Skip to main content
LEGAL

What the SRA Already Expects from You on AI, and Where Most Firms Are Falling Short

12 June 2026

Artificial intelligence arrived in legal practice without much ceremony. One quarter, firms were experimenting cautiously with document review tools; the next, junior lawyers were routinely using large language models to draft correspondence, summarise case files and research precedent. The technology moved faster than the governance frameworks meant to contain it, and the Solicitors Regulation Authority has noticed.

The SRA has not introduced a dedicated AI regulation, and it is unlikely to do so in the near term. What it has done is something more immediately consequential: it has made clear, through published guidance, thematic reviews and public statements, that existing professional obligations already apply to AI use in full. The Handbook has not changed. The expectations have simply been clarified. For many firms, that clarification is uncomfortable reading.

The Regulatory Position, Plainly Stated

The SRA’s position is straightforward, even if its implications are not. Solicitors remain personally responsible for the work they produce, regardless of the tools used to produce it. If an AI system generates an inaccurate legal summary and a solicitor relies on it without adequate review, the professional responsibility for that error rests with the solicitor. The technology is not a defence. It is not a mitigating factor. It is, in the SRA’s framing, simply another tool, and the standard of care expected when using it is the same as for any other.

This matters because the way many firms have adopted AI does not reflect that standard. Deployment has often been informal: individual lawyers choosing their own tools, using personal accounts on consumer-grade platforms, with no firm-wide policy governing what is permissible, what requires review or what must never be done. In that environment, the gap between what the SRA expects and what is actually happening can be considerable.

Competence Is the Starting Point

The SRA Code of Conduct requires solicitors to maintain competence and to keep their professional knowledge and skills up to date. The regulator has indicated that this obligation extends to understanding the tools used in practice, including AI. A solicitor who uses a large language model to draft a contract clause without understanding how that model generates output, what its limitations are, or how errors might arise, may not be meeting the competence standard the Code requires.

This is not an argument for every solicitor to understand machine learning in technical depth. It is an argument for a working understanding of what AI tools can and cannot reliably do in a legal context. The distinction matters in practice. Large language models are capable of producing plausible-sounding text that is factually wrong, legally inaccurate or subtly misleading, a phenomenon sometimes described as hallucination. A competent user of these tools understands that risk and applies appropriate scrutiny. A solicitor who treats AI output as reliable without verification is not applying that scrutiny.

Firms that have not yet provided structured training on AI tools, their capabilities, their failure modes, and the review processes required, are likely operating below the standard the SRA would expect.

Client Confidentiality and Data Handling

The confidentiality obligations that apply to client information do not pause when that information is processed by an AI system. This is an area where informal AI adoption creates particular risk. Consumer-facing AI platforms typically retain user inputs to improve their models. A solicitor who pastes a client’s confidential instructions, financial details or dispute background into such a platform may be disclosing confidential information to a third party without the client’s knowledge or consent, and potentially in breach of both professional obligations and data protection law.

The SRA has been explicit that firms must understand how the AI tools they use handle data. That means reviewing terms of service, understanding data retention practices, and making informed decisions about which tools are appropriate for which tasks. It also means having a clear policy that staff understand and follow. Where enterprise-grade tools with appropriate data processing agreements are available, firms should be using them for client-facing work. Where they are not, the safer position may be to restrict AI use for that category of task entirely.

Many firms have not yet conducted this analysis. The tools have been adopted; the due diligence has not followed.

Where Most Firms Are Falling Short

IMAGE REQUIRED
SRA AI Compliance Framework, Key Expectations for Law Firms · Awaiting supplied asset

Supervision is perhaps the most immediate gap. The SRA’s supervision requirements apply to AI-assisted work as they do to work produced by a trainee or junior fee earner. Output requires review by someone with the competence to identify errors. In practice, the volume and speed of AI-generated content can make that review feel less urgent, the text looks polished, the structure is coherent, and the temptation to treat it as finished is real. That temptation is precisely the risk the SRA is concerned about.

Transparency with clients is a related area where practice has lagged behind expectation. The SRA has not mandated disclosure of AI use in every case, but its guidance on client care and honest communication creates a reasonable expectation that clients should understand, in broad terms, how their matter is being handled. Where AI plays a material role in producing advice or documents, there is a reasonable argument that clients should be informed. Few firms have developed a clear policy on this. Fewer still have addressed it in their client care letters.

Equality and diversity considerations have also entered the regulatory conversation. AI systems trained on historical data can reflect and reproduce existing biases. In a legal context, that risk is not abstract: a tool used to assess the merits of a claim, to draft communications, or to support decision-making in HR-related matters could produce outputs that disadvantage individuals on protected grounds. The SRA expects firms to be alert to this. Most have not yet built that awareness into their AI governance.

What a Proportionate Response Looks Like

None of this requires firms to abandon AI or to build compliance infrastructure that outweighs the practical benefit of the tools themselves. The SRA has been measured in its approach, and the expectation is proportionality rather than prohibition. What is expected is that firms take the matter seriously, that AI use is governed, not merely permitted.

In practical terms, that means a written AI policy that addresses permissible tools, data handling, supervision requirements and client communication. It means training for fee earners that goes beyond a brief introduction and covers the specific risks relevant to legal practice. It means someone in the firm with responsibility for keeping that policy current as the technology and the regulatory environment develop. And it means a culture in which AI output is treated as a starting point for professional judgement, not a substitute for it.

The SRA has signalled that it will continue to monitor how firms are responding to AI. Thematic reviews are a likely mechanism. Firms that have documented their approach, trained their people and built review processes into their workflows will be in a considerably stronger position than those that have not. The firms that are most exposed are not necessarily those using AI most extensively, they are those using it without governance.

The regulatory framework is already in place. The question is whether firms are working within it.

This article is for general information only and does not constitute legal advice.

This website uses cookies. By continuing to use this site, you accept our use of cookies.  Learn more