Beyond “The AI Said So”: Why Governance Infrastructure Is the Missing Layer for Regulated Professionals

Articles

Courts, regulators and insurers have made the position clear: professionals who rely on AI without governance infrastructure face disciplinary action, sanctions and uninsured liability. The global count of court proceedings involving AI-fabricated content reached 1,598 by mid-2026, with sanctions escalating from $5,000 in 2023 to over $109,000 in combined penalties by 2026. The SRA’s August 2026 Warning Notice, the EU AI Act’s transparency obligations now in force, and the emergence of AI-specific professional indemnity exclusions all point to the same conclusion. Acceptable-use policies are necessary, but they are not sufficient. The question is no longer whether professionals should use AI, but whether the infrastructure governing that use can withstand regulatory scrutiny and cross-examination.

Why are acceptable-use policies not enough?

The professional services industry has responded to AI risk with the tool it knows best: policy documents. Firms have drafted acceptable-use policies, circulated guidance notes and run awareness sessions. These are necessary starting points, but they address behaviour rather than infrastructure.

The gap between policy and enforcement is where liability lives. Thomson Reuters’ 2026 Future of Professionals Report found that 34% of professionals use AI tools their organisation has not sanctioned. Among firms with a named AI strategy, 35% say day-to-day practice does not match it. Policy alone cannot close a gap that wide. When a regulator, tribunal or opposing counsel asks how a professional’s AI-assisted work product was governed, a PDF in a shared drive is not a defensible answer.

The SRA’s Warning Notice, published on 17 August 2026, makes the enforcement position explicit. The regulator received 42 reports of potential AI misuse between July 2025 and July 2026, covering fabricated case citations, inadequate supervision and confidentiality breaches. The notice states that failure to comply risks disciplinary action. Crucially, it does not prescribe specific tools or technologies. It requires outcomes: accurate work, proper supervision and protected confidentiality. Achieving those outcomes at scale requires infrastructure, not just instructions.

What does the case law tell us about professional liability?

Courts have moved from surprise to sanction. The trajectory is steep. By mid-2026, a tracking database documented 1,598 court proceedings worldwide involving AI-fabricated content, with the rate accelerating to approximately eight new cases per day. Sanctions escalated from $5,000 in the 2023 Mata v. Avianca case to over $109,000 in combined penalties in Couvrette v. Wisnovsky by 2026. In Withers v. City of Aberdeen, a Mississippi federal judge cancelled a trial and suspended both lead attorneys for two years after finding that both sides had filed fabricated citations.

The duty to verify AI output is now absolute, non-delegable and actively enforced across multiple jurisdictions. The risk is not confined to solicitors drafting briefs. In Kohls v. Ellison, a federal court struck an expert declaration drafted with ChatGPT after finding that cited academic articles did not exist. The ruling confirmed that an expert report drafted with AI carries the same verification duty as a legal brief. For expert witnesses, quantity surveyors and consulting engineers who produce opinion evidence, the implications are direct: every AI-assisted work product that enters a tribunal is subject to the same standard of professional accountability.

In England and Wales, the cases of R (Ayinde) v Haringey LBC [2025] EWHC 1383, UK v SSHD [2026] UKUT 81 (IAC) and BCP v A Mother [2026] EWFC 71 (B) have established that reliance on AI is not a suitable defence. The court in Ayinde noted that referral to the relevant professional regulator is likely to be appropriate whenever a lawyer places false citations before the court.

What does governance infrastructure actually require?

If policy documents are the “what to do” layer, governance infrastructure is the “how it is enforced” layer. For AI-assisted professional work to be defensible, six capabilities must be built into the technology itself, not bolted on through human process alone.

Identity and access. Every interaction with an AI system must be attributable to a named, authenticated professional. Anonymous or shared access makes it impossible to establish who produced, reviewed or approved an AI-assisted output.

Data isolation. Client data entered into an AI system must never be accessible to other clients, other matters or the model provider. The SRA’s Warning Notice specifically addresses confidentiality risks when professionals use public AI tools. Isolation is not a feature; it is a prerequisite for professional privilege.

Data residency. Regulated professionals in many jurisdictions face obligations about where data is processed and stored. The EU AI Act, UK GDPR and sector-specific regulations all impose residency requirements that generic AI tools cannot satisfy.

Adversarial testing. AI outputs used in professional practice must be stress-tested before they reach a client or a court. Ecsper provides AI governance infrastructure for regulated professional services, including challenge mechanisms that test AI-assisted conclusions against contrary positions before a professional relies on them.

Audit trails. Every AI interaction, every prompt, every output and every human review decision must be recorded in a tamper-evident log. When a tribunal asks how a particular conclusion was reached, the professional must be able to produce the complete chain of reasoning, including the AI’s contribution and the human’s verification.

Human authority. The professional must retain final authority over every output. AI systems must augment professional judgement, never replace it. This principle, which the SRA, the courts and the EU AI Act all reinforce, must be enforced architecturally, not merely stated in policy.

How is the regulatory landscape reinforcing these requirements?

The regulatory convergence is remarkable. Three distinct regulatory programmes, each developed independently, have arrived at the same structural requirements.

The SRA Warning Notice (17 August 2026) focuses on two risks: AI hallucinations in court documents and confidentiality breaches through public AI tools. It imposes outcome-based obligations on firms and individuals, leaving the method of compliance to the profession.

The EU AI Act (Regulation (EU) 2024/1689, as amended by the Digital Omnibus (EU) 2026/1744) became broadly applicable on 2 August 2026. Its transparency obligations, AI literacy requirements and GPAI enforcement powers are now in force. High-risk obligations for stand-alone systems follow in December 2027. The Act applies to any organisation placing AI systems on the EU market or deploying them in a professional context within the EU, regardless of where the organisation is based.

Italy’s national AI framework (Law No. 132/2025, effective from October 2025) goes further, explicitly applying to “intellectual professions” including lawyers, accountants, architects and engineers. It requires disclosure to clients when AI has been used in producing professional output and mandates human-oversight certifications for certain categories of AI use. It is the first national law to impose AI governance obligations specifically on regulated professionals.

The direction is consistent: professional accountability does not transfer to the technology. Firms that treat AI governance as an IT procurement decision rather than a professional standards obligation will find themselves exposed.

What does the insurance market signal?

The insurance market is a leading indicator of where liability will settle. Two developments deserve attention.

First, a distinction is emerging between “silent” AI cover (existing professional indemnity policies that have not been amended for AI, leaving coverage uncertain) and “affirmative” AI cover (separate products or endorsements that explicitly cover AI-related claims, typically conditioned on documented governance practices). Affirmative cover requires evidence that the firm governs its AI use. Firms without that evidence face a coverage gap that no amount of premium can close.

Second, the volume of litigation is accelerating. One analysis documented a 978% increase in generative AI-related lawsuits between 2021 and 2025. The first publicly reported professional indemnity claim denial citing an AI exclusion has not yet landed, but the market expects it. When it does, renewal questionnaires will require firms to demonstrate AI governance infrastructure, not just policy documents.

For firms that want to check their governance exposure, the question to ask is: can we produce, on demand, a complete audit trail showing how AI was used, who supervised it, and what verification was performed?

What should regulated professionals do now?

Start with infrastructure, not policy. Three steps matter most.

First, govern the gateway. Every AI interaction in the firm should route through a single, governed access point. No direct access to consumer AI tools for client work. No shadow AI. The Thomson Reuters research finding that 34% of professionals use unsanctioned tools is a governance failure, not an employee behaviour problem. The infrastructure must make the governed path the easiest path.

Second, build the record. Every AI-assisted work product must carry a provenance record: what was asked, what was returned, who reviewed it and what was changed. This is not optional documentation; it is the evidence that a tribunal, regulator or insurer will request.

Third, test before you trust. AI outputs used in professional practice must be challenged before they are relied upon. This means adversarial testing against contrary positions, verification of citations and authorities, and confirmation that the output reflects the professional’s own analysis rather than an unverified model prediction. Consumer AI tools do not provide this. Governed professional infrastructure does.

The professional’s duty has not changed. The tools have. The infrastructure must catch up.

See the full tracker: over 2,000 documented cases of AI misuse in court proceedings. Ecsper AI Risk Intelligence

Sources

  1. SRA Warning Notice: Misuse of AI – Accessed 7 Sep 2026
  2. Thomson Reuters Future of Professionals Report 2026 – Accessed 7 Sep 2026
  3. AI Hallucinations in Law: Court Cases Tracker – Accessed 7 Sep 2026
  4. Norton Rose Fulbright: AI in Litigation, Update on Gen AI Sanctions in 2026 – Accessed 7 Sep 2026
  5. 4 New Square Chambers: SRA Warning Notice on Misuse of AI – Accessed 7 Sep 2026
  6. AI Liability Insurance for Law Firms: A Primary-Source Guide – Accessed 7 Sep 2026
  7. EU AI Act, Regulation (EU) 2024/1689 as amended by Digital Omnibus (EU) 2026/1744 – Accessed 7 Sep 2026
  8. Italy Law No. 132/2025 (AI framework for intellectual professions) – Accessed 7 Sep 2026
  9. Gardiner, D. (2026) "'The AI said so' is not a defence", IR Global / Wilson Wells – Accessed 7 Sep 2026

See how Ecsper governs your practice

Book a 30-minute session to see how Ecsper helps your practice. Or check your exposure first.