
EU AI Act
The EU AI Act (Regulation (EU) 2024/1689): From legal obligation to operating reality
The EU AI Act creates a risk-based regulatory framework for organisations that develop, provide, deploy, import, distribute or materially modify AI systems. For most law firms, the immediate task is to establish which AI systems are being used, determine the firm's role, classify the use cases, identify the applicable obligations and create evidence that those obligations are being addressed.
The Risk Framework
Four categories of obligation
Prohibited practices
Certain uses of AI are prohibited because of their potential impact on rights, safety and human autonomy.
Praxis helps organisations screen internal, employment, client-facing and third-party systems for prohibited-practice triggers.
High-risk systems
AI can be classified as high-risk where it is used in specified sensitive areas or incorporated into regulated products.
Employment and worker management, education, access to essential services, biometrics, migration and certain justice-related systems require particular attention. The AI Omnibus has extended the application timetable for the principal high-risk rules.
Transparency obligations
People must be informed in specified circumstances when they are interacting with AI or encountering certain AI-generated or manipulated content.
Article 50 transparency requirements apply from 2 August 2026.
Limited or minimal-risk systems
Many everyday AI tools may fall outside the high-risk categories, although their use can still create significant professional, contractual, confidentiality, data protection and governance exposure.
Regulatory classification is only one part of the firm's risk assessment.
Organisational Roles
The firm's role determines its obligations
Deployer
Provider
Importer
Distributor
Product manufacturer
Authorised representative
A law firm using an AI tool within its professional activities will commonly be a deployer. Different obligations can arise where an organisation develops an AI system, places it into service under its own name, materially modifies it or changes its intended purpose.
Role mapping must be completed for each material system and use case.
Full Regulatory Timeline
The EU AI Act implementation schedule
Statuses are determined by the current date. Regulatory information last reviewed on 18 August 2026. Timelines and guidance may be amended. Praxis monitors relevant regulatory developments and updates this page accordingly.
1 August 2024
EU AI Act enters into force
The EU AI Act entered into force, establishing the risk-based regulatory framework for artificial intelligence across the European Union.
2 February 2025
AI literacy and initial prohibited practices
The initial prohibited AI practices, relevant definitions and the AI literacy obligation began to apply. Organisations using AI should already be taking measures to ensure an appropriate level of AI literacy among staff and others operating AI systems on their behalf.
2 August 2025
Governance and GPAI obligations begin
Governance rules and obligations for providers of general-purpose AI models began to apply.
27 July 2026
AI Omnibus amendments enter into force
The AI Omnibus amendments entered into force, introducing targeted amendments and extending the application dates for the principal high-risk rules.
2 August 2026
Transparency obligations and most remaining provisions
Most remaining provisions of the Act apply. Article 50 transparency obligations apply. The European Commission's enforcement powers relating to providers of general-purpose AI models also begin to apply.
December 2026
Additional prohibited practice from AI Omnibus
The additional prohibited practice introduced through the AI Omnibus begins to apply. This concerns AI systems used to generate certain non-consensual sexually explicit or intimate content and child sexual abuse material.
2 August 2027
GPAI models placed on market before August 2025
Providers of general-purpose AI models placed on the market before 2 August 2025 must comply with the applicable GPAI obligations.
2 December 2027
High-risk rules for Annex III use cases
The high-risk rules for AI systems used in specified sensitive areas under Annex III apply.
2 August 2028
High-risk rules for regulated products
The high-risk rules for AI systems embedded in regulated products under Annex I apply.
Practical Readiness
What organisations need in practice
AI system and use-case inventory
Organisational role mapping
Prohibited-practice screen
High-risk trigger assessment
Transparency assessment
AI literacy programme
Approved and prohibited use framework
Data, confidentiality and privilege controls
Human oversight and verification procedures
Vendor and procurement controls
Incident and escalation process
Governance records and readiness file
Leadership reporting
Ongoing regulatory monitoring
Law Firms and the AI Act
Legal-sector use cases
Drafting and summarisation
Legal research
Document review
Client intake chatbots
Contract analysis
Litigation support
Translation
Marketing content
Recruitment and performance management
Client risk profiling
Knowledge management
Automated client communication
The same tool may produce a different risk profile depending on the data, users, purpose, workflow and influence of its output.
Law Society Guidance
Professional obligations remain fully engaged
The Law Society of Ireland's guidance on generative AI emphasises professional competence, confidentiality, independence, accuracy, supervision and the responsible verification of AI-assisted work.
AI does not displace the solicitor's responsibility for the accuracy and reliability of professional work. Firms need clear rules concerning permitted use, safeguards, review, accountability and the protection of client information.
Praxis brings the regulatory and professional-governance layers together in one operating framework.
