← Insights / Compliance

SRA issues AI misuse warning after 42 reports: how UK professional services firms face heightened regulatory scrutiny

The Solicitors Regulation Authority has issued a formal warning notice on AI misuse following 42 reports of potential wrongdoing received between July 2025 and July 2026. Several investigations remain ongoing. This is not a hypothetical risk scenario or a forward-looking caution — it is active regul

Compliance 26 August 2026 6 min read

SRA Issues AI Misuse Warning After 42 Reports: What UK Professional Services Firms Must Do Now

The Solicitors Regulation Authority has issued a formal warning notice on AI misuse following 42 reports of potential wrongdoing received between July 2025 and July 2026. Several investigations remain ongoing. This is not a hypothetical risk scenario or a forward-looking caution — it is active regulatory enforcement, and it signals something important for professional services firms well beyond the UK's borders.

If your firm uses AI in client-facing work, internal decision-making, or document production, the question is no longer whether you need an AI compliance framework. It is whether the one you have is sufficient to withstand scrutiny.

What the SRA Found — and Why It Matters

The 42 reports centre on three recurring failures: inaccurate legal citations generated by AI tools, inadequate supervision of AI-assisted work product, and confidentiality breaches arising from how AI systems were used with client data.

UK court judgments from 2025 have made the consequences concrete. In Ayinde R (On the Application Of) v Qatar National Bank QPSC & Anor EWHC 1383 (Admin), a legal team cited five fictitious cases produced by an AI system. The President of the King's Bench Division issued guidance in response. These are not isolated incidents of individual carelessness — they reflect a systemic gap between the pace at which AI tools have been adopted and the governance structures put in place to manage them.

The SRA's warning notice is unambiguous on one point: using AI does not reduce a solicitor's professional responsibilities. The same standard of care, supervision, and accountability applies regardless of which tool generated the output. That principle extends, with local variation, to accountants, HR consultants, marketing agencies, and every other professional services category operating under a regulated framework.

The Regulatory Landscape Is Hardening

The SRA warning sits within a broader regulatory tightening that firms operating internationally need to understand in full.

The Data (Use and Access) Act 2025 (DUAA), which came into force on 19 June 2025, has modified how the UK GDPR applies to automated decision-making. The framework has become more permissive in some respects, but it has also introduced new individual rights safeguards that organisations must implement. The two effects do not cancel each other out — they require careful analysis of where your AI systems sit within the revised rules.

The Information Commissioner's Office (ICO) is developing a statutory Code of Practice on AI and Automated Decision-Making, with final guidance anticipated in Summer 2026. This code will be particularly significant for any organisation using automated tools in recruitment and workforce decision-making. The ICO's "Recruitment Rewired" report, published ahead of the code, identified substantial compliance gaps in how automated decision-making is currently being used in HR — gaps that will become indefensible once the code is in force.

Separately, the ICO updated its guidance on generative AI and web-scraping in December 2024, refining its position on legitimate interests as a legal basis for training AI models on web-scraped data. The updated guidance places significant emphasis on transparency, with particular concern for what the ICO calls "invisible processing" — situations where individuals have no knowledge that their data is being used to train AI systems. For professional services firms using third-party AI tools, this creates a due diligence obligation: you need to understand what the tools you rely on are doing with the data you feed them.

Enforcement Is Already Happening

The ICO's enforcement posture on AI is not theoretical. In February 2026, the ICO launched a formal investigation into xAI regarding the processing of personal data in the creation of non-consensual sexualised imagery by Grok. Potential fines could reach £17.5 million or 4% of annual worldwide turnover, whichever is higher. The Clearview AI case, in which the ICO is pursuing an appeal against an overturned penalty, further demonstrates that the regulator will sustain enforcement action through protracted legal challenges rather than abandon it.

For professional services firms, the relevant enforcement signal is not the scale of these cases but the pattern they reveal: the ICO is actively investigating AI systems that process personal data without adequate legal basis, transparency, or safeguards. If your firm uses AI tools that touch client data, employee data, or any other personal data, that is precisely the territory the ICO is focused on.

The International Dimension

Firms operating outside the UK should not read this as someone else's problem. The regulatory direction is consistent across multiple jurisdictions, even where the specific instruments differ.

In the EU, the AI Act is introducing tiered obligations based on risk classification, with high-risk applications — including those used in employment, legal services, and financial decision-making — subject to the most demanding requirements. Firms with EU operations or EU data subjects need to be mapping their AI systems against those classifications now.

In North America, Canada's Artificial Intelligence and Data Act (AIDA) is progressing through legislative process, and US state-level AI legislation is accelerating, with Colorado, Texas, and Illinois having enacted or advanced measures targeting automated decision-making in employment and consumer contexts. In the Middle East, the UAE's AI regulatory framework continues to develop, with sector-specific guidance emerging from financial and legal regulators.

The common thread across all of these jurisdictions is the same one the SRA has articulated: professional accountability does not transfer to the AI tool. The human or the organisation remains responsible for the output, the decision, and the consequence.

What Professional Services Firms Should Do

There are five areas where action is most urgent.

Audit your AI tools. Catalogue every AI system your firm uses — including tools embedded in standard software platforms — and identify which ones process personal data or generate client-facing outputs. You cannot govern what you have not mapped.

Establish supervision protocols. Every AI-generated output that affects a client, a legal matter, a financial record, or an employment decision needs a human review process with documented accountability. This is what regulators will ask to see.

Review your data processing agreements. Third-party AI tools that process personal data on your behalf require compliant data processing agreements. Review them for compliance with UK GDPR and the DUAA, and ensure they address the transparency obligations the ICO has articulated.

Train your people. The SRA's 42 reports indicate that individual practitioners are making AI-related errors that their firms are being held accountable for. Training needs to cover not just how to use AI tools but what the professional and regulatory boundaries are.

Monitor the regulatory pipeline. The ICO's AI and ADM Code of Practice will create new compliance obligations when it is finalised in 2026. Firms that wait until publication to begin preparation will be behind from the start.

Work With Specialists Who Understand What Regulators Are Looking For

The AI compliance environment is moving quickly, and the cost of being unprepared is rising — in regulatory fines, reputational damage, and professional liability.

Ops Intel helps professional services firms globally build AI compliance frameworks that are practical, defensible, and calibrated to the regulatory environments they operate in. Whether you need a gap analysis, a governance framework, staff training, or ongoing compliance monitoring, our team works with you to make sure your AI use is one you can stand behind.

Contact Ops Intel to find out where your firm stands and what needs to change.

Work with Ops Intel

Need help navigating AI compliance?

We build AI compliance frameworks and automation systems for professional services firms worldwide. Book a free 30-minute call or email us directly.

Call Now Claim Your Free Audit