top of page
web banner Fika Friday.png

Article 4.3 · Navigating the Regulatory Landscape: SRA, Courts, and AI Accountability

  • Writer: Will Whawell
    Will Whawell
  • 4 hours ago
  • 9 min read

T3PS Legal Dynamics · Series 4: Practical AI for Legal Operations · Refreshed June 2026


Published as part of the "Practical AI for Legal Operations" series


If there is one lesson the past twelve months have delivered with unusual clarity, it is this: the regulatory framework for AI in legal practice does not need to be fully formed before it starts to bite. Courts are already making wasted costs orders. The SRA is already authorising AI-driven firms — and setting the conditions under which they operate. Judges are already considering contempt of court proceedings. The profession is living inside a regulatory environment that is more active than most firms have realised, and the firms treating compliance as an afterthought will not enjoy finding out the hard way.


I want to be direct about something before going any further. I am an ISO 9001 and ISO 27001 Lead Auditor. I have spent a considerable part of my career building governance frameworks and management systems in environments where the cost of getting it wrong is high. What I see in most law firms' approach to AI governance is not malicious. It is the same pattern I see in every sector when technology moves faster than process: adoption driven by enthusiasm, risk assessment driven by urgency, and governance arriving last — if at all.

That pattern is no longer an acceptable posture. Let me explain why.


The SRA's Position: Principles Apply, Specific Rules Are Coming

The Solicitors Regulation Authority has not yet enacted AI-specific regulations. This is sometimes interpreted as regulatory permission to proceed without particular caution. It is not. The SRA's position is that its existing Standards and Regulations apply fully to the use of AI — which means that if your AI tools are producing advice that causes client harm, or if your workflows are allowing AI-generated content to reach courts without adequate verification, the existing professional conduct rules are entirely adequate to create liability.


The SRA made its position concrete in May 2025 when it authorised the UK's first AI-driven law firm: Garfield.Law Ltd, which uses a large language model to guide businesses through the small claims court process. The authorisation is a landmark in itself. But the conditions attached to it are more instructive than the headline. The SRA required that: the system will not be able to propose relevant case law (classified as a high-risk area for hallucinations); every step requires client approval; named regulated solicitors remain ultimately accountable for all system outputs; and enhanced oversight applies during the initial phase. Garfield is not autonomous. It is supervised.


The conditions placed on Garfield tell you precisely what the SRA is worried about: AI-generated case law presented without verification; accountability gaps where no human is clearly responsible; and the risk that consumer protections are diluted by the efficiency gains that AI promises. These are not theoretical concerns. They are live issues in English courts right now.


The Hallucination Cases: A Warning the Profession Cannot Ignore

Ayinde v London Borough of Haringey should be required reading for every legal professional using AI tools. The case — decided by the Divisional Court in June 2025 — concerned a judicial review application in which the claimant's grounds cited five cases that did not exist. The barrister's explanation was found to be incoherent: she denied deliberately using AI but accepted she may have inadvertently relied on AI-generated responses to Google searches. The court found that the threshold for contempt of court proceedings had been met — either the barrister had deliberately included fabricated citations, or she had been untruthful in denying AI use. Contempt proceedings were not ultimately pursued, owing in part to the mitigating factor of counsel's relative inexperience. The judge's closing note was unambiguous: "Lawyers who do not comply with their professional obligations in this respect risk severe sanction."


The other case decided at the same hearing — Al-Haroun v Qatar National Bank — presents a perhaps more troubling scenario: the fabricated citations were generated by the lay client, passed to the barrister for advice, and the barrister, while correctly advising that the materials lacked merit, failed to identify that the citations were fictitious. The court found there was "scope for argument" that the barrister should have verified the citations regardless. The court described it as "extraordinary that the lawyer was relying on the client for the accuracy of their legal research, rather than the other way around."


That the client generated the fabricated cases is not a defence. The professional obligation to verify what goes before a court sits squarely with the legal team.


Ndaryiyumvire v Birmingham City University followed in October 2025. A member of the solicitors' administrative team had used a built-in AI research feature in legal software to draft an application, submitted it with two fictitious cases, and — extraordinarily — signed the statement of truth in the solicitor's name without the solicitor's knowledge or consent. The solicitor accepted that the cases were AI-generated and fictitious. HHJ Charman, applying the Ayindeguidance, found the conduct improper, unreasonable, and negligent, and awarded wasted costs on the indemnity basis. The judgment is to be published on the judicial website — a public admonishment.


The lesson from Birmingham City University is particularly sharp, and it is not primarily about AI hallucinations. It is about access control and supervision. A member of the administrative team was able to access an AI research tool, generate an application, and file it in the solicitor's name without any oversight checkpoint. That is a governance failure of the most basic kind, and it is one that a properly designed AI policy would have prevented.


The Regulatory Framework Taking Shape

The Civil Justice Committee's working group on AI in court documents — chaired by Lord Justice Birss — published its interim report and consultation in February 2026, with the consultation closing on 14 April 2026. The proposals are measured and graduated. The working group does not propose blanket prohibition or mandatory disclosure for all AI use. It draws a clear line: where AI has been used to generate evidence on which the court is asked to rely, disclosure is required. Administrative uses — transcription, spell-checking, formatting — do not require a declaration. Expert witness reports are explicitly included, with proposals to amend the statement of truth under Practice Direction 35 to require disclosure of AI use in expert evidence preparation.


Lord Justice Birss framed the objective precisely: "to maintain a balance, ensuring that the latest technology can be used to maximum advantage in the civil justice system in order to enhance access to justice by improving efficiency and reducing costs; while at the same time maintaining confidence in the rule of law."


That balance is achievable. But it requires firms to know, at any given moment, what AI tools have been used in document preparation and how — which in turn requires the governance infrastructure to track that usage.


At the legislative level, the Artificial Intelligence (Regulation) Bill 2025 — a private member's bill introduced in the House of Lords — proposes a dedicated AI Authority with a risk-based classification framework, mandatory impact assessments, and a requirement for businesses developing or deploying AI to appoint a designated AI Responsible Officer. The bill enshrines the five principles from the UK government's 2023 AI White Paper as legally binding duties: safety and security; transparency; fairness; accountability and governance; and contestability and redress. As a private member's bill, it does not currently have government backing and has not passed into law. But its architecture reflects the direction of travel, and the UK's principles-based approach is already being contrasted with the more prescriptive EU AI Act — a distinction that will matter for any firm operating across both jurisdictions.


The SRA's own compliance guidance requires senior oversight — at the level of Compliance Officer for Legal Practice (COLP) at minimum — appropriate governance and risk assessments, data privacy obligations under ICO guidance, and clear accountability when things go wrong. The SRA explicitly states that firms must have "appropriate governance, systems and controls to ensure you are using technology responsibly."


The Law Society of Scotland has made AI a key project for 2026, committing to "deepen and expand members' understanding of the safe, ethical, and effective use of AI in legal practice." This is part of 16 projects for the year, with AI listed alongside regulatory reform and access to justice — an indication of how seriously the profession's representative body in Scotland is taking the governance challenge.


What Firms Actually Need to Do

I want to resist the temptation to produce a generic compliance checklist at this point, because generic checklists produce box-ticking cultures rather than genuine risk management. But there are five practical steps that, in my experience, distinguish firms that manage AI risk well from those that are one wasted costs order away from a difficult conversation.


Appoint a named senior person with AI oversight responsibility. This does not need to be a new hire. It needs to be a named individual — ideally the COLP — who understands the regulatory landscape, is accountable for AI governance, and has the authority to make decisions when problems arise. The SRA's guidance makes senior oversight explicit. The Birmingham City University case illustrates what happens when that oversight is absent.


Build an AI risk register. Every AI tool in use at the firm — including tools adopted informally by fee earners — should be identified, logged, and assessed against a consistent risk framework. What data does it process? What outputs does it produce? Are those outputs verified before they reach clients or courts? Who is responsible for that verification? This is basic ISO 27001 discipline applied to AI, and it is not burdensome if done systematically from the start.


Establish a clear policy on AI-generated legal research. The Ayinde and Birmingham cases both involve AI-generated case citations reaching courts without verification. The policy needs to be simple, unambiguous, and applied to all staff — including administrative staff with access to AI-enabled legal software. Every citation must be verified against an authoritative source before it is filed. No exceptions. The SRA's condition on Garfield — that the system will not propose case law at all — is the most conservative implementation of this principle. For firms using AI research tools, a mandatory verification step is the minimum.


Conduct regular audits of AI tool usage. How frequently are tools being used? By whom? For what types of tasks? Are the outputs being reviewed before use? Are there patterns that suggest the verification steps are being bypassed? This is not surveillance for its own sake — it is the data you need to demonstrate to the SRA, and potentially to a court, that your firm uses AI responsibly. Without audit data, you have assertions. With it, you have evidence.


Train staff at every level. The Birmingham case is a training failure as much as a governance failure. An administrative staff member used an AI research tool without understanding the risks of hallucination, without understanding that citations must be verified, and without understanding the implications of filing a statement of truth. That is not the staff member's fault. It is the firm's. Training needs to reach everyone with access to AI tools, not just the fee earners.


The Wider Picture

The regulatory environment is evolving rapidly and will continue to do so. The CJC consultation closing in April 2026 will produce a final report with proposed rule changes. The AI (Regulation) Bill may or may not pass in its current form, but its principles will shape the regulatory conversation regardless. The PACCAR reversal, if and when it comes — it was absent from the May 2026 King's Speech and so remains uncommenced — will expand the litigation funding market and bring more complex, high-value cases into the system — with corresponding pressure on the AI tools used to run them. And the hallucination cases will continue to arrive at an increasing rate, because the tools are being used more widely by people who do not yet understand their limitations.


The profession that navigates this well is not the profession that waits for specific AI regulations before taking action. It is the profession that applies existing professional obligations rigorously to new technology, builds governance frameworks before problems arise, and treats AI oversight not as a compliance burden but as a fundamental component of the professional duty of care.


That is not a radical proposition. It is exactly what the profession has always done when new tools arrive. The difference this time is the pace of adoption and the severity of the consequences when governance fails. A wasted costs order is embarrassing and expensive. A contempt of court finding is career-defining. A BSB referral is reputational. None of them are inevitable — if the governance is in place.


Questions worth sitting with:

1.    If the SRA came to your firm tomorrow and asked to review your AI governance framework, your risk register, and your staff training records — how confident are you in what they would find?


2.    The Ayinde and Birmingham cases involved AI tools being used by individuals who either did not understand the risks or bypassed verification steps. Do you know who in your firm has access to AI research and drafting tools — including embedded tools in legal software — and whether they have been trained on their obligations?


3.    The CJC's proposed framework draws a line between AI used for administrative purposes and AI used to generate substantive evidence. As AI capabilities evolve and that line becomes harder to identify in practice, what does your firm's approach to disclosure look like — and is it robust enough to survive scrutiny?


Series 4 of "Practical AI for Legal Operations" is written by a legal project manager with 37 years' experience in the UK legal sector, specialising in litigation management, costs, and AI-driven process improvement. Previous series in this collection cover the AI efficiency paradox, pricing models for the AI age, and building practical AI workflows in legal practice.

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page