What happened

The Solicitors Regulation Authority (SRA), the regulator for the legal sector in England and Wales, published a warning notice on August 17 reminding solicitors and law firms of their obligations when using AI. The notice names two areas of concern: AI hallucinations appearing in legal work and court submissions, and confidential client information being entered into public AI tools.

The SRA said it has seen both solicitors self-reporting incidents and reports of potential breaches of its Code of Conduct from senior members of the judiciary. Its guidance is clear that putting AI-generated false material before a court could be treated as contempt of court, and that entering client information into a public AI tool will likely breach client confidentiality, whether the tool is free or paid. Supervisors of junior or non-authorized colleagues could also be held responsible if false citations reach the court through that chain.

Why this is a GRC story

This is a regulator doing exactly what a regulator should do: naming the risk, stating the duty, and leaving the how to the profession. The SRA is outcomes-based, so the notice does not ban AI. Instead it says solicitors remain accountable for AI output, firms need effective governance structures, systems and controls for AI risk, and client data must stay inside a secure environment with contractual, technical and organizational safeguards in place.

For anyone running a firm that touches sensitive data, the pattern is familiar. The technology moves faster than the policy, and the gap shows up in the same two places every time: professionals trusting model output they cannot verify, and data flowing into tools nobody approved. The SRA is telling the sector that accountability does not transfer to the software vendor. It stays with the person who signs the submission.

The human oversight point matters too. The notice explicitly calls for proportionate, risk-based approaches and informed professional judgment. That is the language of risk management, not prohibition, and it gives compliance teams room to build practical controls instead of chasing a ban.

What to watch

Watch how the SRA follows this with enforcement. Warning notices are the polite stage; the question is which firm becomes the example. If you work in a regulated profession, treat this notice as a template: name your high-risk AI uses, decide where human review is mandatory, and map which tools your people are actually using with client data. The regulator just told you what good looks like.

Attribution: Analysis based on Infosecurity Magazine's reporting and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News