Practice area
Law of artificial intelligence: using AI lawfully
Using AI in a business pays off in many places. The legal questions arise beforehand, not once the tool is already in production.
Because it cuts across other fields, using AI in a company raises challenges in several areas of law at once. We offer advice across the board and an AI strategy coordinated between those areas from a single source, from Hannover and in both languages.
Legal problems in the use of AI
- AI and data protectionData protection questions arise both in the development of AI and in the productive use of AI tools. We shape your use of AI in a data protection friendly way.
- AI and copyrightCopyright questions arise both when protected works are entered as input and when the texts, images and other results produced by an AI are used. We make sure your application runs in line with copyright law.
- LiabilityLiability questions arise on several levels: contractually towards AI providers or end customers, and in addition under tort law and product liability law. We help you recognise and minimise the risks.
- Employment lawUsing AI has consequences under employment law. Its use has to be regulated and employees protected against adverse effects. Coordination with the works council may also be required.
- Procurement and contractsUsing AI in a company needs planning. That includes careful selection of the applications, procurement and concluding all the relevant contracts.
- AI governance and policiesThe use of AI has to be settled internally. Who decides which tool may be used and who checks before it goes live? Those using the tools also need to know where and how they may do so. Several instruments come into consideration, and we advise on them.
- Duties under the AI ActThe AI Act attaches to the risk class. High-risk systems face an extensive catalogue of duties, and all others face at least the transparency duties under Article 50 AI Act. We classify your system and say what follows from it.
- Fundamental rights and ethicsThe use of AI also raises questions of principle. An assessment in ethical terms and with a view to affected fundamental rights secures proportionality. The potential for discrimination in particular carries liability risks.
Your firm for artificial intelligence
- Using ChatGPT in the workplace
- Using Microsoft Copilot in the workplace
- Protecting trade secrets when using AI
- GDPR-compliant use of AI
- Avoiding copyright infringement when deploying AI
- Minimising liability risks from AI
- Works agreements and usage policies for AI
- Fundamental rights impact assessment under the AI Act
- Risk classification for AI use under the AI Act
- Data protection impact assessment under the GDPR for AI use
From the role to the trade secret
Provider or deployer
The AI Act ties obligations to the role, not to the size of the business. Anyone who substantially modifies a bought-in system, offers it under their own name or uses it outside its intended purpose can move from deployer to provider. That classification belongs at the start of every project, because everything else builds on it.
Identifying high-risk systems
Most systems are not high-risk, but the exceptions sit closer than many expect, for instance in selection, assessment and access to services. Once the classification is met, an extensive programme applies, from risk management through documentation to human oversight.
Training data and data quality
Where the data comes from and whom it represents decides both the output and the liability. Article 10 AI Act requires providers of high-risk systems to run data governance that detects and mitigates bias. Deployers owe input data that matches the intended purpose.
Transparency and labelling
Anyone talking to a chatbot has to be told, and generated content needs machine-readable marking. These duties do not depend on the risk class and therefore reach almost every deployment. What the marking should look like technically is set out not in the regulation but in the code of practice of 10 June 2026.
Liability and insurance
There is no separate liability regime for AI. Damage is attributed under contract and tort law, with the duties of the AI Act working as protective statutes and the reformed product liability rules covering software expressly. Insurers increasingly exclude AI risks.
Employees and the works council
Several participation rights apply side by side once AI is deployed at work. The most important one does not turn on the employer intention but on whether the system is technically capable of monitoring conduct or performance. A works agreement is usually the calmer route.
Trade secrets
Protection under the German Trade Secrets Act depends on reasonable steps to keep information secret. Feeding confidential material into a cloud tool without safeguards can remove that condition, and with it the protection. Conversely, trade secret protection is often the only way to secure your own model.
Introducing AI without flying blind?
We settle roles, obligations and contracts before the tool goes live.
Request AI adviceTopics in this practice area
- AI and the liability of company managementIntroducing AI is a business judgement under uncertainty. German company law requires preparation, supervision and review of the results.
- AI compliance checkAI compliance check: analysis of the planned AI product, legal assessment and an overview of applicable rules, limits and risks.
- AI for developersAI in software development: licence risks in generated code, trade secrets in prompts, liability and the role under the AI Act.
- AI in local governmentUsing AI in local government: use cases, roles under the AI Act, data protection, staff representation and procurement.
- AI in public administrationAI in administrative procedure: automated decisions, the duty to investigate, reasons, and the fundamental rights impact assessment under the AI Act.
- AI literacy under Art. 4 AI ActThe AI literacy duty applies to providers and deployers alike. What it requires, who it covers and how it is evidenced.
- AI policyThe internal AI policy: what belongs in it, how it relates to co-determination and the AI Act, and why short rules work better.
- Choosing an AI toolThe questions to ask before procuring an AI tool: role, data, rights, records and the points that belong in the contract.
- Data quality and discriminationArticle 10 AI Act requires data governance against bias. Which quality criteria apply, what deployers owe, and how German equal treatment law fits in.
- High-risk AIClassification as high-risk AI under the AI Act: the two routes into the category, the obligations and the exceptions.
- Inputs as training dataAre our inputs used for training? Confidentiality, trade secrets and how to draft the contract with AI providers.
- Liability for AI outputWho answers for damage caused by AI, how the AI Act works as a protective statute, what the reformed product liability changes, and where insurance stops.
- Microsoft 365 and the GDPRUsing Microsoft 365 in line with data protection law: impact assessment, privacy-friendly configuration and representation before the supervisory authority.
- Passing on rights in AI outputPassing AI output to clients: which rights can be granted, which warranties are risky, and when labelling is required.
- Provider or deployerProvider or deployer under the AI Act: what decides the role, and when a deployer becomes a provider without noticing.
- Rights in inputs and outputsWhat AI provider terms say about rights in inputs and outputs, and what an indemnity is actually worth.
- Text and data miningWhat an AI model may be trained on: the exceptions in sections 44b and 60d UrhG, the machine-readable reservation of rights, and the burden of proof.
- Trade secrets and AIHow trade secret protection survives the use of AI, which safeguards count as reasonable, and how to protect your own models and outputs.
- Transcription assistantsDeploying AI meeting notes lawfully: criminal law, employee data protection, works council participation and the usage policy to go with it.
- Transparency and labelling dutiesArticle 50 AI Act: people must learn when they talk to a chatbot, and generated content needs marking. Deadlines and implementation.
- Transparency code of practiceThe Code of Practice on Transparency of 10 June 2026: what it requires, what signing it achieves, and how to show compliance without it.
- Works council participation and AIWhich participation rights a works council has when AI is deployed, when section 87(1) no. 6 BetrVG applies, and what belongs in a works agreement.
Frequently asked questions
Are we a provider or a deployer under the AI Act?
Whoever develops an AI system or places it on the market under their own name is a provider. Whoever uses someone else's system under their own responsibility is a deployer. The line shifts as soon as you substantially modify a bought-in system or offer it under your own brand. The further obligations hang on this classification, which is why it comes first.
Do we have to label AI-generated content?
For certain cases the AI Act provides for transparency obligations, for instance for systems interacting with people and for artificially generated or manipulated content. Whether and how labelling has to look in a particular case is something we assess against your actual use.
May our staff enter customer data into an AI tool?
Not without a policy. Prompting can leak personal and confidential data, and depending on the service inputs are reused for training. What you need is a vetted choice of tool, a contractual basis and a usage policy that gives staff clear boundaries.
From when do the obligations for high-risk systems apply?
In stages, and the Digital Omnibus has moved the dates. For the context-based systems in Annex III they apply from 2 December 2027, and for high-risk systems that are products or safety components from 2 August 2028. Preparing a conformity procedure takes longer than the time remaining, so the postponement is no reason to wait.
Do we really have to train everyone?
The duty under Article 4 AI Act binds the organisation, not the individual. What is required is that the necessary competence exists in the organisation and sits where people work with the systems. Its extent follows the role, which is why a procurement team needs different training from an HR team running AI-assisted shortlisting.
Does the works council have to be involved?
As a rule yes, and through several rights at once. Section 87(1) no. 6 BetrVG applies as soon as the system is technically capable of monitoring conduct or performance. An intention to monitor is irrelevant. The information duty under Article 26(7) AI Act sits alongside it and does not replace co-determination under the BetrVG.
How high can fines under the AI Act be?
Up to 35 million euros or seven per cent of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises the lower figure caps the amount. Third-party claims for damages remain alongside. Fines and liability do not exclude one another.