For COLPs, COFAs and managing partners

The SRA did not write new rules for AI. It did not need to.

The SRA regulates outcomes rather than tools, so every duty that already binds your firm applies unchanged when a model does the work. In February 2026 it went further and said it would expect, as a minimum, the COLP to be responsible for regulatory compliance when new technology is introduced.

Grounded inBAILIIlegislation.gov.ukEUR-LexHUDOCCURIACourts.ie

The Code already applies

Five rules your firm is already bound by.

None of these mentions artificial intelligence. All of them reach it, because they are written about outcomes rather than about tools.

Rule 2.1, effective governance

Firms must have effective governance structures, arrangements, systems and controls. Adopting AI without a documented policy, assigned ownership and active oversight leaves this rule unmet.

Rule 2.2, compliance records

Firms must keep records that demonstrate compliance. For AI that means audit trails, verification logs and evidence that outputs were supervised, rather than a policy that sits in a drawer.

Rule 2.5, risk management

AI belongs in the firm's risk register. Fabricated authority, data leakage, bias and unsupervised use are AI-specific risks the firm must identify, assess and manage.

Rule 4.3, competence of managers and employees

Staff using AI must be able to evaluate what it produces. The SRA expects ongoing competence, not merely access to a tool.

Rules 6.3 to 6.5, confidentiality

Client confidentiality is absolute. Feeding client-identifying information into a tool that trains on inputs, or stores data outside the firm's control, puts these rules at risk.

Rule numbers refer to the SRA Code of Conduct for Firms. Every reference on this page was checked against the Code itself. The full obligations library.

Who is responsible

The two officers the SRA holds accountable.

Not the firm in the abstract. Two named individuals, approved as fit and proper, on the firm's authorisation.

The COLP

Compliance Officer for Legal Practice

The named individual the SRA holds accountable for the firm's compliance with its authorisation and the SRA's regulatory arrangements. When a firm adopts AI, the COLP owns the question the regulator now asks: is this use supervised, recorded and defensible?

  • Ensure the firm meets its SRA authorisation and Code of Conduct obligations
  • Record any failure to comply, and report material breaches to the SRA
  • Own AI governance: policy, oversight and the evidence an inspection would need

The COFA

Compliance Officer for Finance and Administration

Accountable for the firm's compliance with the SRA Accounts Rules, and so for the handling of client money. AI reaches the COFA's remit wherever tools touch billing, client-account reconciliation or financial data.

  • Ensure compliance with the SRA Accounts Rules and safe handling of client money
  • Keep records of, and report, material breaches of the Accounts Rules
  • Govern AI that processes financial or client-account data
  • Both are named on the firm's SRA authorisation and must be approved as fit and proper.
  • Both must record breaches and report serious ones to the SRA as soon as reasonably practicable.
  • Neither role is a formality. The December 2025 thematic review found only one COLP, among those reviewed, who could outline each aspect of the requirements.

A distinction worth getting right

Governance is not security.

Firms that conflate the two end up well protected and still unable to answer the regulator's question.

Security asks

Could the wrong person reach this data?

Encryption, access control, tenancy isolation, penetration testing. Necessary, and your IT director probably has it covered.

Governance asks

Was this output supervised, and can you prove it?

Which tool produced it, whether the authority it cites is real, which policy applied, who signed it off, and whether that record survives being asked for a year later.

Both matter. How we handle the first.

Under inspection

What the SRA can actually ask for.

Four questions, and in most firms the honest answer to at least one of them is currently no.

Which AI tools your firm uses

A live inventory of the AI systems in the firm, who uses them, and for what kind of legal work.

Who is supervising AI output

Evidence that a qualified person reviewed AI-assisted work before it reached a client or a court. The supervision chain, on the record.

How AI risk is managed

Your AI entries in the risk register, the controls in place, and how verification failures are caught and resolved.

The records to prove it

Under section 44B of the Solicitors Act 1974 the SRA can require a firm to produce documents. The notice specifies the period. For AI-assisted work that means an audit trail you can hand over on demand.

Who it lands on

Built for the people the SRA holds responsible.

The same record, scoped to what each role is actually accountable for.

COLPs and compliance officers

One view of every AI-assisted work item, its verification status and what still needs a decision, with reports mapped to what an inspection actually asks for.

Managing partners

Evidence-based answers for PI renewals, panel tenders and SRA enquiries, ready before anyone asks rather than reconstructed afterwards.

Supervising partners

Supervision that works with AI: what your associates produced with it, what was verified, and what needs a human read, without adding a bureaucracy.

Risk managers and COFAs

An AI risk register maintained as a by-product of governed use, with incidents flagged, escalated and resolved on the record.

Regulatory landscape

The obligation is already here.

01In force now

The SRA Standards and Regulations

The SRA already requires proper governance, competence and a record of how work was produced. Every one applies to AI-assisted work today, because the regulator does not wait for new rules.

022025 to 2026

Courts sanctioning unverified AI

In Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank, handed down 6 June 2025, the Divisional Court addressed fabricated authorities in court filings and referred individuals to their regulators. An unverified output is a professional risk, not a convenience.

032 December 2027

EU AI Act, high-risk obligations

The AI Omnibus, in force 27 July 2026, moved the high-risk application date from 2 August 2026 to 2 December 2027 for standalone systems, and to 2 August 2028 where the AI is embedded in a product. Transparency duties and the record-keeping expectation are unchanged, and most off-the-shelf tools still cannot export the record.

04Ongoing

The record is the deliverable

When an inspection comes, the question is the same: can you prove this output was governed? A signed, reproducible audit record is the answer, written as the work happens rather than assembled the night before.

From the blog

The SRA, COLP and COFA library

What the regulator can ask, what a COLP is on the hook for, and the checklist behind it.

The founder

Built by someone who had to stand behind the system.

LegalAI Space is the work of a founder who spent a decade shipping infrastructure that enterprises had to trust, now turned on the part of legal AI that matters most: governance.

Daman Kaur

Daman Kaur

Founder & CEO

She started LegalAI Space because legal AI had inherited the speed of enterprise infrastructure and none of its accountability.

Daman spent a decade building cloud and AI infrastructure for large enterprises at Microsoft and HPE. The question there was never only “does it run?” but “can you stand behind it?”

Firms were being asked to trust output they could not trace. Her focus is the layer that closes the gap: the rules, the verification, and the record that let a partner sign off with confidence.

Engineering, BITS Pilani · Executive product management, IIM Lucknow

Questions

SRA AI compliance, answered.

The questions COLPs and COFAs ask most, answered from the Code and the SRA's own guidance rather than from inference.

Still have questions? Talk to the founder
No, and that is the part firms most often get wrong. There is no standalone SRA AI rulebook, because the SRA regulates outcomes rather than the systems used to achieve them. Its Risk Outlook on artificial intelligence puts it directly: its regulation focuses on the outcomes firms achieve, and not necessarily on the specific systems they use. The practical consequence is that every existing duty applies unchanged when a model does the work, and none of them was written with a waiting period for new technology.

Find out what your firm could produce today.

Ten minutes against 70 controls drawn from the Principles, both Codes, SRA guidance and the case law now governing AI-assisted work. Free, and the gap report is yours.