reportAI GovernanceAI in CourtsEU AI Act
AI in legal practice: what 130 country records require at September 2026
A dataset-first report on AI rules for lawyers and courts across 130 records, with provisional countries separated from checked counts.
Edited and verified by Cognesio LLP
Researched with AI assistance · sources verified by Cognesio LLP · How this was made ↓
Global, as of 4 September 2026, SafeLegalAI’s regulatory map holds 130 country and entity records across 20 AI-in-legal-practice categories: 76 editor-reviewed records and 54 provisional records. The checked tier shows a rule set that is uneven by design. Horizontal AI statutes and data-protection positions are common; filing-disclosure rules, billing rules and arbitration rules remain rare.
Key findings, datestamped 2026-09-04
- As of 2026-09-04, the checked tier contains 76 country or entity records and 1,520 category cells; 172 cells are binding, 327 are official guidance, 49 are proposed, 57 are case law, 730 record that nothing was found and 185 remain unclear.
- The 54 provisional records are a separate research tier: across their 1,080 category cells, only 7 are binding, 20 are guidance and 17 are proposed; 1,036 cells say no rule was found, and none uses case law.
- The most adopted checked category is Horizontal AI statute: 56 of 76 checked records have a binding, guidance, proposed or case-law position, including 32 binding cells.
- The core court-control categories are much narrower: 13 of 76 checked records have any filing-disclosure position, 50 have a verification-duty position and 37 have a judicial-use position.
- Europe supplies 103 checked binding cells and 147 guidance cells, more than any other region in this dataset, but that count includes the EU AI Act footprint across the 27 member states.
- The instrument base is professional before it is statutory: country cells cite bar, law-society and legal-regulator guidance 352 times, statutes and regulations 183 times, and court rules, practice directions or standing orders 89 times.
- Case law is the substitute source for 34 records, all in the checked tier; the sanctions record category accounts for 32 of those country records.
- The EU AI Act creates a 27-state binding horizontal layer, but 21 of those member states also have at least one national regulation document in the tracker; six have only the EU footprint in this dataset.
Why this question
The practical question is not whether lawyers may use generative AI. In most jurisdictions in this dataset, no official source says lawyers are barred from using it. The question is which public body has put a legal or professional condition on that use: a court asking for a certificate, a bar telling lawyers to verify output, a judicial council limiting judges’ use, a data-protection authority constraining client data, or a legislature classifying justice AI as high-risk.
That difference matters because AI rules for legal practice arrive through different channels. A court practice direction binds the filing now. A bar guidance note changes the professional-risk record, but may not bind every practitioner in the same way. A horizontal AI statute may regulate providers and deployers without answering whether a pleading needs an AI declaration. A case can punish fabricated authority without creating a general disclosure rule.
This report maps those channels rather than replacing them with one global yes or no. It uses the regulatory map, the regulation document tracker, the incident tracker and the tools directory as evidence. It treats the 54 provisional records as provisional throughout. Those records are useful for seeing shape and gaps; they are not included in checked-tier claims unless the tier is named.
The result is a rule map with three speeds. A small group of common-law courts has moved to filing declarations or verification certification. A larger group of bars and law societies has issued guidance that says existing competence, confidentiality, supervision and candour duties apply to AI. The broadest group is horizontal: EU-style AI statutes, data-protection guidance, court-technology policies and national AI strategies that touch legal practice without being legal-profession rules.
Method and data
This report uses four SafeLegalAI datasets as of 4 September 2026. The country regulatory map is built from safelegalai-site/src/content/countries/*.yaml and is exported at /regulation/map.json. It contains 130 records, each scored against the 20 categories in src/lib/regmap.ts. The regulation document tracker is built from safelegalai-site/src/content/regulations/*.yaml and is exported at /regulation/documents.json. It contains 324 official documents, each with a current versions[0] entry and, where relevant, earlier versions. The incident tracker is exported at /tracker/incidents.json and contains 122 incident records. The tools directory is exported at /tools/tools.json and contains 129 tool records; it is used here only for context on procurement and vendor-due-diligence categories, not for vendor scoring.
The status taxonomy is the one used by the public tracker at /regulation#categories. A category cell is binding where a rule in force comes from a court, statute, regulator or equivalent public authority. It is guidance where an official non-binding position comes from a judiciary, regulator, bar or public body. It is proposed where a bill, draft rule or consultation is public but not in force. It is case-law where no rule was found, but the position has been set through decisions. It is none where the category was checked and no position was found. It is unclear where the research did not establish a reliable position.
The category names and questions in the tables come from safelegalai-site/src/lib/regmap.ts. The 20 questions are the public-facing questions behind the tracker, such as whether lawyers must disclose AI use in filings, whether lawyers must verify output, whether judges may use AI, whether client data can go into tools, whether AI is barred from deciding cases, and whether courts have sanctioned misuse. Missing category entries in a country record are counted as unclear, matching the helper function used by the map.
The first count in every findings paragraph is the editor-reviewed tier unless the text says provisional, all records or EU member state footprint. The provisional tier matters because 54 records were AI-researched and still await source-by-source editor review. They are marked on country pages and in this report. They are counted in a separate table and never blended into a headline claim without a label.
The analysis excludes three things. First, it does not score vendors or rank tools. The tools dataset is used only to show that procurement and vendor due diligence are part of the taxonomy. Second, it does not treat every national AI strategy as a legal-practice rule. Strategies matter only where a country record has placed a category cell against a source. Third, it does not infer rules from news coverage. Incidents supply context for case-law and sanctions categories, but the regulation map records the rule or absence of a rule.
The limits are visible in the data. English-language and common-law jurisdictions have deeper coverage because court rules and disciplinary decisions are easier to verify from official sites. Some civil-law countries have horizontal AI or data-protection positions but no legal-profession guidance. Some court PDFs and bar PDFs are bot-blocked or not text-readable through WebFetch; where that happened, this run used the YAML summary, keyProvisions and note fields rather than inventing quotations. Appendix B lists the official document URLs used for the documents leaned on in the report.
The checked tier has rules, guidance and large blank areas
The checked tier is not empty, but it is not close to full coverage. Across 76 editor-reviewed records and 20 categories, the map has 1,520 cells. Binding rules account for 172 cells. Official guidance accounts for 327. Proposed rules account for 49. Case law accounts for 57. The two absence states, none and unclear, account for 915 cells. That means the checked tier is best read as a matrix of specific rules, not as a global code.
| Tier | Records | Binding rule | Official guidance | Proposed / consultation | Set by case law | Nothing found | Not yet determined |
|---|---|---|---|---|---|---|---|
| Editor-reviewed tier | 76 | 172 | 327 | 49 | 57 | 730 | 185 |
| Provisional tier | 54 | 7 | 20 | 17 | 0 | 1,036 | 0 |
| All records, labelled mix | 130 | 179 | 347 | 66 | 57 | 1,766 | 185 |
The provisional tier pulls in the opposite direction. It has 54 records and 1,080 category cells, but only 44 active positions: 7 binding, 20 guidance and 17 proposed. The rest are recorded as no rule found. That does not prove legal silence in those countries; it means the provisional research did not locate official AI-in-legal-practice material for most categories. The reporting value is the label. If the provisional tier were blended into the checked tier, it would make global adoption look lower while hiding the fact that the underlying verification standard is different.
A reader should therefore treat any all-record number as a labelled mix. It is helpful for export completeness and map rendering. It is not the primary measure for this report. The working comparison is 76 checked records first, 54 provisional records second.
The shape of the checked tier also explains why one country can look strict in one category and silent in another. The United Kingdom has guidance on judicial use, verification, client data and professional supervision, but no binding filing-disclosure rule in force in England and Wales. Ireland has a binding practice direction on court documents. The United States has federal ethics guidance and judge-level standing orders, but no single nationwide court rule. These are different regulatory methods, not inconsistent data.
Adoption is highest where horizontal law or existing professional duties can be reused
The category ranking shows which questions have reached official sources most often. The leading checked category is horizontal AI statute, with 56 active positions among 76 checked records. That category counts EU AI Act member-state coverage, national AI statutes, AI bills and official horizontal frameworks that classify legal or justice uses. It is broad by design, so it leads.
The second group is closer to daily legal practice. Duty to verify AI output has 50 active checked positions; data protection and legal AI has 43; client data in AI tools has 42; vendor due diligence has 41; and courts’ own AI deployment also has 41. Those categories can be attached to existing legal duties. A bar can say competence now includes checking AI output. A data-protection body can apply existing personal-data rules. A court can write an internal AI policy.
The lowest categories are narrower. Arbitration and ADR has six active checked positions. Consumer AI legal services has eight. AI-generated evidence and billing for AI work have nine each. Filing disclosure and self-represented litigant guidance sit at 13 each. These categories need procedural or professional choices that many authorities have not made.
| Rank | Category | Editor-reviewed active | Editor-reviewed binding/guidance | Provisional active | Provisional binding/guidance |
|---|---|---|---|---|---|
| 1 | Horizontal AI statute | 56/76 (74%) | 36/76 (47%) | 32/54 (59%) | 20/54 (37%) |
| 2 | Duty to verify AI output | 50/76 (66%) | 38/76 (50%) | 0/54 (0%) | 0/54 (0%) |
| 3 | Data protection and legal AI | 43/76 (57%) | 42/76 (55%) | 6/54 (11%) | 3/54 (6%) |
| 4 | Client data in AI tools | 42/76 (55%) | 40/76 (53%) | 0/54 (0%) | 0/54 (0%) |
| 5 | Vendor due diligence | 41/76 (54%) | 40/76 (53%) | 0/54 (0%) | 0/54 (0%) |
| 6 | Courts’ own AI deployment | 41/76 (54%) | 35/76 (46%) | 0/54 (0%) | 0/54 (0%) |
| 7 | Technological competence | 40/76 (53%) | 39/76 (51%) | 1/54 (2%) | 1/54 (2%) |
| 8 | Bar guidance on generative AI | 38/76 (50%) | 36/76 (47%) | 1/54 (2%) | 0/54 (0%) |
| 9 | Judges’ use of AI | 37/76 (49%) | 31/76 (41%) | 2/54 (4%) | 1/54 (2%) |
| 10 | Sanctions for AI misuse | 34/76 (45%) | 2/76 (3%) | 0/54 (0%) | 0/54 (0%) |
| 11 | Supervision of AI work | 32/76 (42%) | 29/76 (38%) | 0/54 (0%) | 0/54 (0%) |
| 12 | AI barred from deciding cases | 32/76 (42%) | 28/76 (37%) | 0/54 (0%) | 0/54 (0%) |
| 13 | Mandatory AI training | 31/76 (41%) | 30/76 (39%) | 1/54 (2%) | 1/54 (2%) |
| 14 | Client consent and transparency | 30/76 (39%) | 30/76 (39%) | 1/54 (2%) | 1/54 (2%) |
| 15 | Disclosure of AI use in filings | 13/76 (17%) | 9/76 (12%) | 0/54 (0%) | 0/54 (0%) |
| 16 | Self-represented litigants | 13/76 (17%) | 8/76 (11%) | 0/54 (0%) | 0/54 (0%) |
| 17 | Billing for AI work | 9/76 (12%) | 8/76 (11%) | 0/54 (0%) | 0/54 (0%) |
| 18 | AI-generated evidence | 9/76 (12%) | 5/76 (7%) | 0/54 (0%) | 0/54 (0%) |
| 19 | Consumer AI legal services | 8/76 (11%) | 7/76 (9%) | 0/54 (0%) | 0/54 (0%) |
| 20 | Arbitration and ADR | 6/76 (8%) | 6/76 (8%) | 0/54 (0%) | 0/54 (0%) |
The ranking also warns against treating disclosure as the whole topic. Filing-disclosure rules are visible because they change litigation documents. They are not the main regulatory channel. Verification duties, client-data rules and competence duties appear more often, and they apply before a document reaches court.
Disclosure, verification and judicial-use rules answer different questions
The three categories most likely to be conflated are filing disclosure, verification duty and judicial use. They should stay separate. A filing-disclosure rule asks whether the court must be told that AI was used. A verification duty asks whether a lawyer, party or judge must check AI output before relying on it. Judicial-use guidance asks whether judges and court staff may use AI in their own work, and on what terms.
| Question | Category | Editor-reviewed binding | Editor-reviewed guidance | Editor-reviewed proposed | Editor-reviewed case-law | Editor-reviewed active | Provisional active |
|---|---|---|---|---|---|---|---|
| Must lawyers disclose AI use in court filings? | Disclosure of AI use in filings | 6 | 3 | 4 | 0 | 13 | 0 |
| Must lawyers verify AI output before relying on it? | Duty to verify AI output | 10 | 28 | 1 | 11 | 50 | 0 |
| May judges and court staff use AI in their own work? | Judges’ use of AI | 10 | 21 | 5 | 1 | 37 | 2 |
The verified-data finding is clear: verification is far more common than filing disclosure. In the checked tier, 50 records have a verification-duty position, compared with 13 for filing disclosure. That is because verification can be derived from existing duties of candour, competence, supervision and accuracy. Disclosure requires a procedural choice about when AI use becomes relevant to the court or the opposing party.
Practice Direction HC 142 in Ireland shows the strict end of the filing-disclosure spectrum. It requires human verification of AI-assisted citations and declarations in affidavits and witness statements. New South Wales Practice Note SC Gen 23 also uses court-document declarations and limits use in affidavits, witness statements and expert reports. The Federal Court of Canada’s AI notice requires a declaration in documents that contain AI-generated content. These are binding court-document controls.
Other jurisdictions reject a general court-filing declaration, at least for now. The Civil Justice Council interim findings record that England and Wales had no AI-specific formal requirement for professional drafting as of the report date, while leaving open questions around witness statements, expert evidence and litigants in person. New Zealand’s court guidelines require checking and confidentiality but say AI use need not be disclosed in court documents. Singapore’s Registrar’s Circular No. 1 of 2024 similarly records no pre-emptive declaration unless the court asks.
Judicial-use guidance cuts across both. The UK judicial guidance, CEPEJ guidelines, CJEU AI material and US federal judiciary interim guidance all address judicial users. The common pattern is permission for limited administrative or support use, human responsibility for the result, verification of output and caution against delegating decision-making.
Region explains much of the binding-versus-guidance split
The regional table counts category cells, not documents. Europe leads in both binding and guidance cells among editor-reviewed records: 103 binding and 147 guidance. That is partly a consequence of the EU AI Act and national data-protection regimes. It is also because many European bars, judiciaries and ministries have issued AI material for courts or lawyers.
| Region | Editor-reviewed records | Binding cells | Guidance cells | Proposed cells | Case-law cells | None/unclear cells | Provisional records | Provisional active cells |
|---|---|---|---|---|---|---|---|---|
| Africa | 6 | 2 | 10 | 17 | 5 | 86 | 15 | 19 |
| Americas | 13 | 19 | 38 | 12 | 13 | 178 | 11 | 0 |
| Asia-Pacific | 18 | 39 | 86 | 9 | 13 | 213 | 11 | 4 |
| Europe | 31 | 103 | 147 | 7 | 22 | 341 | 12 | 16 |
| International bodies | 1 | 0 | 16 | 1 | 0 | 3 | 0 | 0 |
| Middle East | 7 | 9 | 30 | 3 | 4 | 94 | 5 | 5 |
The Americas look different. The dataset has 13 checked records in the region, with 19 binding cells and 38 guidance cells. In the United States, many national-level answers are guidance or local court orders rather than a federal statute. State bars and courts supply much of the operational material. In Canada, court practice directions and law-society guidance are more prominent than general AI legislation for legal practice.
Asia-Pacific has 18 checked records and a large guidance count: 86 cells. That reflects court and ministry guidance in Singapore, court guidelines and legal-profession guidance in New Zealand, judicial and court controls in Australia, and draft or adopted national AI frameworks in countries such as India, South Korea, Japan, Malaysia, Taiwan and Vietnam.
Africa’s checked tier is smaller, with six editor-reviewed records, 2 binding cells, 10 guidance cells and 17 proposed cells. That number is shaped by draft or policy-stage instruments. The provisional African tier has 15 records and 19 active cells, mostly horizontal AI strategy or data-protection material rather than legal-profession rules.
The Middle East has seven checked records, with 9 binding cells and 30 guidance cells. That includes court or arbitration guidance in Gulf records, government AI guidance and data-protection controls. The five provisional Middle East records add 5 active cells and many no-rule cells.
The source base is professional guidance before it is court filing law
The country cells link to regulation documents where the rule or guidance source is held in the document tracker. Counting those links shows which instruments support the map most often. Bar, law-society and legal-regulator guidance is the largest source group, with 352 country-category citations across 50 unique documents. Statutes and regulations come next, with 183 citations across 34 documents. Court rules, practice directions and standing orders account for 89 citations across 31 documents.
| Instrument group | Country-category citations | Unique documents |
|---|---|---|
| Bar, law-society and legal-regulator guidance | 352 | 50 |
| Statutes and regulations | 183 | 34 |
| Other official guidance | 121 | 37 |
| Court or public-body AI policies | 98 | 29 |
| Court rules, practice directions and standing orders | 89 | 31 |
| Judicial and court guidance | 73 | 18 |
| Judgment guidance and case-derived records | 46 | 19 |
| Bar and professional ethics opinions | 35 | 6 |
| Reports and policy papers | 21 | 8 |
| Consultations and proposed rules | 9 | 7 |
| Document type | Country-category citations |
|---|---|
| Guidance | 546 |
| Statute | 124 |
| Policy | 98 |
| Regulation | 59 |
| Practice direction / note | 52 |
| Judgment guidance | 46 |
| Ethics opinion | 35 |
| Court rule | 30 |
| Report | 21 |
| Consultation | 9 |
| Standing order | 7 |
This is the report’s central method point. The AI rule for legal practice is often not an AI Act. It is a bar opinion saying lawyers must understand the tools they use, a court notice requiring a declaration, a judicial policy on internal AI, or a data-protection position on client information. A statutory category can dominate adoption rankings while the rule that changes daily filing practice sits in a court PDF.
The ABA Formal Opinion 512, California guidance, SRA warning notice, Bar Standards Board guidance, CCBE guide, Singapore Ministry of Law guide and New Zealand law and court guidance are all examples of this professional channel. They do not all bind in the same way, but they answer the questions a risk officer asks first: verification, confidentiality, competence, supervision, client notice and fees.
Court rules are fewer, but sharper. Ireland HC 142, NSW SC Gen 23, Connecticut Practice Book Section 4-9, the Federal Court of Australia GPN-AI, Canada’s Federal Court notice, Ontario Superior Court practice directions and Singapore Registrar’s Circular affect filings, evidence, declarations, verification and sanctions more directly.
The EU AI Act footprint is broad, but national instruments still matter
The EU AI Act creates the largest single horizontal footprint in the map. The 27 member states all carry a binding horizontal AI statute cell because Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744, applies across the Union. That does not mean every member state has a national legal-profession AI rule.
| Measure | Count |
|---|---|
| EU member state records | 27 |
| Editor-reviewed EU member records | 26 |
| Provisional EU member records | 1 |
| Members with binding AI Act / horizontal category | 27 |
| Members with at least one national regulation document | 21 |
| Members with national documents linked to active country cells | 21 |
| Members with EU footprint but no national regulation document in this dataset | 6 |
The EU-level layer reaches justice and legal services through risk classification, AI literacy, transparency and general-purpose AI rules. Annex III point 8(a), recorded in the AI Act document page, captures AI systems intended to assist judicial authorities in researching and interpreting facts and law or applying law. The Digital Omnibus amendment defers Annex III high-risk obligations to 2 December 2027 and Annex I product-embedded obligations to 2 August 2028. Article 50 transparency duties applied from 2 August 2026.
National instruments answer the questions the EU Act does not answer. Does a lawyer need to disclose AI use in a pleading? Does a bar require verification? May a judge use a public chatbot? Does a court have a local AI policy? In this dataset, 21 of 27 EU member states have at least one national regulation document, and 21 have national documents linked to active country cells. Six have the EU footprint but no national regulation document in the tracker.
| Member state | Tier | AI Act status | Active categories | National regulation documents | National active categories |
|---|---|---|---|---|---|
| Austria | Editor-reviewed | Binding rule | 10 | 1 | 8 |
| Belgium | Editor-reviewed | Binding rule | 10 | 1 | 7 |
| Bulgaria | Provisional | Binding rule | 3 | 0 | 0 |
| Croatia | Editor-reviewed | Binding rule | 7 | 1 | 2 |
| Cyprus | Editor-reviewed | Binding rule | 1 | 0 | 0 |
| Czechia | Editor-reviewed | Binding rule | 9 | 2 | 6 |
| Denmark | Editor-reviewed | Binding rule | 12 | 2 | 6 |
| Estonia | Editor-reviewed | Binding rule | 9 | 2 | 9 |
| Finland | Editor-reviewed | Binding rule | 9 | 2 | 8 |
| France | Editor-reviewed | Binding rule | 18 | 4 | 13 |
| Germany | Editor-reviewed | Binding rule | 13 | 2 | 11 |
| Greece | Editor-reviewed | Binding rule | 2 | 1 | 1 |
| Hungary | Editor-reviewed | Binding rule | 4 | 0 | 0 |
| Ireland | Editor-reviewed | Binding rule | 15 | 3 | 14 |
| Italy | Editor-reviewed | Binding rule | 13 | 4 | 13 |
| Latvia | Editor-reviewed | Binding rule | 3 | 0 | 0 |
| Lithuania | Editor-reviewed | Binding rule | 3 | 1 | 1 |
| Luxembourg | Editor-reviewed | Binding rule | 7 | 0 | 0 |
| Malta | Editor-reviewed | Binding rule | 1 | 1 | 1 |
| Netherlands | Editor-reviewed | Binding rule | 14 | 1 | 8 |
| Poland | Editor-reviewed | Binding rule | 14 | 2 | 9 |
| Portugal | Editor-reviewed | Binding rule | 8 | 2 | 8 |
| Romania | Editor-reviewed | Binding rule | 3 | 0 | 0 |
| Slovakia | Editor-reviewed | Binding rule | 11 | 1 | 9 |
| Slovenia | Editor-reviewed | Binding rule | 2 | 1 | 1 |
| Spain | Editor-reviewed | Binding rule | 15 | 8 | 14 |
| Sweden | Editor-reviewed | Binding rule | 14 | 1 | 8 |
This is why EU member-state counts need a footnote. Counting the AI Act as binding for all 27 states is correct for the horizontal category. Counting it as a court-filing rule would be wrong. The country pages keep those questions separate.
Case law substitutes for rules, mainly in sanctions and verification
Case law is the safety valve in the map. Where no AI-specific rule exists, courts still sanction fabricated citations, reject filings, refer lawyers to regulators, or set expectations in reasons. The dataset has 34 records with at least one case-law cell. All 34 are editor-reviewed records. None of the 54 provisional records uses case law as a status.
The sanctions pattern is broad because incidents have reached many courts before regulators wrote rules. The incident tracker records the underlying decisions. The country map then records the regulatory effect only where a decision supplies a rule-like position for the category. That is why the sanctions record has 32 case-law countries, while filing disclosure has none. Courts are more often punishing fabricated AI output after the fact than requiring a universal disclosure statement before filing.
Verification is the second case-law category because courts can impose it through existing procedural duties. Even where no AI-specific rule exists, a lawyer who files a false citation may breach duties that predate AI. Case law does not always become prospective guidance, but it changes the risk record and may supply the only official source for a country cell.
The provisional tier mostly records absence, with one broad exception
The provisional tier contains 54 records and 1,080 cells. It is regionally broad and substantively thin. Africa accounts for 15 provisional records, Europe for 12, the Americas for 11, Asia-Pacific for 11 and the Middle East for 5. Across all provisional cells, 1,036 record no rule found. The largest exception is horizontal AI statute, where 32 provisional records have an active position.
| Region | Provisional records | Binding | Guidance | Proposed | Case-law | None | Unclear | Active cells per record |
|---|---|---|---|---|---|---|---|---|
| Africa | 15 | 0 | 12 | 7 | 0 | 281 | 0 | 1.3 |
| Americas | 11 | 0 | 0 | 0 | 0 | 220 | 0 | 0.0 |
| Asia-Pacific | 11 | 3 | 1 | 0 | 0 | 216 | 0 | 0.4 |
| Europe | 12 | 4 | 3 | 9 | 0 | 224 | 0 | 1.3 |
| International bodies | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0.0 |
| Middle East | 5 | 0 | 4 | 1 | 0 | 95 | 0 | 1.0 |
| Rank | Category | Provisional active | Binding | Guidance | Proposed | Case-law |
|---|---|---|---|---|---|---|
| 1 | Horizontal AI statute | 32 | 3 | 17 | 12 | 0 |
| 2 | Duty to verify AI output | 0 | 0 | 0 | 0 | 0 |
| 3 | Data protection and legal AI | 6 | 1 | 2 | 3 | 0 |
| 4 | Client data in AI tools | 0 | 0 | 0 | 0 | 0 |
| 5 | Vendor due diligence | 0 | 0 | 0 | 0 | 0 |
| 6 | Courts’ own AI deployment | 0 | 0 | 0 | 0 | 0 |
| 7 | Technological competence | 1 | 1 | 0 | 0 | 0 |
| 8 | Bar guidance on generative AI | 1 | 0 | 0 | 1 | 0 |
| 9 | Judges’ use of AI | 2 | 0 | 1 | 1 | 0 |
| 10 | Sanctions for AI misuse | 0 | 0 | 0 | 0 | 0 |
| 11 | Supervision of AI work | 0 | 0 | 0 | 0 | 0 |
| 12 | AI barred from deciding cases | 0 | 0 | 0 | 0 | 0 |
| 13 | Mandatory AI training | 1 | 1 | 0 | 0 | 0 |
| 14 | Client consent and transparency | 1 | 1 | 0 | 0 | 0 |
| 15 | Disclosure of AI use in filings | 0 | 0 | 0 | 0 | 0 |
| 16 | Self-represented litigants | 0 | 0 | 0 | 0 | 0 |
| 17 | Billing for AI work | 0 | 0 | 0 | 0 | 0 |
| 18 | AI-generated evidence | 0 | 0 | 0 | 0 | 0 |
| 19 | Consumer AI legal services | 0 | 0 | 0 | 0 | 0 |
| 20 | Arbitration and ADR | 0 | 0 | 0 | 0 | 0 |
The provisional tier’s shape is therefore a data-quality signal. It is not a reason to infer that filing-disclosure rules or verification duties do not exist in those countries. It says the first pass did not locate them. The editor-reviewed tier remains the source for claims about where legal-practice AI rules are mature enough to compare.
Timeline: documents rose after 2023 and peaked in 2025 so far
The document timeline uses current-version dates and all version entries in the regulation tracker. It shows a sharp post-2023 build-up. Documents with current versions dated 2023 total 32; 2024 has 76; 2025 has 111; and 2026 has 101 as of 4 September. Version entries follow the same pattern: 40 in 2023, 93 in 2024, 119 in 2025 and 107 in 2026.
| Year | Documents with current version that year | In-force current documents | Version entries |
|---|---|---|---|
| 2018 | 1 | 1 | 2 |
| 2019 | 0 | 0 | 2 |
| 2020 | 1 | 0 | 2 |
| 2021 | 1 | 1 | 1 |
| 2022 | 1 | 1 | 2 |
| 2023 | 32 | 32 | 40 |
| 2024 | 76 | 69 | 93 |
| 2025 | 111 | 103 | 119 |
| 2026 | 101 | 85 | 107 |
The early years are mostly court-technology and AI-governance instruments rather than legal-profession generative-AI rules. The 2023 line changes after the first widely reported AI-fabricated-citation sanctions and the first judicial guidance documents. The 2024 and 2025 lines show spread through bar guidance, court notices, AI strategies and the EU AI Act. The 2026 line includes both new binding court controls and updates to earlier guidance.
The timeline should not be read as a rate forecast. The tracker is versioned, and it backfills older material when it is found. It is also source-dependent: a new national AI Act, a revised judicial policy and a bar PDF all count as documents, but they are not equal in legal force. The useful point is sequencing. Courts and bars reacted first through guidance and practice notes; statutes then supplied a broader horizontal layer.
What to watch
The main watch item is not a single global rule. It is whether pending consultation material turns into binding court procedure. England and Wales still have the Civil Justice Council’s final report on AI in court documents pending after its 30 June 2026 interim findings. The United States federal evidence-rule work on AI-generated evidence and deepfakes remains a watch item. India has draft Supreme Court AI regulations in the dataset, with a disclosure certificate and restrictions on adjudicatory use, but no final version recorded in this tracker as of 4 September 2026.
The second watch item is effective dates. EU AI Act Article 50 transparency duties applied from 2 August 2026. Annex III high-risk obligations, including justice-related systems, now apply from 2 December 2027 after the Digital Omnibus amendment, and Annex I product-embedded obligations from 2 August 2028. Those dates affect legal AI providers and deployers, but they do not answer national court-filing questions.
The third watch item is whether provisional records graduate. The provisional group has 54 records, and most cells record no rule found. Editor review may confirm that absence, convert some cells to guidance or binding, or move some cells to unclear where the source trail is too weak. This report does not propose graduation; it lists the tier and leaves source-by-source review to the editor.
The fourth watch item is case law. The incident tracker now has 122 records, and 34 country records use case law in at least one category. If more courts turn fabricated AI output into regulator referrals, costs orders, contempt warnings or disciplinary decisions, the sanctions and verification categories will keep changing even without new rules.
Appendix A: data tables
Full category by status table, editor-reviewed records only
| Category | Question | Binding rule | Official guidance | Proposed / consultation | Set by case law | Nothing found | Not yet determined | Active positions | Binding or guidance |
|---|---|---|---|---|---|---|---|---|---|
| Disclosure of AI use in filings | Must lawyers disclose AI use in court filings? | 6 | 3 | 4 | 0 | 57 | 6 | 13 | 9 |
| Duty to verify AI output | Must lawyers verify AI output before relying on it? | 10 | 28 | 1 | 11 | 23 | 3 | 50 | 38 |
| Judges’ use of AI | May judges and court staff use AI in their own work? | 10 | 21 | 5 | 1 | 25 | 14 | 37 | 31 |
| AI barred from deciding cases | Is AI barred from deciding cases or drafting judgments? | 10 | 18 | 3 | 1 | 37 | 7 | 32 | 28 |
| Self-represented litigants | Do self-represented litigants get AI-specific court guidance? | 6 | 2 | 1 | 4 | 56 | 7 | 13 | 8 |
| AI-generated evidence | Are AI-generated evidence and deepfakes covered by rules? | 1 | 4 | 1 | 3 | 58 | 9 | 9 | 5 |
| Client data in AI tools | Can lawyers put client data into AI tools? | 7 | 33 | 2 | 0 | 31 | 3 | 42 | 40 |
| Technological competence | Does competence include understanding AI risks? | 15 | 24 | 1 | 0 | 34 | 2 | 40 | 39 |
| Supervision of AI work | Must supervisors control AI-assisted legal work? | 4 | 25 | 0 | 3 | 38 | 6 | 32 | 29 |
| Client consent and transparency | Must clients be told or asked before AI is used? | 4 | 26 | 0 | 0 | 39 | 7 | 30 | 30 |
| Billing for AI work | Can lawyers bill for AI-assisted work? | 1 | 7 | 0 | 1 | 57 | 10 | 9 | 8 |
| Consumer AI legal services | Are consumer AI legal services regulated as legal practice? | 4 | 3 | 0 | 1 | 57 | 11 | 8 | 7 |
| Bar guidance on generative AI | Has the bar or regulator issued generative-AI guidance? | 4 | 32 | 2 | 0 | 30 | 8 | 38 | 36 |
| Courts’ own AI deployment | Do courts have rules for their own AI systems? | 14 | 21 | 6 | 0 | 12 | 23 | 41 | 35 |
| Data protection and legal AI | Do data-protection rules specifically govern legal AI? | 10 | 32 | 1 | 0 | 20 | 13 | 43 | 42 |
| Horizontal AI statute | Does a horizontal AI law classify legal or justice uses? | 32 | 4 | 20 | 0 | 13 | 7 | 56 | 36 |
| Sanctions for AI misuse | Have courts sanctioned AI misuse? | 1 | 1 | 0 | 32 | 34 | 8 | 34 | 2 |
| Arbitration and ADR | Do arbitration or ADR rules address AI? | 0 | 6 | 0 | 0 | 38 | 32 | 6 | 6 |
| Mandatory AI training | Is AI training mandatory for lawyers? | 21 | 9 | 1 | 0 | 42 | 3 | 31 | 30 |
| Vendor due diligence | Must legal AI vendors pass procurement due diligence? | 12 | 28 | 1 | 0 | 29 | 6 | 41 | 40 |
Full category by status table, provisional records only
| Category | Binding rule | Official guidance | Proposed / consultation | Set by case law | Nothing found | Not yet determined | Active positions | Binding or guidance |
|---|---|---|---|---|---|---|---|---|
| Disclosure of AI use in filings | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Duty to verify AI output | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Judges’ use of AI | 0 | 1 | 1 | 0 | 52 | 0 | 2 | 1 |
| AI barred from deciding cases | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Self-represented litigants | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| AI-generated evidence | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Client data in AI tools | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Technological competence | 1 | 0 | 0 | 0 | 53 | 0 | 1 | 1 |
| Supervision of AI work | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Client consent and transparency | 1 | 0 | 0 | 0 | 53 | 0 | 1 | 1 |
| Billing for AI work | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Consumer AI legal services | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Bar guidance on generative AI | 0 | 0 | 1 | 0 | 53 | 0 | 1 | 0 |
| Courts’ own AI deployment | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Data protection and legal AI | 1 | 2 | 3 | 0 | 48 | 0 | 6 | 3 |
| Horizontal AI statute | 3 | 17 | 12 | 0 | 22 | 0 | 32 | 20 |
| Sanctions for AI misuse | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Arbitration and ADR | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
| Mandatory AI training | 1 | 0 | 0 | 0 | 53 | 0 | 1 | 1 |
| Vendor due diligence | 0 | 0 | 0 | 0 | 54 | 0 | 0 | 0 |
Country list by coverage tier
| Coverage tier | Count | Editor-reviewed | Provisional | Countries |
|---|---|---|---|---|
| Extensive | 14 | 14 | 0 | Australia, Brazil, Canada, France, Germany, International bodies, Ireland, Italy, Philippines, Poland, Slovakia, Spain, United Kingdom, United States |
| Substantial | 21 | 21 | 0 | Argentina, Austria, Belgium, China, Colombia, Czechia, Denmark, Estonia, European Union, Finland, India, Indonesia, Israel, Malaysia, Netherlands, New Zealand, Nigeria, Norway, Singapore, Sweden, Türkiye |
| Developing | 22 | 20 | 2 | Bahrain, Bulgaria (provisional), Chile, Croatia, Hong Kong SAR, Hungary, Japan, Kazakhstan (provisional), Kenya, Latvia, Lithuania, Luxembourg, Nepal, Pakistan, Portugal, Romania, South Africa, South Korea, Switzerland, Taiwan, United Arab Emirates, Vietnam |
| Early: one or two positions | 45 | 15 | 30 | Albania (provisional), Algeria (provisional), Armenia (provisional), Azerbaijan (provisional), Belarus (provisional), Botswana (provisional), Cameroon (provisional), Côte d’Ivoire (provisional), Cyprus, Ecuador, Egypt, Ethiopia (provisional), Georgia (provisional), Ghana, Greece, Iceland, Iran (provisional), Iraq (provisional), Jordan (provisional), Kuwait, Malta, Mauritius (provisional), Mexico, Moldova (provisional), Montenegro (provisional), Morocco, Mozambique (provisional), Namibia (provisional), North Macedonia (provisional), Oman (provisional), Peru, Qatar, Russia (provisional), Rwanda (provisional), Saudi Arabia, Senegal (provisional), Serbia (provisional), Slovenia, Tanzania (provisional), Thailand, Tunisia (provisional), Uganda (provisional), Ukraine (provisional), Zambia (provisional), Zimbabwe (provisional) |
| Checked: no rules found | 28 | 6 | 22 | Afghanistan (provisional), Bangladesh, Bolivia (provisional), Bosnia and Herzegovina (provisional), Brunei (provisional), Cambodia (provisional), Costa Rica, Cuba (provisional), Dominican Republic, El Salvador (provisional), Guatemala (provisional), Honduras (provisional), Jamaica (provisional), Kyrgyzstan (provisional), Laos (provisional), Lebanon (provisional), Macao (provisional), Mongolia (provisional), Myanmar (provisional), Nicaragua (provisional), Panama, Paraguay (provisional), Puerto Rico (provisional), Sri Lanka, Trinidad and Tobago (provisional), Uruguay, Uzbekistan (provisional), Venezuela (provisional) |
Appendix B: sources
Primary documents below are official document URLs from versions[0].url. The report leans on the dataset wording in the relevant YAML summary, keyProvisions and country note fields, with the URLs fetched or archive-checked in this run where the site allowed it.
Appendix C: changes to this report
None.