AI Policy
Last updated: 27 September 2026 · Effective date: 27 September 2026
This AI Policy sets out our approach to the development and deployment of artificial intelligence in Writford. It provides transparency about our practices and principles relating to AI, including compliance with applicable laws, responsible use, data handling, and safeguards.
Research Tool, Not Legal Advice
Writford is a research and drafting assistant. Its output is AI-generated and must be verified by a qualified solicitor before use.
Your Data is Never Used for Training
We contractually prohibit all AI model providers from training on your data. Your queries are processed, then discarded.
Transparency
Every AI response includes source citations. We label source authority levels so you can assess reliability.
Human Oversight Required
All AI output requires solicitor review. We do not make legal decisions or give legal advice.
1. Purpose and Scope
Writford provides AI-powered legal research and document drafting assistance for UK solicitors (England & Wales). The service is designed to accelerate legal research and produce draft documents. It does not replace professional legal judgment, provide legal advice, or make legal decisions.
2. AI Infrastructure
All AI features run on AWS. We use a tiered set of commercial-grade large language models for different workloads (fast general-purpose responses, standard chat and document analysis, and deeper multi-step legal reasoning). Specific model identifiers and versions are internal to our deployment and may change as our providers release updates.
AI requests are processed by Amazon Web Services and may be processed outside the UK under the UK's approved data transfer safeguards. Every AI request goes to AWS and nowhere else: AWS runs each model in its own accounts, and the companies that build the models, such as OpenAI or Anthropic, never receive your prompts, your documents or the answers.
3. Data Handling Principles
- No training on your data: AWS is contractually prohibited from using your queries or content to train any foundation model.
- How documents reach the AI: your files are stored in encrypted storage in the AWS London region as part of your matter. The AI receives the text it needs to answer your question: the text of a file you attach, or the relevant passages of your matter documents. The text of PDFs and images is read by an AWS text-recognition service in London that does not keep them. See Sections 6 and 6B of our Privacy Policy for what is stored for each source and for how long.
- Model-side retention: AWS does not keep your prompt or the answer once the request is done, with one exception: for some models, which may include the one behind the main chat assistant, AWS's automated abuse checks can keep a request they flag for up to 30 days. It stays inside AWS and is not shared with the company that built the model. Conversation history is stored only in our own database, in your account, and is governed by the retention rules in Section 11 of our Privacy Policy; you may delete any conversation at any time.
- Data minimisation: You should apply data minimisation and avoid including unnecessary client identifiers in queries. Only send the information the AI needs to answer your question.
- Matter data is not sent to AI: Matter management data (matter names, references, client and party names, descriptions, time entries, key dates, conflict records and collaboration details) is stored in our database and is not transmitted to any AI model. Only chat conversations are sent to the AI for processing.
4. Accuracy and Limitations
- Source citations: Every research response includes clickable citations to authoritative UK legal sources (legislation.gov.uk, National Archives Case Law, SRA guidance).
- Source quality scoring: Sources are scored by authority level (legislation scores highest, followed by case law, then regulatory guidance, then web sources).
- Strict citation rules: Our AI models are instructed to cite ONLY from provided sources and to explicitly state when sources are insufficient rather than generating unsupported claims.
- Jurisdiction focus: Writford’s system prompts and source-retrieval pipeline are oriented toward English and Welsh law. Scottish and Northern Irish law may differ. Users should verify jurisdiction-specific points.
- No hallucination guarantees: While we implement multiple safeguards, we cannot guarantee zero hallucinations. Professional verification is always required.
5. Safeguards
- Prompt injection protection: We detect and block attempts to manipulate AI behaviour through injection patterns.
- Input sanitisation: All user input is sanitised before processing.
- Rate limiting: Per-user rate limits prevent abuse.
- Audit logging: All AI interactions are logged for security and compliance purposes (metadata only, not query content).
- DRAFT watermark: All exported documents include a “DRAFT: For Solicitor Review Only” watermark.
- Disclaimer on every response: Every AI response ends with “AI-generated. Verify before relying on this.”
6. Human Oversight
Writford is designed to require human oversight at every stage:
- The solicitor decides what to research or draft
- The solicitor reviews all AI output
- The solicitor verifies all citations against primary sources
- The solicitor decides whether to use, modify, or discard the output
- The solicitor bears professional responsibility for any work product shared with clients or submitted to courts
We do not make legal decisions, give legal advice, or determine the outcome of any legal matter. Writford is a tool. The solicitor is always in control.
7. Compliance
Our AI practices are designed to align with:
- UK GDPR and Data Protection Act 2018
- SRA Standards and Regulations (including Principles 2 and 7)
- SRA Code of Conduct for Solicitors (paragraph 3.3: competence in use of technology)
- Emerging UK AI regulatory framework
8. Changes to This Policy
We may update this policy as our AI practices evolve. Material changes will be communicated to users via email. The latest version is always available at this URL.
Contact
Questions about our AI practices: info@writford.co.uk
See also: AI Ethics Code | Privacy Policy | Terms of Service | Sub-Processors | Security