Part of our guide: AI governance and risk
On 22 May 2026 the High Court handed down judgment in Cork v Smith [2026] EWHC 1199 (Ch), where a junior associate had cited a provision of the Insolvency Rules that does not exist. The firm was then required to send the judgment to the Solicitors Regulation Authority within two working days and agreed to pay the clients' additional costs.
That much reads like every other AI hallucination story of the past two years, and one detail makes it different, the detail every board should be looking at.
The AI flagged it. The model itself told the associate that it was unsure of the exact wording and advised checking the legislation directly. The warning was there in the output before anything reached the court, and nobody in the firm acted on it.
ICC Judge Mullen put the principle plainly: legal professionals bear ultimate responsibility for their work and cannot outsource the process of legal research or of legal reasoning to an AI.
The technology produced a false citation and then exposed its own uncertainty, and the supervision around it failed when nobody acted on the warning.
Why this reframes the governance question
Most AI governance effort in mid-market businesses goes into deciding whether a system is accurate enough to use, a procurement question largely settled by the time anyone deploys.
Cork v Smith points at the question underneath it, and that question is what happens next when the system tells you that it is uncertain. The details that matter are who reads the caveat, what they are required to do about it and how anyone would know afterwards whether they did.
In most businesses we look at, the caveat is displayed and nothing is required, so the model hedges, the human skims and the output goes out. There is no record that the hedge existed, so there is no way to demonstrate afterwards that anybody weighed it.
That is a control design problem (not an AI problem), and it is one your business already knows how to solve in other contexts. You would not accept a credit decision where the risk system flagged an exception and the operator had no defined response.
The courts are now the fastest-moving part of AI regulation
This is worth stating because it cuts against the usual framing.
Between May and August 2026 there was no EU AI Act enforcement action of any kind and no UK ICO enforcement involving AI. The AI Act's general obligations began applying on 2 August 2026, with transparency rules included, and the high-risk regime moved. The Digital Omnibus entered into force on 27 July 2026 and pushed Annex III high-risk obligations back to 2 December 2027.
Meanwhile the Court of Rome annulled Italy's flagship 15 million euro fine against OpenAI on jurisdictional grounds rather than merits, so Europe's only completed enforcement decision against a generative AI provider no longer stands.
If you have been waiting for a regulator to tell you what good looks like, the EU today has extensive AI law and very little completed AI enforcement.
The binding decisions are coming from elsewhere, and the Italian data protection authority has been active, fining a data broker two million euros over scraped training data. The same authority warned an employer over a tool that inferred staff emotional state from workplace messages, and the English courts have been busy with AI misuse by professionals. That work includes a case in July 2026 where an "AI hallucinations" excuse for doctored emails was rejected as deliberate manipulation. The rejection there drew a three-year civil restraint order and a referral to the Attorney General for possible contempt proceedings.
For a UK mid-market firm, your first AI incident is far more likely to arrive as a professional conduct problem, a client complaint or a court criticism than as a regulatory fine.
Where UK accountability actually sits
There is no dedicated senior manager function for AI, and the FCA has said it does not plan to introduce extra AI regulation, relying on existing frameworks instead.
What that means in practice is that AI lands inside arrangements you already have, and technology systems normally sit with SMF24, the Chief Operations function. Under the overall responsibility rule any use of AI falls within the scope of a senior manager's responsibilities whether or not it has been assigned. We wrote about the consequences of that in why AI accountability lands on the COO.
The Bank of England and FCA survey of UK financial services found that 84 per cent of firms had an accountable person for AI. Most of those firms reported three or more accountable persons or bodies, and accountability spread that thinly leaves decision rights and escalation unclear.
For listed companies there is a further date, and the Financial Reporting Council's Provision 29 applies to financial years beginning on or after 1 January 2026. The first declarations appear in reports published in 2027, and boards must declare the effectiveness of their material controls, covering operational and compliance controls as well as financial ones. AI is not named in the provision itself, so it falls in scope wherever the board judges the controls to be material. Auditors do not test that declaration and give no assurance on it, so the weight sits on the board's own judgement.
Designing the control that *Cork v Smith* would have needed
The useful thing about this case is that the required control is small and specific.
Treat model uncertainty as an exception, not as decoration. If a system expresses doubt, that is an event, so someone owns it, there is a defined response and the response is recorded. Most tools now surface confidence signals and most organisations discard them.
Define the verification step per use, not per tool. "Check the output" is not a control, and "Any statutory reference, case citation or figure that will leave the firm is verified against the primary source and the check is initialled" is a control. The difference between the two is whether a reviewer six months later can tell from the file that it happened.
Match supervision to the task, not to the technology. The peer-reviewed evidence is clear, and in Organization Science work inside the tasks AI handles well was completed faster and at higher quality. Outside that boundary AI users were 19 per cent less likely to produce a correct answer, and the boundary is real and task-specific, so the supervision has to be too.
Put the strongest supervision on your least experienced people. In the Quarterly Journal of Economics, AI assistance raised customer support resolution by 14 per cent on average, with the gains concentrated in novices. The most experienced staff saw minimal impact, and a junior gets the largest lift from AI while having the least basis for spotting when it is wrong. That combination is precisely the shape of Cork v Smith.
Keep the record. The reason the associate's firm had a bad day is that nothing existed to show anyone had considered whether the answer was right (not that the answer was wrong).
What we would do first
Start with an inventory, because you cannot supervise what you cannot list, and it needs every AI system touching a client, a regulated process or a material control. Each entry needs to carry its owner, its decision boundary, what it does when uncertain and who is required to respond.
Then take one high-consequence process and design the exception path end to end, working through the sequence of signal, owner, required action and evidence rather than a policy document.
Most businesses we work with cannot produce the inventory inside a fortnight, and that is the normal starting position rather than a criticism. It is a fair measure of how far governance sits behind adoption. The IBM study of 2,000 technology executives published in June 2026 found organisations averaging 54 AI agent incidents a year requiring human correction. Only 11 per cent said they were fully prepared for the scale of deployment coming and 77 per cent said adoption already outpaces their governance capability.
The associate in Cork v Smith was not reckless and was working quickly with a tool that was more confident-sounding than it was correct. The firm around them had not decided what to do when the tool said it was unsure, a governance design failure addressable with a defined verification step and a named owner once somebody owns it.
Building that layer is what a Grow engagement is for, and mapping where it needs to exist is the first job in a Breathe discovery sprint. If you cannot currently answer what happens when your AI says it is uncertain, that is the conversation to have.
Sources
- [Cork v Smith [2026] EWHC 1199 (Ch)](https://caselaw.nationalarchives.gov.uk/ewhc/ch/2026/1199)
- European Commission, AI Act regulatory framework
- FCA, AI Update
- Bank of England and FCA, AI in UK financial services 2024
- IBM, CIOs and CTOs face a growing AI control gap
- Dell'Acqua et al., Organization Science