If your company uses ChatGPT, Copilot, Gemini, or any other AI tool — or is evaluating integrating one into workflows that touch customer data — you've probably come across the term «AI legal risk assessment» or «AI legal audit» without being entirely sure what it actually covers, or whether your company needs one now or can wait.
This article explains it plainly: what it is, how it differs from a GDPR audit, what a serious assessment should include, and when it's worth requesting one.
What is an AI legal risk assessment (and how does it differ from a GDPR audit)
An AI legal risk assessment is a focused analysis of how your company uses (or plans to use) AI systems, aimed at identifying:
- Applicable regulatory obligations — primarily the EU AI Act (Regulation (EU) 2024/1689), but also GDPR, intellectual property, and sector-specific rules where relevant
- The risk level of each AI system or use case, following the AI Act's own classification (unacceptable, high, limited, minimal risk)
- Contractual exposure points: what your AI vendor's contract does (or doesn't) say about data use, model training, and liability
- Internal governance gaps: whether an internal AI use policy exists, and whether it's actually followed in practice
The distinction from a GDPR audit matters, and it's a very common point of confusion:
A GDPR audit looks at personal data processing broadly — legal bases, retention periods, security measures. An AI legal risk assessment includes a review of personal data whenever AI touches it, but goes further: it also covers AI Act risk classification, the contractual relationship with the AI vendor specifically, and issues that aren't data protection matters at all — such as who is liable if the model produces an incorrect output, or who owns the intellectual property of AI-generated content.
In short: every AI risk assessment touches on GDPR, but not every GDPR audit covers the specific risks introduced by AI.
What companies actually mean when they say «AI legal audit»
In practice, when a company asks for an «AI legal audit,» they're usually trying to answer one of these questions:
- «Can we safely put customer data into ChatGPT?»
- «What happens if our customer service chatbot gives an incorrect or discriminatory answer?»
- «Do we need to tell customers they're interacting with an AI?»
- «Does the contract we signed with our AI vendor protect us, or leave us exposed?»
- «Does the AI Act apply to us if we only use productivity tools, not AI we've built ourselves?»
The good news (and it often surprises people): most SMEs using AI for productivity — drafting emails, summarizing documents, generating code — fall into the minimal or limited risk category under the AI Act, not high risk. But «minimal risk» doesn't mean «no risk» — GDPR and your vendor's contractual terms still apply regardless.
What a complete AI legal risk assessment includes
A serious report isn't a generic checklist. At minimum, it should include:
Inventory of AI tools in use
Which tools the company uses (ChatGPT, Copilot, Gemini, vertical AI tools), in which departments, and for which specific tasks — many companies discover at this stage that more tools are in use than leadership was aware of.
AI Act classification
For each identified use, determining which risk category it falls into: unacceptable (prohibited), high risk (Annex III or Annex I), limited risk (transparency obligations), or minimal risk.
Data and GDPR review
What personal data flows through each tool, whether there is a processor relationship and a DPA with the vendor, how international transfers are covered, and whether the AI vendor uses that data to train its models (this is critical, and many companies don't know the answer).
Vendor contract review
Terms of service, DPA (Data Processing Agreement), model training clauses, server location, and what happens in the event of a security breach. Where needed, this sits with a contract review.
Internal AI use policy
Whether one exists, whether it reflects what staff actually do in practice, and whether it addresses scenarios like what information should never be entered into external AI tools.
Key AI Act dates 2026–2028
Regulation (EU) 2024/1689 applies on a staggered timeline. The Digital Omnibus on AI — Regulation (EU) 2026/1744, voted by the European Parliament on 16 June 2026 and in force since 27 July 2026 — does not freeze the rules: it postpones part of the high-risk duties and adds targeted changes. The schedule now looks like this:
| Date | What takes effect |
|---|---|
| 2 February 2025 | Prohibited practices and AI literacy (already in force) |
| 2 August 2025 | Obligations for general-purpose AI (GPAI) models, institutional governance, and the penalty regime |
| 2 August 2026 | Wider application, including Article 50 transparency: informing users when they interact with a chatbot or AI system |
| 2 December 2026 | New Article 5 prohibitions (non-consensual intimate content and child-abuse material) and, for generative systems already on the market, the technical marking duty in Article 50(2) |
| 2 August 2027 | GPAI models placed on the market before August 2025 must reach full compliance |
| 2 December 2027 | High-risk systems under Annex III (postponed from August 2026 by the Digital Omnibus) |
| 2 August 2028 | High-risk systems embedded in regulated products (Annex I) |
The important nuance: the Digital Omnibus postponement moved Annex III high-risk obligations from August 2026 to December 2027 — but it did not affect the Article 50 transparency obligations, which still apply from August 2026. 2 December 2026 is not a generic “new prohibitions package” for every company: it is a narrow change. If your company runs a customer-facing chatbot, that transparency duty has not been delayed.
For a full breakdown of each date and what it means for your company depending on how you use AI, see the complete guide: AI Act for companies: 2026–2028 guide.
ChatGPT, Copilot, and customer data: when there's already risk
This is probably the most common — and least monitored — scenario inside companies today:
An employee copies a customer's email, or a snippet of a contract, into ChatGPT to ask for a summary or a better draft. It looks harmless. But several risks can already be at play:
- GDPR risk: if the text contains personal data, you are processing data through a third party (the AI provider). The usual issue is not that “there is no legal basis”, but that a DPA is missing, international transfers are unclear, or the provider trains on that data
- Training risk: depending on the plan and settings, that content may be used to train the model — meaning your customer's confidential information can end up «inside» a system you don't control
- Contractual risk: if you have a confidentiality agreement with that customer, entering their data into an external tool can amount to a breach
This doesn't mean AI use should be banned — it means the risk shows up much earlier than most companies assume, and you don't need to be doing anything «advanced» with AI to be exposed. Everyday productivity use is enough.
For concrete examples of how this plays out day to day (beyond the theory), see our practical cases: 6 signs your company needs an AI Legal Assessment.
How this connects to your contracts (SaaS, ChatGPT Enterprise, DPA, training clauses)
This is where an AI legal risk assessment connects directly to something very concrete: the contract you've already signed (or are about to sign) with your AI vendor.
It doesn't matter how well-designed your internal AI use policy is if the vendor contract:
- Doesn't clearly state whether your data is used to train the model
- Doesn't include a valid Data Processing Agreement (DPA) under GDPR
- Doesn't specify where servers are located (inside or outside the European Economic Area)
- Doesn't define clear liability if the system produces an erroneous or harmful output
- Contains liability limitation clauses disproportionately favoring the vendor
This applies whether you're on a standard ChatGPT plan, have a ChatGPT Enterprise agreement, Copilot for business, or any SaaS tool with AI built in. The more «enterprise» the plan, the more room there usually is to negotiate these clauses — but only if you know what to ask for.
That's why the AI legal risk assessment and contract review go hand in hand: one identifies the risks, the other closes them on paper. See also our guide to AI clauses in SaaS contracts.
When the Quick Check is enough, and when you need the full Assessment
Not every company needs the same depth of analysis. As a rule of thumb:
The AI Act Quick Check (about a 30-minute session) makes sense if:
- You want a first, fast snapshot of which AI Act risk category your AI uses fall into
- You're not yet sure whether you need to go further
- This is your first look at the topic
The full AI Legal Assessment (complete evaluation, 5–10 business days) makes sense if:
- You already use several AI tools across different departments and want a complete picture, not just a first pass
- You're about to sign (or renew) a significant contract with an AI vendor
- You handle sensitive or high-volume customer data through AI tools
- You need to be able to demonstrate due diligence (to customers, partners, or in the event of an inspection)
Frequently asked questions about AI legal risk assessments
Is an AI legal risk assessment mandatory?
The AI Act does not require a document with that name for every company. Limited-risk uses (for example a chatbot) mainly trigger Article 50 transparency. The more demanding risk-management and documentation duties sit with high-risk systems; Annex III obligations, after the Digital Omnibus, are postponed to 2 December 2027. The assessment is the practical way to see what applies to you and to demonstrate it.
How long does the process take?
A Quick Check is a session of about 30 minutes. For most SMEs, a full Assessment takes 5 to 10 business days from the moment you share tools and processes.
Does it replace a GDPR audit?
No. They're complementary. An AI risk assessment includes a review of personal data whenever AI touches it, but it doesn't replace a company-wide GDPR audit.
Does it apply if we only use AI internally, not customer-facing?
Yes, though the obligations differ. A customer-facing chatbot has specific transparency obligations (Art. 50); an internal tool used to draft reports has a different risk profile, but GDPR and vendor contract terms remain relevant in both cases.
What happens if we do nothing?
The AI Act provides for fines of up to €35 million or 7% of worldwide annual turnover for the most serious infringements, and up to €15 million or 3% for others (for example transparency). Beyond the fine, the more immediate risk is usually contractual or reputational: a customer data leak through a poorly configured AI tool, or a vendor contract lacking adequate safeguards.
Legal basis: Regulation (EU) 2024/1689 (AI Act) and Regulation (EU) 2026/1744 (Digital Omnibus on AI). Content reviewed August 2026. General guidance; does not replace personalized legal advice.