On 17 August 2026 the Solicitors Regulation Authority published a warning notice on the misuse of AI. It is not a ban, and it is not a reason to switch every tool off. It is a line in the sand: AI has no separate legal personality, so if your firm uses it, you remain accountable for the output however it was produced.
For the largest firms, that means another workstream for the compliance team. For a small firm or a sole practitioner, it lands on your desk, next to the client work. This post is the short version: what the notice means in practice, and the five things worth doing this month.
Why the SRA is paying attention now
The direction of travel has been clear for a while. The SRA's own research into small firms and sole practitioners found that cost, uncertainty and compliance worries were holding firms back, with only 12% of the firms surveyed using generative AI. The Law Society has been publishing AI guidance of its own, most recently weighing the benefits against the risks.
The warning notice changes the tone. The question is no longer "should we use AI?" It is "if you use AI, can you show it was used properly?" A firm that cannot answer that question is in a worse position than a firm that never touched the tools.
What "misuse" looks like in practice
The failures that get firms into trouble are rarely exotic. They are ordinary shortcuts:
- Pasting client matter details into a consumer chatbot with no data agreement in place
- Filing or sending AI-drafted text that nobody checked, including invented citations
- Fee earners using personal AI accounts the firm does not know about
- No record of which documents went through which tool, so the firm cannot answer a client or regulator question later
- Marketing that claims AI capability the firm cannot evidence
None of these require bad intent. They happen because nobody wrote the rules down.
The notice names the failure modes plainly: fictitious citations reaching court - as in R (Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), which it cites directly - and confidential client information entered into public AI tools. It also says the SRA has received reports from senior members of the judiciary and several self-reports from solicitors.
The five things worth doing this month
A note before the list: the SRA regulates outcomes, not methods - the notice says so itself. None of the below is a prescribed SRA checklist. It is a practical way to meet the obligations the notice points to: competence and supervision of work, effective firm governance, and protecting client confidentiality.
1. Write a one-page AI policy. Which tools are approved, for what work, and what must never go into them. One page beats a forty-page document nobody reads. If you have no policy at all, that is the first gap to close.
2. Ban personal accounts for client work. If a fee earner uses AI on a matter, it should be on a firm account, under a firm agreement, with data handling you have actually read. Shadow AI is the biggest unforced error in small firms.
3. Name a human for every output. Every piece of AI-assisted work needs a named person who checked it before it left the building. "The AI drafted it" is not a review process, and the SRA will not treat it as one.
4. Keep a simple record. Which tool, which matter, what it was used for, who approved the output. A spreadsheet is fine. The point is that you can answer "how does your firm use AI?" in one minute, with evidence.
5. Check your suppliers. Read the data processing terms of every AI tool you pay for. Where does the data go, is it used for training, can you delete it. If a vendor cannot answer plainly, that is your answer.
The upside the warning notice hides
Here is the part worth remembering. The SRA's research says most small firms are not using AI at all. That is an opening: a firm that adopts AI deliberately now, with governance in place, is ahead of most of its market before it has spent a pound on software. The warning notice does not close that opportunity. It raises the value of doing it properly.
A firm that can show a client a clear AI policy, named human review, and a clean audit trail is better placed to meet its obligations - and it is more credible than the firm down the road that is either avoiding AI entirely or using it carelessly. Governance is becoming a selling point.
Where to start if you have done none of this
Start with the baseline, not the tool. Map where AI already touches your matters, formally or informally, then write the policy around reality. Firms that buy a product first and govern it later end up re-doing both.
ClickoAI works with independent law firms and in-house legal teams in the UK and the US on exactly this: an evidence-first baseline, a workable AI policy, and governed workflows that a fee earner will actually follow. Our contract review product, Margo, is currently in controlled development and not yet generally available - it is being designed so that every AI suggestion is grounded in your firm's playbook and approved by a lawyer before it reaches a document. If you want a second pair of eyes on where your firm stands, our Workflow Value Workshop is the fastest starting point, and the answers page covers the questions firms usually ask first.
Frequently asked questions
Did the SRA ban law firms from using AI?
No. The August 2026 warning notice is about misuse, not use. The SRA expects firms that use AI to do it under proper controls: supervision of outputs, protection of client data, and the ability to explain how the tools are used.
Does a sole practitioner really need an AI policy?
The notice does not prescribe a policy document - it regulates outcomes, not paperwork, and those outcomes apply regardless of firm size. In practice, a short written policy - approved tools, permitted uses, what never goes into them - is the simplest way to show those outcomes are being managed, and one page is enough.
Can fee earners keep using free, consumer AI tools for client work?
The notice does not ban any category of tool. It says both paid and free tools may lack the contractual and technical safeguards client confidentiality needs, and that firms should understand the safeguards that apply and check they fit the sensitivity of the information. For client matters, that usually means firm-approved accounts under agreements the firm has actually read.
What records should a small firm keep about AI use?
Enough to answer "how does your firm use AI?" in one minute: which tool, which matter, what it was used for, and who approved the output. A simple spreadsheet is fine. The point is evidence, not bureaucracy.
What happens if a firm gets it wrong?
The notice itself says the SRA has identified a number of misuse cases, has received reports from senior members of the judiciary, and has had several self-reports from solicitors - and that it will have regard to the notice when exercising its regulatory functions. Beyond the regulator, the bigger commercial risk is a client or court discovering unchecked AI output in your work.
This post is general information, not legal advice. For advice on your firm's specific obligations, speak to your compliance officer or a regulatory specialist.