If your company uses ChatGPT, Copilot, a customer-service chatbot or any other AI tool, you may already have a legal risk nobody has flagged yet.
An AI Legal Assessment is how you find out before a client, investor or authority asks. In this article I explain what it is, the signals that your company needs one, and what happens if you keep putting it off.
You do not need to be an AI startup or have a tech department. It is enough that you use AI somewhere: hiring, marketing, customer support, data analysis or content generation. Today, that is almost every company.
What an AI Legal Assessment is (without the jargon)
An AI Legal Assessment is a legal review of how your company uses artificial intelligence: which tools you use, which data you feed them, which decisions they make — or help you make — and which rules apply as a result.
Think of it as an audit, but instead of checking your accounts it reviews your AI-related legal risks: data protection, intellectual property, transparency toward customers and compliance with the EU AI Regulation (AI Act).
The goal is not to stop you or scare you. It is to know exactly where you stand before someone else asks.
6 signals your company needs an AI Legal Assessment
You do not have to wait for a problem to run this review. These are the most common signals:
1. You use AI to make decisions about people
If your AI tool screens CVs, scores customers, adjusts prices or decides which content each user sees, you are on the radar of rules that require transparency and, in some cases, mandatory human oversight.
2. You put customer or employee data into AI tools
Copying and pasting personal information into ChatGPT, Claude or any generative AI without checking what happens to that data is one of the most frequent — and easiest to avoid — risks. GDPR applies even to one-off use.
3. You offer a product or service that uses AI facing the customer
Chatbots, recommenders, automated content, scoring… If the customer interacts with something powered by AI, you may have a legal duty to say so clearly.
4. You sign contracts with AI providers or SaaS tools that include AI
Many tools you use every day already include AI without you having negotiated it explicitly. That means you are accepting terms about your data you probably have not read. More detail in the guide to AI clauses in SaaS contracts.
5. A client or investor has asked for guarantees about your AI use
Before signing a large contract or closing a funding round, it is increasingly common to be asked how you manage AI risk. Without a clear, documented answer you lose credibility — and sometimes the deal.
6. The AI Act starts requiring documentation you do not have
The EU AI Regulation sets staggered duties by risk level. If you do not know your system’s risk level, you also do not know whether you are non-compliant. See the AI Act calendar for companies for what already applies.
What happens if you do nothing
Nothing happens… until it does. AI-related problems rarely show up on day one. They appear when:
- A client asks how you handle their data and you have no clear answer.
- An audit or due diligence finds there is no AI-use policy.
- An employee uploads confidential information to an AI tool without realising they should not.
- The AI Act starts requiring documentation you do not have ready.
In every case, fixing it after the fact costs more than reviewing it in time.
What a solid AI Legal Assessment includes
A good review is not a 40-page report nobody can read. It should be:
- An inventory of AI tools your company uses and for what.
- Concrete legal risks tied to each use (yours, not generic ones).
- Applicable rules for your case: AI Act, GDPR, intellectual property.
- Prioritised recommendations: what to fix now and what can wait.
- Plain language so you can act without a legal dictionary.
At Legal Stones that review is the AI Legal Assessment: a clear remote deliverable, with a report in 5–10 business days.
AI Legal Assessment vs GDPR audit: is it the same?
No. They are related but not the same:
- GDPR audit: focuses on how you process personal data in general.
- AI Legal Assessment: looks specifically at risks from AI use, including data protection and also intellectual property, user transparency and AI Act compliance.
If you already have a GDPR audit, the AI Legal Assessment adds the missing layer: risk specific to AI systems.
Does it work for small companies?
Yes. Most of our cases are SMEs and freelancers using tools like ChatGPT, Copilot or customer-service chatbots — not companies building their own AI. The earlier you do it, the cheaper it tends to be.
FAQ
Is an AI Legal Assessment mandatory by law?
There is no statute with that exact name, but the AI Act does require documenting and assessing risks for certain AI uses, especially high-risk ones. If your company falls into those cases, the assessment stops being optional and becomes mandatory.
How much does an AI Legal Assessment cost?
It depends on how many AI tools you use and how complex your processes are. At Legal Stones we size the scope to each company; the first step is always a short conversation with no obligation.
How long does the review take?
For most SMEs and freelancers, 5 to 10 business days from the moment you share information about your tools and processes.
Do I need an existing legal problem to request one?
No. Most companies contact us preventively, before a client, investor or audit asks for explanations. It is cheaper and faster to review it first.
How is it different from the AI Act Quick Check?
The AI Act Quick Check is a 30-minute orientation to see whether the AI Act applies to you. The AI Legal Assessment is a full analysis: tool inventory, risk classification, roadmap and concrete recommendations.
If two or more of the signals above sound familiar, it is a good time to run the review before someone else asks for it. Request your AI Legal Assessment and we will tell you, with no obligation, what it would cover in your case.