For Partners & Practice Managers of UK Law Firms SRA Warning Notice · 17 August 2026

Someone in your firm is already using AI on client work.
The SRA just made that your problem.

Not the AI you approved. The AI you have never heard of. The SRA's new warning notice makes partners accountable for it, and four court judgments show what happens next.

"We can and will act."
The SRA, closing line of the warning notice
Warning triangle with AI glyph inside a live scan, surrounded by detected unapproved AI apps
17 Aug
The date the SRA put every firm on notice. A warning notice is the document that precedes discipline.
4
Court judgments already naming AI misuse in legal proceedings.
2
Lawyers referred to their regulators from a single case of invented citations.
0
Times "the AI did it" has worked as a defence. The SRA says it never will.
The courts got there first

This is not a hypothetical. These judgments have real lawyers' names in them.

The SRA's notice is built on cases that have already happened. Three of them tell you everything you need to know.

Fake law

AI invented the citations. The High Court noticed.

Ayinde v Haringey [2025] EWHC 1383 (Admin)

Fictitious AI-generated case citations were put before the court. Wasted costs followed. The solicitor and barrister were referred to their regulators.

Putting false material before a court can amount to contempt.
Privilege, gone

Pasting client letters into ChatGPT puts them "in the public domain."

[2026] UKUT 81 (IAC)

The Upper Tribunal's words, not ours. Feeding client correspondence into an open AI tool is publishing it to the internet. There is no motion to un-publish it.

Privilege waived that way may never be recovered.
No excuses

Not intentional. The court treated it seriously anyway.

BCP v A Mother [2026] EWFC 71 (B)

A court misled by AI hallucinations, without any intent to deceive. It made no difference to how seriously the court took it.

"Reliance on an output of AI would not be a suitable defence."

The risk worse than hallucinations: your client's matter becomes the machine's memory.

Free AI tools are free because you pay in data. Paste a matter into one and it can be retained, used to train the model, and echoed back in a stranger's answer. The SRA's rule is explicit: client data must not train an AI model except where explicitly authorised. Of the 12 shadow apps below, how many train on what your staff feed them? The partners could not say either.

Which raises the only question that matters
If a trainee solicitor ran a witness statement through a free AI tool at 11pm last Tuesday, would anyone in your firm know?
The Shadow AI Detection Report

We measured it. Here is one real firm.

A 14-person professional practice. One reporting period. Names removed, numbers untouched. The firm believed the answer was zero.

43%
of staff using AI the firm never approved. Six people out of fourteen.
12
Shadow AI applications in active use. Every one invisible to the partners.
157
sessions in the period. Not one person experimenting once. Habitual, daily use.
1
high-risk application, flagged for what it does with the data fed into it.
Actual client report · Anonymised Weekly Shadow AI app usage, top 10 apps by users, August 2026
Shadow AI usage trends chart from a real WPC detection report, showing ten unapproved AI applications in weekly use
Swipe the chart to explore →
ChatGPT Claude A legal drafting AI nobody procured An assistant rewriting outgoing letters AI image & video tools + 7 more

Scale that to a 60-person firm: roughly 25 people and hundreds of unsupervised sessions a month, some of it on privileged material, all of it under your practising certificate.

The industry calls it Shadow AI. A law firm has an older name for it: unsupervised work on client matters.

Our advice. Yes, it is unfashionable.

Everyone is telling you to embrace AI. We are telling you to block it first.

This is not a don't-use-AI message. It is a know-exactly-which-AI message. You cannot write a credible AI policy for tools you cannot name, so blocking first turns an unmanaged risk into a managed decision. Then three steps, in order:

1

See

Run the Shadow AI report. Get the actual list: who, what, how often, how risky.

You cannot govern a rumour.
2

Block

Technical controls at the network and tenant level that stop unapproved AI tools. On office machines and the laptop in the spare bedroom alike.

A policy without enforcement is a memo.
3

Permit, deliberately

A short written AI policy naming the vetted tools: contracts that keep client data out of training models, and a human verifying every output. Then your firm uses AI with confidence, on your terms.

Your firm, your rules, in writing.
The firms that win with AI will not be the ones that adopted it fastest. They will be the ones that can name every tool touching client data, and prove to a regulator, an insurer or a judge that none of it trains on their clients' matters.
The 20-minute fix

Find out in 20 minutes what the SRA would find out in a year.

One report, run against your Microsoft environment. No installs, no disruption to fee earners.
A written, plain-English answer: who is using AI that you do not know about.
If the answer is nobody: you get that in writing, you sleep well, we leave you alone.
The first page of a real anonymised WPC Shadow AI Detection Report
The actual report. Yours takes 20 minutes.
Better you read it in our report this week than in the SRA's findings next year.
Forward this page to the partner whose name is on the practicing certificate.
Sources: SRA warning notice, Misuse of AI, 17 August 2026 · R (Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin) · [2026] UKUT 81 (IAC) · BCP v A Mother [2026] EWFC 71 (B) · Cork v Smith [2026] EWHC 1199 (Ch) · Anonymised WPC Shadow AI Detection Report, August 2026.