By Rafael Luque Ocaña

Advisory firms and law practices: the Annex III point you fear isn't about you

Law firms look at Annex III.8 and see their own name in it. The literal text says something else: it covers systems used by a judicial authority. The only high risk a professional firm is likely to have sits in the software it uses to hire.

Of all the professional sectors, the one that judges its own AI Act exposure worst is the one that advises everyone else on it.

A law firm reads Annex III, reaches point 8 — "Administration of justice and democratic processes" — and assumes it's the one pointing at them. It's an understandable reflex: they work with case files, draft pleadings, analyse case law. If any point on the list applies to them, it'll be that one.

It isn't. And the literal text leaves no room for doubt.

What point 8 says

“(a) AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution.”

The subject is the judicial authority. The rule is concerned with AI that helps whoever judges, not with AI that helps whoever defends, advises or litigates.

A firm that uses AI to search case law, summarise a case file, draft a claim or review a contract is not covered by point 8. It's doing its job with a tool, and the tool doesn't decide anything: it proposes, and a professional decides and signs off.

The only door point 8 leaves ajar is alternative dispute resolution — arbitration, mediation. If the firm acts as an arbitrator or mediator and uses AI in that role, that's worth a closer look. Advising one party isn't the same as deciding between them.

So where is it

In the same place as in almost any other company: in the software used to hire and evaluate people.

A mid-sized professional firm receives applications, runs selection processes and evaluates performance. If any of those functions relies on AI that filters, scores or ranks, it's Annex III.4 that applies — the point nobody at the firm was watching, because point 8 took all the attention.

It's a complete inversion of the mental map: the risk isn't in the legal work; it's in running the firm itself.

And the real problem, which isn't about classification

It's worth being frank here, because the AI Act isn't the rule that squeezes an advisory firm hardest.

What squeezes is the duty of professional secrecy and confidentiality. A firm handles client information that can't leave its control, and the most common way it leaks out today isn't a security incident: it's someone pasting the text of a contract, a case file or a set of accounts into a public tool to get it summarised.

That doesn't change any risk classification. It's minimal risk from the AI Act's point of view, and it's still the sector's most serious problem — because it compromises a duty that exists independently of any EU regulation, and that carries its own consequences in regulated professions.

A use being minimal risk doesn't mean it carries minimal consequences. It's the distinction most often confused when reading the AI Act, and in this sector it's the one that decides.

What to look at, in three questions

Which AI tools does the team use, and which ones did the firm not procure? Using your own tools on individual initiative is the norm in knowledge work, and by definition it doesn't appear in any inventory — which is the underlying problem behind everything else.

What client information goes into them, and under what processing terms? The answer is usually sitting in a set of terms of service nobody read.

Does any function of the firm's internal administration software filter, score or evaluate people? If it does, that's the only serious high-risk candidate the firm has.

The date, and what doesn't wait for any date

The Annex III regime — point 4 and point 8 alike — starts on 2 December 2027, and the date circulating in many guides is wrong. Today, no firm is failing to comply through this route.

What has been in force since 2 February 2025 is Article 4 on AI literacy — rewritten by the Digital Omnibus without ceasing to be binding — and Article 5 on prohibited practices.

And the duty of secrecy doesn't wait for any of those dates: it's been in force long before the AI Act, and it isn't satisfied by classifying systems. It's satisfied by deciding what information goes into what tool, and writing that down before someone has to ask.

Content in line with Articles 4 and 5 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026).

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.