We write this as a software vendor, not as legal experts. What follows is general information: which obligations apply to a particular firm’s particular use is decided by that firm’s own assessment.
Two different roles: building it and using it
Conversations about EU AI regulation often run aground because two very different situations get mixed together. Someone who develops an AI system and puts it on the market is in one position; someone who applies a finished tool inside their own operation is in quite another. In the overwhelming majority of cases a law firm belongs to the second group: it is not building a model, it is procuring software and using it.
That distinction has a practical payoff. Most of the literature on the regulation is written from the developer’s side, and a firm reading it will conclude its own task is far larger than it is. The questions on the user’s side are much more tangible: what does the tool do, who supervises it, what record remains afterwards, and what happens to the data along the way.
What the regulation is about — themes, not articles
Rather than quoting specific article numbers and deadlines, it is more useful to think through the recurring themes the regulation is built around. They largely coincide, as it happens, with what a well-run firm would do anyway.
Transparency toward clients
The client should know which part of the workflow an AI tool takes part in. That does not mean a long technical explanation; it means saying plainly that the system prepares and the lawyer does the professional work. Many firms settle this in their engagement terms or in a short notice.
Human oversight
The recurring expectation is that the output of an AI tool does not automatically become the final result: there should be an identifiable person who checks it and who is able to overrule it. At a law firm it could hardly be otherwise anyway, since professional responsibility rests with the acting attorney.
Record-keeping and traceability
It should be answerable after the fact which tool was used in a given matter, for what, and who reviewed the result. This does not call for an elaborate system: what helps most is the tool keeping an audit trail itself, and the firm briefly recording what it uses the tool for.
Understanding what the tool does with the data
This is where the regulatory consideration meets the professional secrecy one. A firm that cannot say where the model runs and where the file goes cannot account for the use — neither to its client nor to itself. We worked through that question in a separate piece.
Why human oversight is more than good practice
Plenty of people treat the human-in-the-loop principle as a polite formality: the system gives the answer anyway, and the signature is just administration. The regulatory logic points in the opposite direction. A use where AI prepares and a professional genuinely reviews and decides is simply easier to defend — because there is someone to ask, and something to overrule.
That has a software design consequence too. The tool that actually supports human oversight is the one that produces verifiable output: every statement tied to a specific point in the document, so that the review can really be carried out rather than merely recorded as done. Where the output cannot be traced back, oversight is fooling itself.
This is why, in AI Szerződéselemző, the sixth step — the lawyer reviews and finalises — is not a legal notice in a footnote but a part of the workflow. The system suggests and cites; the acting attorney decides.
Questions worth putting to a vendor
- What purpose was the tool built for, and what is it explicitly not suitable for?
- Where does the model run, and is there an external AI API anywhere in the chain?
- Can it be established what happened to a given document, and how long does that record persist?
- In what form does the user receive the citations that make the output verifiable?
- What happens to the data once the contract ends: can it be exported and deleted?
The answers give a reading not only on compliance questions but on how far the vendor has thought through the environment their product lands in. In practice those two are closely connected.
What this article cannot do for you
It cannot tell you which classification a particular firm’s particular use falls under, and it does not replace the firm’s own assessment. We deliberately quote no article numbers, deadlines or specific obligations: interpretation of the regulation keeps developing, and a half-accurate reference from a marketing page is worse than no reference at all. After orientation, it is the firm’s own decision how deeply, and with whose help, to carry out its assessment.
This article is general information, not legal advice. Judging compliance questions is the firm’s own responsibility and assessment.