Your AI provider can waive your clients' privilege.
The Upper Tribunal confirmed it. Every US-parented AI tool, ChatGPT, Copilot, Gemini, Claude, is in the habit of keeping a copy of what you type. A US court can compel them to produce your client data. That is a privilege waiver your firm cannot undo. Hush is built the opposite way: we do not save your data, we process it, then delete it, so there is nothing left for any court to compel.
Request Governance Evaluation →A Microsoft lawyer told the French Senate, under oath, he could not guarantee your data would never be handed to US authorities. For us that question does not arise: we keep nothing you type, so there is nothing to hand over. We are a UK company on privately owned hardware, with no US parent. Read what was said.
Public AI use can waive privilege.
"Uploading confidential documents into an open-source AI tool, such as ChatGPT, is to place that information into the public domain, resulting in a breach of client confidentiality and a waiver of legal professional privilege."
This is a serious and developing legal risk, not a hypothetical. Privilege, once waived, can be very hard to restore.
Your firm is almost certainly exposed.
of UK fee earners use unapproved AI for client work
of paralegals admit to using ChatGPT on client matters
of firm leaders believe they face "zero risk"
Source: Censuswide survey of 200 UK fee earners and 100 legal leaders, commissioned by Access Legal (May 2026). This is not a discipline problem: fee earners reach for whatever clears the 11pm drafting pile, and the tools they were given keep everything. Give them one that keeps nothing and the exposure ends where it started.
"Approved" AI tools are not structurally safe for privilege.
Microsoft Copilot, ChatGPT Enterprise, and Google Gemini are marketed as secure. They are all US-incorporated entities in the habit of keeping a copy of what you type. A contractual promise of UK data residency cannot override a US federal court order.
"Approved" US AI Providers
- US parent entity, subject to CLOUD Act
- US court can compel data production
- Privilege protection is contractual only
- Data processed on rented cloud infrastructure
- Sub-processors in the data chain
Hush AI
- UK company, no US parent or subsidiary
- Outside CLOUD Act jurisdiction entirely
- Privilege protection is architectural
- Data processed on privately owned hardware
- No third-party AI sub-processors, no training on your data
AI that saves fee earners hours, without compromising privilege.
Every request processed on privately owned hardware, never used for training. Full audit trail for SRA compliance.
Contract review & summarisation
Summarise lengthy contracts, identify key clauses, flag unusual terms. Privileged analysis stays privileged.
Legal research & drafting
Draft correspondence, research memos, and skeleton arguments from instructions. Ready for partner review.
Client correspondence
Generate letters, emails, and advice notes from brief context. Professional, accurate, privilege-protected.
Document comparison
Compare contract versions, identify amendments, track changes between drafts without uploading to cloud services.
Case summaries
Condense lengthy case bundles into structured summaries. Chronologies, key issues, party positions.
SRA-compliant audit trail
Every request logged with timestamp and metadata. Exportable records for regulatory compliance and client billing transparency.
Built for SRA-regulated practice.
Every feature designed with the SRA Code of Conduct in mind.
Privilege Protected
No US jurisdiction. No third-party AI sub-processors. No mechanism for foreign court orders.
Your Content, Your Control
API prompts processed and discarded. Chat history stays encrypted on your own device, never on any server anywhere, until you delete it. Never used for training.
Full Audit Trail
Every request logged. Exportable for SRA, client queries, and billing transparency.
Nothing to Compel
We don't keep your client data, we process it, then delete it. A UK company on privately owned hardware, no US parent, so there is nothing for any court, here or abroad, to demand.
ICO Registered
Data controller registered. DPA and DPIA available for your compliance team.
Independently Verifiable
Two-week governance evaluation. Your DPO tests our claims. We hide nothing.
Two weeks for your compliance team to verify everything.
Not a free trial. A governance evaluation. Your DPO independently verifies our privacy claims.
Architecture briefing
We share our full data flow diagram. Your DPO reviews jurisdiction and sub-processors. No NDAs needed, we have nothing to hide.
Two-week evaluation
Your fee earners use Hush AI on real work. Your compliance team monitors. We provide full audit logs throughout.
Compliance review
Test our zero-retention claim: send data, then ask us to produce it. We cannot. Export the full audit trail for your records.
Decision
Your compliance team is satisfied, or they are not. No lock-in. No penalty. The evidence speaks.
Protect your clients' privilege. Architecturally.
Not by contract. Not by policy. By the physical absence of any mechanism for foreign data access.
Request Governance Evaluation →Or email [email protected] directly.
AI and legal professional privilege · An AI-use policy for law firms · Is your AI provider in the habit of keeping a copy of what you type?
Frequently asked questions
Can law firms use AI without risking client confidentiality or privilege?
The risk with consumer AI is that confidential or privileged material passes to a third party that can be compelled to disclose it. Hush AI drafts correspondence, research memos and file notes on privately owned hardware, outside US CLOUD Act jurisdiction, never used for training, so confidential material stays on privately owned infrastructure under UK law, with an audit trail you own.
Is Hush AI within reach of the US CLOUD Act?
No. Hush is a UK-owned company with no US parent and no US cloud sub-processor for your content, so there is no US entity that could be compelled under the CLOUD Act to disclose client data.
Does Hush AI train on client data?
No. Client content is never used to train models and is stored encrypted locally on your own device until you delete it. A fee-earner reviews every output.
Do you have law firm case studies or reference clients?
We will be straight with you: we are an early-stage UK company, and you would be among our first firms. So rather than showing you another firm's numbers, the free pilot generates your evidence, a written report built from your own audit-log export that is yours to keep whether or not you continue. The company itself is verifiable today at Companies House (17278687) and the ICO (ZC126901).