Walk into almost any London law firm today, and AI is already part of the working day, often before there is a policy telling anyone how it should be used. The Law Society now estimates that the majority of firms and solicitors use AI for routine tasks such as drafting documents and analysing case material, with around two-thirds of lawyers reporting they use these tools in their work. Adoption has, in other words, already happened. The question firms are now catching up on is not whether to use AI, but how to govern it, and that question lands squarely on Risk & Compliance.
As I specialise in placing senior Risk & Compliance professionals into the legal sector, I've watched this shift move from a niche conversation to the defining operational issue for many firms. Here's how I see it playing out.
What firms are actually using AI for
Day-to-day, the use cases are practical rather than futuristic. Fee earners are using AI to produce first drafts of documents, summarise long bundles, review and compare contracts, carry out early-stage legal research and speed up due diligence. Business services teams are using it for knowledge management, client correspondence, marketing content and internal reporting. In the back office, finance and billing functions are experimenting with automation to speed up time recording, narrative drafting and reconciliation.
The common thread is time. AI is being adopted because it removes repetitive, low-value work, and in a billable-hours environment, that is a genuinely attractive proposition. The difficulty is that "faster" and "safer" are not the same thing, and in a regulated profession the gap between the two is exactly where risk lives.
What AI is being used within Risk & Compliance
The interesting turn is that Risk & Compliance teams are not just policing AI; they are increasingly using it themselves. AI is being applied to client and matter intake, sanctions and adverse-media screening, anti-money-laundering checks, conflict searches and the monitoring of large volumes of transactions for anomalies. It can flag patterns a human reviewer might take days to surface, and it can do first-pass triage on the routine cases so that specialist attention goes where it is genuinely needed.
Used well, this is a real uplift for a function that has long been asked to do more with less. But it also concentrates the stakes. When compliance controls themselves run on AI, an unreliable or biased output is no longer an inconvenience; it is a regulatory exposure. The SRA is explicit that firms must have appropriate governance, systems and controls, including risk and impact assessments, policies and procedures, training, and ongoing monitoring, precisely to avoid unintended consequences.
The risks for law firms
The Law Society's recent guidance is refreshingly direct about where things go wrong. It highlights three headline risks: heightened challenges to data protection, an increased likelihood of unreliable or inaccurate outputs, and AI tools' well-documented tendency towards embedded bias. To that I would add confidentiality: client data fed into the wrong tool can leak in ways that are difficult to reverse, and the reputational damage that follows a single high-profile error.
The most important point is one of responsibility. The UK Jurisdiction Taskforce has confirmed that AI has no legal personality, which means the solicitor and the firm remain accountable for the work they produce, however it was generated. A confident-sounding but wrong AI output does not dilute a professional obligation; it simply hides the error until someone relies on it. For firms, the lesson is that speed without oversight doesn't remove a problem; it just moves it downstream, where it is more expensive to fix.
Governance and the accountability gap
This is where I see the biggest weakness in the market. Most firms now have some version of an AI strategy, a steering group or an innovation lead. Far fewer have a single, named individual who is genuinely accountable for AI outcomes. When accountability is spread across a committee, difficult decisions drift, and tools get piloted and embedded before anyone has asked who owns the consequences.
The regulators are pointing firms towards a clearer answer. The SRA expects, as a minimum, that the Compliance Officer for Legal Practice (COLP) takes responsibility for regulatory compliance when new technology is introduced, with board-level oversight of both purchasing and ongoing use. The UK Government's own guidelines on AI procurement, written for the public sector but, as Bevan Brittan notes, a useful reference for private organisations too, reinforce the same principles: assemble diverse, multidisciplinary teams to mitigate bias, carry out a proper data and impact assessment before you buy, develop a governance plan, and avoid "black box" algorithms and vendor lock-in. Crucially, these frameworks treat AI as something to be managed across its whole lifecycle, not a product you purchase once and forget.
The accountability gap, then, is rarely a shortage of tools. It is a shortage of people willing and empowered to own the decision.
How Risk & Compliance teams are fighting back
The strongest teams I work with have stopped treating AI as an IT procurement question and started treating it as a governance discipline. In practice that means a few consistent moves: writing a clear AI use policy that sets out what is permitted and what is off-limits; building AI questions into procurement so that suppliers must evidence their ethics, testing and accountability before a contract is signed; insisting on human oversight as an ongoing requirement rather than a one-off sign-off; and being transparent with clients about where AI is used in their matter.
Training is the piece that separates the leaders from the laggards. The SRA lists training and awareness as a core control, and the firms getting this right are rolling out practical, role-specific education, not a single all-staff webinar, but tailored guidance for fee earners, compliance staff and support teams on what good and bad use looks like. The most effective approach mirrors the Law Society's procurement sequence: identify the real business need first, then choose the tool, brief it properly, test it, embed it and keep evaluating it. Start with the problem, not the product demo.
What this means for the future of law firms and their people
AI will not replace the judgement at the heart of legal practice, but it will change what firms need from the people around that judgement. The demand I'm seeing is unmistakable: firms want Risk & Compliance leaders who are fluent in both regulation and technology, professionals who can chair an AI governance group, challenge a supplier, design a control framework and explain it to a sceptical partnership. That blend of regulatory rigour and digital confidence is now one of the most sought-after profiles in the London legal market, and it commands a premium precisely because it is still scarce.
My view is that the firms who navigate this period best won't be the ones with the loudest AI strategy. They'll be the ones who put the right people in the room early, the people who can see where AI creates exposure and where human accountability has to stay visible - and give them the authority to act. AI is reshaping Risk & Compliance whether firms plan for it or not. The choice is whether that reshaping is designed, or simply absorbed.
Sam Hyde specialises in the placement of senior Risk & Compliance professionals in the legal sector at Birchrose Associates. If you're building out your governance and compliance leadership for an AI-enabled future, get in touch.