Your EU AI Act lawyer in Europe
The AI Act is now law across the EU, and the obligations arrive in stages. We help you work out which ones apply to you, what they mean in practice, and what to do first.
First hour’s on us. No commitment.
You are building, buying or deploying AI, and somewhere between the headlines and the 180 articles of the regulation there is a practical question: what does this actually mean for us? Most companies do not need a full compliance programme. They need to know which of their systems the AI Act touches, which role they hold under it, and which three things to fix first. That is where we start.
What you get
- A classification of every AI system you build or use — prohibited, high-risk, transparency-only or minimal — with written reasoning you can show a customer, an investor or a regulator
- Clarity on your role — provider, deployer, importer or distributor — since the obligations differ sharply between them, and many companies hold more than one
- A prioritised action list with dates, tied to the phase-in schedule rather than to a generic checklist
- Contract language for your AI vendors and customers that allocates the obligations where they belong
- A documentation set — technical file, logging, human oversight, AI literacy — built to the depth your risk category actually requires
How it works
- Intake, 45 minutes. You describe what you build and use. Free, no commitment.
- Assessment, one to three weeks. We map your systems, classify them, and identify the gaps that matter.
- The plan. A written report with prioritised measures and a timeline. You decide whether to run it yourself or with us.
Who you’ll work with
Fidan Ibrahimzada, Legal Counsel for AI and technology law, leads this work. She advises companies on AI regulation, data protection and technology contracts, and previously led the legal department of a commercial law firm. She holds an LL.M. in European Business Law from Lund University. Lawgent is Sweden’s first law firm dedicated to AI and EU regulation — meet the team.
What the EU AI Act actually requires
The AI Act is a product-safety regulation, not a data protection law. It regulates AI systems by the risk they present, and it places most of the weight on the party that puts a system on the market.
Four tiers: a small set of prohibited practices; high-risk systems, which carry the substantive obligations; limited-risk systems with transparency duties, such as telling people they are talking to a chatbot or labelling generated content; and everything else, which the regulation largely leaves alone. Most companies discover that far less of their portfolio is high-risk than they feared — and that one or two systems they had not thought about are.
Separately, providers of general-purpose AI models carry their own obligations: technical documentation, a public summary of training content, and copyright policy, with additional duties for models presenting systemic risk.
The dates that matter
The regulation entered into force on 1 August 2024 and applies in phases:
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices. AI literacy obligation (Article 4) |
| 2 August 2025 | General-purpose AI model obligations. Governance and national authorities |
| 2 December 2026 | Marking and labelling duties for systems placed on the market before August 2026 |
| 2 December 2027 | High-risk systems under Annex III — recruitment, credit, education, critical infrastructure and others |
| 2 August 2028 | High-risk AI embedded in regulated products — medical devices, machinery, toys |
The 2027 and 2028 dates moved later during 2026, when the EU adopted amendments deferring parts of the high-risk regime. The prohibitions and the AI literacy requirement were not deferred and are in force now.
The practical consequence of the deferral is not that the work goes away. It is that you have a usable window to do it properly — and that contracts signed today will still be running when the obligations bite.
Provider or deployer — the question that decides everything
The same company can be a provider of one system and a deployer of another, and the obligations are not comparable in weight.
A provider develops an AI system and places it on the market under its own name. For high-risk systems that means a risk management system, data governance, technical documentation, logging, human oversight design, accuracy and cybersecurity measures, a conformity assessment and CE marking.
A deployer uses a system developed by someone else. The duties are lighter but real: use the system as instructed, assign competent human oversight, monitor operation, keep logs, and in several cases inform affected people or run a fundamental rights impact assessment.
Two things move you from deployer to provider without you intending it: putting your own name or trademark on a third-party system, and substantially modifying one. Both happen routinely in white-label and fine-tuning arrangements, and both are worth checking before a contract is signed rather than after.
Where this meets the rest of your regulatory picture
The AI Act does not replace the GDPR. If your system processes personal data, both apply, and a DPIA may be required alongside the AI Act documentation. If you are a financial entity, DORA governs the operational resilience of the systems the AI runs on. If you fall within the scope of the Swedish Cybersecurity Act, NIS2 obligations sit on top.
The efficient path is to do this once, across all of them, rather than four times in four projects.
Frequently asked questions
Do I need a lawyer for the EU AI Act, or is this a compliance-tool question?
Tools are good at inventory and tracking. Classification is a legal judgement — whether a system falls under Annex III, whether you are the provider, whether an exemption applies — and it is the judgement you will have to defend. Most companies use both.
We only use AI, we do not build it. Are we in scope?
Probably yes, as a deployer. The duties are lighter than a provider’s, but they include human oversight, monitoring and, for some systems, informing the people affected. Companies that put their own brand on a third-party system may also count as providers.
We are based outside the EU. Does the AI Act apply to us?
It can. The regulation reaches providers who place systems on the EU market regardless of where they are established, and in some cases providers whose output is used in the EU. Non-EU providers of high-risk systems generally need an authorised representative in the Union.
The high-risk deadlines moved. Can we wait?
The deferral applies to parts of the high-risk regime. Prohibitions, AI literacy and general-purpose AI model obligations are already in force. And the systems you procure now will still be in production in 2027 — the contracts are the part that is hard to fix later.
What does an assessment cost?
The first conversation is free. After that we scope the work against what you actually have; a focused assessment for a single product line is a different exercise from a group-wide review. You get a fixed price before we start.
Can you work as our ongoing counsel rather than on a single project?
Yes. Many clients use us on demand for specific questions, and some as a dedicated partner with a set monthly scope.
Talk to an AI Act lawyer
You do not need to solve the whole regulation. You need to know what applies to you and what comes first. That is a conversation, not a project — and the first hour is on us.
Related
- AI Governance
- Data & GDPR
- Financial & DORA
- Regulatory Advisory
- Legal Growth Audit
- AI-förordningen – juridisk rådgivning (svenska)
- AI Act compliance consultant
- AI Act high-risk classification
- GDPR for AI systems
- The EU AI Act compliance checklist
- The AI Act in HR and recruitment
- AI Act deployer obligations
- The AI literacy requirement (Article 4)