Nothing in the Legal Services Act 2007 stops a firm putting an AI on its enquiry line. Giving legal advice is not one of the six reserved legal activities, and an agent that takes a name, a number and a broad matter type is nowhere near the ones that are. The permission question passes easily, which is why it is the wrong question to spend the meeting on.
The check that decides this is confidentiality. The SRA Glossary counts prospective clients as clients, so paragraph 6.3 attaches from the caller's first sentence, before any retainer exists. On 17 August 2026 the SRA published a warning notice on the misuse of AI saying that putting confidential client information into tools without appropriate safeguards will likely breach confidentiality and that privilege may be permanently waived and unable to be recovered
. That is the sentence to take into a procurement conversation.
What follows is the checklist in the order a firm meets it: scope, reserved activities, confidentiality, conflicts, money laundering due diligence, complaints, and what the caller has to be told. Rule numbers and dates throughout, each linked to the instrument. This is not legal advice, and two points below are areas where a firm should take its own.
- 01Where the line sits on a first call
- 02Reserved activities: the easy check
- 03Confidentiality arrives before the retainer
- 04The conflict check nobody designs for
- 05Where MLR due diligence starts
- 06Complaints, and a clock that may not run
- 07What the caller has to be told
- 08Two things to stop citing
- 09Six questions, in writing
- 10Dates that will date this post
- An admin-only enquiry line is not a reserved legal activity. Giving legal advice is expressly outside the six activities in LSA 2007 s.12(1), so the authorisation regime is not engaged by the agent itself.
- The firm keeps the accountability. SRA Code for Firms paragraph 2.3:
You remain accountable for compliance with the SRA's regulatory arrangements where your work is carried out through others, including your managers and those you employ or contract with.
- Confidentiality attaches from the first call. The SRA Glossary defines client to include prospective clients, so paragraph 6.3 covers the caller who has not engaged you. The SRA's 17 August 2026 warning notice is explicit about the privilege consequence, and warns that failing to have proper regard to it risks disciplinary action.
- Taking a name and a number does not trigger customer due diligence. MLR 2017 reg 4(1) requires an expected
element of duration
before a business relationship exists. Two of the four triggers in reg 27(1) can still fire on any call. - The Legal Ombudsman clock is one year, one year and six months under the Scheme Rules effective 1 April 2023, and the six-month limb only runs if your final response signposts LeO prominently.
Where the line sits on a first call
Every check below reduces to one design decision: what the agent is allowed to do, and what it is allowed to write down. Get that on paper before you look at a demo, because it is also the document paragraph 2.1 of the Firms Code expects you to have.
The safe side is administrative. The agent captures what the caller said, sorts it by the topic the caller stated, and hands it to a human. The unsafe side is anything that involves the agent forming a view: whether a matter is urgent, whether a caller has a case, whether the firm will act. Seven rows cover almost every specification argument we have had with firms.
Each item in the right-hand column changes which regime applies to the call. That is why the scope document has to exist before procurement, and why paragraph 2.1 expects you to have one.
Reserved activities: the check that passes easily
Section 12(1) of the Legal Services Act 2007 reserves six activities, defined in Schedule 2. Under section 14 it is a criminal offence to carry one on without authorisation or exemption. An enquiry line that gives no advice and no legal information touches none of them.
includes… providing legal advice or assistance in connection with the application of the law or with any form of resolution of legal disputes. That absence does not amount to permission. Advice on a call would still engage competence under SRA paragraph 3.2, your professional indemnity position and the confidentiality duty below, which is the argument for keeping it out of scope rather than relying on it being unreserved.
Confidentiality arrives before the retainer does
This is the live risk, and it is the one the regulator has now written about directly. The SRA's warning notice of 17 August 2026 names two areas of concern: false information in documents produced through AI misuse, and confidential client information entered into tools that lack appropriate safeguards, risking potential breaches of confidentiality and wider data protection requirements
. On privilege it is blunt:
"Using AI tools in this way will likely breach client confidentiality and as a result, legal professional privilege may be permanently waived and unable to be recovered."
SRA, Warning notice: Misuse of AI, 17 August 2026
The notice adds that a firm failing to have proper regard to it is at risk of disciplinary action
. Volume gives some sense of the SRA's attention: the regulator received 42 reports related to potential AI misuse between July 2025 and July 2026, with investigations covering inaccurate legal citations, supervision and confidentiality.
Two points of order about the duty itself. Paragraph 6.3 of the Solicitors Code requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents
, and the SRA Glossary extends client to prospective clients. So an enquiry call is covered. Privilege is narrower and worth not overclaiming: legal advice privilege needs a lawyer and client communicating for the dominant purpose of giving or obtaining advice, which a purely administrative capture may not attract at all. Three Rivers (No 5) [2003] EWCA Civ 474 and (No 6) [2004] UKHL 48 remain the foundation, and the scope of intra-client-group communications is being re-litigated after Aabar Holdings v Glencore (2024). The information is confidential either way, and it may become privileged the moment advice is sought.
Which is where the vendor comes in. The task moves down the chain. The accountability does not.
The Firms Code has no outsourcing rule as such. The obligation lives in paragraph 2.1 on governance and controls, paragraph 2.3 on work carried out through others, and paragraph 3.3(b) on information held by third parties being available for SRA inspection.
Worth noting that the SRA saw this use case coming. Its Risk Outlook on AI in the legal market, dated 20 November 2023, gives capturing client information before a first consultation as an example use, lists administrative chatbots, and flags accuracy, bias and accountability as the risks. Treat that report as context and the 2026 notice as the operative position.
The conflict check nobody designs for
Paragraph 6.1 of the Solicitors Code: You do not act if there is an own interest conflict or a significant risk of such a conflict.
Paragraph 6.2 is the equivalent for client conflicts. Both bite before you act, so the check has to clear before instructions are accepted.
The failure mode is quiet. An agent that helpfully asks who the other side is, and gets an answer, has put adverse-party information into the firm's hands before anyone could decline it. Under paragraph 6.5 the firm may then hold confidential information that is material to a matter, and may be unable to act for either party. No rule was broken by the software. The firm simply lost the option.
- Caller's name
- Callback number and preferred time
- Broad matter category, in the caller's words
- Whether they are an existing client
- How they found the firm
- The opponent's name or organisation
- Matter specifics and factual background
- Documents, dates and figures
- Anything the caller offers about the other side
- Anything that reads as instructions
An agent cannot un-hear a name. If a caller volunteers the other side unprompted, the fix is a script that interrupts and routes the call. There should be no field for it to land in.
Where money laundering due diligence starts
Firms ask whether an AI answering the phone drags customer due diligence forward to the first call. On the text of the regulations, no, with two live exceptions.
Regulation 27(1) of the Money Laundering Regulations 2017 lists four triggers. The first two are events an enquiry call is not. The other two are states of mind, and they can arrive at any point in a conversation.
which… (a) arises out of the business of the relevant person, and (b) is expected by the relevant person, at the time when contact is established, to have an element of duration.A one-off information call with no expectation of an ongoing engagement does not meet it. An agent that starts confirming the firm will take the matter on can create the expectation that does.
Reg 30(2) requires identity verification before the relationship is established. Reg 30(3) allows completion during establishment only where it is necessary not to interrupt the normal conduct of business and there is little risk. The SRA puts it plainly: verify as soon as possible after your first contact with them and before establishing a business relationship
. The threshold in reg 27(2) moved from €15,000 to £12,000 on 30 June 2026 under SI 2026/621.
Two things follow for a call flow. The agent should not be the thing that decides the firm has taken someone on, and it should be able to flag a call that raises suspicion rather than booking it in smoothly. Note also that scope matters here: reg 12(1) catches legal work only when the firm participates in financial or real property transactions of the listed kinds, so much advice-only and litigation work sits outside the Regulations entirely.
Complaints, and a clock that may not be running
The Legal Ombudsman changed its time limits on 1 April 2023, and the current Scheme Rules replaced the old six years and three years with something much shorter. Rules 4.4 and 4.5: a complaint must reach LeO no later than one year from the act or omission, or one year from when the complainant should reasonably have realised there was cause for complaint, and within six months of the firm's final written response.
included prominentlyin the final written response. Where that information is missing, LeO can accept the complaint outside the time limit. A final response that does not signpost properly does not start the clock, and LeO now applies a
fair and reasonabletest to out-of-time complaints rather than the older exceptional-circumstances test.
SRA Code paragraph 8.3 requires clients to be told in writing at the time of engagement about their right to complain to LeO and when they may do so. Paragraph 8.4 requires the same information, plus the time frame and full contact details, if a complaint is unresolved within 8 weeks following the making of a complaint
.
There is a jurisdiction point that touches the agent's script. LeO does not require the complainant to be a client. Rules 2.8(a) and (d) cover services the authorised person provided to the complainant, or offered, or refused to provide, to the complainant
. A purely informational first call from a non-client creates no complaints-handling obligation. An agent that makes a binding service offer, or a refusal, can bring that caller inside the scheme. Design it so it does neither.
As to whether any of this argues for an AI at all, the honest answer is that the available data does not settle it. LeO's 2025/26 complaints data shows what its caseload is made of, and communication and delay dominate. It measures complaints about legal services generally, not about phone answering, and it does not show that automating first contact reduces them.
This describes what LeO's caseload is made of. The fair claim is that responsiveness failures are the largest single category in front of the Ombudsman. The data does not show that AI reduces complaints. We also looked for a primary dataset on missed calls or call abandonment specific to UK legal services and found none, which is why no such figure appears in this post.
What the caller has to be told, and when
Two duties and one soft expectation, all discharged in the first fifteen seconds of the call. UK GDPR Articles 13 and 14 require privacy information at the point of collection, which means before recording begins rather than after. The ICO's transparency guidance for AI systems asks that appropriate and timely privacy information is provided to people to ensure they are sufficiently informed how their personal information is processed by AI systems
.
On telling callers they are speaking to an AI, there is no UK statute that says you must. The ICO's transparency principle points that way, and Article 50 of the EU AI Act, applicable from 2 August 2026, requires it for systems intended to interact directly with people. If your callers include anyone in the EU, treat it as mandatory. If they do not, it is still the sentence that stops a caller feeling misled three minutes in.
Two more data-protection points worth pinning down before go-live. Callers to a law firm routinely volunteer health and criminal offence data, which needs an Article 9 condition and a DPA 2018 Schedule 1 condition. And a system that merely routes calls is unlikely to make an Article 22A decision, while one that declines or prioritises callers might, which is now governed by Articles 22A to 22D rather than the old Article 22.
PECR note: regulations 19 and 21 are drafted around making automated calls for direct marketing, so they bear on outbound campaigns rather than on an inbound enquiry line. Keeping the agent inbound keeps PECR out of the analysis.
Two things to stop citing
Both appear in supplier compliance packs and in briefs we have been sent. Neither survives a look at the source.
"SRA Code for Firms paragraph 5.3 governs outsourcing."
Section 5 of the current Firms Code is client money and assets. There is no outsourcing rule at 5.3. The pre-2019 Code dealt with outsourcing expressly, at outcome O(7.10), and the current outcomes-based Code folds it into accountability and systems instead. Cite paragraphs 2.1, 2.3 and 3.3(b). A supplier quoting 5.3 at you has copied it from something written before 2019.
"LSAG's 2021 anti-money-laundering guidance for the legal sector."
The current edition is LSAG 2025, HM Treasury approved, taking effect 23 April 2025. It supersedes the 2021 guidance and the 2023 update. If your AML procedures reference the older version, that is a document-control problem worth fixing at the same time as this project.
Six questions to put to a supplier in writing
Ask for written answers. A demo settles none of these. Each question maps to a rule above, and paragraph 3.3(b) means you may need to produce the answers to the SRA later.
Where does call content go, and which sub-processors touch it?
Name the model providers and the hosting region. Article 28(4) makes your processor fully liable for its own supply chain, which does nothing for your confidentiality position if the chain is undisclosed.
Is call content used to train any model, and how is it segregated?
This is the specific exposure the SRA's 17 August 2026 notice describes, including the possibility of permanent privilege waiver. Get the answer in the contract, not on a web page.
Show me the Article 28 processing terms and the completed DPIA.
Article 28(3) terms are mandatory. A DPIA before go-live is the defensible baseline for a new technology processing this kind of data.
Which fields can the agent capture, and can I remove one?
Test this against Fig. 4. If the opponent's name cannot be switched off, the product is not built for a law firm.
What does the agent refuse to do, in its own words?
Ask for the refusal script verbatim. It should decline legal advice, decline instructions, and offer a human without being asked twice.
Can the SRA see what you hold on my behalf?
Paragraph 3.3(b) requires third-party-held information critical to your legal services to be available for SRA inspection. Put an access clause in the agreement.
Alongside those, ask for evidence against the NCSC Cloud Security Principles, plus Cyber Essentials Plus or ISO/IEC 27001, and an IDTA or the UK Addendum to the EU SCCs for any US sub-processor. Magixis publishes its own answers to these on the trust page.
Dates that will date this post
Six instruments relevant to this decision changed between April 2023 and August 2026. Check each is still current before relying on anything above.
LeO Scheme Rules. Time limits become one year, one year and six months, replacing six years and three years. The out-of-time test becomes fair and reasonable.
SRA Codes of Conduct for Solicitors and for Firms, current versions in effect. Made by the SRA Board on 16 December 2024.
LSAG AML Guidance 2025 takes effect, HM Treasury approved, superseding the 2021 guidance and the 2023 update.
Data (Use and Access) Act 2025 main data-protection provisions commence under SI 2026/82. Article 22 is replaced by Articles 22A to 22D, a permission-plus-safeguards model.
New s.164A DPA 2018 takes effect: a duty to acknowledge data-protection complaints within 30 days.
SI 2026/621 amends MLR 2017. The occasional-transaction threshold in reg 27(2) becomes £12,000 and a new reg 34A is inserted.
EU AI Act Article 50 transparency obligations become applicable. Systems interacting directly with people must tell them so. A grace period to 2 December 2026 covers only machine-readable marking of generated content on systems already on the market.
SRA warning notice on the misuse of AI published. Confidential information in unsafeguarded tools, permanent privilege waiver, and a stated risk of disciplinary action.
One further item to watch: the ICO's guidance on AI and data protection is currently under review following the Data (Use and Access) Act, and its February 2026 early views on agentic AI stress that solely automated decisions with legal or similarly significant effects engage the Article 22 regime in its new form.
What this post does not do
It does not tell you whether your call flows clear reg 27, whether a given deployment makes an Article 22A significant decision, or whether privilege attaches to a particular enquiry. Those turn on facts we do not have, and in the case of the intra-client-group scope of legal advice privilege, on a question currently being re-litigated. It does not cover authorised firms regulated by the FCA, licensed bodies, or practice outside England and Wales. It is not legal advice, and the AML and automated decision-making points in particular are areas where a firm should take its own. What it does is quote the instruments and link each one, so a partner can read them in an evening.
FAQ
Is it legal for an AI to answer calls for a UK law firm?
Yes, on the current rules, provided the agent stays administrative. Giving legal advice is not a reserved legal activity under LSA 2007 s.12(1), and an enquiry line that takes a name, a number and a broad matter type engages none of the six reserved activities. The firm remains accountable for the agent under SRA Code for Firms paragraph 2.3, and confidentiality under paragraph 6.3 applies from the first call.
Does a first enquiry call trigger client due diligence?
Not by itself. MLR 2017 reg 27(1)(a) triggers CDD on establishing a business relationship, and reg 4(1) requires an expected element of duration at the time contact is established. Taking a name and a callback number does not meet that. Reg 27(1)(c) and (d), on suspicion and on doubt about information previously obtained, have no threshold and can apply to any call.
Can an AI take instructions from a client?
It should not. SRA Code for Solicitors paragraph 3.1 requires you to act only on instructions from the client or someone properly authorised, and accepting instructions is also the point at which the MLR business-relationship analysis and the conflict-check duty change. Keep instructions with a named human.
Does putting call content through an AI vendor waive privilege?
The SRA's warning notice of 17 August 2026 says that entering confidential client information into AI tools lacking appropriate safeguards will likely breach confidentiality and that privilege may be permanently waived and unable to be recovered
. Whether privilege attached to a specific enquiry is a separate question, since legal advice privilege needs a lawyer and client communicating for the dominant purpose of advice. The exposure is real enough that segregation, no model training on call content and a proper Article 28 contract should be conditions of purchase.
Do I have to tell callers they are speaking to an AI?
There is no UK statute requiring it. The ICO's transparency principle points that way, and EU AI Act Article 50 requires it from 2 August 2026 for systems intended to interact directly with people, so it is mandatory in practice if any of your callers are in the EU. Disclosure in the opening line is also the cheapest way to avoid a caller feeling misled.
Can a non-client complain to the Legal Ombudsman about a first call?
Possibly. LeO Scheme Rules 2.8(a) and (d) cover services provided to the complainant, or offered or refused to the complainant, and do not require the complainant to be a client. A purely informational call creates no complaints obligation. An agent that makes a binding offer or refusal of service can bring the caller inside the scheme, which is a reason to script neither.
What should the agent never capture before a conflict check?
The other side's name and any matter detail. Under SRA paragraphs 6.1, 6.2 and 6.5, holding confidential information material to a matter can leave the firm unable to act for either party. Keep capture to name, number, broad category and whether the caller is an existing client, then let a human clear the check.
Where that leaves a decision
An enquiry line that captures and routes is a straightforward piece of administration for most small firms, and the compliance work is finite: a written scope, an Article 28 contract with segregation and no training on call content, a DPIA, a disclosure script, and a conflict-safe capture list. The part that is not finite is the vendor relationship, because paragraph 2.3 keeps the accountability with the firm no matter how the contract is drafted.
If your firm's positioning rests on a partner answering the phone personally, this technology belongs on the out-of-hours number and nowhere else. And if a supplier cannot answer the six questions above in writing, the honest read is that they have not been asked before.
Magixis builds the AI receptionist for UK law firms described here, which is why this post is about paragraph 6.3 and reg 4(1) rather than call-handling benefits in general. If you want the adjacent problem, our post on AI lead routing for clinics and law firms covers where routing stops being administrative.
- SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs
- SRA Code of Conduct for Firms
- SRA Glossary
- SRA warning notice, Misuse of AI, 17 Aug 2026
- SRA news release, responsible use of AI
- SRA Risk Outlook, AI in the legal market, 2023
- SRA guidance, conflicts of interest
- SRA guidance, publishing complaints procedure
- SRA guidance, MLR 2017
- Legal Services Act 2007, s.12
- Legal Services Board, reserved legal activities
- LeO Scheme Rules, April 2023
- LeO guidance on the Scheme Rules
- LeO, 2025/26 complaints data and insight
- Office for Legal Complaints, annual report 2024/25
- MLR 2017, as amended · reg 27 · reg 4 · reg 30 · reg 12
- LSAG AML guidance 2025
- UK GDPR Art 13 · Art 28
- ICO, transparency in AI systems
- ICO, guidance on AI and data protection
- ICO, Data (Use and Access) Act 2025
- European Commission, EU AI Act Article 50
- NCSC Cloud Security Principles
- House of Commons Library, SN03762, on LeO jurisdiction
- LSB, Individual Legal Needs Survey 2023