Skip to main content
Legal Counsel Meets AI Act: One Advisor's Shift from Fintech to Cross-Domain ComplianceLaws and Regulations
5 min readFor Legal Counsel

Legal Counsel Meets AI Act: One Advisor's Shift from Fintech to Cross-Domain Compliance

The Challenge

A Berlin-based technology partner faced a major shift when the EU AI Act transitioned from draft to enforceable regulation. Carsten Kociok, a top-ranked Fintech legal advisor in Germany, had built his practice around financial services, payments law, and blockchain regulation. His clients sought guidance on licensing projects and audit proceedings with financial regulators.

With the arrival of AI regulation, a new framework cut across every sector he served: financial services, healthcare, telecoms, retail, real estate, ecommerce, and media. The challenge wasn't just learning a new regulation. It was integrating AI compliance into existing software systems while maintaining coherence with data privacy obligations that predated the AI Act.

The practical question: How do you advise a payments processor on AI Act compliance when their fraud-detection model also triggers GDPR Article 22 concerns about automated decision-making? Or guide a healthcare client through AI system classification while ensuring their data transfers under Chapter V remain defensible?

The Environment and Constraints

Three constraints shaped the advisory approach:

Regulatory Overlap Without Clear Hierarchy. The EU AI Act doesn't replace GDPR or sector-specific rules. A high-risk AI system in financial services must satisfy AI Act transparency requirements, GDPR's data protection by design principles, and whatever BaFin expects in audit proceedings. There's no single compliance checklist; you're synthesizing frameworks that weren't written to align.

Clients with Deployed Systems, Not Greenfield Projects. Most organizations seeking AI Act guidance already have AI technologies integrated into their operations. They're asking, "How do we document what we built three years ago in a way that satisfies a 2025 regulation?" Retrofitting compliance onto production systems means working within technical constraints you didn't choose.

Cross-Industry Practice Without Sector Silos. When advising clients across financial services, healthcare, and ecommerce, you can't develop deep vertical expertise in each regulator's interpretation of AI risk. You need a framework that travels: principles that work whether you're counseling an e-money provider or a telemedicine platform.

The Approach Taken

Kociok's practice evolution centered on treating AI compliance as an integration problem, not a standalone workstream. The method:

Map AI Act Obligations onto Existing Data Privacy Workflows. Instead of creating separate AI compliance projects, layer AI Act requirements into the data protection impact assessments clients were already conducting under GDPR Article 35. A high-risk AI system triggers both frameworks. Run one assessment that addresses both. Document purpose limitation (GDPR Article 5(1)(b)) and intended purpose (AI Act Article 13) in the same artifact.

Advise on International Data Transfers with AI Processing in Scope. When counseling clients on Chapter V compliance, include AI model training and inference in the transfer impact assessment. If your client's fraud-detection model processes EU user data on US infrastructure, the transfer risk analysis must account for both the training dataset and the real-time scoring. This isn't a separate AI Act workstream; it's an expanded view of what "processing" means in a transfer context.

Develop Sector-Agnostic Classification Frameworks. Rather than memorizing which AI systems count as high-risk in financial services versus healthcare, build a decision tree clients can apply themselves: Does the system fall under Annex III? Does it pose equivalent risk? What's the intended purpose? Train clients to classify their own systems using the regulation's structure, not your sector knowledge.

Integrate AI Compliance into Commercial Contract Review. When advising on licensing projects or vendor agreements, add AI Act diligence to the standard data processing agreement review. If your client is licensing software with embedded AI, the contract must specify who's responsible for conformity assessment, ongoing monitoring, and incident reporting under Articles 61 and 62. Don't treat this as "AI contracting"; treat it as modern technology contracting.

Results and Metrics

The practice shift produced measurable changes in client engagement patterns and advisory scope. Kociok now advises on compliance with the EU AI Act and the integration of AI technologies as a core service line, not an ad hoc request. Clients who initially engaged for payments law or financial services regulation now return for AI Act guidance across their product portfolio.

The cross-domain approach proved particularly effective in data-driven business models, where AI processing and personal data monetization intersect. Clients operating in multiple jurisdictions benefit from counsel that synthesizes AI regulation, data privacy compliance, and international data transfers in a single analysis rather than siloed opinions.

What They Would Do Differently

Three adjustments would have accelerated the transition:

Start the Integration Earlier. Waiting until the AI Act reached final text meant playing catch-up with clients who had already deployed AI systems. Beginning the framework integration when the regulation was still in draft would have given clients more lead time to document and adjust their systems.

Build Sector-Specific Exemplars Despite the Generalist Approach. While the sector-agnostic framework travels well, clients still benefit from seeing how it applies in their specific industry. Developing two or three detailed examples (a fintech fraud model, a healthcare diagnostic tool, a retail recommendation engine) would have made the abstract principles more immediately actionable.

Invest in Technical Training for the Legal Team. Understanding AI regulation requires understanding what AI systems actually do. More time spent with data scientists and ML engineers early in the practice shift would have improved the quality of advice on "integration of AI technologies into existing software systems."

Takeaways for Your Team

If your organization is navigating AI Act compliance while managing existing GDPR, sector-specific, and cross-border obligations:

Don't Create a Separate AI Compliance Program. Layer AI Act requirements into your current data protection governance. Your DPIA template should already address high-risk AI systems. Your vendor diligence checklist should already include AI Act conformity questions. Your data transfer impact assessments should already account for AI processing.

Treat International Data Transfers as an AI Compliance Issue. If you're transferring personal data for AI training or inference, your Chapter V analysis must address the AI processing, not just the data movement. The adequacy decision or standard contractual clauses don't exempt you from documenting how AI systems use transferred data.

Hire Advisors Who Synthesize Frameworks, Not Specialists Who Silo Them. The most valuable counsel right now comes from advisors who can tell you how GDPR Article 22, AI Act Article 13, and your sector regulator's guidance interact in a single system. If your lawyer says, "That's an AI question, not a privacy question," find a different lawyer.

Document Intended Purpose Before Regulators Ask. Whether you're facing a BaFin audit, a CNIL investigation, or an AI Act conformity assessment, the first question is always: What's this system supposed to do? If you can't produce a clear purpose specification that satisfies both GDPR and AI Act requirements, you're not ready for regulatory scrutiny.

The shift from sector-specific regulation to horizontal AI compliance isn't optional. It's the new baseline for technology practice.

You Might Also Like