# The EU AI Act After 2 August 2026: Obligations for Law Firms and Family Offices

> EU AI Act duties for law firms and family offices from 2 August 2026: AI literacy, Article 50 transparency, Article 99 penalties — high-risk duties from 2 December 2027.

Author: Dana Berzeg — Attorney-at-law, Family Office (https://wiki.private.law/en/authors/berzegova)
Last modified: 2026-09-01T23:44:00.000Z
Canonical: https://wiki.private.law/en/eu-ai-act-law-firms
Topics: structures
Jurisdictions: eu
Product tags: compliance, family-office
Semantic tags: compliance, family-office

---

The EU Artificial Intelligence Act — [Regulation \(EU\) 2024/1689](https://eur-lex.europa.eu/eli/reg/2024/1689/oj) — is the European Union's horizontal law on artificial intelligence. It entered into force on 1 August 2024 and became generally applicable on 2 August 2026 under its Article 113. Instead of regulating a sector, it attaches to the technology wherever it is professionally used and distributes obligations by role. The **provider** that develops an AI system or places it on the EU market carries the product side of the regime — conformity assessment, documentation, marking. The **deployer** — any natural or legal person using an AI system under its own authority in a professional context \(Article 3\(4\)\) — carries a separate, lighter set of use-side duties. A law firm running a legal-research assistant, a drafting or transcription tool or a CV-screening system, and a family office using AI for document analysis, reporting or hiring, acts in almost every case as a deployer. Only use by a natural person in a purely personal, non-professional activity sits outside the Act \(Article 2\(10\)\); professional use is in scope, and so is a firm established outside the EU where the system's output is used in the Union \(Article 2\(1\)\).

For a professional-services organisation the Act creates no licence and no registration. Its legal effect is a supervised conduct regime layered onto ordinary work with vendor tools: staff who operate AI must have a sufficient level of AI literacy \(Article 4\); a short list of practices — including emotion recognition in the workplace — is prohibited outright \(Article 5\); defined disclosures are owed when AI interacts with people, generates synthetic content or produces text published to inform the public \(Article 50\); and, for a catalogue of sensitive uses such as recruitment screening, a governance package of human oversight, monitoring, log retention and worker information attaches under Article 26.

The calendar is the part most often misread. The Digital Omnibus on AI — [Regulation \(EU\) 2026/1744](https://eur-lex.europa.eu/eli/reg/2026/1744/oj), published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — amended the AI Act days before the general-application milestone and deferred the high-risk obligations. Duties for systems classified high-risk under Annex III \(employment, creditworthiness assessment, administration of justice, among others\) now apply from **2 December 2027**, and the rules for AI embedded in regulated products under Annex I from **2 August 2028**, as confirmed by the [European Commission](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai). What became enforceable on 2 August 2026 is narrower and use-facing: the Article 50 transparency duties, national market-surveillance enforcement, and the Commission AI Office's enforcement powers over general-purpose AI model providers.

Three structural features distinguish this regime from the frameworks law firms and family offices already know. First, it reaches ordinary users of vendor tools: where GDPR attaches to the processing of personal data and DORA to licensed financial entities, the AI Act binds any organisation that professionally uses an in-scope system. Second, it phases by risk class rather than by entity — the same firm faces one rulebook today, a heavier one from December 2027 and a peripheral one in 2028. Third, its penalty scheme carries a small-and-medium-enterprise correction: for SMEs the lower of the fixed amount and the turnover percentage applies, which materially caps the exposure of most firms and family offices. The whole structure operates without prejudice to data-protection law \(Article 2\(7\)\) — the AI Act adds to GDPR; it replaces nothing. The high-risk rules arriving in 2027 are the reason to read the regime now: the recruitment, screening and assessment tools a firm procures in 2026 will still be running when Article 26 starts to apply to them.

> 🍓 **Position at general application.** Three duty families bind a law firm or family office using AI today: AI literacy \(Article 4, applicable since 2 February 2025 and supervised since 2 August 2026\), the Article 5 prohibitions \(since 2 February 2025, extended from 2 December 2026\), and Article 50 transparency \(since 2 August 2026\). The Annex III high-risk machinery — the heaviest layer for professional users — starts on 2 December 2027, not in 2026.

## Scope: the deployer role

Article 2\(1\)\(b\) applies the Act to deployers that have their place of establishment or are located in the Union; third-country deployers are also caught where the output of the system is used in the Union. Article 3\(4\) defines a deployer as a natural or legal person using an AI system under its authority, except in the course of a personal non-professional activity. Between those two provisions, essentially every professional use of AI inside a law firm or a family office — a research assistant, an internal chatbot, a transcription pipeline, an HR screening tool — places the organisation in the deployer role, whether or not it ever develops a line of code.

The role follows the organisation's actual conduct rather than any contractual label.

> ⚠️ **The reclassification trap.** Under Article 25 a deployer becomes a provider of a high-risk AI system — inheriting the full provider duty set — if it puts its own name or trademark on the system, substantially modifies it, or changes its intended purpose so that the system becomes high-risk. White-labelling a vendor tool as the firm's own product, or deeply customising a model for a high-risk use, moves the firm across that line.

The Act also states its own boundary with data protection: under Article 2\(7\) it is without prejudice to Regulation \(EU\) 2016/679 \(GDPR\), Regulation \(EU\) 2018/1725, Directive 2002/58/EC and Directive \(EU\) 2016/680. Whenever an AI tool processes personal data — which in a law firm is nearly always — GDPR applies in parallel and in full.

## The application timeline

| Date | What applies | Basis |
| --- | --- | --- |
| 2 February 2025 | Article 5 prohibited practices; Article 4 AI literacy duty | Reg. \(EU\) 2024/1689, Art. 113 |
| 2 August 2025 | General-purpose AI model rules, governance framework, penalty provisions; Article 70 deadline for Member States to designate national competent authorities | Reg. \(EU\) 2024/1689, Art. 113 |
| 2 August 2026 | General application: Article 50 transparency duties, national market-surveillance enforcement, AI Office enforcement powers over general-purpose model providers | Reg. \(EU\) 2024/1689, Art. 113 |
| 2 December 2026 | New prohibitions in Article 5\(1\), points \(ba\) and \(bb\); end of the provider-side transitional window for machine-readable marking by generative systems placed on the market before 2 August 2026 | Reg. \(EU\) 2026/1744 |
| 2 December 2027 | Deployer and provider obligations for high-risk AI systems under Annex III, including Article 26 | Reg. \(EU\) 2026/1744 \(deferral\) |
| 2 August 2028 | Obligations for embedded high-risk AI under Article 6\(1\) and Annex I \(products such as machinery, lifts, toys\) | Reg. \(EU\) 2026/1744 \(deferral\) |

> 💡 Why the dates moved: the deferral is the work of [Regulation \(EU\) 2026/1744](https://eur-lex.europa.eu/eli/reg/2026/1744/oj), not of the original Act — obligations for Annex III high-risk systems now follow on 2 December 2027 and the Annex I embedded-product rules on 2 August 2028, while the duties already applicable — Articles 4, 5 and 50 and the Article 99 penalty framework — keep their original dates, as confirmed by the [European Commission](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai).

## Duties already binding on every professional AI user

### AI literacy — Article 4

Applicable since 2 February 2025, and under supervision and enforcement since 2 August 2026: an organisation deploying AI must ensure a sufficient level of AI literacy in the staff and other persons who operate AI systems on its behalf, taking account of their role and context. The AI Office has published AI literacy Questions and Answers and a living repository of more than forty practice examples \([Commission AI literacy page](https://digital-strategy.ec.europa.eu/en/policies/ai-talent-skills-and-literacy)\); replicating a repository practice grants no presumption of compliance. Article 99 assigns no dedicated fine tier to Article 4 — enforcement of the literacy duty runs through national arrangements — but it is the baseline every later duty assumes: Article 26 human oversight, for instance, must be staffed by people with the necessary competence and training.

### Prohibited practices — Article 5

The prohibitions have applied since 2 February 2025. The one with direct relevance to firms is Article 5\(1\)\(f\): emotion-recognition systems in the workplace are banned, which reaches monitoring and HR tools that claim to read employee emotional states. From 2 December 2026 the Digital Omnibus adds new prohibitions in points \(ba\) and \(bb\) of Article 5\(1\), directed at non-consensual intimate imagery and child sexual abuse material generation. Article 5 breaches carry the top penalty tier.

### Transparency — Article 50

The transparency duties took effect with general application on 2 August 2026. On the deployer side, a firm must inform persons exposed to emotion-recognition or biometric-categorisation systems, disclose deepfakes, and disclose AI-generated text that is published with the purpose of informing the public unless the text has passed through human editorial responsibility. On the provider side, systems interacting with natural persons must say so, and synthetic content must be marked in machine-readable form — with a transitional window until 2 December 2026 for generative systems placed on the market before 2 August 2026 \([Commission Article 50 FAQ](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act)\).

The guidance framework for these duties is complete. The Commission published its final [Guidelines on the Article 50 transparency obligations](https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems) on 20 July 2026, and the [Code of Practice on Transparency of AI-Generated Content](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content) \(final version 10 June 2026\) has been assessed by the Commission and the AI Board as an adequate voluntary tool for the marking and labelling obligations. The code is open to deployers as well as providers: a firm deploying generative AI may sign it to evidence its Article 50 compliance, though the underlying obligations bind whether or not it signs. For client-facing chatbots, published AI-assisted commentary and any deepfake-capable tooling, this is the operative duty set today.

## 2 December 2027: the high-risk layer

The high-risk regime is where the AI Act becomes an operating framework rather than a disclosure rule, and it is the layer the Omnibus moved to 2 December 2027. Classification runs through Article 6\(2\) and Annex III; three headings matter for this audience.

| Annex III heading | Covers | Typical exposure |
| --- | --- | --- |
| Point 4 — employment | Recruitment, screening and evaluation of workers | CV-screening and candidate-assessment tools used by the firm's own HR function — the clearest firm-side trigger |
| Point 5 — essential private services | Including creditworthiness assessment | Credit and counterparty scoring in a family-office context |
| Point 8 — administration of justice | Systems used by or on behalf of judicial authorities | Narrow: it targets court-side use, not a firm's own research tools |

When a deployed system falls under Annex III, Article 26 requires the deployer to:

- use the system in accordance with the provider's instructions, supported by appropriate technical and organisational measures;
- assign human oversight to persons with the necessary competence, training and authority;
- ensure that input data under the deployer's control is relevant and sufficiently representative;
- monitor operation and report risks and serious incidents;
- retain automatically generated logs for at least six months;
- inform workers' representatives and affected workers before putting high-risk AI to use in the workplace;
- inform natural persons subject to decisions made or assisted by the system;
- cooperate with competent authorities.
None of this is unfamiliar to an organisation that already runs GDPR governance, but it must exist as a documented, staffed arrangement — and the fifteen months to December 2027 are the period in which to build it around tools already in use.

## Penalties and enforcement

The Article 99 penalty provisions have applied since 2 August 2025.

| Breach | Maximum fine |
| --- | --- |
| Article 5 prohibited practices | €35 million or 7 % of worldwide annual turnover, whichever is higher |
| Other obligations, including Articles 26 and 50 | €15 million or 3 % of worldwide annual turnover, whichever is higher |
| Supplying incorrect information to authorities | €7.5 million or 1 % of worldwide annual turnover, whichever is higher |

For small and medium-sized enterprises each cap is read as the **lower** of the fixed amount and the percentage — the relevant ceiling for most law firms and family offices.

Enforcement is split by layer. Under Article 70, Member States had to designate their national competent authorities and publicise contact points by 2 August 2025; since 2 August 2026, national market-surveillance authorities, alongside the Commission's AI Office, are responsible for implementing, supervising and enforcing the Act — which is the channel that reaches deployers. From the same date the AI Office holds enforcement powers over general-purpose AI model providers: it can request technical documentation, evaluate models, require corrective measures and impose fines. The [General-Purpose AI Code of Practice](https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai) \(10 July 2025\), confirmed as an adequate voluntary tool with chapters on transparency, copyright and safety, is the compliance vehicle on that provider side — relevant to firms mainly as context for how their model vendors are supervised.

## The AI Act inside the wider compliance perimeter

The AI Act is one of four EU regimes that now frame the operations of a law firm or family office, each with its own object and its own dates. Reading them together prevents both double-compliance and false comfort.

| Regime | Object | Reach for a law firm or family office | Key dates |
| --- | --- | --- | --- |
| AI Act — Reg. \(EU\) 2024/1689 | Use and supply of AI systems | Deployer duties for professional AI use | General application 2 Aug 2026; Annex III duties 2 Dec 2027 |
| GDPR — [Reg. \(EU\) 2016/679](https://eur-lex.europa.eu/eli/reg/2016/679/oj) | Personal data | Applies whenever an AI tool processes personal data; Article 22 restricts solely automated decisions | Applicable since 2018; Article 22 unamended |
| DORA — [Reg. \(EU\) 2022/2554](https://eur-lex.europa.eu/eli/reg/2022/2554/oj) | ICT resilience of regulated financial entities | Reaches a family office only through a regulated entity it operates, such as an authorised AIFM; an unregulated single-family office is not among the Article 2 entity categories | Applicable 17 Jan 2025 |
| AML package — [Reg. \(EU\) 2024/1624](https://eur-lex.europa.eu/eli/reg/2024/1624/oj) | Client due diligence by obliged entities | Notaries, lawyers and other independent legal professionals are obliged entities when participating in specified transactions | Applies from 10 Jul 2027 |

The GDPR overlap deserves emphasis because it is not deferred. Article 22 GDPR gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. An AI-assisted recruitment, creditworthiness or client-screening decision therefore already sits under Article 22 today, even though the corresponding Annex III duties only arrive in December 2027. On the model layer, EDPB [Opinion 28/2024](https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf) \(adopted 17 December 2024\) sets the supervisory reading: whether a model is anonymous is a case-by-case assessment, legitimate interest can serve as a legal basis subject to the three-step test, and unlawfully processed training data can affect the lawfulness of subsequent deployment. It is guidance rather than binding law, but it is the reference point a firm should apply when selecting AI vendors.

### Deferred to 2 December 2027

- Annex III high-risk classification — Article 6\(2\)
- Article 26 deployer duties: oversight, input-data control, monitoring, log retention, worker information
### Already binding today

- GDPR Article 22 — solely automated decisions with legal or similarly significant effects
- AI Act Articles 4, 5 and 50 — literacy, prohibitions, transparency
The neighbouring regimes have their own canonical treatments: [DORA: What Operational Resilience Costs an EU Licence Holder](https://wiki.private.law/en/dora-eu) and [The EU AML Package: AMLR, AMLD6 and AMLA — What Actually Changes in 2027–2028](https://wiki.private.law/en/eu-aml-package).

## Confidentiality, privilege and professional duties

The Act touches professional secrecy at one point only: Article 78 obliges the authorities and bodies involved in applying the Regulation to respect the confidentiality of information and data obtained, including intellectual property and trade secrets. It contains no provision harmonising legal professional privilege or lawyers' secrecy duties — it does not displace national professional law and bar rules, which continue to govern what may be put into an AI system in the first place.

The profession's own framework fills that space. The CCBE — the Council of Bars and Law Societies of Europe — published a Guide on the use of generative AI by lawyers on 2 October 2025 and a Technical guide on the use of AI tools and models by lawyers on 27 March 2026. Their framing — understand the tool, keep client data out of unsecured models, verify outputs against fabrication risk, retain human oversight and professional independence — is guidance rather than law, but it is the standard bars will measure conduct against, and it dovetails with the Article 4 literacy duty and the Article 26 oversight duties.

## Preparing between now and December 2027

1. Inventory the AI in use: every tool, its provider, its function, and whether any use falls under Annex III points 4, 5 or 8.
2. Close the literacy gap under Article 4 with role-appropriate training, using the Commission's Questions and Answers and practice repository as reference material without treating replication as compliance.
3. Screen current and planned uses against Article 5 — workplace emotion recognition now, the new points \(ba\) and \(bb\) before 2 December 2026.
4. Implement the Article 50 disclosures for client-facing chatbots, deepfake-capable tools and AI-generated public content; consider signing the transparency Code of Practice as evidence.
5. Build the Article 26 file for any Annex III tool — oversight assignments, input-data controls, log retention of at least six months, worker-information procedures — ahead of 2 December 2027.
6. Hold the provider boundary: no rebranding, substantial modification or repurposing of vendor systems without accepting the Article 25 consequences, and keep the provider's instructions in the contract file.
## Q/A

### **Does a firm that only uses off-the-shelf AI assistants fall under the Act?**

Yes. Professional use of an AI system under the firm's authority makes it a deployer \(Article 3\(4\)\); the personal-use carve-out in Article 2\(10\) covers only natural persons acting outside any professional activity. The live obligations are the Article 4 literacy duty, the Article 5 prohibitions and, where the use matches an Article 50 category, the transparency disclosures. There is no registration, licence or notification requirement for deployers as such.

### **Must AI-generated documents be disclosed to clients?**

Article 50 attaches disclosure to specific categories rather than to AI-assisted work generally: informing persons exposed to emotion-recognition or biometric-categorisation systems, labelling deepfakes, and disclosing AI-generated text published with the purpose of informing the public unless it has passed through human editorial responsibility. A given communication is assessed against those categories. Separately, professional guidance — the CCBE guides — expects lawyers to verify AI outputs and preserve independence regardless of any labelling duty.

### **Are recruitment-screening tools high-risk?**

Yes. Annex III point 4 covers AI used for recruitment, screening and evaluation of workers, which is the clearest firm-side high-risk trigger. The Article 26 deployer duties for such systems apply from 2 December 2027 following the Omnibus deferral. GDPR Article 22 is not deferred: a solely automated hiring decision with significant effects is already restricted today.

### **What is the realistic fine exposure?**

Article 99 sets three tiers — up to €35 million or 7 % of worldwide turnover for prohibited practices, €15 million or 3 % for other obligations including Articles 26 and 50, and €7.5 million or 1 % for supplying incorrect information — with the higher of the two figures applying by default. For SMEs, which most law firms and family offices are, the lower of the two applies instead. The Article 4 literacy duty has no dedicated fine tier; it is enforced through national arrangements.

---

## Factual claims

- The EU Artificial Intelligence Act — Regulation (EU) 2024/1689 — is the European Union's horizontal law on artificial intelligence.
- Three structural features distinguish this regime from the frameworks law firms and family offices already know.
- Article 2(1)(b) applies the Act to deployers that have their place of establishment or are located in the Union; third-country deployers are also caught where the output of the system is used in the Union.
- The Act also states its own boundary with data protection: under Article 2(7) it is without prejudice to Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2018/1725, Directive 2002/58/EC and Directive (EU) 2016/680.
- The prohibitions have applied since 2 February 2025.
- The transparency duties took effect with general application on 2 August 2026.
- The high-risk regime is where the AI Act becomes an operating framework rather than a disclosure rule, and it is the layer the Omnibus moved to 2 December 2027.
- When a deployed system falls under Annex III, Article 26 requires the deployer to:

---

Source: wiki.private.law — the private.law legal knowledge base. When quoting, cite the canonical page URL.
Consultation with a lawyer: https://t.me/private_law_bot
