Tech News : Law Firm Restricts AI Access After Surge in Usage

It’s been reported that international law firm Hill Dickinson has introduced new restrictions on the use of artificial intelligence (AI) tools following a sharp increase in staff engagement with the technology.

What Happened?

The development was first reported by the BBC after it allegedly obtained an internal email from Hill Dickinson’s senior management. The email reportedly revealed that the firm had identified a “significant increase in usage” of AI tools by employees, prompting a review of its policies and subsequent restrictions on access. It seems that the move may have been prompted by growing industry concerns over data security, compliance, and the ethical implications of AI in legal work.

The Email

According to reports about the data cited in the email, in just one week between January and February 2024, Hill Dickinson staff recorded over 32,000 interactions with the AI chatbot ChatGPT, 3,000 with the Chinese AI service DeepSeek, and nearly 50,000 with the writing assistance tool Grammarly. While these figures may illustrate widespread engagement, they don’t clarify how many individuals were actually using the tools or how frequently they returned, as each use could generate multiple interactions.

Limited General Access To The Tools

In response, it’s been reported that the firm has now limited general access to such tools, introducing a request-based approval system to monitor and regulate AI usage more closely. It seems that the internal communication may have highlighted that much of the AI use may not have been in line with the firm’s AI policy, thereby perhaps necessitating stricter oversight.

Why Impose These Restrictions?

It seems that the firm’s AI policy (implemented back in September 2024) actually prohibits employees from uploading client information to AI platforms and requires them to verify the accuracy of AI-generated content. The recent spike in AI engagement may have, therefore, raised concerns that these guidelines were not being strictly followed, potentially exposing the firm to regulatory and security risks.

A spokesperson for Hill Dickinson has been quoted clarifying its stance, stating: “Like many law firms, we are aiming to positively embrace the use of AI tools to enhance our capabilities while always ensuring safe and proper use by our people and for our clients.”

Not An Outright Ban

The firm maintains that it is not banning AI outright but ensuring its application is controlled and compliant. It has already received and approved some individual AI usage requests under the new system.

Broader Industry Implications

The legal profession does appear to be facing a bit of an increasing dilemma over AI adoption. For example, while AI has the potential to streamline tasks such as legal research, contract analysis, and document drafting, it also presents risks related to data security, accuracy, and ethical considerations.

Enter The ICO

Now the UK’s Information Commissioner’s Office (ICO) has weighed in on the debate, warning against excessive restrictions. A spokesperson for the ICO stated: “With AI offering people countless ways to work more efficiently and effectively, the answer cannot be for organisations to outlaw the use of AI and drive staff to use it under the radar. Instead, companies need to offer their staff AI tools that meet their organisational policies and data protection obligations.”

AI Can Help, But Needs Oversight

The Law Society of England and Wales has emphasised its view that AI has potential benefits, with its chief executive, Ian Jeffery, saying: “AI could improve the way we do things a great deal.” However, he also stressed that AI tools require human oversight and that legal professionals must adapt to their responsible use.

Concerns About A Lack of Expertise

Meanwhile, the Solicitors Regulation Authority (SRA) has expressed concerns about an apparent general lack of digital expertise in the legal sector. For example, a spokesperson was recently quoted as warning that “despite this increased interest in new technology, there remains a lack of digital skills across all sectors in the UK. This could present a risk for firms and consumers if legal practitioners do not fully understand the new technology that is implemented.”

This highlights a broader challenge for the legal industry, i.e. embracing AI innovation while ensuring legal professionals are adequately trained and aware of the risks.

Mixed Reactions

Reports of Hill Dickinson’s approach have drawn mixed reactions. Some industry figures argue that overly strict AI regulations could stifle innovation and slow the adoption of technologies that could make legal work more efficient.

Others point out that firms must proceed with caution, particularly regarding data privacy and regulatory compliance. High-profile cases of data breaches linked to AI use have reinforced concerns about inadvertently exposing confidential client information to external platforms.

Not An Isolated Case

It should be noted here that the reported move by Hill Dickinson is certainly not an isolated case. For example, other major corporations (including Samsung, Accenture, and Amazon) have also implemented restrictions on AI tools over concerns about data security and the potential for AI-generated content to be unreliable or misleading.

The Legal Sector Needs To Find A Balance

AI’s increasing presence in the legal world is undeniable, and firms may now be tasked with finding the right balance between harnessing its benefits and mitigating its risks. Hill Dickinson’s decision highlights a broader industry trend of cautious AI integration, ensuring that its use remains secure, ethical, and compliant with professional standards.

What Does This Mean For Your Business?

The reported move by Hill Dickinson to restrict general AI access highlights a growing tension within the legal sector between technological advancement and regulatory caution. AI undoubtedly holds transformative potential, offering efficiencies in legal research, contract analysis, and document drafting. However, its use comes with inherent risks, particularly in an industry where confidentiality, accuracy, and compliance are paramount.

The firm’s reported decision to implement a request-based approval system reflects an industry-wide concern about data security, regulatory obligations, and ethical considerations. While this is not an outright ban, it does indicate that unregulated AI usage in professional settings remains a real concern. It seems that the spike in AI interactions may have signalled that existing policies were not being strictly adhered to, thereby prompting a need for greater oversight. Such caution is understandable, given the possible risks associated with AI-generated inaccuracies or inadvertent data leaks.

At the same time, broader industry voices, including the ICO and the Law Society, have warned against overly restrictive measures that could stifle innovation. Their position suggests that rather than banning AI, firms should focus on implementing clear, structured policies that allow for responsible usage while maintaining compliance with legal and data protection standards. The Solicitors Regulation Authority’s concerns about a lack of digital expertise in the sector further highlight that law firms must not only regulate AI usage but also ensure that legal professionals are adequately trained in its application.

Hill Dickinson’s approach is not just a legal sector issue and, in fact, it has far-reaching implications for businesses of all sizes across the UK. Many large corporations, such as Samsung and Amazon, have already imposed AI restrictions, reflecting wider concerns about security, compliance, and the reliability of AI-generated content. However, for smaller businesses that lack dedicated legal or IT departments, these challenges could be even more pressing. Without clear guidance or internal expertise, SMEs risk either underutilising AI and missing out on its benefits or adopting it without proper safeguards, exposing themselves to potential legal and reputational risks.

This highlights the need for a balanced, industry-wide approach to AI governance. Government agencies and industry bodies may need to step in to provide clearer guidance. Hill Dickinson’s move is far from isolated, as many large corporations have taken similar steps to control AI’s integration into their workflows.

Security Stop-Press: Shadow AI Tools Pose Security Risk for UK Businesses

Nearly half of UK workers admit to using non-approved AI tools at work without their employer’s knowledge, according to Owl Labs’ latest State of Hybrid Work report, raising alarm among IT and security leaders.

This trend of “shadow AI” or “bring your own AI” (BYO-AI), is particularly prevalent among younger employees, with 63 per cent of Gen Z and Millennials using AI tools weekly, compared to 43 per cent of older workers. While often aimed at boosting productivity, the unauthorised use of these tools exposes businesses to risks such as data breaches, security vulnerabilities, and intellectual property violations.

Despite these dangers, 40 per cent of employees believe there is little to no risk in using non-approved AI tools, and a third doubt their employers can even detect such usage. These findings highlight a significant governance challenge for businesses as AI adoption continues to grow.

To mitigate these risks, organisations should implement strict policies on AI use, educate employees on the dangers of shadow AI, and deploy technologies to monitor compliance, ensuring AI is integrated safely and securely into workplace operations.

Featured Article : 3000% Increase in Deepfake Frauds

A new report from ID Verification Company Onfido shows that the availability of cheap generative AI tools has led to Deepfake fraud attempts increasing by 3,000 per cent (specifically, a factor of 31) in 2023.

Free And Cheap AI Tools 

Although deepfakes have now been around for several years, as the report points out, deepfake fraud has become significantly easier and more accessible due to the widespread availability of free and cheap generative AI tools. In simple terms, these tools have democratised the ability to create hyper-realistic fake images and videos, which were once only possible for those with advanced technical skills and access to expensive software.

Prior to the public availability of AI tools, for example, creating a convincing fake video or image required a deep understanding of computer graphics and access to high-end, often costly, software (a barrier to entry for would-be deep-fakers).

Document and Biometric Fraud – The New Frontier 

The Onfido data reveals a worrying trend in that while physical counterfeits are still prevalent, there’s a notable shift towards digital manipulation of documents and biometrics, facilitated by the availability and sophistication of AI tools. Fraudsters are not only altering documents digitally but also exploiting biometric verification systems through deepfakes and other AI-assisted methods. The Onfido report highlights a dramatic rise in the rate of biometric fraud, which doubled from 2022 to 2023.

Deepfakes – A Growing Threat 

As reinforced by the findings of the report, deepfakes pose an emerging and significant threat, particularly in biometric verification. The accessibility of generative AI and face-swap apps has made the creation of deepfakes easier and highly scalable, which is evidenced by a 31X increase in deepfake attempts in 2023 compared to the previous year!

Minimum Effort (And Cost) For Maximum Return

As the Onfido report points out, simple ‘face swapping’ apps (i.e. apps which leverage advanced AI algorithms to seamlessly superimpose one person’s face onto another in photos or videos) offer ease of use and effectiveness in creating convincing fake identities. They are part of an influx of readily available online AI assisted tools that are providing fraudsters with a new avenue into biometric fraud. For example, the Onfido data shows that Biometric fraud attempts are clearly higher this year than in previous years with fraudsters favouring tools like the face-swapping apps to target selfie biometric checks and create fake identities.

The kind of fakes these cheap, easy apps create have been dubbed “cheapfakes” and this conforms with something that’s long been known about online fraudsters and cyber criminals – they seek methods that require minimum effort, minimum expense and minimum personal risk, yet deliver maximum effect.

Sector-Specific Impact of Deepfakes 

The Identity Fraud Report shows that (perhaps obviously) the gambling and financial sectors in particular are facing the brunt of these sophisticated fraud attempts. The lure of cash rewards and high-value transactions in these sectors makes them attractive targets for deepfake-driven frauds. In the gambling industry, for example, fraudsters may be particularly attracted to the sign-up and referral bonuses. In the financial industry, where frauds tend to be based around money laundering and loan theft, Onfido reports that digital attacks are easy to scale, especially when incorporating AI tools.

Implications For UK Businesses In The Age of (AI) Deepfake-Driven Fraud 

The surge in deepfake-driven fraud highlighted by the somewhat startling statistics in Onfido’s 2024 Identity Fraud Report, suggest that UK businesses navigating this new landscape may require a multifaceted approach. This could be achieved by balancing the implementation of cutting-edge technologies with heightened awareness and strategic planning. In more detail, this could involve:

– UK businesses prioritising the reinforcement of their identity verification processes. The traditional methods may no longer suffice against the sophistication of deepfakes. Therefore, Adopting AI-powered solutions that are specifically designed to detect and counter deepfake attempts could be the way forward. This could work as long as such systems can keep up with the advancements in fraudulent techniques (more advanced techniques may emerge as more AI sophisticated AI tools emerge).

– The training of staff, i.e. educating them about the nature of deepfakes and how they can be used to perpetrate fraud. This could empower employees to better recognise potential threats and respond appropriately, particularly in sectors like customer service and security, where human judgment plays a key role.

– Maintaining customer trust. UK businesses must navigate the fine line between implementing robust security measures and ensuring a frictionless customer experience. Transparent communication about the security measures in place and how they protect customer data can help in maintaining and even enhancing customer trust.

– As the use of deepfakes in fraud rises, regulatory bodies may introduce new compliance requirements and UK businesses will need to ensure that they stay abreast of these changes both to protect customers and remain compliant with legal standards. This in turn could require more rigorous data protection protocols or mandatory reporting of deepfake-related breaches.

– Collaboration with industry peers and participation in broader discussions about combating deepfake fraud may also be a way to gain valuable insights. Sharing knowledge and strategies, for example, could help in developing industry-wide best practices. Also, partnerships with technology providers specialising in AI and fraud detection could offer access to the latest tools and expertise.

– Since deepfake fraud may be an ongoing threat, long-term strategic planning may be essential. This perspective could be integrated into long-term business strategies, thereby (hopefully) making sure that resources are available and allocated not just for immediate solutions but also for future-proofing against evolving digital threats.

What Else Can Businesses Do To Combat Threats Like AI-Generated Deepfakes? 

Other ways that businesses can contribute to the necessary comprehensive approach to tackling the AI-generated deepfake threat may also include:

– Implementing biometric verification technologies that require live interactions (so-called ‘liveness solutions’), such as head movements, which are difficult for deepfakes to replicate.

– The use of SDKs (platform-specific building tools for developers) over APIs. For example, SDKs provide better protection against fraudulent submissions as they incorporate live capture and device integrity checks.

The Dual Nature Of Generative AI 

Although, as you’d expect an ‘Identity Fraud Report’ to do, the Onfido report focuses solely on the threats posed by AI, it’s important to remember that AI tools can be used by all businesses to add value, save time, improve productivity, get more creative, and to defend against the AI threats. AI-driven verification tools, for example, are becoming more adept at detecting and preventing fraud, underscoring the technology’s dual nature as both a tool for fraudsters and a shield for businesses.

What Does This Mean For Your Business? 

Tempering the reading of the startling stats in the report with the knowledge that Onfido is selling its own deepfake (liveness) detection solution and SDKs, it still paints a rather worrying picture for businesses. That said, The Onfido 2024 Identity Fraud Report’s findings, highlighting a 3000 per cent increase in deepfake fraud attempts due to readily available generative AI tools, signal a pivotal shift in the landscape of online fraud. This shift could pose new challenges for UK businesses but also open avenues for innovative solutions.

For businesses, the immediate response may involve upgrading identity verification processes with AI-powered solutions tailored to detect and counter deepfakes. However, it’s not just about deploying advanced technology. It’s also about ensuring these systems evolve with the fraudsters’ tactics. Equally crucial is the role of employee training in recognising and responding to these sophisticated fraud attempts.

As regulatory landscapes adjust to these emerging threats, staying informed and compliant is also likely to become essential. The goal is not only to counter current threats but to build resilience and innovation for future challenges.