Your firm has no SRA rule about artificial intelligence to comply with, and that is what makes the compliance work awkward. There is no paragraph headed AI and no approval to seek before a fee earner opens a tool. What exists instead is a set of duties written before these products arrived, a warning notice naming them, expanded supervision guidance and a tribunal decision. This guide turns that material into a checklist you can work through in an afternoon, alongside the companion guide on writing an AI use policy.

Why the SRA's position changed in 2026

For two years the regulator encouraged rather than warned. Its compliance tips for solicitors on AI and technology, updated on 9 February 2026, read as advice you were free to reach later. On 17 August the SRA issued a warning notice on the misuse of AI, a different category of document. Guidance explains what the rules mean. A warning notice sets out the conduct the regulator expects and states that a firm failing to have proper regard to it risks disciplinary action. It arrived with the figure explaining its timing, 42 reports of possible AI misuse received between July 2025 and July 2026.

Three days later came the fourth annual assessment of continuing competence. Competence related reports had risen from 2,720 in 2024 to 4,038 in 2025, and the SRA recorded that it now assesses whether a solicitor is aware of and uses warning notices, guidance and the Statement of Solicitor Competence when planning their learning. The newest item your training record is read against is therefore the notice published three days earlier.

Then the tribunal spoke. On 3 September 2026 the Solicitors Disciplinary Tribunal published its judgment in case 12884-2026, Solicitors Regulation Authority v Abhishek Kumar, the first time a lawyer's use of artificial intelligence in legal proceedings had been litigated before it. Kumar, a registered foreign lawyer, filed a written Answer carrying citations that were wrong and authorities relied on for propositions they did not support. When the regulator pointed him to Ayinde v Haringey LBC [2025] EWHC 1383 (Admin), his reply the next day was drafted with the same kind of tool and carried fresh errors. He told the regulator he lacked the expertise to verify the output. Dishonesty was not alleged and he was acting for himself, and he was struck off, the tribunal recording that it would have imposed the same sanction had the AI allegation stood alone.

Underneath all of it, the SRA had rewritten its supervision guidance and expanded it from nine pages to twenty-four, with the core statement that firms can use AI tools provided an authorised individual remains accountable for the work produced. Nobody is asking your firm to stop. Everybody is asking it to show what sits behind the use.

How the SRA regulates AI without an AI rule

The Standards and Regulations do not mention large language models and do not need to. The SRA Principles require you to act with integrity, in a way that upholds public trust, and in the best interests of each client. None of that alters because a machine produced the opening draft, and if a tool leads to wrong advice the responsibility rests with the solicitor.

The Codes carry the detail. The Code of Conduct for Solicitors expects a competent service, knowledge and skills kept up to date, and confidentiality held as strictly as you remember it, while the Code of Conduct for Firms carries the supervision and governance duties above the desk. The warning notice names those same paragraphs, being competence, effective systems for supervising client matters, governance and controls, and confidentiality.

It then ties each to a failure the regulator keeps meeting. False material reaching a court comes first, with the flat requirement that every authority put before a judge is checked as genuine and accurately cited before filing. Client information comes second, with contractual, technical and organisational safeguards expected before client material enters any tool, and the blunt observation that paid products as much as free ones store what you type or train on it. Supervision comes third, because the supervisor of a junior answers for the output as fully as the person who wrote the prompt.

Aileen Armstrong, the SRA's executive director for strategy and policy, framed the expectation as firms and solicitors having appropriate oversight and controls in place, which is a question about your arrangements rather than your software.

Competence and supervision

1. Establish what your people are using now

Find out which tools are in use and for what, asking each fee earner and secretary directly and counting the assistant inside software you pay for. The answer runs wider than the partners expect, because these tools arrive in a browser tab rather than through a procurement decision. Good looks like one sheet naming each tool, its users and whether it is approved.

2. Set what competence means for each person who uses a tool

Competence now takes in a working understanding of the tools your firm relies on, enough to know what they do well and where they fail. What takes longer than the software is knowing when confident output is wrong, and Kumar shows the alternative, because a lawyer who cannot verify an authority should not be citing it.

3. Name an accountable individual for every piece of AI assisted work

The word the expanded guidance keeps returning to is accountable, meaning that when the work is done a specific authorised person is answerable for it and knows they are. That is an arrangement made in advance, and the exposure the SRA has moved to close is the one where responsibility drifts across desks. Good looks like a named owner on the file before drafting starts.

4. Make the sign off real rather than nominal

The line the guidance draws is between supervision that is real and supervision that is nominal, being a name on a file and a signature at the end with no genuine check between them. Your supervisors need to look for the failure modes these tools bring, being confident wording that misstates the law and citations that do not exist. Good looks like sign off by someone who knows which tool was used.

Confidentiality and client data

5. Read the retention and training terms of everything already in use

Every prompt carrying client information is a disclosure to whoever runs the service behind the tool, and consumer products often store that text and train on it. Four questions settle whether a tool belongs near a matter. Does the contract say client data will not train the provider's models, where is the data processed, who inside the provider can reach it, and is there a data processing agreement meeting the UK GDPR.

6. Decide what staff put into a tool, and write it down

Staff need to know which tools they are allowed to use, for what, and what they must never do, such as putting client identifiers into an unapproved tool. Written boundaries are easier to supervise than a vague sense of caution, and they are the organisational half of the safeguards the notice expects. Good looks like a short prohibition list covering case detail and special category material.

7. Deal with the meeting recorder before it deals with you

An AI note taker that joins a video call records a confidential and often privileged conversation and sends it to a provider to process. Paralegals run them in client calls whether or not the partners have decided anything, because the tool is free and the transcript is useful. Good looks like an approved recorder on firm terms, a rule on when the client is told, and a retention decision.

Client care and disclosure

8. Put the general position in your client care information

The SRA expects a firm to make clear where a client is interfacing with AI. No rule forces a running commentary on background drafting a fee earner checks and owns, but the retainer should not mislead the client about how the work is done. Good looks like a sentence in the standard letter saying the firm uses approved tools while a solicitor remains responsible for the advice, and a short note where AI does more than sit in the background.

9. Train your people to answer a direct question honestly

Clients ask, and the answer a fee earner gives on the telephone is the firm's answer. Explain what the tool does, that the client's information is protected, and that a person checks the output. Good looks like an agreed form of words, so a trainee's answer matches the senior partner's.

Court work and verification

10. Check every authority against the report itself

Treat every citation, quotation and figure from a general model as unverified until a person confirms it against a real source, because a model predicts what tends to follow what and holds no index of cases. In R (Ayinde) v London Borough of Haringey a Divisional Court dealt with submissions citing authorities that did not exist and referred the lawyers responsible to their regulators. Good looks like a named person who opens the authority and reads the passage.

11. Do not let one tool check another

Running an output through the same or another AI tool does not amount to checking it, a point the Irish High Court put in a practice direction in operation from 1 September 2026 that English firms should adopt. Kumar shows the cost, because the second round of errors came from repairing the first with the same tool and the tribunal weighted that repetition heavily. Good looks like corrections written by hand.

12. Extend the rule to your correspondence with the regulator

Kumar's second failure happened in an email to the SRA rather than in a document filed at court. The duty to put forward only what is properly arguable runs through correspondence with the regulator as surely as through pleadings. A firm that checks court documents but not its replies has covered half the ground.

13. Record that the check happened

A verification habit that leaves no trace protects the client and proves nothing, and the regulator's interest is in what you can show. Recording it also makes the step harder to skip, because the drafter is least able to see the fabrication. Good looks like a fixed place on the file naming who checked and when.

Governance and the compliance officers

14. Assess a tool before you adopt it, not after

The SRA expects proper oversight when new technology comes in, with the compliance officer answerable for it and a risk and impact assessment before a tool is adopted rather than afterwards. The ICO expects a data protection impact assessment where processing is likely to pose a high risk to individuals, and matter files are dense with personal data. Good looks like a short written assessment of what the tool does with client data and who signed it off.

15. Work out whether the compliance officer split reaches you

The Legal Services Board granted the SRA's application on consumer protection with effect from 31 July 2026. New rules 8.4 to 8.7 of the Authorisation Rules stop an owner or manager who can unilaterally direct the running of the firm from holding the compliance officer roles once it passes a turnover threshold of £600,000 in the most recently completed accounting period, or a client money threshold of a maximum balance above £2,000,000 at any point in that period. The SRA estimates that around 4,100 firms, some 45 per cent of the sector, fall within the criteria.

This lands on your AI arrangements because the compliance tips put the COLP at the centre of technology, and in an owner-managed firm the owner and the COLP have been one person. Guidance follows this autumn and the changes phase in during early 2027. Good looks like writing down what the owner has been carrying before the handover loses it.

16. Give the compliance officer authority to match the title

These rules exist because the SRA found people overseeing and reporting on their own decisions, and a COLP who cannot stop the owner buying a tool reproduces that problem. The buying decision stays with the owner, while the job of showing the SRA that the firm's AI use meets its obligations moves. Good looks like a written rule that a new tool reaches the COLP before anyone signs for it.

Insurance and risk

17. Answer the proposal form with documents rather than assurances

Brokers and underwriters at the Law Society risk and compliance conference in March treat a firm's use of AI as a live underwriting question bearing on the terms you are offered. One delegate poll found 14 per cent describing AI at their firm as allowed but largely unmanaged, a figure the insurers in the room called alarming. Good looks like the policy, the tool record and the training evidence handed over as a short pack.

18. Close the accountability gap the market has noticed

Asked at the same session who is responsible for managing AI use, almost half of those polled pointed to the individual fee earner and only around a quarter to the supervising or managing partner. For a regulated firm that is the wrong way round, and an underwriter reads it as weak control. Good looks like an answer the partners agree and record.

Records and evidence

19. Build the training record the SRA now reads

The regulator reviewed 123 training records from criminal and civil practitioners across 66 firms for its 2026 assessment. Almost every one was current, and almost half failed to explain how the learning need was identified, which is what turns a list of sessions into evidence of reflection. The SRA has consulted on a rule requiring every solicitor to record how learning needs were identified and addressed, intended to start with the 2027/28 practising year subject to approval by the Legal Services Board.

20. Fix a review date and treat warning notices as triggers

The documents governing this area moved four times in a single year, so a firm reviewing its arrangements annually and no more will always be reading last year's position. Add triggers that bring the review forward, being a new warning notice, a new model handling client data or a change of supplier, and keep that date beside the training record.

What the SRA will ask to see

The regulator's questions follow the same fault lines as the warning notice, and none is about your choice of software. Expect to be asked which tools your people are permitted to use and for what, what assessment was done before each was adopted and who signed it off, and what staff are told they must never put into a tool. Expect a question about the supplier terms on retention and training.

On the work itself, expect to be asked who was accountable for a piece of AI assisted output and how the sign off was recorded, and on court documents who checks that an authority is genuine and accurately cited. Every one of those questions is answered by a document or it is not answered at all.

Common questions

Is there an SRA rule about artificial intelligence?

No, and there does not need to be. The Standards and Regulations do not mention large language models, and the rules governing how you run a file already reach every tool you use to run it. The warning notice of 17 August 2026 names the paragraphs of the Codes in play, being competence, effective systems for supervising client matters, governance and controls, and confidentiality.

Who answers for AI assisted work, the fee earner or the supervisor?

Both. The warning notice states that the supervisor of a junior who used the tool answers for the output as fully as the person who wrote the prompt. The expanded supervision guidance puts it positively, that an authorised individual must remain accountable for the process and for the work produced. Name that person before the work starts rather than after a complaint.

Does a firm have to tell clients that it uses AI?

The SRA expects a firm to make clear where a client is interfacing with AI. No rule forces a blanket disclosure of every background use. A sentence in your client care information, saying the firm uses approved AI tools to support its work while a solicitor stays responsible for the advice, covers the general position and lets a client raise a concern at the outset.

What happens to a solicitor who files AI generated authorities?

The Solicitors Disciplinary Tribunal struck off Abhishek Kumar in a judgment published on 3 September 2026, the first time a lawyer's use of AI in legal proceedings had been litigated before it. He put fabricated authorities before the tribunal, corrected them with the same kind of tool and introduced fresh errors, and told the regulator he lacked the expertise to verify the output.

Where to go next

Work the twenty items against your own firm and mark each done, partly done or not started. Where the answer is a document you do not hold, the guide to writing an AI use policy covers most of them in an afternoon's drafting. Where you want the duties mapped to your tools, there is the AI Governance and Regulatory Mapping engagement, and where you do not know what your people use, the AI Readiness Audit finds out first. If you would rather talk it through, get in touch. Adliora Limited is a management consultancy rather than a law firm, and a question needing formal legal advice should go to your regulated adviser.