SRA Compliance

SRA Shadow AI Warning Notice: what it means for your firm in 2026

โฑ 7 min readUpdated: August 2026By the LegisBox team

The Solicitors Regulation Authority has issued formal Warning Notices on the use of AI tools in legal practice โ€” specifically on what the SRA calls "Shadow AI": the use of unapproved, personal or consumer-grade AI tools in professional contexts. This guide explains what the notices say, which Code of Conduct obligations are engaged, and what your firm needs to do.

1. What is Shadow AI?

Shadow AI refers to the use of AI tools that have not been formally approved or procured by the firm โ€” typically consumer-grade tools like ChatGPT, Claude, Gemini or Copilot used through personal accounts, or business accounts that have not been vetted for data protection compliance in a legal context.

It is called "shadow" because it often happens without the firm's management or compliance officers knowing โ€” individual fee earners using tools they find helpful without realising the professional and regulatory implications.

SRA position: Shadow AI is not a minor technical issue. The SRA treats it as a potential breach of core Code obligations on confidentiality and competence, and has indicated it will investigate and, where appropriate, bring disciplinary proceedings against firms and individuals who expose client data through unapproved AI tools.

2. The SRA Code of Conduct obligations engaged

The SRA Warning Notices identify several specific obligations in the SRA Code of Conduct 2019 that Shadow AI puts at risk:

Paragraph 6.3 โ€” Confidentiality

You must keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. Uploading client files to a cloud AI constitutes disclosure to a third party โ€” the AI provider โ€” without client consent. This is a direct breach of 6.3.

Paragraph 6.4 โ€” Use of confidential information

You must not use confidential information for the benefit of anyone other than the client. If a cloud AI provider uses client data to improve its models, that is precisely what happens โ€” the client's confidential information benefits the AI provider's product development.

Paragraph 3.2 โ€” Competence

You must ensure that the work you and your firm carry out is competent and delivered in a timely manner. The SRA has indicated that using AI tools without understanding their limitations, verifying their outputs, or ensuring they are appropriate for the task may itself be a competence issue.

Paragraph 7.1 โ€” Firm management

Managers of firms must have effective governance arrangements and clear accountability. Failing to have an AI policy that addresses Shadow AI risks โ€” or having a policy but failing to enforce it โ€” can engage the firm-level obligations under Paragraph 7.

3. "Hosted in the UK" is not sufficient

One of the most important points in the SRA's guidance is that a cloud provider claiming to host data in the UK does not eliminate the risks. The SRA specifically notes that:

4. What the SRA expects firms to do

The SRA's guidance sets out clear expectations for compliant AI use:

The practical challenge: most firms cannot meet these requirements with consumer-grade cloud AI tools. A proper DPIA for ChatGPT or Claude used with client data will typically conclude that the risks cannot be adequately mitigated without removing client data from the processing โ€” which is precisely what self-hosted AI does by design.

5. A practical compliance checklist

Shadow AI compliance checklist for law firms

6. How self-hosted AI simplifies SRA compliance

With a cloud AI tool, achieving SRA compliance requires managing a complex web of DPAs, DPIAs, sub-processor agreements and ongoing monitoring. Each new tool version or sub-processor change may require a new assessment.

With a self-hosted solution like LegisBox, the compliance picture is fundamentally simpler. Because client data never leaves the firm's network, the DPIA for client matter processing concludes with a straightforward finding: no third-party processing, no transfer risks, no sub-processor concerns. The SRA's requirements on confidentiality and data security are met by the architecture itself.

LegisBox โ€” SRA compliant by design

No Shadow AI risk. No DPA required for client data. Legal Professional Privilege and UK GDPR protected by architecture.

Book a demo โ†’