New legal practices and emerging regulation

New legal practices and emerging regulation

23 September, 2026

Share:

New legal practices and emerging regulation: insolvency, compliance, AI and cybersecurity

The practice of law is changing rapidly. Companies no longer need only traditional legal advice; they need professionals capable of operating in crisis situations, preventing criminal risks, interpreting new technology regulations, analysing automated decisions and responding to cybersecurity incidents.

In this context, new legal practices are emerging around business transformation, digital regulation, artificial intelligence and preventive risk management. For lawyers, this represents an opportunity to specialize in areas that are increasingly demanded by law firms, companies, consultancies and legal departments.

Insolvency and restructuring: what does a lawyer do in insolvency cases?

Insolvency law and business restructuring are key areas when a company faces financial difficulties, liquidity problems or insolvency risk.

A lawyer specialized in insolvency does not intervene only when the company can no longer pay. Their role is also preventive: analysing the financial situation, assessing alternatives, negotiating with creditors and designing solutions that help preserve activity, employment and business value.

Their usual functions include:

  • Analysing the company’s legal and financial situation.
  • Advising on refinancing processes.
  • Negotiating with creditors, banks or suppliers.
  • Preparing restructuring plans.
  • Acting in insolvency proceedings.
  • Protecting directors’ liability.
  • Coordinating with financial advisors and auditors.
  • Assessing the sale of productive business units.
  • Managing conflicts between shareholders, creditors and governing bodies.

In this field, the Master in Business Law, Arbitration and ADR allows students to go deeper into areas linked to business advisory, dispute resolution and the legal management of complex situations.

Corporate criminal compliance: preventing company criminal liability

Corporate criminal compliance has become an essential tool for preventing risks within organizations. Its purpose is to establish controls, protocols and internal measures that help avoid unlawful conduct and demonstrate that the company acts diligently.

A criminal compliance program may include:

  • Criminal risk maps.
  • Internal action protocols.
  • Whistleblowing channels.
  • Supervision and control systems.
  • Training for employees and managers.
  • Disciplinary measures.
  • Review of third parties and suppliers.
  • Documentation of sensitive decisions.
  • Periodic updating of the model.

Criminal prevention does not only affect the legal area. It also involves management, human resources, finance, operations, technology and governance bodies. For this reason, the specialized lawyer must combine regulatory knowledge, business vision and the ability to design systems that work in practice.

When compliance connects with labour relations, internal protocols, corporate investigations or business culture, the Master in Labour Law, Employment Compliance and New Technologies can provide a complementary perspective. In companies with complex corporate structures, corporate transactions or risks linked to governance, training such as the Master in Corporate, M&A, Finance and Stock Markets can also be useful.

AI Act: what obligations do companies using artificial intelligence already have?

Artificial intelligence is entering business processes, recruitment, marketing, customer service, data analysis, document management, scoring, decision automation and legal services. This requires companies to review how they use these tools and what risks they generate.

In Europe, the AI Act establishes a common framework to regulate artificial intelligence systems. The European Commission states that the regulation entered into force on 1 August 2024 and that its application is progressive, with some obligations already active and others subject to specific deadlines.

Some relevant obligations for companies include:

  • Identifying which AI systems they use.
  • Classifying the risk level of each tool.
  • Checking whether there are prohibited or sensitive uses.
  • Training teams that use AI.
  • Ensuring transparency where required.
  • Documenting processes and decisions.
  • Reviewing contracts with technology providers.
  • Controlling bias, errors and risks to fundamental rights.
  • Defining internal supervision responsibilities.

Obligations for providers of general-purpose AI models began to apply in the EU on 2 August 2025, while other AI Act obligations are activated in phases depending on the type of system and its risk level.

For profiles that want to connect Law, digital strategy and technology management, the Digital MBA can help understand how digital transformation impacts organizations. For those seeking to integrate legal practice, business and digital regulation, the Access to the Legal Profession + Digital MBA offers an approach aimed at lawyers who need to understand technology, business and regulation.

Liability for automated decisions

Automated decisions are one of the major challenges of current law. More and more companies use algorithms to classify customers, assess risks, select candidates, detect fraud, allocate resources or make decisions that may affect individuals.

The problem arises when an automated decision produces legal effects or significantly impacts a person. The European data protection framework recognizes the right not to be subject to decisions based solely on automated processing, including profiling, when they produce legal effects or similarly significant effects.

From a legal perspective, companies must ask themselves:

  • Which decisions are made using automated systems.
  • What data feeds those systems.
  • Whether there is real human intervention.
  • How affected individuals are informed.
  • What criteria the algorithm uses.
  • How errors or bias are detected.
  • Who is responsible if the decision causes harm.
  • What review mechanisms exist.

The lawyer specialized in technology must be able to translate these risks into internal policies, contracts, impact assessments, supervision protocols and defence mechanisms.

Generative AI in legal practice: how it is transforming the work of lawyers and law firms

Generative AI is changing the way lawyers, law firms and legal departments work. Tools capable of drafting, summarizing, classifying, analysing documents or generating drafts can improve efficiency, but they also introduce new risks.

Common uses include:

  • Preliminary document review.
  • Summaries of contracts or case files.
  • Legal information search.
  • Preparation of drafts.
  • Contract risk analysis.
  • Document classification.
  • Support in due diligence.
  • Generation of internal reports.
  • Automation of repetitive tasks.

However, the use of generative AI requires professional control. Lawyers must review outputs, verify sources, protect confidentiality, avoid entering sensitive data without guarantees and ensure that the tool does not replace legal judgment.

The competitive advantage will not lie only in using AI, but in knowing how to integrate it with method, responsibility and understanding of the legal business.

Cybersecurity and law: obligations in the event of a cyberattack

Cybersecurity is now a legal issue, not only a technical one. A cyberattack can affect personal data, trade secrets, business continuity, client relationships, contracts, corporate reputation and regulatory obligations.

In the European Union, the NIS2 Directive seeks to raise the common level of cybersecurity and strengthen resilience and incident response capacity among public and private entities in critical sectors.

In the event of an incident, a company must act quickly and in a coordinated manner. From a legal perspective, it is important to review:

  • Which systems have been affected.
  • Whether personal data has been compromised.
  • What notification obligations exist.
  • Which contracts may be affected.
  • Which providers are involved.
  • What evidence must be preserved.
  • How the incident should be communicated.
  • What corrective measures must be adopted.
  • What liability may arise.
  • How future incidents can be prevented.

A lawyer specialized in cybersecurity must work with technical teams, data protection officers, management, communications and compliance. Their role is to help contain legal risk and ensure an orderly response.

What legal profiles does this new regulation demand?

New legal practices require professionals capable of moving between law, business, technology and risk management.

Some profiles with strong potential include:

  • Lawyer specialized in restructuring.
  • Corporate criminal compliance expert.
  • Advisor in artificial intelligence and digital regulation.
  • Lawyer specialized in data protection.
  • Algorithmic liability consultant.
  • Legal counsel in technology companies.
  • Cybersecurity and law specialist.
  • Legal tech lawyer.
  • Consultant in legal digital transformation.
  • Governance, risk and compliance professional.

These profiles do not replace the traditional lawyer, but they do expand the field of legal practice towards new business and regulatory needs.

What to study to specialize in new legal practices

To work in these areas, the usual starting point is legal training, complemented by specialization in business, technology, compliance, arbitration, digital law, data protection, AI, cybersecurity or restructuring.

Good training should make it possible to understand:

  • How companies in crisis are managed.
  • What criminal risks an organization may assume.
  • How compliance models are applied.
  • What obligations arise from the use of AI.
  • How automated decisions are reviewed.
  • What impact generative AI has on legal work.
  • How to respond to cybersecurity incidents.
  • How to coordinate legal, technical and management teams.

The market demands lawyers capable of understanding the law, but also the business and technological context in which that law is applied.

A new stage for legal practice

New legal practices are redefining the role of the lawyer. It is no longer enough to react to conflicts: anticipating risks, designing preventive systems, interpreting emerging regulation and supporting companies in transformation processes are becoming increasingly important.

Insolvency, criminal compliance, artificial intelligence, automated decisions, generative AI and cybersecurity show how law is adapting to a more complex, digital and regulated economy.

Specializing in these areas means preparing for a more strategic, cross-disciplinary legal practice connected to the major business challenges of the coming years.

Share:

Newsletter

Do you want to receive information about ISDE, new programs, or current news?

logo sticky azul
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.