The EU AI Act in Law Firms: What Applies Starting in August 2026—and What Doesn’t
On August 2, 2026, the transparency requirements of the EU AI Act will take effect—including for law firms. What is now required, what the Omnibus Directive postpones, and what you should do.
Check which Jurono starting point fits your firm.
See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.
On August 2, 2026, a new phase of the EU AI Act will begin: The transparency obligations under Article 50 will take effect, and authorities will be able to enforce compliance for the first time. At the same time, the so-called Digital Omnibus has postponed the high-risk obligations—which many had recently warned about—until the end of 2027. These two conflicting pieces of news are currently causing considerable confusion—even among law firms. This article clarifies what will actually apply starting in August, what has been postponed, and what steps make sense to take now. It is not a substitute for legal advice in individual cases, but it provides a solid working basis.
What Actually Takes Effect on August 2, 2026
The AI Regulation (Regulation (EU) 2024/1689) has been in force since August 1, 2024, and will be phased in gradually. Prohibited practices under Article 5—such as manipulative systems, social scoring, or certain forms of biometric surveillance—have been banned since February 2, 2025. The requirement for AI competence under Article 4 has also been in effect since that same date: Anyone who uses AI systems must ensure that the individuals involved possess a sufficient level of knowledge. Separate obligations have applied to providers of general AI models (GPAI) since August 2025.
August 2, 2026, marks the full implementation of the transparency requirements under Article 50. For law firms, three regulations are particularly relevant in practice.
First, it must be clear when people are interacting with an AI system. Anyone using a chatbot or an AI-powered phone system on a law firm’s website must inform visitors and callers that they are not dealing with a human—unless this is obvious from the outset.
Second, AI-generated or AI-manipulated content must be labeled in a machine-readable format. For generative systems that were already on the market before the effective date, the Digital Omnibus Act provides for a transition period until December 2, 2026.
Third, Article 50(4) concerns synthetic content: deepfakes must be visibly disclosed as artificially generated. AI-generated texts that serve to inform the public on matters of public interest must be labeled as AI-generated—with one important exception for law firms: The labeling requirement does not apply if the content has undergone editorial review and a natural or legal person bears editorial responsibility for the publication. Anyone who uses AI as a writing assistant but carefully reviews and approves the content should generally be exempt from this obligation. Detailed questions have not yet been fully clarified; in May 2026, the European Commission issued guidelines on Article 50 for public consultation, and the final version is still pending.
Another new aspect is practical enforceability: Market surveillance and the imposition of sanctions for these obligations will begin on the effective date. Violations of the transparency rules can be penalized with fines of up to 15 million euros or 3 percent of global annual turnover; for small and medium-sized enterprises, the lower of the two amounts applies.
What the Digital Omnibus Has Postponed—and What It Has Not
The Digital Omnibus on AI (Procedure 2025/0359(COD)) is the first substantial amendment to the AI Regulation, even before its core high-risk obligations have become applicable. The European Parliament approved the text on June 16, 2026, and the Council adopted it on June 29, 2026. As of press time (July 24, 2026), publication in the Official Journal was still pending; the legal act will enter into force on the third day following publication. Until then, the original version remains formally in effect—but planning should nevertheless be based on the new deadlines.
An overview of the most important changes: Standalone high-risk systems as defined in Annex III—such as AI used in personnel selection, in the education sector, or for creditworthiness assessments—will not be required to comply with the full obligations until December 2, 2027, rather than August 2026. AI as a safety component of regulated products (Annex I) will follow on August 2, 2028. The AI competence requirement under Article 4 is being relaxed from a strict obligation to a duty of best efforts: In the future, it will suffice to do one’s best to ensure AI competence; but this does not mean it has been abolished. Newly added are prohibitions against AI systems that generate non-consensual intimate depictions or depictions of abuse. Apart from the aforementioned transition period, nothing changes in Article 50.
Which AI Systems in Law Firms Are Typically Affected
Under the regulation, law firms almost always act as operators, not as providers: they use AI systems developed by others. This limits their obligations but does not exempt them from them. An honest assessment is likely to reveal four groups in most law firms.
Text assistance, summaries, and research tools make up the most common group—ranging from dictation functions to legal databases with AI analysis to general language models for drafting. According to the Regulation’s risk model, these applications generally pose a minimal risk and do not trigger any specific obligations. This does not mean that everything is permitted here: professional ethics and data protection continue to apply in full; more on that shortly.
A chatbot on a law firm’s website or an AI telephone assistant falls directly under Article 50(1). Labeling such systems as AI systems will be mandatory starting in August. Law firms that already handle their initial client interactions digitally should review where AI comes into contact with clients and how this is disclosed—our experiences with digital client onboarding show just how closely transparency and providing good initial information are linked.
AI-supported application processes constitute the third group—and the only one in which law firms themselves can fall into the high-risk category. Annex III, Section 4 covers AI systems used in employment and human resources management, such as for pre-screening job applications. Thanks to the Omnibus Regulation, the deadline for this is now December 2, 2027. Law firms that use or plan to use such recruiting tools should keep an eye on this deadline and have the provider confirm the roadmap to compliance.
The fourth group regularly leads to misunderstandings: Annex III, Section 8 concerns AI in the administration of justice—specifically, systems that assist courts and authorities in researching, interpreting, or applying the law to specific cases. A law firm that uses legal research software does not automatically become the operator of a high-risk system. Nevertheless, it is worth reviewing the provider’s documentation: Reputable providers specify how they classify their system, and this classification should align with the user’s own purposes.
Professional Ethics and Data Protection Remain the Harder Currency
At its core, the AI Act is a law on product safety and market regulation. It does not alter the obligations that actually shape day-to-day client work: attorney-client privilege under § 43a(2) of the Federal Lawyers’ Act (BRAO), the criminal law protection of professional secrecy under § 203 of the German Criminal Code (StGB), and the GDPR. These levels run parallel to the AI Act—and for law firms, they are almost always the stricter ones.
Specifically, this means: Client confidentiality does not belong in consumer versions of general AI services whose terms of use provide for training with input data. Where personal client data is processed, data processing under contract pursuant to Article 28 of the GDPR is required, along with clarity regarding the location of processing and robust confidentiality commitments from the service provider. Whether a specific AI tool meets these requirements must be assessed on a case-by-case basis—our checklist for new tools in law firms provides a structured set of criteria for this purpose. And for those currently comparing providers in general, our article on the law firm software comparison outlines criteria that go beyond the AI Act.
Five Steps Law Firms Should Take Now
The deadline is just a few days away. Realistically, however, most law firms don’t need to launch major projects—they just need to thoroughly handle a few manageable tasks.
First, conduct an honest AI inventory. It’s not just the officially procured systems that count, but also the “hidden” ones: the translation assistant in the browser, the AI feature in the Office suite, the transcription tool for dictations. Without this list, any further measures will remain piecemeal.
Second, set up the necessary disclosures. The website chatbot needs a clear label; for AI-supported content, the law firm should specify who performs editorial review and assumes responsibility—and briefly document this.
Third, organize AI expertise. Even as a duty of care, Article 4 remains the practical lever: a brief internal guideline, training for all AI users, and a clear rule specifying which data may be entered into which systems. This constitutes the due diligence required by professional ethics and serves as evidence of due diligence in the event of a serious incident.
Fourth, assign responsibility. One person should serve as the central point of contact for AI matters at the firm, maintain an inventory of AI tools, and coordinate inquiries with providers. Fifth, inquire with providers about labeling functions, documentation, training data usage, and their roadmap for meeting high-risk requirements starting in 2027.
Oversight and Fines: The AI-MIG Has Been Enacted
In parallel with developments at the European level, Germany has established its national enforcement framework. The Bundestag passed the AI Market Surveillance and Innovation Promotion Act (AI-MIG) on June 11, 2026, and the Bundesrat approved it on July 10, 2026. The law takes effect the day after its promulgation. The Federal Network Agency will serve as the central market surveillance authority; it will also operate a coordination and competence center, a central complaints office, and a free AI service desk designed to provide guidance, particularly to smaller organizations. AI real-world labs, where applications can be tested under supervision, round out the offerings—with priority given to small and medium-sized enterprises. The AI-MIG does not impose new registration requirements on users.
The penalty scale set forth in the regulation remains relevant: Fines of up to 35 million euros or 7 percent of annual revenue may be imposed for prohibited practices; up to 15 million euros or 3 percent for violations of other obligations such as transparency rules; and up to 7.5 million euros or 1 percent for providing false information to authorities. For small and medium-sized enterprises, the lower of the two amounts applies. Realistically, regulators will initially focus on complaints and obvious violations—but no law firm should rely on that.
Conclusion: Use the breathing room, don’t just wait it out
For law firms, the situation can be summed up in one sentence: Starting August 2, 2026, transparency will be key; the high-risk tasks will come later. Law firms that get their chatbots, labeling, and internal rules in order now have covered the essentials—and, in the process, laid the groundwork for the obligations that will follow in 2027. The postponement resulting from the Omnibus Act is therefore less a “all-clear” than a window of opportunity to get work done.
Digital law firm platforms like Jurono can help establish this order: consolidating inquiries, documents, and responsibilities in one place instead of scattering them across inboxes and individual tools. Anyone interested in exploring what structured client processes might look like in their own law firm can find an overview on the Jurono platform page and get started there with no obligation.
Jurono Editorial Team
July 24, 2026
Keep reading
Digitalise your firm?
See how Jurono structures your client intake.
Declining Client Inquiries: Five Workflow Mistakes Law Firms Should Avoid
Rejected Client Inquiry: What Law Firms Delete—and What They Are Allowed to Keep for Conflict Checks
Hiring External ReFa: How Law Firms Regulate Access, Confidentiality, and Handover
Turn magazine insight into a concrete starting point
Evaluate Jurono the privacy-compliant way
See how Jurono unites data protection, client intake and file management in one system – GDPR-compliant and proven in practice.