Claira Stories

Is Your eDiscovery AI High-Risk Under the EU AI Act? Reading Annex III Properly

Summarize with AI

The question now arrives in procurement questionnaires, usually phrased as an assertion rather than a question. Your AI review tool touches litigation. Litigation is the administration of justice. The administration of justice is a high-risk category under the EU AI Act. Therefore your tool is a high-risk AI system, and the full weight of Chapter III applies to it.

The chain sounds tight. It breaks at the first link, and it breaks on the plain text of the provision everyone is citing.

This post covers what Annex III point 8(a) actually says, why party-side document review sits outside it, what the Article 6(3) filter does and does not do, and which obligations genuinely bind a European firm using AI for review today. The short version is that the high-risk regime is aimed at courts rather than at counsel, the deadline most people are anxious about has moved to December 2027, and the duties that are already live are narrower than the ones you are being asked to attest to.

Point 8(a) is gated on who uses the system, not on what it touches

Annex III point 8(a) captures "AI systems intended to be used by a judicial authority or on their behalf to assist a judicial authority in researching and interpreting facts and the law and in applying the law to a concrete set of facts, or to be used in a similar way in alternative dispute resolution."

Read the opening clause slowly. The gateway is the actor. The system must be intended for use by a judicial authority, or by someone acting on that authority's behalf. Subject matter alone does not pull a system into the category. A tool can be steeped in litigation from end to end and still sit outside point 8(a), because proximity to litigation is not the test.

Recital 61 confirms the reading and explains the concern behind it. The classification exists because such systems bear on the rule of law and on "the right to an effective remedy and to a fair trial," and because "the final decision-making must remain a human-driven activity." The recital then carves out "purely ancillary administrative activities that do not affect the actual administration of justice in individual cases."

A responsiveness review run by a party, for a party, inside that party's own review platform, is not a judicial authority doing anything.

The Commission has said this directly, though not yet finally

In May 2026 the Commission published draft guidelines on the classification of high-risk AI systems. The Annex III volume addresses our question almost verbatim, stating that AI systems "intended to be used by parties and their legal representatives, do not fall within the scope of point 8(a) of Annex III, as parties and their representatives are not acting on behalf of a judicial authority."

The draft also reads "on behalf of" more tightly than most people assume. An expert falls inside only where the court appoints or instructs them and they work under its procedural control. A party-appointed expert stays outside.

Two honest caveats. These guidelines remain in draft, and the consultation closed only in July 2026. Even once final, Commission guidelines are interpretive rather than binding, and they do not constrain the Court of Justice or a national court. There is no case law on point. Treat this as the better reading of the text, not as settled authority.

The Article 6(3) filter is a trap you do not need to walk into

Practitioners often reach for Article 6(3), which lets a system inside an Annex III area escape classification where it performs a narrow procedural task, improves a previously completed human activity, detects decision-making patterns, or performs a preparatory task.

Reaching for it here is a mistake, and an instructive one. The Commission's draft guidance says these conditions must be construed narrowly, and it draws a line that cuts against review tools. Deduplication, format conversion and sorting documents into categories are offered as narrow procedural tasks. But systems that "perform a value judgement of data relevant for decision-making," including "attributing a score or ranking," are said not to qualify.

Responsiveness scoring is exactly that kind of value judgement. So if you concede that party-side review sits inside Annex III and then argue your way out through Article 6(3), you will probably lose. The point is not that the filter is unavailable. The point is that you never reach it, because the actor test excluded you three steps earlier. We have written before about the same analytical move in a Canadian setting, in what Crown counsel need to know about AI in evidence review, where the Directive on Automated Decision-Making is routinely raised against tools it was never drafted to reach.

The deadline moved, and the one that did not move is the one that matters

The date circulating in most compliance calendars is 2 August 2026. It is out of date. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted on 8 July 2026 and entered into force on 27 July 2026. It amends Article 113 so that the Annex III high-risk obligations now apply from 2 December 2027, with the Annex I route following on 2 August 2028. The stated reason was the delayed availability of standards and of national competent authorities.

The Omnibus left Article 50 alone. Transparency obligations have applied since 2 August 2026. So has Article 4 on AI literacy, in force since February 2025 and softened by the Omnibus into a duty to support the development of staff AI literacy rather than to guarantee any particular level of it.

For most European firms that inverts the usual anxiety. The obligation you are furthest from is the one the questionnaire asks about. The obligations already live are the ones nobody asks about.

What sits on you, and what sits on your vendor

The distinction that resolves most of these conversations is provider versus deployer. A firm licensing a review platform is a deployer, using the system under its own authority in a professional capacity. Conformity assessment, CE marking, technical documentation and Article 49 registration are provider obligations. They do not migrate to you because you bought the software.

Article 25 is the exception worth knowing. You become a provider if you put your own name or trademark on a high-risk system, substantially modify one, or change the intended purpose of a system so that it becomes high-risk. Firms assembling bespoke agentic workflows on top of a general-purpose model should read that provision carefully. The duty to mark synthetic content also sits on the provider, so it lands on your vendor and on the model provider upstream.

Where to start

Do not begin with a classification memo. Begin with two documents.

The first is a short scope note recording why your review workflow falls outside Annex III point 8(a), citing the actor gateway and the Commission's draft guidance. Keep it to a page. It answers the questionnaire, and it survives the reader who arrives with the assertion rather than the question.

The second is a factual description of where your processing happens, what is retained, and who the subprocessors are. This satisfies clients, and it is separate from AI Act classification. Ours is published in Claira's privacy and security documentation, covering deployment regions, per-request processing and retention. Whatever platform you use, you should be able to produce the equivalent on request.

Then track December 2027 without dreading it. Classification is not something you discover late. It follows from who uses the system and for what, and for party-side discovery that answer is already clear.

If you would like to work through how this reads against your own matters and client questionnaires, book a short session with our team. We would rather help you write the scope note than watch a good project stall on a provision that was never pointed at you.

See Claira on your own documents

Fifteen minutes, on a sample from a real matter. No new platform to evaluate.

Book a 15-minute demo

Claira webinar

11:00 AM EST

Next live webinar

Why Firm Leaders Are Bringing AI Review Into Nuix

Document review is the largest and least differentiated cost on most matters, and it's the line clients scrutinize hardest under fixed fees and budgets. This session is for the partners and firm leaders who own the Nuix relationship and are being asked, with growing frequency, what the firm is actually doing with AI. In about twenty minutes we walk a live matter end to end inside Nuix Discover: defining a responsiveness criterion, running it across a set, and watching the coding land on your existing fields, with the reasoning behind every call visible and the data never leaving your environment. From there we get to what it means for the firm: what AI-assisted review does to hours per document, how that changes the math on a fixed-fee matter, and how it lets you take on volume you would otherwise turn away. We close on how firms run it defensibly - human review, a full audit trail, and Canadian data residency built in - so you can tell clients you use AI review and stand behind exactly how.

Claira webinar

11:00 AM EST

Next live webinar

Why Firm Leaders Are Bringing AI Review Into Nuix

Document review is the largest and least differentiated cost on most matters, and it's the line clients scrutinize hardest under fixed fees and budgets. This session is for the partners and firm leaders who own the Nuix relationship and are being asked, with growing frequency, what the firm is actually doing with AI. In about twenty minutes we walk a live matter end to end inside Nuix Discover: defining a responsiveness criterion, running it across a set, and watching the coding land on your existing fields, with the reasoning behind every call visible and the data never leaving your environment. From there we get to what it means for the firm: what AI-assisted review does to hours per document, how that changes the math on a fixed-fee matter, and how it lets you take on volume you would otherwise turn away. We close on how firms run it defensibly - human review, a full audit trail, and Canadian data residency built in - so you can tell clients you use AI review and stand behind exactly how.

Claira webinar

11:00 AM EST

Next live webinar

Why Firm Leaders Are Bringing AI Review Into Nuix

Document review is the largest and least differentiated cost on most matters, and it's the line clients scrutinize hardest under fixed fees and budgets. This session is for the partners and firm leaders who own the Nuix relationship and are being asked, with growing frequency, what the firm is actually doing with AI. In about twenty minutes we walk a live matter end to end inside Nuix Discover: defining a responsiveness criterion, running it across a set, and watching the coding land on your existing fields, with the reasoning behind every call visible and the data never leaving your environment. From there we get to what it means for the firm: what AI-assisted review does to hours per document, how that changes the math on a fixed-fee matter, and how it lets you take on volume you would otherwise turn away. We close on how firms run it defensibly - human review, a full audit trail, and Canadian data residency built in - so you can tell clients you use AI review and stand behind exactly how.