Skip to content

Regulation Tracker / Other

B 05.2 Data Security Manual [Tietoturvaopas], Annex 5 'AI guide for the advocate' [Tekoälyopas asianajajalle]

Finnish Bar Association [Suomen Asianajajaliitto / Suomen Asianajajat], board

last revised 2025-12-01last verified 2026-09-043 versionscountry page →

GuidanceIn forceVerification dutyConfidentialityCompetenceSupervisionRecord-keepingRisk classification

map categories:Duty to verify AI outputClient data in AI toolsTechnological competenceSupervision of AI workClient consent and transparencyBar guidance on generative AIMandatory AI trainingVendor due diligenceData protection and legal AI

The Finnish Bar's information-security manual, recommendatory in character but functioning as commentary on the binding B 05.1 guideline. Its Annex 5, first added in April 2024 and substantially updated in November 2025, is Finland's principal profession-facing generative-AI guidance for advocates, in force from 1 December 2025.

Applies to
lawyers, firms
Effective
See version history
Current version
13.11.2025 update · 01 Dec 2025
Last verified
04 Sept 2026

What the document requires

  • Annex 5 point 2: whether advice rests wholly or partly on AI output, the advocate is personally liable to the client; tools err in ways that are hard to detect and outputs can look credible while containing factual errors or fabricated references, so the advocate must always verify correctness before use.
  • Annex 5 point 1: a business-grade licence of the AI application must be acquired, applying binding guideline B 05.1 point 6; a free consumer version is not a business subscription.
  • Annex 5 point 4: AI tools may be used only if it can be assured that privileged material is not used, stored or shared contrary to confidentiality; terms and settings, including those of extensions and agents, must be checked so inputs are not used for model training or to answer other users.
  • Annex 5 point 6: firms must ensure staff AI literacy under AI Act Art. 4, covering how AI works, its limits, prohibited uses, human oversight (outputs assessed critically before use) and transparency about when AI was used and how it shaped the result; literacy must be refreshed as systems change.
  • Annex 5 points 3, 7, 8 and 9: periodic risk assessment of each tool; access rights scoped so AI cannot surface material beyond its intended audience; blocking use of firm data or user content for third-party model training; and logging and monitoring of AI use assigned to competent staff because models drift and fabricate.
  • Main text: where a cloud service such as an AI solution offers a version with wider security features that separate the customer's data from other users' data, that version must be adopted.

Version history

VersionDateWhat changedSource
13.11.2025 updatecurrent2025-12-01Board updated Annex 5, the AI guide, on 13 November 2025; the manual is in force from 1 December 2025. Annex 5 now runs to twelve numbered requirements plus a Microsoft 365 Copilot deployment guide.official
19.4.2024 update2024-04-19Board added Annex 5 (the AI guide) and amended the 'Background' section to note that AI use increases the risks of handling confidential data.official
Original2018-11-23Manual adopted by the Bar's board on 23 November 2018; earlier updates 12 Dec 2019, 24 Sept 2021 and 14 Dec 2023.official

Sources

Cite this record

SafeLegalAI Legal AI Regulation Tracker, "B 05.2 Data Security Manual [Tietoturvaopas], Annex 5 'AI guide for the advocate' [Tekoälyopas asianajajalle]" (Finnish Bar Association [Suomen Asianajajaliitto / Suomen Asianajajat], board, 13.11.2025 update, 2025-12-01), safelegalai.com/regulation/other/fi-bar-tietoturvaopas-b052 (accessed 2026-09-04). Data: CC BY 4.0.

More official documents in Other