← Back to resources

Resources

EU AI Act for law firms

This piece is orientation, not legal advice, and it is not a summary of the regulation. It looks for a direction on one practical question: what a law firm that uses AI tools should be paying attention to — thematically, without article numbers.

We write this as a software vendor, not as legal experts. What follows is general information: which obligations apply to a particular firm’s particular use is decided by that firm’s own assessment.

Two different roles: building it and using it

Conversations about EU AI regulation often run aground because two very different situations get mixed together. Someone who develops an AI system and puts it on the market is in one position; someone who applies a finished tool inside their own operation is in quite another. In the overwhelming majority of cases a law firm belongs to the second group: it is not building a model, it is procuring software and using it.

That distinction has a practical payoff. Most of the literature on the regulation is written from the developer’s side, and a firm reading it will conclude its own task is far larger than it is. The questions on the user’s side are much more tangible: what does the tool do, who supervises it, what record remains afterwards, and what happens to the data along the way.

What the regulation is about — themes, not articles

Rather than quoting specific article numbers and deadlines, it is more useful to think through the recurring themes the regulation is built around. They largely coincide, as it happens, with what a well-run firm would do anyway.

Transparency toward clients

The client should know which part of the workflow an AI tool takes part in. That does not mean a long technical explanation; it means saying plainly that the system prepares and the lawyer does the professional work. Many firms settle this in their engagement terms or in a short notice.

Human oversight

The recurring expectation is that the output of an AI tool does not automatically become the final result: there should be an identifiable person who checks it and who is able to overrule it. At a law firm it could hardly be otherwise anyway, since professional responsibility rests with the acting attorney.

Record-keeping and traceability

It should be answerable after the fact which tool was used in a given matter, for what, and who reviewed the result. This does not call for an elaborate system: what helps most is the tool keeping an audit trail itself, and the firm briefly recording what it uses the tool for.

Understanding what the tool does with the data

This is where the regulatory consideration meets the professional secrecy one. A firm that cannot say where the model runs and where the file goes cannot account for the use — neither to its client nor to itself. We worked through that question in a separate piece.

Why human oversight is more than good practice

Plenty of people treat the human-in-the-loop principle as a polite formality: the system gives the answer anyway, and the signature is just administration. The regulatory logic points in the opposite direction. A use where AI prepares and a professional genuinely reviews and decides is simply easier to defend — because there is someone to ask, and something to overrule.

That has a software design consequence too. The tool that actually supports human oversight is the one that produces verifiable output: every statement tied to a specific point in the document, so that the review can really be carried out rather than merely recorded as done. Where the output cannot be traced back, oversight is fooling itself.

This is why, in AI Szerződéselemző, the sixth step — the lawyer reviews and finalises — is not a legal notice in a footnote but a part of the workflow. The system suggests and cites; the acting attorney decides.

Questions worth putting to a vendor

The answers give a reading not only on compliance questions but on how far the vendor has thought through the environment their product lands in. In practice those two are closely connected.

What this article cannot do for you

It cannot tell you which classification a particular firm’s particular use falls under, and it does not replace the firm’s own assessment. We deliberately quote no article numbers, deadlines or specific obligations: interpretation of the regulation keeps developing, and a half-accurate reference from a marketing page is worse than no reference at all. After orientation, it is the firm’s own decision how deeply, and with whose help, to carry out its assessment.

This article is general information, not legal advice. Judging compliance questions is the firm’s own responsibility and assessment.

From the software side we can give concrete answers to the questions above: where the system runs, what audit trail it keeps, and what verifiable output looks like in practice. On a demo we show that on your own contract type.