Skip to content
LegalAI Space

Regulation

What the SRA can ask about your use of AI

Seven questions recur across a regulator's interest, a client audit and your own risk committee. A firm that can answer them from records is in a different place from one that can only produce a policy.

5 minute read

Read SRA guidance on AI next to a client's audit questionnaire and the same seven questions appear: which tools you use, who authorised them, what data goes in, who supervised the output, what was checked, what was refused, and what is retained. A firm that can answer those from records is in a good position. A firm that can only produce a policy document is not.

Who asks, and when

Three groups ask. Your own risk committee asks on a schedule you set. A client's in-house team asks through an outside-counsel questionnaire, with a deadline and a spreadsheet. The regulator's interest sits behind both.

The practical point is that you do not get to prepare the answer at the moment of asking. Either the record exists or it does not.

The published sources worth reading in full

Four public documents are worth reading before you write anything internally. The SRA Risk Outlook report on the use of artificial intelligence in the legal market (November 2023) is the regulator's published report on the subject. The SRA thematic review of compliance officers (December 2025) and the SRA guidance update on new technology and COLP responsibility (February 2026) put the compliance officer at the centre of the technology question.

Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank were before the Divisional Court in June 2025, and concern citations to authorities that did not exist. Anything else you read about the regulator's expectations, including this page, is somebody's reading of those documents. Treat it that way.

The evidence the product produces

LegalAI Space works inside a matter with a client, a reference and a responsible partner. A run screens for personal data against an allow-list and passes a jurisdiction gate on the way in. Every authority carries a verdict: verified, needs a check, or not found, and the 'Where we looked' panel shows the sources that were searched.

Ten paywalled domains are refused by name, covering Westlaw, Practical Law, Lexis, Bloomberg Law, Justis and vLex, because a passage the check cannot open is a passage it cannot confirm. The audit and compliance register records runs, verification, sharing, documents, members and conflict checks, and exports to CSV.

The file you would hand over

Open a matter with two or three documents and run an agent against them. Read the verdicts, open the 'Where we looked' panel behind one marked verified, then press 'Verify all' and watch the verdicts settle. Go to the audit and compliance register, set the date range to cover the run, and export the CSV.

Finally, produce the printable inspection bundle. It carries a content digest, so you can show that the copy in someone's hand is the copy the register produced. It is not a certificate and it is not a tamper-evident hash chain. It is a bundle with a digest, and the honest description is the useful one.

What this does not do

A register is not a policy. The product will tell you what was run, by whom, on which matter, against which sources, and with what verdicts. It will not tell you whether your firm should be doing that work with AI, which practice areas are out of scope, or how long you keep any of it. Those are decisions your firm makes and writes down.

There are no live connectors to iManage, NetDocuments or SharePoint; documents come in by upload. There are no ethical walls, only restricted matters and conflict redaction, which is a narrower mechanism. Coverage is England and Wales plus EU primary sources, not US, Canadian or Australian law.

See it run on your own matter.

Free plan, two seats, 500 welcome credits, no card.