The UK Solicitors Regulation Authority (SRA) has published a stark warning to the legal profession about the risks of AI, citing real-world cases of AI "hallucinations" in court submissions and breaches of client confidentiality. The regulator says it has already received reports from senior members of the judiciary about potential violations of its Code of Conduct stemming from AI misuse.
What is the SRA concerned about?
The SRA identifies two primary areas of concern. The first is court and legal documents containing false or incorrect information — including fabricated case citations — generated by AI tools. The second is the use of AI systems that put client confidentiality at risk, particularly when solicitors input sensitive personal data into public-facing AI platforms without adequate safeguards.
"AI tools can produce 'hallucinations', generating fictitious cases, references or seemingly factual assertions that may appear convincing despite having no basis in fact," the SRA warned. "We are also concerned that those we regulate are not fully considering and appropriately mitigating risks to client confidentiality when using AI systems, particularly in relation to clients' personal data or other confidential information."
Real cases of AI hallucinations in legal proceedings
The SRA reports that evidence of AI hallucinations has already appeared in submissions to court. This has prompted reports of potential Code of Conduct breaches from senior judiciary members. There have also been multiple instances of solicitors self-reporting after discovering they had relied on AI-generated content that turned out to be inaccurate or misleading.
One high-profile example cited by the SRA is the R v Haringey LBC case of 2025, in which AI-generated case citations that did not exist were submitted to the court. The incident drew significant public attention to the dangers of relying on unverified AI outputs in legal submissions.
Separate instances of confidential client information being entered into public AI tools have also come to light, raising concerns about both professional obligations and wider data protection requirements under UK law.
How the SRA regulates AI use in law firms
The SRA takes what it describes as an outcomes-focused approach to regulation. Rather than prescribing exactly how solicitors and firms must work, it sets the standards they are expected to meet and leaves it to individual firms to determine how those standards are achieved in practice. This means firms are free to adopt AI tools and new working methods — but they remain fully responsible for ensuring compliance with the SRA's standards.
That flexibility, the SRA implies, comes with a clear obligation: firms cannot outsource accountability to an AI system. If an AI tool generates a false citation or leaks client data, the responsibility lies with the solicitor or firm that deployed it without adequate verification and oversight.
What should law firms do?
The SRA's warning signals that AI governance is no longer optional for law firms operating in the UK. Firms using AI tools for drafting documents, researching case law, or communicating with clients should ensure that:
- All AI-generated content — particularly case citations and legal references — is independently verified before submission to any court or tribunal.
- Client data and confidential information are never entered into publicly accessible AI tools without explicit assessment of data protection and confidentiality risks.
- Internal policies on AI use are documented and reviewed regularly, with staff trained to understand the limitations of the technology.
The legal sector's rapid adoption of AI reflects a broader trend across professional services, but the consequences of AI errors in legal proceedings can be severe — for clients, for firms, and for the integrity of the justice system. The SRA's intervention makes clear that regulators are watching closely.
