Safe Generative AI Use for Legal Professionals
Following the SRA's August 2026 warning notice on AI misuse, a practical guide to using generative AI tools safely — confidentiality, verification and supervision.
In August 2026 the SRA issued a formal warning notice on the misuse of AI by legal professionals, flagging accuracy, confidentiality, privilege and supervision as the core risk areas. The message was not that AI has no place in legal practice — it plainly does — but that using it without proper safeguards is now a live regulatory concern, not a hypothetical one.
Why this matters now
Generative AI tools have moved from novelty to normal working practice at extraordinary speed, and legal teams are no exception. That speed is the problem. A tool that drafts fluently and confidently can produce output that is fluent, confident, and wrong — and the more natural the output reads, the easier it is to forget to check it. The SRA's warning notice makes clear that professional obligations around competence, confidentiality and supervision do not pause just because a task was AI-assisted. Firms and individuals remain fully accountable for the accuracy and propriety of any work product, whatever tool helped produce it.
The confidentiality problem
The single most avoidable risk is putting confidential or privileged client information into a public or non-enterprise AI tool. Many consumer-facing AI tools use submitted content to help train future models, or retain it in ways that are not compatible with a solicitor's duty of confidentiality — and once client information has been typed into a tool outside the firm's control, it cannot reliably be un-shared. The safe default is straightforward: nothing confidential or privileged goes into an AI tool unless the firm has specifically approved that tool, understands its data handling terms, and has authorised its use for that category of information. If you are unsure whether a tool qualifies, treat it as though it does not.
The accuracy problem
AI tools, including those built specifically for legal research, can generate plausible-sounding case citations, statutory references or legal propositions that are simply incorrect — sometimes citing cases that do not exist at all. This is not a rare edge case; it is a known and well-documented characteristic of how these tools generate text. The practical rule is unambiguous: every AI-generated citation and legal proposition must be independently verified against a primary source before it appears in any document that leaves your desk, whether that is advice to a client, a submission to a court, or an internal memo relied on by colleagues. Our companion piece on verifying AI-assisted legal research sets out a practical workflow for doing this efficiently rather than treating it as a burdensome extra step.
Supervision and accountability
AI use needs to sit inside, not outside, a firm's normal supervision structure. That means junior staff should be told clearly which tools are approved, for which tasks, and what checking is required before AI-assisted work is relied on — and supervisors need to actually ask, as a matter of routine, whether AI was used and how the output was verified. Silence on the question is itself a risk: if nobody asks, nobody is accountable, and problems surface only when something has already gone wrong.
A practical starting checklist
- Use only AI tools your firm has specifically approved for handling client-related work, and understand what each tool does with the data you input.
- Never input confidential or privileged information into a public or unapproved tool, even for something that feels low-risk.
- Independently verify every citation, quotation and factual claim an AI tool produces before it is relied upon.
- Keep a simple record of where AI assistance was used on a matter, so supervision and quality checks can be targeted appropriately.
- Maintain human judgement and sign-off as the final step on any AI-assisted work product — the tool assists the professional; it does not replace their responsibility.
The bottom line
None of this means avoiding AI. Used well, with the right guardrails, it can genuinely speed up research, drafting and administrative work. The risk sits entirely in unsupervised, unverified use — and that risk is now squarely on the regulator's radar.
Can solicitors use ChatGPT or similar tools for client work at all?
Only within limits set by the firm, and never with confidential or privileged client information unless the specific tool has been approved for that purpose. General research or drafting assistance on non-confidential matters is lower risk, but output still needs independent verification.
Who is responsible if an AI tool produces an inaccurate citation that ends up in a filed document?
The solicitor who relied on it and signed it off, not the AI tool or its provider. Professional responsibility for accuracy and competence rests with the individual and the firm, regardless of what tool was used to help produce the work.
Does firm-wide AI policy need to be in writing?
It should be. A clear, written policy setting out approved tools, permitted uses and verification requirements gives staff a concrete standard to work to and gives supervisors something to check compliance against.
Does this apply equally to trainees and experienced solicitors?
Yes. Experience does not remove the risk of AI-generated inaccuracy — if anything, an experienced solicitor's confidence in their own judgement can make it easier to skip verification on output that reads convincingly.
Used with the right safeguards, generative AI is a genuine productivity gain rather than a liability waiting to surface. Learnsignal's CPD courses cover safe, practical AI use alongside the other skills legal professionals need to stay current.
This page was last updated:
Learnsignal Education Team
Expert Tutor at Learnsignal
Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.
View all posts by Learnsignal Education Team


