The SRA AI warning notice, published on 17 August 2026, tells every regulated firm and individual that artificial intelligence carries no professional responsibility of its own. It raises two concerns: false content and fabricated citations reaching the courts, and client confidentiality entering AI systems that lack adequate safeguards. Supervisors and compliance officers sit squarely inside its scope.

What does the SRA AI warning notice say?

The regulator has issued its first dedicated warning notice on the misuse of AI, a document it will have regard to when exercising its regulatory functions, and one that applies to all firms and individuals it regulates as well as other authorised persons practising inside SRA-regulated firms. Legal Futures reported that the regulator has received 42 reports of potential AI misuse over the past year, with a number of investigations still running, a figure that appears in the trade coverage rather than in the notice itself.

Two concerns drive the document. The first is court and other documents carrying false or incorrect information, including citations, because AI tools generate fictitious cases and confident-sounding assertions with no basis in fact. The second is client confidentiality, where the notice makes the point that free and paid tools alike may fail to provide the contractual and technical safeguards confidential material requires.

Neither concern is new to anyone following the case law, and what has changed is the status of the statement. Guidance describes; a warning notice sets an expectation the regulator can later say a firm should have met, and it closes by stating plainly that a failure to have proper regard to it puts a firm at risk of disciplinary action.

Why are supervisors named alongside the drafter?

Those who supervise junior or non-authorised colleagues may themselves be found to have breached regulatory requirements and professional duties where false citations reach the court without adequate review, which converts a drafting failure into a management failure with two sets of names attached to it.

The notice assembles the relevant provisions carefully. Paragraph 3.5 of the Code of Conduct for Solicitors, RELs, RFLs and RSLs keeps a supervisor accountable for work carried out through others and requires effective supervision of client work, while paragraph 3.6 requires those managed to be competent and up to date on their legal, ethical and regulatory obligations. On the firm side, paragraphs 4.3 and 4.4 of the Code of Conduct for Firms require effective systems for supervising client matters, and paragraph 2.1 requires governance structures adequate to manage risk. A compliance officer for legal practice carries a separate duty at paragraph 9.1 to take all reasonable steps to secure compliance with the arrangements on supervision, which places the COLP inside the frame alongside the fee earner and the supervising partner.

Rule 9.4 of the Authorisation of Firms Rules gets a restatement too, requiring authorised bodies to have regulated work supervised by at least one person who has practised as a lawyer for three years or more, though the notice adds that this requirement does not reach every supervisor and that firms should still satisfy themselves anyone with supervisory responsibility has appropriate experience. Our guide to who can conduct litigation under supervision sets out how that structure operates in practice, and the recent separation of the COLP and COFA roles makes the compliance officer question more pointed rather than less.

Does putting client material into a public AI tool waive privilege?

On the confidentiality side the notice adopts the Upper Tribunal’s reasoning that putting client letters and Home Office decision letters into an open source tool such as ChatGPT places that information on the internet in the public domain. Using AI tools in that way will likely breach client confidentiality, and the notice states that legal professional privilege may then be permanently waived and incapable of recovery.

The document does not stop at free tools. Depending on a provider’s terms, settings and technical architecture, information entered into any AI system may be stored, retained or used to improve the product, which means a firm can lose practical control over how client material is processed. Client information should only go into a system where contractual, technical and organisational safeguards keep the data secure, away from unauthorised third parties, out of training sets except where explicitly authorised, and retained no longer than necessary. In-house solicitors get a paragraph of their own, since a business may have built tools for its own field that were never designed for legal work, and since its enthusiasm for its AI programme can pull against a solicitor’s duties under the Principles and the Code. Our checklist on AI tools, confidentiality and privilege covers the questions to settle before anything client-facing goes near a model.

Which cases does the notice rely on?

Four authorities carry the argument. R (on the application of Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin) supplies the point at paragraph 29 that a reference to the regulator is likely to be appropriate where a lawyer puts false citations before the court, and the notice adds that reliance on an AI output would not be a suitable defence. Cork and another v Smith [2026] EWHC 1199 (Ch) is cited for the courts reiterating the responsibilities of authorised persons where errors trace back to unchecked hallucinations, and Brett v The Solicitors Regulation Authority [2014] EWHC 2974 (Admin) for the description of misleading the court as among the most serious offences an advocate or litigator can commit.

Two of the four repay a closer look at how they are named. The Upper Tribunal decision appears in the notice as UK v Secretary of State for the Home Department [2026] UKUT 81 (IAC), the principal name on the ICLR record; the same decision carries R (Munir) v Secretary of State for the Home Department as an additional name, and is reported at [2026] 4 WLR 37 and [2026] WLR(D) 187 before Upper Tribunal Judges Lindsley, Keith and Blundell. We use the Munir form, so readers cross-checking the notice against our earlier coverage of the privilege point are looking at one decision rather than two. The fourth authority, cited as BCP v A Mother [2026] EWFC 71 (B), was published in March 2026 under the title Re A, B, C, D (Extension of assessment; Use of AI: hallucinations), and the person who put the hallucinated authorities before the family court was an unregistered, non-practising barrister acting first as a lay advocate and then as a litigant in person. She was not someone the SRA regulates, which is worth holding in mind when the notice offers the case as an illustration of what the courts do about hallucinations.

What should firms do before the next filing?

The notice names five Principles as particularly engaged: the rule of law and the proper administration of justice, public trust and confidence, honesty, integrity, and the best interests of each client. Around them sit the Code provisions on not misleading the court at 1.4, properly arguable submissions at 2.4, contempt at 2.5, wasting the court’s time at 2.6, competence at 3.2, confidentiality at 6.3 in both Codes, and the requirement at 7.2 to justify decisions and demonstrate compliance. That last provision does most of the practical work, because it turns an undocumented AI policy into an evidential problem the moment the regulator asks a question.

A firm that can produce a written policy, an approved-tools list, a record of who supervises what, and a verification step that sits between an AI draft and a court filing is answering paragraph 7.2 in advance. A firm that cannot is relying on nobody ever asking.

Why It Matters

A warning notice is the document the SRA will point to when it decides whether a firm should have known better. This one names supervision rather than the drafting lawyer alone, and it treats client material going into a public tool as a confidentiality breach capable of waiving privilege permanently. Firms without a written AI policy, an approved-tools list and a supervision record now carry a documented regulatory expectation they cannot say they had not seen.