AI policies in law firms need constant attention

In 15 years of helping professional services firms develop the policies that underpin how they operate, the one thing we’ve learnt at Enderley is that even the best-run firms can find themselves behind the curve. Nowhere is that more true right now than with AI, and a recent referral to the SRA makes the stakes very clear.

The pace of change in AI has been genuinely extraordinary. Guidance that was considered current 18 months ago may bear little resemblance to how the tools are actually being used in your firm today. That’s not a failing, it’s a reality that almost every firm we speak to is grappling with. But it does make regular, structured review of your AI policy more important than ever.

Two recent cases, both from May 2026, bring that point home. In the first, a circuit judge in Dudley referred two solicitors to the SRA after AI-generated hallucinated case citations were submitted to court. The cases either didn’t exist, had wrong citations, or failed to support the propositions they were supposed to establish. The judge was unequivocal: this was inexcusable, and a public admonishment alone was not sufficient.

In the second, Pinsent Masons self-referred to the SRA after a junior solicitor used AI to draft two misleading emails to the High Court. The AI hallucinated fake rules and statutory wording — while simultaneously warning the lawyer to verify the material against authoritative sources before using it. The judge found the junior solicitor had “almost entirely outsourced the thinking process” and described the firm’s response as “astonishing”.

In both cases, the solicitors involved were not found to have acted deliberately. But that wasn’t enough to avoid regulatory consequences, because the checking processes simply hadn’t been there.

Why AI policies date so quickly

Over the years we’ve helped firms build policies covering everything from data protection and social media use to client care and file management. In each case, the challenge is not just writing the policy, it’s keeping it current as the landscape changes around it.

AI presents that challenge in a particularly acute form. The tools available today are materially different from those available 12 months ago. The ways in which fee earners are using them – whether that be for research, drafting, or document review – have expanded significantly, often faster than formal guidance has followed.

A policy written at a fixed point in time will inevitably develop gaps. That’s not a criticism of the firm that wrote it, it’s simply the nature of a technology that is evolving faster than any policy framework we’ve previously had to keep pace with. The important thing is to have a process in place to spot those gaps and close them before they become a problem.

What the courts are now expecting to see

These cases are part of a clear pattern of judicial messaging. Following earlier High Court guidance, judges have been told to take a robust approach when lawyers cite fictitious or unsupported cases. Contempt proceedings, SRA referrals and referrals to a Hamid judge are all on the table.

Critically, the threshold is not dishonesty but negligence. In the Dudley case, the judge noted that even the most basic checks would have revealed the problems with the citations. That is not a high bar, which makes it all the more important that firms have clear, documented processes in place to ensure those checks happen as a matter of routine.

A signed statement of truth on a document containing AI-generated errors is, as the judge pointed out, a particularly serious aggravating factor, something every fee earner using AI tools in litigation needs to be aware of.

What a current AI policy in a law firm needs to cover

Based on our experience of helping firms develop and review operational policies, and on the specific risks that AI presents, a fit-for-purpose AI policy in 2026 should address at minimum:

  • Which tools are approved for use, and which are not. A general awareness that staff use AI is not sufficient.
  • Verification requirements. Any AI-generated content used in a client matter or submitted to court must be checked by a qualified person before it goes anywhere.
  • Supervision of AI-assisted work. Who is responsible for reviewing research or drafts produced with AI assistance by paralegals, trainees or support staff?
  • Confidentiality and data handling. What client information, if any, may be entered into an AI tool, and under what conditions?
  • Do your people understand not just how to use these tools, but what they cannot reliably be trusted to do?
  • A review schedule. Your AI policy needs a named owner and a date in the diary to review it – not just a place in the policy folder.


Process matters as much as policy

One of the things these cases illustrate clearly is that a policy on its own is not enough. In the Dudley matter, the solicitor involved accepted that he simply hadn’t checked the paralegal’s research before it was submitted.

In the Pinsent Masons matter, the judge found that the failure was in substance a failure of management and supervision at firm level. Whether or not a policy existed, the process of verification wasn’t embedded in how the work was done.

That’s the gap that matters most: not the absence of a document, but the absence of a habit. A good AI policy creates the framework, but it still needs to be accompanied by supervision structures and a shared understanding across the team of what ‘checking AI output’ actually means in practice.

Experience and seniority are not substitutes for that. The Dudley case involved a small claims matter, not complex high-stakes litigation. The Pinsent Masons case involved routine insolvency “boxwork” – an uncontested block transfer application. These situations arise in ordinary, everyday work.

This article is intended for general information purposes and does not constitute legal advice.