Skip to main content

§ 01 · AI & quality

Is your legal AI a high-risk system? Annex III examined soberly

The high-risk provision for legal AI attaches to the judicial authority — the words “law firm” do not appear in Annex III. Why most firm tools are therefore not high-risk systems, what price the exceptions in Art. 6 Abs. 3 carry, and by what inconspicuous route firms nevertheless end up in this category.

5 minAI & quality
A heavy stone scale pan in half-darkness, on which a single bright point of light rests, while the rest of the room lies in deep shadow.

In one sentence

The high-risk provision that almost everyone means when they talk about legal AI attaches to the judicial authority — not to legal work as such; most firm tools are therefore not high-risk systems, though firms do end up there by a quite different route.

What Annex III No. 8(a) actually says

The high-risk classification of legal AI has been discussed for months, mostly without a look at the wording. Annex III No. 8(a) of the AI Regulation — VO (EU) 2024/1689 — covers AI systems intended to be used by a judicial authority or on its behalf to support it in researching and interpreting facts and the law and in applying the law to concrete facts; comparable use in alternative dispute resolution is placed on the same footing.

The words “law firm” do not appear in it. The point of attachment is the deciding body, not the legal activity: anyone drafting pleadings supports a party — not the court. The distinction is not trivial: the boundary with alternative dispute resolution is fluid and, in case of doubt, to be clarified with a lawyer.

The exceptions in Art. 6 Abs. 3 — and their price

Even where a system falls under Annex III, it is not regarded as high-risk under Art. 6 Abs. 3 as long as there is no significant risk to health, safety or fundamental rights. Four categories of case are named:

  • a narrowly limited procedural task — formatting, classification, extraction;
  • the improvement of the result of a previously completed human activity;
  • the detection of decision-making patterns or of deviations from them, without replacing the human assessment;
  • a preparatory task for an assessment under Annex III.

Two qualifications belong with this: if the system carries out profiling of natural persons, it remains high-risk. And anyone relying on the exception has to document that under Art. 6 Abs. 4 — a duty to give reasons, not a free pass.

Where firms do end up in the high-risk area

The most likely case has nothing to do with legal tech: Annex III No. 4 covers AI in employment and personnel management — filtering applications, assessing candidates, serving job advertisements. A firm that uses something of the kind for its own recruitment is a deployer of a high-risk system and bears the duties under Art. 26: use in accordance with the provider’s instructions, human oversight by suitable persons, monitoring, logs, informing employees. These duties have been postponed to 2 December 2027 by the “Digital Omnibus” — but postponed is not cancelled.

Two levels have long been applicable independently of that: the transparency duties under Art. 50 have applied since 2 August 2026 — anyone interacting with an AI must be able to recognise it (more on this). And Art. 4 requires a sufficient level of AI literacy. The range of fines extends to 35 million euros or 7 % of worldwide turnover.

Four questions instead of one blanket answer

The classification does not follow the product category. As a rule these questions take you further:

  1. Who is using it? A judicial authority or someone acting on its behalf — or a party?
  2. What does it do? A narrowly limited procedural task — or an assessment that shapes a decision in advance?
  3. Does the human assessment remain the load-bearing one — or does the system effectively replace it?
  4. Is there a second use in the house? Personnel selection, access control, creditworthiness.

Limits of this classification

This text places a legal position in context, it does not answer an individual case: the classification depends on your purpose of use, not on the product name. Caution is called for with providers who present “AI Act compliant” as a seal of quality: the Regulation knows no such seal. Only what a provider discloses is reliable.

AI transparency · System limits · Compliance for firms · The AI Act from August 2026

Lexi, digitale Rechts-Assistenz

Ready to clarify your matter?

{n} credits free. No credit card required. Ready in 2 minutes.

Start free now

No credit card required · GDPR-compliant · Start for free

Start free
No credit card
Get started