Sooner or later, every firm of 2-20 fee earners will get this question from a client: did a person write this, or did a machine? The honest answer in most firms is "both". The harder question is whether the firm's client-care documents say so.
There is no single SRA rule that says "tell clients when you use AI". Nobody should pretend there is - and nobody should pretend that ends the matter. The existing duties can require information, and in some situations consent, on specific matters, and the SRA's own AI Risk Outlook advises firms to be ready to explain how AI is used on a client's case and how it works. This guide is about handling that qualified position properly, not with a blanket answer in either direction.
Direct answer
Does a law firm have to tell clients it uses AI?
No blanket, AI-specific rule currently forces a law firm in England and Wales to disclose AI use to clients. But existing obligations can require information - and in some situations consent - matter by matter: the duty to give clients the information they need to make informed decisions, the duty of confidentiality over client information fed into third-party tools, and the duty to supervise everything the firm produces however it was drafted. The SRA's AI Risk Outlook adds guidance that firms should be able to explain when and how AI is used on a client's case. So the practical answer is not "no disclosure needed"; it is "no generic rule - decide it per matter, and be able to explain your answer in writing".
What the rules actually say
The SRA's framework was written before generative AI and it shows. Nothing in the Principles or the Codes names AI. What they do require is familiar: act in a way that upholds public trust, give clients information in a way they can understand, keep client affairs confidential, and make sure the work the firm puts its name to is competent and supervised. The regulator's AI Risk Outlook reads those duties onto AI use directly, and advises firms to explain to clients when AI is used on their case and how it works - guidance, not a new rule, but a clear sign of where supervision questions will land.
AI does not create new duties. It creates new ways to breach old ones. A fee earner who pastes a client's settlement position into a consumer chatbot has a confidentiality problem. A firm whose "supervision" of AI-drafted advice is a skim-read has a supervision problem. A client who asked a straight question and got a waffle answer has a complaint route. None of that needs a new rule.
The three places disclosure already lives
The client-care letter. This is where the decision belongs. Firms do not need to disclose every tool in the stack; they need to say the true thing: that the firm uses technology, including AI, inside supervised professional workflows, that no client document leaves the firm's control without safeguards, and that a named fee earner stands behind everything the client receives. One paragraph. Clients who care will ask follow-up questions; clients who do not have been told the truth.
The retainer conversation on fees. If AI meaningfully changes how the firm delivers the work - faster document review, for instance - that is information a client needs when weighing the fee. A firm charging the same hours for work a machine accelerated is making a disclosure decision whether it says so or not.
The client's own terms. Commercial clients increasingly put AI clauses in their outside counsel guidelines and supply terms: what may be used, on what data, with what human review. If a client's terms restrict AI use, the duty to disclose is no longer a judgement call - it is a contract. Someone in the firm has to read those terms before the work starts, not after the question arrives.
What not to do
Do not bury a generic "we may use technology" clause copied from a template site and treat it as disclosure. It answers nothing and reads like hiding. Do not promise "no AI is ever used" unless that is literally true and will stay true; in 2026 that claim covers spell-checkers and search ranking as much as drafting tools, and it will age badly. And do not wait for clients to ask: the firm that raises this first reads as confident, the firm that answers it second reads as caught.
The one-paragraph test
A workable disclosure paragraph passes three tests. It is true (it matches what the firm actually does, tool by tool). It is specific about the safeguard that matters (a named human reviews what leaves the building). And it is answerable (the client knows who to ask). One qualification matters: no generic paragraph is sufficient for every matter. A clause that fits routine work will not carry a complex, high-stakes instruction, which deserves the actual conversation, not just the letter. And if your current client-care letter cannot produce that paragraph at all, the gap is not a marketing task - it is usually that the underlying decisions have not been made. Which tools, whose authority, what review, where the data goes: those are the same questions your insurer will ask at renewal, and the same written answers serve both.
We run a half-day workshop that exists for exactly this: map the workflows, make the decisions, leave with the documents - the inventory, the data map, the review rules, the policy, the incident route - that sit behind the paragraph. Margo, our AI assistant for legal teams, is in controlled development rather than general availability, and is being built around the same answers. If you want to test the water alone first, our free readiness score runs one workflow through the checks in ten minutes.
Frequently asked questions
Does the SRA require us to disclose AI use to clients?
Not by name: there is no blanket AI-specific disclosure rule today. The obligations that bite are the existing ones - informed decisions, confidentiality, supervision - and they can require disclosure or consent on particular matters even without an AI-named rule. The SRA's AI Risk Outlook advises firms to be ready to explain their AI use on a client's case and how it works, and its recent public warnings make clear it expects firms to manage the risks under the current framework, not wait for new rules.
What if a client's terms ban AI use entirely?
Then the terms govern, and the firm needs to know they exist before work starts. Build a check for AI clauses into client onboarding for commercial clients. If the firm's whole process depends on a tool a client has banned, that is a conversation to have at instruction, not at invoice.
Do we have to disclose which specific tools we use?
Not as a rule. Name the safeguard, not the stack: the firm uses AI tools within supervised workflows, client data is handled under written rules, a fee earner reviews output before it is relied on. Keep the tool inventory as an internal document - but be ready to show it if a client, an insurer or the regulator asks.
Will telling clients put them off?
No published evidence settles this either way, so treat confident claims with suspicion. The position that does not depend on surveys: a client told up front about supervised use has nothing to complain about, while a client who discovers undisclosed use after the fact does. The firms that look weakest here are the ones whose answer changes depending on who is asked.
Is this different for sole practitioners?
The duties are the same but the answer is simpler: one person, one tool inventory, one paragraph. A sole practitioner can do the whole exercise in an afternoon; the workshop is built for firms where the answers live in five heads at once.
Related: direct answers to the questions small firms ask about legal AI.