Part of the AI Regulation News hub.
The SRA has issued a warning notice on AI misuse, and it says reliance on an AI output is not a suitable defence for false citations put before a court
A warning notice is not a new rule. It is the regulator telling you which existing rules it will reach for, and naming the two things it has already seen going wrong.
Bottom line: Published and operative as guidance. The SRA says of the notice: "We will have regard to it when exercising our regulatory functions." It creates no new obligation. It maps AI misuse onto Principles and Code provisions that already bind you, and states: "If you fail to have proper regard to this warning notice, you are at risk of disciplinary action. We can and will act where we find evidence that solicitors, firms and/or their employees contravene our rules."
Added 21 August 2026: In the news release announcing the notice, the SRA said it received 42 reports related to the potential misuse of AI between July 2025 and July 2026, and that a number of investigations are ongoing. It did not say how many investigations, or what share of the 42 reports led to one.
Who this affects: Every firm and individual the SRA regulates, plus other authorised persons practising within SRA-regulated firms. Supervising solicitors and COLPs carry named exposure of their own, and in-house solicitors get a dedicated warning.
Issue date: Published 17 August 2026. The notice carries a publication date and no commencement date, comment period or transition provision. It is guidance on obligations that are already in force.
Primary sources: SRA Warning Notice: Misuse of AI, 17 August 2026 · SRA news release announcing the notice, 17 August 2026
- Instrument (EN)
- Warning notice, Misuse of AI
- Authority
- Solicitors Regulation Authority (SRA), England and Wales
- Jurisdiction
- England and Wales. Applies to SRA-regulated firms and individuals, and the SRA says it is likely to be relevant to other authorised persons practising within SRA-regulated firms
- Status
- Published 17 August 2026. The notice's own status wording: it is designed to help you understand your obligations and how to comply with them, and the SRA will have regard to it when exercising its regulatory functions
- Bindingness
- The notice creates no new rule. The SRA states it will have regard to the notice when exercising its regulatory functions, and that failing to have proper regard to it puts you at risk of disciplinary action. The binding obligations are the SRA Principles, the two Codes of Conduct and the Authorisation of Firms rules it cites
- Reports received (added 21 August 2026)
- The SRA said it received 42 reports related to the potential misuse of AI between July 2025 and July 2026. These are reports of potential misuse, not findings
- Investigations
- The SRA said a number of investigations are ongoing, covering issues including inaccurate legal citations, supervision and confidentiality. It published no figure
- Provisions cited
- SRA Principles 1, 2, 4, 5 and 7; Code for Solicitors paragraphs 1.4, 2.1, 2.2, 2.4, 2.5, 2.6, 2.7, 3.2, 3.5, 3.6, 6.3 and 7.2; Code for Firms paragraphs 1.4, 2.1, 2.3, 4.2, 4.3, 4.4, 6.3, 8.1 and 9.1; Authorisation of Firms Rule 9.4
- Issue date / next deadline
- 17 August 2026. No deadline; it is guidance on obligations already in force
- Primary source
- https://www.sra.org.uk/solicitors/guidance/misuse-ai/
The two things the SRA says it has actually seen
The SRA names two concerns and organises the notice around them, then works outward into competence, contempt, supervision and in-house conflicts.
The first is court and other documents containing false or incorrect information, including citations, as a result of AI misuse. The notice describes what it calls hallucinations, "generating fictitious cases, references or seemingly factual assertions that may appear convincing despite having no basis in fact."
The second is client confidentiality. The SRA says those it regulates are not fully considering and appropriately mitigating risks when using AI systems, and makes a point that cuts against a common assumption: "Both paid for and free-to-use AI tools may not provide the contractual, and technical safeguards needed to maintain client confidentiality." Paying for the tool does not answer the question.
On how it knows, the notice is unusually direct. It says the SRA has received reports of potential breaches of its Code of Conduct from senior members of the judiciary, and that there have been several instances of solicitors self-reporting after relying on AI tools that generated inaccurate or misleading content.
Added 21 August 2026: the SRA has put a number on the reports
When we published this on 20 August we noted that the notice gave no figure for how much AI misuse the SRA had actually seen, and that we had not found one. The SRA did publish a figure, in the news release that announced the notice on the same day, and we had not read that release.
The SRA said it received 42 reports related to the potential misuse of AI between July 2025 and July 2026. Those are reports of potential misuse. They are not findings, not cases proved, and not a count of solicitors or firms.
The SRA also said a number of investigations into AI misuse are ongoing, covering issues including inaccurate legal citations, supervision and confidentiality. It did not specify how many investigations are under way, or how many of the 42 reports have resulted in a formal investigation. Those are named issue-categories under investigation, not established failures.
The SRA has not published comparative figures for prior years, the proportion of solicitors or firms this represents, or what share of the 42 reports led to formal investigation. So it is not possible to say from this release whether AI misuse is rising, whether reporting awareness is rising, or both. We are not going to tell you that 42 is a large number or a small one, because nothing in the published record supports either reading.
The release also records that the SRA added further sections on AI to its guidance on effective supervision in June 2026. The release states that as a fact alongside the report count. It does not say the guidance was changed because of these reports, and neither do we.
Where the notice puts accountability
One line disposes of the idea that responsibility can move to a tool: "AI has no separate legal personality; solicitors and regulated individuals who use AI in the course of delivering legal services remain accountable for their work and outputs, regardless of how that work has been prepared."
Discussing the Ayinde litigation, it closes the obvious argument: "Reliance on an output of AI would not be a suitable defence in this scenario."
The positive duty is expressed as an assurance standard. To uphold the duty to the court, the notice says, "you should be assured that all submissions of named case law authorities are genuine, relevant, have a verifiable citation, and advance the arguments that are being put forward in your documents."
Existence is only the first of the four. A citation that is real but does not support the proposition fails the same test, and so does one that is genuine and relevant but does not advance the argument it is cited for.
The judgments the SRA cites
R (on the application of Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), which the notice describes as bringing two cases together under the court's Hamid jurisdiction. The solicitor and barrister faced a wasted costs application and were referred to their regulators for conduct the notice calls improper and unreasonable. The SRA quotes paragraph 29 for the proposition that it is "likely to be appropriate for the court to make a reference to the regulator" when a lawyer places false citations before the court, whether or not AI was involved.
UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), where, on the SRA's account, the Tribunal made observations about confidentiality alongside its primary focus on inaccurate AI-generated authorities.
BCP v A Mother [2026] EWFC 71 (B). The SRA describes this as a case in which an unregistered barrister holding herself out as a lawyer misled the court through AI hallucinations. On the SRA's account the court found no deliberate intention to mislead and was still concerned that the person minimised the seriousness. We have not opened the judgment.
Cork and another v Smith [2026] EWHC 1199 (Ch), cited for the courts reiterating the responsibilities on authorised persons where errors are attributable to unchecked hallucinations.
The notice also reaches back to Brett v The Solicitors Regulation Authority [2014] EWHC 2974 (Admin) for the courts' view that misleading the court is "one of the most serious offences that an advocate or litigator can commit".
The confidentiality point, and why it may not be fixable
A hallucinated citation can be corrected once it is caught. On the notice's account a confidentiality breach may not be correctable at all.
It quotes the Upper Tribunal in UK v SSHD at paragraph 21: "to put client letters and decision letters from the Home Office into an open source AI tool, such as ChatGPT, is to place this information on the internet in the public domain."
The SRA's own gloss goes further. Using AI tools in this way, it says, "will likely breach client confidentiality and as a result, legal professional privilege may be permanently waived and unable to be recovered." There is no remediation step offered, because on that reading there is not one.
There is a positive condition for entering client information into any AI system: only where appropriate contractual, technical and organisational safeguards are in place. Firms should satisfy themselves that client data "remains within a secure environment, is not accessed by unauthorised third parties, is not used to train AI models except where explicitly authorised and appropriate to do so, and is not retained longer than necessary".
In-house solicitors get a separate paragraph. The business may have built AI tools that were not designed for legal work, and the notice asks in-house solicitors to consider whether the organisation's interest in furthering its use of AI might conflict with their own duties under the Principles and Code.
Where the exposure actually sits in a firm
Liability is spread deliberately. Supervisors of junior or non-authorised colleagues may be found in breach if false citations reach the court without adequate review, under Code paragraph 3.5, which makes a supervising solicitor accountable for work carried out through others, and paragraph 3.6 on competence of those they manage.
At firm level it cites paragraph 2.1 of the Code for Firms on effective governance structures, systems and controls to manage risks including those arising from AI use, and paragraphs 4.3 and 4.4 on supervision systems. The COLP is named separately under paragraph 9.1, which requires all reasonable steps to ensure compliance including on supervision.
There is one concrete structural requirement worth checking against your org chart. The notice cites Authorisation of Firms Rule 9.4, which requires authorised bodies to have regulated work supervised by at least one person who has practised as a lawyer for at least three years, "whether as a manager, employee or external resource". That last limb is how a small firm satisfies the rule. The SRA adds that while the three-year requirement does not apply to all supervisors, firms should ensure anyone with supervisory responsibilities has appropriate experience.
Read together, the notice is describing a delegation failure. That is why it lands on supervision paragraphs. The notice points to no AI-specific rule.
That reading is consistent with the issue-categories the SRA named in its release when it said investigations are ongoing: inaccurate legal citations, supervision and confidentiality.
What the SRA did not do
It did not make a rule. The notice is explicit that the SRA takes an outcomes-focused approach: "we set the standards we expect solicitors and firms to meet, but we do not prescribe exactly how those standards should be met in different circumstances."
It did not impose a disclosure duty. Nothing in the notice requires a solicitor to tell a client, an opponent or a court that AI was used. The duty it describes is verification and confidentiality.
It did not ban any tool or category of tool, and it says AI "can be a valuable tool and, when used appropriately, can support the delivery of legal services."
What we did not verify
We opened the SRA warning notice in full and every quotation from the notice above is taken from it. We have now also opened the SRA news release of 17 August 2026, and the report count, the reference to ongoing investigations and the June 2026 supervision-guidance update come from that release.
The 42-reports figure is the SRA's own account of its own caseload. We report that the SRA said it, which is what the release establishes. We have not independently verified the count, and nothing confirms it is complete or representative.
We still do not know how many investigations the SRA has opened. The release says a number are ongoing and gives no figure, so no number should be inferred from the 42.
We did not open the five judgments the notice cites, so where we describe Ayinde, UK v SSHD, BCP v A Mother, Cork v Smith or Brett, we are reporting the SRA's characterisation of them and the passages the SRA itself quotes, not our own reading of the judgments.
We did not open the SRA's effective-supervision guidance, so we report only that the release says AI sections were added to it in June 2026.
We make no claim about whether the Bar Standards Board, the CLC or CILEX have issued or will issue anything equivalent. The notice links to BSB guidance but we have not opened it.
The SRA has not made an AI rule. It has told you which existing Principles and Code paragraphs it will use, that AI has no separate legal personality so accountability does not move, and that reliance on an AI output is not a defence. The verification standard is four-part: genuine, relevant, verifiable citation, and actually advancing your argument. On confidentiality, the notice treats privilege waiver as potentially permanent, so which tool a firm allows is a supervision question. The SRA has now said it received 42 reports of potential AI misuse in twelve months and that investigations are ongoing, without saying how many.
Source File
https://www.sra.org.uk/solicitors/guidance/misuse-ai/
Open the SRA warning notice of 17 August 2026 and confirm the publication date, the status wording about having regard to it when exercising regulatory functions, the sentence that AI has no separate legal personality, the four-part assurance standard for cited authorities, the Upper Tribunal quotation at paragraph 21, and the list of Principles and Code paragraphs cited. Then open the SRA news release of the same date and confirm the sentence giving 42 reports between July 2025 and July 2026, the reference to a number of ongoing investigations with no figure attached, and the statement that AI sections were added to the effective-supervision guidance in June 2026.
AI has no separate legal personality; solicitors and regulated individuals who use AI in the course of delivering legal services remain accountable for their work and outputs, regardless of how that work has been prepared. ยท SRA Warning Notice, Misuse of AI, 17 August 2026
FAQ
Does the SRA warning notice create a new rule for solicitors using AI?
No. It creates no new obligation. It explains how the existing SRA Principles, the Code of Conduct for Solicitors, the Code of Conduct for Firms and the Authorisation of Firms rules apply to AI use. The SRA says it will have regard to the notice when exercising its regulatory functions, and that failing to have proper regard to it puts you at risk of disciplinary action.
How much AI misuse has the SRA actually seen?
In the release announcing the notice, the SRA said it received 42 reports related to the potential misuse of AI between July 2025 and July 2026, and that a number of investigations are ongoing covering issues including inaccurate legal citations, supervision and confidentiality. It did not say how many investigations, or how many of the 42 reports led to one. It has published no prior-year comparison and no proportion of solicitors or firms, so the figure does not by itself show a trend.
Can a solicitor rely on the AI tool being at fault?
No. The notice states that AI has no separate legal personality and that regulated individuals remain accountable for their work and outputs regardless of how the work was prepared. Discussing the Ayinde litigation it says reliance on an output of AI would not be a suitable defence.
What does the notice say about putting client information into AI tools?
It quotes the Upper Tribunal that putting client letters into an open source AI tool places the information in the public domain, and says this will likely breach client confidentiality with legal professional privilege potentially waived permanently and unable to be recovered. It says both paid and free tools may lack the necessary contractual and technical safeguards, and that client information should only be entered where appropriate contractual, technical and organisational safeguards exist.
Related briefings
Sponsored Training
Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.