What Your Risk, IT and Compliance Teams Need in Place Before You Deploy
What good AI governance looks like for a UK law firm – and what each of your teams needs in place before any tool goes live.
What AI governance actually means for a law firm
That responsibility point is the one the regulator keeps returning to. The SRA’s position is that whatever the technology, the lawyer remains the person making the decision and carrying professional responsibility for it and has to be able to explain and justify their own work. Governance is how a firm makes that real rather than aspirational.
And it’s worth stating plainly: governance is not a synonym for restriction. The SRA has authorised firms that deliver legal services through AI, working closely with them to get the right protections in place first. The regulator’s interest is in controls and accountability, not in the technology itself. Get the foundations right and you can move quickly. Without them, you’re exposed whether you’ve deployed one tool or ten.
it’s worth stating plainly: governance is not a synonym for restriction.
Why governance has to come before deployment
Once a tool is embedded in how people work, reining it in becomes a change-management problem rather than a procurement decision. Data that should never have gone into a system can’t easily be pulled back out. Habits formed in the first few weeks tend to set.
The cost of leaving the work undone usually shows up as hesitation. Firms rarely stall on AI because the tools are weak, they stall because nobody has defined what good use looks like, and in the absence of that clarity, caution is the only sensible default.
Uncertainty reads as risk, and unmanaged risk reads as “not yet.”
Pre-deployment governance is what turns that hesitation into confident, defensible adoption. That’s what the rest of this guide is for.
The regulatory picture every UK firm should understand
The clearest obligation sits in data protection. The ICO treats a Data Protection Impact Assessment as mandatory before high-risk AI processing, and given the nature of AI, the large majority of new use cases involving personal data will trigger that requirement.
In practice, the DPIA works as a go-live gate: documented, reviewed by the firm’s Data Protection Officer before deployment, and treated as a non-negotiable step in project approval. The same regime brings related duties – building compliance in from the outset under privacy by design and default and making sure there’s meaningful human oversight wherever an AI system feeds an automated decision with significant effects. We go deeper on what this means for privilege and confidentiality in our guide to client confidentiality and AI.
The wider horizon matters too. The EU AI Act reaches any organisation whose AI use affects people in the European Union, wherever the firm itself is based. Its most demanding obligations (the ones covering high-risk systems) were due to apply from August 2026, but the European Parliament voted in June 2026 to push them back to December 2027, a change still awaiting formal sign-off from the Council. Its transparency obligations still apply from August 2026 regardless.
For a UK firm, the practical reading is simple: the EU framework matters if you act for EU clients or handle EU data, but the duties that bind you today come from the SRA and the ICO.
Solicitors Regulation Authority
Information Commissioner’s Office
The UK’s direction for now is regulation through individual regulators rather than a single AI Act, so your footing rests on obligations you already understand.
AI governance by function: risk, IT, compliance and fee earners
Risk
Risk owns what could go wrong, and who answers for it when it does.
Before go-live, that means a documented, risk-based assessment of the specific tool and use case rather than a blanket position on “AI”; a named owner accountable for each tool; clear supervision of AI-assisted work, particularly from junior colleagues; and an honest read of how it sits with your PI cover, since insurers weigh a firm’s documented risk-management practices at renewal (and AI is steadily becoming part of that picture).
The test is the regulator’s own. When something goes wrong, can the firm show a documented, risk-based approach, proper supervision, and an awareness of the relevant guidance.
IT and security
IT owns the boundary between the tool and the firm’s data. The central question is simple to ask and easy to get wrong: where does the information go, who can see it, and is it used to train someone else’s model?
Before go-live, that means written answers on data residency, retention and model training; the tool sitting inside your security perimeter rather than alongside it as someone’s personal account; a clear line between sanctioned tools and the consumer-grade ones people will otherwise reach for; and logging that lets you reconstruct what was used, by whom, and when.
The most common AI data incident in a law firm isn’t a sophisticated breach. It’s a fee earner pasting confidential text into a free tool.
Compliance and data protection
Compliance owns the firm’s standing with the regulators whose rules apply whether or not AI is in the picture. The DPIA gate lives here, alongside lawful-basis decisions, retention schedules, and the records that evidence them.
The job before go-live is to have made and documented these decisions, not to be assembling them under pressure after the fact. Most of it ends up captured in a written position, which we cover in our guide to building an AI policy.
Fee Earners
The other three functions can do everything right and still be undone at the point of use.
Fee earners need to know, before they touch a tool, what it’s for, what it must never be used for, and where the line sits – a short, usable set of ground rules, not a policy nobody reads.
In practice that’s which tools are approved, what information can and can’t go into them, and the standing expectation that AI-assisted work is checked by a qualified person before it reaches a client or a court. Most people aren’t trying to cut corners; without clear rules, they just improvise.
The prerequisite most firms underestimate
Point a capable tool at messy underlying data and it’ll give you confident, plausible, occasionally wrong answers – the worst failure mode there is, because it’s the hardest to catch.
Sorting the data out is rarely the exciting part of an AI project. It’s often the part that decides whether the project works at all. We treat data readiness as a governance issue in its own right in our guide to choosing and deploying AI tools.
Choosing AI tools you can actually govern
A tool you can’t govern is one you probably shouldn’t have bought. The questions worth asking before you sign, on data handling, transparency, supervision and exit, are mostly the ones a good governance framework already asks.
Bringing risk, IT and compliance into the evaluation early is far cheaper than finding the gap after the contract’s signed. Our guide to choosing and deploying AI tools sets out the questions worth asking before you commit.
Who should own AI governance
Governance that belongs to everyone in general belongs to no one in particular.
We’ve put all of the above into a single pre-deployment governance checklist, organised by function and built to be used as a working document. It’s what we’d want in front of us before signing off any AI tool for live use.