In one sentence
Client data belongs only in an AI whose data processing arrangements, hosting location and deletion periods you can document in writing — and since 2 August 2026 the EU AI Act additionally requires that the use of AI be clearly labelled.
Why ChatGPT and the like are risky without an additional agreement
Anyone who pastes pleadings, contracts or client emails into a freely available AI tool is handing over professional secrets. Three points make this risky:
- Third-country transfers: Standard offerings often process your input on US servers, without you being able to control or guarantee where the processing takes place.
- Training use: Without an explicit agreement, your input can be reused to improve the model — sensitive matters included.
- Retention periods: How long prompts are stored and who can access them is rarely clearly documented for consumer services.
For a law firm this means: without additional agreements, there is no legal basis for feeding in client data at all. Read more under Why not just use ChatGPT.
The checklist for any AI tool
Before a tool is allowed anywhere near real case files, five points should be verifiable — only then can you speak of a data-protection-compliant AI:
- Data processing agreement (DPA): a signed contract that binds the provider as a processor.
- Sub-processor transparency: an open, up-to-date list of all service providers involved.
- EU hosting or EU pinning: an assurance that processing stays within the EU — even when premium models are switched in.
- Deletion and retention periods: documentation of how long data is stored and when it is deleted.
- Roles and access model: who in your firm sees which data — and that the provider itself has no plain-text access.
If one of these points is missing, that is not a detail but a deal-breaker.
Since 2 August 2026: the EU AI Act
Since 2 August 2026, the transparency obligations under Article 50 of the EU AI Act have applied: AI-generated content and the use of chatbots must be recognisable as such. The stricter obligations for high-risk systems under Annex III were postponed to 2 December 2027 via the "Digital Omnibus" — but a delay is not a repeal. The scale of fines is meant seriously: up to 35 million euros or 7% of worldwide annual turnover. For law firms this means: the use of AI needs to be documented, labelled and embedded into your own compliance.
PII masking and AI redaction as a second line of defence
Even with sound data processing in place, data minimisation remains the best safeguard. A second line of defence kicks in before a model is even called: personal data is detected and masked, documents are redacted before they are shared. That way, as little plain text as possible ever leaves the firm. Our articles on PII masking and AI-assisted PDF redaction show what this looks like in practice.
How SmartLegalPro handles this
SmartLegalPro is built for EU hosting. Even the optional premium model (the Fable add-on) is automatically pinned to EU regions and only used after a firm has explicitly opted in. Client data does not feed into training. Which service providers are involved is set out openly in the sub-processor list; how AI is used and labelled is explained on the AI transparency page.
One thing remains essential: AI does not replace review by a lawyer. Courts have repeatedly made clear that the lawyer's duty to review applies to every AI output. SmartLegalPro provides the tools for exactly that — from the fact graph and the second-check on deadlines to the autonomy control in the Anwaltsportal. You stay in control.




