AI Act: what the EU regulation on AI changes for lawyers

The AI Act, Regulation (EU) 2024/1689, classifies AI systems by level of risk and imposes obligations, some of which already apply to law firms. Amended in July 2026, it postpones the "high-risk" obligations to 2027 and 2028. For a law firm, the most concrete obligation is already in force: providing AI training to the people who use it.

A regulation built on levels of risk

The AI Act grades obligations according to the level of risk of AI systems. The Direction générale des Entreprises (the French Directorate-General for Enterprise) presents them in four levels:

General-purpose AI models, for their part, have their own rules, which are aimed at their providers.

The application timeline

The Regulation applies in successive waves. The initial timeline was revised by Regulation (EU) 2026/1744 of 8 July 2026, known as the "Digital Omnibus", which entered into force on 27 July 2026:

DateWhat applies
1 August 2024Entry into force of the Regulation
2 February 2025Ban on unacceptable-risk practices and the AI literacy obligation (AI training)
2 August 2025Rules on general-purpose AI models
2 August 2026General application, including the transparency obligations (marking of generated content: until 2 December 2026 for systems already on the market)
2 December 2027Obligations for the high-risk AI systems in Annex III
2 August 2028Obligations for high-risk AI systems embedded in regulated products

The obligations for the high-risk AI systems in Annex III were originally scheduled for 2 August 2026.

What already applies to a law firm

The first obligation that concerns a law firm is AI literacy. Since 2 February 2025, organisations that use AI systems must act so that the people who use them understand how they work, their limits and their risks. Since the July 2026 revision, the text requires them to take measures to support this knowledge, without requiring them to guarantee a specific level for each person. For a law firm, this means training the lawyers and staff who use an AI tool: what it does, what it does not do, and how to check its results.

The transparency obligations, applicable since 2 August 2026, require in particular informing a person that they are interacting with an AI and marking AI-generated content.

Where does a legal AI fit?

A law firm's first question is whether its AI tool is "high-risk". It all depends on the use. Annex III covers AI systems intended to be used by a judicial authority, or on its behalf, to assist it in researching and interpreting facts and the law and in applying the law to a concrete set of facts. It also covers systems used in a similar way in alternative dispute resolution.

A tool that a lawyer uses to prepare their client's file is not, on that basis, a system used by a judicial authority. The classification nonetheless depends on the tool's exact function and is assessed case by case. Ask the provider to document the risk level of its product.

What a law firm can do right now

Without waiting for the 2027 deadlines, a law firm can already act on four points:

The Regulation does not replace professional ethics

The AI Act adds a layer of compliance; it does not take the place of the profession's rules. A tool that complies with the Regulation must still respect the lawyer's professional secrecy (secret professionnel) and sovereignty requirements, as well as the GDPR for clients' personal data. And compliance says nothing about the reliability of the answers: the risk of hallucination by a generalist AI remains in full, and it is a separate issue.

For a law firm, these requirements converge on a single criterion: being able to understand, check and trace what the tool produces. It is also one of the criteria in our overview of the best legal AI for lawyers.

Plato's answer

Plato is designed for this use: every result remains verifiable and traceable back to its source, the data is hosted in a sovereign way suited to sensitive data, and the lawyer keeps control of, and responsibility for, what they produce.

Frequently asked questions

What is the AI Act?

It is Regulation (EU) 2024/1689 on artificial intelligence, which entered into force on 1 August 2024 and was amended by Regulation (EU) 2026/1744 of 8 July 2026. It classifies AI systems according to their level of risk and imposes graduated obligations, applicable in stages until 2028.

Which AI Act obligations already apply to a law firm?

The AI literacy obligation, applicable since 2 February 2025: taking measures so that the people who use an AI system understand how it works, its limits and its risks. Since July 2026, the text no longer requires a specific level to be guaranteed for each person. Unacceptable-risk practices have been prohibited since 2 February 2025.

Is a legal AI a high-risk AI system?

Not necessarily. Annex III covers systems used by a judicial authority, or on its behalf, to research and interpret facts and the law, as well as similar uses in alternative dispute resolution. A tool used by a lawyer to prepare a case file is not covered on that basis; the classification depends on the use and is assessed case by case.

When do the obligations for high-risk AI systems apply?

On 2 December 2027 for the systems in Annex III, and on 2 August 2028 for those embedded in regulated products. These dates result from Regulation (EU) 2026/1744, which pushed back the original deadline of 2 August 2026.

What is the "Digital Omnibus"?

It is Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July and in force since 27 July 2026. Among its amendments, three directly concern a law firm: the postponement of the obligations for high-risk AI systems, the rewriting of the AI literacy obligation, which no longer requires a specific level to be guaranteed, and a deadline of 2 December 2026 for marking content generated by systems already on the market.

Does the AI Act replace professional secrecy and the GDPR?

No. It adds to the profession's obligations. A tool that complies with the Regulation must still respect professional secrecy, data sovereignty and the GDPR, and its compliance does not guarantee the reliability of its answers.

How do you choose an AI that is compliant and reliable?

By checking that the provider documents its product's risk level, guarantees the confidentiality and sovereignty of the data, and makes it possible to trace each answer back to its source. Traceability is the criterion common to compliance, professional ethics and reliability. It is Plato's design principle, with the lawyer keeping final control.