Please find below a short summary of the EU AI Act for all interested parties!
The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It turns “trustworthy AI” from a policy slogan into a binding, risk‑based compliance regime that affects not only tech companies, but also law firms, consultancies and other professional services using AI in client work.
The AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 and applies in phases, with most core obligations for high‑risk systems taking effect from 2 August 2026. It applies to:
🔶 Providers: organisations that develop AI systems and place them on the EU market;
🔶 Deployers: organisations that use AI systems in a professional context within the EU.
If your firm is based in Romania or elsewhere in Europe and uses AI tools for legal research, contract drafting, due diligence, HR screening, client communication or analytics, you are almost certainly a deployer under the Act. The rules also have extraterritorial reach: they apply to non‑EU providers whose AI outputs are used in the EU.
For professional services, the main implications are:
🔶New compliance duties around AI literacy, transparency, and, in some cases, high‑risk obligations.
🔶Contractual and vendor‑management work: updating engagement letters, data processing agreements and AI‑vendor due diligence.
🔶New service lines: advising clients on AI governance, risk classification, documentation and conformity assessments.
The AI Act classifies AI systems into four risk tiers, each with different obligations:
🟡 Unacceptable risk (prohibited): practices deemed too harmful are banned outright (e.g. certain social scoring systems, some forms of manipulative or exploitative AI, and tightly restricted real‑time biometric identification in public spaces).
🟡 High risk: systems that significantly affect health, safety or fundamental rights (e.g. AI in recruitment, credit scoring, education, certain biometric uses, and some critical infrastructure applications).
🟡 Limited risk: systems where users must be informed they are interacting with AI (e.g. chatbots, deepfakes and some emotion‑recognition tools).
🟡 Minimal risk: most everyday AI uses (e.g. spam filters, basic productivity tools) remain largely unregulated.
For law firms and consultancies, the most common touchpoints today are AI literacy, transparency obligations, and, depending on your practice areas, potential high‑risk classifications (e.g. HR screening tools or AI used in credit/insurance assessments).
Several provisions are already applicable or will be fully in force in 2026:
🔷 AI literacy (Article 4): staff and associates who use AI on your behalf must have an appropriate level of AI literacy. This has been in force since 2 February 2025.
🔷 Prohibited practices (Article 5): you must ensure none of your AI uses fall within the banned categories; this has applied since 2 February 2025.
🔷 Transparency (Article 50): from 2 August 2026, client‑facing chatbots and certain AI‑generated content must be clearly disclosed and labeled.
🔷 High‑risk obligations: for systems classified as high‑risk under Annex III, requirements include risk management, data governance, technical documentation, logging, human oversight, accuracy/robustness/cybersecurity, and conformity assessment/CE marking. These obligations largely apply from 2 August 2026, with some legacy transitions until 2028.
🔷 Non‑compliance can lead to significant fines: up to €35 million or 7% of global annual turnover for prohibited practices, and up to €15 million or 3% for many other breaches, including transparency and high‑risk obligations.
Even if you are not building AI systems, as a deployer you should:
🟢 Map your AI use cases: list all AI tools used internally and in client work (legal research, drafting, translation, analytics, HR, marketing, etc.).
🟢 Classify by risk tier: confirm whether any tool falls into prohibited, high‑risk, limited‑risk or minimal‑risk categories.
🟢 Adopt an internal AI policy: a short, written policy covering acceptable uses, confidentiality, data protection, human oversight and labeling requirements.
🟢 Train your people: ensure partners, lawyers, consultants and support staff understand the AI Act’s basics and your internal rules.
🟢 Update contracts and vendor due diligence: include AI‑specific clauses on compliance, data protection, transparency, logging and incident reporting in vendor and client agreements.
1. Governance and policy
⚡️ Appoint an AI lead or working group (partner‑level sponsorship plus compliance/IT/HR).
⚡️ Approve a one‑ to two‑page internal AI policy covering acceptable uses, confidentiality, data protection and labeling.
2. Inventory and risk classification
⚡️ Create an inventory of all AI tools used in the firm (name, provider, purpose, users, data processed).
⚡️ Classify each tool by risk tier (prohibited / high‑risk / limited‑risk / minimal‑risk).
⚡️ For any potentially high‑risk uses (e.g. HR screening, credit/insurance assessments, biometrics), seek specialist advice and document your reasoning.
3. AI literacy and training
⚡️ Ensure all staff and contractors using AI complete basic AI‑literacy training and acknowledge the internal policy.
⚡️ Provide targeted training for teams using AI in client‑facing or high‑impact contexts (e.g. litigation support, due diligence, compliance).
4. Transparency and client communication
⚡️ Implement clear disclosures for client‑facing chatbots and AI assistants.
⚡️ Label AI‑generated content where required (e.g. synthetic images, deepfakes, certain automated reports).
⚡️Update engagement letters and proposals to explain how AI is used, what safeguards are in place, and any limitations.
5. Vendor and contract management
⚡️ Review key AI vendor contracts for compliance with the AI Act (transparency, logging, security, incident reporting).
⚡️ Add AI‑specific clauses to new and renewed contracts, covering risk classification, documentation, human oversight and liability.
6. Monitoring and continuous improvement
⚡️ Set up a simple process to log AI incidents or near‑misses and to review them periodically.
⚡️ Revisit your AI inventory and risk classification at least annually or when introducing new tools.
To be continued!
………………………….
✨Hi, I am Iulia,
Legal English Trainer | SEO Copywriter | Helping Lawyers Master English for Global Wins | Founder @ Start English | Empowering Global Legal Pros with Badass English & SEO Mastery
💥We can work together to craft your personalized content, polish your English-speaking skills, and secure your place in the sun.
⚡️Without excellent English, there’s no path forward!
AI-generated photo based on the content above.
https://blog.seocopywriting.ro/2026/08/10/start-english-curs-de-engleza-juridica-pentru-avocati/
CURS DE ENGLEZĂ JURIDICĂ PENTRU AVOCAȚI BUCURESTI ȘI BRAȘOV
