Why AI governance matters
Olivier Roth, Policy Manager in the SRA's Innovation Policy team, discusses putting in place an effective framework for managing AI use.

Olivier Roth
The sophistication of AI technology and the degree to which it is becoming embedded into legal services continues to grow fast. For instance, last year, at the SRA, we authorised the first AI-driven law firm. And last month we announced we are playing a key role in the government's Advisory AI Growth Lab initiative, which aims to accelerate AI development and deployment.
The advent of agentic AI is also poised to bring significant change. This was discussed in detail at our recent SRA Innovate event in Bristol. Agentic AI systems are built around autonomous AI ‘agents’ that can plan and deliver multi-stage processes without continuous human oversight.
But increased capability and complexity bring greater risk for law firms and lawyers. Any firm serious about harnessing AI to improve efficiency or enhance client services should give equal attention to AI governance. While AI can support legal work, it does not have a legal personality of its own. Law firms and lawyers remain responsible for the decisions they make and the services they provide, including where AI has been used to support them.
Identify the risks
A key objective of AI governance is understanding and managing risk. Common AI-related risks include:
- bias and unfair outcomes in decision making
- hallucinations, errors and inaccurate outputs
- data leakage, confidentiality breaches or misuse of information.
The risks associated with AI will vary depending on how it is being used and the nature of a firm’s work. A useful starting point is to identify what AI systems are used, how staff are using these tools, and where these tools interact with clients, legal work, business processes or sensitive information. This can help firms to understand the risk profile and put appropriate controls and safeguards in place.
Lisa McClory, Of Counsel, DeepTech and Innovation at CMS, in her keynote presentation at SRA Innovate suggested firms should make sure they understand their system architecture and how data flows through it. Doing this will enable them to identify potential risks at every stage of an AI workflow.
This is important because not all risks will be immediately obvious. For instance, ‘data can be processed and shared across multiple parts of an AI system’ McClory points out, ‘often in a non-transparent way’. She suggests mapping out all the points at which users need to supply data, such as when they log in, or the times where AI may pick up on other identifying details, such as an IP address.
Once you have mapped out processes and identified potential risks and consequences, next is to put in place appropriate mitigations. Examples could include making a technical change to how an AI tool works or introducing steps where human verification is required. This is not a one and done exercise, it will need to be reviewed on a regular basis.
She also suggests it is vital to have clear lines of human accountability and oversight for all AI tools that an organisation is using.
'Firms should not assume that AI governance only becomes relevant when a new AI tool is purchased’
AI is closer than you think
Whether or not your firm has embarked on a major AI change programme, it is important to understand AI risks related to the software you are already using. Many mainstream platforms and applications used for email, messaging, and document drafting and sharing now have some degree of AI embedded within them.
Speaking on our first panel discussion about ‘practical use of AI in legal practice’ at SRA Innovate, Rupert Poole, Chief Technology Officer at law firm Hugh James commented: ‘the reality for any law firm is that even if you haven't got AI [formally] deployed, your staff are probably already using it’.
This is why firms should not assume that AI governance only becomes relevant when a new AI tool is purchased. Establishing clear internal guidelines on which AI tools can be used, how they should be used, and the safeguards that apply is an important foundation for managing risk and supporting responsible adoption.
Building the right skills and culture
Internal policies and guidelines are important, but as Sue Turner OBE, founder of consultancy, AI Governance, cautions they need to be part of a wider approach to embedding responsible AI use into your organisation and its culture. ‘We can put together checklists, we can tick the boxes, we can do impact assessments and then think it's safe to use. But there are so many grey areas when we're using AI,’ she said.
In the Q&A session following the second panel at SRA Innovate, ‘what’s on the horizon’, an audience member asked how firms can ensure that staff have the skills needed to be able to monitor and critically assess AI-generated outputs. While there is no single answer, firms can help build capability through a combination of training, education and practical experience.
Training and education will need to be multifaceted, providing staff with baseline technical knowledge as well as appropriate practical opportunities to apply and develop that knowledge. Such opportunities could include creating a controlled environment where staff are able to experiment with AI, and learn about the opportunities and risks associated with the technology.
'Firms can realise the benefits of AI while continuing to meet their professional and regulatory obligations'
Supporting innovation while maintaining standards
Such efforts can help to create a culture where staff feel confident to experiment and innovate, while also understanding AI’s limitations and risks. Just as importantly, staff should feel empowered to recognise and say when AI isn’t the right tool for a particular task.
AI familiarity and literacy is becoming increasingly important as client expectations evolve.
Our keynote speaker, Lisa McClory, said her firm gets questions from clients around whether they can use AI to do things faster, adding there is sometimes an expectation you can ‘receive a human level of advice but at an AI-related speed’.
This is creating a clear need for firms to put the appropriate ‘oversight and governance in place so that we can deliver on those expectations’ she says. Delivering fast cannot mean taking shortcuts.
The legal profession has adapted to significant technological change before, such as digital case management systems and cloud-based services. AI presents another opportunity to innovate and improve services. With appropriate governance, effective training and a clear understanding of the associated risks, firms can realise the benefits of AI while continuing to meet their professional and regulatory obligations.

About the author
Olivier Roth is Policy Manager in the SRA's Innovation team specialising in the intersection of artificial intelligence, technology, and legal regulation. With a background in law, tech and human rights, Olivier leads initiatives that shape the SRA's approach to innovation and digital transformation.