Regulation
EU AI Act: What Legal Teams Must Do
Obligations by risk tier, the dates that matter and a checklist for in-house counsel who have to classify systems the company is already using.
The EU AI Act is in force and its obligations arrive in stages. For most legal departments the question is not whether it applies — it is which of the systems already in use fall inside it, and who inside the company is going to say so in writing.
On this page
What the Act Actually Regulates
The Act regulates AI systems placed on the EU market or used in the EU, and it allocates duties by role. A provider develops a system and puts it on the market. A deployer uses one under its own authority. Most legal departments are deployers, and the duties of a deployer are considerably lighter than those of a provider — but they are not nothing, and they are not discharged by the vendor.
The distinction matters more than it looks. Fine-tuning a model on your own data, or putting your own branding on a system, can move a company from deployer to provider for that system.
The Risk Tiers
- Prohibited. A short list including social scoring and certain biometric categorisation. Not a grey area — these cannot be used.
- High-risk. Systems in listed areas such as employment, credit, education and access to essential services. Conformity assessment, risk management, logging and human oversight apply.
- Limited risk. Transparency duties, mainly telling people they are interacting with an AI system or seeing generated content.
- Minimal risk. Everything else, which is where most contract review and document search sits.
General-purpose AI models carry their own obligations, largely on the model provider rather than on the company using the model through a product.
Dates That Matter
The obligations phase in rather than landing at once: prohibitions and AI literacy duties first, general-purpose model obligations next, then the bulk of the high-risk regime, with certain systems embedded in regulated products following later still. Confirm the current dates against the Official Journal text before building a plan around them — the staging has been amended once already, and secondary guidance is still arriving.
What Legal Teams Should Do Now
- Inventory the AI systems already in use, including the ones procured by other departments without legal involvement.
- Assign a role per system — provider or deployer — and write down the reasoning, because the answer is not always obvious.
- Classify each system by tier, and keep the evidence behind the classification rather than the conclusion alone.
- Check vendor contracts for the information you need to meet your own duties; many do not currently provide it.
- Put human oversight in place where a system materially affects a person, and record who exercises it.
- Run AI literacy training for staff who use these systems — this duty applies broadly and is easy to evidence.
Where This Commonly Goes Wrong
Two failures recur. The first is treating the Act as a data protection problem and handing it to the DPO alone; the classification questions are product and procurement questions as much as privacy ones. The second is classifying once and never revisiting, when the systems in use change every quarter.
The unglamorous work — an inventory that is current, a written reason per classification, and a named person for oversight — is what a supervisory authority will ask for. It is also the part that takes months if it is started late.
This article is general information about a regulation, not legal advice on your situation. Confirm current dates and guidance before relying on any of it.
Related
Where this connects to the rest of the site.
VentosCompliance
System inventory, risk classification and the technical file each tier requires.
SolutionAI Contract Review
Where AI sits inside contract work, and what stays with the lawyer.
ReferenceFrequently Asked Questions
Common questions on security, deployment and how the models are used.
Ready to see it on your documents?
Book a demo and we will run the platform against a sample of your contracts or matters, in your jurisdiction.