The SRA’s AI warning: responsibility cannot be delegated to the technology

The Solicitors Regulation Authority has issued a new warning notice (published on 17 August 2026) on the misuse of artificial intelligence in legal services. It focuses on two risks: inaccurate AI-generated content and the exposure of confidential client information.

The central message is straightforward – AI may assist with legal work, but it does not assume responsibility for that work.  Solicitors remain accountable for the accuracy of their advice, the material placed before a court and the protection of client information.

Verification must be substantive

The SRA highlights cases in which fabricated authorities, incorrect citations and other AI-generated inaccuracies have appeared in legal documents and court submissions.

An AI system can produce an answer that is fluent, plausible and… entirely wrong. Consequently, reviewing an AI-generated document cannot be treated as a light-touch proofreading exercise. Cases must be confirmed against authoritative sources, quotations checked in context and legal propositions independently validated.

The warning also reinforces the importance of effective supervision. Responsibility does not sit only with the person who entered the prompt. Supervising solicitors, managers and firms remain accountable for work produced from the most junior to the most senior lawyers, other employees and contractors.

Confidentiality requires more than a paid subscription

The second major concern is the use of AI systems to process client-confidential or privileged material.

Firms should not assume that a tool is suitable for confidential information merely because it is a paid or business product. They need to understand the relevant contractual terms, security controls, data-retention arrangements, model-training provisions, hosting locations and access permissions.

Before client information is entered into an AI system, the firm should be satisfied that appropriate contractual, technical and organisational safeguards are in place. The assessment should reflect the nature and sensitivity of the information involved, rather than relying on a generic approval of the product.

In-house lawyers face an additional issue: an AI tool approved for general business use may not be appropriate for legal work. Organisational enthusiasm for adoption does not override an individual lawyer’s professional duties.

What should firms do now?

The warning notice is not an argument against adopting AI. The SRA expressly recognises its potential value and continues to take an outcomes-focused approach. However, firms must be able to demonstrate that their use of AI is controlled, informed and consistent with their existing obligations.

As an immediate priority, firms should:

  1. identify which AI systems are already being used, including tools adopted informally by individuals
  2. define what information may or may not be entered into each approved system
  3. introduce verification requirements proportionate to the risk and intended use of the output
  4. assign clear responsibility for reviewing AI-assisted work through authorisation processes
  5. provide practical training on AI error management, confidentiality, privilege and professional duties
  6. incorporate AI use into supervision, matter-risk and incident-reporting arrangements
  7. retain enough evidence to explain and justify their governance decision

The SRA’s notice makes clear that AI governance is no longer simply an innovation or information-security project. It is a matter of professional competence, supervision and regulatory compliance.

The technology may be new. The duties are not.

Read the SRA warning notice on the misuse of AI.

Cathy Kirby

Cathy Kirby

07388 027471

Latest Articles

Keep It Real 5: Backups – The Last Line of Defence (Often Untested)

Keep It Real 5: Backups – The Last Line of Defence (Often Untested)

Most organisations say they have backups. Few can say, confidently, that they’ll work when the worst happens and they are needed. Backups are treated as a background safety net but in ransomware attacks, system failure or data loss they’re not a nice-to-have; they’re...

Keep It Real 4: Access Control. Who Actually Has Access to What?

Keep It Real 4: Access Control. Who Actually Has Access to What?

Most organisations assume access is under control: logins exist, permissions are assigned and systems sit behind authentication. On paper it looks tidy but in reality access piles up over time, with little visibility and less removal. “Access creep” is one of the most...

Talk to us today

Get In Touch

Discover more from Baskerville Drummond LLP

Subscribe now to keep reading and get access to the full archive.

Continue reading