AI Governance and Technology Procurement for Law Firms

The SRA's warning notice puts AI governance at firm level, not just individual use - what the notice actually requires, how to build a real governance framework, and a practical vendor due diligence checklist.

Learnsignal Education Team
Updated

Most of the AI conversation in law firms has focused on the individual practitioner - what a solicitor should and shouldn't paste into ChatGPT, how to verify an AI-drafted citation before it reaches a bundle. Our guide to safe generative AI use for legal professionals covers that ground. This piece is aimed one level up: at partners, risk and compliance leads, and whoever signs off on new software, because the SRA's own warning notice makes clear that responsibility for AI use sits with the firm, not just the fee earner typing the prompt.

What the SRA's warning notice actually asks of firms

The SRA published its warning notice on the misuse of AI on 17 August 2026, and its firm-level requirements go well beyond "train your staff." It expects effective governance structures, systems and controls around how AI is adopted and used - not an informal "people are using Copilot, that's fine" position, but an actual framework a firm can point to. It expects supervision arrangements specifically for AI-assisted work, with at least one supervisor holding three or more years' relevant legal experience overseeing regulated work that touches AI output, and it makes clear that managers remain accountable for compliance even where the underlying work has been delegated to a tool or a more junior colleague using one.

Two further requirements matter for anyone involved in buying AI tools rather than just using them. Client confidentiality obligations extend to the AI systems themselves: firms need appropriate contractual, technical and organisational safeguards protecting client data handled by third-party AI products, including making sure a vendor isn't retaining firm or client data to train its own models without explicit authorisation. And there's an implicit but real vendor due diligence expectation - a firm needs to actually understand what a provider's terms say about data retention and technical architecture before rolling a tool out, not just take a sales deck's word for it. Underpinning all of it: the notice is explicit that human oversight and professional judgement are non-delegable, whatever tool sits in the workflow.

Building a governance framework that isn't just a policy document

A one-page "acceptable AI use" policy satisfies almost none of this on its own. A governance framework that would actually hold up needs an approved-tools list (so staff aren't independently deciding to try a new AI product on client matters), a named owner for AI governance who isn't purely IT, a supervision structure that specifies who reviews AI-assisted output and at what stage, and a record of what due diligence was done on each tool before it was approved. For workflow-specific detail on where supervision actually needs to bite - drafting and document review versus legal research - our guides to AI-assisted drafting and document review and AI-assisted legal research and hallucination risk set out the practical checkpoints for each.

Governance also has to cover what happens when something goes wrong - a hallucinated citation reaches a filed document, a tool is found to be retaining data it shouldn't, an AI-generated draft contains a material error a reviewer missed. Firms that can show they had a functioning framework in place, with defined ownership and a paper trail, are in a materially different position with the SRA than firms that adopted tools ad hoc and are reconstructing a policy after the fact.

Vendor due diligence and procurement: what to actually check

Procurement for an AI tool needs a different checklist to a standard SaaS purchase, because the data-handling and liability questions are sharper. Before signing, a firm should be satisfied on: where client data is processed and stored, and whether it ever leaves an approved jurisdiction; whether the vendor uses firm or client inputs to train or fine-tune its models, and whether that can be contractually excluded; what the vendor's data retention and deletion terms actually say, not just what the sales team says; who owns the output the tool generates; what audit or logging capability exists, so a firm can reconstruct what happened if a matter is later queried; and what the vendor's own security certifications and sub-processor arrangements look like.

Liability and insurance deserve particular attention. Many AI vendor contracts push liability heavily toward the customer, and professional indemnity cover that was written before generative AI tools were in routine use doesn't always contemplate this class of risk clearly - a gap worth raising with the firm's insurance broker directly rather than assuming existing cover extends automatically to AI-related errors. A short, standing procurement checklist - confidentiality and data-use terms, retention and deletion, output ownership, audit capability, liability allocation, and an insurance sense-check - turns this from a one-off negotiation into something repeatable across every new tool a firm considers.

FAQ

Does the SRA's warning notice apply even to firms that have only informally adopted AI tools, like staff using ChatGPT on their own initiative?
Yes. The notice's governance and supervision expectations apply to how AI is actually being used in the firm, regardless of whether adoption was a formal IT-led rollout or something that grew informally. An absence of a written policy doesn't put a firm outside scope - it more likely means the firm can't yet demonstrate compliance.

Who should own AI governance within a firm - IT, risk and compliance, or a managing partner?
The SRA notice doesn't mandate a specific role, but it does require a supervisor with at least three years' relevant legal experience involved in overseeing AI-assisted regulated work. In practice, effective frameworks combine that legal supervision with risk/compliance ownership of the vendor due diligence and policy side, rather than leaving procurement decisions purely to IT.

Can a firm rely on a vendor's own security certifications instead of doing its own due diligence?
Certifications are useful evidence but don't substitute for a firm actually reading the data retention, training-use and sub-processor terms in the contract itself. The due diligence expectation in the warning notice is about the firm's own understanding, not just the vendor's paperwork.

Does professional indemnity insurance automatically cover AI-related errors?
Not necessarily, and firms shouldn't assume it does. Policies written before generative AI was in routine use may not clearly contemplate this risk category, which is why a direct conversation with the firm's insurance broker is worth having as part of AI governance planning, not left until after an incident.

Getting AI governance right is now a firm-level compliance obligation, not a matter of individual good judgement - and it sits alongside the practitioner-level skills covered elsewhere in this series. Learnsignal's Legal CPD training covers both the governance and practical-use sides, mapped to the SRA's current expectations.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience helping students advance their professional careers.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Legal CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans