The Solicitors Regulation Authority has issued a new warning notice telling solicitors and law firms that using artificial intelligence does not transfer or reduce their professional responsibility. Published on 17 August 2026, the notice focuses on two risks the regulator says it has already observed: false or inaccurate AI-generated material in legal work, and confidential client information being entered into public AI tools.
The development matters because this is not simply a general technology explainer. The SRA’s warning notice says the regulator will have regard to it when exercising its regulatory functions. It also states that failure to give the notice proper regard may expose solicitors, firms or their employees to disciplinary action.
What has the SRA warned about?
The notice applies to all firms and individuals regulated by the SRA. It recognises that many legal businesses use AI safely, but says the regulator is particularly concerned about two areas.
First, generative AI can invent cases, citations, references or factual assertions that appear convincing. The SRA says it has received reports from senior judges about possible Code of Conduct breaches and has also seen solicitors self-report after relying on inaccurate or misleading AI output.
Secondly, the regulator warns that both free and paid AI services may lack the contractual and technical safeguards required to protect confidential information. Depending on a provider’s terms, settings and architecture, material entered into a tool may be stored, retained, made accessible to others or used to improve the system.
Independent coverage by Infosecurity Magazine reported the warning as a response to growing concern about hallucinated legal content and data leakage in the regulated sector.
Lawyers remain responsible for AI-assisted work
The SRA’s central message is straightforward: an AI system has no separate legal personality, so the regulated person remains accountable for the work produced with it.
That has several practical consequences. A solicitor submitting named authorities should be satisfied that each case is genuine, relevant and supported by a verifiable citation. The notice says reliance on AI would not be a defence where false material is put before a court. Depending on the circumstances, misleading material may lead to regulatory referral, wasted-costs consequences or contempt issues.
Responsibility also extends to supervision. Solicitors who manage junior or non-authorised colleagues remain accountable for work carried out through them, while firms must maintain effective systems for supervising client matters. AI-assisted drafting therefore cannot sit outside the firm’s normal review and escalation structure.
Confidentiality requires more than a paid subscription
The notice rejects the assumption that paying for an AI product automatically makes it suitable for confidential legal work. Firms must understand the actual safeguards that apply to the particular service and the sensitivity of the material being processed.
The SRA says client information should enter an AI system only where appropriate contractual, technical and organisational protections are in place. Firms should satisfy themselves that data remains in a secure environment, is not available to unauthorised third parties, is not used to train models without appropriate authority, and is not retained longer than necessary.
The regulator also highlights legal professional privilege. Referring to UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), it warns that placing client material into an open public tool may breach confidentiality and could permanently waive privilege.
What should firms review now?
The notice does not prescribe a single technical solution. The SRA follows an outcomes-focused approach, leaving firms flexibility over how they meet the required standards. But the document makes clear that a defensible AI workflow should include:
- human verification of legal propositions and citations;
- clear approval and supervision routes for AI-assisted work;
- an inventory of approved tools and prohibited data uses;
- due diligence on retention, training, access and security terms;
- staff training that covers professional duties as well as product features;
- incident reporting and remediation when inaccurate output or data exposure is discovered.
In-house solicitors receive a specific warning too. A tool developed for the wider business may not have been designed for legal work, and the organisation’s enthusiasm for AI adoption may conflict with the lawyer’s independent professional duties.
What happens next?
The warning notice applies existing professional and legal obligations rather than creating a new standalone AI statute. Its importance lies in the SRA’s stated enforcement posture: accountability, competent service, effective supervision, duties to the court and client confidentiality all continue to apply regardless of which technology produced a first draft.
Firms should now compare their written AI policy with actual day-to-day practice. A policy that says “check AI output” will carry little weight if lawyers cannot show how citations are verified, which systems are approved, what data may be entered, and who reviews higher-risk work.
This article is for general information only and is not legal advice.