SRA Warning Notice puts AI governance and client confidentiality into the spotlight
Home » SRA Warning Notice puts AI governance and client confidentiality into the spotlight
Anne Austin
Director
On 17 August 2026, the Solicitors Regulation Authority (SRA) published a warning notice on the misuse of AI, alongside a news release setting out its concerns in plain terms.
The message for every SRA-regulated firm is straightforward: using AI does not change what is expected of you, and it is not a defence when something goes wrong. If your firm doesn’t yet have a considered approach to how AI is used, and checked, this notice is your prompt to build one.
We’ve written before about the gap between how firms perceive AI risk and how they actually manage it (see our earlier piece, AI and the regulatory blind spot). This latest notice moves the conversation from something worth thinking about to something the SRA now expects firms to have addressed.
Why are the SRA issuing a warning now?
Between July 2025 and July 2026, the SRA received 42 reports connected to potential AI misuse, and it has a number of ongoing investigations covering inaccurate citations, supervision failures and confidentiality breaches. AI use across law firms has grown quickly, covering research, drafting, document review and administrative tasks, and the regulator has concluded that oversight hasn’t always kept pace.
AI does not change the professional standards expected of solicitors and law firms.
Aileen Armstrong, SRS Executive Director, Strategy and Policy
Firms and individuals remain accountable for what is submitted to a court, given to a client, or entered into an AI tool, regardless of which tool did the drafting.
Two main areas of concern
The warning notice focuses on two problems the SRA has seen recur.
- AI hallucinations. Generative AI tools can produce fabricated case citations and confidently wrong information that reads as entirely genuine. The SRA points to R (Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), where fabricated case citations were put before the court and the solicitor and barrister involved faced a wasted costs application and referral to their regulators. Related warnings followed in BCP v A Mother [2026] EWFC 71 (B) and Cork and another v Smith [2026] EWHC 1199 (Ch). In none of these cases did the outcome turn on whether AI was used deliberately to mislead the court; unchecked reliance on AI output was enough to raise serious regulatory concern.
- Client confidentiality. The Upper Tribunal’s comments in UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC) are worth reading carefully: putting client and Home Office correspondence into an open AI tool effectively places that information in the public domain. Where legal professional privilege is waived this way, it may not be recoverable. The SRA is clear that both free and paid-for AI tools can carry this risk, depending on the provider’s terms, data retention practices and technical architecture.
What this means under the Codes
The notice ties both concerns back to existing obligations rather than creating new ones. Relevant SRA Principles include acting with honesty and integrity, upholding the rule of law, and acting in clients’ best interests. Under the Codes of Conduct, firms and individuals are expected to:
- deliver a competent service, with effective supervision of the work carried out;
- keep client affairs confidential;
- only put forward submissions that are properly arguable, and avoid misleading the court;
- maintain effective governance, systems and controls; and
- be able to justify their decisions and actions to the SRA.
Supervisors and COLPs carry particular exposure here. The Code for Solicitors makes clear that anyone supervising or managing others remains accountable for the work produced through them, so a hallucinated citation slipping through a junior colleague’s draft is a supervision failure as much as an individual one. COLPs must also be able to show that reasonable steps were taken to ensure compliance, including around AI use. This is where a structured file review or AML spot-check schedule earns its keep: building AI-use checks into the ordinary supervision cycle, rather than treating it as a one-off audit.
What law firms should be doing concerning their AI usage
The SRA isn’t prescribing a specific approach; it takes an outcomes-focused view. But a few practical steps consistently come up in our client work:
- Put a written AI use policy in place, covering which tools are approved, what information can and can’t be entered into them, and who signs off the output before AI-assisted content is used with clients or the court.
- Build a verification step into any workflow involving AI-generated research, drafting or citations. Never rely on AI output that hasn’t been checked against a primary source.
- Confirm (and document the outcome of your checks) the contractual and technical safeguards behind any AI tool in use, including whether client data is used to train the model, where it is stored, and for how long – as well as updates to the AI models terms and conditions.
- Extend supervision and file review procedures to specifically capture AI use, so COLPs can evidence oversight rather than assume it.
- Train staff at every level. The SRA’s concerns apply as much to junior fee earners using AI to shortcut research as to partners relying on it for drafting.
The wider picture
This warning notice sits within a broader SRA programme on AI. The Regulator is involved in the government’s Advisory AI Growth Lab (applications open until 27 September)[1], and its effective supervision guidance was updated with AI-specific content in June of this year. Firms exploring how to adopt AI safely, rather than simply avoid it, may find the SRA’s Risk Outlook report on AI in the legal market a useful starting point.
How Enderley can help
If you haven’t yet reviewed your firm’s AI use against this notice, now is the time. We can help with:
- Developing a fit-for-purpose AI policy designed specifically to your practice
- a gap analysis of your current AI use against the SRA’s expectations;
[1] The Growth Lab is a government sandbox for organisations developing AI products for legal services, not firms simply using AI day to day, giving them direct regulatory input while they test. It’s open to LawTech providers, law firms, ABSs and other AI developers, with applications closing 27 September 2026.