The Solicitors Regulation Authority’s warning notice on misuse of AI, published on 17 August 2026, is important partly because of what it does not say. It does not prohibit AI. It does not prescribe a particular architecture. And it does not create a certification called “SRA-compliant AI”.
Instead, the notice brings AI use back to existing professional responsibility. Regulated individuals and firms remain accountable for the work produced, and the SRA highlights two recurring risk areas: inaccurate or fabricated material entering legal work, and confidential client information being exposed through tools without appropriate safeguards.
1. AI does not move professional responsibility elsewhere
The central operational point is straightforward: a solicitor cannot treat the model as the responsible author. If an AI-assisted proposition is used in advice, pleadings, correspondence or submissions, the professional still needs to understand what is being relied upon and whether it is accurate and appropriate.
That makes review a workflow question. It is not enough for a firm to approve an AI product centrally and assume that individual outputs are therefore safe.
2. Verification must be designed into the work
The warning notice refers to fictitious cases, references and apparently factual assertions that can look convincing despite lacking a factual basis. A practical response is to make verification easy: preserve source identity, expose the passage being relied upon, distinguish quotation from inference, and record what the lawyer checked.
This is not a claim that source linkage satisfies the SRA. It is a design response to the professional need to check AI-assisted work.
3. Supervision is more than procurement
Firms need policies, training and controls around approved tools, but supervision also operates at matter level. Questions include who may use the system, what kinds of tasks are appropriate, what information may be entered, what review is required before work leaves the firm, and what happens when the output cannot be verified.
The SRA’s separate announcement accompanying the warning notice reported 42 reports relating to potential misuse of AI between July 2025 and July 2026, including ongoing investigations touching inaccurate citations, supervision and confidentiality. That figure should be described carefully: it is a count of reports of potential misuse, not a finding of 42 breaches.
4. Confidentiality requires factual due diligence
The right question is not “is cloud AI confidential?” in the abstract. A firm needs to know what data is processed, whether prompts or documents may be retained, whether they may be used for training or product development, which subprocessors are involved, where processing occurs, how access is controlled and what contractual protections apply.
The answer may differ by provider, deployment, configuration and matter. That is why absolute assurances such as “privilege guaranteed” or “zero data leakage” should be avoided.
5. Contentious teams need a use-case risk model
Not every task carries the same professional risk. Organising public judgments is different from analysing confidential witness material. Drafting an internal chronology is different from filing a skeleton argument. Summarising an email is different from shaping a witness’s recollection.
A useful policy therefore connects the control to the task: permitted data, source checking, required reviewer, retention, escalation and whether the resulting material may become part of the approved case state.
6. What a disputes team can implement now
- Use only approved systems for client work.
- Classify the task and the sensitivity of the information before use.
- Require authoritative-source checking for legal propositions and case citations.
- Preserve a route from factual propositions back to the matter evidence.
- Keep AI-assisted findings distinguishable from lawyer-approved conclusions.
- Define when outputs may be used externally and who must review them.
- Maintain clear rules for confidential data, retention and provider settings.
- Record incidents and near misses so controls can improve.
7. Avoid the “SRA compliant AI” shortcut
The SRA regulates solicitors and firms, not a marketing label attached to software. A technology can contain controls that support a firm’s compliance programme, but professional compliance depends on the people, matter, process, configuration and use. The more credible vendor language is therefore “designed to support professional verification and oversight”, coupled with specific evidence about the controls that actually exist.
8. Build governance around the life cycle of the work
A useful governance model follows the work from intake to output. Before use: approve the tool, understand provider terms and define permitted data. During use: keep the task within scope, preserve source linkage and apply the required review. Before external use: check factual and legal accuracy, confidentiality and procedural fitness. After use: retain whatever record is needed for supervision, audit or incident review.
This life-cycle approach is more practical than a generic policy saying “AI outputs must be checked”. It tells the practitioner what checking means at each stage.
9. Matter sensitivity should change the control level
A public legal-research query and a confidential witness-analysis task should not automatically be governed identically. The latter may involve privileged or highly sensitive material, a narrower group of authorised users and stronger restrictions on provider processing or retention.
Firms therefore need a risk-based approach that considers both the technology and the matter. The BSB’s 2026 guidance adopts a similar risk-oriented logic for barristers, reinforcing the usefulness of matching controls to the task rather than treating “AI” as one undifferentiated category.
10. Supervision needs observable evidence
A supervising lawyer cannot meaningfully supervise an invisible process. If the system produces a conclusion without showing the material relied upon, supervision becomes dependent on repeating the underlying research or trusting the output.
Source-linked review can make supervision more concrete: the supervisor can inspect the proposition, the sources checked, any contradictory material and the professional decision. That is not a regulatory requirement for a particular architecture; it is a practical way of supporting the existing obligation to supervise legal work effectively.
11. Procurement and professional use should remain connected
Security questionnaires and data-processing terms matter, but they do not answer whether lawyers are using the system well. Conversely, excellent matter-level review cannot cure a provider configuration that mishandles confidential information.
The governance stack therefore has at least two layers: organisational assurance about the provider and system, and professional assurance about the work produced in the matter. Serious adoption needs both.
12. Firms should distinguish policy evidence from matter evidence
A firm may be able to show that it has an AI policy, training programme and approved-vendor process. Those are important governance controls. They are not the same thing as evidence that a particular piece of client work was adequately reviewed.
For higher-risk contentious tasks, supervision should therefore leave matter-level evidence: the source was checked, the legal authority was verified, confidential information was handled under the approved conditions and the responsible lawyer approved the resulting work. This does not require a new bureaucracy around every prompt. It requires proportionate evidence that the important professional step actually happened.
The distinction is useful during incident review as well. If something goes wrong, the firm should be able to ask whether the problem arose from provider configuration, user behaviour, inadequate training, weak review or an incomplete matter corpus. Different causes require different remedies.
Conclusion
The SRA’s 2026 warning does not make AI unusable in contentious practice. It makes the human and organisational responsibilities harder to ignore. The practical response is a reviewable workflow in which source checking, supervision, confidentiality and professional decision-making remain visible.
Related LegalRAG Pro Insights
Professional context. This article discusses legal-technology workflow and professional-risk questions. It is not legal advice and should not be treated as a substitute for checking the current procedural, regulatory and factual position in a particular matter.