Blog

Your AI Vendor Made the Mistake. The SRA Says You May Still Be Responsible.

18 Aug 2026
Your AI Vendor Made the Mistake. The SRA Says You May Still Be Responsible.

Law firms are rapidly adopting AI.

From legal research and document review to drafting, case management and client-facing assistants, AI is moving from experimentation into everyday legal workflows.

But there is a question every law firm using AI should be asking:

If the AI gets something wrong, who is responsible?

The position of the Solicitors Regulation Authority (SRA) in England and Wales is particularly important.

And the answer should get the attention of every managing partner, General Counsel, CIO, risk officer and compliance professional using AI.

You can’t outsource the responsibility

The SRA has previously made a remarkably clear statement about technology used to deliver legal services:

Law firms remain responsible for the services they provide not the AI vendor

Think about the implications.

Your firm may not have developed the AI.

You may be using technology supplied by one of the world’s largest software companies.

The model itself may come from another provider.

But if your firm uses that technology to deliver regulated legal services, responsibility doesn’t simply transfer to the vendor.

The SRA’s position is outcomes-based. Its Principles and Codes of Conduct continue to apply regardless of the technology a firm chooses to use.

But there is another part of the SRA’s position that is arguably even more important

The SRA has also indicated that where an AI system supplied by a separate technology company contains an error or flaw, regulatory action is unlikely where the firm has done everything it reasonably could to assure itself that the system was appropriate and to prevent issues arising.

That creates a very important question:

How do you prove that you did?

It’s one thing to say:

We tested the system.

It’s another to demonstrate it.

Can you show what was tested?

When it was tested?

Which AI model and version were involved?

What standards or policies it was tested against?

What the results were?

Whether performance changed after deployment?

Whether previously identified problems reappeared?

Whether different models performed differently?

Whether the system continued to meet the firm’s risk and compliance requirements months after implementation?

And, perhaps most importantly, can you produce that evidence if challenged by a regulator, client, insurer or court?

That is where AI governance starts becoming AI assurance.

Testing at implementation isn’t enough

The SRA identified this issue years before generative AI became mainstream.

In its work on technology and legal services, it specifically stated that testing and assurance should be an ongoing process, drawing an analogy with the way firms supervise and periodically assess trainees.

That principle has become considerably more important with modern generative AI.

AI isn’t conventional software.

Models change. Prompts change. Knowledge sources change. Integrations change. Policies change. And the same question can sometimes produce different answers.

A system that performed acceptably when it was approved for production six months ago isn’t necessarily performing the same way today.

Governance therefore cannot simply be a policy document or an approval process completed before deployment.

Effective AI assurance needs to continue throughout the operational life of the system.

This is why we built Hoot

At Hoot, we believe AI governance needs to extend beyond frameworks and policies.

Organisations need measurable, repeatable and auditable evidence showing how their AI systems actually perform.

Hoot provides an independent AI assurance layer that enables organisations to continuously test and measure AI performance, compare models and systems, identify changes in behaviour and maintain historical evidence of those results.

For law firms, that creates something increasingly valuable:

The ability not merely to say that appropriate AI governance existed, but to demonstrate what was actually tested, what happened and what actions were taken.

Some law firms recognised this challenge early and chose Hoot for exactly this reason.

The question may eventually become very simple

When an AI-related incident occurs, the first question might be:

“What went wrong?”

But the more important regulatory question could become:

“What did you do to assure yourself that this wouldn’t happen?”

And the question after that:

“Can you prove it?”

Strong governance and defensible, evidence-based AI assurance are rapidly becoming business imperatives.

For law firms adopting AI, the evidence behind the answer may ultimately be just as important as the answer itself.


SRA sources:
SRA – Technology and legal services
SRA – First AI-driven law firm authorised

#ArtificialIntelligence #LegalAI #AIGovernance #AIAssurance #LegalTechnology #RiskManagement #Hoot


Leave a Reply

Your email address will not be published. Required fields are marked *