The EU AI Act's August 2026 transparency rules apply to UK law firms with EU clients too, and most firm websites and chatbots aren't ready.
Direct answer: If your UK law firm has EU-based clients, contacts, or website visitors, the EU AI Act's transparency obligations that took effect in August 2026 likely apply to you even though the firm sits outside the EU, because the Act's reach follows where an AI system's output is used, not where the company issuing it is registered. In practice, that means every AI-facing touchpoint on your website and client systems — chatbots, AI-drafted marketing copy, automated intake tools — needs a fresh look for whether it discloses its AI nature clearly enough. Firms running a modern, well-documented web stack have a short, manageable list of fixes; firms running years-old bolt-on chat widgets and undocumented scripts have considerably more work to do.
Deloitte's UK Tech Trends coverage of EU AI Act enforcement, published in August 2026, flagged a pattern a lot of UK businesses had quietly filed under "someone else's problem": the Act's transparency rules, which came into force that month, extend to UK companies that serve EU customers, regardless of Brexit and regardless of where the company is headquartered. That is the same extraterritorial logic that made GDPR relevant to UK firms with EU clients years after the UK left the EU legally — jurisdiction follows the person interacting with your systems, not your company's postal address. For law firms specifically, this lands at an awkward angle: many have leaned on AI tools for client-facing chat, document triage, and even first-pass drafting over the last two years, often without much formal review of what disclosure those tools legally require. A precise figure for how many UK law firms currently have EU-facing AI touchpoints that fall short of the new transparency standard is not publicly available, and we won't invent one — but the general pattern Deloitte describes, of transparency compliance lagging AI adoption across UK businesses serving EU markets, applies squarely to a profession that has adopted AI quickly and updated its client-facing web presence slowly.
What the EU AI Act's August 2026 Transparency Rules Actually Cover
The EU AI Act is a large piece of legislation with different obligations phasing in on different timelines, and it is easy to conflate its headline provisions — the ones covering "high-risk" AI systems — with the transparency rules that Deloitte's August 2026 coverage is actually about. The transparency obligations are narrower and, for most businesses, more immediately relevant than the high-risk category. At their core, they require that a person interacting with an AI system be told they are doing so, and that content generated or substantially altered by AI be identifiable as such, rather than presented as if a human produced it without assistance.
Disclosure, Not Prohibition
It is worth being precise about what these rules do and don't do, because the distinction changes how a firm should respond. The transparency chapter does not ban law firms from using AI chatbots, AI-assisted drafting, or automated client intake. It requires that the AI's involvement be disclosed clearly enough that a reasonable person isn't misled about whether they're dealing with a human or a system. That is a materially lower bar to clear than redesigning your entire AI stack, but it is also a bar that is easy to miss quietly, because most AI-facing tools were bought or built before this expectation existed, and disclosure was treated as a nice-to-have rather than a requirement.
Where "Serving EU Customers" Starts to Bite
The harder question for most firms isn't what the rules require — it's whether the rules apply to them at all. A UK firm with no EU offices and no EU-qualified lawyers might still serve EU customers in ways that trigger scope: cross-border transactional work for an EU-incorporated client, advisory work for an EU subsidiary of a UK group, a marketing site that EU visitors reach and interact with through a chatbot, or simply a client base that includes individuals resident in the EU. None of that requires a physical EU presence. The Act's logic, as Deloitte's reporting frames it, tracks the AI system's effect on EU-based users and customers, which is a fundamentally different scoping test than "do we have an EU office," and it is the test that catches firms off guard.
Provider or Deployer — Why the Distinction Matters
The Act generally separates obligations between the organization that builds or supplies an AI system and the organization that puts it to use with real people. Most law firms sit on the "deployer" side of that line: they didn't build the chatbot's underlying model, they configured a vendor's tool and pointed it at their website. That distinction matters practically, because it means a firm's realistic obligation usually isn't re-engineering how a third-party AI tool works internally — it's making sure the tool is configured, labelled, and disclosed correctly at the point where the firm's own clients and visitors encounter it. That's a much more tractable problem for an in-house team or a web development partner to solve than trying to audit a vendor's underlying model.
Why UK Law Firms Serving EU Clients Are Squarely in Scope
Law firms are a specific case worth separating out from "UK businesses generally," because a few features of how firms operate make this trend land harder on them than on an average services business.
First, client trust is the product. A law firm's entire value proposition rests on clients believing they are getting careful, accountable, human judgment. An AI chatbot on a law firm's website that fields an initial enquiry from a prospective EU client, without disclosing it's AI, doesn't just risk a compliance gap — it risks the client relationship itself once the client works out, mid-engagement, that their first interaction with the firm wasn't with a person. Transparency rules and client trust point in exactly the same direction here, which makes this less a "regulatory tax" and more a case where doing it properly is also the better business decision.
Second, firms increasingly use AI for content that looks and reads like expert commentary: client alerts, sector briefings, "what this ruling means for you" articles. If any of that copy is AI-drafted or AI-assisted and reaches EU readers without disclosure, it sits in exactly the territory the transparency rules were written to cover — content presented as if it reflects unaided human expertise when a system did meaningful work on it. For a profession whose credibility depends on precision, an undisclosed AI-generated client alert is a bad look even before you get to the regulatory angle.
Third, and less obviously, many firms have client portals or automated intake systems that route enquiries through AI triage before a human ever sees them — sorting by practice area, flagging urgency, drafting acknowledgment emails. These systems typically sit behind the public-facing chatbot most firms think to check, which is exactly why they get missed in a first-pass review. A firm that audits only its visible chatbot and misses its backend intake automation has done half the job.
Fourth, firms with referral relationships or co-counsel arrangements involving EU-based practices have another layer to consider. If a UK firm's website or client communications feed enquiries into a shared intake system with an EU partner firm, or if joint client alerts go out under both firms' names, the disclosure question doesn't disappear just because one side of the relationship is UK-based. It's worth a direct conversation with any EU co-counsel about how each side is handling AI disclosure, rather than assuming the other firm has it covered.
What Changes in Practice on Your Website, Chatbot, and Client Systems
Translating "transparency obligations" into an actual website change list is where most of the ambiguity disappears. The practical work breaks into three categories.
The first is disclosure at the point of interaction. Any chatbot, virtual assistant, or automated intake flow that an EU-based visitor might use needs a clear, upfront statement that they're interacting with an AI system, not a person — not buried in a terms-of-service page three clicks away, but visible at or near the point of first interaction. This is a genuinely small front-end change in most modern web stacks: a labelled chat header, an opening message, a persistent badge. It is a much larger change in a stack built on an old embedded third-party widget with no easy way to customize its copy or behavior, which is one of the quieter reasons firms end up needing a broader front-end refresh rather than a patch.
The second is labelling AI-influenced content. Client alerts, blog posts, sector updates, and marketing copy that are AI-drafted or AI-substantially-edited need some form of identification if they're likely to reach EU readers and could reasonably be mistaken for unaided human authorship. This is more of an editorial and content-management workflow question than a pure engineering one, but it usually surfaces a technical gap too: most firm content management systems have no field for "this was AI-assisted," which means the fix has to happen at both the workflow level and the site's data model.
The third, and the one firms most often skip, is auditing what's actually running on the site. A meaningful share of the AI touchpoints on a typical firm website weren't built in-house — they arrived as a third-party chat plugin, a marketing automation tool with generative features quietly switched on in an update, or an analytics vendor's "AI insights" add-on that also happens to generate visitor-facing text. None of those show up in a mental review of "the AI things we built." They show up in a proper technical audit of every script and integration actually running against the live site, which is the kind of work that sits squarely inside solid Web Development practice rather than a one-off compliance checkbox exercise. The same audit discipline that catches an undisclosed AI widget tends to catch other quietly-added integrations worth reviewing on security grounds too — the kind of exposure covered in more depth in Rate Limiting and API Security: Protecting Your Backend from Abuse, since client intake forms and portals are frequently the same endpoints handling sensitive matter details.
How to Tell If Your Firm Is Actually Affected
Before committing budget to a fix, it's worth running a short, honest self-audit rather than assuming either "we're fine" or "we need to rebuild everything."
Questions Worth Answering Directly
Does the firm have any clients, matters, or counterparties based in the EU, even occasionally? Does the public website use a chatbot, AI-powered search, or an automated intake form that an EU visitor could reach? Is any client-facing content — alerts, briefings, FAQ pages — drafted with meaningful AI assistance and published under the firm's name without disclosure? Does the firm use any third-party tool (chat, CRM, marketing platform) with AI features turned on by default that the firm didn't explicitly configure or review?
A firm that answers "no" honestly to all four has a genuinely short list of things to verify and can likely close this out with a documentation exercise. A firm that answers "yes" to even one, particularly the third-party tooling question, should treat this as a real project rather than a memo. The honest answer for most established firms with any international client base is somewhere in the middle — a few systems clearly in scope, a few unclear ones worth checking, and at least one third-party integration nobody has looked at closely since it was switched on.
It's also worth testing disclosure across every device and context a client might actually use, not just the desktop view a marketing team reviewed when the chatbot was first installed. A disclosure statement that renders clearly on desktop can easily get clipped, hidden behind a scroll, or dropped entirely on a mobile layout if it was never specifically checked there — and mobile is where a growing share of first client contact actually happens. The same goes for any embedded widget that loads asynchronously: if the disclosure text appears a second or two after the chat window itself opens, a visitor could plausibly start typing before it displays, which defeats the purpose of having it at all.
Building Compliance Into Your Web Development Roadmap
The instinct with any new regulatory obligation is to treat it as a standalone compliance project, bolted onto the existing website with the least possible disruption. That instinct is understandable but usually produces the worst outcome for firms whose sites are already carrying years of incremental additions: another disclosure banner stacked on top of an already-cluttered interface, a hastily added label that doesn't match the site's design system, a fix that technically satisfies the letter of the rule while making the client experience slightly worse.
The better approach treats this as a prompt to do a proper technical review of the site's AI-facing surface area — chatbot, intake forms, content workflow, third-party scripts — and to fix disclosure as part of that review rather than as an emergency patch. That's a genuine web development exercise: auditing what's actually deployed, deciding what needs to change at the component level versus the content level, and shipping it in a way that's consistent with the rest of the site rather than visibly bolted on. It's also worth thinking about this alongside the broader question of whether the AI tools the firm has deployed are actually earning their keep, which is a separate but related exercise covered in AI Automation ROI: How to Measure Whether It's Actually Working — a compliance review is a natural moment to also ask whether the chatbot you're now disclosing is worth having at all.
It's also worth situating this inside the wider pattern of AI regulation moving faster than most businesses' internal processes, which isn't unique to the EU AI Act. Courts and regulators across multiple jurisdictions have spent 2026 actively defining how AI intersects with existing law in real time rather than waiting for settled consensus, a dynamic covered from a different angle in AI Copyright Litigation in 2026: Inside the Global Lawsuits Reshaping AI Training Data. The throughline for any firm operating internationally is the same: assume the regulatory ground under AI-facing systems will keep shifting, and build web infrastructure that can absorb a disclosure change or a workflow adjustment without a full rebuild each time.
What This Kind of Work Typically Costs
The scope of work here varies a lot by how much of the firm's AI-facing surface area is custom-built versus third-party, and how outdated the underlying site is. As a general guide to where this kind of engagement typically falls:
| Tier | Typical scope | Fits firms that need |
|---|---|---|
| Essential — $1,000 | Audit of existing chatbot, forms, and third-party scripts; disclosure copy and placement fixes on components already in place | A modern site with one or two AI touchpoints needing disclosure added or clarified |
| Growth — $2,000 | Full site AI-surface audit, chatbot and intake redesign for clear disclosure, content workflow updates for AI-assisted publishing | A firm with several client-facing AI tools, a content team publishing regularly, and some third-party integrations to untangle |
| Enterprise — $4,000+ | End-to-end rebuild of client-facing AI touchpoints, custom chatbot and portal work, ongoing monitoring for new AI features added by vendors | A larger firm with a client portal, multiple offices, and an older site architecture that needs deeper structural work alongside compliance |
These figures describe the shape of the work, not a quote for any specific firm's site — the right starting point is an honest look at what's actually live on your domain before committing to a tier.
Key Takeaways
- The EU AI Act's transparency rules follow the AI system's effect on EU-based users, not your firm's registered address — a UK-only office doesn't put you out of scope if your clients or visitors are in the EU.
- Audit every AI-facing touchpoint separately: the visible chatbot, backend intake automation, AI-assisted content workflows, and any third-party tool with AI features switched on by default.
- Disclosure needs to sit at the point of interaction, not buried in a terms page — a labelled chat header or an opening statement is usually enough for a chatbot.
- AI-assisted client alerts and marketing content need some form of identification if EU readers could mistake them for unaided human authorship.
- Treat this as a proper web development review rather than a bolt-on patch, since a rushed fix on a cluttered site usually makes both compliance and client experience worse.
- Third-party integrations are the most commonly missed source of undisclosed AI behavior — review vendor tools with the same scrutiny as anything built in-house.
Working out exactly which of your firm's systems are in scope, and what a clean fix actually looks like on your specific site, is easier with someone who can look at what's actually deployed rather than guess from a checklist. If you want help figuring out where your firm stands and what to prioritize first, book a meeting with our team.
Frequently Asked Questions
What is the EU AI Act's transparency chapter, in plain terms?
It's the part of the EU AI Act that requires people to be told when they're interacting with an AI system rather than a human, and requires AI-generated or AI-substantially-altered content to be identifiable as such. It doesn't ban the use of AI — it requires disclosure so people aren't misled about what they're dealing with.
Why would a UK law firm be covered by an EU law at all?
Because the Act's scope follows where an AI system's output is used or who it affects, not where the company deploying it is headquartered. A UK firm with EU-based clients, contacts, or website visitors can fall within scope the same way GDPR applied to UK firms with EU data subjects after Brexit.
Does Brexit exempt UK law firms from this?
No. Brexit changed the UK's own regulatory framework, but it doesn't stop EU law from applying to non-EU companies whose products or services reach EU-based individuals. The relevant test is whether your AI systems affect people in the EU, not whether your firm is legally based there.
What counts as "serving EU customers" for a law firm?
It can include EU-incorporated clients, EU subsidiaries of UK group clients, cross-border matters involving EU counterparties, or simply website visitors and enquiry contacts based in the EU. None of these require the firm to have an EU office or EU-qualified staff.
Does this only apply to firms with an EU office?
No — that's the most common misunderstanding. A firm with zero physical presence in the EU can still be in scope if EU-based people interact with its AI-facing systems, such as a website chatbot or an automated intake form.
What specific AI systems on a law firm's site are most likely to be affected?
Client-facing chatbots and virtual assistants, automated intake or triage tools, AI-assisted content on client alerts or blog pages, and any third-party marketing or CRM tool with generative AI features enabled are the most common candidates.
Do AI-drafted client alerts and briefings need a disclosure too?
If the content is AI-drafted or substantially AI-edited and could reasonably be mistaken for unaided human authorship by an EU reader, it falls into the same transparency logic as a chatbot — some form of identification is the safer approach.
What does a compliant chatbot disclosure actually look like?
Typically a visible statement at or near the start of the interaction — a labelled chat header, an opening message identifying it as an AI assistant, or a persistent badge — rather than a disclosure buried in a terms-of-service page the visitor is unlikely to read.
Is a small disclaimer in the site footer enough?
Generally not, because the intent of the rule is that the disclosure reaches the person at the point they're actually interacting with the system, not somewhere they'd have to go looking for it separately.
What if our chatbot is a third-party plugin we didn't build ourselves?
You're still responsible for what it does on your site and to your visitors. The fix might mean configuring the vendor's disclosure settings, requesting a change from the vendor, or replacing the tool if it can't be made compliant on your site.
How do we even find out what AI tools are running on our site?
A proper technical audit of every script, plugin, and third-party integration actually live on the site is the only reliable way — mental recall of "what we set up" reliably misses vendor tools that shipped with AI features turned on by default in an update.
Our marketing platform added generative AI features in an update we didn't request. Are we responsible?
Yes, in practical terms — the rule is concerned with the effect on the person interacting with your systems, not with whether your firm actively chose to enable the feature. Reviewing vendor tools for unannounced feature changes needs to become a recurring check, not a one-time task.
How long does a compliance audit like this typically take?
For a firm with a handful of AI touchpoints on a reasonably modern site, an audit and fix can often be scoped and completed within a few weeks. A firm with an older site, a client portal, and several third-party integrations to untangle should expect a longer, more structured project.
What does an engagement like this typically cost?
It depends on scope. Straightforward disclosure fixes on an already-modern site tend to fall around the Essential tier ($1,000), a fuller audit with chatbot and content workflow changes tends to land in the Growth tier ($2,000), and a larger firm needing structural portal or site work tends to sit in Enterprise ($4,000+).
Can this be handled internally by our IT team instead of an external partner?
If your IT team has the capacity to audit every script and third-party tool on the site, update chatbot configurations, and revise content workflows, yes. Many firms find the audit step alone — knowing exactly what's running and where — is where outside expertise saves the most time.
What happens if our firm simply does nothing?
The immediate risk is regulatory exposure tied to the EU AI Act's enforcement framework, but the more likely near-term risk for a law firm is reputational: an EU client discovering, after the fact, that an undisclosed AI system handled part of their initial interaction with the firm.
Is this connected to GDPR in any way?
They're separate pieces of legislation with separate obligations, but they share the same extraterritorial logic — both apply based on the effect on EU-based individuals rather than the company's location — and firms already familiar with GDPR scoping will recognize the pattern here.
Does the Solicitors Regulation Authority have its own separate AI transparency requirements?
The SRA's professional conduct rules and the EU AI Act's transparency obligations are distinct frameworks with different origins and different enforcement bodies. Firms should treat compliance with one as separate from, not a substitute for, compliance with the other.
Are in-house AI tools used only by lawyers (not clients) affected?
The transparency rules are primarily concerned with systems that interact with or produce content for people, particularly where someone could be misled about whether they're dealing with AI or a human. Purely internal tools used by trained staff who know they're using AI carry a different risk profile than client-facing systems.
Does document review or contract analysis software fall under these transparency rules?
That depends on whether the tool's output reaches a client or third party in a way that could be mistaken for unaided human work product, versus being used purely as an internal research aid before a lawyer's own review and sign-off. The safer assumption for client-facing deliverables is to disclose meaningful AI involvement.
Do sole practitioners and small firms need to worry about this too?
Scope depends on whether the firm has EU-based clients or website visitors interacting with AI systems, not on firm size. A small firm with a chatbot and even one or two EU-connected clients faces the same basic questions as a larger firm, just with a shorter list of systems to check.
How do larger firms with multiple offices approach this differently?
Larger firms typically have more AI touchpoints to inventory — separate office websites, multiple client portals, several marketing tools — and benefit from a centralized audit rather than each office handling it independently, since inconsistent disclosure across offices creates its own confusion.
What's the first practical step a firm should take this week?
List every AI-facing tool actually live on the website and client systems — chatbot, intake forms, marketing platform AI features, content tools — before deciding what needs to change. You can't fix disclosure gaps in systems you haven't identified yet.
Should we just remove our chatbot to avoid the issue entirely?
That avoids the disclosure question but usually isn't the better business decision if the chatbot is actually useful for client intake. Adding clear disclosure is typically simpler than removing a tool that's doing real work for the firm.
Does labelling AI content hurt how professional our marketing looks?
Not if it's designed properly. A brief, well-placed disclosure integrated into the site's existing design language reads as transparent and confident, not as a disclaimer bolted on as an afterthought — the difference comes down to how it's implemented, not whether it's required.
Will this affect our website's SEO or search rankings?
Adding clear, well-designed disclosure shouldn't hurt search performance, and in some cases clearer labelling of AI-assisted content can support trust signals that search engines and readers both respond to. The risk to rankings comes more from a rushed, cluttered implementation than from disclosure itself.
How do we handle AI-assisted content that was published before August 2026?
A pragmatic approach is to prioritize a review of content most likely to still be actively read or linked to by EU-based visitors — recent client alerts, evergreen guidance pages — rather than attempting to retroactively audit years of archived content at once.
Does this apply to social media posts and LinkedIn content too, or just the website?
The Act's transparency logic is about the interaction and content reaching a person, not the specific platform, so the same disclosure principle reasonably extends to any AI-assisted content a firm publishes and EU-based contacts might see, including on social platforms.
What if we're not sure whether a specific client counts as "EU-based"?
Where there's genuine ambiguity — a client with operations in multiple countries, for instance — the more conservative and lower-risk approach is to apply clear AI disclosure practices consistently across all client-facing systems rather than trying to segment disclosure by client location.
Are there specific penalties named for non-compliance that we should budget for?
A precise, verified figure specific to this transparency obligation and this audience isn't something we're able to state with confidence here, and inventing one would be worse than not answering. The safer planning assumption is that enforcement of AI transparency rules is an active, developing area, and the practical priority is closing genuine disclosure gaps rather than estimating a specific financial exposure number.
Who actually enforces these rules against a UK firm?
Enforcement mechanisms for extraterritorial AI regulation are still maturing, and the practical exposure for most firms is less about a specific enforcement action and more about client trust, professional reputation, and the general direction regulators in multiple jurisdictions are moving. Firms are better served preparing for the trend than trying to predict a single enforcement pathway.
Should our professional indemnity insurer know about this?
It's reasonable to mention AI transparency compliance work to your insurer as part of general risk management conversations, particularly if the firm uses AI in ways that touch client-facing work, though the specifics of any policy implications are a conversation for your insurance adviser rather than a web development one.
Is this a one-time fix or an ongoing obligation?
Ongoing. New AI features get added to third-party tools regularly, content workflows change, and client bases shift over time, so this needs to become a recurring review rather than a single project marked complete.
How often should we re-check our AI-facing systems after the initial fix?
A reasonable cadence is to review AI-facing systems and third-party tool settings at least twice a year, or whenever a significant vendor tool is updated or a new client-facing feature is added to the site.
Does this affect how we should evaluate new legal tech vendors going forward?
Yes — it's worth adding AI transparency and disclosure configurability to the evaluation criteria for any new client-facing tool, alongside the usual security and functionality questions, so it doesn't become an afterthought discovered after the tool is already live.
What's the relationship between this and the firm's overall AI governance policy?
AI transparency compliance is one piece of a broader AI governance approach that should also cover data handling, confidentiality, and appropriate use of AI in legal work. Treating the website disclosure piece in isolation misses the chance to build one coherent policy.
Can our existing content management system handle AI-content labelling, or do we need a new one?
Many modern content management systems can support a simple "AI-assisted" flag or label with configuration rather than a full replacement, but older or heavily customized systems may need development work to add that capability cleanly.
What's involved in auditing a client portal specifically?
A portal audit looks at every point where the system generates text, flags, or responses that a client sees — automated status updates, AI-suggested next steps, chat features — and checks whether any of that could read as unaided human communication without being disclosed as AI-assisted.
Is there a difference between "AI-generated" and "AI-assisted" content for disclosure purposes?
The practical distinction that matters is whether AI played a meaningful role in producing content that a client or website visitor consumes as if it reflects unaided human judgment — a lawyer using AI as a drafting aid before fully reviewing and revising the output is a different scenario from publishing largely unedited AI output.
Will UK law itself introduce similar transparency rules independent of the EU?
The UK's own AI regulatory approach has been evolving separately from the EU's, and firms should watch for UK-specific developments as a parallel track rather than assuming EU compliance automatically satisfies any future UK-specific requirement.
Should we expect these transparency rules to get stricter over time?
The general direction of AI regulation globally in 2026 has been toward more specificity and more active enforcement rather than less, so firms that build flexible, well-documented AI-facing systems now are better positioned for whatever comes next than firms doing the minimum to pass today's bar.
How does this connect to the EU AI Act's other phases, like the high-risk system rules?
The transparency obligations are a distinct, narrower chapter from the high-risk system requirements, which apply to a different category of AI use case and phase in on a separate timeline. Most law firm website AI touchpoints fall under transparency rather than the high-risk category, but firms using AI for things like automated decision-making on client matters should check both.
What if our firm plans to expand into the EU market more directly?
That's a strong reason to treat AI transparency compliance as foundational rather than reactive, since a firm actively building an EU client base will only see more AI-facing touchpoints in scope over time, not fewer.
Does this affect how we should build a new website if we're already planning a redesign?
Yes — if a redesign is already planned, this is the right moment to build AI disclosure, content labelling, and vendor tool review directly into the new site's architecture rather than adding it as a retrofit later.
What's the risk of a rushed, minimal-effort fix versus doing this properly?
A rushed fix risks technically satisfying the letter of the rule while creating a confusing or unprofessional client experience, and often misses less obvious touchpoints like third-party tools, which means the firm ends up doing the work twice.
How do we measure whether our AI disclosure and audit work actually solved the problem?
Track it the same way you'd track any web development change: confirm every identified AI touchpoint has clear, tested disclosure, document the audit for internal record-keeping, and revisit the list on a set schedule rather than treating it as done indefinitely.
Is it worth also reassessing whether our AI tools are delivering value, not just whether they're compliant?
Yes — a compliance audit is a natural moment to also evaluate whether tools like your chatbot are actually improving client intake or engagement, since disclosure changes are often easiest to implement well when paired with a broader look at whether the tool is worth keeping in its current form.
Where should a firm start if it has never done any kind of AI or website audit before?
Start with a complete inventory of what's live — every script, plugin, chatbot, and content workflow touching the public site and client portal — before making any changes, since decisions made before that inventory exists tend to miss the systems that matter most.
How does Scult approach this kind of engagement for a law firm?
The starting point is always a technical audit of what's actually deployed on the firm's site and client systems, followed by a scoped plan that fixes disclosure and content workflow gaps as part of a broader, well-documented web development effort rather than a disconnected patch.
What should we ask a web development partner before hiring them for this work?
Ask how they audit third-party integrations, whether they document what's changed and why, and how they'd handle disclosure design so it fits the site's existing look rather than reading as a bolted-on warning label.



