In partnership with

For most of the past year this newsletter has covered AI as something lawyers use. This week it approaches from the other direction. The SRA has rewritten the technology section of its money laundering risk assessment around AI-enabled impersonation, which means "is the client on your video call real?". The government's legal services AI sandbox also opened for applications, with a September deadline.

AI in Practice

The SRA puts AI-enabled fraud into your firm-wide risk assessment

The Solicitors Regulation Authority updated its sectoral risk assessment on 6 August. The document covers money laundering, terrorist financing, proliferation financing and sanctions, and it has been substantially rewritten. Buried in the SRA's own summary of changes is a single line that will cost some firms a morning: "Technology risk has been updated to focus on recent AI risks." The legal sector continues to be assessed as high risk for money laundering, with no significant change in vulnerabilities since 2020.

Two passages carry the new material. Under emerging risks, the assessment says that "AI-enabled impersonation techniques, including deepfakes, may increase the risk of identity fraud and misrepresentation during client onboarding and throughout the life of a matter", and that "the risk may be greater where firms rely on remote verification methods or digital onboarding processes". Under delivery channel risk, dealing with remote clients, it goes further: "Remote onboarding and non-face-to-face interaction can increase exposure to impersonation, synthetic identity and deepfake-enabled fraud, particularly where verification relies heavily on digital information or video-based interaction." The SRA points firms to the Financial Action Task Force's horizon scan on AI and deepfakes, to the government's Digital Identity and Attributes Trust Framework register, and to a Five Eyes alert on AI-enabled cybercrime.

The reason this is not simply interesting reading is Regulation 18. Under Regulations 18 and 18A of the Money Laundering Regulations 2017, firms must have regard to the SRA's sectoral risk assessment, and to any updates to it, when creating and maintaining their own firm-wide risk assessment. The SRA also states plainly that if a firm is selected for a proactive inspection or a desk-based review, the firm-wide risk assessment is one of the key documents it will request. A firm-wide risk assessment dated before 6 August which says nothing about AI-enabled impersonation is therefore a document with a gap in it, and the gap is one the regulator has just written down in public.

This author would make two observations. The first is that the SRA's language is heavily hedged, as it usually is. Everything "may" increase risk, and digital identification services "may" be a relevant consideration. There is no requirement to buy deepfake detection software, and the assessment stops well short of prescribing a control. The obligation to take the assessment into account, though, is not hedged at all. The second observation is about exposure. Conveyancing remains the practice area the SRA rates as carrying the greatest inherent money laundering risk, and the one its MLRO reports list as generating the highest number of reports. It is also, since the pandemic, among the practice areas most likely to onboard a client who will never be met in person. Those two facts have been sitting next to each other for a while, and the SRA has now joined them up.

Takeaways

  • Act: Open your firm-wide risk assessment and check whether it says anything about AI-enabled impersonation, deepfakes or synthetic identity at onboarding. If it does not, add it, date the revision, and record what you considered.

  • Watch: Whether the SRA moves from "may be a relevant consideration" to an expectation that firms use a registered digital identity service or deepfake detection. The signposting to the government's DVS Register is where that would start.

  • Risk: Relying on a video call to verify a client you will never meet. The regulator has now put in writing that this is a heightened risk, so a firm doing it without a documented control has a harder conversation on inspection than it did a fortnight ago.

On your radar

  • The government's AI sandbox for legal services is open, and applications close on 27 September: The Legal Services AI Growth Lab opened to applications on 6 August. The Ministry of Justice is asking law firms, conveyancing businesses and lawtech developers for real-world AI proposals, with around a dozen to be selected for a process taking roughly nine months. The Legal Services Board, the SRA, the Council for Licensed Conveyancers and the Information Commissioner's Office are all providing regulatory input, and the MoJ has been careful to say that the lab cannot change legislation or create exemptions from the law, and that taking part is not approval, endorsement or authorisation. The regulatory questions it expects to see include client confidentiality, legal professional privilege, data protection and the use of client data. Why it matters for UK lawyers: this is the first structured route to ask a regulator directly how the existing rules apply to something you are building, instead of guessing and hoping nobody asks later. If you have an AI project that has stalled on a confidentiality or privilege question, read the eligibility criteria before 27 September. (GOV.UK, Legal Futures)

  • £3.62m of lawtech funding is out to tender, and the deadline is a fortnight away: The Ministry of Justice is looking for an organisation to deliver the third phase of LawtechUK, running from November 2026 to March 2029, with £3.62m attached. Applications close on 26 August. Most readers of this newsletter will not be bidding, but whoever wins will shape which lawtech gets funded, tested and promoted to smaller firms for the next three years. (Law Society Gazette)

  • Agentic AI: you can be accountable for work you had no way of supervising: Following the SRA's agentic AI post covered a fortnight ago, a piece in Legal Futures on 12 August by Yazad Bajina of Kord sets the accountability problem out more sharply. Using an AI tool does not transfer or dilute professional responsibility, but an agent which completes multi-step tasks in the background is, by design, beyond ordinary human review, so a solicitor can be held responsible for work they had no real means to oversee. It is a vendor byline and should be read as such, but two points in it are worth having: the Law Society's April 2026 foresight report found no evidence that agentic AI is actually being used in legal practice yet, and the SRA's own suggestion is that an accountable person needs data logs sufficient to reconstruct what the agent has been doing. Why it matters for UK lawyers: the supervision duty does not bend to accommodate a tool that cannot be watched, so the audit trail has to do the work instead. Before approving any agentic pilot, ask the vendor what logs it produces and whether a supervisor could reconstruct a matter from them. (Legal Futures)

  • Bird & Bird buys its transformation capability from EY: Bird & Bird has hired a legal transformation team from EY, led by Shahin Baghaei, reported on 10 August. The Big Four have spent years building legal-adjacent transformation practices, and this is talent moving in the opposite direction. Why it matters for UK lawyers: it suggests firms have decided that AI and process change capability is worth owning rather than renting by the day, which is a different calculation from buying a tool. If your firm has AI change work planned, ask who is actually leading it, and whether that person has delivery time or a full fee-earning diary. (Artificial Lawyer)

  • Must the head of "Claude for Legal" be a lawyer?: Anthropic's appointment of Robert Mahari to lead Claude for Legal has drawn criticism on the basis that he has not spent long in practice, and Artificial Lawyer argued on 10 August that the objection misses what the role needs, which is an understanding of the work lawyers do and of how the technology behaves. Why it matters for UK lawyers: this is the vendor-side version of last week's finding that only 35% of the AI leads appointed across the top 100 UK firms hold a practising certificate, so the same question is now being asked in both directions. When a vendor tells you its product understands your practice area, ask who inside the company has done that work. (Artificial Lawyer)

Ad Break

In order to help cover the running costs of this newsletter, please check out the advert below. In line with my promises from the start, adverts will always be declared.

Write docs 4x faster. Without hating every second.

Nobody became a developer to write documentation. But the docs still need to get written — PRDs, README updates, architecture decisions, onboarding guides.

Wispr Flow lets you talk through it instead. Speak naturally about what the code does, how it works, and why you built it that way. Flow formats everything into clean, professional text you can paste into Notion, Confluence, or GitHub.

Used by engineering teams at OpenAI, Vercel, and Clay. 89% of messages sent with zero edits. Works system-wide on Mac, Windows, and iPhone.

For Review

Sectoral Risk Assessment: anti-money laundering, terrorist financing, proliferation financing and sanctions (SRA)

The document behind this week's lead, updated on 6 August. If you are short of time, open the Technology heading under "Emerging and current risks" and the "Remote clients" heading under delivery channel risk. Between them they are the two paragraphs your firm-wide risk assessment now has to answer, and they run to about 150 words.

Horizon scan: AI and deepfakes (Financial Action Task Force)

The source the SRA relies on for its AI conclusions. It is a PDF, and it contains the case studies the SRA does not reproduce: how deepfakes have been used to defeat liveness detection in customer due diligence, and which controls held up. Worth the time if you are the MLRO or MLCO and need something more concrete than an instruction to be aware of the risk.

Read or listen: FATF

'This was a righteous case. A holy war': the lawyer who took on Meta and Google, and won (The Guardian)

A profile of Mark Lanier, who persuaded a jury that Meta and Google had designed their products to be addictive to children, and which may open the way to thousands of similar claims. Published on 12 July, so a weekend read rather than news, and not an AI story. It earns its place because it is the clearest recent account of how a novel technology harm gets converted into a cause of action a court will actually run, which is the exercise the profession will be attempting on AI before long.

Read or listen: The Guardian

Practice Prompt

Try the below prompt to work out what your firm-wide risk assessment now has to say about AI-enabled identity fraud, so you can close the gap the SRA opened on 6 August rather than discover it on inspection. Ensure you fill in context and constraints and other aspects marked with {}. Remember to adhere to the Golden Rules and do not upload confidential or privileged information to public tools.

You are assisting the MLRO or MLCO of a law firm in England and Wales. Your task is to
produce a gap analysis of the firm's existing firm-wide risk assessment against the
AI-enabled identity fraud risks the SRA added to its sectoral risk assessment, as a
planning aid only.

Context to apply:
- The firm: {size, offices, and number of fee earners}
- Work in scope of the Money Laundering Regulations: {e.g., "residential and commercial
  conveyancing, company and commercial, private client"}
- How clients are onboarded today: {e.g., "in person for private client, electronic ID
  provider plus a video call for conveyancing, no face-to-face requirement"}
- Electronic verification in use: {name the provider, and say whether it is on the
  government's Digital Identity and Attributes Trust Framework register, or that you do
  not know}
- What the current firm-wide risk assessment says about remote onboarding and identity
  fraud: {paste the relevant section, redacted, or say "nothing"}
- Date the firm-wide risk assessment was last reviewed: {date}

Produce the analysis under these headings:

1. What the firm currently says
   Summarise, neutrally, what the existing risk assessment already covers on delivery
   channel risk, remote clients and identity verification. Do not improve it: describe it.

2. Gaps against the sectoral risk assessment
   Identify where the firm's assessment is silent on, or inconsistent with, the risks of
   AI-enabled impersonation, deepfakes and synthetic identity at onboarding and during the
   life of a matter, including the heightened risk where verification relies on video-based
   interaction. Set out each gap as a discrete item.

3. Practice areas ranked by exposure
   Rank the firm's in-scope work by how exposed it is, taking account of transaction value,
   how often the client is met in person, and how far the matter relies on remote or digital
   verification. Explain each ranking in one or two lines.

4. Controls to consider
   For each gap, set out the range of responses available, from documentation changes
   (recording the risk and the firm's reasoning) through process changes (a face-to-face or
   enhanced check trigger at a stated value or risk level) to technology (deepfake detection,
   a registered digital identity service). Give the trade-offs of each. Do not recommend a
   single option.

5. Evidence and questions for the provider
   List the questions to put to the firm's electronic verification provider, including what
   liveness detection it uses, whether it tests for deepfake presentation attacks, what it
   reports when a check is marginal, and where liability sits when a check is defeated.

6. What this analysis cannot tell you
   Flag every point where the output depends on an assumption you have had to make, and say
   what the firm would need to establish to replace it with a fact.

Constraints:
- {Add firm-specific constraints, for example a fixed-fee conveyancing model, an insurer
  requirement, or an existing provider contract with time left to run.}
- Apply the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the
  Payer) Regulations 2017 as amended, the SRA Standards and Regulations, and LSAG guidance.
- Do not invent regulatory requirements, SRA expectations, enforcement outcomes or product
  capabilities. Where the position is not known, mark it as a question rather than an answer.
- Do not state that any control is sufficient for compliance. The purpose is to surface gaps
  and options, not to certify the firm.
- This is a planning aid, not legal or compliance advice. The MLRO, MLCO and the firm's
  managers remain responsible for the firm-wide risk assessment and for the decisions taken
  on the back of it.

How did we do?

Hit reply and tell me what you would like covered in future issues or any feedback. We read every email!

Thanks for reading,

Serhan, UK Legal AI Brief

Disclaimer

Guidance and news only. Not legal advice. Always use AI tools safely.

Recommended Newsletters

Below are a few newsletters that I recommend, for various reasons. Check them out!

Staying Ahead with AI

Staying Ahead with AI

Step by step on how to use the latest in AI and how it ranks against what you're already using!

There's An AI For That

There's An AI For That

The #1 AI newsletter. Read and trusted by over 2.5 million readers, including employees at Google, Microsoft, Meta, Salesforce, Intel, Samsung, Zoom, Wix, HubSpot, Nebius, Suno, Zapier, as well as ...

Superhuman AI

Superhuman AI

Keep up with the latest AI news, trends, and tools in just 3 minutes a day. Join 1,500,000+ professionals.