From the journal

UK Solicitors Regulation Authority Issues Warning Notice on AI Misuse in Legal Practice, 17 August 2026

The Solicitors Regulation Authority published a Warning Notice on 17 August 2026 alerting solicitors and law firms in England and Wales to professional conduct risks from AI misuse, including submission of non-existent AI-generated citations and confidentiality breaches through open-source AI tools. The SRA received 42 AI-related misconduct reports between July 2025 and July 2026 and confirmed ongoing investigations.

2 min read

The Solicitors Regulation Authority (SRA) published a Warning Notice on 17 August 2026 directed at solicitors and law firms regulated under the SRA Standards and Regulations in England and Wales. The notice is a regulatory guidance instrument signalling enforcement priorities. It does not amend the Code of Conduct but identifies conduct already prohibited under existing obligations.

The Warning Notice invokes solicitors' duties under SRA Principles 2 and 7 (acting with integrity and in clients' best interests) and Code of Conduct obligations on competence, candour to the court, and confidentiality. The SRA cited two decided cases: in R (on the application of Ayinde) v Haringey LBC [2025] EWHC 1383 (Admin), AI-generated case citations that did not exist were filed with the Administrative Court. In Secretary of State for the Home Department v UK [2026] UKUT 81 (IAC), the Upper Tribunal found that uploading client documents and Home Office letters to an open-source AI tool such as ChatGPT likely constituted a breach of client confidentiality obligations.

Solicitors must verify every AI-generated citation before filing any document with a court or tribunal; personal responsibility for accuracy cannot be delegated to an AI tool. Law firms and in-house legal teams that allow staff to feed client-sensitive information into open-source AI tools without data processing agreements and confidentiality controls risk disciplinary referral to the SRA and notification obligations under UK GDPR Article 33 in the event of a personal data breach.

The SRA received 42 reports of potential AI misuse in the twelve months to July 2026 and confirmed multiple ongoing investigations. No amendments to the Code of Conduct to create AI-specific conduct rules have been proposed. Supervision of staff who use AI tools in client-facing work remains a firm-level obligation under the SRA's employer requirements. The SRA stated it would take regulatory action where breaches of existing duties are established.

Licentium advises law firms, in-house legal departments, and legal technology businesses on AI governance in regulated legal practice, including data processing compliance and supervision procedures for AI-assisted workflows. We may draw on our partner network for SRA and UK GDPR specialist counsel. Work we undertake includes AI policy drafting for legal teams, data protection impact assessments for AI tools, professional conduct advisory, and legal technology regulatory analysis.

Source: Solicitors Regulation Authority, Misuse of AI Warning Notice, 17 August 2026

More from the journal

See all
Illia Prokopiev

Foreign Ownership of a Delaware or Wyoming Entity: Federal Tax Classification, Information Reporting, Withholding, and State Duties

A non-U.S. person may own a Delaware or Wyoming LLC or a Delaware corporation, yet formation alone does not settle the federal tax result, the reporting burden, confidentiality, or the right to work in the country. This part takes the U.S. entity as chosen and examines classification, Form 5472 reporting, source and effectively connected income, partner and shareholder withholding, tax residence and immigration, duties beyond the formation state, real property and estate exposure, and treaty and home-country dependencies.

Illia Prokopiev

Structuring Cross-Border Digital-Asset Ventures (Part 2)

A cross-border digital-asset group must allocate protocol stewardship, token issuance, customer-facing regulated services, pooled investment, treasury, and founder functions before it selects any jurisdiction. The question presented is where each of those functions can lawfully sit across sixteen jurisdictions and the European Union and EEA overlay, as of 27 August 2026.

Illia Prokopiev

Function-First Entity Design for Cross-Border Digital-Asset Ventures

Cross-border digital-asset ventures often separate several legal roles. Those roles include the venture issuer, operating company, customer-facing licensee, token issuer, pooled vehicle, treasury body, and protocol administrator. The Question Presented is which roles eight jurisdictions can support as of 27 August 2026.