The EU AI Act deadline everyone feared moved. The one that matters for law firms did not.
On 27 July 2026 the Digital Omnibus on AI entered into force and pushed the high-risk obligations of Annex III from 2 August 2026 to 2 December 2027. Law firms were never the target of that regime. What binds a law firm under the EU AI Act is Article 4, the AI-literacy duty, which has applied since 2 February 2025, was reworded rather than removed, and became enforceable by national authorities on 2 August 2026. Asked whether a company whose staff use ChatGPT for writing must comply, the European Commission’s answer is one line: “Yes, they should be informed about the specific risks, for example hallucination.”
So the EU AI Act for law firms is mostly a question about training, records and a few transparency rules. Here is what applies, what changed in July 2026, and what to keep on file.
The EU AI Act for law firms in one paragraph
Regulation (EU) 2024/1689 sorts AI systems by risk: prohibited practices (Article 5), high-risk systems (Annexes I and III, with the heavy conformity duties), general-purpose models, and everything else, which gets the light-touch duties in Article 4 (literacy) and Article 50 (transparency). A firm using an AI system under its own authority is a deployer under Article 3(4); the CCBE’s technical guide notes that Article 4 “obliges the providers and deployers of AI systems (which includes lawyers)”, and BRAK calls firms “Betreiber”. The timeline, as amended:
| Date | What applies |
|---|---|
| 1 August 2024 | Entry into force |
| 2 February 2025 | Article 5 prohibitions; Article 4 AI literacy |
| 2 August 2025 | General-purpose AI model obligations |
| 2 August 2026 | Article 50 transparency; national authorities supervise and enforce Article 4 |
| 2 December 2027 | Annex III high-risk obligations (was 2 August 2026) |
| 2 August 2028 | Annex I product-embedded high-risk obligations |
The professional rules that sit alongside the Act are in the ethics and regulation hub.
Article 4: AI literacy since 2 February 2025
The original text, which most commentary paraphrases loosely:
“Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used.” — Article 4, Regulation (EU) 2024/1689 (original wording, applicable from 2 February 2025)
The duty attaches to any AI system, not to legal AI; beck-aktuell’s analysis says it binds firms “unabhängig von der Umsatzstärke oder der Anzahl der Mitarbeitenden” and covers “alle KI-Tools, wie zum Beispiel Microsoft CoPilot, DeepL, ChatGPT oder BeckChat”, free licences included. DeepL (70.7%) and ChatGPT (69.2%) were the most-used tools in the Bayerischer AnwaltVerband’s survey, so nearly every firm is a deployer already, and “other persons” using AI on your behalf, such as a freelance translator, count too.
What the Commission says “sufficient literacy” means
The Commission’s AI-literacy Q&A sets the minimum content: (a) a general understanding of AI within the organisation, including which systems it uses and their dangers; (b) the organisation’s role, provider or deployer; © the risk level of the systems used; (d) measures tailored to staff knowledge and context, with legal and ethical aspects included. Then the limits: “no specific – or ‘sufficient’ - level is mandated”; no certificate is required (“Organisations can keep an internal record of trainings”); no AI officer or governance board.
The sentence to underline:
“Simply relying on the AI systems’ instructions for use or asking the staff to read them might be ineffective.” — European Commission, AI Literacy Questions and Answers
That rules out compliance by email, where a memo attaches the vendor’s usage policy and asks everyone to confirm they have read it.
The Digital Omnibus (Regulation 2026/1744): what softened
The Omnibus was signed on 8 July 2026, published in the Official Journal on 24 July and entered into force on 27 July 2026.
Softer wording is not no wording. The duty survives, as Covington’s summary makes clear, and a duty to “take measures” is proved by showing the measures: keep records.
Enforcement from 2 August 2026
Article 99, the penalty provision, lists no fine for Article 4. Enforcement is left to national law: the Commission’s Q&A says penalties “will be based on national laws that Member States are due to adopt by 2 August 2025” and “must be proportionate”, and that national market surveillance authorities supervise and enforce from 2 August 2026. And:
Sanctions are “more likely if there is proof of an incident due to lack of appropriate training”. — European Commission, AI Literacy Questions and Answers
Annex III high-risk: delayed to December 2027, and why it is not your problem
Annex III point 8(a) covers AI used by or on behalf of judicial authorities to research and interpret facts and law and apply it to concrete facts. Read quickly, that sounds like every legal research tool; read with Recital 61, it is about courts. BRAK’s guidance is explicit: the AI systems used in a law firm “zählen jedenfalls nicht” to the Annex III 8(a) high-risk systems, because that use case refers to Justizbehörden and not the Anwaltschaft. The DAV agrees that “die meisten in der Anwaltskanzlei eingesetzten KI-Systeme nicht als hochriskant eingestuft werden”.
Two caveats. A firm that develops its own system and puts it into service under its own name may become a provider. And your clients are different: an HR department screening candidates with AI, or a bank scoring creditworthiness, is squarely in Annex III from 2 December 2027. That is advisory work, covered below.
Deployer duties beyond literacy: transparency, oversight and GDPR
Article 50 applies from 2 August 2026. For a firm, it means two things. A client-facing chatbot on your website must tell users they are dealing with a machine. AI-generated text you publish to inform the public on matters of public interest would need a label, except that Article 50(4) exempts content that has undergone human review or editorial control with a person holding responsibility; BRAK points to that exemption for lawyer-published text.
The GDPR runs in parallel and is where most of the real risk sits: every provider needs an Article 28 processing agreement, and transfers to US providers still rest on the EU-US Data Privacy Framework, which the General Court upheld in Latombe on 3 September 2025, with an appeal to the CJEU filed on 31 October 2025 still pending. Where each tool actually processes data, and which offer EU residency, is set out in the EU data residency guide.
Documenting compliance: the training record template
ki-kanzlei.de’s five-step plan is as good a skeleton as any: inventory of AI systems and affected staff, needs analysis, a differentiated training concept, documentation, and periodic refreshers. Turned into a record, it looks like this:
| Record element | What to write down | Why |
|---|---|---|
| AI inventory | Every system in use, tier, purpose, who uses it | Q&A point (a): “What AI is used in our organisation?” |
| Role and risk | Deployer; risk class per system (none high-risk; Article 50 for the website bot) | Q&A points (b) and © |
| Needs analysis by group | Lawyers, paralegals, secretaries, IT, marketing; what each does with AI and what can go wrong | Q&A point (d): tailored measures |
| Measures taken | Date, format, trainer, content, duration; hands-on components; attendance list | “Measures to support the development of” literacy |
| Refresh cycle | Review date; triggers (new tool, new model, an incident) | Periodic reassessment |
| Incident log | Near-misses and errors caught, with the corrective step | The “proof of an incident” test, turned to your advantage |
Draft an AI-literacy record for a [law firm of N staff in [Germany / Austria / jurisdiction]] under Article 4 of the EU AI Act. Structure it around the Commission's minimum content: general understanding of AI (what it is, how it works, which systems we use, opportunities and dangers including hallucination); our role as deployer; the risk level of each system in <inventory>...</inventory>; measures tailored to staff groups. Include a needs analysis per group, a training plan with dates and formats (hands-on, not lecture), how attendance is documented, and the refresh cycle. Mark any statement of law [VERIFY].For each staff group in <groups>[e.g. transactional lawyers, litigators, paralegals, secretaries, marketing, IT]</groups> and the tools they use in <inventory>...</inventory>, produce a table: Group | Tools and tasks | Three failure modes most likely to harm a client or the firm (e.g. hallucinated citations, confidential data in a consumer tier) | What the group must be able to do afterwards (observable skills) | Format and length of training | Evidence we will keep. Be specific to legal practice, not generic AI awareness.As for the measure itself: Paul Weiss found its first PowerPoint session “ineffective” and moved to a hands-on workshop; beck-aktuell’s three principles are self-directed practice (“Wer nur Inhalte konsumiert und sich nicht selbst mit praktischen Anwendungsfällen befasst, wird kein nachhaltiges KI-Verständnis aufbauen”), continuous learning, and learning in groups with internal multipliers. Formats are covered in the training guide and the implementation playbook.
The CCBE and national bar positions
Each bar treats AI competence as a professional duty in its own right, which means a firm that ignores Article 4 is usually breaching something older.
| Body | Instrument | Position on competence and training |
|---|---|---|
| CCBE | Generative AI guide (2 October 2025); technical guide (27 March 2026) | “knowing how to question GenAI in order to reach the correct answer … might be considered essential training in the future”; warns of “erosion of professional skills” among juniors |
| BRAK (Germany) | Hinweise zum Einsatz von KI (December 2024) | Staff instructions and training are “ein wesentlicher Bestandteil einer verantwortungsvollen Nutzung von KI”; larger firms may need a documented risk-management system |
| DAV (Germany) | Initiativ-Stellungnahme 32/2025 (July 2025) | “Der Anwaltschaft steht es frei, die ihr durch KI eröffneten Möglichkeiten zu nutzen”; most firm systems not high-risk |
| ÖRAK (Austria) | Leitfaden KI in Anwaltskanzleien (September 2025) | “Die Nutzung von KI-Systemen ist nur zulässig, wenn eine KI-Kompetenz der Mitarbeiterinnen und Mitarbeiter besteht”; signable provider checklist |
Austria’s formulation is the strictest (no competence, no permitted use) and the most useful: it turns the Article 4 record into the document that proves your firm was allowed to use the tool at all. The German-language detail is in KI in der Kanzlei: BRAK, DAV und ÖRAK; the tool options are in the DACH tools guide.
Advising clients on their own AI Act duties
The same Q&A binds your clients, and most have not read it. The European Legal Technology Association’s 2024 survey, as reported by Anwaltsblatt, found 93% of firm representatives had tried generative AI but only 41% worked with specific tools; in-house counsel are no further ahead, and are now asked whether the marketing team’s new tool triggers Annex III. The literacy duty is the easiest place to start that conversation: every client with staff on ChatGPT already owes it.
Produce a briefing for the general counsel of a [sector, size, Member State] company on its obligations as a deployer under the EU AI Act as at [today's date], after Regulation (EU) 2026/1744. Cover: which of its AI uses in <uses>...</uses> are prohibited, high-risk (Annex III, from 2 December 2027), subject to Article 50 transparency, or only Article 4 literacy; the literacy measures and records the Commission's Q&A expects; the national enforcement authority and penalty law [VERIFY]; and five actions for the next 90 days. Use only <sources>[EUR-Lex, the Commission Q&A, the national authority's page]</sources> and give the source next to every date. Under 1,200 words.The jurisdiction-by-jurisdiction ethics guide sets the Act beside the professional rules, the AI policy template is where the inventory and approved-tool list live, and the prompt library has the record and briefing prompts. A live, documented, hands-on session is the kind of measure a firm can put on file, and AI Lab for Lawyers, four two-hour live classes with a certificate of completion, was built to be exactly that.
Frequently asked questions
Does the EU AI Act apply to law firms?
Yes, as deployers. Article 3(4) defines a deployer as anyone using an AI system under their own authority, and both BRAK and the CCBE confirm this covers lawyers and law firms. The obligations that bite in practice are Article 4 (AI literacy, since 2 February 2025) and Article 50 (transparency for chatbots and certain AI-generated content, since 2 August 2026). The high-risk regime in Annex III does not cover ordinary law-firm tools.
What is Article 4 AI literacy?
Article 4 requires providers and deployers of AI systems to take measures to support the development of AI literacy among staff and others using AI on their behalf, taking into account their technical knowledge, experience, education and the context of use. The Commission's Q&A expects a general understanding of AI, knowledge of the organisation's role as deployer, the risk level of the systems used, and measures tailored to staff groups, with legal and ethical aspects included.
Do lawyers need an AI Act certificate?
No. The European Commission's AI-literacy Q&A states that no certificate is required and no AI officer or governance board is mandated. Organisations 'can keep an internal record of trainings', and after the Digital Omnibus firms are advised to maintain records of the measures taken. A dated attendance list, the training content and a short needs analysis by staff group are the evidence a market surveillance authority would expect to see.
When is the EU AI Act enforced?
In stages. Prohibitions and Article 4 applied from 2 February 2025; general-purpose model duties from 2 August 2025; Article 50 transparency from 2 August 2026, which is also the date from which national market surveillance authorities supervise and enforce Article 4. After the Digital Omnibus, Annex III high-risk obligations apply from 2 December 2027 and Annex I product-embedded systems from 2 August 2028.
Is legal AI high-risk under the AI Act?
Generally not for law firms. Annex III point 8(a) covers AI used by or on behalf of judicial authorities to research and apply the law; BRAK reads it, with Recital 61, as covering courts rather than the Anwaltschaft, and DAV says most systems used in firms are not high-risk. A firm that builds its own system and puts it into service under its own name could become a provider, which is a different analysis.