What happened
The Solicitors Regulation Authority, the independent regulator for solicitors and law firms in England and Wales, has issued a warning about the misuse of artificial intelligence in legal practice. The guidance highlights risks around confidentiality breaches, inaccurate outputs presented as legal advice, inadequate supervision of junior staff using AI tools, and the absence of clear firm-level policies governing when and how generative AI may be used on client matters.
The SRA's intervention follows reported incidents where solicitors submitted court documents containing hallucinated case citations generated by AI, disclosed client confidential information through public AI chat interfaces, and delegated substantive legal analysis to tools without competent review. The regulator has signaled that existing principles in the SRA Code of Conduct: competence, confidentiality, honesty, and proper supervision: apply fully to AI-assisted work.
Why this is a GRC story
Three things make this regulatory signal worth studying across sectors.
First, principle-based enforcement precedes specific rules. The SRA has not published a dedicated AI rulebook. It has applied existing conduct rules to a new technology context. This is the model most professional regulators will follow: accountancy, medicine, financial services, architecture. They will not wait for an AI Act equivalent. They will map current professional obligations to AI use cases and enforce against the gaps. GRC teams in regulated professions should assume their regulator is already doing the same mapping.
Second, the supervision gap is the enforcement target. The SRA's emphasis on supervision of junior staff using AI reveals the real compliance failure mode. It is not the technology. It is the governance layer that should sit between the tool and the client deliverable. Firms that have rolled out Copilot or ChatGPT Enterprise without updating supervision protocols, file review checklists, and training requirements have a governance gap that their regulator can see.
Third, confidentiality in the prompt layer is a data protection issue. When a solicitor pastes client matter details into a public LLM interface, that is a personal data breach under UK GDPR and a breach of professional confidentiality. The SRA treats it as both. For GRC teams, this means AI governance must include technical controls: approved tool lists with data processing agreements, network-level blocks on unapproved AI domains, prompt logging for audit, and clear escalation paths when staff inadvertently expose protected data.
What GRC teams should take from this
Audit your professional obligations through an AI lens. For each regulatory rule or conduct principle that applies to your organization, ask: how does generative AI change the risk profile of compliance with this rule? What controls are missing? Document the answers. That document becomes your AI governance framework, and it should exist before your regulator asks for it.
Implement a three-tier control model: technical (approved tools with contractual protections, blocks on unapproved tools), procedural (prompt hygiene training, mandatory review checkpoints, client consent protocols for AI-assisted work), and accountability (named AI governance owner, incident reporting for AI-related breaches, board-level visibility on AI risk). The SRA has effectively mandated this model for law firms. Other regulated sectors should treat it as the emerging standard.
Attribution: Analysis based on Infosecurity Magazine and related public reporting. This article is original commentary, not a repost of the source material.
