UK compliance hub

What the SRA actually says about AI in law firms

Risk Outlook report: the use of artificial intelligence in the legal market

Issued by
Solicitors Regulation Authority
Published
20 November 2023
We reviewed
17 July 2026
In one minute

The SRA’s Risk Outlook report on AI in the legal market (November 2023) is notable for what it does not say: it does not tell firms to avoid AI. It reports that, reportedly, three quarters of the largest solicitors’ firms were already using AI, and frames the risk as failing to adopt safely rather than adopting at all. For smaller firms the message is uncomfortable in the other direction: the technology gap is real, and the safe-adoption expectations (confidentiality, accuracy, accountability) apply at every firm size.

What the guidance says

three quarters of the largest solicitors’ firms were using AI, nearly twice the number from just three years ago
Solicitors Regulation AuthorityAI adoption in the legal market is already mainstream at the top end — the report cites that, reportedly, three quarters of the largest firms were using AI by late 2023.
The risk to firms might not come from adopting AI, but from failing to do so.
Solicitors Regulation AuthorityNot adopting AI is itself framed as a competitive and client-service risk.
We want to help firms and consumers safely gain the benefits that AI can bring.
Solicitors Regulation AuthorityThe regulator’s posture is enablement with conditions: AI must operate within the law, and firms remain accountable.

What this means for your firm

  • The SRA is not a reason to ban AI — it is a reason to be able to show your AI use is controlled.
  • Confidentiality and accountability expectations apply regardless of firm size; "we are too small to need controls" is not a position the report supports.
  • The firms that benefit are the ones that can adopt quickly because their control story is already in place.
  • Separate SRA compliance tips on AI and technology (updated February 2026) reinforce responsible adoption — check the SRA site for the current text.

Guidance → control, line by line

How each expectation maps to a NeutralAI control. The full cross-regulator table lives on the UK guidance map.

Adopt AI safely rather than abstain

Mask before send

Staff keep using AI tools for productivity; the control removes client-identifiable data from prompts automatically, so adoption does not depend on perfect user discipline.

Remain accountable for AI use

Audit trail

Category-level masking logs show what was protected, when, and under which policy — the evidence layer for supervision and file reviews.

Operate within the law across tools

Policy + whitelist

Tenant policies and whitelisted terms apply the same masking rules across every supported AI site, rather than per-tool ad hoc decisions.

Common questions

Does the SRA require law firms to use AI?

No. The Risk Outlook report observes that most large firms already use AI and frames non-adoption as a potential competitive risk — but it requires nothing. Its practical weight is in the safe-adoption expectations it sets for firms that do use AI.

Is the 75% adoption statistic current?

The figure comes from the SRA’s November 2023 report, which itself qualifies it as "reportedly". Treat it as a dated, directional signal about large-firm adoption, not a live market measurement.

What does "safe adoption" look like for a small firm?

A defined policy, an approved-tools list, a technical control that stops client identifiers reaching public AI tools, and evidence that the control ran. That combination is achievable without a security team.

This page summarises third-party guidance for convenience and is not legal advice. Summaries can go stale — always read the original at the source link above before relying on it. Last reviewed: 17 July 2026.

See what this control looks like in practice

The AI Confidentiality Checklist walks through usage discovery, exposure, policy, controls, and evidence in about 20 minutes — or bring one low-risk workflow to a live review.

The control

detect → mask → send → restore → audit

Reversible vault, 15-minute TTL. The model only ever sees placeholders.