Artificial Intelligence

In an era of rapid technological innovation, artificial intelligence (AI) is central to transforming companies. This technology not only optimizes operational processes but also opens new horizons for innovative business models. Despite AI's vast potential and numerous applications, companies must implement it effectively while adhering to legal and ethical standards to minimize liability risks. Implementing AI is more than a technical task; it requires a strategic approach.
We are here to support you in developing and implementing AI projects, ensuring compliance with all legal requirements, including the AI Regulation.

What is AI?

AI refers to computer systems that simulate human-like intelligence. These systems learn from data, analyze complex patterns, make informed decisions, and optimize processes with a speed and precision that surpass human capabilities. With advanced algorithms and machine learning, companies can efficiently tackle challenges and conduct in-depth data analysis for accurate predictions and data-driven decisions.

What are the advantages of AI?

Integrating AI into companies offers numerous benefits beyond simple automation. It enables more precise market analyses and trend predictions through advanced data analysis, helping companies make informed decisions. Another advantage is personalization: AI improves the customer experience through tailored offers and services adapted to individual needs without any special effort.
Additionally, the intelligent optimization of processes leads to considerable cost savings. Finally, AI opens new opportunities for innovative business strategies by helping companies develop new business models and strengthen their competitiveness in the long term.

How is AI currently regulated?

The regulation of AI in the EU is based on a series of provisions designed to ensure responsible use. The AI Regulation sets uniform rules for the development and use of AI systems and follows a risk-based approach. It is supplemented by the AI Liability Directive, which creates clear guidelines on liability in the event of AI-related damage. Specific guidelines should be adopted for the use of generative AI in the company, considering copyright, trade secret protection, trademark and patent protection, and data protection. These regulations ensure security and innovation in the use of AI.

Our services in the field of artificial intelligence

  • Consulting and strategy development
    We identify potential uses for AI in your company and develop legally compliant and customized governance strategies.
  • Legal support
    Our experts ensure compliance with all legal requirements, in particular the European AI Regulation.
  • Ethics consulting
    We help develop ethical guidelines for the responsible use of AI.
  • Training courses and workshops
    We offer training courses to guide your team in the legally compliant use of AI technologies and to fully exploit their potential.

With our holistic approach, we ensure that your AI projects are legally compliant and ethically justifiable.

Contact persons

Bernhard Veeck

Bernhard Veeck

Attorney at Law | Partner

LL.M. (Media Law) | Adjunct Professor at Frankfurt University of Applied Sciences | Data Protection Officer (TÜV)

Olga Stepanova

Olga Stepanova

Attorney at Law | Partner

LL.M. (Berkeley) | CIPP/E | Certified Specialist for Intellectual Property Law | Certified Specialist for IT Law | Data Protection Officer (TÜV)

Artificial Intelligence

First, it must be assessed which risk category the system falls into under the AI Act (EU) 2024/1689, as this gives rise to specific obligations regarding documentation, transparency and human oversight. It must be borne in mind that the obligations under the Act become applicable in stages over time. Data protection issues must be clarified in parallel where personal data are processed. In addition, rights of use in the outputs, as well as internal responsibilities and control mechanisms, should be defined contractually and organisationally.

Under German law, purely AI-generated content without a significant human creative contribution is generally not protected by copyright, because it lacks a personal intellectual creation within the meaning of Section 2(2) UrhG (German Copyright Act). If, however, a result is shaped by substantial human editing or creative selection, separate protection may arise in respect of it. For companies, it is also important to consider which rights of use the relevant AI provider grants in its standard terms and conditions and whether those rights are transferable and sufficiently broad for the intended use.

German law does not recognise a separate form of strict ‘AI liability’. Liability towards third parties therefore generally requires a breach of duty and fault, for example under Section 280 BGB (German Civil Code) in a contractual relationship or under Section 823 BGB in tort; the conduct of persons deployed by the company is attributed to it under Section 278 BGB or Section 831 BGB, respectively. In practical terms, a company using an AI application will generally be liable if it has breached the necessary duties of selection, control and supervision. It is not legally possible to avoid liability merely by stating that ‘the AI made the decision’, since the decision to deploy the system and to adopt its outputs rests with the company. Appropriate control and approval processes for AI-supported decisions are therefore important, particularly for high-risk applications, for which the AI Act expressly imposes corresponding obligations. In addition, the recast EU Product Liability Directive (Directive (EU) 2024/2853) expressly includes software and AI systems within the concept of a product, thereby opening the way to strict liability of manufacturers and certain other economic operators for defective digital products. Companies should therefore assess at an early stage whether, in the specific deployment scenario, they are merely users or—owing, for example, to their own adaptations or placing the product on the market under their own name—are themselves manufacturers within the meaning of these provisions.

Training with personal data is permissible under data protection law only if there is a legal basis under the GDPR, such as consent or a legitimate interest following a prior balancing of interests. Principles such as data minimisation and purpose limitation must also be observed, which creates particular challenges when training large models. Careful documentation of the legal basis is required in every case.

Agentic AI goes beyond conventional AI assistants in that it not only creates content or answers questions, but also independently performs tasks, prepares decisions and co-ordinates different systems. Companies can use Agentic AI, for example, to process customer enquiries, automate compliance and documentation processes, analyse contracts or manage complex workflows. Before it is introduced, however, responsibilities, control mechanisms, data protection requirements and the necessary human oversight should be clearly defined. It is particularly important that automated decisions with legal or economic effects are always adequately monitored and documented in a comprehensible manner; in the case of solely automated decisions in individual cases, Article 22 GDPR must also be observed. In the case of specific AI agents, such as Agentic Commerce agents that automatically enter into purchase or licence agreements, the interaction with the national law governing the legal transaction must also be considered, in particular issues of authority to represent, attribution of declarations of intent and avoidance in the event of malfunctions.