Accountability Is Architected In, Not Delegated — Luminity Digital
Claude for Legal  ·  Companion Dispatch  ·  Regulatory Convergence  ·  July 2026
Companion Dispatch

Accountability Is Architected In, Not Delegated

The Solicitors Regulation Authority (SRA) said it as regulatory doctrine in 2023. Luminity names it as a design principle. Accountability for an AI-produced output cannot be delegated to the tool, the vendor, or the method that produced it — it has to be built into the system at both the build-time and output-time certification gates.

July 2026 Tom M. Gomez Luminity Digital 11 Min Read
This dispatch draws on Bjarne P. Tellmann’s commentary “Reorientation in the AI era must begin with the client” (Legal Futures, 2026) and on primary guidance published by the Solicitors Regulation Authority (SRA). What follows is an independent Luminity reading connecting that commentary and that guidance to our own analytical framework; it makes no claim to the underlying regulatory text or to Tellmann’s argument, and the JPMorgan COIN figures cited below are his sourcing, not independently verified by Luminity. This piece extends the architectural claim first made in Series 23, “Assurance by Architecture” — specifically Post 1, “Defensible Legal AI Is an Architecture, Not a Model”, and Post 3, “Governance Is a Byproduct, Not a Binder.”

Most commentary on AI and law firms is arguing about the wrong layer.

The live question isn’t which tools firms adopt or how deeply they integrate into a client’s stack. It’s who is accountable when the integrated system produces a wrong answer — and whether that accountability was designed in or assumed after the fact.

The market signal

Tellmann’s argument is structural: corporations are reorganizing around AI-native operating models — continuous learning, rapid experimentation, decision-making automated at scale — and law firms that keep operating through siloed teams and manual coordination are drifting out of step with the clients they serve [1]. His evidence is JPMorgan’s COIN contract-intelligence platform, which he reports cut contract review time by roughly 360,000 hours a year and saved the bank approximately $150 million in fraud-related losses in its first year of operation [1]. His prescription is integration: firms need to become interoperable nodes inside the client’s operational core, not external vendors billing by the hour.

That’s the diagnosis. What it opens is the next question: once a firm becomes that interoperable node, what makes the node itself defensible when something inside it goes wrong? That’s where this dispatch picks up.

The regulator already answered this

Tellmann names the symptom precisely — friction in “speed, accountability and the ability to translate legal insight into business action” [1]. The next layer down is what the SRA had already addressed, more than two years before his piece ran.

The SRA’s Risk Outlook on the use of artificial intelligence in the legal market states the position without qualification: firms remain responsible and accountable for the outputs of any AI they use, including outputs from third-party tools, and — the load-bearing line — “you cannot delegate accountability to an IT team or external provider: you must remain responsible for your firm’s activities” [2]. The same report requires firms to keep records showing where information or advice is based on AI-generated inferences, specifically so the firm can respond if that advice is later challenged [2].

Plenty of ink goes into telling firms to “stay accountable” for their AI. Almost none of it cites the one sentence where the SRA already told them what that means.

The Attestation Boundary

Luminity names this seam the Attestation Boundary — the certification event, present at both the deployment layer and the per-output layer, at which an AI-produced output becomes a representation a named, accountable party stands behind. This construct is Luminity’s analytical contribution; it is not drawn from the SRA’s guidance or from Tellmann’s commentary, though both independently confirm the structure it describes. Its output-time gate already has a US appellate anchor: Lnu v. Blanche turned on the same question the SRA is asking — whose signature stands behind the output — and reached it independently of any UK regulatory guidance [4]. Put compactly: the seam is fixed by who certifies an output, not by how the output was produced.

The applied precedent

This isn’t theoretical for the SRA. In May 2025 it authorized Garfield.law as England and Wales’s first AI-only law firm, and it attached conditions that are the output-time half of the Attestation Boundary made operational: the system cannot propose case law, as a guard against hallucination, and it cannot operate autonomously — client approval is required at each step [3]. A regulator, presented with a live agentic legal system, did not ask whether the firm had integrated well. It asked where the certification event sat, and it wrote the answer into the authorization.

That is the applied version of the claim this dispatch is making: integration is a workflow question the market is already answering. Certification is a liability question the regulator is already enforcing. They are not the same question, and a firm that solves only the first has not touched the second.

The US contrast

No single US regulator mirrors the SRA. The American Bar Association’s Formal Opinion 512 (2024) sets an advisory national baseline; enforcement sits with 35+ individual state bars, fragmented and inconsistent [5]. California’s State Bar is the exception moving toward binding force — proposed rule amendments folding AI obligations directly into the Rules of Professional Conduct, comment period closing May 4, 2026, not yet adopted [6].

Where the SRA authorizes and conditions, the US enforces after the fact, through courts. Mata v. Avianca and Lnu v. Blanche are sanctions and signature-liability rulings, not regulatory authorizations [7]. UK accountability is regulator-first; US accountability is court-first — a structural asymmetry worth naming plainly rather than papering over with a false parallel.

Where we pick up the script

Tellmann’s “interoperable node” is a real and useful description of where client-facing legal delivery is headed, and it’s the frame this dispatch builds on rather than around. A firm can integrate perfectly into a client’s data environment and decision cadence and still face the SRA’s question — who is standing behind this specific output, and can the firm produce the record showing why. Integration is the workflow half of the answer. Certification is the other half, and it’s the half we take up here.

The Hard Claim

Firms building toward deeper client integration without a named, accountable certification event at both build time and output time are not ahead of the regulatory curve — they are building on top of a gap the SRA closed on paper in 2023 and will close on individual firms in practice, through an investigation, a discovery dispute over an unverifiable AI-assisted work product, or a client risk committee that asks the six-question test and gets no answer.

Integration is necessary. It is not the structural property that makes the integrated system defensible. Certification is.

The next dispatch in this line takes up the build-time half of the boundary directly — what a firm’s skill-spec sign-off has to look like for the certification to hold up under exactly this kind of regulatory scrutiny.

Integration Is the Workflow Question. Certification Is the Liability Question. Luminity Architects for Both.

If you are navigating the accountability architecture behind your firm’s AI deployment and want a practitioner conversation, the calendar is open.

Start the conversation
Assurance by Architecture  ·  Series 23  ·  Companion Dispatch
Series 23  ·  Post 3 Governance Is a Byproduct, Not a Binder
Companion Dispatch  ·  Now Reading Accountability Is Architected In, Not Delegated
References & Sources

Share this:

Like this:

Like Loading…