Monochrome modern European Union building with a row of EU flags waving outside

EU AI Act

The EU AI Act (Regulation (EU) 2024/1689): From legal obligation to operating reality

The EU AI Act creates a risk-based regulatory framework for organisations that develop, provide, deploy, import, distribute or materially modify AI systems. For most law firms, the immediate task is to establish which AI systems are being used, determine the firm's role, classify the use cases, identify the applicable obligations and create evidence that those obligations are being addressed.

The Risk Framework

Four categories of obligation

01

Prohibited practices

Certain uses of AI are prohibited because of their potential impact on rights, safety and human autonomy.

Praxis helps organisations screen internal, employment, client-facing and third-party systems for prohibited-practice triggers.

02

High-risk systems

AI can be classified as high-risk where it is used in specified sensitive areas or incorporated into regulated products.

Employment and worker management, education, access to essential services, biometrics, migration and certain justice-related systems require particular attention. The AI Omnibus has extended the application timetable for the principal high-risk rules.

03

Transparency obligations

People must be informed in specified circumstances when they are interacting with AI or encountering certain AI-generated or manipulated content.

Article 50 transparency requirements apply from 2 August 2026.

04

Limited or minimal-risk systems

Many everyday AI tools may fall outside the high-risk categories, although their use can still create significant professional, contractual, confidentiality, data protection and governance exposure.

Regulatory classification is only one part of the firm's risk assessment.

Organisational Roles

The firm's role determines its obligations

Deployer

Provider

Importer

Distributor

Product manufacturer

Authorised representative

A law firm using an AI tool within its professional activities will commonly be a deployer. Different obligations can arise where an organisation develops an AI system, places it into service under its own name, materially modifies it or changes its intended purpose.

Role mapping must be completed for each material system and use case.

Full Regulatory Timeline

The EU AI Act implementation schedule

Statuses are determined by the current date. Regulatory information last reviewed on 18 August 2026. Timelines and guidance may be amended. Praxis monitors relevant regulatory developments and updates this page accordingly.

1 August 2024

Already applicable

EU AI Act enters into force

The EU AI Act entered into force, establishing the risk-based regulatory framework for artificial intelligence across the European Union.

2 February 2025

Already applicable

AI literacy and initial prohibited practices

The initial prohibited AI practices, relevant definitions and the AI literacy obligation began to apply. Organisations using AI should already be taking measures to ensure an appropriate level of AI literacy among staff and others operating AI systems on their behalf.

2 August 2025

Already applicable

Governance and GPAI obligations begin

Governance rules and obligations for providers of general-purpose AI models began to apply.

27 July 2026

Already applicable

AI Omnibus amendments enter into force

The AI Omnibus amendments entered into force, introducing targeted amendments and extending the application dates for the principal high-risk rules.

2 August 2026

Already applicable

Transparency obligations and most remaining provisions

Most remaining provisions of the Act apply. Article 50 transparency obligations apply. The European Commission's enforcement powers relating to providers of general-purpose AI models also begin to apply.

December 2026

Future milestone

Additional prohibited practice from AI Omnibus

The additional prohibited practice introduced through the AI Omnibus begins to apply. This concerns AI systems used to generate certain non-consensual sexually explicit or intimate content and child sexual abuse material.

2 August 2027

Future milestone

GPAI models placed on market before August 2025

Providers of general-purpose AI models placed on the market before 2 August 2025 must comply with the applicable GPAI obligations.

2 December 2027

Future milestone

High-risk rules for Annex III use cases

The high-risk rules for AI systems used in specified sensitive areas under Annex III apply.

2 August 2028

Future milestone

High-risk rules for regulated products

The high-risk rules for AI systems embedded in regulated products under Annex I apply.

Practical Readiness

What organisations need in practice

01

AI system and use-case inventory

02

Organisational role mapping

03

Prohibited-practice screen

04

High-risk trigger assessment

05

Transparency assessment

06

AI literacy programme

07

Approved and prohibited use framework

08

Data, confidentiality and privilege controls

09

Human oversight and verification procedures

10

Vendor and procurement controls

11

Incident and escalation process

12

Governance records and readiness file

13

Leadership reporting

14

Ongoing regulatory monitoring

Law Firms and the AI Act

Legal-sector use cases

Drafting and summarisation

Legal research

Document review

Client intake chatbots

Contract analysis

Litigation support

Translation

Marketing content

Recruitment and performance management

Client risk profiling

Knowledge management

Automated client communication

The same tool may produce a different risk profile depending on the data, users, purpose, workflow and influence of its output.

Law Society Guidance

Professional obligations remain fully engaged

The Law Society of Ireland's guidance on generative AI emphasises professional competence, confidentiality, independence, accuracy, supervision and the responsible verification of AI-assisted work.

AI does not displace the solicitor's responsibility for the accuracy and reliability of professional work. Firms need clear rules concerning permitted use, safeguards, review, accountability and the protection of client information.

Praxis brings the regulatory and professional-governance layers together in one operating framework.

Turn the legislation into a practical programme of work.