A bright office corridor with glass walled rooms and open glass doors

Whistleblowing became part of your AI risk on 2 June, and few firms have noticed. On that day the Solicitors Regulation Authority became a prescribed person under the Public Interest Disclosure Act 1998. Anyone who works for or with a regulated firm, including paralegals, clerks, trainees and agency workers, can take a concern to the regulator and keep the protection of employment law while doing it. The Law Society Gazette reported on 18 September that the confidential red alert line opened alongside the designation has taken 85 calls, of which 37 met the criteria and led to enquiries or investigations.

Who sees the mistake first

The person who finds an AI failure in your firm is almost never the partner who owns the file. It is the trainee who checked a citation and found no such case. It is the paralegal who watched a colleague paste a client's medical records into a free chatbot to get a summary by lunchtime. It is the secretary who noticed that an attendance note describes a meeting nobody attended. Before June, raising any of that carried a career cost and no cover. Now the same person has a route to the regulator, and dismissal or detriment for taking it is unlawful.

Read that as a change in arithmetic rather than a change in morals. Your staff always knew what they were looking at. What has moved is the price of saying so, and it has moved in one direction.

Make your own route the easy one

A report to the SRA does not sink a firm on its own. What does the damage is a report you knew nothing about, written by someone who felt they had no choice, arriving as the first account of your practice the regulator ever reads. The defence against that is an internal route people trust enough to use first.

Name a person rather than a role, and make sure it is not the supervisor whose file is in question, because a concern about AI use is usually a concern about somebody's supervision. Give a deadline for the reply and keep it short, because silence is what sends people elsewhere. Write down what happens after a report lands, who looks at the file, what record survives, and what the person who raised it gets told. Then say all of it out loud at a team meeting, because a policy nobody has heard of protects nobody.

Treat the substance as a compliance question and never as a performance question about the reporter. A fabricated authority in a draft is a file problem with a client on the other end of it. Client data in a public tool is a data protection problem with its own clock running. Your own duty to report a serious breach stands whichever way the concern reaches you, and a breach you report yourself reads differently from the same breach reported about you.

Ask one question before Friday. If a trainee at your firm found an invented case in a partner's draft this afternoon, who would they tell, and what would happen next? A firm that cannot answer both halves has already chosen the red alert line by default.

The SRA set out the designation and what it protects on 2 June, and the release is open to any reader at the Solicitors Regulation Authority.

If you want an internal reporting route that works on the day it is needed, written by someone who has run a firm and judged the results of the ones that did not, start with a conversation.