This is a five-part implementation kit for the SRA's warning notice on the misuse of AI: the owner, the shadow AI audit, the one-page policy, the verification rule and the insurer questions a managing partner of a small firm works through this month. It has been three weeks since the Solicitors Regulation Authority published its warning notice on the misuse of AI on 17 August 2026. The first wave of commentary told you what the notice says. This post is about the part nobody has packaged: what a managing partner of a small firm actually does about it, in what order, this month.
The short version: the notice turns AI from a technology question into an operations question. Its own words: "AI has no separate legal personality; solicitors and regulated individuals who use AI in the course of delivering legal services remain accountable for their work and outputs, regardless of how that work has been prepared." The firms that will struggle are not the ones that used AI. They are the ones that cannot show how it was used. Here is the five-part kit.
Part 1: Name one owner
Before any policy or tool decision, one named person owns AI use in the firm. In a two-to-twenty fee-earner firm that is usually the managing partner or the COLP, and it cannot be "everyone". The owner keeps the register of approved tools, signs off new ones, and is the person who answers if a client, insurer or the SRA asks how the firm uses AI. If that question currently has no answer in your firm, that is the first gap to close, and it costs nothing.
Part 2: Run a shadow AI audit
The uncomfortable signal in the adoption data is the gap between individual and firmwide use. In the 2026 Legal Industry Report from practice-management vendor 8am, 69% of surveyed solo and small-firm legal professionals reported using AI tools, while firmwide adoption of legal-specific AI sat far lower. That cohort is not specific to England and Wales, so read it as directional rather than local prevalence. What it frames is the risk this audit exists to test in your own firm: whether fee earners are using tools the firm has never approved, on accounts the firm cannot see, with no record kept. Treat those as the questions, not the foregone conclusion.
A shadow AI audit for a small firm takes an afternoon, not a project:
- An anonymous five-question survey: which tools, for which tasks, on which accounts, with what client material, and what would make them stop.
- An expense and subscription scan: AI tool receipts on firm and personal cards claimed back.
- A browser and extension review on firm machines.
- A short conversation with each fee earner, framed as inventory, not discipline.
The output is a one-page list: every tool in real use, what touches it, and whether any client-confidential material has gone into a consumer product with no data agreement. That list drives everything else. (For the next stage, our contract review playbook explains how to turn agreed positions into review instructions.)
Part 3: Write the one-page policy
A small firm does not need a forty-page AI governance framework. It needs one page every fee earner has actually read, covering:
- The approved tool list, and the rule that anything not on it is not used for client work
- What categories of information never go into any AI tool without a data agreement: client identity, matter details, anything privileged
- The verification rule (Part 4 below)
- Who approves exceptions, and how they are recorded
- What happens when someone spots a problem - a named route, no blame
The SRA notice does not prescribe a policy format. What it expects is that the firm can demonstrate control. One page, signed, dated and actually enforced demonstrates more control than a framework nobody opened.
Part 4: Set the verification rule in writing
The notice demands accountability and effective, proportionate supervision; it does not prescribe one exact procedure, and its explicit verification discussion concerns legal submissions built on genuine authorities. This kit's recommended bright line goes further than the letter of the notice, deliberately: nothing AI-assisted leaves the firm - to a court, a client or a counterparty - without a named human checking it against primary sources. The reason is no longer hypothetical. In Ayinde v London Borough of Haringey [2025] EWHC 1383, fictitious AI-generated citations were put before the court, and the lawyers involved were referred to their regulators.
Write the firm's rule as a bright line: any citation, quotation or factual claim in AI-assisted drafting is verified against the primary source before the document goes out, and the checker is named on the file. Not "reviewed". Verified, by a person whose name is recorded.
Part 5: Take three questions to your insurer and your clients
Two conversations follow from the first four parts, and both are easier before an incident than after:
Your insurer or broker. Ask three things in writing: whether your current policy wording treats AI-assisted work any differently; whether unapproved tool use by a fee earner could affect cover; and what evidence of supervision the insurer would expect after a claim. These are questions, not obligations - the answers vary by wording, which is exactly why you want them on file now.
Your clients, where it matters. You do not need to announce your tooling in every engagement letter. But if a client care letter or terms of business is silent on AI while fee earners use it daily on that client's matters, the gap is worth closing at the next natural renewal. What that wording should say is a question for your own legal advice - this kit is operational, not legal advice.
The US parallel, in one paragraph
If you work with US firms or US-qualified colleagues, the shape is the same. The American Bar Association's Formal Opinion 512 (July 2024) reached the same destination through existing duties: competence, confidentiality, candour and reasonable fees all apply to generative AI use unchanged. Different regulator, same operational answer: named ownership, controlled tools, verified output.
What this could look like in a three-fee-earner firm (an illustrative scenario, not a client case study)
Monday: the senior partner names herself owner and sends the anonymous survey. Wednesday: expense scan and a forty-five minute conversation per fee earner produces the tool list - four tools, two unapproved, one with client material in a personal account. The personal-account use is documented and stopped the same day, with evidence retained first - closing things down before preserving what happened is how small incidents become bigger ones. Friday: the one-page policy is signed, the verification rule is on the intranet banner, and the three insurer questions go to the broker. In this illustration the total cost is two afternoons. That is the whole kit, and it is exactly the kind of evidence trail the warning notice is asking firms to be able to show.
Where tooling fits
None of the five parts requires buying anything. Tooling enters later, when the firm has a named workflow, real numbers and a decision to make - which is the shape of our half-day Workshop and the questions we collect in Answers. On the product side: Margo, our contract-review tool, is in controlled development and not generally available; the same evidence-first rules above are what we are building it to satisfy. You can read the approach at /margo/.
Frequently asked questions
Does the SRA warning notice ban AI use in law firms?
No. The 17 August 2026 notice warns about misuse - unverified output, confidentiality failures, lack of supervision. It does not prohibit AI. A firm that uses approved tools with named ownership and verified output is in a far better position than one with a blanket ban nobody follows.
Does the notice apply to sole practitioners?
Yes. The accountability framing in the notice attaches to solicitors and firms regardless of size. For a sole practitioner the five parts collapse into one person's habits: an approved tool list, a verification rule, and a record of both.
Do we have to tell clients we use AI?
The notice does not create a blanket disclosure duty. The practical questions are what your client care letters currently say, what your insurer expects, and whether a specific client has imposed its own conditions. Get wording advice specific to your firm rather than copying a template.
What counts as adequate supervision of AI output?
The notice expects effective, proportionate supervision rather than one fixed procedure. The standard this kit recommends is verifiability: a named person checks AI-assisted work against primary sources before it leaves the firm, and the check is recorded. The Ayinde v Haringey referral shows where unverified filing ends up.
We already use AI daily and have nothing written down. Where do we start?
Start with Part 2, the shadow AI audit. You cannot policy your way out of usage you have not inventoried, and the audit is the piece that turns the notice from a worry into a two-afternoon job.