How it worksPricingServicesDevicesAboutFree assessment

Find where AI pays off in your business, and prove the return. A Logicly company.

Product

  • How it works
  • Pricing
  • The assessment
  • Graft Devices

Company

  • Services
  • About
  • Contact

Industries

  • AI for law firms
  • AI for accountancy firms

Resources

  • Blog

Legal

  • Privacy
  • Terms
© Graftgraft.bot
  1. Home
  2. /Blog
  3. /The SRA's AI warning notice: how to respond without banning AI

The SRA's AI warning notice: how to respond without banning AI

The SRA's 17 August 2026 warning notice named two AI risks for law firms. Banning AI quietly makes both worse. Here is the response that lowers risk instead.

This is general information, not legal or regulatory advice, and Graft is not a law firm. For advice on your obligations under the SRA Standards and Regulations, speak to your COLP, COFA, or a qualified solicitor.

The Solicitors Regulation Authority published its warning notice on the misuse of AI on 17 August 2026. It followed 42 reports of potential AI misuse between July 2025 and July 2026, which the regulator is now investigating. If you run risk or compliance at a law firm, it has probably already landed on your desk with a "what do we do about this" attached.

The notice does not ban AI. It draws a line under two specific failures the regulator keeps seeing.

What the SRA actually said

The first concern is hallucinated law. AI tools invent cases, citations, and confident-sounding assertions that have no basis in fact, and some of those have ended up in front of judges. The SRA's own view is blunt: reliance on an AI output is not a defence, and where false citations reach a court, the court is likely to refer the matter to the regulator. Supervisors are on the hook too, if work goes out without adequate review.

The second concern is confidentiality. Client information gets entered into public tools that carry no safeguards. The SRA warns that doing this will likely breach client confidentiality, and that legal professional privilege may be permanently waived and impossible to recover. Once a client's file has gone into an open model, you cannot pull it back out.

Underneath both is one line the notice repeats in different words: "The use of AI does not diminish or transfer your professional responsibilities." A tool has no practising certificate. The solicitor who relied on it does.

None of this is anti-AI. The SRA's own news release notes that firms are already using AI to improve services, and asks for oversight and controls rather than abstinence.

The two traps

Most firms react in one of two ways, and both make the problem worse.

The first is to ban it. Send the all-staff email, block the domains, declare AI off-limits until further notice. It feels decisive. It doesn't work. The fee-earner who was quietly saving time with ChatGPT does not stop. They stop telling you. The usage moves onto personal phones and home laptops where you have no logging, no policy, and no way of knowing a client matter went into a public model until it surfaces somewhere you cannot retract it. A ban does not remove the risk the SRA is worried about. It removes your sight of it.

The second trap is to do nothing. Drop a paragraph into the staff handbook, link the warning notice, and hope. That leaves every risk in place and adds a paper trail proving you knew about it.

The move that actually lowers risk

You cannot govern what you cannot see. Before you write another policy, find out where AI is already being used across the firm, in which matters, and against what data. Then judge each use on two questions: is it safe, and is it paying off.

That order matters. A blanket rule written in the dark either strangles the work that was helping or waves through the work that was dangerous, because you had no way to tell them apart. Visibility first, then a decision you can actually defend.

Where Graft fits

Graft connects to the systems your firm already runs on, your practice and document management, email, and finance tools, and reads how work actually flows. It does not ask fee-earners to fill in a survey they will rush on a Friday afternoon. That surfaces the AI use you know about and the shadow AI you don't, mapped to the matters and the data each touches.

From there the decisions get easier. Shut down what is unsafe. Put proper, sanctioned tooling around what is valuable. Show the return in pounds on the parts worth keeping, and keep a record that the controls are working.

That last part is the half of the notice most coverage skips. The SRA wants oversight and controls. "Here is every place AI touches client work, and here is the evidence it is controlled and paying its way" is a far easier conversation to have with a regulator, a client, or your own board than a policy nobody can prove anyone follows.

What to do this week

You do not need a committee to start. Get a real picture of where AI already sits in the firm before you decide anything. That single step turns the warning notice from a threat into a plan: safe, and paying off, with the evidence for both.

Graft's free connected assessment finds where AI is already at work in your firm and where it will actually pay off, by reading your real systems rather than asking. For the fuller picture built for firms, read AI for law firms.