Delivery

Questions partners actually ask

Straight answers, including the ones that are not flattering to us. Ordered by what a partner worries about first.

01Who makes the decisions, and what happens if it gets something wrong?

Your people make the decisions. Always.

The system never rates a client, never scores a risk and never writes a reason. A named person makes every judgement, against your firm's own criteria, and the record shows who decided and when. If anyone asks how a decision was reached at your firm, the answer is a person, and the record proves it.

When something is wrong, a fee earner sees every drafted output before it counts for anything, so a mistake is caught by the same person who would have caught it before. The system cannot approve a file, cannot decide a risk and cannot close a step on its own. When something breaks operationally, we operate it, so fixing it is our job and not another task on your staff.

02Is this AI, and how does that sit with the SRA warning notice?

Parts of it are, and it is worth using your regulator's own definition. The SRA describes AI as technology that operates with a degree of autonomy and produces outputs not explicitly determined in advance, and genAI as the subset that generates new text, code or images.

By that definition two parts of this qualify. Reading what is outstanding on a file against your checklist, and drafting the wording of a message to a client. Both sit behind a person at your firm who sees the message before it goes. The deciding is not AI at all. It is a named person at your firm, and nothing is rated, scored, ranked or reasoned by a machine, because the system was built so that it cannot be.

The notice

It was published on 17 August 2026 and applies to the use of AI in the provision of legal services by firms the SRA regulates. Its duties on governance, supervision and confidentiality reach any system your firm uses, including this one. We are not going to tell you we sit outside your regulator's scope. We sit inside it, and here is how each duty is met.

The two concerns the notice raises

The first is AI producing false or incorrect material, including invented citations, in legal work and before the court. This system does not research, does not advise, does not draft argument and does not write reasoning, so it cannot produce any of that. The second is confidential client information going into AI tools without proper safeguards. That one applies to us directly, and the notice sets out what to satisfy yourself about.

Confidentiality, taking the notice's four points in its own order

Client data stays in a secure environment. It is held in the United Kingdom and the European Union, in named services, and every processor is listed in our privacy notice.

It is not reached by unauthorised third parties. Access is limited to the named people operating your build, and we will not add a processor without telling you first.

It is not used to train AI models. That is written into the agreement as an express term rather than offered as a reassurance.

It is not kept longer than necessary. Retention is set by you and recorded before we start.

The notice also expects contractual, technical and organisational safeguards before client information enters an AI system. A data processing agreement is signed before any client data is touched, the processing sits in the services named above, and the people operating it are named.

Governance and supervision

The notice and the codes behind it put accountability on the supervisor rather than only on the person who used the tool, and Code 7.2 requires a solicitor to be able to justify his decisions and actions in order to demonstrate compliance. A supervisor can only do that with a record. Every request, every reminder, every document and every named decision is recorded as it happens, with who and when, and that record is produced for you rather than assembled by you when somebody asks.

Where responsibility sits

The SRA states plainly that using AI does not diminish or transfer your professional responsibilities, and that you remain accountable for the work and advice delivered to clients whether or not AI was used. That is the right position and we are not going to soften it.

Separately, this is how the system is built. It never rates a client, never scores a risk, never ranks a matter and never writes the reason for a decision. A named person at your firm makes every regulatory judgement, against your firm's own criteria, at a recorded time. Our other arm assesses other organisations' AI agents for a living, so where a machine is allowed to decide and where it is not was a settled question here before it became a headline.

What we are not claiming

The SRA sets the standards and does not prescribe how a firm must meet them, which is exactly why no software can carry your regulator's approval. Nobody holds such a thing, we do not claim it, and a supplier who suggests otherwise is describing something that does not exist. Your obligations remain yours. What we do is make them easier to evidence.

03What about regulators and standards beyond the SRA?

The SRA is your regulator and the answer above is about that. This one is about everything else that bears on building a system like this, because a firm should know whether its supplier has thought past the one regulator it answers to.

Data protection

The Information Commissioner reaches you directly, and the SRA's own notice points firms to the ICO's work on AI. You stay the controller of your client data and we act as your processor on your written instructions, under a data processing agreement signed before any client data is touched. Data stays in the United Kingdom and the European Union, it is never used to train a model, retention is set by you, and every processor is named. If anything went wrong you hear it from us quickly, with what happened and what we did about it.

The EU AI Act

For a firm serving clients in the United Kingdom it usually does not apply, and we are not going to imply otherwise in order to sound thorough. We built to its two central expectations anyway, because they are good design rather than a compliance exercise. A person stays in control of consequential decisions, and anyone affected can find out what the system did.

Recognised AI frameworks

The design draws on the NIST AI Risk Management Framework and on ISO 42001 where they apply. Draws on is the accurate phrase and we are not going to stretch it. There is no control by control mapping of your build to either standard, and we hold no certification against either.

What we can point at is concrete. Every agent we build sits in a fixed band that decides what it is allowed to do. The top band never produces a regulatory judgement of any kind. The band below it can recommend, and a named person approves before anything counts. Only low consequence actions run on their own. Everything any of them does is recorded as it happens.

Where the discipline came from

This was built by someone who spent fifteen years putting risk and control frameworks into banks and insurers under FCA and PRA supervision. Neither regulator has anything to do with your firm and we are not suggesting they do. The point is the standard the design was held to. A change is evidenced, an approval is named, and a record is produced as the work happens rather than reconstructed afterwards.

The wider risks nobody asks about

The SRA's own research on AI in the legal market names bias, opacity, cyber security and uncertainty over accountability alongside accuracy and confidentiality. Those are the questions we would put to any AI supplier, so we expect you to put them to us.

One rule sits above all of it. We never assess what we build. If we build for you, we are not the ones who come back and validate it, and you should expect that separation from any supplier who does both.

04Where does our client data go, how long is it kept, and what happens if we leave?

It stays in the United Kingdom and the European Union. It is never used to train anyone's model. The processors we use are named in our privacy notice and we will not add one without telling you.

Retention is set by you and written into the agreement before we start.

The record belongs to you. If we part company it leaves with you in a form you can read without us, because a record you cannot take with you is not really yours.

05Do we have to change our systems, and how much of our time does it take?

No, and less than you expect.

This sits on top of what you already run. We build around how your firm opens a file rather than asking your people to work a new way, and your templates and your wording stay yours. If a supplier needs you to change your systems before their product works, that cost is yours and it is usually larger than the product.

Your side of the build is one conversation about how your firm opens a file, then we build it, show you it running, and adjust it. Measured in a conversation or two rather than weeks. If it needs more of your time than that, we have designed it wrong.

06What does it cost, and are we tied in?

Setup is published from two and a half thousand pounds, then a monthly fee from twelve hundred and fifty. The monthly fee is set by which job it does and never by how many files you open, so a good month never costs you more than a quiet one. Both figures are quoted in writing before you commit to anything, and there is a sixty day exit if it does not earn its place.

It is a from figure because firms differ and we will not price work we have not seen. You price your own matters the same way. Once we have looked at how your firm opens a file, both figures are fixed in writing and they do not move afterwards.

You are not tied in. Sixty days' notice and you are out, there is no minimum term and no exit fee, and the record goes with you.

07What does it actually do, and which part of the work does it cover?

It takes over the chasing. A file opens, the system reads what is outstanding against your own checklist, asks the client for it in your firm's own words, and keeps asking until it arrives. Every request, every reminder and every document is logged as it happens, and the file is then handed to a named fee earner to sign off. Nothing is replaced. Your case management system stays exactly where it is.

Client onboarding first, because that is where the unbilled hours sit. The client file and then billing and collections follow. We would rather run one job properly than claim to run all three.

08Are you replacing our staff?

No. Nobody loses work they bill for. They lose the work nobody pays them for.

In my experience of putting controls into regulated firms, that is the argument that wins the room, because the person doing the chasing wants it gone more than the partner does.

09Who else uses it, and are you insured?

We are taking the first three firms now, so the honest answer today is nobody yet. You would be early, which is why the first three pay less for the build and why the only thing we ask in return is your name on the case study once it has worked. If you would rather wait until there are references, that is a reasonable position and we will not press you.

On cover, it is arranged before any engagement begins and the certificate comes with the engagement pack. A walkthrough carries no client data and no advice, so there is nothing to indemnify at that stage.

10How would we know it is working?

Every month you get a plain report. Chases sent, documents recovered, files carried to sign off, and the hours that work would have taken. The hours figure uses your own assumption about what an hour of that work costs you, agreed in writing before we start. Our count, your rate. The number stays arithmetic rather than a claim, which is why it is still standing when you look at it six months later.

If your question is not here, ask it. A written answer comes back the same working day, and there is a thirty minute walkthrough at The Build if you would rather see it running.