Privilege · GDPR Art. 9 · EU AI Act · NIS2

AI solutions for Hungarian law firms

Privilege-aware RAG, on-prem Llama / Qwen LLM, Hungarian-language contract redlining inside Word, permission-aware knowledge base and EU AI Act Article 4 governance — one codebase, EU-only data. Last updated 2026-05-04.

TL;DR

  • Attorney privilege under Act LXXVIII of 2017 + 6/2018 MÜK code is absolute — uploading a client contract to public ChatGPT is a serious risk.
  • GDPR Article 9 special-category data is essentially always present; Art. 9(2)(f) is the legal-claim basis.
  • EU AI Act Article 4 AI literacy has applied since 2025-02-02 — staff AI training is mandatory.
  • On-prem Llama 3.3 70B / Qwen 2.5 72B + RAG with citations is the right baseline for Hungarian.
  • Project ranges: HUF 2-42M depending on scope, EU-only deploy and Hungarian Kft. contract.

Pain map — what partners are dealing with right now

Concrete, named problems from Hungarian law firms.

ChatGPT shadow IT — associates use it secretly

Junior associates copy contracts into ChatGPT / Claude.com because it's fast. Attorney privilege under Act LXXVIII of 2017 is absolute — handing data to a third party (US / EU mix) is a serious risk. We deliver a privilege-aware internal tool so juniors don't have to resort to shadow IT.

Hungarian-language legal research — generic AI hallucinates

Generic ChatGPT prompts on Hungarian BH numbers, MK reasoning or Pp. paragraphs are unreliable: the model hallucinates or mixes in US law. We build RAG over the firm's BH digest, commentaries and prior briefs — always with source citations.

Contract review in 2 hours instead of 2 days

First-pass markup of a 30-page SPA takes a senior 4-8 hours. AI first pass cuts this to 30-60 minutes — liability stays with the lawyer, but billable hours free up for higher-value work.

Fragmented document management — knowledge isn't shared

Precedent search in many firms happens in Outlook folders, local PDFs, ad-hoc Word files. A partner's departure means a huge knowledge loss. We deliver a permission-aware searchable knowledge base on top of SharePoint / Microsoft 365 / proprietary DMS.

EU AI Act Article 4 — training duty since 2025-02-02

Article 4 (AI literacy) has applied since 2025-02-02: every organisation that provides or uses AI must give documented AI training to staff. Many firms haven't started — it's a simple but mandatory item.

Regulatory landscape for legal AI

Only items grounded in official sources (Net.jogtár, EUR-Lex, MÜK).

Regulation / codeApplicableScopePenalty
Act LXXVIII of 2017 (attorney activity)In forceAttorney privilege, absolute and indefiniteMÜK disciplinary, bar exclusion
6/2018. (III. 26.) MÜK codeIn forceAttorney ethical code (privilege handling, technology use)MÜK disciplinary
GDPR — Reg. (EU) 2016/6792018-05-25Article 9 special category, Art. 9(2)(f) legal claims<= EUR 20M or 4%
EU AI Act — Reg. (EU) 2024/1689Art. 4 literacy 2025-02-02; Art. 50 transparency 2026-08-02Limited risk (legal-support AI), high only for binding decisions<= EUR 15M or 3% (Art. 99(4))
NIS2 — Dir. (EU) 2022/2555HU 2026-01-06 (Act LXIX of 2024)Larger firms by size + sector may fall under Annex II / III>= EUR 7M or 1.4%

Integration matrix — what we connect to

Every named system has a documented API.

SystemProtocolNote
Microsoft 365 / SharePoint / OneDriveGraph API + OAuth2Dominant DMS layer in legal; permission-aware indexing.
Microsoft WordOffice Add-in (Office.js)Word panel for the redlining UX, native track-changes.
Llama 3.3 70B / Qwen 2.5 72B (on-prem LLM)OpenAI-compatible RESTvLLM / Ollama / TGI on a GPU server with 4-bit quantisation.
ChromaDB / Qdrant / pgvectorREST + gRPCVector search for the RAG layer, hybrid keyword + dense.
MS Copilot / OpenAI / Anthropic API (alternative)REST + EU-region endpointIf the firm accepts a commercial model — Azure OpenAI in an EU DC, for example.
JurStore / proprietary practice managementREST / SOAP / DBClient, matter and case integration.
DocuSign / Adobe Sign / OneSpanREST + eIDAS QESElectronic signature, eIDAS qualified signature on demand.
Számlázz.hu / Billingo billingREST + NAV connectorDetailed time-billing and invoicing.

Why pick us for a legal AI project

Privilege-aware architecture

On-prem Llama / Qwen, EU-only VPC, encryption-at-rest, opt-out fine-tune, retention policy, audit log.

RAG with citations

No answer without a source; the partner can click through to the BH number, commentary point or brief paragraph.

Word-native redlining

Office Add-in (not a separate webapp), native track changes, fine-tuned on the firm's own boilerplate.

EU AI Act governance ready

Article 4 AI literacy training material, Article 50 transparency disclaimers, FRIA template if the system steps into high-risk.

Pricing for legal AI projects

Our published project ranges (see /pricing.md), adjusted for legal overhead (about +10-15% for privilege-aware audit logging).

  • · Privilege-aware RAG MVP: 2-3 months, HUF 6-15M
  • · On-prem LLM deploy (Llama / Qwen + fine-tune): 3-5 months, HUF 14-32M
  • · Word add-in contract redlining: 4-6 months, HUF 18-42M
  • · DMS integration (Microsoft 365 / proprietary): 2-4 months, HUF 8-20M
  • · Article 4 AI literacy + governance roadmap: 4-6 weeks, HUF 2-5M
  • · Continuous retainer: HUF 0.6-1.8M / month

Talk in person, near our office

In a 30-minute scoping call we map the partner needs and the privilege framework, and give you a tight estimate. Call +36 30 098 0767 or drop in.

Budapest office: Bank Center, Szabadság tér 7., 1054 Budapest, 1st floor, office 112. Mon-Fri 9:00-18:00 by appointment · balint@appforge.hu
Internal links if you want to go deeper: AI development · EU AI Act checklist · Process automation.
GYIK

Legal AI — frequently asked

Look at this through the attorney privilege lens (Act LXXVIII of 2017 and the 6/2018 MÜK ethical code): privilege is an absolute, indefinite obligation that does not end with the engagement. Uploading a contract to a public ChatGPT / Claude.com / Gemini is risky even with the 'don't train on my data' switch, because the data physically moves into a third party's US-region (or unknown) infrastructure. We build on-prem or EU-only deploys (Llama 3.x, Qwen 2.x, Mistral) where the contract never leaves the firm's network.

Let's start the legal AI scoping call

In 30 minutes we map the partner needs and privilege framework and give you a tight time-and-cost estimate.

Start a project