The EU AI Act and Legal Practice: A Compliance Roadmap
Which obligations bite, when, and for whom — plus a staged programme legal teams can run without pausing every AI project in the business.
Contract approval, delegation of authority and side letters are control points. Treating them as such makes the audit far less painful.
Section 404 is generally treated as a finance problem. A significant proportion of the control failures that surface in testing, however, sit in processes that legal owns.
Three places, mainly. Contract approval is a control over the commitments the company makes. Delegation of authority is the control that determines whether the person who signed had the authority to. Revenue-relevant terms — acceptance criteria, termination rights, extended payment terms, side letters — feed directly into revenue recognition, and a term that contradicts the standard agreement can change the accounting.
The classic finding. A sales team agrees a concession in a separate document that never reaches finance, and revenue is recognised on the basis of terms that have been varied. The control is not a policy prohibiting side letters; that policy already exists and is already breached. The control is a single contract repository with a completeness check, so that the absence of a document is detectable.
Testing asks for evidence that a control operated, not that it existed. For contract approval this means an approval record with the approver’s identity, the date, the version approved and a link to the executed document. Email approval threads technically satisfy this and reliably fail sampling, because the thread for the one contract the tester selected cannot be found.
Legal teams that treat these as controls rather than as administration spend markedly less time on audit season, because the evidence is generated by the process instead of assembled after it.
This article is general information about legal technology and practice, not legal advice, and it does not create a lawyer–client relationship. JuriPro is a technology company, not a law firm. Take advice from a qualified lawyer admitted in the relevant jurisdiction before acting on anything here.
Head of Compliance, JuriPro
Privacy and regulatory lead; previously data protection officer at a multinational financial services group.
Which obligations bite, when, and for whom — plus a staged programme legal teams can run without pausing every AI project in the business.
Horizon scanning is only step one. The value is in the routing, impact assessment and evidence trail that follow it.
A plain-English account of how a language model reads an agreement, where its judgement is genuinely useful, and the four failure modes every reviewing lawyer should know about.
Start a 14-day trial, or book a 30-minute walkthrough with someone who has practised.