Home Platform Solutions Services Pricing Insights About Contact Request Demo

Regulation

EU AI Act: What Legal Teams Must Do

Obligations by risk tier, the dates that matter and a checklist for in-house counsel who have to classify systems the company is already using.

Published 18 August 2026 · Updated 1 September 2026 · By Olga Petrova, VP of Product

The EU AI Act is in force and its obligations arrive in stages. For most legal departments the question is not whether it applies — it is which of the systems already in use fall inside it, and who inside the company is going to say so in writing.

What the Act Actually Regulates

The Act regulates AI systems placed on the EU market or used in the EU, and it allocates duties by role. A provider develops a system and puts it on the market. A deployer uses one under its own authority. Most legal departments are deployers, and the duties of a deployer are considerably lighter than those of a provider — but they are not nothing, and they are not discharged by the vendor.

The distinction matters more than it looks. Fine-tuning a model on your own data, or putting your own branding on a system, can move a company from deployer to provider for that system.

The Risk Tiers

  • Prohibited. A short list including social scoring and certain biometric categorisation. Not a grey area — these cannot be used.
  • High-risk. Systems in listed areas such as employment, credit, education and access to essential services. Conformity assessment, risk management, logging and human oversight apply.
  • Limited risk. Transparency duties, mainly telling people they are interacting with an AI system or seeing generated content.
  • Minimal risk. Everything else, which is where most contract review and document search sits.

General-purpose AI models carry their own obligations, largely on the model provider rather than on the company using the model through a product.

Dates That Matter

The obligations phase in rather than landing at once: prohibitions and AI literacy duties first, general-purpose model obligations next, then the bulk of the high-risk regime, with certain systems embedded in regulated products following later still. Confirm the current dates against the Official Journal text before building a plan around them — the staging has been amended once already, and secondary guidance is still arriving.

What Legal Teams Should Do Now

  • Inventory the AI systems already in use, including the ones procured by other departments without legal involvement.
  • Assign a role per system — provider or deployer — and write down the reasoning, because the answer is not always obvious.
  • Classify each system by tier, and keep the evidence behind the classification rather than the conclusion alone.
  • Check vendor contracts for the information you need to meet your own duties; many do not currently provide it.
  • Put human oversight in place where a system materially affects a person, and record who exercises it.
  • Run AI literacy training for staff who use these systems — this duty applies broadly and is easy to evidence.

Where This Commonly Goes Wrong

Two failures recur. The first is treating the Act as a data protection problem and handing it to the DPO alone; the classification questions are product and procurement questions as much as privacy ones. The second is classifying once and never revisiting, when the systems in use change every quarter.

The unglamorous work — an inventory that is current, a written reason per classification, and a named person for oversight — is what a supervisory authority will ask for. It is also the part that takes months if it is started late.

This article is general information about a regulation, not legal advice on your situation. Confirm current dates and guidance before relying on any of it.

Ready to see it on your documents?

Book a demo and we will run the platform against a sample of your contracts or matters, in your jurisdiction.