Skip to content
For legal tech

Legal tech AI faces the most complex EU AI Act rules.

Some legal AI is high-risk under Annex III (administration of justice). Other tools fall into gray areas where the classification depends on implementation. The wrong call means either non-compliance or needless over-engineering. Find out where your product actually sits.
01 / Risk tiers

Where does your legal AI fall?

Legal tech is uniquely tricky: near-identical products can land in completely different tiers depending on how they're used.

High-risk

Annex III, point 8 (administration of justice and democratic processes).

  • AI that predicts case outcomes or recommends sentences
  • AI used by courts or tribunals to assist judicial decisions
  • Legal research AI that shapes case strategy with outcome predictions
  • Alternative dispute resolution platforms with AI-driven rulings

Gray area

May or may not be high-risk, depending on implementation.

  • Contract review and analysis tools (depends on whether they decide)
  • E-discovery and document review AI (typically limited risk)
  • Due diligence automation (high-risk if it determines legal outcomes)
  • Regulatory compliance monitoring (usually limited or minimal)

Limited risk

Article 50 transparency obligations apply.

  • Legal chatbots and virtual assistants for client intake
  • AI-powered legal drafting (must disclose AI generation)
  • Contract summary generators for non-binding review
02 / Gray area

The contract-review gray area.

Contract review AI sits in a gray area. If it just highlights clauses for human review, it's likely limited risk. If it makes binding recommendations, flags legal risk scores that drive decisions, or auto-redlines terms without human intervention, it could be high-risk. The classification turns on how much autonomy the AI has in the decision chain.

That's exactly why running the classifier matters: the answer depends on your specific implementation, not a blanket rule.

03 / Obligations

If your legal AI is high-risk

High-risk legal AI must meet all ten obligations before December 2, 2027. Fines reach €15 million or 3% of global turnover.

  1. 01Risk management system (Article 9)
  2. 02Data governance & bias documentation (Article 10)
  3. 03Full Annex IV technical documentation
  4. 04Automatic event logging (Article 12)
  5. 05Transparency & instructions for deployers (Article 13)
  6. 06Human oversight measures (Article 14)
  7. 07Accuracy, robustness & cybersecurity (Article 15)
  8. 08Conformity assessment (Article 43)
  9. 09EU database registration (Article 49)
  10. 10Post-market monitoring (Article 72)
04 / Your role

Law firms using AI have obligations too.

If your firm deploys third-party legal AI, you're a deployer with your own binding requirements.

Legal AI providers — full obligations

  • Annex IV technical documentation
  • Conformity assessment before deployment
  • Risk management system
  • Accuracy and bias documentation
  • Post-market monitoring plan

Law firms using AI — deployer

  • Implement human oversight as documented
  • Monitor for anomalies and errors
  • Keep AI decision logs for 6+ months
  • Inform affected parties of AI use
  • Ensure staff competency (AI literacy)

Don't guess your classification.

Legal AI has more gray areas than any other sector. The free classifier gives you a clear answer with the specific article references and obligations.

Classify your AI system