LegalAI[Space]

What the SRA can ask about your use of AI

Seven questions recur across a regulator's interest, a client audit and your own risk committee. A firm that can answer them from records is in a different place from one that can only produce a policy.

Published
Reading time
5 minutes
Written by
The LegalAI Space team, Cognesio LLP

Read SRA guidance on AI next to a client's audit questionnaire and the same seven questions appear: which tools you use, who authorised them, what data goes in, who supervised the output, what was checked, what was refused, and what is retained. A firm that can answer those from records is in a good position. A firm that can only produce a policy document is not.

Who asks, and when

Three groups ask. Your own risk committee asks on a schedule you set. A client's in-house team asks through an outside-counsel questionnaire, with a deadline and a spreadsheet. The regulator's interest sits behind both.

The practical point is that you do not get to prepare the answer at the moment of asking. Either the record exists or it does not.

The published sources worth reading in full

Four public documents are worth reading before you write anything internally. The SRA Risk Outlook report on the use of artificial intelligence in the legal market (November 2023) is the regulator's published report on the subject. The SRA thematic review of compliance officers (December 2025) and the SRA guidance update on new technology and COLP responsibility (February 2026) put the compliance officer at the centre of the technology question.

Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank were before the Divisional Court in June 2025, and concern citations to authorities that did not exist. Anything else you read about the regulator's expectations, including this page, is somebody's reading of those documents. Treat it that way.

The evidence the product produces

LegalAI Space works inside a matter with a client, a reference and a responsible partner, and the matter carries its own jurisdiction. A run screens for personal data against an allow-list and passes the Jurisdiction Gatekeeper on the way in. Every authority carries a verdict: verified, needs a check, or not found, and the 'Where we looked' panel shows the sources that were searched.

Paywalled subscription databases are not read, because a passage the check cannot open is a passage it cannot confirm. The audit and compliance register records runs, verification, sharing, documents, members and conflict checks, and exports to CSV.

The file you would hand over

Open a matter with two or three documents and run an agent against them. Read the verdicts, open the 'Where we looked' panel behind one marked verified, then press 'Verify all' and watch the verdicts settle. Go to the audit and compliance register, set the date range to cover the run, and export the CSV.

Finally, produce the printable bundle. It carries a content digest, so you can show that the copy in someone's hand is the copy the register produced. It is not a certificate and it is not a tamper-evident hash chain. It is a bundle with a digest, and the honest description is the useful one.

What this does not do

A register is not a policy. The product will tell you what was run, by whom, on which matter, against which sources, and with what verdicts. It will not tell you whether your firm should be doing that work with AI, which practice areas are out of scope, or how long you keep any of it. Those are decisions your firm makes and writes down.

There are no live connectors to iManage, NetDocuments or SharePoint; documents come in by upload. There are no ethical walls, only restricted matters and conflict redaction, which is a narrower mechanism. Verified source lists cover the UK, Ireland, the EU and the ECHR today. Elsewhere, research runs at open-web quality with the same gates, and the output says so.

Start free

See it run on your own matter.

Free plan, two seats, 500 welcome credits, no card.