Products
SCRS — the AI data firewall Other Me — the workspace Compare both products
Solutions
All solutions AI Assistants Email + Projects CRM Live Chat Ticketing Flows HR-lite Control Center
By industry
Accountancy Legal Mortgage & IFA Healthcare
Company
Custom Solutions Pricing Blog About Us
Log in
SCRS login Other Me — Business Other Me — Family Get started with SCRS
Legal · · 11 min read

SRA Guidance on AI for UK Solicitors (2026): What Your Firm Actually Needs

AS

Founder & CEO, Pop Hasta Labs

From my perspective, the SRA has been quieter on AI than most people expect, and that quietness is being misread. Firms I speak to are assuming that no explicit AI rule means no AI risk. I believe this is backwards. The SRA hasn’t written an AI-specific rulebook because it doesn’t need to. The Principles and the Code of Conduct already apply to AI use, exactly as they apply to a paralegal filing papers at 4pm. If AI use breaches Principle 7, you’ve breached Principle 7.

So the question isn’t “what does the SRA say about AI?” The question is “how do the Principles and Code apply to AI use in my practice, and what evidence would my COLP need to show compliance?” That’s what this piece tries to answer.

Principle 7: confidentiality applies to AI tools

Principle 7 is the one every solicitor knows: you must act in a way that keeps the affairs of clients confidential. This principle doesn’t exclude AI. Specially when you consider how most AI tools work — ChatGPT, Claude, Gemini in their consumer form send your prompts to a third-party model and may use them for training. If your associate pastes a client’s bundle into ChatGPT to summarise it, that bundle has left your control. Principle 7 has been breached, whether or not there’s an enforcement action.

The SRA’s position, even without specific AI guidance, would be that a solicitor using AI must take reasonable steps to ensure confidential information is not disclosed. “Reasonable steps” in 2026 means using an AI tool where confidentiality is architectural, not just promised. It means being able to demonstrate — to a COLP review, to a client who asks, to the SRA if they ever do — exactly where client data travels when your firm uses AI.

The Code of Conduct: competence and supervision

Code paragraph 3.4 requires you to supervise and control matters. Paragraph 3.6 requires you to ensure services to clients are performed by staff with appropriate experience. Apart from this, the Code requires you to keep your knowledge up to date. All three apply directly to AI use.

In practice, this means three things. One, an AI-assisted piece of work still needs qualified fee-earner sign-off. The AI can draft; the solicitor must review and take responsibility. Two, the solicitor must understand the AI well enough to spot when it’s wrong — hallucinations are a real risk and any fee-earner relying on AI output without reading it is failing the competence test. Three, supervising AI use across the firm is now part of the managing partner’s job, not an optional extra.

What your COLP needs to evidence

Specially for firms in the 2 to 30-fee-earner range, COLPs are asking themselves what they’d show the SRA if an AI-related complaint ever arrived. I tend to focus on four evidence streams when I advise a practice.

First, policy. A written AI policy that states what tools are approved, what data may go into them, and what sign-off is required. Second, audit. A log showing which fee-earner used AI on which matter, what data the AI saw, what output was produced, and who signed off. Third, matter isolation. Evidence that client A’s matter doesn’t leak into client B’s matter through the AI tool — Chinese walls made structural, not just written into the policy. Fourth, leaver handling. Evidence that when staff leave, their AI access and historical prompt data are dealt with cleanly.

From my perspective, this evidence list is actually easier to produce with AI than without, provided you’re using a tool built for it. SCRS — our patent-pending AI data firewall — produces this audit chain as a matter of course, and Other Me, the governed workspace built on it, hands you that evidence rather than making you reconstruct it. Without such a tool, you’re relying on the honesty of your fee-earners’ browser histories, which isn’t an evidential standard.

Practical steps for your firm this quarter

If you’re a COLP or managing partner reading this, I’d start with three practical actions. Audit what AI your fee-earners are using right now — a plain conversation, not a disciplinary one. Write a short AI policy (we’ve published a free template for UK SMEs that you can adapt for a solicitor firm in an hour). And put a governed AI platform in front of your fee-earners that gives you the evidence your COLP review will need, without changing how your associates work day-to-day.

This is exactly the scenario SCRS was built for. Per-matter retrieval isolation, tamper-evident audit chain, a kill switch on leavers — the whole control environment a COLP would want, with Other Me giving your fee-earners a governed workspace on top of it. You can read how it works for SRA-regulated firms on the law firms solution page, or get started and see for yourself.

Where I think SRA guidance goes next

I believe the SRA will publish AI-specific thematic guidance within the next 12 months, probably via the Thematic Review process that’s been used for money-laundering and equality in previous years. The guidance will, in my view, be less about banning AI and more about evidencing appropriate controls. Firms that already have the policy, the audit chain, and the governed tool in place will have nothing to retrofit. Firms that haven’t started will be scrambling.

Apart from this, I think the SRA’s clients — meaning the clients your firm serves — will move faster than the regulator. Fintech clients, regulated institutions, public bodies are already asking their legal advisors how AI use is controlled. If you have a good answer, you keep the client. If you don’t, you lose them to a firm that does.

AS

Abhishek Sharma

Founder & CEO of Pop Hasta Labs. Building SCRS — the patent-pending AI data firewall — and Other Me, the governed workspace built on it. Based in London.

Related articles

Govern the AI your team already uses.

SCRS keeps client data out of the model — and Other Me is the whole governed workspace, built on it. No sales calls; set yourself up in minutes.

Get started with SCRS → Try Other Me