A single document with a signature line and a checkmark beside it.
Legal sectorAI riskGovernanceCompliance

The SRA's new AI warning notice holds supervisors accountable too

The SRA's new warning notice on AI misuse holds firms and supervisors accountable too, alongside the person who used the tool. Any client-facing firm can run a five-minute supervision check this week to close that gap.

Good Transformer6 min read

The Solicitors Regulation Authority published a warning notice yesterday on the misuse of AI. Its real news is not the two risks it names.

The notice now holds other people responsible too.

Hallucinated case citations and leaked client data are both already covered on this site. What the SRA adds is a third failure. A firm or a supervisor can be found in breach for letting AI-assisted work go out unchecked, even when they never touched the AI tool themselves.

The same reasoning applies elsewhere.

What the SRA actually said

The notice names two concerns. First, AI tools "can produce 'hallucinations', generating fictitious cases, references or seemingly factual assertions that may appear convincing despite having no basis in fact." Second, confidential client information going into AI tools "without appropriate contractual, technical and organisational safeguards" risks the client's confidentiality and, potentially, legal privilege.

Both points rest on real cases. In R (Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), fabricated case citations reached the court's own hearings. The judgment said a lawyer who places false citations before a court is likely to face a reference to their regulator, whether or not AI produced the errors.

In UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the tribunal considered what happens when client letters go into an open AI tool such as ChatGPT. It found that doing so places that information "on the internet in the public domain".

We covered both cases in detail in our earlier pieces on how to stop AI hallucinations reaching your work and what AI does to client confidentiality, so we will not repeat the arguments here.

Supervisors are accountable too

The SRA has now said something new: "Those who supervise junior or non-authorised colleagues may also be found to have breached regulatory requirements and professional duties if false citations are put before the court without adequate review and/or supervision."

The notice backs that with the SRA's existing rules on supervision, not new law. Solicitors who manage others must "effectively supervise work being done for clients" and remain accountable for it. Firms need supervision systems that fit the risk of the work.

A firm's compliance officer for legal practice must take reasonable steps to see those systems are followed. These rules predate AI. They still cover it.

"Someone checked this work" stops being enough the moment nobody can say who checked it, what they checked it against, or when. A supervisor who signs off work without knowing AI produced it has not done their job. Neither has one who never checked whether a junior colleague's research was verified at all.

AI is new. The duty to know what reached a client was never optional.

Why the SRA's supervision logic reaches beyond law firms

The SRA regulates solicitors, not accountants, financial advisers, architects or consultancies. No other regulator has issued a matching notice, and this piece is not claiming one has. But the reasoning behind the notice applies more widely than law. Competence, supervision and confidentiality are duties that exist, in some form, in every regulated profession and in most client contracts even where no regulator is involved.

Think of a finance team that lets an AI-drafted board pack go out unchecked. Think of an insurance broker that lets an AI summary of a client's risk profile reach an insurer without a second look. Think of a consultancy that lets an AI-drafted report reach a client unverified.

Skip the check, and any of them could face the same problem the SRA is warning about. None of them has a regulator's notice to point to as an early warning. That is the argument for building the habit before a regulator asks whether it exists.

The five-minute AI supervision check

Before AI-assisted work reaches a client, a court or a regulator, whoever is responsible for it should be able to answer four questions.

  1. Who checked it? Name a specific person, not "the team" or "someone".
  2. Checked against what? Name the source document, the client's actual instructions, or the underlying case law and legislation. The reviewer's memory of what sounds right does not count.
  3. Is there a record? Keep a date, initials, or a short note saying what was checked. It does not need a formal sign-off process. It needs a trail.
  4. Would that record hold up if read aloud to the client, or to a regulator? If the honest answer is "we would have to guess who looked at this", the check has not happened yet, whatever anyone assumed.

This is the same idea as keeping a written record of how a human was involved in an AI-assisted decision, or naming an owner for every AI process running in the business. Apply it to the moment before AI-assisted work reaches a client.

What to do this week

Do not start with a policy. Start with the next piece of AI-assisted work about to reach a client: an email, a report, a submission. Run the four questions on it before it goes.

If the answers come easily, the habit already exists and the notice changes nothing in practice. If they do not, that mismatch is exactly what the SRA has now said it will look for. It is worth fixing before a client, a court or a regulator forces the question.

Common questions

Does this only apply to law firms?

The warning notice itself only binds solicitors and SRA-regulated firms. The duties it rests on (competence, supervision, confidentiality) apply well beyond law. So the practical lesson (name a reviewer, check against the source, keep a record) applies more widely even though the notice itself does not.

What if we do not have a formal reviewer for AI-assisted work?

Start by naming one, even informally, for the highest-risk category of work first (anything reaching a client, a regulator or a court). Naming someone without a written process is a stronger position than a written process nobody owns.

Does using AI create the risk, or does using it unsupervised create the risk?

The SRA's own notice draws that line explicitly: it does not tell firms to stop using AI, and neither do we. The risk sits in the gap between using a tool and checking what it produced. That gap is a supervision failure, not an AI failure.


This is general information about a regulatory publication, not legal advice. If AI-assisted work in your firm touches a regulator, a court or a client contract with specific compliance terms, take advice on your own obligations rather than relying on this summary.

Good Transformer helps firms build the checking habits that make their AI use defensible. If you want a second opinion on how AI-assisted work gets reviewed before it reaches a client, book a conversation.

Work with Good Transformer

Turn this thinking into working practice.

Explore team advisory

Newsletter

Get new Insights by email

Practical notes on using AI with judgement, and the AI news leaders actually need. No hype, no spam, unsubscribe anytime.

Choose how often you want the digest

Keep reading

AI risk12 min read

How to stop AI making things up in business use

Almost everyone checks that a source is real. That check misses AI's worst mistakes, because those mistakes cite real sources and then describe what the source says incorrectly.

17 August 2026