Skip to content
[ blog post ]

Legal AI confidentiality and the EU AI Act: privilege in Europe

Legal AI confidentiality architecture diagram: privileged communication staying inside the law firm perimeter, with Council of Bars, BRAK, and NOvA references and the EU AI Act layer in the footer band.

May 2, 2026

H. Kamkar

The European answer to the privilege question

Legal AI confidentiality is now an architectural question, not a contractual one. The Council of Bars and Law Societies of Europe published its Generative AI Guide in October 2025. The EU AI Act, which entered into force in August 2024, has deployer obligations that begin to apply to high-risk AI systems in August 2026. The two regulatory layers were drafted independently and on different timelines. Both point at where the AI runs and who controls it.

The European conversation about generative AI in legal practice has been quieter than the United States one and has reached a different conclusion. The Council of Bars and Law Societies of Europe, the body that represents the European bar associations, explicitly endorses in its October 2025 guide "AI systems set up to run locally or within a secured environment controlled by the law firm." That recommendation is unusually clear for a soft-law instrument and is largely absent from how generative AI is positioned to European law firms today.

This post is for the founder or chief technology officer at a European legal-tech startup whose law firm customer's compliance function has just asked how the firm's privileged communications stay confidential when generative AI touches them. It walks through what the Council of Bars and Law Societies of Europe said in October 2025, what the German federal bar said in December 2024, where the Dutch national bar sits in 2026, and how those positions intersect with the EU AI Act's deployer obligations. The four sources point at the same architectural answer: private AI for legal-tech deployed inside the law firm's environment, not behind a public AI API.

A note on regulatory weight. The Council of Bars and Law Societies of Europe is not a legislative body and its guide is not binding law. The guide is an authoritative interpretation by the body that represents the European bar associations, and it carries weight in disciplinary proceedings and in the procurement decisions of European law firms. The same applies to the German federal bar and Dutch national bar positions described below. They shape practice without binding it.

"Legal AI confidentiality is now an architectural question, not a contractual one."

What the European bars have said

The Council of Bars and Law Societies of Europe position (October 2025)

The October 2025 Generative AI Guide is the strongest single recommendation about deployment architecture in any European bar instrument to date. The guide acknowledges that generative AI tools are increasingly central to legal practice and that the question of how they handle privileged information is not hypothetical. It then recommends, plainly, that AI systems used in legal practice should be set up to run locally or within a secured environment controlled by the law firm. The reasoning the guide offers is direct: keeping privileged information inside an environment the firm controls is the most reliable way to maintain the confidentiality obligations that underpin attorney-client privilege.

The guide does not ban hosted generative AI tools, and it does not name vendors. It does set a clear directional preference: the architecturally safer choice is local or firm-controlled deployment. For a vendor selling generative AI into European law firms, this is the single most useful sentence in any pitch deck because it converts a soft preference into an authoritative reference point.

The German federal bar position (BRAK, December 2024)

The German federal bar (Bundesrechtsanwaltskammer, BRAK) issued a position on AI use in legal practice in December 2024. The position connects to the German Federal Lawyers' Code (Bundesrechtsanwaltsordnung) and to the broader information-security framework administered by the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). BRAK emphasizes two things: lawyers retain personal responsibility for any output generated with AI assistance, and the choice of AI tooling must be consistent with the lawyer's confidentiality and data-protection obligations.

The BRAK position is procedural rather than architectural, but it points at the same destination as the Council of Bars guide. Tools that keep privileged information inside the firm's controlled environment are easier to defend in disciplinary proceedings than tools that send it to external services. German law firms have been early adopters of customer-environment deployment requirements in procurement, likely because the BRAK guidance and the BSI framework make the case concretely.

The Dutch national bar position (NOvA)

The Nederlandse Orde van Advocaten (the Dutch national bar association, commonly NOvA) has not published a single comprehensive position on generative AI in the same form as the Council of Bars guide. Its position in 2026 emerges from disciplinary case law and from working-group statements that touch on AI. The throughline: lawyers are personally responsible for the technology choices they make, those choices must be consistent with the confidentiality obligations in the Dutch Lawyers' Act (Advocatenwet), and lawyers should be able to explain their AI tool choices to a disciplinary panel if asked.

NOvA is less directive than the German or pan-European positions. It points at the same operational outcome anyway: a lawyer using customer-environment deployment of AI sits on stronger disciplinary ground than one using a hosted AI service whose data path the lawyer cannot audit. For a Dutch legal-tech vendor, this is the local-bar answer to the European architectural question.

Where the bar guidance meets the EU AI Act

Bar association guidance is one regulatory layer. The EU AI Act is another. The two layers were drafted for different audiences and push toward the same architectural answer.

When a law firm uses an AI system in legal work, the firm becomes a deployer within the meaning of the EU AI Act. Most legal-sector AI use (document triage, case-file drafting, correspondence generation) sits outside the high-risk classification in Annex III, so the heavy Article 26 obligations on logging, human oversight, and monitoring do not automatically attach. The EU AI Act still imposes general obligations on every deployer: AI literacy among the staff who operate the system under Article 4, and transparency disclosure under Article 50 where the system interacts with natural persons or generates synthetic content. Those general obligations are lighter than Article 26 but still presuppose that the deployer can see what the AI is doing.

Annex III's point 8 (administration of justice and democratic processes) sets the line above which Article 26 attaches in full. Most law-firm AI sits below it; a tool that triages incoming case files or drafts initial correspondence is far from an AI system used by a judicial authority. The line moves with the use case, not with the vendor's marketing.

The architectural requirement does not depend on the high-risk classification. Bar association discipline requires the lawyer to maintain confidentiality whether the tool is high-risk or not. EU AI Act deployer obligations require the deployer to know what the system is doing whether the tool is high-risk or not. A hosted AI service whose runtime sits behind a vendor's management plane fails both tests from the outset. Customer-environment deployment passes both. This is the structural meaning of legal AI confidentiality in 2026.

Why the three positions converge on customer-environment deployment

Three bars in three different jurisdictions, plus the EU AI Act. The recommendation they converge on is architectural, and the mechanism is single: attorney-client privilege fails when a third party enters the confidentiality relationship, and EU AI Act deployer obligations fail when a vendor-controlled management plane enters the runtime path the firm cannot audit. A hosted AI service does both. The bars are uncomfortable with the first; the EU AI Act assumes the second cannot exist.

Customer-environment deployment removes both. The AI runs inside the law firm's environment: its on-premises hardware or its cloud account. The firm holds the keys, the access controls, and the logs. There is no vendor back-channel into the management plane; there is no third party in the data path. The deployment is the same architectural pattern that customer-environment private AI takes for fintech and health-tech buyers, with one difference. The legal sector is where two regulatory layers converged on the architecture before the cloud-AI vendors had time to argue against it.

Three-column comparison table of European bar positions on legal AI confidentiality: bar association, regulatory position, and architectural implication for AI deployment.

If you are selling generative AI tooling into European law firms in 2026, the Council of Bars and Law Societies of Europe Guide is the single strongest reference you can point at when the firm's compliance or information-security function asks how your tool handles privileged information. The guide is publicly available, authoritative within the European legal community, and architecturally directive. Most of your competitors are not using it, because they are positioning around a hosted-API model that the guide does not endorse.

For a legal-tech startup whose product depends on running generative AI against case files, customer-environment deployment maps onto both the Council of Bars guidance and the EU AI Act Article 26 deployer obligations. The deployment runs inside the law firm's environment: on-premises hardware or the firm's own cloud account. Privileged data never leaves the firm's perimeter. The runtime stays visible to the firm's information-security team for monitoring, logging, and human-oversight purposes. The lawyer can defend the architecture in front of any disciplinary panel using the bar's own guidance, and in front of any EU AI Act audit using the deployer obligations directly.

deeplit® is the customer-environment deployment infrastructure for this pattern in the legal-tech market. We deploy open-weight models inside the law firm's environment, with the access pattern and the audit boundary documented in their own posts. The law firm holds the keys, the access controls, and the logs. There is no deeplit® management-plane back-channel into the runtime: no remote support access, no telemetry path back to deeplit® systems, no model updates pushed without the firm's approval. The deployment is designed to support the General Data Protection Regulation and the EU AI Act, plus the Council of Bars architectural recommendations by inheritance.

If your law firm customer is asking where AI processes their case files, the next step is a thirty-minute deployment call. Bring the firm's information-security questionnaire, and we will walk through the bar-association references and the Article 26 deployer obligations with you. Book a deployment call.

If your law firm end-customer's information-security officer is the one asking where case files go, this post is written to be forwarded to them. The Council of Bars recommendation is theirs to cite.

The European bars converged on architecture before US bars converged on policy.

The Council of Bars guidance and the EU AI Act Article 26 deployer obligations point at the same architectural choice.

Frequently asked questions

No, it is not binding law. It is an authoritative interpretation by the body that represents the European bar associations, and it carries weight in disciplinary proceedings and in procurement decisions, but a court would not treat it as a directly applicable rule. For most procurement conversations, the distinction does not matter; the guide is treated as the directional reference point regardless. The EU AI Act sits next to the guide as binding law in parallel: Article 26 deployer obligations attach when the legal AI use case falls into a high-risk category under Annex III, and the general deployer obligations under Article 4 and Article 50 attach to every legal AI use case. The architectural conclusion is reinforced from both the soft-law and the binding-law side.

Does the recommendation apply to non-European Union law firms with European Union clients?

The Council of Bars and Law Societies of Europe Guide is directed at European bars and lawyers practicing under European bar regulation. A non-European Union law firm with European Union clients is not directly subject to it, but if the firm advertises European Union legal capability or operates a European Union office, the bar association governing that office will apply the guidance. The cleanest practical answer for a vendor: assume the guide's architectural recommendation applies to any European Union legal-practice context.

What about firms that already use hosted generative AI tools?

The October 2025 guide is forward-looking. It does not retrospectively invalidate hosted-tool usage. Many European law firms already have hosted-tool relationships under data processing agreements that predate the guide. The practical effect is to shift the architectural preference for new procurement, not to require a rip-and-replace of existing deployments. The harder question for an existing hosted deployment is the EU AI Act layer: if the use case crosses the Annex III line at any point, the deployer obligations attach to the firm regardless of when the deployment was contracted, and the architecture has to support the obligations the firm now owes.

Is "locally" narrower than "within a secured environment controlled by the law firm"?

The guide treats them as alternative means to the same end. "Locally" usually means on hardware physically located at the law firm's premises. "Within a secured environment controlled by the law firm" is broader and includes deployment in the firm's own cloud account, deployment on hardware in a colocation facility the firm controls, or deployment on managed hardware where the firm holds the keys and the access controls. Customer-environment deployment, in either the cloud-account or on-premises variant, falls within "within a secured environment controlled by the law firm."

Most law-firm AI sits outside the EU AI Act's high-risk classification today. Annex III's point 8 covers AI systems used by judicial authorities or on their behalf in the administration of justice and democratic processes; advocates and law firms are not judicial authorities, so a tool that drafts correspondence or triages incoming case files is well below the line. A tool that automates an aspect of judicial decision support, under contract to a court, sits much closer. The classification follows the use case, not the vendor; legal-tech founders should expect to revisit it whenever the product scope changes.

Read next

H. Kamkar headshot

H. Kamkar

Building private AI infrastructure for startups selling into regulated industries.