5–7 minutes
1,143 words

For law firms across Europe, the AI regulatory landscape changed again.The important date is still 2 August 2026 — but not because every major AI Act obligation suddenly applies on that day.Under the updated EU timeline, the AI Act’s Article 50 transparency obligations apply from 2 August 2026, including requirements concerning disclosure when people interact with certain AI systems and the labelling of certain AI-generated or manipulated content. The European Commission published detailed guidance on these obligations in July 2026.

At the same time, the application of the main rules for certain high-risk AI systems has been extended. The Commission now states that those rules apply from 2 December 2027, with AI embedded in regulated physical products following a later timeline.That creates an interesting situation for law firms.You have more time to prepare.

But you also have more time to make the mistake of doing nothing.

The Deadline Moving Doesn’t Remove the Governance Problem

Many law firms are already using AI for:

  • legal research;
  • document review;
  • drafting;
  • client communication;
  • knowledge management;
  • administrative workflows;
  • intake and triage.

The regulatory timetable does not change the fact that these systems are already interacting with professional obligations.A firm therefore shouldn’t begin its AI governance work when the next deadline arrives.It should begin by understanding what is already happening.

The first question is no longer:“Are we using AI?”

It is:“Do we actually know how AI is being used across our firm?”

The AI Visibility Problem

Imagine asking your firm’s management team:How many AI systems are currently being used by employees?Who approved them?What information is being entered?Which vendors process that information?Which systems retain data?Which outputs are being relied upon?Who reviews those outputs?What happens when something goes wrong?Can you answer all of those questions?

If not, the problem is not simply compliance.It is visibility.You cannot govern an AI system that you do not know exists.

The Data Question

Legal AI creates another fundamental governance issue:What data is going into these systems?

A lawyer might use AI to summarise a client document.Another might use an AI assistant to draft correspondence.Someone else might paste a confidential research problem into a general-purpose chatbot.Individually, these actions may appear small.Collectively, they can create a significant information-governance problem.A firm’s AI policy therefore needs to address more than which tools are approved.

It needs to establish clear rules around:

  • confidential information;
  • personal data;
  • client privilege;
  • vendor data processing;
  • retention;
  • access;
  • and appropriate use cases.

Who Is Responsible for the Output?

There is another question that becomes increasingly important as AI use expands:Who owns the decision?

If AI produces a research result, who verifies it?If AI drafts a client communication, who reviews it?If AI identifies a contractual risk, who determines whether that risk actually matters?If an AI system makes a mistake, who is accountable?

The answer cannot simply be:“The AI did it.”

Technology can assist professional work.It does not automatically absorb professional responsibility.That is why human oversight needs to be designed into workflows rather than added as an afterthought.

Transparency Is Already Here

One part of the AI Act is not waiting for 2027.

From 2 August 2026, Article 50 transparency obligations apply to systems within their scope. These include requirements designed to make people aware when they are directly interacting with certain AI systems and requirements concerning the marking or disclosure of certain AI-generated or manipulated content.

For firms using AI-facing client interfaces, this makes transparency particularly relevant.

If a prospective client is communicating with an AI intake assistant, for example, the firm should consider whether the person is being appropriately informed that they are interacting with AI and what other disclosures or safeguards apply to that workflow.

Transparency is not merely a regulatory checkbox.It is part of the relationship between the client and the firm.

The High-Risk Delay Should Not Become a Strategic Delay

The extension of the high-risk timeline may tempt some organisations to postpone their governance work.That would be a mistake.The additional time is valuable precisely because responsible AI governance takes time.

A firm needs to:Map its current AI usage.Classify its use cases according to risk.Assess data and confidentiality implications.Define human oversight.Establish internal policies.Train lawyers and staff.Document decisions.Test systems.Monitor performance.

And then continuously update the framework as the firm’s AI use evolves.That is not something you want to start immediately before a regulatory deadline.

Governance Before Automation

The most mature law firms will increasingly treat AI governance as infrastructure.

Before deploying a new AI workflow, they will ask:What is the purpose?

What problem are we actually trying to solve?What data does it require?

Is all of that data necessary?What is the risk?

Could the system affect confidentiality, rights, clients, or professional obligations?Where does human judgment remain mandatory?

Which decisions cannot be delegated?How do we verify the output?

What testing and quality controls exist?Can we demonstrate responsible use?

If a regulator, client, court, or professional body asks how the system works, can the firm explain it?

The Strategic Advantage of Starting Early

There is also a commercial reason to begin now.The firms that build governance early will not simply be better positioned for compliance.They may also be better positioned to adopt AI faster.That sounds counterintuitive.But governance creates boundaries.Once lawyers understand which data can be used, which tools are approved, which workflows require review, and who is accountable, experimentation becomes easier.The firm does not have to debate every AI use case from scratch.

It has a framework.Good governance can therefore accelerate responsible innovation rather than preventing it.

The Deadline Is a Signal, Not the Strategy

The EU AI Act timeline will continue to evolve.Regulations will be interpreted.Technical standards will develop.Guidance will change.New AI capabilities will create new questions.A firm that builds its strategy around individual deadlines will constantly be reacting.A firm that builds an underlying governance framework can adapt.

That is the difference between compliance-driven AI adoption and governance-led AI adoption.

Conclusion

The EU AI Act’s implementation timeline has changed.Some high-risk obligations have moved further into the future, while important transparency requirements are now applying from 2 August 2026.

That should not be interpreted as:“We have more time, so we can wait.”

It should be interpreted as:“We have more time to get this right.”

The most important question for a law firm is not when the next deadline arrives.

It is whether the firm already knows:what AI it is using,what data it is giving AI,what AI is producing,who is responsible,where human judgment remains essential,and whether it can demonstrate that the entire process is governed responsibly.

The deadline may have moved.The need for AI readiness hasn’t.

References

  • European Commission, Navigating the AI Act — current application timeline and high-risk provisions.
  • European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, July 2026.
  • European Commission, AI Omnibus enters into force, 27 July 2026.
  • European Commission, Code of Practice on marking and labelling AI-generated content.