CattleGrid

CISO / Head of InfoSec

CISO / Head of InfoSec

The stake

The SRA Standards and Regulations 2019 engage the moment AI tools touch client work. The Code of Conduct for Solicitors sets out Principle 2 (integrity), Principle 7 (client best interests), the duty of competence, client confidentiality, and proper supervision — all of them live obligations, not aspirational ones. The Code of Conduct for Firms adds firm-level governance duties and places COLP accountability squarely on the shoulders of one named individual when third-party technology arrangements go wrong. The SRA has issued its own guidance on generative AI use in practice, and has published warning notices specifically on AI and data governance — this is not a regulator waiting to legislate before it acts.

The underlying exposure is not abstract. 71% of UK employees are using AI tools their employer hasn't sanctioned, and 51% do so weekly (Microsoft/Censuswide UK Shadow AI Survey, October 2025). In a legal practice, that behaviour has a specific and more serious shape: a fee earner uploading a client contract, a case file, or correspondence to a consumer AI tool to summarise or draft from — at which point client confidentiality and legal professional privilege, protections that exist to protect the client, have been extended to a third party the firm never assessed and the client never consented to.

What CattleGrid actually does

It applies your privilege and confidentiality boundary through configurable rules, checked before anything goes live. CattleGrid's inspection engine runs UK-specific pattern templates — National Insurance numbers, addresses, dates of birth, financial identifiers — alongside a custom rule builder your firm can use to flag client names, matter references, or content marked privileged or confidential. Test Bench lets you paste representative case content and see exactly what a rule would catch, and what it would redact, before it's switched on for live traffic.

Document uploads are inspected, not just prompts. Contracts, case bundles, and correspondence are exactly what fee earners upload to AI tools to summarise — and it is now a governed data path, not a blind spot. CattleGrid extracts and inspects text from PDF, Word (.doc/.docx), Excel spreadsheets, OpenDocument Text, and RTF files against the same policy engine as pasted prompts, then discards the file. Nothing is retained.

The audit trail is the governance evidence a COLP needs. Every inspection decision — what was sent, what was blocked, what was redacted, when, and under which rule — is written to a cryptographically verifiable record, tamper-evident by design. That is precisely the kind of controlled, audited AI use the SRA's own guidance points firms towards being able to demonstrate, and it exists automatically, without depending on a fee earner remembering to log anything.

Deployment does not disrupt fee-earner workflows. CattleGrid sits inline between your applications and the AI providers they call — OpenAI, Anthropic, Google Gemini, and Mistral, plus any provider reachable through a standard OpenAI-compatible API. The only change is the web address requests are sent to. Nothing about how a fee earner works day to day needs to change for the governance layer to be in place underneath it.

What this looks like once it's running

A firm running CattleGrid can show, rather than assert, that AI use is supervised: a rule configuration a COLP can point to, an audit trail that stands as governance evidence if the SRA or a client ever asks, and a document-handling boundary that keeps privileged material inside the firm's control rather than inside a consumer AI provider's. That is a materially stronger position heading into a regulatory enquiry, a client's own due-diligence request, or a professional indemnity conversation than "we trust our staff to use good judgement."

What CattleGrid does not do

CattleGrid does not conduct client care letter reviews or provide SRA compliance sign-off, and it does not assess the suitability of AI-generated legal outputs — that judgement remains the fee earner's and the firm's. It does not draft AI governance policies for law firms beyond an Acceptable Use Policy template, which is a starting point, not a substitute for your own policy work. It does not provide advice on professional indemnity implications of AI use. What it provides is the technical control and the evidence trail that make your own governance decisions defensible — not the decisions themselves.

Pricing →