MICKAI®ArticlesThe SRA Is Watching AI in 2026: H…
Article · 1 August 2026

The SRA Is Watching AI in 2026: How UK Law Firms Review Contracts Without Sending Client Data to the Cloud

Redline, extract and draft on the firm's own hardware, with privilege preserved and no client data in the cloud.

Author
Micky Irons
Published
1 August 2026
Follow Micky Irons
LinkedInX
legal-aicontract-reviewsra-complianceon-premise-ailaw-firms
The SRA Is Watching AI in 2026: How UK Law Firms Review Contracts Without Sending Client Data to the Cloud

UK law firms can do legal AI contract review without sending a single client document to the cloud: run the redlining, due diligence extraction and clause drafting on the firm's own hardware, and the client data never leaves the building. That is the saving. You stop paying per seat for cloud legal AI and per matter for cloud processing, you remove the confidentiality exposure the SRA has put firms on notice about, and the money moves into one system you own rather than a stack of subscriptions you rent.

Why legal AI contract review confidentiality is the risk the SRA is watching in 2026

The regulator has already spelled out where this goes wrong. Industry reporting on the SRA's risk outlook for AI in the legal market flagged confidentiality, competence and supervision as the live concerns, and it treats putting confidential client information into a public AI tool as a likely breach of the duty of confidentiality, one that can also risk waiving legal professional privilege. A May 2026 survey found that most UK legal professionals had already used unauthorised AI tools for client work, which means the exposure is not theoretical, it is happening quietly on personal accounts.

The uncomfortable part is that the cheapest tools are the ones most likely to breach. A free public chatbot has no contractual wall around your client's data, and the paid cloud suites still move that data off your infrastructure to a vendor you do not control. The way to close the risk is not another policy memo, it is to make the sanctioned tool the one that keeps the data on site.

What cloud legal AI costs a firm today

Two bills sit on top of each other. First is the licence: contract review and due diligence platforms are quoted per seat, and for a mid market firm putting a tool in front of every fee earner, that number scales with headcount whether or not a given seat is busy that month. Second is the processing: documents uploaded for review carry cloud fees, often billed per matter, so a heavy diligence exercise on a transaction becomes its own line item.

Then there is the cost that never appears on an invoice. Every matter run through an external cloud tool is a matter whose confidentiality now depends on someone else's security and someone else's training practices. The SRA has made clear the accountability stays with the solicitor. A breach or a privilege waiver is not a software refund, it is a professional and reputational cost that dwarfs the subscription.

How Astraea reviews contracts on the firm's own hardware

Astraea is our contracts studio, and a studio is a ready made application for one business function that runs inside a single system. Astraea redlines contracts, extracts due diligence points and drafts clauses, and it does all of it offline on the firm's own hardware. It is built to replace Harvey, Luminance, Kira and Ironclad, but the difference that matters is where the work happens: nothing leaves the machine.

The Assistant that drives Astraea runs on the firm's own brain, a model built on the firm's own data and precedent rather than a shared cloud service. Privilege is preserved because the document, the prompt and the output all stay on infrastructure the firm controls, and no client data enters an external training set. When a partner asks the hard question, whether a diligence exercise put client data at risk, the honest answer is that it never left the room.

What you replace, and what you save

What you run todayWhat it costs youWith Mickai
Harvey, a generative legal assistantPer seat licence, and prompts leave the firmAstraea drafts and researches offline, no per seat meter and no data egress
Luminance or Kira for contract review and due diligence extractionPer seat or per matter, with documents uploaded to a vendor cloudExtraction runs on the firm's own hardware, the per matter cloud fee disappears
Ironclad for redlining and contract lifecyclePer seat subscription plus cloud storageRedlining on owned hardware, each run sealed to the Open Audit Record
Free public chatbots used off the books for client workConfidentiality breach and privilege waiver exposureA sanctioned offline system where no prompt leaves the machine
Outside review or offshore extraction hoursHourly labour billed per matterThe Assistant runs on the firm's own brain, the labour stays in house

The audit trail that answers a supervision question

Supervision is the third thing the SRA named, and it is the one AI makes harder, because a system can produce far more output than a partner can read line by line. Astraea seals every run under post-quantum cryptography into the Open Audit Record, a signed, tamper evident log of who ran what, on which document, and when. That is not a compliance certificate, it is the evidence a supervising solicitor needs to show the work was overseen, and it is produced as a by product of doing the job rather than assembled after the fact.

It also changes the shape of a regulatory or client query. Instead of reconstructing what a cloud vendor did with a matter, the firm holds a local, verifiable record on its own hardware. The evidence supports the confidentiality and supervision standards the SRA examines, without claiming any certification the firm has not earned.

How a matter runs end to end, offline

In practice a matter moves through Astraea like this, and every step stays on the firm's own hardware:

  • Load the contract set and the matter's data room into Astraea on the firm's own hardware, with no upload to any external cloud.
  • The Assistant, running on the firm's own brain, redlines against your house positions and playbook and flags the clauses that fall outside them.
  • Due diligence points and risk items are extracted with a citation back to the source document, so a fee earner can verify each one against the paper.
  • A fee earner reviews and approves; the model drafts and marks up but does not send, file or complete anything irreversible on its own.
  • Each run is sealed under post-quantum cryptography into the Open Audit Record, so who ran what, when, and on which document is answerable later.

What specifically leaves the software budget

Fold it up and three recurring lines come off. The per seat legal AI licence stops, because the owned system carries no seat meter. The per matter cloud processing fee stops, because the processing happens on hardware the firm already runs. And the shadow spend on personal chatbot subscriptions has a sanctioned home to move to, which removes both the cost and the breach exposure that came with it. What replaces them is a one off owned capability, paid for once and kept, on infrastructure the firm controls.

Frequently asked questions

Does using AI for contract review breach SRA confidentiality rules?

It can, if the tool sends client data off your infrastructure. Industry reporting on the SRA's AI risk outlook treats putting confidential client information into a public AI tool as a likely breach of confidentiality, and warns it can waive privilege. Running the review offline on the firm's own hardware, as Astraea does, keeps the data in the building and closes that specific exposure.

What tools does Astraea replace?

Astraea is built to replace per seat cloud tools such as Harvey, Luminance, Kira and Ironclad for redlining, due diligence extraction and clause drafting. The saving is that the per seat licence and the per matter cloud processing fee both disappear, and the work moves onto hardware the firm owns.

Does the model send client data anywhere for training?

No. Astraea runs offline on the firm's own hardware and the Assistant runs on the firm's own brain, a model built on the firm's own data. The document, the prompt and the output stay on infrastructure the firm controls, so no client data enters an external training set.

How does a firm evidence supervision of the AI?

Every run is sealed under post-quantum cryptography into the Open Audit Record, a signed, tamper evident log of who ran what, on which document, and when. That gives a supervising solicitor a local, verifiable record of oversight, produced as a by product of the work rather than reconstructed later.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/law-firms-sra-confidentiality-offline-contract-ai. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles
14 Aug 2026
How to Meet NIS2 Without Splunk Scale SIEM Bills: A Sovereign Security Operations Studio
You can meet NIS2 on hardware you own and stop paying a per gigabyte SIEM bill at the same time. Phylax runs the security operations centre on premise with no data volume charge, moving the NIS2 compliance cost from a rising subscription into one owned system.
14 Aug 2026
Only 15 Percent of Companies Can Run Agentic AI: Close the Readiness Gap Without a Consultancy Bill
Only about 15 percent of companies can run agentic AI in production. You can close the AI readiness gap 2026 on your own hardware, with Forge and Vault running the readiness pass and Omni standing the Assistant up on your own data, so the budget buys a system you keep rather than a consultancy slide deck.
13 Aug 2026
The Average Company Runs 275 SaaS Apps and Wastes Half the Licences: Consolidate to One Owned System
SaaS sprawl consolidation in 2026 means moving the business functions you rent as separate subscriptions onto one system you own, running offline on your own hardware with no per seat meter, so recurring licence spend becomes a single owned cost.
13 Aug 2026
CSRD After the 2026 Omnibus: Fewer Datapoints Still Need an Assured Evidence Trail
The CSRD Omnibus 2026 cut mandatory datapoints by roughly 61 percent, yet the figures that remain still need a limited assurance evidence trail. Gaia computes Scope 1, 2 and 3 and seals that trail on your own hardware, so the work moves in house instead of into annual ESG platform fees.