The transmission of personal data from one jurisdiction to another, subject to GDPR transfer mechanisms such as Standard Contractual Clauses or adequacy decisions when EU data is involved.
Last reviewed: 2026/05/18
An AI system classified under Annex III of the EU AI Act as posing significant risk to health, safety, or fundamental rights, subject to conformity assessment before deployment.
EU RegulationThe EU AI Act's mandatory pre-deployment verification process confirming a high-risk AI system meets safety, transparency, and accuracy requirements before market placement.
EU RegulationThe EU's comprehensive AI regulation, in force August 2024, imposing risk-tiered obligations on AI developers and deployers — with legal sector compliance requirements escalating through 2026–2027.
EU RegulationThe EU AI Act's mandate that high-risk AI systems be designed to allow human monitoring, intervention, and override — directly applicable to legal AI tools used in client-facing or adjudicative contexts.
Move from this definition to role-based legal AI shortlists and the selection criteria that matter for each type of legal team.
Am Law 200 and global firm workflows: accuracy at scale, security compliance, and matter-level auditability.
Specialist firm workflows: deep practice area expertise, premium client service, selective tool adoption.
Legal department workflows: contract lifecycle, regulatory tracking, outside counsel management, and risk.
Last reviewed: 2026/05/18. Definitions are written by the LawyerAI Editorial team. Commercial relationships are disclosed and do not determine editorial scores or conclusions. See our Sponsorship & Affiliate Disclosure.
A cross-border data transfer occurs whenever personal data is moved from one country to another, including through remote access, cloud processing, or API calls to servers abroad. Under GDPR, transferring personal data outside the EU/EEA is restricted unless the destination country has been granted an adequacy decision by the European Commission, or an approved transfer mechanism — most commonly Standard Contractual Clauses (SCCs) or Binding Corporate Rules — is in place. The 2023 EU-US Data Privacy Framework provides an adequacy basis for transfers to certified US organisations, though its continued validity is subject to legal challenge.
Every time a lawyer uploads a document containing personal data to a cloud-based AI tool hosted outside the EU, a cross-border data transfer may be occurring. Firms must map these data flows, ensure appropriate transfer mechanisms are in place with each vendor, and document their legal basis. The absence of a valid transfer mechanism is a GDPR infringement that can attract significant fines and reputational damage.