For COLPs, COFAs and managing partners
The SRA did not write new rules for AI. It did not need to.
The SRA regulates outcomes rather than tools, so every duty that already binds your firm applies unchanged when a model does the work. In February 2026 it went further and said it would expect, as a minimum, the COLP to be responsible for regulatory compliance when new technology is introduced.
The Code already applies
Five rules your firm is already bound by.
None of these mentions artificial intelligence. All of them reach it, because they are written about outcomes rather than about tools.
Rule 2.1, effective governance
Firms must have effective governance structures, arrangements, systems and controls. Adopting AI without a documented policy, assigned ownership and active oversight leaves this rule unmet.
Rule 2.2, compliance records
Firms must keep records that demonstrate compliance. For AI that means audit trails, verification logs and evidence that outputs were supervised, rather than a policy that sits in a drawer.
Rule 2.5, risk management
AI belongs in the firm's risk register. Fabricated authority, data leakage, bias and unsupervised use are AI-specific risks the firm must identify, assess and manage.
Rule 4.3, competence of managers and employees
Staff using AI must be able to evaluate what it produces. The SRA expects ongoing competence, not merely access to a tool.
Rules 6.3 to 6.5, confidentiality
Client confidentiality is absolute. Feeding client-identifying information into a tool that trains on inputs, or stores data outside the firm's control, puts these rules at risk.
Rule numbers refer to the SRA Code of Conduct for Firms. Every reference on this page was checked against the Code itself. The full obligations library.
Who is responsible
The two officers the SRA holds accountable.
Not the firm in the abstract. Two named individuals, approved as fit and proper, on the firm's authorisation.
The COLP
Compliance Officer for Legal Practice
The named individual the SRA holds accountable for the firm's compliance with its authorisation and the SRA's regulatory arrangements. When a firm adopts AI, the COLP owns the question the regulator now asks: is this use supervised, recorded and defensible?
- Ensure the firm meets its SRA authorisation and Code of Conduct obligations
- Record any failure to comply, and report material breaches to the SRA
- Own AI governance: policy, oversight and the evidence an inspection would need
The COFA
Compliance Officer for Finance and Administration
Accountable for the firm's compliance with the SRA Accounts Rules, and so for the handling of client money. AI reaches the COFA's remit wherever tools touch billing, client-account reconciliation or financial data.
- Ensure compliance with the SRA Accounts Rules and safe handling of client money
- Keep records of, and report, material breaches of the Accounts Rules
- Govern AI that processes financial or client-account data
- Both are named on the firm's SRA authorisation and must be approved as fit and proper.
- Both must record breaches and report serious ones to the SRA as soon as reasonably practicable.
- Neither role is a formality. The December 2025 thematic review found only one COLP, among those reviewed, who could outline each aspect of the requirements.
A distinction worth getting right
Governance is not security.
Firms that conflate the two end up well protected and still unable to answer the regulator's question.
Security asks
Could the wrong person reach this data?
Encryption, access control, tenancy isolation, penetration testing. Necessary, and your IT director probably has it covered.
Governance asks
Was this output supervised, and can you prove it?
Which tool produced it, whether the authority it cites is real, which policy applied, who signed it off, and whether that record survives being asked for a year later.
Both matter. How we handle the first.
Under inspection
What the SRA can actually ask for.
Four questions, and in most firms the honest answer to at least one of them is currently no.
Which AI tools your firm uses
A live inventory of the AI systems in the firm, who uses them, and for what kind of legal work.
Who is supervising AI output
Evidence that a qualified person reviewed AI-assisted work before it reached a client or a court. The supervision chain, on the record.
How AI risk is managed
Your AI entries in the risk register, the controls in place, and how verification failures are caught and resolved.
The records to prove it
Under section 44B of the Solicitors Act 1974 the SRA can require a firm to produce documents. The notice specifies the period. For AI-assisted work that means an audit trail you can hand over on demand.
Who it lands on
Built for the people the SRA holds responsible.
The same record, scoped to what each role is actually accountable for.
COLPs and compliance officers
One view of every AI-assisted work item, its verification status and what still needs a decision, with reports mapped to what an inspection actually asks for.
Managing partners
Evidence-based answers for PI renewals, panel tenders and SRA enquiries, ready before anyone asks rather than reconstructed afterwards.
Supervising partners
Supervision that works with AI: what your associates produced with it, what was verified, and what needs a human read, without adding a bureaucracy.
Risk managers and COFAs
An AI risk register maintained as a by-product of governed use, with incidents flagged, escalated and resolved on the record.
The obligation is already here.
The SRA Standards and Regulations
The SRA already requires proper governance, competence and a record of how work was produced. Every one applies to AI-assisted work today, because the regulator does not wait for new rules.
Courts sanctioning unverified AI
In Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank, handed down 6 June 2025, the Divisional Court addressed fabricated authorities in court filings and referred individuals to their regulators. An unverified output is a professional risk, not a convenience.
EU AI Act, high-risk obligations
The AI Omnibus, in force 27 July 2026, moved the high-risk application date from 2 August 2026 to 2 December 2027 for standalone systems, and to 2 August 2028 where the AI is embedded in a product. Transparency duties and the record-keeping expectation are unchanged, and most off-the-shelf tools still cannot export the record.
The record is the deliverable
When an inspection comes, the question is the same: can you prove this output was governed? A signed, reproducible audit record is the answer, written as the work happens rather than assembled the night before.
From the blog
The SRA, COLP and COFA library
What the regulator can ask, what a COLP is on the hook for, and the checklist behind it.
The founder
Built by someone who had to stand behind the system.
LegalAI Space is the work of a founder who spent a decade shipping infrastructure that enterprises had to trust, now turned on the part of legal AI that matters most: governance.
She started LegalAI Space because legal AI had inherited the speed of enterprise infrastructure and none of its accountability.
Daman spent a decade building cloud and AI infrastructure for large enterprises at Microsoft and HPE. The question there was never only “does it run?” but “can you stand behind it?”
Firms were being asked to trust output they could not trace. Her focus is the layer that closes the gap: the rules, the verification, and the record that let a partner sign off with confidence.
Engineering, BITS Pilani · Executive product management, IIM Lucknow
SRA AI compliance, answered.
The questions COLPs and COFAs ask most, answered from the Code and the SRA's own guidance rather than from inference.
Still have questions? Talk to the founderFind out what your firm could produce today.
Ten minutes against 70 controls drawn from the Principles, both Codes, SRA guidance and the case law now governing AI-assisted work. Free, and the gap report is yours.
