SRA AI Compliance Tips, Explained: What UK Solicitors Actually Need to Do in 2026

The SRA's February 2026 update restates how existing Standards and Regulations apply to AI. Here's what it actually means for a firm working out its AI approach in 2026.

The SRA has not banned AI, and it has not written new rules for it either. Its Compliance tips for solicitors regarding the use of AI and technology, last updated 9 February 2026, restates how the existing Standards and Regulations apply to AI tools. The short version: you may use AI, you stay personally accountable for anything it produces, you must protect client confidentiality, and it should always be clear to clients where they are interfacing with AI.

Everything else in the guidance is detail on how to operationalise those four points. Here’s what that detail actually means for a firm working out its AI approach in 2026.


What the SRA’s February 2026 Update Actually Says

The compliance tips page isn’t a standalone AI policy: it’s guidance woven through the SRA’s broader “lawtech” resource, covering everything from cloud storage to electronic ID verification. The AI-specific content sits within that wider frame, and it comes down to a few recurring expectations:

  • Governance sits with the COLP. The SRA expects the Compliance Officer for Legal Practice to be responsible for regulatory compliance whenever new technology, including AI, is introduced. Board-level oversight of both purchasing and ongoing use is flagged as critical.
  • Client interests come first, structurally. Firms need “appropriate governance, systems and controls”, not just good intentions, to use AI responsibly.
  • Transparency is non-negotiable. The guidance states plainly that “it should always be made clear to clients where they are interfacing with AI.”
  • Data protection obligations apply in full. If your AI product processes personal data, ICO obligations on explaining automated decisions and profiling apply, on top of standard confidentiality duties.
  • Vulnerable clients need extra thought. The SRA asks firms to identify and address risk factors that could let AI-driven services exploit vulnerable consumers.

None of this introduces a new legal test. It’s the SRA doing what it typically does with new technology: regulating by outcome, not by prescribing specific tools or techniques, and leaving the “how” to the firm.


The Five-Part Governance Framework

Read across the guidance, the SRA is asking firms to build AI governance around five activities:

  1. Leadership and oversight: someone senior (in practice, the COLP) owns AI use across the firm.
  2. Risk and impact assessments: done before a tool is adopted, and revisited as use scales.
  3. Policies and procedures: documented, not assumed.
  4. Training and awareness: for anyone actually using the tools, not just the person who bought them.
  5. Monitoring and evaluation: checking for unintended consequences on an ongoing basis, not a one-off sign-off.

If your firm can’t point to something concrete under each of these five headings, you don’t currently have an SRA-aligned AI governance approach; you have a tool subscription.


Which Existing Code Obligations Actually Bite

The compliance tips page sits on top of obligations that were already in the SRA Code of Conduct for Solicitors and Code of Conduct for Firms before AI existed. Three matter most in practice; the paragraph numbers below are those of the Code of Conduct for Solicitors, RELs and RFLs.

Competence. Paragraphs 3.2 and 3.3 require competent, timely service and up-to-date professional skills. Applied to AI, this means understanding a tool well enough to catch it being wrong, not just well enough to operate it.

Confidentiality. Paragraph 6.3 requires current and former client information to stay confidential. Before any client data goes into a third-party AI system, a firm needs to have actually assessed the provider: where data is processed, whether it’s used to train the underlying model, and whether an appropriate data processing agreement is in place.

Not misleading the client. Paragraph 1.4, read with SRA Principles 4 and 5 (honesty and integrity), is the provision that underpins the SRA’s transparency expectation. If a client is engaging with AI-generated advice or drafting without knowing it, that’s a live compliance question, not a hypothetical one.


The Citation Problem the SRA Is Really Worried About

The compliance tips don’t spell out hallucination case by case, but it’s the risk sitting behind the guidance’s emphasis on competence and verification, and it’s already produced real consequences in English courts.

In Ayinde v Haringey LBC and Al-Haroun v Qatar National Bank [2025] EWHC 1383 (Admin), decided together by the Divisional Court on 6 June 2025, the court (Dame Victoria Sharp P and Johnson J) held that “freely available generative artificial intelligence tools, trained on a large language model such as ChatGPT are not capable of conducting reliable legal research” and warned that lawyers relying on unverified AI output risk penalties up to contempt of court.

In Ndaryiyumvire v Birmingham City University (County Court at Birmingham, 14 October 2025), HHJ Charman made a wasted costs order against the claimant’s firm after two fictitious AI-generated authorities appeared in an application verified by a statement of truth; he found the conduct of both the solicitor and the firm improper, unreasonable and negligent, but declined to make a separate SRA referral of the solicitor, treating the failure as one of firm-level supervision and document control.

In 2026, Recorder Howard at Bournemouth Family Court ordered that a lay advocate — an unregistered barrister who held herself out as a lawyer and offered paid legal work to the public — be named in the published judgment after her skeleton argument advanced four citations or propositions that were not real.

The pattern across all of these: the AI tool isn’t the one facing sanctions. The lawyer who filed without checking is.

Minimum verification steps for AI-assisted legal research:

  1. Check every case citation against an authoritative source. Ayinde names the National Archives’ Find Case Law database, the official Law Reports, and the databases of reputable legal publishers such as Westlaw and LexisNexis.
  2. Check every statutory reference against legislation.gov.uk.
  3. Check any regulatory guidance reference directly against sra.org.uk.
  4. Keep a record of what was checked and when.

Tools that retrieve from live legal sources rather than generating text purely from training data reduce this risk substantially, but they don’t eliminate the solicitor’s duty to verify.


What a Compliant AI Policy Should Cover

The SRA doesn’t mandate a template, but its enforcement approach weighs whether a firm took reasonable, documented steps. A proportionate policy — even a one-pager for a small firm — should cover:

  • Approved tools, and which tasks each one is cleared for.
  • Verification obligations, spelled out per task type, not left to individual judgement.
  • Confidentiality controls, including what categories of client data may never go into a general-purpose AI tool.
  • Billing guidance, so AI-assisted time is recorded and charged consistently with what clients were told.
  • Record-keeping, so AI use in a matter is documented, not invisible.
  • Training, completed before anyone uses an approved tool unsupervised.

Practical Next Steps

  1. Read the SRA’s compliance tips page directly and bookmark it; it’s updated periodically, most recently 9 February 2026.
  2. Audit what AI tools fee-earners are already using informally. Most firms are behind on this, not ahead.
  3. Add a line on AI use to client care letters where it’s material to the matter.
  4. Draft or update a firm AI policy against the six points above.
  5. Choose research tools that surface verifiable, clickable citations by default, so verification is a built-in step rather than a separate task someone has to remember to do.

Frequently Asked Questions

Does the SRA allow solicitors to use AI tools? Yes. The SRA has not banned AI. Solicitors may use it provided they remain personally responsible for the work produced, verify AI outputs, and protect client confidentiality.

Who is responsible if AI gets the law wrong? The solicitor, not the AI provider. Using AI does not transfer or dilute professional responsibility under the SRA Standards and Regulations.

Do solicitors have to tell clients they used AI? The SRA’s guidance states it should always be clear to clients where they are interfacing with AI. How and where that’s disclosed — typically in a client care letter — is left to the firm’s judgement based on the circumstances.

What happens if a solicitor files fake AI-generated citations? UK courts have already sanctioned lawyers for this. Consequences documented in reported cases range from wasted costs orders against the firm to public naming and warnings of contempt proceedings for unverified AI-generated citations.

When was the SRA’s AI guidance last updated? The compliance tips page was last updated 9 February 2026. It does not create new rules; it applies the existing SRA Standards and Regulations to AI use.


The AI Bar’s AI Foundations for Lawyers and Legal Research with AI modules cover verification workflows and governance frameworks like the one above in practical detail, built for solicitors, advocates and in-house teams working across UK, India and common law jurisdictions.