AI Client Intake for UK Law Firms: What the Rules Allow

·Ali Amin

AI client intake in a UK law firm can safely run the administrative half of onboarding — capturing enquiry details, verifying identity documents, chasing what has not come back and booking the first appointment — but it cannot decide who becomes a client, assess whether a source of funds is credible, clear a conflict or give advice. Those four steps are governed by the Money Laundering Regulations 2017, the SRA Code of Conduct and the UK GDPR's automated-decision rules, which changed on 5 February 2026.

Nearly everything published on legal intake automation is written for American firms, and the UK-facing results are vendors describing their own products. This is the UK version, with a diagnostic to run on your own intake first.

What does AI client intake mean in a UK firm?

Client intake is everything between first contact and a signed engagement, and it does four jobs that get discussed as one. It captures — name, matter type, other side, dates. It qualifies — is this work the firm does, at a fee it can run. It checks — client due diligence, sanctions and conflicts. And it contracts — client care letter, terms of business, costs information.

Capture and contract are document-movement problems software solved years ago, and checking is part mechanical, part regulated judgement. Qualifying is where firms get into trouble, because a "qualification" ending in a rejection is a decision about a person, not a data-entry step.

Why is the advice you find online wrong for a UK firm?

Two reasons. The first is jurisdiction: the results are dominated by US practice-management and intake vendors whose compliance sections are built on American professional-conduct rules. Nothing sampled on 11 September 2026 mentioned the Money Laundering Regulations 2017, the SRA Code of Conduct, or the UK's automated-decision regime.

The second is arithmetic that does not survive checking. That sampling turned up claims that a three-day intake loses 20 to 30 per cent of prospective clients, that automation raises conversion by up to 40 per cent, and that a new client takes 45 minutes to an hour of pure admin. Not one carried a primary source. None is repeated here as fact, and any percentage you cannot follow to a named study is marketing.

The one dated, sourced number worth knowing is a regulator's. The SRA's warning notice on the misuse of AI records 42 reports of potential AI misuse between July 2025 and July 2026, with open investigations covering inaccurate legal citations, supervision and confidentiality (SRA, Misuse of AI warning notice, checked 11 September 2026). The regulator's problem is not too much admin automation. It is tools left to speak or decide unsupervised.

Which intake steps can software decide, and which cannot?

This is the question the category avoids, and the UK answer moved this year. Section 80 of the Data (Use and Access) Act 2025 replaced Article 22 of the UK GDPR, and section 14 of the Data Protection Act 2018, with Articles 22A to 22D (Data (Use and Access) Act 2025, section 80, checked 11 September 2026). It took effect on 5 February 2026, and the transitional provision is explicit that the new regime does not reach back to earlier decisions (SI 2026/82, checked 11 September 2026).

The new framework is more permissive, not less: the ICO describes it as allowing solely automated decisions with legal or similarly significant effects in wider circumstances, provided safeguards are in place (ICO, what the DUAA means for organisations, checked 11 September 2026). Those safeguards, in Article 22C, are that the individual is told about the decision, can make representations, can obtain human intervention, and can contest it. The wider permission does not extend to decisions based on special category data, where the stricter regime still applies.

Refusing to take someone on is the textbook significant decision. Automating it is not barred, but you inherit four obligations you must be able to perform, and few small firms have a route for a rejected enquirer to contest anything. Keeping that decision with a named person is cheaper and safer.

What does client due diligence require at intake?

Regulation 28 of the Money Laundering Regulations 2017 sets out what due diligence consists of: identifying and verifying the client, anyone purporting to act for them, and any beneficial owner, and assessing the purpose and intended nature of the relationship (MLR 2017, regulation 28, checked 11 September 2026). Three details decide how much of it a workflow can hold.

Timing. Regulation 30 requires verification before the business relationship is established, with a narrow exception allowing it to be completed during establishment where that happens as soon as practicable after first contact (MLR 2017, regulation 30, checked 11 September 2026). An intake flow that books a first substantive meeting before verification finishes is making a risk decision nobody signed off.

Source of funds is a judgement, not a field. Regulation 28(11)(a) requires scrutiny of transactions to ensure the source of funds remains consistent with what the firm knows of the client, and the Law Society is clear this is risk-based rather than mechanical (Law Society, customer due diligence, checked 11 September 2026). A form can collect bank statements; deciding whether they are credible is not a form's job.

You must be able to show your working. Regulation 28(16) requires a firm to demonstrate to its supervisor that the due diligence applied was appropriate to the risk. That makes the audit trail part of the deliverable, and it is the commonest gap in a self-built intake automation.

Electronic verification is accepted: the Legal Sector Affinity Group guidance, approved by HM Treasury and in effect from 23 April 2025, supports different routes to identification and verification where a client cannot be met face to face (Law Society, AML guidance for the legal sector, checked 11 September 2026). The screening rules also moved this year: following the Money Laundering and Terrorist Financing (Amendment) Regulations 2026, from 30 June 2026 high-risk third countries are defined by reference to the FATF call-for-action list. A hard-coded country list is already out of date.

Why conflict checking stays with a person

Paragraph 6.2 of the SRA Code of Conduct prohibits acting where there is a conflict of interest or a significant risk of one, unless clients have a substantially common interest or compete for the same objective and every condition is met: informed consent given or evidenced in writing, effective safeguards for confidential information, and the solicitor satisfied it is reasonable to act (SRA, conflicts of interest guidance, checked 11 September 2026). The database search should be automated. Everything after it is a judgement about relationships, and informed consent is a conversation, not a tick-box.

The same line applies to advice. Section 12 of the Legal Services Act 2007 lists the reserved legal activities, and section 14 makes it an offence to carry one on without entitlement (Legal Services Act 2007, section 12, checked 11 September 2026). An intake bot that tells a caller whether they have a claim, or how long they have to bring one, has stopped collecting and started advising.

A nine-step diagnostic before you automate client intake

Run this over your last twelve weeks of enquiries. It takes an afternoon, and it will change what you buy.

  1. Time the whole thing. Median hours from first contact to signed engagement letter, per matter type — not the average, which one stalled probate file distorts.
  2. Mark where each lost enquiry stopped. No reply from you, no reply from them, ID never returned, conflict, fee, or out of scope. The largest category is the actual problem, and rarely the expected one.
  3. Split the four jobs. Tag every step capture, qualify, check or contract. Capture and contract usually absorb the time; qualify and check absorb the worry.
  4. Label each step admin or decision. If a step could end with someone being turned away, it is a decision.
  5. Name the human for every decision step. If you cannot name one, that is the finding.
  6. Test the refusal path. If software could cause a refusal, can you tell the person, hear representations, offer human intervention and let them contest it? If not, it stays manual.
  7. Classify the data each field collects. Health, criminal allegations and family circumstances arrive routinely in legal enquiries, and change what the tooling has to be.
  8. Follow the data to where it lands. Confidentiality under the SRA Principles does not pause for a free tool that trains on its inputs.
  9. Only now price it. Cost the automation against the admin steps from step 3, not the whole intake.

What to automate, and what to leave alone

Intake stepAutomate?Why
Enquiry acknowledgement and triageYesBuys back response time; no advice given
Requesting ID, chasing what is missingYesDocument movement; the chase is where files stall
Electronic identity verificationYesSupported by LSAG guidance; keep the evidence
Running the conflict searchYesThe search is mechanical
Clearing the conflictNoParagraph 6.2 judgement, plus informed consent
Assessing source of funds or wealthNoRisk judgement under regulation 28
Accept or decline the clientNoA significant decision about a person
Answering "do I have a case"NoReserved activity territory
Drafting the client care letterYesDraft, then a fee earner reviews and sends

The pattern holds across professional services: automate the movement of information and documents, never the assessment of a person. The same logic on a different regulated workflow is in our piece on GDPR-compliant AI automation.

Do you need a DPIA, and does a supplier take on the risk?

On the first, assess it rather than assume. The ICO lists innovative technology including AI, data concerning vulnerable individuals, and sensitive data among the criteria indicating high-risk processing, and says a combination of two usually means a data protection impact assessment is required (ICO, when do we need to do a DPIA, checked 11 September 2026). Family, crime and immigration intake often meets two or three.

On the second, no. The SRA's position is that a firm cannot abrogate responsibility for compliance and remains accountable where work is carried out through others (SRA, lawtech providers Q&A, checked 11 September 2026). A supplier can build and run it; the duty stays with the firm, which is why the audit trail and the named decision-maker matter more than the model.

None of this is legal or compliance advice. It describes obligations and points at the official source for each; how they apply to your firm is for your COLP, your MLRO and your own advisers.

Frequently asked questions

Can AI decide whether a law firm takes on a client? Not on its own. Declining a prospective client is a decision with a significant effect on that person, and since 5 February 2026 the UK GDPR rules on solely automated decisions sit in Articles 22A to 22D. Software gathers, structures and flags; a named person accepts or declines, and the record should show who.

Does an intake chatbot have to say it is not a solicitor? In practice, yes. The SRA Principles require you not to mislead clients or the public, and a prospective client who believes they are talking to a solicitor is being misled. Say what the tool is at the start, say it cannot advise, and route substantive questions to a person.

Can an automated system run client due diligence checks? It can collect and verify. Regulation 28 of the Money Laundering Regulations 2017 requires you to identify and verify the client and understand the purpose of the relationship, and electronic verification is accepted. What software must not do is form the risk judgement, because regulation 28(16) requires you to show the measures suited the risk.

Do I need a DPIA before automating client intake? Assess it rather than assume. The ICO lists innovative technology including AI, vulnerable individuals and sensitive data among its high-risk criteria, and says two or more together usually mean a data protection impact assessment is needed. Legal intake often touches several, so for most firms the answer is yes.

How much does it cost to automate law firm client intake? Ihsan Ops starts with an AI Opportunity Audit from £1,000, which is how scope and price get established before anything is built. A single well-scoped workflow runs £2,000 to £5,000 over two to four weeks, with recurring platform and model costs of £100 to £600 per workflow per month.

Where to start

Run the nine-step diagnostic first. If most lost enquiries stall at "ID never returned", that is a chasing problem automation fixes cheaply and safely. If they stall at "no reply from you", the fix may be a rota, not software.

Ihsan Ops is a UK AI automation agency in Bedford, working with professional services firms, accounting practices, trades and appointment-based businesses. Every engagement starts with an AI Opportunity Audit from £1,000, which maps the workflows worth automating and the ones that are not before any build is quoted; custom workflow and CRM builds for practices run from £4,000 — more on our process automation and AI strategy consulting pages. To talk it through against your own intake numbers, book a 30-minute call.