Home 01Prompt Builder ✦About Adam 02Books 03Journal 04Contact 05
Home/Journal/Regulation
Regulation · Updated September 2026

The EU AI Act for lawyers: what applies now, and what the Omnibus moved

Six days before the headline August 2026 deadline, the EU changed the timetable. Some obligations slipped to 2027 and 2028. Others did not move at all. Here is the picture a lawyer needs — for their own firm, and for the clients who will ask.

13 min readInteractive timelineClient-advisory checklist

Key takeaways

  • The Digital Omnibus on AI entered into force on 27 July 2026.
  • High-risk duties for Annex III systems now apply from 2 December 2027; for AI in Annex I regulated products, from 2 August 2028.
  • Article 50 transparency obligations still applied from 2 August 2026 — with a watermarking grace period to 2 December 2026 for systems already on the market.
  • Prohibited practices and general-purpose AI model obligations were already in force and were not reopened.
Important: this is an educational overview, not legal advice. The Act and its amendments should be read in their consolidated form, alongside Commission guidance, before advising on any specific system.

The timeline at a glance

The gold marker shows where we are today. Filled markers have already passed.

1 August 2024The AI Act enters into force

Regulation (EU) 2024/1689 becomes law, with obligations phased in over the following years.

2 February 2025Prohibitions and AI literacy

Bans on unacceptable-risk practices apply, together with the Article 4 AI-literacy provision.

2 August 2025General-purpose AI models

Obligations for providers of general-purpose AI models apply, alongside governance and penalty provisions.

24–27 July 2026Digital Omnibus on AI

Published in the Official Journal on 24 July and in force on 27 July, deferring the high-risk timetable.

2 August 2026Transparency obligations (Article 50)

Disclosure duties for AI that interacts with people and for certain AI-generated content apply as originally scheduled.

2 December 2026Watermarking grace period ends

The end of the four-month grace period for marking AI-generated content from systems already on the market.

2 December 2027High-risk: Annex III systems

Obligations for stand-alone high-risk systems — including those used in employment, essential services and the administration of justice.

2 August 2028High-risk: Annex I products

Obligations for AI embedded in products already covered by EU product-safety legislation.

What the Digital Omnibus actually changed — and why

The European Commission proposed the Digital Omnibus on AI on 19 November 2025. Its reasoning was practical: neither industry nor the European standardisation bodies (CEN and CENELEC) were likely to be ready, and the conformity-assessment infrastructure the Act assumes had not matured in time.

The result is a deferral, not a cancellation. The substance of the high-risk regime remains. What moved is when it bites. For advisers, the most common error in autumn 2026 is telling clients “the AI Act was delayed” without distinguishing the parts that were not.

The Omnibus also revisited some supporting provisions, including how the AI-literacy duty is framed. Check the consolidated text for the current wording before relying on any summary — including this one.

Who it applies to (it may include you)

The Act uses roles rather than industries. The two that matter most for lawyers are:

  • Providers — those who develop an AI system, or have it developed, and place it on the market under their own name.
  • Deployers — those who use an AI system under their authority in a professional capacity. A law firm using an AI tool is a deployer.

Its reach is extraterritorial. It covers deployers located in the EU, and providers and deployers outside the EU where the output of the AI system is used in the EU. A firm in London, Dubai, Lahore or New York serving EU clients should not assume it is out of scope.

The four risk tiers, briefly

TierWhat it coversStatus
Unacceptable riskProhibited practices, such as social scoring and certain manipulative or exploitative systemsBanned since 2 February 2025
High riskAnnex III uses (e.g. employment, credit, essential services, law enforcement, migration, administration of justice) and Annex I product-safety usesDeferred to 2 December 2027 / 2 August 2028
Transparency riskChatbots and systems generating synthetic content that must be disclosed or markedApplies from 2 August 2026
Minimal riskMost other AI, such as spam filters or ordinary productivity toolsNo specific obligations; voluntary codes encouraged

Penalties are significant: up to €35 million or 7% of worldwide annual turnover for prohibited practices, up to €15 million or 3% for most other infringements, and up to €7.5 million or 1% for supplying incorrect information to authorities.

What it means for your own law firm

For most firms, day-to-day legal AI — drafting, summarising, research assistance — is not itself high-risk. But being a deployer still brings responsibilities and, just as importantly, client expectations. A sensible firm programme looks like this:

  1. Inventory the AI tools in use, including those individual lawyers adopted on their own.
  2. Classify each use. HR screening tools, for example, can fall into high-risk employment categories.
  3. Review vendor terms for data use, security certifications and the vendor’s own AI Act position.
  4. Be transparent where clients or the public interact with AI, such as website chatbots.
  5. Train people. Whatever the final framing of the literacy duty, competent use is also a professional-conduct obligation.
AI for Lawyers 2026 book cover
Regulation, explained for practitioners

AI for Lawyers 2026

The EU AI Act and professional-responsibility duties alongside the tools and 100 practical prompts.

See it on Amazon

Advising clients: the questions to ask

Clients building or buying AI will ask what the delay means for them. Start with these questions:

  • Are you a provider, a deployer, or both — for each system?
  • Is any output of the system used in the EU?
  • Does any use fall within an Annex III area? If so, is a compliance plan in place for December 2027?
  • Do any systems interact with people or generate content that triggers Article 50 disclosure now?
  • Do your contracts allocate AI Act responsibilities between vendor and customer?

Much of that work ends up in documents: AI-use policies, transparency notices, vendor and customer terms. For technology businesses, TECHLAWG prepares AI governance policies, disclosures and contracts, and its free policy checker is a useful first look at documentation gaps.

Outside the EU: the professional-conduct baseline

Even where the AI Act does not apply, professional rules do. In the United States, ABA Formal Opinion 512 (29 July 2024) applies existing Model Rules to generative AI across six areas: competence, confidentiality, communication with clients, candour toward the tribunal, supervision, and reasonable fees. Regulators and bar bodies elsewhere have issued comparable guidance. The practical overlap with the AI Act is large: understand your tools, protect data, tell people what they need to know, and keep a human responsible.

The most visible failure of that baseline is fabricated citations — see AI hallucinations in court for the cases and a verification checklist.

Frequently asked questions

Was the August 2026 AI Act deadline delayed?

Partly. High-risk obligations moved to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). Article 50 transparency obligations still applied from 2 August 2026, with a watermarking grace period to 2 December 2026 for systems already on the market.

Does the AI Act apply to firms outside the EU?

It can, where a provider places systems on the EU market or where the output of an AI system is used in the EU.

Is using ChatGPT or Claude in a law firm “high-risk”?

Ordinary drafting and summarising generally is not. Specific uses can be, such as AI for recruitment decisions, or AI intended to assist judicial authorities in researching and applying the law.

What should a firm do first?

Inventory the AI in use, classify each use, review vendor terms, write a short policy and train people. Organisational training can cover the last step.

Brief your whole team in one session

We deliver EU AI Act and AI-ethics sessions for firms, chambers and bar associations.