SRA AI Warning Notice: What Your Firm Has to Put in Place
At a Glance
- Who this is for: COLPs, risk partners and Heads of IT at SRA-regulated firms where fee earners already use AI tools on client work.
- The problem: The SRA's AI warning notice says what firms must achieve when they use AI, and leaves each firm to decide how to prove it.
- What is changing: Since 17 August 2026 the SRA has stated that anyone who fails to have proper regard to the notice is at risk of disciplinary action.
- The takeaway: Give every duty in the notice a named owner and a record, and check the terms of each AI tool before client data goes into it.

The SRA AI warning notice confirms that AI changes none of a solicitor's professional duties. It ties two risks, invented content and client data entered into tools without safeguards, to named paragraphs of the Codes of Conduct. It also names who answers for them: the solicitor, the supervisor, the firm and the COLP.
Why the SRA AI Warning Notice Matters Now
The SRA published the notice, titled Misuse of AI, on 17 August 2026. It applies to every firm and individual the SRA regulates. On the same day the regulator said it had received 42 reports of potential AI misuse between July 2025 and July 2026, with several investigations under way (Law Gazette).
A warning notice carries more weight than a press release. The SRA says it will have regard to the notice when it exercises its regulatory functions, and the text is blunt: "If you fail to have proper regard to this warning notice, you are at risk of disciplinary action."
The notice is supportive of AI used well. It says many firms already use it safely, and that firms are free to use it as long as they keep meeting SRA standards.
What the notice leaves out is the how. The SRA regulates on outcomes, so each firm decides which controls to build and how to show they work. That gap is where most of the practical effort now sits.
Aileen Armstrong, the SRA's Executive Director of Strategy and Policy, summed up the principle when the notice came out: "Individuals remain responsible for the work they produce and the advice they provide."
What the SRA AI Warning Notice Requires on Accuracy and Supervision
The first concern is hallucination: AI producing cases, references or facts that look credible and do not exist. The notice links it to these duties:
- Work must be competent and effectively supervised (Code of Conduct for Solicitors, paragraphs 3.2 and 3.5).
- Representations to the court must be properly arguable (paragraph 2.4).
- Any case named must be genuine, relevant and carry a verifiable citation (paragraphs 2.2 and 2.4).
- Supervisors remain accountable for work done by junior and unauthorised staff (paragraphs 3.5 and 3.6, and Code of Conduct for Firms, paragraphs 4.3 and 4.4).
- Firms need governance, systems and controls that cover AI risk (Code for Firms, paragraph 2.1).
- The COLP must take reasonable steps to secure compliance (Code for Firms, paragraph 9.1).
The supervision point carries the most exposure for a busy practice. If a trainee's draft reaches a court with a fabricated authority in it, and it went out without proper review, the supervisor has a regulatory problem as well as the trainee.
The SRA had already moved in this direction. In June 2026 it added a section on AI to its effective supervision guidance, saying AI-assisted output should get appropriate human review and that an authorised individual keeps ultimate responsibility for the work.
Among the judgments the notice cites is Cork and another v Smith [2026] EWHC 1199 (Ch). We walked through what went wrong in that case, and the controls that would have caught it, in AI governance for law firms: what a CTO actually has to build.
What the Notice Says About Client Confidentiality
The second concern probably affects more firms day to day. Under paragraph 6.3 of the Codes of Conduct, client information should go into an AI system only where appropriate contractual, technical and organisational safeguards are in place. The notice lists what firms should be satisfied of:
- The data stays in a secure environment.
- Unauthorised third parties cannot access it.
- It is not used to train models unless that has been explicitly authorised.
- It is not kept for longer than necessary.
The notice is clear that free and paid tools can both fall short, depending on their terms, settings and architecture. Whether a tool passes depends on its contract and configuration, so an enterprise licence needs the same review as a free tool.
The notice also cites an Upper Tribunal decision, UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC). The tribunal found that putting client letters and Home Office decision letters into a public AI tool such as ChatGPT places that information in the public domain. Legal Futures' report of the decision records the panel's view that this breaches confidentiality and waives privilege, and its point that closed tools which keep data private are available for jobs like summarising.
For in-house solicitors the notice adds one more check: whether a tool was built for legal work at all, and whether the organisation's interest in AI conflicts with their professional duties.
Who Owns Each Duty in the SRA AI Warning Notice
The notice names the solicitor, the supervisor and the COLP. It does not say who should own the tool checks or the controls. The split below is how we would allocate them; your firm may draw the lines differently, and that's fine as long as every row has a name against it.
| Duty | Where it comes from | Owner | Evidence worth keeping |
|---|---|---|---|
| Verify every authority and quotation | Code for Solicitors, 2.2 and 2.4 | The fee earner who signs the document | A note of the primary source each citation was checked against |
| Review AI-assisted work before it leaves the firm | Code for Solicitors, 3.5 and 3.6; Code for Firms, 4.3 and 4.4 | The supervising solicitor | A named reviewer for each type of AI-assisted work, with sign-off recorded |
| Systems and controls for AI risk | Code for Firms, 2.1 | Management board or risk partner | A register of approved tools and the work each one is approved for |
| Client data only with safeguards | Codes of Conduct, 6.3 | Head of IT, with the risk team | A written terms review for each tool covering training, retention, location and access |
| Reasonable steps to secure compliance | Code for Firms, 9.1 | COLP | A periodic review of the rows above and a route for staff to report misuse |
The last column matters most on a bad day. If the SRA asks how a fabricated citation reached a court, a policy document is a weak answer. A record showing who reviewed the draft and what they checked is a strong one.
Questions to Ask About Every AI Tool Before Client Data Goes In
The confidentiality test in the notice turns on facts about each tool, and most of those facts sit in the supplier's contract. These six questions cover them:
- Where are prompts, documents and outputs processed and stored, and in which jurisdiction?
- Do the terms allow the supplier to use our data to train or improve models? If training is switched off, is that fixed in the contract or a setting someone could change?
- How long are prompts and outputs kept, and can we set that period ourselves?
- Which of the supplier's staff and subprocessors can access client data, and in what circumstances?
- Does the tool respect the document management permissions and ethical walls we already have?
- Can we export a record of what was asked, what came back and who reviewed it?
If a supplier cannot answer the first four in writing, the firm cannot show it has the safeguards paragraph 6.3 asks for. Questions 5 and 6 go further than the notice, but they decide whether the firm can prove supervision took place.
The same questions apply to the free tools fee earners use on their own phones. A register of approved tools only works if everyone also knows which tools are off limits for client work.
Common Pitfalls
- Treating an enterprise licence as proof the confidentiality test is met, without reading the training and retention terms.
- Leaving AI-assisted work to the general supervision policy, with no named reviewer for AI output.
- Checking citations in court documents while letters, advice notes and client reports go out unchecked.
- Writing an AI policy without a register of which tools are approved for which work.
- Making the COLP accountable without giving them the information: no tool register, no review record and no route for reporting misuse.
How 3Rive Approaches This
Most of the confidentiality test comes down to where a tool runs. Our AI services team builds legal AI tooling, including court-ready redaction, knowledge mining and matter chronologies, inside the firm's own tenant, so firm data never leaves the firm's environment. That turns the terms review in the table above into a short conversation with your own IT team.
Where a firm has not yet mapped its tools and owners, AI Readiness in Five Days through Tech Advisory produces a data-flow map for each tool, named reviewers, a written exclusion list and a costed 90-day plan. We set out what that week covers in AI readiness assessment for law firms. The same habit runs through our delivery work, as in our case management consolidation for a global law firm, where the reconciliation checks were agreed before any data moved.
Key Takeaways
- The SRA published its Misuse of AI warning notice on 17 August 2026, after receiving 42 reports of potential AI misuse between July 2025 and July 2026.
- The notice ties invented content and confidentiality breaches to named paragraphs of the Codes of Conduct, and warns that failing to have proper regard to it risks disciplinary action.
- Supervisors remain accountable for AI-assisted work by junior and unauthorised staff, and the COLP must take reasonable steps to secure compliance.
- Client data should go into an AI tool only with contractual, technical and organisational safeguards covering security, access, model training and retention.
- Each duty in the SRA AI warning notice needs a named owner and a record that shows it was carried out.