SRA warning notice on AI misuse (18 September 2026): solicitors' liability for confidentiality, advice, and court conduct
On 18 September 2026, the Solicitors Regulation Authority issued a formal warning notice on the misuse of artificial intelligence. For UK solicitors, it is not a gentle nudge. It is a regulatory statement of intent: existing professional duties apply in full to AI-assisted work, and the regulator is
Solicitors and AI: The SRA Has Spoken — What Professional Firms Need to Do Now
On 18 September 2026, the Solicitors Regulation Authority issued a formal warning notice on the misuse of artificial intelligence. For UK solicitors, it is not a gentle nudge. It is a regulatory statement of intent: existing professional duties apply in full to AI-assisted work, and the regulator is watching.
The notice covers three core areas — competence, supervision, and the handling of confidential information — and it makes one thing unambiguous: the fact that an AI tool produced, drafted, or recommended something does not reduce a solicitor's responsibility for it. That responsibility remains entirely with the lawyer.
This matters well beyond England and Wales. Law firms operating internationally, and the professional services businesses that work alongside them — accountants, HR consultancies, and marketing agencies — are all encountering the same underlying problem: AI tools are being adopted faster than compliance frameworks are being built around them. The SRA's notice is a useful benchmark for any professional firm trying to understand where its obligations begin and end.
What the SRA Warning Notice Actually Says
The SRA's warning notice does not introduce new rules. That is precisely the point. It clarifies that existing obligations already govern how solicitors use AI. The regulator does not need to draft fresh legislation to hold solicitors accountable — the professional standards already in place are sufficient.
Three duties sit at the centre of the notice.
Competence. Solicitors must understand the tools they use. Using an AI system to draft advice, summarise case law, or prepare documents does not satisfy the duty of competence unless the solicitor has sufficient understanding of what the tool does, how it can fail, and what its outputs require in terms of verification. Blind reliance on AI-generated content is a competence failure.
Supervision. The notice is explicit that solicitors must supervise AI use within their firms. This includes oversight of how junior staff or support functions interact with AI tools. A supervision failure involving AI carries the same professional consequences as any other supervision failure.
Confidentiality and misleading conduct. Inputting client information into an AI system that processes data in ways the client has not consented to may constitute a breach of confidentiality. Separately, submitting AI-generated material to a court without proper verification — and without understanding its accuracy — risks misleading the court. Both are serious professional conduct matters.
Why This Is Not Just a UK Issue
The SRA's notice arrives at a moment when regulators across multiple jurisdictions are arriving at similar conclusions through different mechanisms.
In California, Governor Gavin Newsom signed an executive order on the same date directing a working group to develop recommendations for strengthening AI safety laws, including the potential requirement for frontier AI companies to build emergency shutoff mechanisms for their models. Two pieces of California legislation also entered force around the same period: Senate Bill 813, which establishes a framework for independent verification organisations to assess AI systems for safety and risk, and Assembly Bill 1405, which creates a state registry for AI auditors.
The Californian approach is structural — it targets AI developers and large-scale deployments. The SRA's approach is professional — it targets the practitioners using AI in client-facing work. Together, they represent the two directions from which AI regulation is travelling: top-down from governments and regulators of technology, and sideways from professional bodies that govern conduct.
For a law firm with offices in London, New York, and Singapore, or an accounting practice serving clients across the EU and the Gulf, the regulatory picture is no longer theoretical. Different standards apply in different places, and the pace of regulatory development means that what was permissible practice twelve months ago may now carry material compliance risk.
The Implications for Professional Services Firms
The SRA's notice is directed at solicitors, but the underlying obligations it describes — competence, supervision, confidentiality — are structural features of professional services regulation everywhere. Accountants, HR consultants, and marketing agencies handling client data or providing regulated advice face equivalent duties under their own frameworks.
Several practical implications follow.
AI tool selection is a compliance decision. Choosing an AI tool is not a technology procurement question alone. It is a question about data handling, jurisdictional risk, and professional liability. Before any tool is deployed in client-facing work, firms need to understand where data is processed, how it is retained, and whether its use is consistent with client confidentiality obligations and applicable data protection law.
Supervision frameworks need to reflect AI use. Most firms have supervision policies that predate meaningful AI adoption. Those policies are likely inadequate. If AI is being used to draft advice, prepare documents, or summarise information, the supervision framework must account for it — who reviews AI outputs, at what stage, and with what level of scrutiny.
Client transparency is becoming a baseline expectation. Firms should consider whether clients are informed when AI tools are used in their matters, particularly where those tools process client data. In some jurisdictions this is already a legal requirement. In others it is rapidly becoming an expectation. Getting ahead of this is preferable to being asked about it after an incident.
Staff training cannot be optional. The SRA's competence requirement implies that solicitors must understand the tools they use. The same logic applies across professional services. Firms that deploy AI without ensuring staff are trained on its limitations, failure modes, and appropriate use are creating liability that competent oversight could prevent.
The Regulatory Direction of Travel
Across the UK, the US, the EU, and Asia-Pacific, the regulatory direction is consistent even where the specific rules differ. Professional responsibility frameworks are being interpreted to cover AI use. New legislation is creating audit requirements, registry obligations, and verification frameworks. The expectation that professionals bear responsibility for AI-assisted outputs is hardening into formal regulatory doctrine.
Firms that are still treating AI compliance as a future problem are already behind. The SRA's warning notice is a clear signal that regulators are not waiting for AI-specific legislation before enforcing existing standards. Any firm using AI in client-facing work should already have addressed competence, supervision, and confidentiality in a documented and auditable way.
How Ops Intel Can Help
Ops Intel works with professional services firms globally to build AI compliance programmes that are practical, jurisdiction-aware, and proportionate to how firms actually operate. Whether you are a solicitor's practice navigating the SRA's expectations, an accounting firm assessing your obligations under multiple regulatory frameworks, or a marketing or HR consultancy trying to establish defensible AI governance, we can help you move from exposure to control.
If your firm is using AI tools in client-facing work and has not yet conducted a structured compliance review, now is the right time to do it.
Visit Ops Intel at https://www.opsintel.io to find out how we can support your firm's AI compliance programme.
Follow us in Google
See Ops Intel first when AI rules change
One click tells Google you want our compliance briefings near the top of your results — and marks us as a preferred source inside Google's AI answers. It applies to your Google account only, and you can undo it any time.
What to do about it
The news is what changed. A framework is what you do about it.
Ops Intel writes AI compliance frameworks for small and medium businesses worldwide. Before you spend anything, read a real one — the whole pack, produced by the same system that will write yours.