Two AI rulebooks were written last week, and only one of them binds anybody
On Monday 14 September the Joint Committee on Human Rights published a report demanding a dedicated AI Bill, a statutory regulator with enforcement powers, and outright prohibitions on a short list of applications. The following morning, senior partners from the City of London’s largest firms met at Guildhall to weigh which parts of the law firm model AI is going to change, and which parts it is not. The legal commentator Joshua Rozenberg, writing in A Lawyer Writes, put those two events side by side in a single short column and, in doing so, exposed the more useful question: one of these gatherings was proposing law that does not exist, and the other was ratifying practice that already does.
Strategic Reality: The committee’s report is addressed to a government that has declined to legislate for two years. The Guildhall conference was addressed to firms that have already bought the software. Only one of those audiences has to act on Monday morning.
Why the committee aimed at a lever Britain does not hold
The report’s headline ask is unusually blunt for a select committee. Alongside the familiar architecture of a risk-tiered regime and a single oversight body, the committee wants a statutory bar on building or supplying artificial general intelligence and its superintelligent successors. Rozenberg reads the recommendation as resting on two claimed dangers: harm on a broad scale, and systems that slip beyond any meaningful human control.
The proposal is not eccentric in context. The committee’s chair, the Labour MP Alex Sobel, had tabled a private member’s bill on artificial superintelligence the week before, a point noted in the regulatory consultancy Handley Gill’s analysis of the report. But as that same analysis observes, the organisations sprinting towards this goal are overwhelmingly American, which puts a British statutory prohibition in an awkward position: it constrains a class of activity that is not meaningfully happening here.
Ministers have already made that argument in almost those words. When peers considered a narrower proposal for a legal power to shut down a misbehaving frontier model earlier in September, the Cabinet Office responded that Britain cannot simply turn AI off, since restricting a model domestically does nothing about it being built or misused abroad. Our news desk covered the committee’s report and the government’s counter-position when both landed.
Critical Context: Labour’s 2024 manifesto promised binding regulation for the handful of companies building the most capable models. That year’s King’s Speech repeated the commitment. This year’s contained no AI bill. The gap between stated intention and legislative programme is now long enough to be a policy in its own right.
| What was proposed | Who it binds today | Realistic route to force |
|---|---|---|
| Ban on developing AGI and superintelligence | Nobody; no UK developer is building at that frontier | Requires primary legislation plus international alignment |
| Statutory AI regulator with sanction powers | Nobody; the AI Security Institute has no statutory power | Requires a bill Whitehall has not scheduled |
| Prohibited uses: subliminal techniques, emotional inference, misused profiling and biometrics | Nobody yet, though the list signals political risk | Requires the same bill, plus consultation on scope |
| Court practice directions on AI-assisted material | Every litigator in England and Wales, now | Already in force |
| SRA conduct obligations on competence and supervision | Every regulated solicitor, now | Already in force |
| Client outside counsel guidelines on AI use | Whichever firms want the mandate | Already in force, firm by firm |
The pattern in that table is the argument. Everything with teeth is already operating, and none of it came from an AI bill.
What the committee got right is the part nobody is discussing
Buried in the same report is a diagnosis far more consequential for legal services than the superintelligence recommendation, and it has attracted a fraction of the attention. The committee observes that UK laws capable of applying to AI do so mainly at the point of deployment, which leaves responsibility sitting with users rather than designers. Regulators, it notes, have no power to test or evaluate systems before release, and model developers engage with the AI Security Institute voluntarily.
Read that from a partner’s chair. It is a statement that the legal liability for a defective AI system lands on the professional who used it, not the company that shipped it. That allocation is not a gap the committee is proposing to close in the short term; it is the settled position, and an AI Bill of the kind proposed would rearrange the upstream obligations whilst leaving the downstream ones exactly where they are.
The second buried finding is sharper still. The committee states that the mere presence of a human in the loop is not sufficient to constitute meaningful human involvement or intervention. That sentence was written about automated decision-making under data protection law. It reads as a description of what happens when a trainee accepts a first-draft research memo without checking the citations, and it maps precisely onto the failure mode we set out in our analysis of hallucination as a supervision problem rather than a technology problem.
Hidden Cost: A firm can satisfy every current rule about disclosing AI use and still fail the standard the committee describes, because the standard is about the quality of the human check, and no firm measures that. Disclosure is auditable. Attention is not.
Is the profession regulating itself by default?
The City of London Law Society speaks for over 22,000 solicitors across 70 corporate member firms, on the figures it published in June. It has stood up a specialist AI committee, chaired by Minesh Tanna, who is global AI lead at Simmons & Simmons, with a remit its chair Colin Passmore described as joining policy discussions on AI regulation and coordinating the response of London’s leading firms. It runs twenty other specialist committees on the same model, and they have been shaping the detail of commercial law for decades.
That is a standards body in everything but name, and it is already operating whilst the statutory regulator remains a recommendation. The published line-up for the 15 September Guildhall conference put the SRA’s chief executive, Sarah Rapson, on the programme alongside those firms and general counsel from HSBC, Lloyds and Canary Wharf Group. Vendors were billed too, among them Harvey’s legal innovation partner. The people who will decide what acceptable AI use looks like in UK legal services were assembled in one building, and none of them needed a bill to convene.
Competitive Reality: When a profession’s representative body, its regulator, its largest clients and its software vendors all meet to settle what good practice means, the output is a de facto standard. Firms that are not in that conversation will still be held to its conclusions.
The reliability problem the City is actually arguing about
Rozenberg reports that Passmore’s concern about AI is its current unreliability, and that he also addressed the ethical questions raised by the Post Office scandal. Those two things belong together, and the pairing is more instructive than either alone.
Unreliability in a legal tool is not a bug rate. It is a supervision cost, and it is borne by the person least able to refuse it. Adoption among legal professionals has reached 94% while anxiety about fabricated output climbed to 83%, a combination that describes a profession using a tool it does not fully trust because the alternative is being outpriced. AI hallucination is the visible failure. The invisible one is the reviewer who stops looking because the output has been right eleven times running.
The Post Office reference points at the institutional version of the same failure: a computer system treated as reliable by people with a strong incentive not to interrogate it, and a chain of professional judgment that deferred to the machine at every link. The lesson the profession drew from that scandal was about the duty to challenge evidence produced by software. Generative AI puts that duty inside the firm’s own workflow rather than on the other side of the case.
| Stakeholder | What the deployment layer demands of them | What the AI Bill would change | Where the real exposure sits |
|---|---|---|---|
| Managing partner | A defensible firm position on AI use and its limits | Almost nothing in the near term | Client audit and professional indemnity renewal |
| Practice group head | Verification standards that survive a bad matter | Nothing | Supervision of assisted work |
| General counsel (client side) | Outside counsel guidelines specifying permitted use | Nothing | Reliance on advice produced by tools they cannot inspect |
| Junior lawyer | The judgment to reject plausible output | Nothing | Career formation without the drafting reps |
| SRA | Conduct enforcement with existing powers | Possible transfer of AI oversight to a new body | Capacity, not authority |
| Frontier developer | Voluntary engagement with AISI | A statutory duty regime, if enacted | None, currently |
The column marked “what the AI Bill would change” is the point. For everyone in UK legal services except the developers, the proposed statute is close to a null operation.
What a firm should do while the legislation does not arrive
The temptation is to wait for clarity. That reading misunderstands where clarity comes from in this market. The binding constraints on a City firm’s AI use over the next two years will come from four sources, none of which is Parliament: the courts, through practice directions and costs sanctions; the SRA, through existing conduct rules; clients, through outside counsel guidelines; and insurers, through renewal questionnaires. All four are already asking.
Implementation Note: Build the firm’s AI position against the deployment layer, not the legislative one. A governance framework designed to satisfy the courts, the SRA, clients and insurers will satisfy an AI Bill if one arrives. A framework designed for a hypothetical statute satisfies none of them today.
For firms with no written position yet: produce one document that states which categories of work may use AI assistance, which may not, and what verification is required before assisted output reaches a client. Get it approved by the board rather than the IT committee. The absence of a written position is itself the finding an insurer or a client audit will record.
For firms with a policy but no evidence: start instrumenting. Record which matters used assisted work, who verified it, and how long verification took. This is the data that answers a client’s audit question and the data that tells the board whether the licence spend is returning anything. Most firms have neither.
For firms already measuring: move to the part that actually differentiates. The committee’s warning about the insufficiency of a human in the loop is a direct instruction to test whether your reviewers are catching planted errors. A firm that can demonstrate its verification works has something no competitor can license, and something the profession’s emerging standard will eventually require.
Success Factor: The firms that come through this well will be the ones that treated AI governance as a supervision discipline owned by lawyers, rather than a compliance artefact owned by risk. The distinction shows up the first time a matter goes wrong.
Four problems that will not announce themselves
The standard will be set by the firms with the most to spend. A representative body’s committee output reflects the practice of its most active members, and the most active members are the ones with dedicated AI leads and Berlin technology labs. We set out in our analysis of the build-versus-buy divide why mid-market firms cannot match that spending. They will nonetheless be measured against a standard partly shaped by it. The mitigation is participation: committee membership is cheaper than compliance with a standard you had no hand in writing.
Regulatory reorganisation could reset everything. If an AI Bill does pass and establishes a single oversight body, some portion of AI supervision for legal services may migrate away from the SRA. Firms that have built their governance around SRA guidance specifically, rather than around defensible professional judgment generally, will be re-papering. Write the framework so it survives a change of regulator.
Client guidelines are converging faster than anyone is tracking. Outside counsel guidelines on AI use are being drafted independently by dozens of in-house teams, and they will not agree. A firm acting for twenty major clients may soon be operating under twenty incompatible AI clauses, with no central record of which matter sits under which rule. This is a knowledge-management failure waiting to become a breach, and almost no firm has a register.
The junior pipeline degrades silently. Assisted drafting removes exactly the repetitions through which judgment used to form. The cost does not appear for four or five years, at which point the firm discovers its mid-level associates cannot tell when the output is wrong. No regulation will catch this, because nothing about it is a breach. Our news desk has covered the warning that City firms risk a crisis of judgment as juniors accept AI output uncritically; the mitigation is deliberate and expensive, which is why it keeps getting deferred.
⚠️ Warning: Of these four, only the first is visible on a risk register today. The other three produce no incident, no complaint and no finding until the damage is structural.
What the two meetings actually settled
The committee has done something valuable, and it is not the superintelligence recommendation. It has put on the record, in a parliamentary document, that Britain’s AI liability sits with deployers rather than developers, and that a human signature is not the same as human judgment. Both statements describe the conditions under which UK law firms are already working, and both will be cited long after the legislative proposal has lapsed.
The practical conclusion for anybody running a legal business is that the de facto standard for AI in UK legal services is being written at Guildhall, in SRA guidance, in court practice directions and in client procurement documents, and that it is being written now.
Three things determine whether a firm is on the right side of it. First, a board-level position on AI use that a client auditor could read without embarrassment. Second, evidence that verification of assisted work actually happens and actually catches things. Third, a seat, however junior, in the forums where the profession’s expectations are being negotiated, because those expectations will apply whether or not the firm helped shape them.
The checklist is short. Write the position down. Measure the checking. Turn up to the conversation.
Take Action: Ask one question at the next partners’ meeting: if a client asked us tomorrow to evidence how we verify AI-assisted work, what document would we send? If the answer is a policy rather than a record, the work has not started.
Source and attribution
This analysis draws on Joshua Rozenberg’s column “City lawyers take on AI”, published in A Lawyer Writes on 14 September 2026, which set the committee’s recommendations alongside the City law society’s Guildhall conference and Colin Passmore’s comments on AI reliability. Supporting detail on the committee’s recommendations comes from its own press release on the report of 14 September 2026, and from Handley Gill’s published analysis of the report. Conference details and membership figures are taken from the society’s own announcements.
This strategic analysis was written by Resultsense, a UK-focused AI news and analysis publication. We will be watching whether the profession’s own AI committee output starts to function as a compliance benchmark before any statute reaches the floor of the Commons. Read more analysis at Insights, or get in touch.