Every legal team adopting AI eventually asks the same question: are the tools we use "high-risk" under the EU AI Act? The direct answer: usually not. The Act's high-risk category for the justice sector targets AI used by or on behalf of courts to decide or help decide cases - not the research, drafting, and review tools lawyers run inside their own practice. But "usually not" is doing real work in that sentence: employment uses of AI, ADR work, and the prohibited-practices list all catch firms that never checked. This guide - a spoke of our EU AI Act timeline pillar - walks through the classification, entry by entry.
This is legal information, not legal advice. Classification is per system and per intended use - confirm your own analysis with a qualified lawyer before relying on it.
The short answer for legal teams
Under Regulation (EU) 2024/1689, a lawyer-facing AI tool used for legal research, document review, contract analysis, or drafting inside a firm or legal department is, in the ordinary case, not a high-risk AI system. It is typically a minimal-risk or transparency-tier system built on a general-purpose model. The high-risk label attaches to intended purposes listed in Annex III - and the justice entry is written around judicial authorities, not private practitioners.
The classification still has to be done, tool by tool, because the same platform can be fine in one use and regulated in another. The employer running a recruitment screen and the firm assisting an arbitral tribunal both cross into Annex III without buying new software. Classification is a property of the use, anchored in the system's intended purpose.
How the Act classifies AI systems: four tiers
The Act sorts AI systems into four buckets, with obligations that scale accordingly. For definitions of the building-block terms - AI system, provider, deployer, general-purpose AI - see our glossary; the tier logic is what matters here.
| Tier | What it covers | Legal-sector examples |
|---|---|---|
| Prohibited (Article 5) | Eight banned practices, in force since 2 February 2025 | Emotion recognition of employees; social scoring |
| High-risk (Article 6, Annexes I and III) | Listed intended purposes with strict provider and deployer duties | Recruitment screening tools; AI assisting courts or ADR bodies |
| Transparency (Article 50) | Disclosure duties for interactive and generative systems | Client-facing chatbots; AI-generated content |
| Minimal risk | Everything else - no new obligations | Research, review, and drafting assistants used by lawyers |
Two structural points prevent misreadings. The tiers are not exclusive: a high-risk system can also carry Article 50 duties, and a minimal-risk tool can still be deployed into a prohibited practice. And the high-risk tier splits in two - Annex I covers AI embedded in regulated products, Annex III lists stand-alone uses. Legal-sector questions live almost entirely in Annex III.
The administration-of-justice entry, read closely
Annex III point 8(a) classifies as high-risk: AI systems "intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution" (see the full Annex III text). Three phrases carry the weight. "By a judicial authority or on their behalf" anchors the category to courts: the intended user is the bench or someone acting for it, not a party's counsel preparing their own case. "Researching and interpreting facts and the law" means research-stage tools are in scope for courts - the entry is not limited to systems that draft decisions. And "in a similar way in alternative dispute resolution" pulls in arbitration and similar processes: recital 61 confirms ADR use is high-risk when the proceedings produce legal effects for the parties.
Recital 61 also draws the outer boundary: the classification does not extend to "purely ancillary administrative activities" - anonymising decisions, personnel communications, administrative tasks. And it states the design principle behind the entry: AI can support judicial decision-making, but final decisions must remain human-driven. That principle - the machine assists, the human decides - is worth adopting internally whatever tier your tools land in; it is the same logic as human-in-the-loop legal AI.
Why most lawyer-facing tools are not high-risk
Run the ordinary law-firm stack against the list and the result is consistent. A research assistant answering a lawyer's question, a review tool flagging contract risks, a drafting assistant producing a first cut of a clause - none of these is intended for use by or on behalf of a judicial authority, none decides access to employment, credit, education, or public benefits, and none touches biometrics or law enforcement. They fall outside every Annex III entry, which leaves them in the minimal-risk tier, possibly with Article 50 transparency duties if they interact with clients or generate content published outward.
Classification rests on intended purpose as documented by the provider - the instructions for use, marketing, and technical documentation. That is why vendor paperwork matters even for low-tier tools: a provider that states its intended purpose clearly gives you the anchor for your own classification file. Our vendor due-diligence questions spoke covers exactly what to ask for.
The two traps that catch law firms anyway
The first trap is employment. Annex III point 4 covers AI used in recruitment and selection - placing targeted job ads, filtering applications, evaluating candidates - and AI making or materially informing decisions on promotion, termination, task allocation, or monitoring. A firm that lets an AI tool score training-contract applicants or rank associates for retention is deploying a high-risk system in the Act's core sense, however low-tech the rest of its stack. From 2 December 2027 that means the full deployer duty set described in our deployer obligations guide.
The second trap is the prohibited list, which has applied since February 2025 and carries the Act's highest fines. The entry most likely to surface in a professional-services firm is emotion recognition in the workplace: AI inferring employees' emotional states - in call monitoring, meeting analytics, or wellbeing dashboards - is banned outside medical and safety uses, and the prohibition binds the deployer regardless of what the vendor's terms say. A third, narrower route is Article 25: a firm that puts its own name on a high-risk system, substantially modifies one, or repurposes a tool into a high-risk use becomes the provider, inheriting the heavy end of the compliance duties.
A classification workflow you can document
A defensible classification file is a repeatable sequence, not a one-off memo.
- Inventory: list every AI system in use, including AI features inside existing software - the classification duty does not care whether procurement noticed the AI.
- Screen against Article 5: confirm no use touches a prohibited practice; retire or reconfigure anything that does.
- Map to Annex III: check each system's intended purpose against the listed categories, with employment and administration-of-justice read carefully for legal teams.
- Check Article 50: flag systems that interact with natural persons or generate content, and assign the disclosure and marking duties that start 2 August 2026.
- Record the conclusion: intended purpose, categories assessed, reasoning, owner, and date - and revisit when the vendor changes the product or you change the use.
Where a tool operates in an Annex III area but you conclude it does not pose a significant risk of harm - the Article 6(3) derogation for narrow procedural or preparatory tasks - the Act expects the assessment to be documented and the system registered. The derogation survived the Digital Omnibus in streamlined form; treat it as a documented exception, never a silent one.
Timing: what the December 2027 date changes
The Digital Omnibus moved the Annex III high-risk regime - and with it most consequences of a high-risk classification - from 2 August 2026 to 2 December 2027. It did not move the prohibitions, the literacy duty, or the August 2026 transparency wave, and it did not change what belongs in your classification file. The Commission consulted on classification guidelines during 2025; check the AI Act Service Desk for the current guidance status before finalising borderline calls.
The practical read: classify now, remediate on the new timetable. A firm that knows by this autumn which of its systems sit where can spread vendor conversations, contract updates, and any FRIA or DPIA work - see the FRIA vs DPIA spoke - across eighteen months instead of a scramble.
Where Judicio fits
Judicio's tools are built for the lawyer-facing work that sits outside the high-risk tier - and engineered as if the oversight expectations applied anyway. Document Review returns findings quoted to the page so a human can verify before relying; research answers carry citations to primary sources; access is role-based with an activity trail. The provider-side documentation that classification depends on - intended purpose, methodology, security controls - is published on our methodology and security pages.
If you are running a classification pass this quarter, our AI governance policy template gives the inventory and screening steps a home. You can start a 7-day free trial or explore the full feature set; for the EU regulatory backdrop, see the Europe hub.