A risk-based regulation
Regulation (EU) 2024/1689 differentiates obligations and prohibitions according to the system and context of use. Not every AI tool used by a professional is automatically high-risk.
Classification depends on the organisation’s role, the system’s function and the specific legal category involved.
Provider, deployer and professional firms
A professional firm using a third-party system will normally act as a deployer, although its role may change if it develops, substantially modifies or markets its own systems. Correct role identification determines the applicable obligations.
Annex III covers specific uses in the administration of justice without turning every research or drafting tool used by lawyers into a high-risk system.
AI literacy and application
AI literacy obligations have applied since 2 February 2025 and the Regulation became generally applicable on 2 August 2026, while certain provisions follow specific transition calendars. High-risk systems require checking the EU timetable in force at the relevant time.
User competence is therefore already an organisational requirement rather than a future concern.
Transparency, GDPR and confidentiality
The AI Act and GDPR operate on complementary planes. Personal data, professional secrecy, document confidentiality and transfers to external providers must be assessed before use.
Even systems that are not classified as high-risk may create significant risk for a firm if used without governance.
From policy to governance
An effective AI policy should identify authorised tools, permitted data, output verification, authorisation levels and cases requiring human review. It should also address shadow AI.
The decisive shift is from formal compliance to governance: knowing which systems are used, by whom, for what activities and under which controls.
