Two things happened to the EU AI Act this year, and they pull in opposite directions. The transparency obligations in Article 50 became applicable on 2 August 2026.[1] Shortly before that, the Digital Omnibus deferred the high-risk regime — the part most compliance programmes were built around — to 2 December 2027 for standalone Annex III systems, and to 2 August 2028 for systems embedded in regulated products.[1][2]

The result is a widespread misreading in both directions: firms that believe the whole Act was postponed, and firms that have started building a high-risk conformity programme two years early. Neither is right, and the distinction is easy to state.

A firm is a deployer, not a provider

Almost every obligation in Article 50 is addressed to one of two roles, and which one you occupy decides most of the answer. A provider develops an AI system and places it on the market. A deployer uses one under its own authority. A law firm buying a legal AI platform is a deployer.

The provider obligations are the ones that get quoted: telling users they are interacting with an AI system, and marking synthetic audio, image, video and text in a machine-readable, detectable format.[3] Those are your vendor's obligations, not yours. The right response is to ask the vendor how it discharges them, not to build the capability yourself.

The deployer duties, and why most legal work escapes them

Article 50 imposes three duties on deployers. Two of them a law firm is unlikely to touch: disclosing deepfakes depicting real persons, places or events, and informing people exposed to emotion recognition or biometric categorisation systems.[3]

The third looks closer to home and then turns away. A deployer publishing AI-generated or manipulated text for the purpose of informing the public on matters of public interest must disclose that it is artificial. But the obligation expressly does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.[3]

That exemption describes the ordinary shape of supervised legal drafting. A submission drafted with AI assistance, reviewed by the practitioner responsible for it and filed under that practitioner's name, has a human holding editorial responsibility by construction. The firm whose workflow has a real approval gate is outside the disclosure duty; the firm whose workflow does not is the one that has to think about it. Assistive editing functions — grammar correction and minor alterations — are separately exempt.[3]

Deferred is not cancelled

The Omnibus moved the high-risk dates; it did not remove the regime. Annex III systems now have until 2 December 2027, and legacy generative systems already on the market have until 2 December 2026 to meet the marking obligations.[1] Prohibitions on unacceptable practices and the general-purpose model obligations stayed on their original schedule.

The enforcement figure for Article 50 is up to €15 million or 3% of worldwide annual turnover.[1] For most firms the reputational exposure of getting this wrong in front of a client arrives long before the fine does.

What actually constrains a firm today

Here is the part that a compliance programme organised around the AI Act tends to miss. For a firm processing client matters, the binding constraints in Europe today are mostly not in the AI Act at all.

  • Professional secrecy. In civil-law jurisdictions the duty is criminal, not merely regulatory, and it attaches to disclosure to a third party — which is what sending matter content to a processor is, unless something in the architecture prevents it.
  • Data protection. Article 32 security of processing, Article 30 records, Article 35 impact assessments and the international transfer rules apply to AI processing exactly as they apply to everything else, and they applied before the AI Act existed.
  • Client mandates. Outside-counsel guidelines that restrict third-party AI processing are contractual, immediate, and increasingly common — and they do not wait for December 2027.

A firm that answers those three well will find the AI Act's deployer duties largely already satisfied. A firm that builds an AI Act programme first will have documentation without an answer to the question its clients are actually asking.

A short reading list for the next eighteen months

Confirm with each vendor how it meets the Article 50 provider obligations and get the answer in writing. Establish whether any system you deploy is likely to fall into Annex III when the high-risk regime applies, because the classification work takes longer than the remediation. And record which practitioner holds editorial responsibility for AI-assisted output — the exemption that keeps most legal drafting outside the disclosure duty is the same evidence you would want in a professional-conduct question.

This page states our reading, dated. It is not legal advice, and the regulation has already moved once this year.