Regulatory update — June 2026
This article refers to an August 2026 deadline for the EU AI Act's high-risk (Annex III) obligations. Under the EU's Digital Omnibus — provisionally agreed in 2026 but not yet final law — that deadline is now deferred to 2 December 2027 (high-risk AI embedded in regulated products under Annex I is deferred further still). Treat the August 2026 dates referenced below as the original statutory timeline, and confirm the current status before relying on either date.
Law firms occupy an unusual position in the European AI regulatory landscape. They are simultaneously subject to AI regulation as deployers of AI tools and advisors on AI regulation for their clients. Getting the firm's own compliance right is not just a legal obligation — it is a reputational imperative.
Double compliance burden
Law firms face both GDPR and EU AI Act simultaneously — the only sector where this dual obligation is standard.
The overlap between GDPR and the EU AI Act
GDPR and the EU AI Act share significant conceptual ground — both are built around transparency, accountability, and data subject rights — but they operate on different axes:
Scroll horizontally to view all columns.
For a law firm deploying an AI tool that processes client personal data (which most do), both frameworks apply simultaneously.
Risk classification under the EU AI Act
The EU AI Act introduces a four-tier risk classification:
- Unacceptable risk — Prohibited outright (social scoring, real-time biometric surveillance)
- High risk — Requires conformity assessment, documentation, human oversight
- Limited risk — Transparency obligations only
- Minimal risk — No specific obligations
For most law firm AI use cases:
- AI-assisted legal research → likely limited risk (transparency obligations)
- AI in employment law matters → potentially high risk (employment and HR management is a listed high-risk category)
- Predictive litigation tools → likely high risk (administration of justice is listed)
- Contract drafting assistants → likely limited or minimal risk
High-risk AI systems used in the administration of justice require conformity assessment, documentation, and continuous human oversight.
Focus
GDPR: Personal data processing
EU AI Act: AI system risk classification
Trigger
GDPR: Any processing of personal data
EU AI Act: Using or providing an AI system
Key obligation
GDPR: Lawful basis, consent, data subject rights
EU AI Act: Risk classification, documentation, human oversight
Enforcement
GDPR: Up to €20M or 4% global turnover
EU AI Act: Up to €35M or 7% turnover (prohibited AI)
Impact assessment
GDPR: DPIA (Art. 35 GDPR)
EU AI Act: Conformity assessment for high-risk systems
Overlap area
GDPR: Transparency, accountability, record keeping, vendor contracts
EU AI Act: Transparency, accountability, record keeping, vendor contracts
Practical compliance steps for law firms
1. Maintain an AI inventory
Document every AI tool in use across the firm, including:
- Vendor and product name
- Use case and practice group
- Data processed (personal / sensitive / client confidential)
- Risk classification (self-assessed)
2. Update your client engagement terms
If you use AI tools in delivering client services, your engagement letters should:
- Disclose that AI tools may be used
- Specify the categories of AI use
- Confirm your human oversight procedures
3. Appoint an AI governance lead
Firms of any meaningful size should designate an individual responsible for AI governance. This role overlaps with — but is not identical to — the Data Protection Officer role under GDPR.
4. Train your lawyers
EU AI Act compliance is not solely an IT or compliance department matter. Every lawyer using AI tools needs to understand the basic obligations around transparency and human oversight.
AI Compliance Quick Check
0/7The opportunity in compliance
Firms that develop strict AI compliance frameworks will find themselves well-positioned to advise clients facing the same challenges. The internal work of getting your own house in order becomes the experiential foundation for a practice area.
Integrating DPIA with AI Impact Assessments
Firms already conducting Data Protection Impact Assessments under FADP can extend them to cover AI-specific risks rather than building a separate framework. ISO 42001 explicitly endorses this approach: AI system impact assessments focused on privacy "may need to be integrated into the organization's broader risk management program." A unified DPIA/AI impact assessment avoids duplicative work.
The DPIA should examine more closely than a general AI assessment, examining: purpose of data collection, method and scope of processing, data sensitivity classification, affected data subjects, processing context, and opportunities for individual participation. For a 10-lawyer firm, one unified document covering both data protection and AI governance is more practical — and more defensible — than two separate assessments.
Secondary Use: The Hidden Vendor Risk
When an AI vendor's terms are ambiguous about model training, a specific risk materialises: secondary use — repurposing data collected from your clients for AI model training without consent. Three specific threats:
- Training new models on client data without explicit prohibition in the DPA
- Inference risk — AI algorithms predicting characteristics your client would prefer to keep private, even if the individual never provided that information directly
- Web-scraping training data that may include documents your firm published on behalf of clients
The EU Data Act Article 6(1) reinforces this: third parties receiving personal data must process it "only for the purposes and under the conditions agreed with the user." If your AI vendor cannot produce a DPA clause explicitly prohibiting model training on your client data, do not use the tool.
Is Your Firm AI-Compliant?
5 questions
1. Does your firm maintain a complete AI tool inventory?
2. Do your engagement letters disclose AI usage?
3. Have you reviewed vendor DPAs for model-training clauses?
4. Do you have an appointed AI governance lead?
5. Have fee earners received AI oversight training?
Key Takeaway
GDPR and the EU AI Act apply simultaneously to any law firm deploying AI tools that process client personal data. The good news: firms already conducting DPIAs under FADP can extend them to cover AI-specific risks rather than building a separate framework. Demand an explicit DPA clause prohibiting model training on client data from every AI vendor — and conduct integrated DPIA/AI impact assessments rather than maintaining parallel processes.
Adriana Adafinoaiei advises law firms on GDPR compliance, EU AI Act implementation, and legal technology governance. Get in touch to discuss your firm's compliance posture.