AI takes legal due diligence to a new scale: clause extraction, anomaly detection, risk mapping and review prioritisation, all within hours rather than weeks. But this acceleration must remain fully compliant with the European AI Regulation (AI Act) and GDPR, overseen in France by the CNIL.
What AI changes in legal due diligence
- Mass analysis: processing thousands of documents (data rooms, contracts, litigation, IP) with automatic detection of sensitive clauses.
- Risk mapping: thematic scoring (key contracts, compliance, data, intellectual property) and actionable red flags.
- Traceability and comparisons: contract-by-contract alignment with an M&A playbook and deviation reports.
- Shorter timelines: observed savings of up to 50–70% of analysis time, subject to systematic human oversight.
- Security by design: pseudonymisation, logging and sample-based validation.
These advances require governance compliant with GDPR and the forthcoming AI Act regime, whose obligations ramp up by August 2026 (European Commission – AI framework ; EUR‑Lex – AI Act).
Applicable legal framework in France and the EU
AI Act: risk classification and obligations
The AI Act classifies systems by risk level (unacceptable, high, limited, minimal), with prohibitions applying 6 months after entry into force and enhanced obligations for high-risk systems by August 2026 (European Commission ; EUR‑Lex). Certain practices are prohibited from 2025 (e.g. cognitive manipulation, social scoring, large-scale biometric data extraction). For due diligence:
- A document-analysis assistance tool used in a business will often present limited risk (transparency and user-information duties).
- If the tool targets uses significantly affecting rights or involves the “administration of justice” (e.g. assisting judicial authorities), it may be high risk, with increased duties: risk management, data quality, technical documentation, traceability, human oversight, cybersecurity and conformity assessment.
Classification depends on the purpose declared by the provider and deployer. Maintain classification documentation and a use-case register. For implementation developments and technical details, also consult the dedicated website EU Artificial Intelligence Act.
GDPR and the French Data Protection Act: the backbone
Whenever AI processes personal data (employees, clients, target-company directors), you must comply with GDPR and the loi Informatique et Libertés. Key points:
- Lawful basis and data minimisation; safeguards for transfers outside the EU.
- DPIA where rights and freedoms face high risk (GDPR art. 35).
- Data processing agreements (DPAs) with the publisher/host; processing records.
- Individual rights and clear information, including in an AI context.
- Security: encryption, pseudonymisation, access management and logging.
Useful references: CNIL – Artificial intelligence, CNIL.fr, Legifrance, Service-Public Pro — business guidance.
Professional ethics, professional secrecy and human control
Lawyers and legal professionals must retain intellectual control of the analysis. Human oversight is required by the AI Act for high-risk systems and remains good practice for any AI use. Professional secrecy, confidentiality and evidence integrity take precedence (Justice.fr).
An AI-first method for faster, compliant due diligence
- Define your use cases and classify each AI system (limited vs high risk), with a factsheet for each tool and purpose.
- Data governance: source inventory (data room, messaging, CRM), GDPR lawful basis, retention policies, pseudonymisation.
- DPIA for high-risk processing and checks on international transfers.
- Supplier contracts: AI Act/GDPR, security, logs, exit arrangements, audit rights, indemnities (see “Clauses” below).
- Human oversight: sample-based review, escalation thresholds, double validation of major red flags.
- Traceability: log prompts, model versions, datasets, decisions and reasons.
- Security: isolated environments, access control, robustness tests, leak scans.
- Training: prompt-writing instructions, usage policy, error/hallucination handling.
We deliver this approach end to end. Learn more: Discover the Initial journey and Explore AI and law resources.
Key contractual clauses with AI publishers
- AI Act & GDPR compliance: classification commitment, technical documentation, cooperative DPIA, DPA, EU location.
- Logs and traceability: access to logs, model versions, reference training datasets (or quality sheets).
- Cybersecurity: encryption at rest/in transit, regular penetration tests, incident response plan.
- Liability/indemnification for non-compliance, data leaks or manifestly erroneous outputs causing harm.
- Usage restrictions: prohibit model training on your data without agreement.
- Intellectual property rights in outputs and non-infringement warranties (useful for auditing patent portfolios; see INPI).
- Subprocessors listed and bound by the same duties, veto right.
- Exit arrangements and data portability, including logs and specific models trained on your behalf.
Risks and penalties: where the thresholds lie
- Data protection: the CNIL can impose fines of up to 4% of worldwide turnover for serious GDPR breaches (CNIL).
- AI Act: a dedicated EU-wide penalty regime, with higher levels for prohibited practices and breaches of high-risk system obligations (EUR‑Lex – AI Act).
- Guidance for regulated sectors: in transactions involving regulated entities, incorporate AMF expectations (governance, internal control, security) (AMF).
Operational checklist for AI-assisted due diligence
- Classify AI systems used (AI Act) and document the GDPR lawful basis.
- Conduct DPIAs for high-risk processing and create processing records.
- Require technical documentation, activity logs and mitigation measures.
- Contractually allocate liabilities/warranties with publishers and subprocessors.
- Choose EU-hosted solutions with a DPA and proven security practices.
- Implement systematic human validation and trace every key decision.
- Update internal procedures: governance, pseudonymisation, regulatory monitoring.
Practical due diligence use cases
- Commercial contracts: extract change-of-control, exclusivity, penalty, termination, indexation, audit-rights and GDPR clauses.
- Regulatory compliance for regulated targets (finance/insurance): map potential breaches to report to the buyer (prudential framework, security, governance – AMF).
- Intellectual property: chain of title, licences, trademark/patent coexistence, alerts on assignment and co-ownership clauses (see INPI).
- Data & privacy: map databases, transfers, retention periods and contractual deviations from GDPR clauses (CNIL – AI).
2025–2026 roadmap
- 2025: bans on unacceptable practices, first GPAI obligations, consolidation of codes of conduct (European Commission).
- 2026: full obligations for high-risk systems (documentation, risk management, human oversight, registration where required) — prepare now (artificialintelligenceact.eu).
Further reading
See our related guides: Automating contract drafting with AI, Essential AI tools for a lawyer and Comparing LLMs for legal professionals.
Further reading
Related resources
Frequently asked questions
FAQ
Is AI in due diligence automatically classified as high risk under the AI Act?
No. Classification depends on purpose. Business document assistance is often limited risk. Uses close to the administration of justice or significantly affecting rights may be high risk.
Must we perform a DPIA for AI-assisted due diligence?
Yes, if processing presents high risk to individuals. Assess the data processed, purposes and security measures. The CNIL provides practical guides.
Which clauses should we require from an AI provider for due diligence?
AI Act/GDPR compliance, DPA, logs and auditability, security, data-use restrictions, warranties/indemnities, exit arrangements, IP rights in outputs, subprocessor management.
Can audits achieve 70% time savings?
Yes, during extraction and preliminary analysis, provided data is properly scoped, tools are suitable and human validation is systematic.
What are the main potential penalties?
Up to 4% of worldwide turnover for GDPR breaches (CNIL). The AI Act also has its own penalty regime for prohibited practices and failures to meet obligations.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.