Who's liable when
AI gets it wrong.
The question the profession assumed would take years to answer is already being tested in open court, and the early answers are more uncomfortable than either the AI-sceptics or the AI-evangelists expected.
Start with the version of this question most lawyers expect to be asked: what happens when a solicitor relies on an AI tool that gets something wrong? The answer, it turns out, is the less interesting half of the story. The UK Jurisdiction Taskforce, the body responsible for confirming how English private law applies to new technology, published its final legal statement on liability for AI harms this year, and its central finding is closer to a warning than a clarification. Existing negligence law, it concludes, already covers AI-related harm without needing new legislation. The profession does not get to wait for bespoke AI regulation to tell it what the rules are. The rules already apply, and they apply now.
The starting position hasn't moved
The Solicitors Regulation Authority has been clear that it is not banning AI tools, and has no plans to. Its compliance guidance, updated earlier this year, restates rather than rewrites the existing Standards and Regulations: a solicitor remains personally responsible for every piece of work leaving the firm, regardless of what produced the first draft. That means verifying AI-generated content before it is relied upon, protecting client confidentiality when data is put into a tool, and being transparent with clients about where AI has been used in their matter. None of this is new law. What has changed is that "I didn't know the AI was wrong" is no longer treated by courts or regulators as a mitigating factor. It's evidence the check didn't happen.
The UKJT statement: no new law, but a sharper duty of care
The UKJT's statement does most of its work by confirming what was already assumed and closing the gaps that weren't. AI systems have no legal personality, so nobody can be vicariously liable for the actions of the AI itself, there is no "suing the algorithm." But an employer can be vicariously liable where harm results from an employee using AI wrongfully in the course of their work, and a professional's existing duty to exercise reasonable skill and care extends fully to how they use AI tools. Negligence can now arise from using AI inappropriately, choosing an unsuitable model for the task, failing to carry out due diligence before adopting a tool, or failing to test and validate its outputs. In the absence of a specific contract governing the point, ordinary negligence principles apply, adapted where necessary to the facts. In short: the standard of care hasn't been lowered for AI-assisted work, it has been made explicit.
The genuinely counterintuitive part of the statement, and the one doing the most to change how firms think about adoption, is the implication running the other way. Legal commentary following the statement has been direct about this: a professional could be found negligent not only for misusing AI, but for failing to use it at all, where a reasonably competent practitioner in the same position would have. That reframes the entire conversation. AI is moving from "optional efficiency tool" to a component of the standard of care itself, in the same category as using precedent databases or case-law research tools rather than working from memory. Firms that have been treating AI adoption as a discretionary, wait-and-see decision are increasingly the ones exposed on both ends: liable for errors if they use it carelessly, and now potentially liable for negligence if they don't use it at all.
This isn't theoretical anymore
The clearest signal that this has moved from academic debate to operational reality is how many UK court decisions already involve it. Independent tracking of UK cases now puts the number of court proceedings involving AI hallucinations or fabricated citations in the dozens and rising through 2026, not the handful most lawyers assume.
Two rulings illustrate exactly where the line is being drawn. In the Divisional Court decision in Ayinde v Haringey LBC and Al-Haroun v Qatar National Bank, Dame Victoria Sharp P found that "a language model such as ChatGPT is not capable of conducting reliable legal research" and put the profession on notice that lawyers relying on such tools without independent verification face penalties up to and including contempt of court. That is about as unambiguous as judicial language gets.
More recently, in Rodney v Gee'z Micro Bar and Pitstop, Judge Grimshaw referred two solicitors to the SRA after AI-assisted drafting produced court documents containing fabricated case citations and case law cited in support of arguments it did not actually support. One of the solicitors told the court the drafting had been prepared with a paralegal's help and accepted he should have checked the research himself. The judge's response was pointed: "admonishment is not enough," and judges should take "a robust approach" to what she called a serious and growing threat to the integrity of the justice system. The point in both cases wasn't that AI was used. It was that nobody checked before it went in front of a judge.
There's a quieter risk sitting behind both of these: privilege. In a recent Upper Tribunal decision, the court held that uploading documents or client information into an open, general-purpose AI tool can itself constitute a waiver of privilege, entirely separate from whether the output was accurate. Getting the answer right and still losing privilege over the underlying material is not a trade-off most clients would knowingly accept, which is exactly why the SRA treats putting client data into public AI tools as a likely breach of the core duty of confidentiality in its own right.
Three parties, and the risk doesn't sit where firms assume
When something goes wrong, there are three parties who could plausibly carry the liability: the individual lawyer, the firm, and the AI vendor. Firms often assume, implicitly, that the vendor absorbs more of that risk than it actually does.
Under the current legal position, the organisation that deploys an AI system generally carries primary liability for the harm it causes, not the company that built the underlying model. The Competition and Markets Authority has confirmed this principle directly: where a business deploys an AI agent that causes harm, the deploying business is responsible even though a third party built the model. For a law firm, that means the firm, not the AI vendor, is very likely the first and primary point of liability when something goes wrong in client work, regardless of whose technology produced the error.
This matters more than it might first appear, because vendor contracts frequently don't close that gap the way firms assume they do. Reviews of AI vendor agreements have found that only around 17% explicitly commit the vendor to complying with all applicable law, compared with 36% for standard SaaS contracts. In practice, many AI tool contracts are written to shift accountability toward the deploying business rather than share it. A properly negotiated agreement should require the vendor to indemnify the firm for harm arising from its own training data and model design, while the firm accepts responsibility for how it chooses to use the tool, which reflects where genuine control actually sits. It should also include a data processing agreement compliant with UK GDPR, a contractual bar on client data being used to train or improve the vendor's models without anonymisation and specific consent, and a requirement that the vendor maintain its own insurance covering AI-related risk. Firms that haven't reviewed their existing AI contracts against this checklist are, in most cases, carrying more of the downside than they think they negotiated for.
The insurance market is already repricing this
Professional indemnity insurers don't wait for case law to settle before they reprice risk, and AI is now one of the most active underwriting themes in the 2026 PI market. Insurers are asking firms directly how AI is used across the business and what verification controls exist before quoting terms. Advisers are increasingly warning firms to seek explicit, "express" cover for AI-related claims rather than relying on silent, unspecified inclusion in existing wording, because silent cover is exactly the kind of ambiguity insurers are moving to close. Separately, close to 38% of insurers have said they've considered reducing exposure to, or exiting, the solicitors' PI market altogether, largely over profitability concerns that predate AI but that AI-related claims are now adding to. None of this requires a single major AI negligence judgment to land before it changes what firms pay for cover, and in many cases it already has.
Adoption has outrun governance
None of this is an argument against using AI. It's the opposite. UK legal professionals now report the highest AI usage of any market globally: 61% of UK lawyers use generative AI at work, up sharply from 46% at the start of 2025, and 31% use it daily as a core part of how they work. Roughly half of that usage now runs through purpose-built legal tools rather than general-purpose models. The profession has not been slow to adopt AI. If anything, UK firms are ahead of most other markets in embracing it.
What hasn't kept pace is governance. Despite that adoption curve, 77% of lawyers say they remain concerned about AI producing inaccurate output, and confidentiality and regulatory compliance are consistently cited as the biggest barriers to using it more. That's the real story sitting underneath every case above: the risk isn't coming from firms that refuse to use AI, and it isn't coming from AI itself being unreliable in some unusual or unpredictable way. It's coming from the gap between how fast firms have adopted the tools and how slowly most have built the verification habits, training, and contractual protections around them. Every case cited above is, at its root, a governance failure rather than a technology failure.
What this means in practice
Closing that gap isn't primarily a technology decision, it's a people and process one. Someone in the firm needs to own AI verification protocols and be accountable for them, not as a side responsibility but as a defined one. Client disclosure about where and how AI is used in a matter needs to be a standard part of engagement, not an ad hoc judgment call. Vendor contracts need to be reviewed against the indemnity, data protection, and insurance points above, not assumed to be adequate because the tool is well known. And junior lawyers, who are often the heaviest users of these tools day to day, need AI literacy and verification discipline treated as a trained, checked competency during qualification and early practice, not something picked up informally.
That last point is increasingly a hiring and development question as much as a compliance one. Firms building this properly are starting to look for it explicitly, whether that's a risk or professional support lawyer who owns AI governance, associates who can demonstrate real verification discipline rather than just tool familiarity, or practice leads capable of setting the policy in the first place. As liability for AI use becomes as much a feature of legal practice as liability for missed limitation dates, the firms that treat it as a defined competency, and hire and train for it accordingly, are the ones least likely to be the next case study.
Read the full analysis
inside the NMG Legal Circle.
The remainder of this piece, including the recent UK rulings, the vendor-contract checklist and what firms are now hiring for on AI governance, is reserved for members of the NMG Legal Circle. Membership is free and gives you first access to our market intelligence, salary benchmarks and long-form analysis.
- · Free membership
- · First access
- · Unsubscribe anytime