Skip to content
Call, 0511 – 47 55 58 11

Practice area

Law of artificial intelligence: using AI lawfully

Using AI in a business pays off in many places. The legal questions arise beforehand, not once the tool is already in production.

Because it cuts across other fields, using AI in a company raises challenges in several areas of law at once. We offer advice across the board and an AI strategy coordinated between those areas from a single source, from Hannover and in both languages.

  • AI and data protectionData protection questions arise both in the development of AI and in the productive use of AI tools. We shape your use of AI in a data protection friendly way.
  • AI and copyrightCopyright questions arise both when protected works are entered as input and when the texts, images and other results produced by an AI are used. We make sure your application runs in line with copyright law.
  • LiabilityLiability questions arise on several levels: contractually towards AI providers or end customers, and in addition under tort law and product liability law. We help you recognise and minimise the risks.
  • Employment lawUsing AI has consequences under employment law. Its use has to be regulated and employees protected against adverse effects. Coordination with the works council may also be required.
  • Procurement and contractsUsing AI in a company needs planning. That includes careful selection of the applications, procurement and concluding all the relevant contracts.
  • AI governance and policiesThe use of AI has to be settled internally. Who decides which tool may be used and who checks before it goes live? Those using the tools also need to know where and how they may do so. Several instruments come into consideration, and we advise on them.
  • Duties under the AI ActThe AI Act attaches to the risk class. High-risk systems face an extensive catalogue of duties, and all others face at least the transparency duties under Article 50 AI Act. We classify your system and say what follows from it.
  • Fundamental rights and ethicsThe use of AI also raises questions of principle. An assessment in ethical terms and with a view to affected fundamental rights secures proportionality. The potential for discrimination in particular carries liability risks.

Your firm for artificial intelligence

From the role to the trade secret

Provider or deployer

The AI Act ties obligations to the role, not to the size of the business. Anyone who substantially modifies a bought-in system, offers it under their own name or uses it outside its intended purpose can move from deployer to provider. That classification belongs at the start of every project, because everything else builds on it.

Roles and obligations in detail

Identifying high-risk systems

Most systems are not high-risk, but the exceptions sit closer than many expect, for instance in selection, assessment and access to services. Once the classification is met, an extensive programme applies, from risk management through documentation to human oversight.

High-risk systems in detail

Training data and data quality

Where the data comes from and whom it represents decides both the output and the liability. Article 10 AI Act requires providers of high-risk systems to run data governance that detects and mitigates bias. Deployers owe input data that matches the intended purpose.

Data quality and discrimination

Transparency and labelling

Anyone talking to a chatbot has to be told, and generated content needs machine-readable marking. These duties do not depend on the risk class and therefore reach almost every deployment. What the marking should look like technically is set out not in the regulation but in the code of practice of 10 June 2026.

The transparency code of practice

Liability and insurance

There is no separate liability regime for AI. Damage is attributed under contract and tort law, with the duties of the AI Act working as protective statutes and the reformed product liability rules covering software expressly. Insurers increasingly exclude AI risks.

Liability for AI output

Employees and the works council

Several participation rights apply side by side once AI is deployed at work. The most important one does not turn on the employer intention but on whether the system is technically capable of monitoring conduct or performance. A works agreement is usually the calmer route.

Works council participation in detail

Trade secrets

Protection under the German Trade Secrets Act depends on reasonable steps to keep information secret. Feeding confidential material into a cloud tool without safeguards can remove that condition, and with it the protection. Conversely, trade secret protection is often the only way to secure your own model.

Trade secrets and AI

Introducing AI without flying blind?

We settle roles, obligations and contracts before the tool goes live.

Request AI advice

Topics in this practice area

Frequently asked questions

Are we a provider or a deployer under the AI Act?

Whoever develops an AI system or places it on the market under their own name is a provider. Whoever uses someone else's system under their own responsibility is a deployer. The line shifts as soon as you substantially modify a bought-in system or offer it under your own brand. The further obligations hang on this classification, which is why it comes first.

Do we have to label AI-generated content?

For certain cases the AI Act provides for transparency obligations, for instance for systems interacting with people and for artificially generated or manipulated content. Whether and how labelling has to look in a particular case is something we assess against your actual use.

May our staff enter customer data into an AI tool?

Not without a policy. Prompting can leak personal and confidential data, and depending on the service inputs are reused for training. What you need is a vetted choice of tool, a contractual basis and a usage policy that gives staff clear boundaries.

From when do the obligations for high-risk systems apply?

In stages, and the Digital Omnibus has moved the dates. For the context-based systems in Annex III they apply from 2 December 2027, and for high-risk systems that are products or safety components from 2 August 2028. Preparing a conformity procedure takes longer than the time remaining, so the postponement is no reason to wait.

Do we really have to train everyone?

The duty under Article 4 AI Act binds the organisation, not the individual. What is required is that the necessary competence exists in the organisation and sits where people work with the systems. Its extent follows the role, which is why a procurement team needs different training from an HR team running AI-assisted shortlisting.

Does the works council have to be involved?

As a rule yes, and through several rights at once. Section 87(1) no. 6 BetrVG applies as soon as the system is technically capable of monitoring conduct or performance. An intention to monitor is irrelevant. The information duty under Article 26(7) AI Act sits alongside it and does not replace co-determination under the BetrVG.

How high can fines under the AI Act be?

Up to 35 million euros or seven per cent of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises the lower figure caps the amount. Third-party claims for damages remain alongside. Fines and liability do not exclude one another.