Why a solicitor asked me whether there is an offline AI
Tuesday, 7.20pm, a two-partner firm in Leeds. A trainee solicitor is alone in the office with a 312-page disclosure bundle and a client meeting at 9am; the partner wants a chronology and a one-page summary of each witness statement. She has used a free chatbot on her phone for "help with wording" for months, so she pastes the first statement in and asks for a summary.
It is good. Then she reads the statement again — the client's name, the neighbour's name, the medical detail in paragraph 14 — and puts the phone face down on the desk. The message she sent the partner that night was one line: "Is there an offline AI? Something that doesn't send this anywhere?" The partner forwarded it to me the next morning with one word added. "Well?"
The honest answer is yes. The useful answer is longer, because "offline AI" means three different things depending on whether you are one person on a train or a regulated firm with nine staff. This article is the longer answer.
How common the quiet paste has become
Almost universal, and mostly unspoken. Clio's UK & Ireland Legal Insights Report 2026, which surveyed 513 legal professionals and 500 members of the public, found that 89% of legal professionals now use AI tools and 70% adopted them in the past year. On the other side of the desk, 79% of the public want to be told when AI is involved in their matter; 7% recall their lawyer mentioning it. Some 17% of firms had no AI policy at all.
The regulator has noticed. The SRA told the Law Gazette it received 42 reports of potential AI misuse between July 2025 and July 2026, covering invented citations and client information going into AI tools. Its warning notice on the misuse of AI, published on 17 August 2026, puts the rule in one sentence: "Client information should only be entered into AI systems where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality." It adds that "both free to use and paid for AI systems may pose risks", and that information entered "may be stored, retained or used to improve the tool". That is not hypothetical: ChatGPT's free and Plus tiers train on conversations by default unless a setting called "Improve the model for everyone" is switched off. The trainee had never seen the setting.
What the tribunal said, and the word it got slightly wrong
In UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), handed down in November 2025, an immigration adviser had uploaded Home Office decision letters into ChatGPT to summarise them for clients. The Upper Tribunal observed that "uploading confidential documents into an open source AI tool such as ChatGPT is to place this information on the public domain" and to waive legal privilege. The SRA's notice repeats the point: privilege, once waived, "may be permanently waived and unable to be recovered".
One quibble, and it matters for the rest of this article. ChatGPT is not open source; it is a closed product that happens to be public. The models that actually run offline are usually open-weight, meaning the maker has published the model file so anyone can run it on their own hardware. The tribunal reached the right conclusion with the wrong adjective. Public is the problem, and open is a large part of the solution.
The three questions inside the one
When a practitioner asks whether there is an offline AI, they are asking three things, and the app reviews online only answer the first.
- Does it exist? Yes, on a phone, a laptop and an office machine. Section two.
- Is it good enough to be worth the bother? For most document work, yes, with limits. Also section two.
- Can a nine-person firm use it without acquiring an IT department? Yes, and that is not a download. Section three.
