Measures All Employers / Firms Must Take & Verifiably Document When Using Any AI-Based Tools & Software

All firms using any AI-based technology (which includes normal search engines, which will undoubtedly be 100% of offices) are now obliged to “take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf”.

This means active, role-specific educational training programmes for every single member of staff, and the office maintaining a comprehensive documented compliance trail.

If you are unsure whether your office is in full compliance with Article 4 of the EU AI Act in this regard, this video is a must-watch for everyone in your office if you are to know what your obligations are and be able to take the mandated measures to formally confirm and verifiably document that you have successfully implemented and fulfilled the mandatory AI Literacy requirements enacted under Article 4 of the European Union Artificial Intelligence Act (Regulation (EU) 2024/1689), as aligned with the simplifying updates of the Digital Omnibus on AI (Regulation (EU) 2026/1744), and that all practicing solicitors, partners, and legal support staff completed a comprehensive, 1-hour internal training module detailing:

  1. The underlying mechanics, token prediction behaviours, and structural flaws (including hallucination vectors) of Large Language Models (LLMs).
  2. The specific intersection of generative AI with GDPR compliance, client confidentiality, and data sovereignty boundaries.
  3. The four-tier risk classification architecture under EU law, focusing specifically on prohibited legal tech applications and vendor alignment with the July 2025 General Purpose AI (GPAI) Code of Practice.
  4. Firm-mandated protocols for absolute human oversight, data cordoning, and source document auditability.

You do not need to watch this video if your office has documented proof that:

(a) every piece of software your systems/staff use is logged on an office compliance file and falls within the legally acceptable risk classification, and

(b) every member of staff (practitioners & support staff) is sufficiently trained to understand:

  • the capabilities, limitations and risks of every such software tool they use that incorporates any form of AI (incl. “under the hood”, such as spellcheckers, drafting, generative-AI research, document-review, transcription, translation, client-intake or workflow tools, etc.) when carrying out their own specific daily operational responsibilities within the firm, and
  • what the impact can be on anyone whosoever may possibly be affected by any incident of misuse of AI by that employee, which obviously would include the firm’s clients, staff, and partners’ themselves.

But it should be watched by anyone and everyone in your office if they are unaware of our recent mandatory obligation under the EU AI Act to actively train, and document such training of, every single person in your office (practitioners and support staff) deploying or relying on any form of AI systems in their daily work, including even the likes of standard legal search tools, spellcheckers, drafting assistants, ChatGPT or similar AI tools, and whether on their office or personal devices. This obligation actually became fully applicable over 18 months ago, on the 2nd February 2025.

Passive office policies are no longer enough; your firm must show documented proof of having taken active measures to ensure all staff members have a sufficient level of IT literacy, which obviously includes staff training, for everyone. If a data breach occurs or a flawed AI output compromises a client matter (e.g. text that could identify your client is entered into a publicly available AI tool like ChatGPT, etc.), the very first question regulators and professional indemnity insurers will ask is: 'Where is the documented proof that this specific employee was trained to understand the risks of that system?' Article 4 of the EU AI Act changes AI training from an optional professional development elective into a fundamental statutory requirement for the lawful practice of law!

And it is the principals / partners who are liable for inadvertent data breach occurring or any flawed AI output that compromises a client matter. For example, if you take a confidential draft of an agreement that contains client information, and paste them into a public model to check for, say, grammatical errors or to summarize the clauses, you have just broadcast that information outside the secure boundaries of the firm. That data is now part of an external computational matrix. If a competitor or a journalist later asks that same public AI system about something relating to that subject matter in general, the system can output information directly derived from your confidential prompt !

This is a severe breach of your duty of confidentiality, and in direct conflict with the General Data Protection Regulation. And to further emphasise the severe consequences of such an occurrence, under GDPR Article 17, European citizens possess the 'Right to Erasure'—the right to demand that an organization delete their personal data from all active systems. If a client exercises this right, a law firm must delete their records from its databases.

However, if that client’s sensitive personal data were previously uploaded into a public AI tool and absorbed into the underlying mathematical weights of that model, it is computationally impossible to extract or delete that data without completely retraining the model at a cost of millions of euros. Therefore, by uploading personal data into an unvetted AI tool, someone in your office may inadvertently place your firm in a position of permanent, non-remediable non-compliance with the GDPR, risking severe financial penalties.

Category of CPD: Category C / B / A
Duration: 1.15 Hours

 

To view this webinar and print your CPD Certificate immediately afterwards, click on Purchase (or on Login if you have already registered and purchased this webinar).

Purchase Login