SRA Issues Formal Warning Notice on AI Misuse After Receiving 42 Reports of Potential Breaches in 12 Months
The Solicitors Regulation Authority (SRA) published a warning notice to the solicitors' profession, disclosing that it received 42 reports of potential AI misuse between July 2025 and July 2026, with a number of investigations currently ongoing. The notice addresses two categories of risk: AI-generated hallucinations in legal research, advice, and court submissions; and confidentiality breaches arising from entering client information into AI tools without adequate safeguards. The SRA cited the case of Pinsent Masons, which self-reported after a junior solicitor used AI to draft two misleading letters in an insolvency application. The case is referred to by name in the warning notice as *Cork and another v Smith*, in which Insolvency and Companies Court Judge Mullen publicly admonished the firm. Sullivan and Cromwell is also referenced in coverage of the notice for a separate incident in which AI-hallucinated citations appeared in a filing to a New York judge. The notice states that solicitors remain accountable for their work regardless of how it was prepared, and that firms must have effective governance structures and controls in place to manage AI risks. On confidentiality, the SRA warned that entering client information into open-source tools such as ChatGPT would amount to a waiver of privilege, and that client data should only be entered into AI systems where appropriate contractual, technical, and organisational safeguards exist. The Bar Standards Board (BSB) had earlier in 2026 issued a similar notice warning barristers that free AI tools would generally be unsuitable for legal work. Law Society of England and Wales vice president Brett Dixon welcomed the notice.
Why this matters
The SRA's warning notice is significant because it is the first time the regulator has issued a formal, sector-wide alert specifically addressing AI misuse, backed by a disclosed volume of reports and named enforcement referrals. The 42 reports in 12 months, combined with ongoing investigations, signals that AI-related professional conduct risk is now a live regulatory enforcement issue rather than a theoretical concern. The naming of Pinsent Masons sets a precedent that self-reporting does not guarantee anonymity and that AI-related conduct failures can reach the public record. For firms deploying generative AI at scale, the notice creates an urgent compliance obligation to document governance frameworks and safeguards.
On the Ground
The notice creates immediate demand for AI governance policy work across all SRA-regulated firms, including audits of which AI tools are in use, whether appropriate data processing agreements are in place, and whether oversight protocols meet the SRA's expectations. Lawyers advising law firms on regulatory compliance will be reviewing existing AI policies against the notice's requirements. Trainees and junior associates should expect to assist in drafting or updating AI governance policies, reviewing vendor contracts for data handling provisions, completing vendor due diligence questionnaires, and preparing regulatory impact assessment memos summarising the SRA's stated expectations.
Interview prep
Question you might get
“How does the SRA's warning notice change the compliance obligations of a law firm that already uses generative AI tools for legal research?”
Sign up free to see the full answer
A model answer you can lift into an interview — how to frame this story for a partner.
Sign up freeSources
My notes
saved