LIVE · cybersecurity feed
Live wire
breach

UK Legal Regulator Raises AI Misuse Concerns

Solicitors Regulation Authority sounds the alarm over AI hallucinations and data leaks

zeroday.news ·

The Solicitors Regulation Authority (SRA), the regulatory body for the UK's legal sector, issued a warning notice on August 17, reminding solicitors and law firms of their obligations regarding the safe and responsible use of artificial intelligence. The SRA highlighted two primary areas of concern: AI-generated "hallucinations" in legal work and court submissions, and the potential for data leaks involving confidential client information.

The SRA stated that it has observed instances of AI hallucinations, with both solicitors self-reporting issues and senior members of the judiciary reporting potential breaches of the SRA's Code of Conduct. These hallucinations involve AI systems producing false or inaccurate information, including non-existent case law authorities. The regulator emphasized that presenting such false material to the court could lead to serious consequences, including potential contempt of court.

Another significant concern is the entry of confidential client data into public AI tools. The SRA noted that this practice raises serious data protection and confidentiality issues. It warned that using both free and paid-for AI systems without appropriate contractual, technical, and organizational safeguards could breach client confidentiality. The SRA stressed that client information must always remain within a secure environment.

The regulator underscored that solicitors and regulated individuals remain fully accountable for any AI output. Firms are expected to implement effective governance structures, systems, and controls to manage AI-related risks. The SRA also clarified that those supervising junior or unauthorized colleagues could be held responsible if false citations are presented to the court.

The SRA's approach to regulation is outcomes-based, meaning it sets the expected standards but does not dictate specific methods for achieving them. The warning notice provided a comprehensive list of considerations for the legal profession, emphasizing the need for appropriate human oversight, informed professional judgment, and a risk-based approach to ensure compliance with regulatory and legal obligations.

The SRA cautioned that these incidents can result in poor client outcomes, slow down case progression, and damage public trust in the legal profession. The Law Society of England and Wales affirmed that solicitors have a duty to use AI and other technologies responsibly to act in their clients' best interests, and called for continued clear guidance from the SRA as AI use evolves.

breachnation-stateai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

security

Meta Ran Ads for an App That Promised to Nudify Female Politicians

One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

security

Hackers target Ukrainian agency managing assets seized from sanctioned Russians

The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages.

vulnerabilitycritical

NASA Ground Control Software Flaw Enables Unauthenticated Commands

Critical AIT-GUI flaws expose spacecraft commands and scripts to unauthenticated attackers

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

security

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume