Someone in your firm is already using AI on client work.
The SRA just made that your problem.
Not the AI you approved. The AI you have never heard of. The SRA's new warning notice makes partners accountable for it, and four court judgments show what happens next.

This is not a hypothetical. These judgments have real lawyers' names in them.
The SRA's notice is built on cases that have already happened. Three of them tell you everything you need to know.
AI invented the citations. The High Court noticed.
Fictitious AI-generated case citations were put before the court. Wasted costs followed. The solicitor and barrister were referred to their regulators.
Pasting client letters into ChatGPT puts them "in the public domain."
The Upper Tribunal's words, not ours. Feeding client correspondence into an open AI tool is publishing it to the internet. There is no motion to un-publish it.
Not intentional. The court treated it seriously anyway.
A court misled by AI hallucinations, without any intent to deceive. It made no difference to how seriously the court took it.
The risk worse than hallucinations: your client's matter becomes the machine's memory.
Free AI tools are free because you pay in data. Paste a matter into one and it can be retained, used to train the model, and echoed back in a stranger's answer. The SRA's rule is explicit: client data must not train an AI model except where explicitly authorised. Of the 12 shadow apps below, how many train on what your staff feed them? The partners could not say either.
We measured it. Here is one real firm.
A 14-person professional practice. One reporting period. Names removed, numbers untouched. The firm believed the answer was zero.
Scale that to a 60-person firm: roughly 25 people and hundreds of unsupervised sessions a month, some of it on privileged material, all of it under your practising certificate.
The industry calls it Shadow AI. A law firm has an older name for it: unsupervised work on client matters.
Everyone is telling you to embrace AI. We are telling you to block it first.
This is not a don't-use-AI message. It is a know-exactly-which-AI message. You cannot write a credible AI policy for tools you cannot name, so blocking first turns an unmanaged risk into a managed decision. Then three steps, in order:
See
Run the Shadow AI report. Get the actual list: who, what, how often, how risky.
Block
Technical controls at the network and tenant level that stop unapproved AI tools. On office machines and the laptop in the spare bedroom alike.
Permit, deliberately
A short written AI policy naming the vetted tools: contracts that keep client data out of training models, and a human verifying every output. Then your firm uses AI with confidence, on your terms.
