For barristers’ chambers
Your members are using AI. Your policy assumes they read it.
The BSB’s guidance (May 2026) expects every member and every barrister who manages chambers (rC89) to be able to demonstrate a reasonably active and informed approach to AI risk, with records to show for it. A policy your members haven’t read, while some use AI anyway, is documented awareness of an unmanaged risk. We fix that: tool register, member playbooks, training with records, and the evidence pack behind it. Fifteen working days. Fixed fee.
The standard you already face
Why your AI Policy is not enough.
Most chambers responded to AI the same way: a policy was drafted, circulated, and filed. The May 2026 guidance quietly moved the bar from having a document to evidencing an approach.
A demonstrable approach and proper AI governance is expected
Every member should be able to show an active, informed approach to technology risk, proportionate to the harm (Core Duty 10). Barristers with management responsibility must additionally ensure chambers itself is administered competently. The guidance addresses chambers-level AI policies, shared systems, and records through rC87/rC89 directly.
Core Duty 10 · rC87/rC89Policy circulated without evidence of its implementation and compliance
Members are self-employed so Policy-Practice decoupling is a real challenge. Tools arrive on personal accounts and inside software chambers already licenses. The policy was circulated but compliance is not effectively governed.
Shadow AI · unread policyThe courts are already acting
The Hamid jurisdiction has been exercised over AI-generated citations (Ayinde), and Munir holds that putting confidential material into an uncontrolled AI tool breaches confidentiality and waives privilege. The question after an incident won't be “did chambers have a policy”, it will be “what did chambers actually do.”
Ayinde [2025] · Munir [2026]What you’re already asserting
These questions are already being answered on your behalf. AI is what makes the answers hard to stand behind.
To panel clients, to professional clients’ due-diligence questionnaires, to Bar Mutual, and to your own management, chambers already represents that its risks are managed.
Management
What has chambers done about AI risk since the BSB guidance?
“We have a policy” was the answer that worked last year. It is not an account of what members actually do.
Panel client · due diligence
Does chambers maintain a register of AI tools used on instructed matters, and controls over confidential material?
Professional clients under their own SRA supervision duties are starting to ask. What would you send them today?
Chambers-level systems
Where AI systems are shared across chambers, can members view or infer another member's client information?
The guidance raises this scenario explicitly, including where members of the same set act for opposing parties.
Confidentiality · privilege
Has chambers ever asked whether client-confidential or privileged material is going into tools it doesn't control?
Chambers can't audit members' personal accounts, but after Munir, never having asked is the worst version of “we don't know.”
Competence · CPD
Can chambers evidence that members are competent in the tools they've adopted?
How is this managed?
Phase one
Chambers AI Exposure Review
Know exactly where AI lives across your members and staff, what chambers is accountable for, where the gaps are against the guidance, and what closing them will involve. Fifteen working days. Fixed fee. You keep the artefacts whether or not you go further.
AI footprint map
The enquiry, evidenced
Full inventory of the systems chambers controls (shared platforms, staff and pupil use, AI features inside licensed software etc) plus a documented member enquiry: a short, voluntary survey of what members use on instructed work, with the responses recorded. Chambers can't mandate members' tools; it can prove it asked.
AI tools register
Your single source of truth
The operational inventory of every AI system in use, with confidentiality and data-processing assessments against rC86.3, and an owner against each. The document your policy refers to and the approved and/or recommended list members actually consult.
Gap list against the BSB guidance
What's missing, and what it exposes
Records, training evidence, shared-system configuration, audit logs. Mapped clause-by-clause to the May 2026 guidance and prioritised, with the exposure named plainly.
Costed plan for closing the gaps
Makes the next decision concrete
A fixed-price, evidence-based scope for the governance build. No open-ended professional fees.
- Duration
- 15 working days
- Price
- Fixed, scaled to chambers size
- Member time
- One short survey, one session
- If you proceed
- Fee credited against the build
Phase two · optional
Then: the build, and the training members will thank you for.
Phase one tells you what’s actually there. Phase two turns the policy into a AI governance practice aligned with ISO/IEC 42001, the framework the BSB guidance itself cites, without the weight or cost of a certification programme.
AI Governance Build
The register, records and controls that let a chambers director answer the committee, a panel client, or the BSB; and that make the existing policy true.
- Policy refreshed against the May 2026 guidance and against real usage
- AI Risk register with risk treatment plan and controls implementation
- Approved-tools register with confidentiality assessments (rC86.3)
- Record-keeping layer: audit logs, prompt retention and deletion procedures (rC87.2)
- Shared-system configuration review, including information barriers between members
- Evidence pack, presented to the management
Members’ training
Practical and task-level, not a compliance lecture because the risk is a member pasting instructions into a public tool at ten at night, and the fix is showing them a faster, safe way to do the same work.
- Task-level playbooks: research, first drafts, summarising safely
- Verification and the duty not to mislead the court (Ayinde)
- Confidentiality, privilege, and what never leaves chambers (Munir)
- What the approved and/or recommended tools are, and how to get value from them
- Attendance records chambers can evidence
Honest fit
Who this is for, and who it isn’t.
A good fit if
- You’re a professionally managed set with a chambers director, CEO, or senior clerk owning practice risk
- An AI policy exists, and you cannot tell which members read and comply with it
- You know that members are using AI.
- Nobody has formally asked who uses what, or written the answers down
- The management committee, a panel client, or an incident is about to ask the question
Not a good fit if
- You have a risk and compliance function already running AI risk register and risk treatment, AI Tool register, and audits
- You’ve already mapped member AI use and can evidence it
- You want ISO 42001 certification now — that’s a different engagement
- You want another policy document with nothing behind it
Who you’d be working with
We don’t sell paperwork.
A policy that claims a control chambers doesn’t run is worse than none: it’s a written standard you can be measured against, sitting under the director’s signature. Everything we build is evidenced, and defensible because demonstrability, not documentation, is the standard the guidance sets.

Certified
ISO/IEC 42001 Lead Implementer, the AI Governance standard the BSB guidance cites as its reference framework
Standards
Committee member, BSI & ISO technical committees
Delivery
Regulated, sensitive-data environments, including legal services
Questions
What chambers directors ask us.
Why is AI governance a chambers problem?
rC89: every barrister with management responsibility, the head of chambers, the management committee carries a personal duty to ensure chambers is administered competently, and the May 2026 guidance addresses chambers-level AI policies, shared systems, and records through exactly that rule. In practice, the committee has delegated the discharge of that duty to its director or senior clerk. This engagement is how it gets discharged with evidence that it was.
We already have an AI policy.
Then you're where most chambers are and that's exactly the position this addresses. The harder question is whether the policy matches what members actually do. A policy nobody has read, while members use AI anyway, doesn't reduce the exposure: it documents that the risk was identified and then left unmanaged. The guidance asks chambers to demonstrate a practice, and a policy describes what should happen, not what does.
Our members are self-employed. Chambers can't police them.
Members remain individually responsible under the Handbook, and chambers has no authority over the tools they choose. But limited authority is exactly why the enquiry is the whole game: chambers can't control what members use, but it can prove it asked, recorded the answers, provided approved and/or recommended vetted options, and trained anyone who showed up. For a set of self-employed practitioners, that is what a demonstrable approach looks like and it protects chambers, and its director, regardless of the members who don't engage.
The BSB document is only guidance. Why act on it?
The guidance itself is non-mandatory, but it interprets duties that aren't: Core Duty 10, rC86 on outsourcing, rC87/rC89 on managing your practice and chambers, Core Duty 6 on confidentiality. It is also the yardstick a court, the BSB, or a panel client will reach for after an incident; and Ayinde and Munir show that incidents are already reaching the courts. Guidance defines what “reasonable” looks like, which is precisely why acting after it exists is cheap and explaining inaction after an incident is not.
Will members actually engage with this?
Members may not have engaged with your AI policy because it offered them nothing. This is designed the other way round: members get a governed, best practiced-driven way to use AI that makes them faster on research, first drafts, and summarising, with clear lines on what never leaves chambers. In our experience the session sells itself once the first silk asks a practical question. The director gets the attendance record either way.
Does this make us ISO 42001 certified?
No. This is a lightweight, ISO/IEC 42001-aligned governance baseline, the standard the BSB guidance itself points to without the weight or cost of a certification programme. It's the right foundation if chambers ever pursues certification, but the point of it is to let you answer the committee, a client, or the regulator now.
We handle this in-house.
Some sets can, and if your practice management team is actively maintaining a tool register, AI risk register and its associated risk treatment plan, and audit logs, you don't need us. Where we earn our place is doing the enquiry and the build quickly, in the form the guidance expects, without consuming the director's year. We bring ISO 42001 grounding the guidance references.
Before the committee asks
Has anyone actually asked your members what they’re using?
A 20-minute call. We’ll walk through what the May 2026 guidance expects a chambers to be able to demonstrate — and you’ll leave knowing whether you could evidence it. Whether or not you work with us.
Book a 20-minute call