-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
Germany does not have a standalone domestic AI statute and, therefore, does not maintain its own legislative definition of artificial intelligence. In practice, the legal definition that matters is the one provided in Article 3(1) of Regulation (EU) 2024/1689 (the “EU AI Act”) for AI systems, which entered into force in August 2024 and applies directly across all EU Member States, including Germany. The AI Act defines an AI system as a “machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.”
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
Germany was among the early movers in establishing a national AI strategy. The federal government adopted its National Strategy for Artificial Intelligence in July 2018, setting out three core objectives: to make Germany a leading AI location and secure its future competitiveness, to ensure the responsible and public welfare-oriented development and use of AI, and to ensure that AI applications are considered ethically, legally, culturally, and institutionally and brought into line with existing principles of social coexistence. The strategy foresaw significant investment in scientific research facilities and easier access to public funding programs for start-ups.
In 2023, the federal government developed an AI Action Plan aimed at strengthening AI research, expanding AI infrastructure, advancing AI skills across the workforce, and fostering the transfer of AI into real-world value creation. The current federal government has continued this approach and has explicitly identified AI as a driver of economic growth and a tool for making public administration more efficient.
At the level of the Länder, all sixteen German states have developed digitalization strategies that include provisions on the use of AI in public services, administration, and courts.
The overall trajectory of Germany’s AI strategy is, however, increasingly shaped by EU-level initiatives rather than purely domestic choices – a pattern that is expected to continue as the AI Act’s substantive obligations progressively take effect.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
Germany has not enacted any horizontal domestic AI legislation of its own. The central regulatory instrument is the EU AI Act. The AI Act takes a risk-based approach: it prohibits certain AI practices entirely, imposes extensive obligations on providers and deployers of high-risk AI systems, and introduces lighter-touch transparency requirements for limited-risk systems such as chatbots. In addition, the EU AI Act determines obligations for providers of general-purpose AI models (GPAI). As obligations under the AI Act phase in progressively, providers and deployers across Germany are required to adapt their practices accordingly.
At domestic level, a targeted legislative development in 2025 permitted social security institutions to use the social data they hold to develop, train, validate, and test AI models, provided these serve to fulfil the institution’s statutory tasks. This marked a notable expansion beyond the earlier permission for health and long-term care insurance funds to conduct data-driven analyses for individual health risk identification.
Beyond this sector-specific measure, AI in Germany is governed by a patchwork of existing legal frameworks, each of which presents its own interpretive challenges when applied to AI systems. The GDPR applies wherever AI processes personal data and raises persistent difficulties around legal bases for training data, the application of purpose limitation to machine learning pipelines, and the right not to be subject to solely automated decision-making under Article 22. For the training of algorithms on health data, the European Health Data Space Regulation (EU) 2025/327 provides a dedicated legal framework, conditioning access on a data permit issued by a health data access body, processing within a secure environment, and a demonstrable link to scientific research in the health or care sector under Article 53(1)(e). Intellectual property law applies to questions of copyright in training data and AI outputs, with significant interpretive uncertainty around the scope of the text and data mining exception under sections 44b and 60d of the Copyright Act. Product liability law, currently being reformed through the new EU Product Liability Directive, applies to AI-related harm. Anti-discrimination law, particularly the General Equal Treatment Act (AGG), applies where AI influences employment decisions. Competition law and the EU Digital Markets Act apply to AI-enabled services offered by large platforms.
At EU level, amendments adopted in 2026 under the Digital Omnibus package adjusted certain AI Act timelines, clarified aspects of prohibited practices, introduced limited flexibility for SMEs, and provided a narrow exception for processing special categories of personal data for bias detection in high-risk AI systems. The amendment does not, however, introduce a general sector exemption for conformity assessments. An earlier proposal would have allowed, e.g. AI-assisted medical devices to satisfy conformity requirements exclusively under the Medical Device Regulation (MDR), removing the need for a parallel AI Act conformity assessment. That relief did not survive trilogue negotiations; the only sector-specific simplification that was retained applies in the area of general machinery regulation.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
Yes, and the obligations are becoming significantly more concrete with the EU AI Act’s transparency requirements. Article 50 creates three distinct categories of obligation. First, providers of AI systems designed to interact with natural persons – such as chatbots and voicebots – must ensure that users are informed they are interacting with AI, unless this is obvious from the context. The disclosure must be made no later than the first interaction, and there is no prescribed technical form, but it must be effective, including for vulnerable groups.
Second, providers of AI systems that generate synthetic audio, image, video, or text content must ensure that outputs are marked in a machine-readable format and remain detectable as AI-generated or manipulated. A layered, risk-based combination of methods is likely to be necessary to meet all the AI Act’s requirements.
Third, deployers of AI systems used to generate or manipulate content that constitutes a deep fake must disclose that the content has been artificially generated or manipulated.
Beyond Article 50, the AI Act imposes broader transparency and documentation obligations on providers of high-risk AI systems, including the obligation to draw up technical documentation, keep logs, provide information to deployers, and, in certain cases, register the system in the EU database for high-risk AI. Deployers of high-risk systems that make or assist with individual decisions affecting natural persons must, in many cases, inform those persons that they have been subject to an AI-assisted decision and, upon request, provide a meaningful explanation.
Transparency obligations also flow from the GDPR, which requires controllers to inform data subjects about the existence of automated decision-making, the logic involved, and the significance and likely consequences of such processing.
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
Human oversight is a core requirement of both the EU AI Act and the GDPR as applied in Germany. Under Article 22 GDPR, individuals have a right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them. Controllers must implement suitable measures to safeguard data subjects’ rights, including at minimum the right to obtain human intervention, to express a point of view, and to contest the decision. German data protection authorities have interpreted this provision strictly, treating it as a meaningful constraint on the automation of consequential decisions rather than a box-ticking exercise.
The AI Act reinforces this position considerably. Providers of high-risk AI systems must design their systems in a way that allows deployers to effectively oversee and, where necessary, interrupt, override, or shut down the AI system. Deployers, in turn, are obliged to implement the technical and organizational measures set out by the provider and to assign human oversight to persons with the necessary competence and authority. The DSK’s 2019 Hambach Declaration stated that AI must not turn human beings into objects and that AI systems must not make decisions without the possibility of human intervention – a principle that continues to guide supervisory practice under the current framework.
In regulated sectors, the requirements are even more explicit. In financial services, German supervisory practice requires that institutions retain the ability to understand, monitor, and override AI-driven decisions, including those taken by autonomous agents, whether in real time or through self-learning processes. In healthcare, responsibility for diagnosis and treatment remains with licensed professionals under German medical law, and fully autonomous AI decision-making in clinical practice is regarded as legally and ethically problematic. For AI systems used in medical devices, the EU AI Act reinforces this by classifying many such systems as high-risk, which triggers explicit human oversight obligations: providers must design systems that actively support human review, and deployers must ensure that clinical staff retain meaningful control over AI-assisted outputs and that the system’s limitations are clearly communicated.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
Germany addresses algorithmic bias and discrimination through a combination of existing general laws and the emerging AI Act framework. At domestic level, the General Equal Treatment Act (AGG) prohibits discrimination in employment and various areas of private legal transactions on grounds including race or ethnic origin, gender, religion or belief, disability, age, and sexual identity. Where AI systems are used in hiring, evaluation, or other employment decisions, they fall squarely within the AGG’s scope. Importantly, under section 22 of the AGG, it is not the person affected by discrimination who must prove actual discrimination; the party accused of discrimination must justify the non-discriminatory nature of its decision once unequal treatment has been plausibly demonstrated. This burden-shifting rule is particularly significant in AI-assisted decision-making, where the internal logic of the system may be opaque.
From a data protection perspective, the fairness principle under Article 5(1)(a) GDPR applies to AI systems that process personal data. The DSK’s Hambach Declaration explicitly identified the avoidance of discrimination through AI as a core supervisory requirement, calling for countermeasures to be applied before an AI system is put into use and for appropriate risk monitoring during operation.
The EU AI Act significantly extends the ex ante dimension of bias governance. High-risk AI systems – which include systems used in employment decisions, credit scoring, and access to essential services – must meet requirements for data governance, accuracy, robustness, and freedom from bias as part of their conformity obligations. The June 2026 amendment introduced a new Article 4a permitting the exceptional processing of special categories of personal data where this is strictly necessary for bias detection and correction, subject to narrow and carefully defined conditions.
In employment contexts, AI-driven decision-making is also subject to the co-determination rights of works councils. Where algorithmic systems influence hiring, performance assessment, or termination decisions, works councils typically have information and co-determination rights under the Works Constitution Act that must be exercised before such systems are introduced or materially changed.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
Liability for AI-related harm in Germany is currently assessed under a combination of fault-based liability under the Civil Code (sections 280 and 823 BGB) and strict product liability under the German Product Liability Act (ProdHaftG), which implements EU Directive 85/374/EEC. The ProdHaftG applies only to products – traditionally understood as movable items – and this has created a significant gap for AI systems offered purely as cloud-based or API-accessed services, which generally fall outside the product liability regime and must be assessed under contract and general tort law.
This gap is being addressed by the new EU Product Liability Directive (EU) 2024/2853, which Germany must implement by December 2026. The new directive explicitly includes software, digital manufacturing files, and AI systems within its scope, irrespective of whether they are embedded in hardware or provided independently. It also provides that a product may be defective not only due to its initial design but also due to its ability to learn, update, or change behavior after being placed on the market. Defectiveness may further arise from inadequate post-market monitoring or from failure to provide necessary safety updates.
German courts are already grappling with attribution questions in AI-related disputes. Recent German case law indicates a tendency towards holding operators of AI-based interfaces responsible for misleading or inaccurate AI-generated outputs. In several recent decisions, German courts have addressed liability issues arising from AI-generated content.
The emerging picture from German case law is that operators of AI-facing public interfaces will be held responsible for the outputs of their systems, and that general disclaimers about AI inaccuracy will not provide adequate protection. Burden-shifting mechanisms in the new Product Liability Directive are expected to ease the practical position of claimants, who historically faced significant difficulties in proving causation in cases involving complex or opaque AI systems.
-
What cybersecurity obligations apply to AI systems?
The cybersecurity obligations applicable to AI systems in Germany are primarily determined by two EU legislative instruments that have come into force or been transposed in recent years. The EU Cyber Resilience Act (CRA), which entered into force in late 2024, sets minimum cybersecurity requirements for products with digital elements across the EU. Manufacturers of such products must meet compliance obligations in phases: conformity body notification from mid-2026, vulnerability and incident reporting from September 2026, and full compliance with substantive cybersecurity and lifecycle requirements by December 2027. Products meeting CRA requirements carry CE marking, and reporting obligations to the Federal Office for Information Security (BSI) begin before the full substantive requirements apply.
The EU NIS2 Directive has been transposed into German law through the NIS2 Implementation Act (NIS2UmsG), which entered into force on 6 December 2025. This legislation significantly expands the cybersecurity regime through an updated Act on the Federal Office for Information Security (BSIG). A much wider range of organizations – including essential and important entities across multiple sectors – are now subject to risk-based security, incident reporting, and governance obligations.
AI-specific cybersecurity concerns are also recognized at regulatory level. AI models themselves increasingly represent critical attack surfaces: model poisoning, data exfiltration, and prompt injection can each undermine system integrity. In January 2026, the BSI published guidance on countermeasures for prompt injections, jailbreaks, and adversarial attacks specifically targeting large language models. The EU AI Act reinforces the cybersecurity dimension by requiring providers of high-risk AI systems to ensure robustness and accuracy throughout the system lifecycle and to implement measures against adversarial attacks.
In defense and security contexts, additional requirements relating to classified information, sovereign infrastructure, and national security considerations may significantly restrict the use of commercial AI platforms. Public-sector IT security guidelines issued by the BSI reinforce this by strongly recommending the use of sovereign or EU-based environments for ministries, police, defense, and national security sectors.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
AI-related risks are, in principle, insurable in Germany, though the insurance market for AI-specific risks remains at an early stage of development. Standard cyber insurance policies may cover some AI-related incidents, particularly where AI systems are implicated in data breaches, ransomware events, or business interruption caused by a cybersecurity failure. However, the precise scope of coverage depends heavily on policy wording, and many cyber policies were drafted before the widespread deployment of generative AI, leaving gaps in coverage for AI-specific loss scenarios.
Insuring against AI-specific risks – including hallucination liability, model drift causing operational failures, or AI-generated disinformation – is more complex. Underwriters face significant challenges in assessing risk profiles for AI systems, particularly where the system’s behavior is probabilistic and may change over time through continuous retraining or user interaction. The entry into force of the new Product Liability Directive is expected to increase exposure for providers of AI systems and may prompt greater market development in this area.
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No. The Legal Board of Appeal of the European Patent Office ruled on 21 December 2021 that only a human being can be named as an inventor within the meaning of Article 81 of the European Patent Convention. An AI cannot be an inventor, and a human being cannot be regarded as the legal successor of an AI as the actual inventor of a patent (J 8/20 and J 9/20).
The position under German domestic patent law is consistent. AI systems are not legal persons and cannot hold rights or obligations. Where AI tools are used as instruments in the inventive process, inventorship must be attributed to the natural person or persons who made the relevant creative and technical decisions leading to the invention.
In practice, the increasing use of generative AI tools in research and development has created new documentation challenges. Companies must ensure that inventorship records accurately reflect the human creative input and that the use of AI tools in the development process is documented so as not to jeopardize novelty through inadvertent prior disclosure.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
German copyright law is strongly shaped by the concept of the author as the creative force behind a work – a moral right that permeates the entire copyright system. This foundation does not permit the recognition of non-human systems as creators. Works generated solely by AI systems are therefore not amenable to copyright protection in Germany.
If there is sufficient human creative input in the act of creation – for example, where a person makes meaningful and creative choices in directing, curating, or transforming AI output – only those natural persons can be recognized as authors under German law. The threshold for what counts as a sufficient human creative contribution remains a live interpretive question, and one that courts have not yet definitively resolved in the context of generative AI.
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
AI in the workplace raises a convergence of legal obligations spanning data protection law, anti-discrimination law, labor law, and the EU AI Act. Several issues stand out as particularly significant in practice.
The use of AI in recruitment, performance assessment, or monitoring of employees processes personal data and is, therefore, subject to the GDPR. Purpose limitation, data minimization, and the prohibition on fully automated decision-making under Article 22 of the GDPR all apply. Where employee monitoring by AI involves biometric data – including facial recognition, voice analysis, or emotion recognition – it constitutes processing of a special category of data under Article 9 of the GDPR, requiring an explicit legal basis. The EU AI Act explicitly restricts the use of emotion recognition systems in workplace and educational settings. The AI Act’s June 2026 amendment postponed the application of full high-risk obligations for standalone AI systems in employment contexts to December 2027, providing additional time for compliance preparation, though governance structures should be put in place well before that deadline.
The co-determination rights of works councils under the Works Constitution Act (BetrVG) are a defining feature of AI governance in the German workplace. Works councils must typically be informed and, in many cases, must co-determine the introduction of technical systems capable of monitoring employee behavior or performance – a category that clearly covers AI-driven monitoring and assessment tools. Works councils may negotiate works agreements that impose additional restrictions or requirements on the deployment of such systems. The failure to involve works councils in AI deployment is a common and costly compliance gap.
The AGG applies where AI-assisted hiring or performance assessment produces discriminatory outcomes. As noted above, the burden of proof under section 22 of the AGG shifts to the employer once unequal treatment has been plausibly demonstrated, which creates meaningful exposure for organizations that cannot explain or audit their AI systems.
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
Germany has one of the most active data protection supervisory landscapes in the EU, and AI has been a recurring focus of supervisory attention. The central reference document for AI compliance in Germany is the DSK’s Guidance on Artificial Intelligence and Data Protection (Orientierungshilfe Künstliche Intelligenz und Datenschutz), which sets out the supervisory authorities’ expectations for the entire lifecycle of AI systems. The guidance draws on seven core principles: AI must not objectify human beings; it must be used only for constitutionally legitimate purposes; it must be transparent, comprehensible, and explainable; it must avoid discrimination; it must comply with data minimization; controllers must bear clear responsibility; and technical and organizational standards must be developed.
The DSK published further guidance on recommended technical and organizational measures for the development and operation of AI systems, which takes a lifecycle approach across four phases: design, development, deployment, and operation/monitoring. And it addressed a particularly contemporary challenge with guidance specifically on generative AI systems that use retrieval augmented generation (RAG) – systems where large language models are combined with controlled access to internal organizational data.
German DPAs have not reached a fully common position on all AI-related questions. The Hamburg DPA took the view that the mere storage of a large language model does not constitute processing of personal data within the meaning of Article 4(2) of the GDPR because no personal data are stored in the model weights, a position that diverges from the approaches taken by other DPAs. This interpretive divergence creates residual legal uncertainty for providers of AI models, particularly those operating across multiple German jurisdictions.
The key practical takeaways from supervisory guidance are: that the lawfulness of using personal data for AI training is not a binary question but depends on a careful lifecycle analysis; that legal bases must be specifically identified for each processing phase; that purpose limitation applies to training as well as deployment; and that data subjects’ rights under the GDPR must be operationally feasible throughout the system’s lifecycle.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
Data scraping for AI training intersects three distinct legal regimes in Germany: copyright law, data protection law, and competition law. The key copyright question is whether the text and data mining exception under sections 44b and 60d of the Copyright Act (UrhG) applies to the large-scale scraping of web content for training generative AI models. The legislative history of these provisions does not contemplate generative AI – the DSM Directive was adopted in 2019, before large language models had become commercially significant – and there is genuine uncertainty as to whether the exception was intended to cover this use case.
Recent German case law has begun to resolve some of this uncertainty, though not uniformly. In September 2024, the Regional Court of Hamburg held that the creation of an AI training dataset by scraping and downloading a photographer’s image was covered by the scientific research exception under section 60d of the Copyright Act. The Higher Regional Court of Hamburg upheld this outcome in December 2025, while adding the important clarification that natural-language prohibitions in website terms of use are insufficient to constitute an effective reservation under section 44b(3). For the commercial text and data mining exception under section 44b UrhG, an effective reservation of rights must be expressed in a machine-readable form. At the same time, the Regional Court of Munich I found in November 2025 that OpenAI’s training on copyrighted song lyrics was not covered by the exception and constituted infringement, with the court holding that model memorization and subsequent output reproduction engaged copyright exploitation rights.
From a data protection perspective, scraping personal data from publicly accessible websites does not render the data processing lawful merely because the data is publicly available. A valid legal basis under Article 6 GDPR is required, and the purpose limitation principle restricts the subsequent use of scraped personal data for purposes that are incompatible with the original purpose of publication. German data protection authorities have taken a strict approach to this question.
Competition law may also be relevant where scraping is combined with market-dominant platforms or where scraped data is used to create unfair competitive advantages. The German Federal Cartel Office and the European Commission have identified data access and control as key competitive dynamics in digital markets.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
The most significant development in this area is the ruling of the Higher Regional Court of Hamburg of December 2025, which held that natural-language usage restrictions in website terms – such as terms prohibiting crawling or automated access – are insufficient to constitute an effective rights reservation for the purposes of section 44b(3) of the Copyright Act. A machine-readable reservation is required to exclude the statutory text and data mining permission. This means that, for copyright purposes at least, a scraping prohibition buried in website terms will not override the statutory TDM exception unless it is also communicated in a machine-readable format compliant with the applicable standard.
For personal data, the position is different. A contractual term purporting to consent to scraping does not create a valid legal basis for GDPR purposes, and equally, a contractual prohibition does not substitute for a GDPR-compliant analysis. The obligation to have a valid legal basis for each processing purpose operates independently of any contractual arrangement.
In summary, the practical enforceability of website scraping prohibitions against AI developers in Germany is limited: for copyright purposes, only a machine-readable reservation is effective; for data protection purposes, the contractual position is irrelevant to the GDPR analysis.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
The Federal Network Agency (BNetzA) will be established as the central AI regulatory authority in Germany. It will be responsible for market surveillance, including oversight of prohibited practices and high-risk AI systems. The BNetzA will also serve as the market surveillance and complaints office for businesses. Authorities that are already responsible for market surveillance in fully harmonized areas of product regulation are to become the authorities responsible for market surveillance and notification under the AI Act as well. The regulatory landscape will be shaped by complex processes involving coordination between federal authorities and the data protection and other authorities of the Länder.
At EU level, the European AI Office, established within the European Commission, has direct supervisory and enforcement powers over general-purpose AI models and coordinates the implementation of the AI Act across Member States. German companies placing general-purpose AI models on the market are subject to the AI Office’s oversight as well as national supervision.
In addition to AI Act enforcement, several existing authorities exercise relevant supervisory powers. The Federal Office for Information Security (BSI) supervises cybersecurity obligations, publishes guidance on AI security risks, and receives incident reports under the NIS2 regime. The Federal Cartel Office (Bundeskartellamt) has authority over competition-related conduct involving AI, including under the special market-dominance tool in section 19a of the Act against Restraints of Competition (GWB). The German data protection authorities, both at federal level (the Federal Commissioner for Data Protection and Freedom of Information, BfDI) and at Länder level, have enforcement powers under the GDPR, including the power to impose fines of up to EUR 20 million or four per cent of global annual turnover, whichever is amount is higher.
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
AI adoption in Germany has accelerated significantly since 2023, driven by the availability of large language models and generative AI tools and by competitive pressure across industries. The OECD’s 2024 review of Germany’s AI ecosystem acknowledged a robust research landscape and strong public-private cooperation, while also noting structural challenges in scaling AI innovations and translating research into globally competitive products.
The sectors leading in AI adoption reflect Germany’s industrial structure. Manufacturing and automotive industries have been early and substantial adopters, applying AI to predictive maintenance, quality control, and autonomous vehicle development. Financial services use AI extensively for fraud detection, credit assessment, risk modelling, and regulatory compliance. Healthcare and life sciences have seen growing deployment of AI in diagnostic imaging, drug discovery, and personalized medicine; AI is no longer a future technology in medical devices but an integral component of many products on the market today. Logistics and supply chain management, particularly in the e-commerce and automotive supply chain sectors, rely heavily on AI-driven optimization. Defense and security is an increasingly prominent sector: Germany’s National Security and Defense Industry Strategy explicitly identifies technological sovereignty in critical IT, cybersecurity, and defense-relevant technologies as a strategic priority, and AI capabilities feature prominently in procurement and operational planning.
Public administration is a growing area of AI deployment. Federal and Länder governments have launched pilot projects for document analysis, workflow automation, and decision support in administrative and judicial contexts. However, the pace of adoption in the public sector remains slower than in the private sector, partly due to procurement rules, workforce concerns, and data governance requirements.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
AI adoption in the German legal sector is growing rapidly, though it remains uneven across firm sizes and practice areas. Large commercial law firms have invested in document review, contract analysis, due diligence, and legal research tools powered by AI. In-house legal teams in corporate environments, particularly in technology, financial services, and manufacturing, are among the most active adopters of AI-driven contract management and compliance monitoring tools. Smaller firms and individual practitioners are increasingly using general-purpose AI tools, though often without structured governance frameworks.
AI governance is itself a rapidly growing practice area. As companies across all industries are required to implement compliance structures for the EU AI Act – risk assessments, technical documentation, conformity obligations, and transparency disclosures – the demand for legal advice on AI regulatory matters has grown substantially. In practice, the most common questions currently brought to German technology lawyers concern governance models for enterprise AI adoption and AI developments, contractual allocation of risks between AI providers and customers, protection of IP and know-how and compliance assessments under the AI Act and GDPR.
The main regulatory concerns around AI in the legal sector include confidentiality and trade secret risks when client information is entered into third-party AI tools – particularly where providers reserve broad rights to reuse inputs for training – the risk that AI-generated legal analysis contains errors or hallucinations that could expose the advising lawyer to liability, and the absence of specific professional guidance from German bar associations on the ethical use of AI. Professional responsibility obligations require lawyers to maintain competence and diligence; it remains unclear how these obligations interact with reliance on AI tools, particularly where the reasoning behind an AI-generated output cannot be independently verified.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
Key Challenges
The first and perhaps most persistent challenge is regulatory fragmentation and complexity. Lawyers advising on AI must navigate the intersection of the EU AI Act, the GDPR, sector-specific product regulation, copyright law, product liability, anti-discrimination law, and competition law – a combination that no single regulatory instrument fully integrates. The evolving nature of the regulatory framework, including the June 2026 AI Act amendment, means that compliance positions that were accurate six months ago may already require revision.
Second, confidentiality risks associated with AI tools represent a serious concern. Information entered into AI systems may be stored, reused for model training, or exposed to third parties in ways that breach professional secrecy obligations and/or undermine trade secret protection. The increasing use of cloud-based AI services means that the security perimeter of a corporation or enterprise has effectively been extended to include the AI provider’s infrastructure.
Third, liability for AI-generated errors poses a growing risk. As businesses increasingly rely on AI tools for research, drafting, and analysis, the question of responsibility for AI-generated content that is incorrect, outdated, or hallucinated becomes more acute. Disclaimers will not substitute for competent review, and the pace of AI output generation may encourage overreliance and under-review.
Fourth, governance of AI adoption and AI developments within companies is itself a significant challenge. Effective AI governance must now cover the entire lifecycle of AI systems – from use case intake and risk assessment through validation, security testing, deployment, monitoring, and retirement. Many organizations are still operating with relatively narrow AI usage policies that address only what employees may do, not how AI initiatives are governed, how responsibility is allocated, or how compliance is maintained over time. Without a lifecycle-based operating model, the risk of shadow AI – teams developing or testing systems outside governed processes – is significant.
Fifth, contract law has not kept pace with the technical characteristics of AI systems. Standard contractual frameworks built around deterministic software – fixed acceptance criteria, objective quality standards, fault-based warranty and liability regimes – do not translate to probabilistic, self-learning AI systems. Lawyers drafting AI contracts must develop new approaches to performance standards, service level regimes, adaptive adjustment mechanisms, and lifecycle governance that function in a dynamic technical environment.
Key Opportunities
First, AI regulation has created an entirely new practice area of significant depth and commercial importance. Advising clients on AI Act compliance, data governance, regulatory risk assessment, and AI-related contract structuring requires a combination of technical understanding and legal expertise that well-positioned firms are developing into a competitive differentiator.
Second, AI tools offer genuine improvements in efficiency and quality for many categories of legal work. Document review, contract analysis, due diligence, legal research, and template drafting are all areas where AI can reduce time investment and surface relevant information that might otherwise be missed. Lawyers who develop the skill to direct and critically evaluate AI output will be able to serve clients more efficiently and at higher quality – a structural shift in the economics of legal practice.
Third, AI’s growing role in business decision-making creates demand for lawyers who understand how AI systems work and can advise on the legal implications of AI-driven operational decisions. In-house roles that combine legal and AI governance expertise are increasingly valued, and law firms that build genuine technical depth in AI will be better positioned to serve clients at the intersection of legal and operational risk.
Fourth, the growing body of AI-related litigation – across liability, copyright, data protection, and competition law – creates significant dispute resolution work. As German courts continue to develop case law on AI-generated content, platform operator liability, and copyright infringement by training, lawyers with expertise in the technical and legal dimensions of these disputes will be in high demand.
Fifth, AI regulation creates transactional opportunities. M&A transactions involving AI-driven businesses require due diligence on regulatory compliance, data sourcing, IP ownership, and liability exposure. Investors and acquirers of AI companies need lawyers who can assess whether a target’s AI stack is legally sound – a question that is becoming standard in technology transactions.
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
The next twelve months will be defined above all by the phased entry into application of the EU AI Act’s substantive obligations and by the settlement of national enforcement structures to give those obligations practical effect. The full obligations for high-risk standalone AI systems apply from December 2027, while the AI Act’s general-purpose AI model obligations and the transparency requirements of Article 50 are already in force or imminently so. Enforcement actions by German data protection authorities and, once designated, national market surveillance authorities are expected to increase, particularly in sectors where AI deployment is most advanced.
The implementation of the new EU Product Liability Directive by December 2026 will reshape the liability landscape for AI systems placed on the market. The extension of strict liability to standalone software and AI systems, and the new rules on liability for AI systems that learn and change behavior after deployment, will affect providers across all sectors and is expected to accelerate the development of specific AI liability insurance products.
In copyright, the appellate trajectory of the OpenAI/GEMA case before the Higher Regional Court of Munich will be closely watched, as it may establish or refine the rules on AI training data and the scope of the text and data mining exception under German law. Further litigation on copyright in AI-generated outputs is also anticipated.
Finally, the interplay between AI governance and contractual frameworks will become an increasingly active area of legal development. As AI systems move from pilot to production and from simple usage to internal development, the inadequacy of standard contractual frameworks will become more apparent. The development of AI-specific contract structures is a field in which German practitioners are active and where further standardization and precedent development is expected over the coming year.
Two sector-specific developments merit particular attention: In medical devices, the December 2027 deadline for embedded high-risk AI systems under the AI Act – combined with the December 2026 implementation deadline for the new Product Liability Directive – l means that MedTech companies face simultaneous compliance pressures across two demanding regulatory regimes with no sectoral relief from dual conformity assessment.
As AI capabilities become more deeply embedded in defense-critical systems, the legal framework governing procurement, data localization, and liability in this sector will require closer attention from advisers working at the intersection of technology law and national security.
Germany: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in Germany.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?