What the SRA actually says about AI in law firms
Risk Outlook report: the use of artificial intelligence in the legal market
- Issued by
- Solicitors Regulation Authority
- Published
- 20 November 2023
- We reviewed
- 17 July 2026
The SRA’s Risk Outlook report on AI in the legal market (November 2023) is notable for what it does not say: it does not tell firms to avoid AI. It reports that, reportedly, three quarters of the largest solicitors’ firms were already using AI, and frames the risk as failing to adopt safely rather than adopting at all. For smaller firms the message is uncomfortable in the other direction: the technology gap is real, and the safe-adoption expectations (confidentiality, accuracy, accountability) apply at every firm size.
What the guidance says
“three quarters of the largest solicitors’ firms were using AI, nearly twice the number from just three years ago”
“The risk to firms might not come from adopting AI, but from failing to do so.”
“We want to help firms and consumers safely gain the benefits that AI can bring.”
What this means for your firm
- The SRA is not a reason to ban AI — it is a reason to be able to show your AI use is controlled.
- Confidentiality and accountability expectations apply regardless of firm size; "we are too small to need controls" is not a position the report supports.
- The firms that benefit are the ones that can adopt quickly because their control story is already in place.
- Separate SRA compliance tips on AI and technology (updated February 2026) reinforce responsible adoption — check the SRA site for the current text.
Guidance → control, line by line
How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.
Adopt AI safely rather than abstain
Staff keep using AI tools for productivity; the control removes client-identifiable data from prompts automatically, so adoption does not depend on perfect user discipline.
Remain accountable for AI use
Category-level masking logs show what was protected, when, and under which policy — the evidence layer for supervision and file reviews.
Operate within the law across tools
Tenant policies and whitelisted terms apply the same masking rules across every supported AI site, rather than per-tool ad hoc decisions.
Common questions
Does the SRA require law firms to use AI?
No. The Risk Outlook report observes that most large firms already use AI and frames non-adoption as a potential competitive risk — but it requires nothing. Its practical weight is in the safe-adoption expectations it sets for firms that do use AI.
Is the 75% adoption statistic current?
The figure comes from the SRA’s November 2023 report, which itself qualifies it as "reportedly". Treat it as a dated, directional signal about large-firm adoption, not a live market measurement.
What does "safe adoption" look like for a small firm?
A defined policy, an approved-tools list, a technical control that stops client identifiers reaching public AI tools, and evidence that the control ran. That combination is achievable without a security team.
This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.
See what this control looks like in practice
The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.
The control
detect → mask → send → restore → audit
Reversible vault, 15-minute TTL. The model only ever sees placeholders.