Two different questions get mixed together here. "Is my legal-tech product high-risk?" is a classification problem with a named Annex III category. "What do I tell clients who use AI in my firm?" is a professional-duty problem, and the AI Act is only part of it.
Legal tech: Annex III point 8 is narrower than people assume
Annex III point 8 covers AI intended to be used by a judicial authority, or on its behalf, to research and interpret facts and law and to apply the law to a concrete set of facts. It also covers systems intended to influence the outcome of an election or voting behaviour.
The operative words are "by a judicial authority". Tooling sold to law firms, in-house teams or litigants is generally not in point 8. A contract-review product used by a commercial firm is not a system assisting a court. Vendors routinely over-classify themselves here.
| Product | Likely tier | Why |
|---|---|---|
| Research or drafting tool sold to a court or tribunal | High-risk | Annex III 8(a) - used by a judicial authority |
| Contract review / due diligence for firms | Minimal or limited | Analysing documents, not assisting a court, and no person is evaluated |
| Case-law research, summarisation, drafting | Minimal or limited | Same - Article 50 if it converses |
| Litigation outcome prediction sold to firms | Assess carefully | Not point 8 if the buyer isn't a court - but if it profiles the parties, look again |
| Recidivism or offender risk scoring | High-risk | Annex III point 6 - law enforcement, a separate category |
| Legal chatbot for the public | Limited | Article 50 - and consumer-protection duties on top |
| Firm's own AI recruitment or appraisal tool | High-risk | Annex III point 4 - you're a deployer. See HR |
Law firms are deployers, and mostly of minimal-risk systems
A firm using AI for research, drafting or document review is a deployer of a minimal-risk system. Chapter III does not apply. What does:
- Article 4 - recorded AI literacy for fee earners and support staff. For a profession whose regulators are already asking about AI competence, this is the cheapest possible evidence.
- Article 50 - any client-facing bot on the firm's site discloses.
- Article 5 - no emotion inference on staff. Some legal-ops monitoring tools include it.
Professional duties bite harder than the AI Act here. Confidentiality and privilege when client material goes into a third-party model, competence when output is filed unchecked, and the courts' own directions on AI-assisted filings are live issues in several member states - none of which the AI Act governs. A firm can be fully AI Act compliant and still in trouble with its regulator.
The question clients are actually asking
Most firms encounter the AI Act through clients, not through their own tooling. The recurring question is some version of "our product uses AI, are we in scope, and what do we have to do?" - and the honest answer usually needs a structured pass through role, GPAI status, tier and the Article 6(3) exemption before it's worth billing time on.
That is the gap this tool is built for. A dated, reasoned self-assessment naming the client's product turns the first hour of an engagement into a review of an existing position rather than an extraction exercise. Our classification methodology is published in full so you can see where you'd disagree, and the sample report is unredacted.
Reglynn is not a law firm, is not a notified body, and issues no certification. It is a structured self-assessment - explicitly the input to legal advice, not a substitute for it. If you advise clients in this area and want to check our reasoning on a specific point, the changelog records every classification change we make and why.
Assessing a client's product?
A dated self-assessment turns the first billable hour into reviewing a position rather than extracting one. The methodology is published in full.
Start the free scanNo card, no account. Full gap report from €59. See a real report first.
Self-assessment, not legal advice. This page and the Reglynn report are a structured self-assessment based on the EU AI Act (Regulation 2024/1689, as amended by the June 2026 Omnibus). They indicate where you likely stand and what to verify with a qualified advisor. Reglynn is not a notified body and issues no certification.
How this was made. Reglynn reports are generated by an AI system built on Anthropic's Claude and reviewed before delivery. Reglynn is a Limited Risk AI system under Article 50; we disclose AI involvement wherever it occurs, including in our chat assistant. Our own self-assessment.