A single document with a signature line and a checkmark beside it.
Legal sectorAI riskGovernanceCompliance

What the SRA's AI warning notice means for supervisors

The SRA's warning notice on AI misuse makes clear that responsibility for AI-assisted work reaches past the person who used the tool. A four-question check can expose the weak points before work reaches a client, a court or a regulator.

Good Transformer6 min read

The Solicitors Regulation Authority published a warning notice on the misuse of AI on 17 August. Most of the attention has gone to its two immediate concerns: false information produced by AI, and confidential client data entered into tools without proper safeguards.

The notice makes a third point, about supervision. A firm or a supervisor can breach existing duties when AI-assisted work is not properly reviewed, even if they never touched the tool themselves.

That is not a new obligation. It is the SRA applying existing duties on competence, supervision and governance to work produced with AI, and saying so directly.

What the SRA actually said

The notice names two concerns. First, AI tools "can produce 'hallucinations', generating fictitious cases, references or seemingly factual assertions that may appear convincing despite having no basis in fact." Second, the notice says client information should only be entered into AI systems "where appropriate contractual, technical and organisational safeguards are in place to protect confidentiality". Using them without those safeguards puts the client's confidentiality at risk, and potentially legal privilege with it.

The notice draws on several recent cases, two of which we have already covered. In R (Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), fabricated case citations were submitted to the High Court. The judgment said a lawyer who places false citations before a court is likely to face a reference to their regulator, whether or not AI produced the errors.

In UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the tribunal considered the confidentiality implications of putting client letters into a public AI tool such as ChatGPT. It observed that doing so places that information "on the internet in the public domain".

We covered both cases in detail in our earlier pieces on how to stop AI hallucinations reaching your work and what AI does to client confidentiality, so we will not repeat the arguments here.

What the notice says about supervision

On supervision, the notice says: "Those who supervise junior or non-authorised colleagues may also be found to have breached regulatory requirements and professional duties if false citations are put before the court without adequate review and/or supervision."

This rests on rules that were already in place. Solicitors who manage others must "effectively supervise work being done for clients" and remain accountable for it. Firms need supervision systems that fit the risk of the work. A firm's compliance officer for legal practice must take all reasonable steps to make sure those systems are followed.

The SRA had already applied this to AI directly. Its effective supervision guidance, updated on 12 June 2026, says AI outputs should be "subject to appropriate human review, scrutiny and professional judgement". It adds that "an authorised individual retains ultimate responsibility for any legal services delivered with AI assistance".

That guidance states plainly that it sets out no new standards. What the warning notice adds is prominence, and enforcement language: fail to have proper regard to it, the SRA says, and you are at risk of disciplinary action.

A general assurance that someone checked the work is not evidence of effective supervision. A supervisor who signs off work without adequately checking its accuracy has not discharged that responsibility.

Firms also need arrangements that let supervisors understand when and how AI is being used by the people they supervise.

Why this reaches beyond law firms

The SRA regulates solicitors, not accountants, financial advisers, architects or consultancies. But the control underneath the notice is not specific to legal work.

The same problem arises when a finance team circulates an unverified AI-drafted board pack, an insurance broker sends an AI-generated risk summary to an insurer, or a consultancy hands a client an AI-assisted report without checking its claims. Different rules govern each of those, and none of them is the SRA's. What holds steady is the requirement that someone remain responsible for the accuracy of the work, and for how the information in it was handled.

Competence, supervision and confidentiality are duties that exist in many regulated professions, and often in the contracts governing professional work even where no regulator is involved.

The four-question AI supervision check

The SRA does not prescribe a single review process. Its approach is outcomes-focused and proportionate to risk. As a practical starting point, whoever is responsible for AI-assisted work should be able to answer four questions before it goes out.

  1. Who checked it? Name a specific person, not "the team" or "someone".
  2. What was it checked against? Name the source document, the client's actual instructions, or the underlying case law and legislation. The reviewer's memory of what sounds right does not count.
  3. Is there a record? Keep initials, a date, or a short note showing what was reviewed. The record should be proportionate to the risk of the work and to any requirements that apply to your firm.
  4. Could you explain the review? Could you show that record to a client or a regulator and say who checked the work and how? If the firm would have to reconstruct or guess what happened, the review has not been adequately recorded.

This is the same idea as keeping a written record of how a human was involved in an AI-assisted decision, or naming an owner for every AI process running in the business. Apply it to the moment before AI-assisted work reaches a client.

What to do this week

Do not wait for a complete policy before improving the next piece of work. Take the next AI-assisted email, report or submission due to reach a client, and apply the four questions before it goes.

If the answers come easily, the habit already exists. If they do not, that is the kind of supervision gap the warning notice addresses, and it is worth fixing before a client, a court or a regulator raises it first.

Common questions

Does this only apply to law firms?

The warning notice itself only binds solicitors and SRA-regulated firms. But the duties it rests on, competence, supervision and confidentiality, appear in many regulated professions and in a good deal of professional contracting. The practical lesson applies well beyond solicitors, even though the notice does not.

What if you do not have a formal reviewer for AI-assisted work?

Assign responsibility first for the highest-risk work, particularly anything reaching a client, a court or a regulator. Record who holds it and what their review covers. How formal the process needs to be should reflect the risk of the work and any regulatory requirements that apply to your firm.

Does using AI create the risk, or does using it unsupervised create the risk?

AI use creates more than one kind of risk, and they do not behave the same way. Where the problem is inaccurate output, the failure is usually the absence of verification and professional judgement before the work went out.

Confidentiality is different. Harm can arise the moment sensitive information is entered into a tool without appropriate safeguards, even if the output is checked carefully afterwards. The SRA's notice does not tell firms to stop using AI, and neither do we.


This is general information about a regulatory publication, not legal advice. If AI-assisted work in your firm touches a regulator, a court or a client contract with specific compliance terms, take advice on your own obligations rather than relying on this summary.

Good Transformer helps firms build the checking habits that make their AI use defensible. If you want a second opinion on how AI-assisted work gets reviewed before it reaches a client, book a conversation.

Work with Good Transformer

Turn this thinking into working practice.

Explore team advisory

Newsletter

Get new Insights by email

Practical notes on using AI with judgement, and the AI news leaders actually need. No hype, no spam, unsubscribe anytime.

Choose how often you want the digest

Keep reading