⚖️ AI rules: Lawyers, accountants, consultants
Mostly minimal-risk AI use — but professional secrecy and client data make GDPR and confidentiality the main issue.
Typical AI uses and their risk level
Minimal; a professional checks every output; beware of invented case law.
Only in tools with a DPA and no training on data — or pseudonymise first.
Minimal; DPA with the provider.
High risk (Annex III, point 8) when used by or for judicial authorities.
What to do
- Agree with clients whether and how AI is used on their files.
- Use business plans or local tools; pseudonymise documents.
- Verify every citation and figure.
Common pitfalls
- Professional secrecy is broken if client files go to a tool that uses them for training.
Examples
Courts in several countries sanctioned lawyers for citing invented cases — always check sources.
Rules that apply
For most companies GDPR matters more than the AI Act: it decides whether you may put customer or employee data into an AI tool at all. In Slovenia it is supplemented by ZVOP-2 and supervised by the Information Commissioner.
Applies in phasesAI ActApplies to anyone who develops AI (provider), uses AI in their business (deployer), imports or distributes it in the EU — also to companies outside the EU if the output is used in the EU. Private, non-professional use is excluded.
In forceCopyright and AIProviders of general-purpose AI models must have a copyright policy that respects opt-outs and publish a summary of training content (AI Act, Art. 53). Pure AI output without human creative input is generally not protected by copyright.
In forceZVOP-2AI on cameras (face recognition, behaviour analysis) and biometric attendance systems fall under strict ZVOP-2 rules — often they are simply not allowed. The Information Commissioner has published opinions on AI, e.g. on misleading use of AI systems and on accountability.
General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.