Why the SRA's warning on AI deepfakes is a wake-up call for legal sector verification
- legal
- Anti-Money Laundering (AML)
- Monitoring & Reporting
In the first two weeks of August 2026, two things happened that every property and legal firm in the UK should take seriously.
First, three of the world's largest AI companies (OpenAI, Anthropic, and Meta) disclosed that their models had, in controlled testing, escaped containment. In the Anthropic case, the model generated synthetic identities and used them to target real people with malicious emails, and did so successfully enough to pass a UK government test.
Second, the Solicitors Regulation Authority published its updated Sectoral Risk Assessment on AML, terrorist financing, proliferation financing and sanctions. In that update, the SRA moved AI-enabled impersonation and deepfakes from the horizon-risk category to the live-operational-concern category. In its own words, "AI-enabled impersonation techniques, including deepfakes, may increase the risk of identity fraud and misrepresentation during client onboarding and throughout the life of a matter. The risk may be greater where firms rely on remote verification methods or digital onboarding processes."
Those two events are related. What is happening inside AI research laboratories is what fraudsters will be attempting against regulated firms within months. The regulator has seen it, and it is now speaking directly to the sector about it.
The problem is not that the sector doesn't know. It's that the response hasn't caught up
The most striking pattern I see across our customer conversations is not that firms are unaware of the threat. It is that they know, and they are still relying on processes that predate the threat entirely.
Our own research, based on a survey of 1,000 UK decision-makers across regulated firms, tells that story bluntly. Across the legal sector, 54% of identity checks are still carried out by hand. 49% of firms report difficulty establishing who ultimately owns the businesses they act for. And yet, when asked about their compliance risk concerns, identity fraud is named more often than any other risk category combined.
The result is a sector that recognises the threat, quantifies the exposure, and continues to defend against it with tools designed for a slower generation of fraud. That is a difficult position to be in when the regulator has just signalled that it now sees AI-enabled fraud as a current threat rather than an emerging one.
What the SRA is actually saying
The updated Assessment does not just warn about AI. It anchors the response in specific regulatory reference points.
It confirms conveyancing as the highest inherent money laundering risk area in the legal sector. It points explicitly to the government's Digital Identity and Attributes Trust Framework (DIATF) as a relevant consideration for firms choosing digital verification providers. And it names source of funds as a central control across multiple high-risk areas, not just at the point of onboarding but throughout the life of a matter.
Read in combination, the SRA is doing something more consequential than warning about deepfakes. It is moving from principle to signal. It is now pointing at the specific standards and controls that firms are expected to align with.
The regulatory pressure is not just SRA
The SRA's Assessment sits within a wider regulatory tightening that firms should be tracking together, not in isolation.
Earlier this year, the National Economic Crime Centre issued an alert on the scale of AI's use in bypassing customer due diligence checks in the financial services sector. The Failure to Prevent Fraud offence, coming into force in 2027, introduces corporate criminal liability for organisations that cannot demonstrate they took reasonable steps to prevent fraud. The FCA is expected to become the single AML supervisor for legal firms by 2027, replacing the current OPBAS-led model. Further amendments to the Money Laundering Regulations are anticipated later this year.
Every one of those changes puts more responsibility on regulated firms to know exactly who they are dealing with, at scale, at pace, and with a defensible audit trail. And every one of them assumes a level of technological readiness that the 54% manual verification statistic suggests is not yet there.
Why manual processes are no longer defensible
Manual identity checks were built to catch a particular kind of fraud, in which a document, a name or a company structure looked wrong to a human eye. That model works when the fraud attempt is visible. It does not work when the fraud attempt is engineered by the same generation of AI tools that regulators are now warning about.
An AI-generated identity document can pass basic visual review. An AI-generated deepfake can convince a video verification call. A synthetic identity built from harvested data can pass individual field-level checks. These are not theoretical failure modes. They are the failure modes the SRA has just named.
Firms that continue to rely on fragmented or manual processes to catch financial crime will soon find it increasingly difficult to demonstrate a defensible compliance position to regulators. That is not just a compliance risk. It is a commercial one. Penalties, potential criminal sentences, and the lost trust that comes with facilitating illicit activity, even unknowingly, are real exposures. And under the Failure to Prevent Fraud offence, the "we didn't know" defence no longer works if you cannot show what reasonable steps you took.
What legal and property firms should do now
The updated Assessment does not require immediate operational change for firms that already have modern digital verification and source of funds workflows in place. For firms still relying on manual identity checks, or on digital providers that sit outside the DIATF framework, the priorities are clear.
Four steps worth taking seriously in the next quarter:
- Audit your current identity verification method against DIATF standards. If your provider is not on the register, understand what your defensible position looks like when a check is later reviewed.
- Stress-test your remote onboarding process for AI-enabled fraud. Deepfake and synthetic identity attempts are no longer edge cases. Understand how your current setup would perform against them, and what evidence trail exists if a check is later challenged.
- Review your source of funds process end-to-end. The SRA has moved this from a discrete check to a continuous control. Firms that treat it as a one-off will find themselves working through a substantial change.
- Bring your beneficial ownership process forward. With half the legal sector still reporting difficulty establishing ultimate beneficial ownership, this is where enforcement pressure will land first when it does.
The direction of travel is now unambiguous
The regulator has been consistent for years about where financial crime risk sits in the legal sector. What is new in August 2026 is that the tools of fraud have caught up with the theory, and the regulator has responded by pointing directly at the standards firms need to align with.
Firms that anticipated this shift will find themselves in a good position. Firms that assumed manual processes would remain acceptable will find the next twelve months operationally heavy. The gap between those two groups is now widening quickly. Where a firm sits on either side of it will be, in many cases, the single most important compliance decision of the year.
SmartSearch commentary on the SRA update was covered by the Law Gazette in August 2026.
See it in action
Get in touch with our team of experts today to discuss your business requirements and how SmartSearch can help with a bespoke solution.