wording is for members behind a login, and we have not read it. We found nothing from the SRA or the Law Society on 24 September 2026. ICAEW calls its helpsheet best practice, not a professional standard, so adapt whatever you start from.
How does Nonimo relate to sub-clause 12.3?
Option 1 of 12.3 promises that identifying details are swapped for codes on the firm's own machines before a tool sees them. Nonimo is desktop software for Mac and Windows that makes that swap when a fee earner presses its key, and puts the details back when the reply is read. The clause does not mention it. It prevents nothing pasted without the key, and context that identifies someone still needs a person's eye.