Perspectives

Authorised at Entry, Answerable in Use: Governing AI in English Legal Practice

England and Wales has produced, within a single year, both the first regulatory authorisation of an AI-driven law firm and the sharpest judicial warning yet issued about unverified AI output, and the space between those two decisions is where professional AI governance now lives.

Law July 22, 2026
The Brief
Recommendations & Citations

THE BRIEF

In May 2025 the Solicitors Regulation Authority authorised Garfield.Law Ltd, the first purely AI-based firm approved to provide regulated legal services in England and Wales [1]. One month later, the Divisional Court in Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank warned that lawyers who place unverified AI-generated citations before a court face a sanctions ladder that runs from wasted costs through regulatory referral to contempt proceedings and, in the most egregious cases, referral for the offence of perverting the course of justice [2].

The two decisions are consistent rather than contradictory. Entry into the market is governed permissively, through conditions engineered into the authorisation itself; use is governed strictly, through personal professional accountability at the moment output reaches a court.

Adoption has outrun internal governance. In 2025, 26% of legal professionals reported using generative AI, nearly double the 2024 figure, while 48% of surveyed firms lacked formal policies [3].

The court has stated where its next inquiry will land. Heads of chambers and managing partners should expect to be asked whether practical and effective measures were in place [2].

I. ONE REGULATOR, ONE COURT, ONE MONTH

On 6 May 2025 the Solicitors Regulation Authority approved Garfield.Law Ltd as the first purely AI-based firm authorised to provide regulated legal services in England and Wales, offering small and medium-sized businesses an AI-powered litigation assistant that guides them through the small claims court process, up to trial, to recover unpaid debts [1]. The regulator's chief executive framed the decision as an access measure, observing that responsible use of AI by law firms could improve legal services while making them easier to access and more affordable [1]. On 6 June 2025, the President of the King's Bench Division and Mr Justice Johnson handed down judgment in Ayinde v London Borough of Haringey and Al-Haroun v Qatar National Bank [2025] EWHC 1383 (Admin), the most severe judicial statement yet made in the jurisdiction on lawyers who put fabricated, AI-generated authority before a court [2].

A reader encountering the two decisions in isolation could take them for a regulator and a judiciary pulling in opposite directions. They are better read as one settlement with two tracks. The permission to deploy an AI system into regulated legal work is available, and on generous terms; the accountability for what that system produces, once a professional adopts it, is absolute and personal. That allocation relocates the operative risk surface away from the regulator's rulebook and into the organisation's internal verification architecture, which is precisely the layer that current adoption data shows to be thinnest. The pattern is worked through English legal practice here, and the closing sections return to why it will not stay there.

II. WHAT THE COURT HELD, AND HOW FAR THE SANCTIONS LADDER RUNS

The facts before the Divisional Court were unusually clean illustrations of the failure mode. In Ayinde, a barrister settled grounds for judicial review containing five citations to cases that do not exist and materially misrepresented a provision of the Housing Act 1996; challenged on the citations, she characterised the errors as cosmetic [2]. In Al-Haroun, a solicitor relied on research supplied by his client in evidence containing 45 problematic citations, 18 of which referred to cases that do not exist [2]. The court was direct on the second point: a lawyer is not entitled to rely on a lay client for the accuracy of citations of authority put before the court by the lawyer [2].

Exercising the Hamid jurisdiction, the court's inherent power to regulate its own procedures and enforce the duties lawyers owe to it, the judgment set out the full range of available responses: public admonition, which save in exceptional circumstances is unlikely to be a sufficient response to fake material; wasted costs orders; strike-out of proceedings; referral to the regulator; contempt proceedings carrying a maximum of two years' imprisonment; and, in the most egregious cases, referral for the common law offence of perverting the course of justice, which carries a maximum sentence of life imprisonment [2]. On the facts, the court referred the barrister to the Bar Standards Board and referred the solicitors concerned in both matters to the Solicitors Regulation Authority rather than initiating contempt proceedings [2]. Professional press coverage of the underlying first-instance ruling records wasted costs orders of GBP 2,000 [4].

The duty the judgment fixes is unambiguous: those who use artificial intelligence to conduct legal research have a professional duty to check the accuracy of that research against authoritative sources before using it in the course of their professional work [2]. Nothing in that sentence is new law. What is new is the court's stated intention to police it institutionally.

III. WHAT AUTHORISATION ACTUALLY REQUIRED OF THE ALGORITHM

The Garfield.Law authorisation rewards close reading, because the conditions attached to it prohibit, by design, the precise failure mode the Divisional Court was about to punish. As described in the regulator's announcement, the system cannot propose relevant case law, an area the SRA identified as high risk for AI hallucination [1]. Clients must approve any step before the system takes it, quality-check processes apply to work output, confidentiality and conflict-of-interest safeguards are required, oversight is enhanced during the initial launch phase, and professional indemnity insurance is mandatory [1]. Most consequentially, named regulated solicitors remain ultimately accountable and responsible for the system's outputs [1][5].

The structure of the authorisation matters more than its novelty. The SRA did not certify a model as safe; it engineered the unsafe function out of the permission and pinned residual accountability to named professionals. Entry regulation and use regulation therefore converge on a single design principle: the high-risk function is either removed from the system or placed behind a mandatory human checkpoint, and a named person answers for what remains. An organisation seeking to understand what regulators will ask of professional AI deployment over the next several years will learn more from that condition set than from any strategy paper.

IV. THE GUIDANCE LAYER IS THICK, CONSISTENT, AND NON-DELEGATING

The professional guidance surrounding these two decisions is now extensive, and its striking feature is uniformity. The SRA's Risk Outlook report on artificial intelligence, published in November 2023, found that three quarters of the largest solicitors' firms were already using AI, warned that generative language models produce highly plausible but incorrect results, and told firms in terms that they remain responsible and accountable for the outputs of the AI they use and cannot delegate that accountability to an IT team or an external provider [6]. The Law Society's guidance, updated in September 2025, states that deriving output from generative AI tools does not absolve the solicitor of legal responsibility or liability if the results are incorrect [7]. The Bar Council's updated guidance of November 2025, revised in the light of the recent case law, maintains that barristers retain ultimate responsibility for all work produced with AI assistance and that verification of accuracy is mandatory before use [8][9]. The judiciary has bound itself to a parallel discipline: refreshed guidance for judicial office holders, issued in October 2025 over the signatures of the Lady Chief Justice, the Master of the Rolls, the Senior President of Tribunals, and the lead judge for artificial intelligence, expands on hallucination and bias risks and instructs judges not to enter private information into public AI tools [10].

The same allocation holds across jurisdictions. The American Bar Association's Formal Opinion 512, issued in July 2024, requires a reasonable understanding of the capabilities and limitations of any generative tool employed, prohibits uncritical reliance on outputs without independent verification, and directs managerial lawyers to establish clear policies governing the firm's permissible use of generative AI [11]. The Council of Bars and Law Societies of Europe issued guidance in October 2025 requiring lawyers to verify generative output before use and warning that unverified content invites professional misconduct sanctions and malpractice exposure [12]. The judicial line runs back to Mata v Avianca in the Southern District of New York, where the submission of six fabricated decisions produced a USD 5,000 sanction and the court's observation that many harms flow from the submission of fake opinions [13]. Five issuing bodies across three jurisdictions have converged on one rule: verification is a professional function, and it cannot be delegated to the tool, the client, or the vendor. Almost none of this is new obligation. The instruments restate duties that predate the technology; what has changed is the failure rate at which those duties are now tested.

V. ADOPTION IS OUTRUNNING GOVERNANCE, AND THE COURT HAS NAMED WHO OWNS THE GAP

The governance gap is measurable. Thomson Reuters' 2025 survey of nearly 1,800 professionals found that 26% of legal professionals were using generative AI, up from 14% a year earlier, while 48% of respondents' firms still lacked formal generative AI policies [3]. Set against the guidance layer described above, the figures describe a profession in which the tool has arrived roughly twice as fast as the policy meant to govern it.

The Divisional Court's response was to name the owners of that gap. Practical and effective measures, the court held, must now be taken by those within the legal profession with individual leadership responsibilities, such as heads of chambers and managing partners, and by those with responsibility for regulating the provision of legal services; in future Hamid hearings, the profession can expect the court to inquire whether those leadership responsibilities have been fulfilled [2]. Commentary on the judgment has drawn the practical conclusion that circulating guidance is insufficient and that training, supervision structures, and verification protocols are what the inquiry will look for [14]. The American position is structurally identical, since Formal Opinion 512 grounds the same expectations in the supervisory rules governing managerial lawyers [11]. The enforcement point has moved inside the organisation. Professional discipline, wasted costs, and the courts' inherent jurisdiction now function, collectively, as the de facto regulator of AI use in legal practice, and what they examine is the firm's internal architecture: who verified, under what protocol, with what training, and under whose signature.

VI. THE PORTABLE PATTERN, AND WHERE IT GOES NEXT

The two-track settlement visible in English legal practice is the shape regulation tends to take when a technology's benefits are conceded and its failure modes are individually attributable. The state itself is committed to the first track: the Ministry of Justice's AI Action Plan for Justice, published on 31 July 2025, sets a three-year programme to embed AI across the justice system on a scan, pilot, scale approach, with safety and fairness placed first among its principles [15]. The trajectory is not restraint but conditional permission, and the conditions migrate downward into the organisations that deploy.

Three developments follow from the analysis. First, authorisation by condition, meaning the functional prohibition of high-risk outputs, mandatory human checkpoints, and named accountable professionals, will become the template for professional-services AI approvals well beyond England and Wales, because it lets regulators permit deployment without certifying models. Second, the disciplinary outcomes of the Ayinde referrals will set the sanction benchmark for the profession, and a suspension or strike-off traceable to unverified AI output should be expected in the jurisdiction within the next two years. Third, at the point of failure, organisations able to evidence a working verification architecture, with named owners and audit trails, will be treated materially differently from organisations able to produce only a circulated policy. For any regulated organisation deploying generative systems, legal or otherwise, the tribunal's question will be not whether the tool erred but whether the institution had built the checking function that the permission to deploy always assumed.

VII. CONCLUSION

England and Wales has not chosen between enabling professional AI and punishing its misuse. It has assigned enabling to the regulator, punishment to the court, and left the middle layer, where errors are actually caught, to the governance of firms. The Divisional Court stated the underlying principle in terms that generalise well past the legal profession: the administration of justice depends upon the court being able to rely without question on the integrity of those who appear before it [2]. Read together, the Garfield.Law authorisation and the Ayinde judgment define the current obligation with unusual precision. Permission to deploy is available, and accountability for use is absolute; the distance between the two is the exact size of the governance an institution must build for itself.

RECOMMENDATIONS

Within 30 days:

Inventory generative AI use across the organisation, including unsanctioned use of personal accounts on client work, and adopt or update a written AI policy that names the prohibited functions and the mandatory human checkpoints. Unverified citation and authority generation belongs at the top of the prohibited list; the SRA's condition set for Garfield.Law is a usable template for identifying which functions to remove or gate [1][11].

Within 90 days:

Stand up tool-specific verification protocols that state, for each approved system, what must be checked, against which authoritative sources, and by whom. Assign named individual accountability for AI-assisted output, mirroring the named-solicitor accountability the SRA required at authorisation [1]. Train supervisors on the capabilities and limitations of each approved tool, since supervisory rules are where both the English court and the American opinion place the obligation [2][11].

Within 6 months:

Test the verification architecture against a live failure scenario and audit actual compliance rather than policy existence. Report the results at board or management-committee level. The design questions involved belong to the same discipline that governs any organisation's AI governance programme.

Benchmarks that should change the recommendation:

The disciplinary outcomes of the Ayinde referrals to the Bar Standards Board and the Solicitors Regulation Authority; any further Divisional Court Hamid rulings on AI-generated material; new SRA guidance following the judgment; and the implementation pace of the Ministry of Justice action plan. A first suspension or strike-off for unverified AI output would convert the recommendations above from prudent to urgent.

CAVEATS

Jurisdictional scope: The analysis centres on England and Wales. The ABA and CCBE instruments cited are comparators demonstrating convergence; they are not binding in that jurisdiction.

Survey basis: The Thomson Reuters figures derive from a global survey of nearly 1,800 professionals across legal, tax, accounting, risk, and government sectors; they are not specific to England and Wales, and adoption rates vary materially by firm size [3].

Authorisation detail: The Garfield.Law conditions are drawn from the SRA's public announcement and professional analyses of it; the full authorisation instrument has not been reviewed for this analysis [1][5].

Pending outcomes: The regulatory referrals arising from the Ayinde judgment were undetermined at the time of writing. Their outcomes may reset the sanction benchmark in either direction.

Currency of guidance: The judicial guidance and Bar Council guidance cited are the versions current as of October and November 2025 respectively; both bodies have refreshed their guidance repeatedly and should be checked before reliance.

Costs figure: The GBP 2,000 wasted costs figure derives from International Bar Association coverage of the first-instance ruling rather than from the Divisional Court judgment itself [4].

REFERENCES

[1] Solicitors Regulation Authority. "SRA approves first AI-driven law firm." 6 May 2025. https://news.sra.org.uk/news/news/press/2025-press-releases/garfield-ai-authorised/

[2] High Court of Justice, King's Bench Division (Divisional Court). "Ayinde v London Borough of Haringey; Al-Haroun v Qatar National Bank [2025] EWHC 1383 (Admin)." 6 June 2025. https://www.judiciary.uk/wp-content/uploads/2025/06/Ayinde-v-London-Borough-of-Haringey-and-Al-Haroun-v-Qatar-National-Bank.pdf

[3] Thomson Reuters. "Generative AI Adoption Nearly Doubles as Professional Services Reach Crossroads (2025 Generative AI in Professional Services Report)." 15 April 2025. https://www.thomsonreuters.com/en/press-releases/2025/april/from-incubation-to-integration-generative-ai-adoption-nearly-doubles-as-professional-services-reach-crossroads

[4] International Bar Association. "Technology: UK judge warns lawyers about risks of AI use in court." 28 July 2025. https://www.ibanet.org/Technology-UK-judge-warns-lawyers-about-risks-of-AI-use-in-court

[5] Dechert LLP. "Solicitors Regulation Authority Authorizes UK's First AI-Based Law Firm." 30 June 2025. https://www.dechert.com/content/dechert/en/knowledge/re-torts/2025/6/solicitors-regulation-authority-authorizes-uk-s-first-ai-based-l.html

[6] Solicitors Regulation Authority. "Risk Outlook report: The use of artificial intelligence in the legal market." 20 November 2023. https://www.sra.org.uk/sra/research-publications/artificial-intelligence-legal-market/

[7] The Law Society. "Generative AI – the essentials." Updated September 2025. https://www.lawsociety.org.uk/topics/ai-and-lawtech/generative-ai-the-essentials

[8] Bar Council. "Updated guidance on generative AI for the Bar." 26 November 2025. https://www.barcouncil.org.uk/resource/updated-guidance-on-generative-ai-for-the-bar.html

[9] Hogan Lovells. "Bar Council's updated AI guidance – clearer expectations, limited change in practice." 2 December 2025. https://www.hoganlovells.com/en/publications/bar-councils-updated-ai-guidance-clearer-expectations-limited-change-in-practice

[10] Courts and Tribunals Judiciary. "Artificial Intelligence (AI): Guidance for Judicial Office Holders." 31 October 2025. https://www.judiciary.uk/guidance-and-resources/artificial-intelligence-ai-judicial-guidance-october-2025/

[11] American Bar Association, Standing Committee on Ethics and Professional Responsibility. "Formal Opinion 512: Generative Artificial Intelligence Tools." 29 July 2024. https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-opinion-512.pdf

[12] Council of Bars and Law Societies of Europe (CCBE). "Guide on the use of generative AI by lawyers." 2 October 2025. https://www.ccbe.eu/fileadmin/speciality_distribution/public/documents/IT_LAW/ITL_Guides_recommendations/EN_ITL_20251002_CCBE-guide-on-the-use-of-the-use-of-generative-AI-for-lawyers.pdf

[13] United States District Court, Southern District of New York. "Mata v Avianca, Inc., Opinion and Order on Sanctions (No. 1:22-cv-01461)." 22 June 2023. https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2022cv01461/575368/54/

[14] Burges Salmon. "Professional conduct and AI - Ayinde v Haringey." 8 July 2025. https://www.burges-salmon.com/articles/102krxw/professional-conduct-and-ai-ayinde-v-haringey/

[15] Ministry of Justice. "AI Action Plan for Justice." 31 July 2025 (official announcement as published by techUK). https://www.techuk.org/resource/ai-action-plan-for-justice.html