In 2026, artificial intelligence (AI) is no longer merely a headline: it now shapes legal work in law firms and legal departments. French courts are adopting decision-support tools and intelligent caseload management as part of a controlled modernisation process (Ministère de la Justice; Justice.fr). On compliance, the European AI Act applies progressively according to risk levels and imposes new obligations on deployers and professional users (EUR-Lex – AI Act), alongside the continuing requirements of the GDPR and professional ethical principles (professional secrecy, independence) set out on Legifrance and by the CNIL.
Risk alert: using AI tools without human supervision, or tools hosted outside the EU without adequate safeguards, creates exposure to breaches of professional secrecy and the GDPR, and increased civil and disciplinary liability (CNIL).
What is changing in practice at law firms in 2026
Enhanced case-law research and monitoring
AI search engines summarise, classify and rank dozens of decisions in minutes; the legal professional retains control over legal characterisation and source relevance. Courts themselves promote easier access to the law and transparency of algorithms used in the judicial process (Ministère de la Justice).
Drafting legal documents and analyses
AI prepares preliminary drafts of notes, written submissions, formal notices and internal memoranda, which the lawyer then reviews. AI accelerates production, but strategy, legal characterisation and the final arguments remain human responsibilities, in accordance with the ethical requirements in the RIN on Legifrance and recommended professional practice (Juritravail).
Due diligence and contract review
Clause extraction, detection of subtle warning signs (obligations to achieve a specified result, penalties, change of control) and compliance tables are automated. Legal approval, risk decisions and negotiation remain under counsel’s direction.
Litigation support and augmented courts
Intelligent organisation of exhibits, factual chronologies and mapping of legal grounds: AI structures the case file. Courts are experimenting with support tools without affecting judges’ independent power of assessment (Justice.fr; Ministère de la Justice).
The legal and ethical framework to follow
AI Act: classify the risk and fulfil the obligations
- Minimal/limited risk: transparency and information obligations regarding AI use.
- High risk: enhanced requirements (data governance, incident management, traceability, conformity assessment). Deployers and professional users must demonstrate their diligence (EUR-Lex – AI Act).
- Targeted prohibitions: certain uses that infringe fundamental rights are prohibited (see the AI Act).
Before any deployment, identify the system’s risk category and document it in your compliance file.
GDPR, transfers and professional secrecy
- Minimisation: share only strictly necessary data, favouring masking/pseudonymisation (CNIL).
- Transfers outside the EU: check server locations and the contractual framework for processors. Transfers to third countries require appropriate safeguards (standard clauses, country-risk assessments); heightened vigilance is needed regarding extraterritorial orders (CNIL).
- DPIA: conduct an impact assessment for risky use cases (profiling, sensitive data); tools and guidance are available from Service Public Pro and the CNIL.
- Professional secrecy: no blind delegation or uncontrolled outsourcing. Professional ethical principles remain inviolable (RIN, Legifrance).
Public recommendations and charters
The profession is formalising its practices: court guidelines and professional initiatives, including publicly available usage charters in late 2025, call for transparency, traceability and continuous human supervision (Justice.fr; Village de la Justice).
An operational AI-first method for a law firm in 2026
Key steps
- 1. Map use cases: research, contract review, drafting, knowledge management and litigation support.
- 2. Assess AI Act/GDPR risks: classify the risk level, check the legal basis and define technical/organisational measures (AI Act; CNIL).
- 3. Choose EU-compliant solutions: European hosting, encryption, model governance and an option preventing reuse for training.
- 4. Plan human supervision: two-stage approval of AI outputs for every external deliverable, quality criteria and a decision log.
- 5. Safeguard supplier contracts: DPA clauses, location, subprocessors, audit rights, exit and migration arrangements, indemnities. See our dedicated service: Explore AI and law resources.
- 6. Measure and manage: quality/cost/time indicators, control samples and quarterly reviews.
- 7. Inform clients: transparency about AI use and consent where relevant, with standardised information notices (Service Public Pro).
Initial takes a design approach centred on compliance and value. Understand the AI transformation journey.
AI/SaaS contract checklist to incorporate
- Data protection: a GDPR-compliant DPA, records of processing, listed subprocessors and advance notice of changes (CNIL).
- Location/transfer restrictions: processing and backups within the EU; mechanisms for any transfer outside the EU; country assessment and supplementary measures (CNIL).
- No training on client data: explicit opt-out with “no” as the default.
- Confidentiality/professional secrecy: enhanced commitments, restricted access, encryption at rest/in transit and logging.
- Traceability/explainability: inference logs, model versions and retention suited to litigation needs.
- SLA/security: RTO/RPO, penetration testing, incident management, notification within 72h and a continuity plan.
- Intellectual property: ownership of deliverables and non-infringement warranties; attention to databases and trade secrets (see INPI good practice).
- Exit and migration: data export and open formats at the end of the contract.
- Audit/control: audit rights, third-party certifications and evidence of AI Act compliance.
Need an audit or supplier negotiation? Explore AI and law resources.
Use cases by practice area
Corporate/M&A
- Contractual due diligence: extracting warranties, liability limitations and non-compete undertakings; review by a lawyer.
- Augmented data room: deduplication, thematic classification and a Q&A roadmap.
Employment law
- Analysis of internal policies and collective agreements; compliance checks and alerts on sensitive clauses.
- Preparation for employment tribunal proceedings: organising exhibits and lines of defence, without predictive scoring.
Litigation/compliance
- Factual chronologies, mapping of complaints and identification of inconsistencies; procedural strategy remains human (principles restated by Justice.fr).
- Automated regulatory monitoring across multiple sources (Legifrance, CNIL, sector regulators).
Points to watch and mistakes to avoid
- Hallucinations: require source citations and check every reference (Legifrance, official case law).
- Shadow AI: prohibit unapproved tools and log prompts.
- Data leaks: prohibit pasting unredacted sensitive exhibits into public services without GDPR safeguards (CNIL).
- Unlawful transfers: check the processing chain and hosting locations (Service Public Pro, CNIL).
- Overconfidence: maintain human supervision and document approval, including under the AI Act.
For safe deployment, draw on 2026 guidance and practical experience (Village de la Justice; Juritravail).
90-day roadmap
- Days 1–30: internal AI policy, use-case mapping, AI Act classification, preliminary DPIA and selection of an EU-hosted proof of concept (AI Act; CNIL).
- Days 31–60: negotiation of critical clauses (DPA, location, no training, audit), supervision procedures and quality control. Need support? Explore AI and law resources.
- Days 61–90: pilot deployment, training, indicators, compliance review and client information. Explore AI and law resources.
Further reading
See our related guides: Essential AI tools for a lawyer in 2026, What is an AI-first law firm? and Training your legal teams in AI.
Quick FAQ
Can AI sign a legal document? No: it assists with drafting; the lawyer approves it and takes responsibility (see professional ethical principles on Legifrance).
Must clients be told about AI use? Yes, for transparency, and their agreement should be obtained where relevant, particularly when data is shared (CNIL).
Does the AI Act apply to law firms? Yes, as professional users/deployers of AI tools, with obligations according to risk level (EUR-Lex).
Do judges use decision-making AI? The tools support decisions and management; judges retain their power of assessment (Justice.fr; Ministère de la Justice).
Further reading
Related resources
Frequently asked questions
FAQ
What are the main benefits of AI for a law firm in 2026?
Faster research, contract review and legal drafting. The lawyer focuses on strategy, negotiation and final approval.
What obligations does the AI Act impose on professional users?
Classify the system by risk level, document compliance, ensure traceability, incident management and human supervision proportionate to the risk.
How can you remain GDPR-compliant when using AI?
Minimise data, favour EU hosting, safeguard transfers, conduct a DPIA where necessary and sign a robust DPA with the provider.
Can sensitive exhibits be entrusted to public AI tools?
Avoid doing so without safeguards. Prefer EU solutions, strong encryption, no training by default and strict control over processors.
Must clients be informed about AI use?
Yes, for transparency. Obtain agreement if personal data is processed or if the tool significantly influences the service.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.