The SRA's warning notice of 17 August 2026 confirms that using AI does not move responsibility away from the solicitor. It targets two failures: false citations reaching a court, and client data entered into public AI tools. Firms need appropriate contractual, technical and organisational safeguards, effective supervision, and records showing what was actually checked.
What is the SRA Misuse of AI warning notice?
The Solicitors Regulation Authority published Misuse of AI as a warning notice on 17 August 2026. A warning notice does not create new rules. It tells you how the regulator reads obligations you already hold, once a particular risk starts appearing in real files, and it becomes the reference point if your firm later has to explain itself.
The position is plain. AI has no separate legal personality. It cannot hold a practising certificate, owe a duty to the court, or answer to a tribunal. Responsibility therefore does not move anywhere. Whatever drafted the words, the solicitor who puts them in front of a client or a judge owns them.
Which two failures does the notice target?
Fabricated authorities reaching a court, and client information going into a public AI tool. Both have already happened in England and Wales, which is why this notice exists rather than a general statement of principle.
On the first, the duty is unchanged. You put forward only properly arguable submissions, and any named authority should be genuine, relevant, verifiably citable and actually supportive of the argument you are making. A case reference produced by a language model and never opened satisfies none of that. The notice makes clear that relying on the tool is not a defence, and courts have shown they will refer practitioners to their regulator.
On the second, the notice leans on the Upper Tribunal (Immigration and Asylum Chamber) in a judgment reported as [2026] UKUT 81 (IAC), handed down on 17 November 2025. The tribunal held that uploading confidential documents into an open source tool such as a consumer chatbot is "to place this information on the internet in the public domain", breaching confidentiality and waiving privilege. It added that a regulated professional or firm that has done this would be advised to consult the Information Commissioner's Office. If you have not read that judgment, read it before you write your policy. I have set out the verification side of it separately in this piece on the High Court, hallucinated citations and SRA referral.
What safeguards does the notice require for client data?
Client information should only be entered into an AI system where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality. Three words, chosen deliberately, and a firm needs an answer under each of them.
Contractual: what the provider's terms actually permit. Retention periods, whether inputs or outputs can be used to improve the tool, sub-processors, governing law, and what happens to your data on termination.
Technical: where the data physically sits, who at the provider can reach it, whether prompts and responses are logged, and whether anything crosses a border.
Organisational: which people may use which tool for which category of work, who approves an exception, and how you find out when somebody uses something unapproved.
The notice also closes a gap firms walk into. Paid systems and free systems can both create confidentiality risk, because retention and reuse depend on the provider's terms, its settings and its technical architecture. Buying a business licence is not, on its own, an answer to the question the regulator is asking.
Who is accountable when AI output goes wrong?
The named solicitor first. Then whoever was supposed to be supervising. Then the firm, through its managers and its Compliance Officer for Legal Practice. That distribution is the whole point of the notice, and it is why the drafting tool's reputation is not a mitigating factor.
This changes what a vendor can honestly sell you. A contractual indemnity may cover a financial loss. It does not move a regulatory finding. No supplier, including us, can take on your accountability, and a supplier implying otherwise is describing something that does not exist. So the procurement question is not whether the vendor stands behind the output. It is whether the tool leaves you able to show what happened.
What supervision does the notice expect?
Supervision that actually occurs and can be evidenced. Under rule 9.4 of the SRA Authorisation of Firms Rules, regulated work has to be supervised by at least one person who has practised as a lawyer for at least three years, and the SRA's effective supervision guidance expects supervision to be effective rather than nominal.
The Upper Tribunal went further, and it is worth reading alongside the notice. Where a junior lawyer files false citations, the supervisor who did not check may be the more culpable party, because the failure is one of development as well as review. Assume a regulator will reason the same way.
In practice, supervising AI-assisted work means the supervisor can see more than a polished draft. What was the tool asked, what did it return, what did the fee earner change, and what was independently checked against a real source? If the only artefact is the finished document, you are reviewing the output of a process nobody watched.
What records should a firm keep?
Enough to reconstruct a decision months later without relying on anybody's memory. The SRA's compliance tips for solicitors, updated 9 February 2026, expect risk and impact assessments, written policies and procedures, staff training, monitoring, oversight from the COLP and the board, and security practice in line with the National Cyber Security Centre.
A workable minimum looks like this. The approved tool list, and what each tool may be used for. The due diligence behind each approval, including which version of the provider's terms you relied on and the date you read them. Which matters used which tool. What was verified before anything left the firm, by whom, and against what source. Every incident, and what changed afterwards.
One uncomfortable detail. Records a firm can quietly amend later are worth less than records it cannot. If your log of checks lives in a system your own administrators can rewrite, it evidences your process but says nothing about the integrity of the log itself. That gap only matters once, and it matters at the worst possible moment.
How do firms meet this without banning AI?
A ban does not survive contact with a deadline. Fee earners use their phones instead, and the firm loses the benefit and the visibility at the same time. The route through is to put the work somewhere the safeguards are demonstrable rather than asserted, which is the argument for sovereign AI in a regulated practice.
That is what we build at Mickai LTD (Companies House 17166618). The Mickai Sovereign Intelligence Operating System runs on hardware the customer owns. It is offline capable, with no data egress, so the contractual and technical questions stop being a supplier's promises and become facts about your own estate. There are 63 studios in total, 14 production-ready at launch and 49 in development, with 50 specialised models behind them. Consequential actions wait for a named person to approve them, which is supervision expressed as software rather than as a policy nobody reads. The design is covered by 104 filed UK patent applications carrying 2,340 claims.
Records are the part a regulator will actually test. The Open Audit Record seals every consequential action under ML-DSA-65, the post-quantum signature scheme NIST published as FIPS 204 in 2024. An auditor exports a record and verifies it offline with a public key, using tools that are not ours. It is tamper-evident, not tamper-proof, and that distinction is the product. We cannot stop somebody altering a sealed record. We can make verification fail when they do, which is exactly what you need when the question is whether your own account of events holds up.
On document handling I will not overstate where we are. A local OCR runtime has read scanned PDFs in controlled tests. Extraction and ingestion integration into SIOS is still being completed, so scanned bundles are not something I would put on a firm's critical path this quarter. What does work today is querying a firm's own material through private knowledge bases that never leave the estate.
None of this is an argument against the companies building compute or cloud infrastructure. Cloud remains the right answer for plenty of non-regulated work, and we are not competing with that layer. The assumption worth rejecting is narrower: that a regulated organisation must rent its intelligence, send privileged material offsite and accept a vendor's account of what happened to it.
Finally, the thing no supplier should say to you. Running AI on your own servers does not make you compliant, and the SRA certifies nothing and endorses nobody. Owned infrastructure removes one class of question. Supervision, verification and records remain yours. Our closed beta is open, with one regulated company onboarding as a design partner.
Frequently asked questions
Delete this FAQ entry (the date and the compliance-tips reference are already covered in the answer-first block and the first H2 section), leaving five questions.
The Solicitors Regulation Authority published it on 17 August 2026, under the title Misuse of AI. It is a warning notice rather than new regulation, so it explains how existing obligations apply when AI is used in legal services. Read it alongside the SRA's compliance tips for solicitors, updated 9 February 2026.
Does the notice ban law firms from using AI?
No. It does not prohibit AI use. It sets conditions: client information only goes into systems with appropriate contractual, technical and organisational safeguards, submissions and authorities are verified before they reach a court, and work is effectively supervised. The regulator's concern is unchecked use and confidentiality loss, not the technology itself.
What safeguards does the SRA expect around client data?
Appropriate contractual, technical and organisational safeguards before client information enters any AI system. Check what the provider's terms permit on retention and improving the tool, where data sits and who can reach it, and which staff may use which tool for which work. Paid and free systems can both retain or reuse data.
Who is accountable if AI produces a false citation?
The solicitor who put it forward, and then whoever supervised them. AI has no legal personality, so responsibility stays with regulated people. Relying on the tool is not a defence. The Upper Tribunal has indicated that a supervisor who failed to check a junior's citations may be the more culpable party.
Do we need a written AI policy to satisfy the notice?
Effectively, yes. The SRA's compliance guidance expects written policies and procedures, risk assessments, training, monitoring and COLP oversight, and a policy is how you show which tools are approved for which work. A policy alone is not enough: you also need dated evidence that verification and supervision actually happened.
Does running AI on our own servers make us SRA compliant?
No. Owned, offline infrastructure removes a set of questions about data egress, provider terms and third-party access, which is why it helps with the confidentiality limb. It does not create compliance. The SRA certifies no tool. Accountability stays with the named solicitor and the COLP, and supervision and verification remain your job.
Written by Micky Irons, founder and chief executive of Mickai LTD, which builds a sovereign AI operating system for regulated organisations. More at mickai.co.uk.
Top comments (0)