AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities
AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities is becoming an increasingly important topic for law firms, legal departments, compliance teams, Data Protection Officers and organisations introducing artificial intelligence into everyday work.
Artificial intelligence is no longer relevant only to software engineers and technology companies. Lawyers and DPOs already use AI tools to review documents, organise information, prepare drafts, create training materials, analyse contracts and support compliance-related work.
These tools can save time and improve productivity, but their use also creates important legal and organisational questions:
- Can confidential information be entered into an AI tool?
- Can an AI system process personal data?
- Who verifies the accuracy of AI-generated content?
- May AI support decisions that affect individuals?
- Does the organisation know where submitted data is stored?
- Are employees trained to use AI responsibly?
- What internal rules should apply before AI tools are introduced?
These questions are no longer theoretical. They are becoming part of daily legal, compliance and data protection practice.
The European Union adopted Regulation (EU) 2024/1689, known as the Artificial Intelligence Act. It establishes harmonised rules for artificial intelligence and introduces obligations based on the risks created by particular AI systems and their uses.
AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities is not only a regulatory topic, but also a practical question of how professionals use AI in everyday work.

AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities in daily work
The most useful way to approach AI in legal and data protection work is straightforward: AI can support professionals, but it should not replace their judgment.
A lawyer may use AI to prepare a first draft, compare clauses, summarise a lengthy document or organise legal arguments. However, the lawyer must still:
- verify legal accuracy;
- check the relevant jurisdiction;
- examine the context;
- confirm legal sources;
- identify missing information;
- take responsibility for the final advice.
A DPO may use AI to prepare training materials, organise questions for a data protection impact assessment, draft internal procedures or summarise regulatory guidance. However, the DPO must still assess the organisation’s actual processing activities, identify genuine risks and determine whether the processing complies with applicable data protection rules.
AI may accelerate certain tasks, but speed has value only when the final result is accurate, lawful and properly reviewed.
How can lawyers use AI in practice?
AI can be useful in legal work where professionals need to review, structure or compare large amounts of information.
AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities also requires lawyers to verify every AI-generated legal reference, conclusion and recommendation.
Possible uses include:
- preparing the first structure of a legal memorandum;
- summarising long documents;
- comparing different contract versions;
- identifying potentially missing clauses;
- organising arguments;
- preparing internal checklists;
- creating client-friendly explanations;
- reviewing policies;
- preparing questions for legal research;
- structuring training materials.
In contract work, AI may help identify differences between drafts, extract obligations and flag provisions that require closer examination.
In legal research, it may help structure the research process and summarise materials. However, AI-generated cases, citations, statutory references and legal conclusions must always be independently verified.
AI systems can produce information that appears convincing while being incomplete, outdated or incorrect. For that reason, AI-generated legal content should be treated as a working draft rather than final legal advice.
How can DPOs and privacy professionals use AI?
Data protection work frequently involves large volumes of documents, internal procedures, registers and correspondence. AI may assist DPOs and privacy professionals by helping them prepare or organise:
- privacy notice drafts;
- employee data protection notices;
- internal policies;
- data protection training;
- DPIA questionnaires;
- vendor assessment checklists;
- breach response templates;
- records of processing activities;
- summaries of regulatory guidance;
- data-mapping interview questions.
AI can also help structure information collected from different departments. For example, it may assist with grouping processing activities by department, purpose, category of data or type of data subject.
However, the DPO must understand how the AI tool itself processes information.
Before using an AI system, the DPO should examine:
- whether personal data is entered into the tool;
- whether special-category data is involved;
- whether confidential information is submitted;
- whether prompts and uploaded files are retained;
- whether the data may be used for model training;
- where the data is stored;
- whether international data transfers occur;
- what role the provider has under data protection law;
- whether appropriate contractual safeguards exist.
The European Data Protection Board’s Opinion 28/2024 addresses important questions concerning personal data and AI models, including when an AI model may be considered anonymous, the possible use of legitimate interests and the consequences of unlawfully processed personal data during model development.
The AI Act follows a risk-based approach
A central element of AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities is understanding that not every use of AI creates the same level of risk.
The EU AI Act uses a risk-based framework. Obligations depend on the AI system, its intended purpose and the context in which it is deployed. Official EU guidance distinguishes between prohibited practices, high-risk uses, transparency-related risks and uses presenting minimal or no risk.
An AI tool used to summarise publicly available legal information does not create the same risks as a system used to:
- assess job applicants;
- monitor employees;
- evaluate work performance;
- determine access to essential services;
- score customers;
- analyse behaviour;
- influence decisions concerning individuals;
- perform biometric identification or categorisation.
The legal assessment should therefore begin with the intended use rather than merely the name or provider of the tool.
The organisation should ask:
- What is the AI system used for?
- Who uses it?
- What data does it process?
- Does it process personal or confidential information?
- Who may be affected by the output?
- Does AI merely support a person or influence the final decision?
- Is meaningful human review provided?
- Can the output be explained and challenged?
- Have the risks been documented?
- Are users properly trained?
The AI Act does not replace the GDPR
The AI Act and the GDPR address different but frequently overlapping issues.
AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities must therefore be considered together with GDPR compliance whenever personal data is involved.
Where an AI system processes personal data, the organisation may need to comply with both frameworks.
GDPR requirements may include:
- identifying a lawful basis;
- providing transparent information;
- limiting processing to defined purposes;
- minimising the data used;
- ensuring data accuracy;
- establishing retention periods;
- applying appropriate security measures;
- regulating processors and service providers;
- respecting data subject rights;
- performing a DPIA where required;
- demonstrating accountability.
For example, when AI supports recruitment, employee monitoring, customer classification, personalised services, profiling or decisions that affect individuals, both AI regulation and data protection rules may be relevant.
This is why lawyers and DPOs should work together.
The lawyer may examine regulatory requirements, contracts, liability and legal consequences. The DPO may focus on personal data, lawful bases, transparency, data subject rights and risks to individuals. Technology and security teams should explain how the system operates and what happens to submitted data.
Responsible AI governance requires these perspectives to be connected.
Confidentiality and professional secrecy
Lawyers, DPOs and compliance teams regularly handle information that should not be entered into publicly accessible AI tools without an appropriate assessment.
This may include:
- client documents;
- legal opinions;
- litigation strategies;
- employment records;
- internal investigations;
- business plans;
- commercial secrets;
- personal data;
- health information;
- disciplinary records;
- security incidents;
- unpublished contracts.
Before uploading information, the user should understand whether the provider retains prompts and files, uses them for model improvement, permits administrator access or transfers data to other jurisdictions.
Where possible, confidential and personal information should be removed or anonymised before an AI tool is used. However, replacing a person’s name does not necessarily make the information anonymous if that person can still be identified from the remaining details.
A clear internal policy should explain which information must never be entered into unapproved AI systems.
Human review and responsibility
AI-generated content should not be accepted without meaningful professional review.
Human review does not mean briefly reading the output and approving it. The reviewer should understand:
- the purpose of the task;
- the relevant facts;
- the legal framework;
- the limitations of the AI tool;
- the possible consequences of an error.
For legal work, the reviewer should verify statutory provisions, judgments, deadlines, legal terminology and the applicability of cited authorities.
For data protection work, the reviewer should confirm that documents reflect actual processing activities rather than generic assumptions made by the AI system.
Responsibility remains with the professional and the organisation using the output. An AI tool cannot assume professional, disciplinary or organisational responsibility for inaccurate advice.
AI literacy is a compliance issue
Responsible AI use requires employees to understand the systems they use.
Article 4 of the AI Act requires providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy among staff and other persons using AI systems on their behalf. The appropriate level depends on factors such as knowledge, experience, training, context of use and the people who may be affected. This obligation has applied since 2 February 2025.
AI literacy does not mean that every lawyer, DPO or compliance officer must become a programmer.
Employees should understand:
- what the AI tool is designed to do;
- what its limitations are;
- that outputs may be incorrect;
- when human review is mandatory;
- what data may be entered;
- which tools the organisation has approved;
- which uses are prohibited;
- how to report a mistake or incident;
- who is responsible for the final result.
An instruction simply stating “use AI carefully” is not enough. Organisations need practical examples, approved-use cases and clear escalation procedures.
What should an internal AI policy contain?
A practical AI policy should be understandable to employees and connected to the organisation’s actual use of AI.
It may regulate:
Approved AI tools
The organisation should identify which tools may be used for business purposes and who approves new tools.
Permitted uses
Employees should understand whether AI may be used for drafting, summarising, translation, research, analysis or other tasks.
Prohibited information
The policy should explain whether users may enter personal data, confidential information, trade secrets, privileged documents or internal records.
Human review
The organisation should determine which outputs require professional verification and who is responsible for final approval.
Documentation
Certain uses may need to be recorded, particularly where AI affects individuals, supports important decisions or presents significant risks.
Incident reporting
Employees should know what to do if confidential information is submitted, an incorrect output is used or another AI-related incident occurs.
Training
The organisation should provide AI literacy training appropriate to the roles and responsibilities of its employees.
A useful policy should answer practical questions such as:
- Can I upload a client contract?
- May I use AI to summarise employee records?
- Can AI prepare a client email?
- May AI be used to analyse job applications?
- Can I rely on AI-generated legal citations?
- Who approves new tools?
- What should I do if I enter information by mistake?
The role of lawyers and DPOs in AI governance
AI governance should not be assigned exclusively to the IT department.
IT teams understand systems, security and technical infrastructure. Lawyers and DPOs contribute knowledge concerning legal responsibility, personal data, transparency, accountability, contracts and regulatory risk.
Lawyers and DPOs can support organisations by:
- preparing internal AI policies;
- reviewing AI provider contracts;
- assessing legal and data protection risks;
- identifying high-risk use cases;
- defining human review requirements;
- preparing transparency information;
- supporting DPIAs;
- creating employee guidance;
- delivering AI literacy training;
- documenting roles and responsibilities;
- monitoring regulatory developments.
For DPOs, AI will continue to be an important part of privacy work because many AI systems depend on data, including personal data.
For lawyers, AI will increasingly appear in commercial contracts, employment matters, intellectual property, litigation, liability assessments, technology procurement and regulatory compliance.
Professionals who understand both legal rules and the practical operation of AI systems will be better positioned to help organisations use technology responsibly.
AI for Lawyers and DPOs: Practical Use, Risks and Responsibilities should be translated into clear internal rules, employee training and defined responsibilities.

How we can help?
For many companies and institutions, the problem is not whether AI is useful. The problem is that AI is already being used without clear internal rules.
Employees may be using AI to draft emails, summarise documents, prepare reports or analyse information before the organisation has assessed the legal and compliance risks.
This is where we can help.
We can support companies, institutions, law firms and professional teams in understanding how AI can be used responsibly in legal, compliance, data protection and technology-related work.
Our support can include preparation of internal AI policies, AI literacy training, assessment of AI-related data protection risks, review of internal procedures, preparation of practical guidelines for employees, analysis of AI use cases and support in connecting AI governance with GDPR compliance.
The goal is not to create documents that exist only formally. The goal is to help your organisation understand how AI is actually used, what risks exist and what rules should be established before those risks become a problem.
If your organisation is already using AI tools, or plans to introduce them, now is the right time to define clear rules and ensure that AI supports your work without creating unnecessary legal, compliance or reputational risks.
Visit our page gdpr-compliance-package/
Official sources used: European Commission, EUR-Lex and European Data Protection Board.
