A shadow AI audit is a structured count of the AI tools your people already use, what data goes into them, and which ones the firm will approve, replace or remove. You can run a first pass in two hours with a spreadsheet and three questions, and the output - a dated tools register - is a practical way to hold the kind of evidence of control the SRA's warning notice on the misuse of AI looks for. The notice sets governance expectations; it does not prescribe this template, and what follows is one operator's method, not a regulator's form.
This is Part 2 of the SRA implementation-kit series: named owner, shadow AI audit, one-page policy, verification rule, insurer and client conversations. The one-page policy template assumed you had done this audit first, because its approved-tools clause points at the register you are about to build. This post is the audit.
Why this is the urgent part
The SRA's warning notice, published 17 August 2026, does not ban AI and does not prescribe tools. It expects a firm to demonstrate control: effective governance under paragraph 2.1 of the Code of Conduct for Firms, competent and properly supervised work under paragraphs 3.2 and 3.5 of the Code of Conduct for Solicitors, and confidentiality under paragraph 6.3 of both Codes. You cannot demonstrate control over usage you have not counted.
The same logic applies in the US. The ABA's Formal Opinion 512 (July 2024) tells lawyers their existing duties - competence, confidentiality, supervision - apply unchanged to generative AI. Different regulator, same shape: the duty sits on the firm, and "we did not know our people were using it" is not a defence, it is the finding.
Meanwhile the usage is already there. Clio's 2025 Legal Trends Report - a survey of 1,702 legal professionals in the United States, including support staff, published in 2025 and cited in Clio's own guide to shadow IT and AI - reports AI use at 79% and firms with no AI use policy at 44%. That is a US sample, not a UK census, so it should not be read across to your firm. The safer statement needs no statistics at all: if your firm has no register, nobody can say how many people are using AI, into which tools, or with what data.
In-house teams are not exempt from any of this - the pattern just runs in the other direction. There, the shadow AI problem is the business pasting contracts, disputes and HR material into tools legal never approved. The same two hours works; the owner is the GC or head of legal ops, and the population being audited is the whole company, not the legal team.
The two hours, minute by minute
Book one session with the named AI owner and whoever knows the firm's IT. A spreadsheet open. No questionnaires longer than three questions, no procurement process, no consultants - this pass is about visibility, not perfection.
0:00 to 0:20 - Ask. Send every fee earner three questions, answerable in two minutes, no blame attached: Which AI tools or AI features have you used for work in the last month? What did you use them for? Did any client or matter information go in? Say explicitly that honest answers now carry no discipline - concealment later does. The answers will be incomplete. That is fine. They give you the self-reported layer and, just as important, they tell the firm the audit exists.
0:20 to 0:50 - Sweep. Self-reporting misses everything people have stopped noticing. Check the places AI hides:
- Browser extensions on firm machines (summarisers, grammar tools, sidebar assistants).
- Meeting tools: transcription and AI-summary features in your video platform, switched on by default in many products.
- PDF and document tools with summarise or explain buttons.
- Expense claims and card statements for personal AI subscriptions.
- SSO and app logs if you have them; connected apps in your email and document platforms.
- Personal accounts used on firm devices - the hardest layer, which is why the ask matters as much as the sweep.
0:50 to 1:20 - Triage. Take the combined list and mark every tool approve, replace or remove. Approve: firm-controlled accounts with data terms you have actually read, covering confidentiality and a commitment not to train on your inputs. Replace: the workflow is useful but the tool is too opaque - find a firm-controlled equivalent. Remove: personal accounts for client work, free tools with unread data terms, anything with sweeping permissions into your email or files. Do not relitigate each tool for a week. First pass, best judgement, move.
1:20 to 2:00 - Write the register. One row per tool: tool name, account type (firm or personal), who uses it, what it is approved for, which data terms you reviewed and when, review date. Add the never-paste list at the top of the same sheet, then circulate it to the firm the same day. A register that exists and is slightly wrong beats a perfect one that ships in November.
The never-paste list
Unless a tool is on the register with data terms that cover confidentiality and no training on inputs, none of this goes into any AI tool, ever:
- Client or matter identity, or facts that make them identifiable
- Client documents, data or extracts
- Anything privileged
- Anything confidential to a third party - the other side, experts, suppliers
- For in-house teams: board material, unpublished financials, employee and dispute data
If you would not put it in an unsecured email, it does not go into an unregistered tool.
What done looks like
At the end of the two hours you hold four things: a dated register, a never-paste list the firm has seen, a triage decision for every tool you found, and a review date in the diary - quarterly is right for most small firms, because tools and features change faster than policies. That set is what you show an insurer, a client doing due diligence, or the SRA if it comes asking. It is also the register your one-page AI policy points to, so the policy stops being decoration.
One honest limit: a two-hour pass finds most of it, not all of it. Shadow AI is a habit, not an event, so the audit repeats. The point of the first pass is not completeness - it is moving the firm from no visibility to documented visibility, which is a different regulatory posture entirely.
Frequently asked questions
What is shadow AI in a law firm? AI tools or AI features used for firm work without formal approval or oversight - chat tools, document summarisers, browser extensions, meeting transcription - whether or not anyone thinks of them as "AI". The defining feature is that the firm cannot say what data goes in or where it is stored.
How often should a small firm run the audit? Quarterly for the register review, with a full re-run once a year or after any major tool adoption. AI features appear inside tools the firm already owns without announcement, so the sweep step matters as much as the ask step on re-runs.
Does this apply to in-house legal teams? Yes, with a wider lens. The risk there is the wider business feeding contracts and disputes into unapproved tools. The GC or legal ops lead owns the register, and the audit population is every department that sends legal its material.
What if the audit finds client data already went into an unapproved tool? Record what, which tool and roughly when; check that tool's data terms and deletion options now; and fold it into the breach and raising-a-problem clauses of your policy. In the UK, if confidential client material is involved, read the SRA warning notice's expectations on governance and confidentiality and take advice on your specific position. The mistake is recoverable; concealing it is not.
---
This series is what ClickoAI implements with firms: owner, audit, policy, verification, insurer and client conversations. If you want the audit run with you rather than by you, the fit check takes three minutes. Our answers library covers the common questions, and Margo - our matter-aware drafting assistant, in controlled development and not generally available - is being built around the same governance questions this series covers.