Is SRA’s AI warning a wake-up call for UK law firms?

The SRA has issued a new warning notice on the misuse of AI, highlighting two risks that are becoming increasingly difficult for law firms to ignore. These are AI-generated inaccuracies and the exposure of confidential client information.

The warning, published on 17 August, comes as AI becomes embedded in everyday legal work, from research and drafting to document review and administrative tasks.

The SRA recognises that the technology can improve efficiency and enhance services for consumers and it is not telling law firms to stop using it. But it is highlighting that using AI does not change a solicitor’s professional obligations or their responsibility for the work they produce.

42 reports in one year with more investigations underway

The SRA received 42 reports relating to potential misuse of AI between July 2025 and July 2026. Several investigations remain ongoing, involving issues including inaccurate legal citations, supervision and confidentiality.

That represents a shift in the regulatory landscape.

AI misuse is no longer a hypothetical risk that firms can address through a general statement saying employees should “use AI responsibly”. Regulators are now seeing real-world incidents and investigating whether they amount to breaches of professional obligations.

The SRA has specifically highlighted cases where AI has generated fictitious or inaccurate legal authorities and where confidential client information has been entered into AI systems without adequate safeguards.

AI can sound authoritative and still be wrong

One of the most significant risks identified by the SRA is the use of AI-generated material in legal research, advice, analysis and court submissions.

Generative AI can produce convincing-looking case names, citations, quotations and legal propositions that do not actually exist. The problem is particularly serious in legal practice because an erroneous answer can look perfectly plausible to someone who does not independently verify it.

The SRA points to previous cases involving fabricated authorities and notes that it has received reports of solicitors relying on AI-generated inaccuracies. And the consequences can extend well beyond an embarrassing mistake.

A solicitor who submits a non-existent case to a court could face serious professional consequences. The SRA warns that putting false material before a court could potentially amount to contempt of court.

Every authority used in advice, correspondence or submissions needs to be checked against a reliable source. The same applies to legislation, quotations, procedural requirements, factual assertions and anything else where accuracy matters.

Confidentiality is the other major red flag

The SRA’s second major concern is what happens to client information when it is entered into an AI system?

The warning specifically highlights instances where confidential client information has been entered into AI tools without appropriate safeguards.

The fact that an AI tool is widely used or commercially available does not make it appropriate for confidential legal work.

The SRA warns that putting client information into a public AI tool will likely breach client confidentiality. Both free and paid-for AI systems can present risks if firms have not established appropriate contractual, technical and organisational safeguards.

This is not simply an AI policy issue. It potentially engages a range of existing obligations, including confidentiality, data protection, legal professional privilege and professional conduct requirements.

The SRA points to the case of UK v Secretary of State for the Home Department, where the Upper Tribunal raised concerns about putting client and decision letters into an open AI tool.

The warning is particularly significant because it demonstrates how an apparently simple action, copying information into a chatbot to summarise, analyse or draft a response, can create consequences that extend far beyond the immediate task.

“We have a policy” is just not enough

The SRA takes an outcomes-based approach to regulation. It does not prescribe a particular AI platform or dictate exactly how every firm must deploy the technology.

Instead, firms need to demonstrate that they have effective governance, systems and controls proportionate to the risks they face. That means an AI policy sitting in the firm’s intranet is unlikely to be sufficient on its own.

Firms should be able to demonstrate that they have a clear understanding of how AI is being used across the business. This includes knowing which AI tools are approved and which are prohibited, what client information can be entered into those systems, and how confidential information is protected. Firms should also know whether their IT and data protection teams have assessed the relevant tools and whether the AI provider offers appropriate contractual protections.

They should also have clear processes for verifying AI-generated legal authorities and determining who is responsible for reviewing AI-generated work. Additional controls may be needed for higher-risk activities such as litigation, while supervision arrangements should ensure that junior lawyers and support staff are using AI appropriately. Finally, firms need a clear process for responding when confidential information is accidentally entered into an unauthorised AI tool, as well as mechanisms for recording, monitoring and regularly reviewing AI use across the firm.

Human oversight must be meaningful

The SRA’s message about human oversight is also important. “Human in the loop” cannot mean that someone clicks a button approving an AI-generated document. The person reviewing the output needs the expertise, time and authority to identify errors and challenge the AI’s conclusions.

This is especially important where AI is being used by junior lawyers, paralegals or non-authorised staff.

The SRA makes clear that those responsible for supervision may themselves face consequences if inadequate supervision allows false citations or other inaccurate material to reach the court or client.

What should UK law firms do now?

It’s time for firms to reassess AI governance now. Don’t wait for an enforcement case involving the firm.

1. Create an approved AI environment

Firms should establish a clear list of AI tools that staff are permitted to use for work purposes.

Approval should consider security, confidentiality, data protection, contractual terms, data retention, model training, access controls and the location and handling of data.

The default should not be that employees can use whichever AI tool they prefer.

2. Classify AI use by risk

Not every AI use case carries the same level of risk.

A sensible framework could distinguish between:

Lower risk: administrative tasks, brainstorming or generic drafting using non-confidential information.

Medium risk: document analysis, internal research or drafting involving firm information.

High risk: client advice, legal research, litigation, court submissions, confidential information or privileged material.

The higher the risk, the stronger the controls and human review should be.

3. Make verification mandatory

Firms should establish clear requirements for verifying AI-generated legal content.

Verification should extend to every substantive element of AI-generated legal work. This includes checking case names and citations, legislation and quotations, as well as the accuracy of legal propositions and factual claims. Firms should also verify any references to regulatory requirements and, most importantly, carefully review all AI-generated material before it is submitted to a court or relied upon in legal advice. 

The person signing off the work must understand that “the AI produced it” is not a defence.

4. Protect client confidentiality

Staff should understand exactly what information can and cannot be entered into AI tools.

Training should cover more than simply saying “don’t put confidential information into ChatGPT”.

Employees need to understand why seemingly innocuous information can become sensitive when combined with other data, and what safeguards an approved enterprise AI system actually provides.

5. Train everyone 

AI governance cannot be delegated to the firm’s IT department.

Solicitors, trainees, paralegals, administrative staff and supervisors all need to understand their responsibilities.

Training should include practical examples of hallucinated authorities, inappropriate disclosure of client information and situations where AI output requires escalation or additional review.

6. Review supervision arrangements

Firms should revisit their supervision frameworks to reflect the reality that AI may be used at multiple stages of a matter.

The regulatory direction 

The SRA has already added AI-specific material to its effective supervision guidance, and it is participating in the government’s Advisory AI Growth Lab. Its proposed 2026/27 business plan also includes strengthening its Innovate work programme to support firms adopting technology responsibly.

Meanwhile, courts are also setting expectations.

Recent judicial guidance has emphasised that generative AI can assist with litigation, but its use must be appropriate, responsible and undertaken with due care.

AI may draft the document, summarise the case or suggest the authority. But the solicitor remains accountable for what ultimately goes to the client, the court or a third party.

For UK law firms, responsible AI use is therefore no longer simply an innovation objective. It is becoming a core part of professional, regulatory, confidentiality and risk management.

Read our guide: How to build a compliant AI programme

Download it here →