Lawyers grapple with the reputational perils of AI misuse

26 Aug 2026

Oliver Simpson reports on new regulatory guidance designed to keep law firms on the straight and narrow when it comes to AI

Legal watch dog, the Solicitors Regulation Authority (SRA), has issued a new warning notice on the use of artificial intelligence in legal services. Its message is straightforward: AI may change how legal work is produced, but it does not change who is responsible for it.

The intervention follows 42 reports of potential AI misuse received by the regulator between July 2025 and July 2026. Ongoing investigations include concerns around inaccurate legal citations, inadequate supervision and breaches of client confidentiality. While the SRA recognises that AI can benefit both consumers and legal professionals, it is clear that firms and individual solicitors remain accountable for every output produced using it.

The SRA is not alone in drawing attention to and addressing these risks. In May, the Bar Standards Board also issued guidance on the safe and responsible use of AI, emphasising that barristers must understand the technology and continue to meet their existing professional duties.

Importantly, the SRA notes that there are serious implications for the reputation of lawyers and the law if AI is misused by those operating in the legal services sector.

What the warning means in practice

The SRA focuses on two principal risks. The first is the risk presented by “hallucinations”: AI generating convincing but false material, including fabricated authorities and inaccurate legal analysis. The second is client confidentiality, particularly where client information is entered into public or inadequately protected AI tools.

Neither creates a new category of professional obligation. Instead, the SRA is applying familiar duties (including competence, supervision, confidentiality and the obligation not to mislead the court) to new technology. Reliance on AI will not provide a defence where inaccurate material is submitted, while supervisors may also be held responsible where work has not been reviewed adequately.

Therefore, the notice is less a restriction on AI adoption than a warning against the outsourcing of professional judgement. Firms retain freedom to decide how they use these tools, but must be able to demonstrate appropriate human oversight, informed professional judgement and a proportionate, risk-based approach. Failure to do so may result in disciplinary action.

Therefore, the notice is less a restriction on AI adoption than a warning against the outsourcing of professional judgement.

When an AI error becomes a reputational crisis

The communications implications and risks extend beyond regulatory compliance. An invented citation or confidentiality breach is unlikely to be perceived or dismissed as a discrete technical mistake. It may instead raise broader questions about professional competence and a firm’s ability to ensure client confidentiality.

Firms should communicate the warning internally in clear and practical terms. This should include:

  • Explaining what the SRA’s notice means for different teams and areas of practice;
  • Reminding staff which AI tools are approved and what information must never be entered into them;
  • Clarifying who is responsible for checking AI-assisted work;
  • Providing a clear route and mechanisms for reporting errors or suspected confidentiality breaches; and
  • Ensuring senior leaders reinforce that responsibility for an output always remains with the individual lawyers and the firm.

The notice also makes communications preparation critical. Communications teams should understand where AI is being used, who owns the associated risks and how an incident would be escalated. Any response will require close coordination between a broad set of actors, including legal, compliance, information security and communications teams to establish what information entered the system, how its output was used, who was affected and whether the regulator, court or clients must be notified.

The instinct to describe an incident as isolated “human error” should also be treated cautiously. Where the underlying problem concerns weak supervision or absent controls, that framing may appear evasive and create a second credibility problem.

Equally, silence or a blanket rejection of AI is unlikely to provide a sustainable answer. Clients increasingly expect firms to use technology effectively and securely. The strongest reputational position will belong to those able to demonstrate responsible adoption: clear policies, meaningful oversight, workforce training and credible evidence that AI tools and output remain subordinate to professional judgement.

The wider lesson from the SRA’s warning is that an AI failure will rarely be judged as a failure of technology alone. Stakeholders and the public will look instead at the decisions surrounding its use: the controls in place, the judgement exercised and the organisation’s response when something went wrong. Those factors will determine whether an error is contained or becomes a broader crisis of trust.