AI-Assisted Drafting and Document Review: Guidance for Solicitors

What the SRA's warning notice and the Law Society's guidance mean in practice: competence and supervision duties, confidentiality risk with third-party AI tools, the hallucinated-citation cases that reached the High Court, and a practical adoption checklist for firms.

Learnsignal Education Team
9 min read
Updated

Generative AI tools are now a normal part of how many solicitors draft letters, summarise disclosure, and research points of law. Used well, they save time. Used carelessly, they have already put solicitors and barristers in front of the High Court and the regulator. This guide sets out what the Solicitors Regulation Authority (SRA) and the Law Society expect from firms using AI in client work, the real cases where fabricated citations caused serious professional consequences, and a practical framework for adopting these tools without exposing the firm — or the client — to risk.

Why the regulators are paying close attention now

The SRA has been explicit that existing professional obligations apply in full to AI-assisted work — there is no lighter-touch standard because a document was drafted with help from a chatbot. In its warning notice on the misuse of AI, issued 17 August 2026, the SRA flagged three recurring problems it was seeing across reports and investigations: fabricated case law and legal authorities appearing in court documents, client confidentiality being put at risk through the use of public AI tools, and inadequate supervision of junior staff and support workers using AI without proper verification of the output. The notice followed a period in which the SRA said it was looking into dozens of reports of AI misuse by firms and individual solicitors.

The message is consistent with the Law Society's own position in its "Generative AI — the essentials" guidance: AI can be a legitimate and valuable tool, but the solicitor who signs, files or sends a document remains fully accountable for its content, exactly as if they had drafted it entirely by hand. If your firm is building AI into its workflow, it is worth pairing that work with wider continuing professional development on legal technology and risk so that fee earners understand not just how to use these tools, but where the professional conduct lines sit.

The duty of competence and supervision

Under the SRA Principles and the Code of Conduct, solicitors must act with competence, and supervising solicitors must ensure the work of those they supervise is properly checked. Neither obligation is diminished by delegating a task to software rather than a trainee or paralegal. In practice, this means:

  • A solicitor must understand, at least at a working level, the limitations of the AI tool they are using — including that outputs can be fluent, confident and completely wrong.
  • Supervisors are responsible for the AI-assisted output of everyone they supervise, including support staff and paralegals who may reach for a public chatbot without realising the professional conduct implications.
  • "I didn't know the AI made it up" is not a defence to a competence or supervision complaint — the duty to verify sits with the human signing off the work, not the tool that produced it.

Firms that treat AI competence as a one-off induction session tend to see the same errors resurface with each new hire or new tool rollout. Building it into ongoing training — alongside broader skills like clear legal writing, which AI drafting tools can undermine as easily as they can support — keeps the standard consistent as the technology and the team both change.

Confidentiality and privilege risk with third-party AI tools

Client data pasted into a public or consumer-grade AI tool does not necessarily stay confidential. Many free or low-cost AI services retain user inputs to train or improve their models unless a firm has negotiated specific contractual terms — an enterprise agreement with data-processing and no-training clauses, for example — that prevent this. Pasting privileged material, personal data, or commercially sensitive client information into a tool without checking those terms can amount to an unauthorised disclosure, a breach of the SRA's confidentiality requirements, and a potential data protection failure under UK GDPR.

There is also a subtler privilege risk: once client information has left the firm's controlled environment and been processed by a third party without appropriate safeguards, it becomes harder to argue that legal professional privilege was maintained, because privilege depends on confidentiality being preserved throughout. Firms that want to understand this risk in more depth — not just for AI, but for the wider range of situations where privilege can be inadvertently waived — should read our companion guide on legal professional privilege in practice.

The practical fix is procurement, not prohibition. Firms should maintain an approved list of AI tools that have been through proper due diligence — checking where data is processed and stored, whether it is used for model training, and what contractual protections apply — rather than leaving individual fee earners to make that judgement call tool by tool.

When AI invents the law: the hallucinated citation cases

The clearest illustration of what goes wrong reached the High Court in 2025. In the joined judgment R (Ayinde) v London Borough of Haringey and Al-Haroun v Qatar National Bank [2025] EWHC 1383 (Admin), handed down on 6 June 2025, the Divisional Court dealt with two unrelated cases in which fabricated case law had been put before the court.

In the Ayinde case, grounds for judicial review in a homelessness matter contained at least five fabricated case citations — including a case that did not exist at all — along with a misstatement of the Housing Act 1996. The court found that the pupil barrister who drafted the document had met the threshold for contempt of court, though it exercised its discretion not to bring formal contempt proceedings. She was referred to the Bar Standards Board, and the instructing solicitor was referred to the SRA over the supervision failures that allowed the document to be filed unchecked.

In the Al-Haroun case, witness statements filed in an $89.4 million claim against Qatar National Bank contained numerous false case citations and misquotations, after the lay client used ChatGPT and online research tools and passed the output to his solicitor without independent verification. The court described the solicitor's reliance on that unchecked research as an "extraordinary" and "lamentable failure," and both the solicitor and his firm were referred to the SRA.

No one involved was found to have deliberately misled the court, but that was precisely the court's point: the risk is not solicitors knowingly filing lies, it is solicitors and their supervisees trusting fluent-sounding AI output without checking it against the real law reports. The judgment has become a standard reference point in SRA and Law Society guidance precisely because it shows the disciplinary consequences are real, not theoretical, and they fall on the solicitor of record and their supervisor — not the software.

Human review before filing or sending: a practical checklist

Whatever tool is used, nothing AI-assisted should leave the firm — whether filed with a court, sent to opposing counsel, or emailed to a client — without a human check against primary sources. A workable minimum standard includes:

  • Verify every citation independently. Every case name, citation and quoted passage generated or suggested by AI should be checked against a proper legal database (Westlaw, Lexis, BAILII, or the official law reports) before it appears in any document leaving the firm.
  • Check facts against the file, not the model. AI tools can misstate dates, figures, and even the terms of documents you have already given them — always reconcile output against the source documents.
  • Never let AI be the final signatory-level check. A qualified fee earner with responsibility for the matter should read the final version in full before it is sent or filed, exactly as they would with a trainee's draft.
  • Record what was AI-assisted. Some courts and tribunals now expect disclosure of AI use in submissions — check the relevant practice direction for the court or tribunal in question before filing.
  • Treat AI drafts as a first draft, not a final one. Tone, nuance and strategic judgement — knowing what not to say, or how a particular judge or opposing solicitor is likely to react — remain squarely a human responsibility.

Practical adoption guidance for firms

Firms do not need to choose between banning AI outright and letting it run unsupervised — both extremes carry risk. A workable middle path includes:

AreaWhat good practice looks like
Tool approvalA short, maintained list of approved AI tools with data-processing terms checked, rather than an unofficial free-for-all
Written policyA clear AI use policy covering what can and cannot be entered into AI tools, and when disclosure of AI use is required
TrainingInduction and refresher training for all fee earners and support staff, not just those who volunteer to use AI
SupervisionExplicit sign-off responsibility built into file review, so AI-assisted work is checked the same way delegated work always has been
Client transparencyClarity with clients, where relevant, about how AI tools are used on their matter and what safeguards apply

Getting this right is as much a change-management exercise as a technology one. Firms that treat responsible AI adoption as a firm-wide standard, rather than leaving it to individual discretion, tend to see fewer incidents — our wider guide to responsible generative AI use in the workplace sets out a broader framework that applies well beyond legal practice.

FAQ

Can solicitors use AI tools like ChatGPT for legal drafting at all?

Yes — neither the SRA nor the Law Society prohibits AI use. Both treat it as a legitimate tool provided existing duties of competence, confidentiality and supervision are met, and every output is independently verified before it is relied upon or sent to a client or the court.

Who is responsible if an AI tool fabricates a case citation that ends up in a court filing?

The solicitor with conduct of the matter and their supervisor, not the AI provider. As the Ayinde and Al-Haroun judgments show, both the drafter and the supervising solicitor can be referred to their regulator for failing to verify AI-generated content before it was filed.

Is it safe to paste client information into a free AI chatbot to speed up a summary?

Only if the firm has confirmed the tool's data-processing terms — including whether inputs are used for model training and where data is stored or retained. Absent that check, it risks a confidentiality breach and can undermine legal professional privilege.

Does a firm need a formal AI policy, or is informal good practice enough?

A written policy is strongly advisable. The SRA's warning notice specifically flags inadequate governance and supervision as a recurring problem, and a documented policy gives the firm a clear standard to train to and to point to if a complaint or investigation arises.

AI-assisted drafting and document review is here to stay in legal practice, and used with proper verification it can genuinely improve efficiency. Getting the guardrails right — competence, supervision, confidentiality and human review — is now core professional knowledge for every solicitor. Learnsignal's CPD courses for legal professionals cover AI risk, professional conduct and the practical compliance skills firms need to adopt these tools safely — browse the current programme to keep your practising certificate requirements on track.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Legal CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans