The short version
An AI agent is set up to act on a matter: to answer correspondence, file documents or change records. Nobody reads what it does before it does it, and the work still goes out from the firm.
What it is
A chatbot answers, and a person decides what to do with the answer. An agent acts. The judicial guidance defines an AI agent as a programme that uses AI to "take actions to achieve its goals, based on the inputted information", and observes that "Some generative AI tools are designed to take actions" (Artificial Intelligence (AI): Guidance for Judicial Office Holders, 31 October 2025, section 2).
The error is removing the last point at which a person sees the work before it leaves. It is the forwarded answer with the person in the middle taken out.
The SRA's Risk Outlook report on AI, of 20 November 2023, named autonomy: "some AI systems can make decisions without the express intent or ongoing control of a human. This can make it harder to say who is responsible for the system's outputs." It adds: "As with any other technology or system in your firm, you will remain responsible and accountable for the outputs from AI you are using" (SRA).
The Code of Conduct speaks of supervising people. Paragraph 3.5 of the SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs reads: "Where you supervise or manage others providing legal services: (a) you remain accountable for the work carried out through them; and (b) you effectively supervise work being done for clients." Paragraph 3.6 requires you to ensure that "the individuals you manage are competent to carry out their role". Applying them to an agent's work is a question for advice on the facts.
For AI research, the Divisional Court has already drawn the comparison with delegation. In R (Ayinde) v London Borough of Haringey [2025] EWHC 1383 (Admin), the duty to check rests on lawyers who "rely on the work of others who have done so", which the court called "no different from the responsibility of a lawyer who relies on the work of a trainee solicitor" (paragraph 8, National Archives).
A sighting
Two vendors' own pages, as they read on 1 October 2026:
- Anthropic, Claude Code. Its page on permission modes says a permission mode "sets which actions Claude can take in a session without asking you first". In auto mode, "a second model, the classifier, reviews actions instead of you". The page warns that auto mode "reduces permission prompts but does not guarantee safety", and is for "tasks where you trust the general direction, not as a replacement for review on sensitive operations". The bypass permissions mode "disables permission prompts and safety checks so tool calls execute immediately" and "offers no protection against prompt injection or unintended actions". The page reserves it for "Isolated containers and VMs only"; it can only be turned on at launch, and administrators can block it.
- Microsoft, Copilot Studio. The event triggers overview, updated 9 September 2026, says that "event triggers allow your agent to act autonomously in response to the defined event occurring", and that once published the agent "reacts automatically each time its triggers are activated". Its guidance on autonomous agents advises: "For high-stakes tasks, keep a human in the loop. Configure the agent to request approval or confirmation from a person before executing actions that could be sensitive."
On both pages the human checkpoint is something to configure. Leaving it out is also a configuration.
The example below is made up to show the pattern. An agent watches the inbox for a group of debt recovery matters, acknowledges each letter and updates the case management system. On one matter the debtor's solicitors dispute the debt. The agent sends the standard acknowledgement, which restates the sum claimed and the date for payment, and marks the file as chased. The fee earner reads the letter a fortnight later.
Why it happens
The vendors present fewer interruptions as the benefit. Anthropic's table of modes says auto mode is best for "Long tasks, reducing prompt fatigue"; Microsoft says autonomy lets agents "handle time-sensitive or routine tasks". The person who sets up an agent need not be the one whose name is on the matter, and the setting that decides whether anyone looks first sits in a screen the fee earner may never open.
What to say back
"Which of its actions reach someone outside the firm, and where does a person see them before they go? If nowhere, who is supervising the work it does?"
Origin
- 20 November 2023. The SRA's Risk Outlook report names autonomy, and says firms stay responsible for AI outputs.
- 6 June 2025. Ayinde and Al-Haroun: the duty to check rests on lawyers who rely on the work of others (paragraph 8).
- 31 October 2025. The current judicial guidance defines an AI agent (section 2).
- Now. On 1 October 2026, Anthropic's documentation gave auto mode as Claude Code's starting mode for interactive terminal and VS Code sessions from v2.1.283, and Microsoft's described agents that act on events with no input from a user. No source cited here records a ruling in England and Wales on an agent that acted without review.