Gana Misra
By Gana MisraCEO, Finrep
Thu Sep 10 2026

Disco RegTech Review 2026: GDPR & EU AI Act Compliance Verdict

Share
Disco RegTech Review 2026: GDPR & EU AI Act Compliance Verdict

Evaluating Disco as a Centralized RegTech Tool for GDPR and the EU AI Act

Compliance teams are being asked to evaluate AI tools against two overlapping EU frameworks simultaneously, with almost no vendor-neutral guidance on how to do it. This article does exactly that for Disco, the legal AI platform best known for eDiscovery, and gives a frank procurement verdict.

Key takeaway: Disco is not a RegTech platform. It is a legal AI tool with genuine compliance-adjacent capabilities, but it was not designed to satisfy GDPR or EU AI Act obligations end-to-end. Whether it belongs in your stack depends on which obligations you are trying to satisfy, and which you are willing to own yourself.

What Disco Actually Is (and What It Is Not)

Disco is a US-headquartered legal AI company founded in 2013, primarily built for AI-powered eDiscovery, legal document review, and case management. Its core product, DISCO Ediscovery, uses machine learning to classify, review, and produce legal documents at scale. DISCO Case Builder and a generative AI layer called DISCO AI sit on top of that foundation.

This positioning matters enormously for any compliance evaluation. Deloitte's RegTech Universe, which catalogues over 531 RegTech companies across regulatory reporting, risk management, identity management, compliance, and transaction monitoring, does not include Disco. That is not an oversight. Disco is a legal AI tool being stretched into RegTech-adjacent use cases, not a purpose-built compliance platform.

Purpose-built GDPR and AI Act compliance platforms, including OneTrust, TrustArc, Securiti.ai, and BigID, are designed from the ground up to map data flows, automate DPIA workflows, manage consent, and generate compliance documentation. Any honest evaluation of Disco must benchmark it against these alternatives.

Disco vs. Purpose-Built Compliance Platforms: Feature Comparison

CapabilityDiscoOneTrust / TrustArc / Securiti.ai
AI-assisted document reviewYes (core product)No
Data flow mapping and inventoryPartial (within matters)Yes (enterprise-wide)
DPIA workflow automationNoYes
Consent managementNoYes
DSAR managementNoYes
Records of processing activities (RoPA)Partial (processor records only)Yes (controller + processor)
Audit trail for document accessYesYes
AI Act technical documentation (Article 11)Not confirmedVaries by vendor
Cross-border transfer safeguards documentationPartial (DPA/SCCs available)Yes
Fundamental rights impact assessment (Article 27)NoEmerging

The table makes the gap visible. Disco's centralized architecture is genuinely strong for what it was built to do: consolidating document review, access controls, and audit trails within a legal matter. Outside that perimeter, the compliance infrastructure thins out quickly.

Is Disco a High-Risk AI System Under the EU AI Act?

This is the most consequential regulatory question for any enterprise deploying Disco in an EU context, and almost no vendor evaluation addresses it.

The EU AI Act (Regulation (EU) 2024/1689), which entered into force on 1 August 2024, lists AI systems used in the administration of justice and legal proceedings explicitly in Annex III, Point 8, as high-risk AI systems. If Disco's AI assists in legal proceedings, document review for litigation, or judicial decision-support, it may qualify.

The scope of "administration of justice" is still being actively interpreted by national competent authorities. Civil litigation eDiscovery may or may not fall within it. But the risk is live, and the consequences of misclassification are significant.

If Disco is classified as a high-risk AI system, the following obligations are triggered:

  • Article 11: Technical documentation must be drawn up before the system is placed on the market and kept current. Enterprises must request this documentation as part of vendor due diligence. Its absence is a red flag.
  • Article 13: The system must be sufficiently transparent to allow deployers to interpret outputs. For Disco, this means its document classifications, relevance rankings, and privilege determinations must be explainable, not just asserted.
  • Article 14: Human oversight must be genuinely effective. Reviewers must be able to override, interrupt, or disregard AI outputs, not rubber-stamp them. Workflow design must demonstrate this, not just claim it.
  • Article 15: Accuracy, robustness, and cybersecurity requirements apply throughout the system's lifecycle.

High-risk AI system obligations for Annex III systems apply from 2 August 2026. That deadline is now.

The Provider/Deployer Split: Compliance Responsibility Is Shared

One of the most important points that competing content consistently misses: the EU AI Act distinguishes between providers (those who develop and place AI systems on the market) and deployers (those who use AI systems professionally). Disco is the provider. Your enterprise is the deployer.

Under Articles 26 and 27 of the AI Act, deployers of high-risk AI systems carry their own obligations:

  • Conducting fundamental rights impact assessments before deployment
  • Ensuring effective human oversight during use
  • Monitoring system performance in production
  • Maintaining logs of system operation

Disco cannot absorb these obligations on your behalf. Procurement teams that assume the vendor handles AI Act compliance are taking on undisclosed liability.

How Disco's Centralized Architecture Maps to GDPR

Disco processes large volumes of legal documents. Those documents routinely contain personal data, and often special category data under GDPR Article 9: health information, legal proceedings data, financial records. Here is how Disco's centralized model interacts with the specific GDPR articles that matter most.

Article 25: Data Protection by Design and by Default

GDPR Article 25 requires that data protection principles, including data minimization and purpose limitation, be embedded into processing activities from the outset. Disco's centralized architecture can support this if configured correctly: access controls, matter-level data segregation, and retention policies can all be implemented within the platform. The question is whether they are implemented by default, or whether the burden falls on the customer to configure them. Vendor due diligence must answer this directly.

Article 30: Records of Processing Activities

GDPR Article 30 requires both controllers and processors to maintain records of processing activities. As a data processor, Disco must maintain its own processor RoPA and provide sufficient information for the controller (your enterprise) to complete its own. Centralized platforms handling data across multiple legal matters and clients create complex RoPA obligations. Verify that Disco's standard DPA addresses this explicitly.

Article 32: Security of Processing

GDPR Article 32 requires appropriate technical and organisational security measures, including encryption, pseudonymization, and resilience of processing systems. Centralization concentrates risk: a single breach on Disco's platform could expose data across multiple legal matters simultaneously. Evaluators must assess encryption standards at rest and in transit, penetration testing cadence, and incident response SLAs before signing.

Article 35: Data Protection Impact Assessment

GDPR Article 35 requires a DPIA for processing likely to result in high risk to individuals, including large-scale processing of sensitive data. Deploying Disco to process large volumes of legal documents containing special category data almost certainly triggers this obligation. The DPIA must be completed before deployment, not after. This is a near-certain requirement that many procurement teams discover too late.

Article 28: The Data Processing Agreement

GDPR Article 28 requires that controllers only use processors who provide sufficient guarantees. Disco's standard DPA must specify the subject matter, duration, nature and purpose of processing, type of personal data, categories of data subjects, and the obligations and rights of the controller. Review it against these requirements and negotiate amendments where the standard terms fall short.

The Cross-Border Transfer Problem

Disco is headquartered in Austin, Texas. Its cloud infrastructure runs on AWS, with processing in US and potentially other non-EEA regions. This creates a live GDPR Chapter V compliance question.

Post-Schrems II (CJEU C-311/18, July 2020), transfers of EU personal data to the US require either reliance on the EU-US Data Privacy Framework (DPF), adopted by the European Commission on 10 July 2023, or Standard Contractual Clauses (SCCs) accompanied by a Transfer Impact Assessment (TIA).

DPF certification is not permanent. It requires annual renewal and can be revoked. Before signing with Disco, verify current certification status on the DPF list. If Disco is not DPF-certified, SCCs and a TIA are required, and the TIA must genuinely assess US surveillance law risks, not just check a box.

The AI Model Training Risk: EDPB Opinion 28/2024

This is the compliance risk that almost no existing vendor evaluation addresses. The EDPB's Opinion 28/2024 on AI models, published in December 2024, clarifies that AI models trained on personal data must have a lawful basis under GDPR Article 6, and that anonymization of training data must meet a high standard.

If Disco trains or fine-tunes its AI models on customer legal document data, this creates a significant GDPR lawful basis question, particularly where that data contains special category data. The EDPB also concluded in the same opinion that legitimate interests cannot be used as a blanket justification for AI model training. It must be assessed case-by-case with a balancing test.

Enterprise customers must ask Disco directly: does the platform use customer data to train or improve its models? If yes, what is the lawful basis, and how is special category data handled? The answer must be in the DPA, not just in a sales conversation.

The Centralization Advantage: Where Disco Genuinely Helps

Centralized platforms do offer a real compliance benefit, and it is worth stating clearly. A single system of record for all compliance-relevant actions, including document access, review decisions, and exports, simplifies demonstrating accountability under GDPR Article 5(2) (the accountability principle) and satisfying AI Act Article 12 logging requirements for high-risk AI systems.

For legal teams managing large-scale litigation or regulatory investigations, Disco's audit trail consolidation is a genuine asset. The alternative, managing document review across fragmented tools, creates its own accountability gaps.

The catch is that centralization also means a single misconfiguration or breach can compromise the entire compliance record. That trade-off must be weighed explicitly, not assumed away.

The AI Act Timeline: Which Obligations Are Live Now

MilestoneDateWhat It Means for Disco Deployers
AI Act enters into force1 August 2024Regulation is law
Prohibited AI practices banned2 February 2025Verify Disco does not use prohibited techniques
GPAI model obligations apply2 August 2025If Disco's generative AI layer qualifies as GPAI
High-risk AI system obligations (Annex III)2 August 2026Conformity assessment, Article 11 docs, human oversight
Full application2 August 2027All remaining provisions

The August 2026 deadline for high-risk AI system obligations is current. If Disco's use case in your organisation falls within Annex III, the clock has already run.

Procurement Due Diligence Checklist

Before deploying Disco in an EU regulatory context, compliance and procurement teams should work through the following:

  1. Confirm DPF certification status on dataprivacyframework.gov. If not certified, obtain SCCs and conduct a Transfer Impact Assessment.
  2. Review Disco's standard DPA against GDPR Article 28 requirements. Negotiate amendments where the standard terms are insufficient.
  3. Request AI Act technical documentation under Article 11. If Disco cannot produce it, that is a material gap.
  4. Conduct a DPIA under GDPR Article 35 before deployment. Large-scale processing of legal documents containing special category data almost certainly triggers this.
  5. Assess high-risk classification under EU AI Act Annex III, Point 8. Document your reasoning and keep it on file for regulators.
  6. Conduct a fundamental rights impact assessment under AI Act Article 27 as the deployer.
  7. Ask about model training practices explicitly. Get the answer in writing in the DPA.
  8. Verify human oversight workflows satisfy Article 14. Reviewers must be able to meaningfully override AI outputs, with UI and process design that demonstrates this.
  9. Assess whether Disco alone satisfies your GDPR obligations or whether a purpose-built platform (OneTrust, Securiti.ai, BigID) is needed alongside it.
  10. Check the EDPB/EU AI Office joint framework status. As of mid-2026, the joint framework addressing the GDPR/AI Act intersection has not been finalized, meaning interpretive uncertainty remains. Build in review points as guidance develops.

The Verdict

Disco is a capable legal AI platform that offers real compliance-adjacent value, specifically consolidated audit trails, centralized access governance, and AI-assisted document review. It is not a GDPR or EU AI Act compliance platform, and it should not be procured as one.

For enterprises that already use Disco for eDiscovery and want to understand their regulatory exposure, the analysis above maps the obligations you own as the deployer. For enterprises evaluating Disco as a centralized compliance tool to satisfy both GDPR and the EU AI Act simultaneously, the honest answer is that purpose-built platforms are better suited to that job.

The global RegTech market is projected to reach approximately $86 billion by 2032, driven in large part by AI-specific regulation. That growth reflects genuine demand for tools that can satisfy overlapping frameworks. Disco is riding that wave, but it was not built for it.

As Nemko Digital puts it: "The question for manufacturers and service providers is no longer 'are we compliant?' but 'can we prove it, continuously, across jurisdictions?'" Disco can help you prove some of it. The rest is yours to build.

FAQ

Is Disco classified as a RegTech company? No. Disco does not appear in the Deloitte RegTech Universe, which catalogues over 531 RegTech companies. It is a legal AI and eDiscovery platform, not a purpose-built compliance tool.

Does Disco qualify as a high-risk AI system under the EU AI Act? Possibly. EU AI Act Annex III, Point 8 covers AI systems used in the administration of justice and legal proceedings. Whether civil litigation eDiscovery falls within that scope is still being interpreted by national competent authorities. Enterprises must assess this and document their reasoning before the August 2026 high-risk obligation deadline.

Does deploying Disco trigger a GDPR DPIA? Almost certainly, if deployed at scale. GDPR Article 35 requires a DPIA for large-scale processing of sensitive data. Legal documents routinely contain special category data. The DPIA must be completed before deployment.

Is Disco a data controller or data processor under GDPR? Disco is typically a data processor; your enterprise is the controller. This means you bear primary GDPR accountability, and Disco must provide sufficient guarantees under Article 28. Review the DPA carefully.

How does Disco handle cross-border data transfers under GDPR? Disco is a US company using AWS infrastructure. Transfers of EU personal data require either DPF certification (verify on dataprivacyframework.gov) or SCCs with a Transfer Impact Assessment. Confirm current certification status before signing.

Can Disco replace a purpose-built GDPR compliance platform? No. Disco does not offer data flow mapping, consent management, DSAR handling, or DPIA workflow automation. For full GDPR compliance infrastructure, a purpose-built platform such as OneTrust, TrustArc, Securiti.ai, or BigID is required alongside Disco.

What should I ask Disco about AI model training? Ask whether customer legal document data is used to train or improve Disco's AI models, what the lawful basis is under GDPR Article 6, and how special category data is handled. Get the answer in the DPA, not just in a sales call. The EDPB's Opinion 28/2024 makes this a live and material risk.

Run your financial reporting on Finrep