Insights
Updated September 2026

EU AI Act: Which Legal AI Systems Are High-Risk?

Classify legal AI by its intended purpose and role under Article 6 and Annex III, then identify the applicable obligations and dates.

8 min read

General information, not legal advice. Legal position as of . Limitations in the Legal Notice

Review status: legal and language review by a named human reviewer is pending.

In this article

Substantive update

Regulation (EU) 2026/1744, the Digital Omnibus on AI, has amended the AI Act since 27 July 2026. The relevant Annex III high-risk duties apply from 2 December 2027; the corresponding Annex I product-related duties from 2 August 2028. Under Article 111(2), the Act applies to high-risk systems placed on the market or put into service before the relevant date only if their design changes significantly from that date; providers and deployers of high-risk systems intended for use by public authorities must comply by 2 August 2030 in any case. Article 50 transparency duties generally apply from 2 August 2026; Article 111(4) gives providers of generative systems placed on the market before that date until 2 December 2026 to meet Article 50(2). Two new Article 5 prohibitions apply from 2 December 2026 (see below).

Article 4 on AI literacy has applied since 2 February 2025, with two wordings. Until 26 July 2026 it required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff. Since 27 July 2026 it requires measures to support the development of AI literacy, and it does not require providers or deployers to guarantee any specific level of AI literacy of any individual. Check the specific provision, role and transition rather than one deadline for the whole Act. Consolidated Articles 4, 5, 111 and 113; Commission timeline.

Using AI in a law firm does not automatically make the system high-risk. Classification depends on intended purpose, the activity listed in the Act, and the role your organisation actually performs. Keep the AI Act assessment separate from data protection and professional secrecy.

Reliability and legal classification also need separate evidence. Dahl and colleagues' 2024 study documented hallucinations and susceptibility to incorrect premises in public-facing models tested on US case law. It supports source verification; it does not show that every legal AI tool is high-risk under the Act, and its results are not current error rates for all products or for Swiss law.

Establish territorial scope

Article 2 covers, among others, providers placing systems on the EU market, deployers established in the EU, and certain providers or deployers outside the EU where system output is used in the Union. Record which of these connections applies to the specific use, and any exclusion. An EU client or an EU-marketed product is a starting point for that check, not its conclusion.

Classify the intended use

Article 5 prohibits specified practices, subject to the conditions and exceptions in that article. High-risk classification follows Article 6 and Annex I or Annex III. Article 6(3) provides a limited route for certain Annex III systems that do not pose a significant risk, subject to its conditions; systems profiling natural persons remain high-risk. A human making the final decision does not by itself remove the classification.

Regulation (EU) 2026/1744 added two prohibitions that apply from 2 December 2026. Article 5(1)(ba) prohibits placing on the market, putting into service or using an AI system that generates or manipulates realistic images, video, audio or similar material showing an identifiable person's intimate parts, or an identifiable person engaged in sexually explicit activities, without that person's freely given, specific, informed, unambiguous and explicit consent to that generation or manipulation. Article 5(1)(bb) covers child sexual abuse material or performances within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU, subject to the national-law exception stated in that point. Under Article 5(1a), a provider is caught where that generation or manipulation is the system's intended purpose, or a reasonably foreseeable and reproducible outcome without significant technical modification and without adequate safeguards to prevent it; a deployer is caught when it uses a system for that purpose. For point (ba) only, Article 5(1b) provides that an AI system which manipulates material without increasing the exposure of depicted intimate parts or altering the nature of depicted sexually explicit activities does not constitute manipulation. Neither point contains an exception for labelled content, so an Article 50 disclosure does not make a prohibited practice lawful.

  • Employment systems may fall under Annex III point 4, including recruitment, candidate filtering and specified worker-management uses.
  • Annex III point 8(a) concerns systems intended for judicial authorities or on their behalf, and similar use in alternative dispute resolution. Ordinary private legal research or litigation advice is not automatically covered.
  • Annex III point 5 includes specified uses involving essential services, creditworthiness and life or health insurance. General financial advice is not synonymous with these categories.

Separate provider and deployer duties

Providers of high-risk systems have duties concerning risk management, technical documentation, conformity assessment and registration, as applicable. Articles 9, 11, 16, 43 and 49 address these areas. Registration is not governed by Article 51, which concerns classification of general-purpose AI models with systemic risk.

Article 4a, inserted by the same amendment, allows providers of high-risk systems exceptionally to process special categories of personal data to the extent strictly necessary for bias detection and correction under Article 10(2), points (f) and (g), subject to appropriate safeguards for fundamental rights and freedoms. It applies in addition to the GDPR and only where all six of its conditions are met: other data, including synthetic or anonymised data, cannot effectively achieve the purpose; the data is subject to technical limits on re-use and to state-of-the-art security and privacy-preserving measures, including pseudonymisation; access is strictly controlled, documented and limited to authorised persons bound by confidentiality; the data is not transmitted to, transferred to or otherwise accessed by other parties; it is deleted once the bias is corrected or its retention period ends, whichever comes first; and the record of processing explains why the processing was strictly necessary and why other data could not achieve that objective. Under Article 4a(2), deployers of high-risk systems and providers and deployers of other AI systems and models may process such data only where this is strictly necessary to detect and correct possible biases likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination prohibited under Union law, and where all the conditions and safeguards of paragraph 1 are applied. Article 4a(2) creates no obligation to carry out such bias detection and correction.

Deployers should examine Article 26: follow instructions, assign competent human oversight, monitor operation and keep the logs under their control. Article 27 requires a fundamental-rights impact assessment for specified deployers and uses, not every law firm. Rebranding, substantial modification or changed intended purpose may make a deployer a provider under Article 25. Document that role decision before assigning tasks to the vendor.

Transparency, explanations and Swiss obligations

Article 50 contains specific disclosure and machine-readable marking duties, with exceptions. Article 86 gives a right to an explanation for certain decisions based on Annex III high-risk systems that produce legal or similarly significant adverse effects; it is narrower than a general right to challenge every AI-assisted legal opinion.

Swiss data protection and professional secrecy require their own analysis of data, recipients, access and confidentiality. For lawyers, Article 13 of the Lawyers Act (BGFA) sets professional secrecy, unlimited in time, for everything clients entrust to them in their professional capacity, and requires them to ensure that their auxiliary staff preserve it. Article 321 of the Criminal Code makes disclosure of such secrets by lawyers and their auxiliaries a criminal offence. Under FADP Article 9, processing may be assigned to a processor only if no statutory or contractual duty of confidentiality prohibits the assignment. Swiss hosting alone does not settle these questions. Review contractual confidentiality, subprocessors, international disclosure, training reuse and access by matter. A private legal adviser remains responsible for reviewing material used in advice.

A practical preparation record

Record the classification decision

0/6

For retrieval-based tools, test whether source permissions carry through to retrieved passages and generated answers. Check cross-matter leakage, misleading citations and instructions embedded in source documents. Keep a manual fallback and record unresolved questions.

Key Takeaway

Classify the use and the operator role first. Then map each duty to its provision, date, evidence and responsible person.

Primary sources

Clarify how AI decisions are made

Connect business, HR, IT and risk through clear ownership and review routines.

You might also like

Need clearer footing for an AI decision?

Start with a focused conversation about a live AI use case, workflow bottleneck, training need, or governance gap.