Summary
- The SRA received 42 reports of potential AI misuse between July 2025 and July 2026 and has investigations under way.
- Its warning concentrates on inaccurate outputs, confidential information, supervision, and the continuing responsibility of solicitors for AI-assisted work.
- Law-firm AI adoption increasingly requires governance, approved systems, access controls, verification, and audit processes rather than unrestricted tool access.
Artificial intelligence in English and Welsh law firms is moving from an adoption question into a professional-conduct issue, with the Solicitors Regulation Authority warning that inaccurate outputs, weak supervision, and confidentiality failures can trigger existing regulatory obligations rather than sitting outside them as a novel technology problem.
The regulator received 42 reports related to potential misuse of AI between July 2025 and July 2026 and says investigations are under way into issues including inaccurate legal citations, supervision, and confidentiality. The warning follows a series of court cases and disciplinary concerns in which generative systems have produced invented authorities or unreliable legal material.
The SRA’s position is that solicitors remain responsible for work produced with AI assistance, regardless of whether the error originated in a model, a prompt, or an automated workflow. That places verification, supervision, and client confidentiality inside the same professional framework that applies when work is delegated to a junior colleague or external provider.
As firms move from experimentation into wider use, the regulatory burden therefore falls less on whether a product is labelled as AI and more on how it is procured, controlled, monitored, and incorporated into legal work.
AI does not inherit professional responsibility
Generative systems can accelerate research, summarisation, drafting, document review, and administrative work, but they can also produce confident answers unsupported by the underlying law. In legal practice, a fabricated citation or inaccurate statement can move quickly from an internal draft into correspondence, advice, or court documents if no effective checking process sits between generation and submission.
The SRA’s warning makes clear that use of an AI tool does not transfer accountability to the vendor. Solicitors must still ensure that work is competent and accurate, while managers and supervisors remain responsible for the systems through which legal services are delivered.
That distinction makes human review more than a general recommendation. A firm that deploys an AI drafting tool without defining when outputs must be checked, who is authorised to approve them, and what evidence should be retained may have difficulty demonstrating effective supervision when something goes wrong.
Confidentiality changes the procurement calculation
Legal AI adoption also creates a data-handling problem because prompts can contain client facts, privileged material, internal strategy, or personal information. Sending that material into a public or poorly governed service can expose it to retention, processing, or access arrangements inconsistent with the firm’s duties.
Procurement therefore has to examine model hosting, data retention, training policies, access controls, logging, and contractual safeguards rather than treating the product as another office application. Approved-tool lists and technical restrictions can reduce casual use of consumer services, although they only work when lawyers understand why those boundaries exist.
Private and enterprise AI platforms may offer stronger controls, but they do not eliminate the need to know what information enters the system and where it travels. Retrieval systems, plug-ins, agents, and connected data sources can widen the number of services involved in a workflow, increasing the importance of access management and audit trails.
Existing duties are becoming AI regulation
The SRA has not created a separate code of conduct for artificial intelligence. Instead, it is applying duties around competence, supervision, confidentiality, integrity, and service delivery to new tools, an approach that mirrors how several UK regulators are handling AI under existing sector rules.
That can give firms flexibility because it avoids prescribing one technical architecture, but it also removes the defence that a particular failure was too novel to fit established obligations. If an AI-assisted process causes inaccurate work or exposes client information, the regulatory question remains whether the firm acted competently and maintained appropriate controls.
Law firms consequently need governance that can survive ordinary operational pressure: approved systems, defined review thresholds, training, access controls, incident reporting, and records showing how AI-assisted work was checked. Those controls are less visible than a new chatbot, but they determine whether adoption can expand without turning efficiency gains into disciplinary exposure.
The 42 reports received over the past year remain small relative to the size of the profession, yet they show that AI-related conduct issues are already reaching the regulator. As deployment becomes routine, the boundary between technology governance and professional supervision will become increasingly difficult for firms to separate.












