The Solicitors Regulation Authority (SRA) issued a warning on August 17, making it clear: AI governance is no longer optional. Solicitors have reported AI hallucinations in court submissions, and senior judiciary members have noted potential breaches of the Code of Conduct. When confidential client information is entered into public AI tools, it's not just a tech issue, it's a data protection and professional accountability problem.
This checklist translates the SRA's outcomes-based expectations into actionable controls your firm can implement today.
Prerequisites
Before proceeding, ensure these essentials are in place:
Designated accountability. Assign a partner, compliance officer, or risk lead to own AI governance decisions and be ready to answer SRA inquiries.
Inventory visibility. Know which AI tools your solicitors and support staff use, whether they're free public systems or paid enterprise platforms.
Access to contracts. For paid AI services, have vendor agreements that detail data handling, confidentiality protections, and liability terms.
If these elements aren't in place, establish them before moving on with the checklist.
Checklist Items
1. Human Review Gate for Court Submissions
Status: [ ] Done [ ] Not Done
Ensure every citation, case reference, or legal authority generated by AI is verified by a qualified solicitor before submission to any court or tribunal.
What good looks like: Your workflow management system flags AI-assisted documents for mandatory human review. The reviewing solicitor confirms each citation exists, is relevant, and includes a verifiable reference. You can demonstrate this review through audit logs or file notes.
2. Client Data Entry Controls
Status: [ ] Done [ ] Not Done
Prevent confidential client information from being entered into public AI tools like free ChatGPT or similar platforms without enterprise agreements.
What good looks like: You've blocked access to public AI interfaces on firm devices or implemented controls to prevent client data from being pasted into browser-based AI tools. Training records show that staff understand the restriction and know what alternatives to use.
3. Vendor Contractual Safeguards
Status: [ ] Done [ ] Not Done
Ensure contracts for paid AI services include provisions addressing confidentiality, data residency, and usage restrictions.
What good looks like: Vendor agreements state that client data remains confidential, won't be used for model training, stays within defined geographic boundaries, and can be deleted on request. Document which AI tools meet these criteria.
4. Supervision Framework for Junior Staff
Status: [ ] Done [ ] Not Done
Supervisors should review AI-assisted work from junior solicitors or non-authorized colleagues before it leaves the firm.
What good looks like: Your supervision policy covers AI-generated content. Junior staff must disclose AI assistance. Supervisors check legal reasoning and the provenance of citations and claims. You can show the SRA that supervisors were involved in reviewing work that went to court.
5. Risk Assessment Documentation
Status: [ ] Done [ ] Not Done
Conduct a written risk assessment covering AI hallucination risks, data protection obligations, and confidentiality breaches.
What good looks like: Your risk register identifies practice areas with the highest AI-related risks. Document mitigation controls and assign owners. Reference your obligations under the SRA Code of Conduct and relevant data protection regulations.
6. Secure Environment Verification
Status: [ ] Done [ ] Not Done
Ensure client data entered into AI systems stays within a secure environment with appropriate safeguards.
What good looks like: Describe the security architecture: enterprise AI instances with encrypted data transmission, access controls, audit logging, and no data persistence beyond the session unless configured. Your IT team has verified and documented these controls.
7. Breach Response Procedure
Status: [ ] Done [ ] Not Done
Have a documented procedure for responding to AI hallucinations or exposure of confidential information.
What good looks like: The procedure specifies immediate steps, investigation requirements, and reporting obligations. Test this procedure with a tabletop exercise.
8. Training Records
Status: [ ] Done [ ] Not Done
Ensure all solicitors and relevant staff have completed training on AI risks, usage policies, and accountability for AI output.
What good looks like: Training covers real examples of AI hallucinations, explains confidentiality risks, and clarifies personal accountability. Maintain attendance records and refresh training annually.
Common Mistakes
Assuming paid AI tools solve confidentiality problems. Even enterprise AI platforms need proper configuration. Review your vendor's actual implementation, not just their marketing claims.
Treating AI review as a one-time task. Solicitors will adopt new AI tools. Build quarterly reviews into your compliance calendar.
Delegating verification to non-qualified staff. Only a qualified solicitor can verify a case authority. Don't rely on junior staff to "check" AI output without oversight.
Overlooking mobile devices and personal accounts. Address this in your acceptable use policy and consider mobile device management solutions.
Next Steps
If you've checked fewer than six items as "Done," prioritize items 1, 2, and 4. These address the specific concerns the SRA highlighted in its notice and prevent the scenarios that triggered regulatory attention.
If you've completed most items but lack documentation, spend the next two weeks creating written evidence. The SRA's outcomes-based approach means you need to prove you've met standards.
Schedule a review meeting with your managing partner or compliance committee within 30 days. Present this checklist, identify gaps, and assign owners for each incomplete item. The SRA expects "effective governance structures," meaning someone must be accountable for closing these gaps, and you need a timeline.
Your next audit or regulatory inquiry will ask how you're managing AI risks. This checklist gives you a defensible answer.



