The AI Act imposes new rules on law firms using LegalTech solutions, as users and those responsible for technological choices. The article details the obligations of lawyers and developers, the distinction between limited or high-risk tools, and the requirements regarding confidentiality and data sovereignty.
The AI Act regulation introduces a major distinction between **providers** and **deployers** of artificial intelligence systems. For law firms as well as LegalTech developers, understanding this division of roles is essential.
LegalTech developers, creators of solutions such as predictive analysis or automated writing tools, are considered **providers**. As such, they must comply with all the requirements of the AI Act regulation: technical documentation, risk management, transparency regarding the functioning of the systems. Law firms, for their part, are **deployers** when they use these technologies in their practice, which implies responsibility for the choice, supervision, and compliance of the tools, in accordance with the professional ethical rules.
AI Act and LegalTech: What are the responsibilities for lawyers and developers?
This complementarity requires close cooperation: providers must deliver comprehensive documentation on the limits and safeguards of their AI, while lawyers are required to ensure that the use of these tools respects professional secrecy and confidentiality. EU Regulation 2024/1689 requires deployers to verify the compliance of the systems used.
LegalTech tools concerned: How to classify them under the AI Act?
Not all LegalTech tools integrating AI are subject to the same constraints. Their classification depends on their purpose and their impact on legal decision-making.
**Document research** solutions (e.g., Lexis+ AI or Doctrine) are generally classified as **limited risk**. They must inform the user that they are interacting with an AI, but do not require a heavy compliance procedure. Conversely, tools for **predictive litigation analysis** or **judicial decision support** may be considered **high risk** if their use directly influences a legal or judicial decision.
The AI Act Glossary details that high-risk systems require a risk assessment, complete technical documentation, and permanent human oversight. Thus, a writing tool like Harvey AI will often fall under limited risk, while a litigation prediction tool will require reinforced compliance.
**Limited risk:**
- Document research
- Case law summary
- Assisted writing
**High risk:**
- Predictive litigation analysis
- Judicial decision support tools
- Legal risk scoring
**Prohibited:**
- Systems seeking to manipulate judicial decisions or circumvent the rights of the defense
High-risk systems: Focus on Annex III.8
The Annex III of the AI Act regulation lists AI systems considered high risk, particularly those used in the judicial sector.
According to Annex III.8, AI used by or on behalf of judicial authorities to perform the following are high risk:
- searching for facts or evidence,
- interpreting or applying the law to concrete situations.
This definition also covers tools used by lawyers if they directly influence a judicial decision. For example, a system that predicts the outcome of a dispute and guides a client's strategy falls into this category. The developers of such tools must then meet strict requirements: detailed documentation, traceability, and human oversight.
> "A lawyer using an AI to anticipate the outcome of a trial assumes professional liability if the prediction influences a strategic decision without human control."
In 2024, the National Bar Council (CNB) published a guide on AI and ethics, insisting on the vigilance to be adopted regarding AI tools. This guide recalls that the lawyer remains responsible for the advice provided, even when it is based on an AI.
Confidentiality, professional secrecy, and data sovereignty under the AI Act
Data entrusted to a lawyer is subject to enhanced protection. The use of AI tools thus poses major challenges in terms of confidentiality.
**Professional secrecy** and the **GDPR** require lawyers to ensure the security of client information. Using AI hosted outside the EU, particularly on American clouds, presents a legal risk: the Cloud Act allows American authorities to access data stored by American companies, even if they are hosted in Europe.
To comply with the AI Act and the GDPR, it is recommended to favor sovereign solutions, hosted in the European Union and compliant with European data protection standards. LegalTech developers must also document the confidentiality measures implemented. The CNIL recommends:
- data encryption,
- anonymization or pseudonymization of sensitive data,
- hosting on servers located in the EU.
Lawyers also have an obligation to inform their clients of the use of AI in the management of their case, in accordance with the transparency rules of the AI Act regulation and the GDPR.
Increased responsibility of lawyers regarding AI: Issues and precautions
The integration of AI tools into the activity of law firms creates new legal risks.
A lawyer who relies on an AI to advise a client sees their **professional liability** engaged. In the event of an error or bias in the AI, they could be held responsible, especially if the use has not been properly supervised and documented. The AI Act accentuates this responsibility by imposing obligations of **human oversight** and **traceability** on deployers of high-risk systems.
LegalTech developers are also concerned. As providers, they must guarantee the compliance of their tools: transparency, risk management, documentation. In case of failure, their civil or criminal liability may be engaged. Contracts between firms and developers must therefore specify the responsibilities and guarantees of each party.
**Deployer obligations:**
- Selection of tools
- Human oversight
- Traceability of decisions
- Informing the client
**Provider obligations:**
- Technical documentation
- Transparency
- Risk management
- GDPR compliance
**Risks incurred:**
- Engagement of professional liability
- Sanctions related to the AI Act
- Reputational damage
To limit these risks, it is advisable for firms to define an **AI usage policy**: team training, regular assessment of tools, documentation of supervision processes. Developers must integrate AI Act compliance from the design stage, via a *privacy by design* and *security by design* approach.
To learn more: consult the official text of EU Regulation 2024/1689, the AI Act glossary, Annex III, Annex IV, the CNB guide, and the CNIL recommendations.