Isartal Legal is a Munich partnership of roughly sixty lawyers whose technology and regulatory group advises banks, payment institutions, insurers and their software suppliers on the EU AI Act and the GDPR. The work tends to arrive in one of three forms. Supervisory-driven questions come from compliance functions at BaFin-regulated firms, where the issue is how AI Act obligations interact with existing outsourcing, model-risk and data-protection duties. Product questions come from vendors that need a defensible classification of a credit-scoring or claims-triage system and a documentation package to support it. And then there is drafting: AI use policies, provider and deployer contract clauses, and internal conformity assessment procedures for Annex III systems. Gap analyses are quoted individually after a scoping call rather than from a rate card. Ongoing advisory is offered on monthly retainers, with most clients sitting between five and fifteen thousand dollars a month depending on volume. Lawyers work from the Munich office and travel regularly to client sites across Germany and neighbouring EU countries. The firm does not provide technical testing, does not implement management systems, and does not act for private individuals.