LegalAI Space

The SRA's warning notice on AI: a line-by-line guide for COLPs

The notice is short and names two concerns: fabricated citations, and confidentiality when client material goes into public AI tools. Each needs a different fix.

Published
Reading time
7 minutes
Written by
The LegalAI Space team, Cognesio LLP

The SRA published a warning notice titled 'Misuse of AI' on 17 August 2026. It is short, and it names two concerns rather than a general anxiety: fabricated citations, and confidentiality when client material is put into public AI tools. A COLP reading it for the first time should treat those as two separate pieces of work, because the control that fixes one does nothing at all for the other.

What a warning notice is

A warning notice sets out the regulator's view of conduct that risks breaching its rules. It is not a new rulebook, and it is not a certification scheme. The SRA does not approve or endorse software, so any product described to you as approved by the regulator is being described inaccurately, and that alone is worth knowing before your next vendor call.

What a notice does change is the conversation afterwards. Once the regulator has published its view of a risk, a firm that carries on without addressing it is in a weaker position than one that read it, decided what to do, and wrote the decision down. That is the practical value of spending an hour on it now rather than later.

Concern one: authorities that do not exist

The notice puts the first concern in a single sentence: "AI tools can produce 'hallucinations', generating fictitious cases, references or seemingly factual assertions that may appear convincing despite having no basis in fact." The phrase doing the work is 'appear convincing'. The risk is not that the output looks wrong. It is that it reads exactly like competent work.

The notice refers to Ayinde. R (Ayinde) v London Borough of Haringey and Al-Haroun v Qatar National Bank QPSC [2025] EWHC 1383 (Admin) were heard together by the Divisional Court, with Dame Victoria Sharp P presiding, and judgment came in June 2025. Submissions in both cited authorities that did not exist, the court made wasted costs orders, and matters were referred to the regulators.

Concern two: confidentiality and privilege

The second concern is what happens when client material goes into a public AI tool. The notice refers to UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC) on confidentiality and privilege. The Law Society's position, stated plainly, is that sharing case details with tools like ChatGPT will likely breach client confidentiality, and that privilege may be permanently waived.

Read that last clause slowly, because it is the part fee-earners underestimate. A confidentiality breach can sometimes be contained and managed. Privilege, once waived, is not something the firm can put back afterwards. Law Society Vice President Brett Dixon welcomed the SRA guidance in the Law Gazette in August 2026, and the two bodies are saying the same thing from different directions.

The 42 reports, and what they tell you

The SRA news release of 17 August 2026 states that it received 42 reports of potential AI misuse between July 2025 and July 2026, covering inaccurate legal citations, supervision and confidentiality. Do not read too much into the number in either direction. It is not a measure of how much AI misuse occurred. It is a measure of how much was reported to the regulator in a twelve-month window.

The useful part is the composition. Three categories, and only one of them is about citations. Supervision and confidentiality account for the rest, which tells a COLP something specific: a firm whose entire AI response is a citation-checking rule has addressed roughly a third of what the regulator is actually seeing.

Supervision, and the June 2026 additions

The SRA added AI-specific sections to its Effective Supervision guidance in June 2026. That matters more than it sounds, because supervision is the doctrine that already existed. Nobody needed a new rule to establish that a supervising solicitor answers for work that leaves the firm under their name. What the additions remove is the argument that AI-assisted work is a special case where the ordinary expectations are unclear.

Set alongside the SRA guidance update on new technology and COLP responsibility from February 2026, and the SRA Risk Outlook report on the use of artificial intelligence in the legal market from November 2023, the regulator's line has been consistent for nearly three years. The tools changed a great deal in that time. The expectations did not.

One action for each concern

For citations: require that every authority in work going to a court, a client or the other side has been opened, and that the file records who opened it. Not searched for, not recognised, opened. This is a five-minute rule that fits on one line of a supervision note, and it addresses the failure mode the notice describes.

For confidentiality: publish the list of sanctioned tools and, more importantly, provide one that is faster than the unsanctioned alternative. A prohibition without a replacement produces the behaviour it prohibits, quietly and at scale. If the sanctioned route takes longer than pasting a clause into a consumer chatbot, the notice will be read, agreed with, and then ignored by the people under the most pressure.

Where the product sits against these two concerns

On citations: research reads only a fixed list of 74 approved public sources, ten paywalled domains are refused by name, and every authority carries a verdict of verified, needs a check, or not found. Four deterministic gates run on output as code rather than as a model grading its own work: one checks the authority set, one checks quotations word for word, one caps confidence, and one refuses any source host outside the approved list.

On confidentiality: before any model sees a prompt, the run screens it for personal and client data and redacts where needed, so that a neutral citation number becomes a reference. Data is stored in the Microsoft Azure UK region, encrypted in transit and at rest, and never used to train any model. You can bring your own provider key on every plan, including Free. We hold no ISO 27001, SOC 2 or Cyber Essentials certification today, and we would rather say that than let a procurement form imply otherwise.

The honest edge

None of this makes a firm compliant, and no product can. Compliance is a set of decisions your firm makes about what work AI touches, which practice areas are out of scope, who supervises, and how long records are kept. Software can produce evidence for those decisions. It cannot make them, and a vendor describing its product as certified by the SRA is describing something the regulator does not issue to anyone.

Redaction before a prompt reaches a model reduces exposure. It does not eliminate it. A fee-earner can still describe a matter in enough detail to identify it, and no screening layer reads intent. The strongest control remains a firm that has told its people, in writing, what may and may not be typed into a machine, and has given them somewhere better to type it.

See it run on your own matter.

Free plan, two seats, 500 welcome credits, no card.