Search results for

Lawyers

45

Dr. Dorothee Altenburg represents clients in all aspects of intellectual property law. She is particularly experienced in the area of trademark law. Operating in Germany as well as internationally, Dr. Altenburg devises legal strategies to establish and defend trademarks, design rights, and patents. She represents clients before the relevant authorities in Germany, in the European Union, and in WIPO proceedings. She conducts trademark registrations worldwide. She has substantial experience in drafting licensing agreements. She is acquainted with the litigation issues that arise in the environs of intellectual property and (unfair) competition law. She represents clients before customs authorities counterfeiting cases. She also coordinates EU-wide customs seizure proceedings against counterfeit products.

Dr. Altenburg further represents publishers, media companies, and artists in matters to do with copyright, publishing law, and personality rights. 

Nikolaus Bertermann has been a lawyer for a Europe-wide leading internet service provider for ten years and can therefore rely on in-depth technical expertise, a sound knowledge of the IT industry, and many years of experience as a company lawyer.

He provides comprehensive advice on all forms of classic and agile software creation and IT project contracts, the use and adaptation of open source software, and cloud computing within and outside the EU.

Mr. Bertermann conducts data protection audits, advises companies on the legally compliant design of data processing procedures within and outside corporate structures, and accompanies clients in projects to implement the requirements of the EU General Data Protection Regulation. He commented on the central provisions of the GDPR for publishing house C.H.Beck.

Eva Bonacker advises German and international clients on diverse matters of competition, M&A, corporate and general commercial law, with a special focus on European and German antitrust and competition law.

Eva Bonacker has advised clients from various industries including media, IT and software, e-commerce, publishing, information and business intelligence, energy, climate technology, and consumer goods.

Dr. Mathias Pajunk advises on all issues of public commercial law. The main focus of his work lies on advising public authorities on the award of public contracts and service concessions. This includes the monitoring of awards at all stages, including the drafting of contracts. At the same time, Dr. Mathias Pajunk represents both public authorities and bidders in the context of review proceedings. His other fields of activity include dealing with complex issues in the areas of state aid and antitrust law.

Dr. Brock specializes in IP law (trademarks, patents, designs, copyright law, etc.), unfair competition law (including advertising law), IT law, data protection law as well as distribution and contract law.

He advises comprehensively on IP matters, including the filing of national and international intellectual property rights as well as licensing and enforcement in disputes in and out of court. He further advises on innovation and know-how protection (including trade secrets), on cross-border research and development projects, on employees’ inventions law, and on standard essential patents (SEP). Furthermore, his advice includes the development of brand-based labeling and quality seal systems.

While his client base covers a wide selection of industries (for instance health care & life sciences, information technology and consumer goods), he focuses on technology-driven and innovative companies, ranging from start-ups to mid-sized companies to globally operating corporations.

Dr. Oliver M. Bühr has been advising on IT matters for many years. This includes software, hardware, projects, and outsourcing. He frequently supports his clients in all matters relating to data protection, especially in the implementation of the GDPR. He also has extensive experience in e-business and advises companies on designing their offerings on the internet. Innovative topics such as cloud computing or the advising of FinTechs are also a key part of his work. Many of the projects on which he advises have an international dimension, and he works closely with lawyers from foreign legal systems.

As a notary, he works particularly in the areas of property law, corporate law, and inheritance law.

Markus von Fuchs advises in intellectual property law, in particular in competition, patent, and trademark law as well as on the protection of know-how. He advises companies on protecting and commercially exploiting intellectual property, for example through licensing, sales, R&D, and cooperation agreements. He also focuses on the judicial and extrajudicial defense of intellectual property rights in interim injunction and principal proceedings. He further advises on border seizing procedures, initiates and advises on criminal measures relating to product and brand piracy, and on the infringement of business and business secrets. Markus von Fuchs also advises many companies on developing and introducing new technologies and business models. He has particular expertise in the optical and medical technology sectors.

Christoph Haesner’s work comprises the entire range of media law, copyright law, and entertainment law. He advises clients in the fields of film and TV, and in sales and licensing on legal issues at all stages of development, production, distribution, and evaluation of audiovisual productions, both nationally and internationally.

His work focuses on all matters pertaining to movie financing, not only for purely national projects, but also for those with major international connections.

He also advises on transactions (M&A) in the media sector. Christoph Haesner regularly supports companies throughout the transaction phase and advises on all matters arising from M&A transactions, under corporate law, contract law, copyright law, and media law.

Dr. Johann Heyde provides comprehensive legal advisory throughout media and entertainment law, in which film and television compose a main focus of his practice. Mr. Heyde advises on all aspects of national and international film and TV productions from film financing and subsidization, right clearance particularly in terms of copyright and privacy law, as well as licensing and exploitation of such productions.

Moreover, Dr. Johann Heyde’s advisory work spans all levels of digital commerce and business with a particular emphasis on improving internet portals, online services and other digital media (including on- demand platforms) and counseling on all relevant legal issues in e-commerce, some of which include terms and conditions, consumer protection, advertising and competition law, licensing and the dissemination of all forms of content over the internet.

Dr. Johann Heyde’s expertise includes his command of music law and especially collecting societies law in particular with respect to digital media.

Dr. Magnus Hirsch advises both German and international clients on a wide variety of matters which fall within the area of trademarks, designs, copyrights, patents, and unfair competition – in both preventative and contentious situations.

He also has more than 25 years of intellectual property litigation experience, having worked on numerous litigation matters regarding all kinds of IP issues and has appeared in many Federal District Courts, as well as Courts of Appeal, throughout Germany, and has represented several clients in proceedings up to the Federal Court of Justice.

In particular, his specialization comprises portfolio management as well as enforcing clients’ rights against counterfeiters, parallel importers and domain name pirates, both through court proceedings, as well as international dispute systems. Mr. Hirsch also represents clients before the German Patent and Trademark Office and the European Union Intellectual Property Office (EUIPO) registering or opposing German national trademarks and Community Trade Marks, respectively. He also has significant experience in drafting IP-related agreements, such as trademark license agreements, priority agreements and agreements with publicity agencies.

A further focus lies in the field of trademark and competition infringements on the Internet, in particular in the conduct of litigation in and out of court, also in connection with Internet domains, as well as the litigation of patent infringements.

Dr. Magnus Hirsch spent several months practicing at the Hong Kong office of an international law firm where he focused on Asian IP law, especially the enforcement of intellectual property rights in and out of court and the prosecution of product piracy and trademark counterfeiting in Southeast Asia.

Dr. Oliver Hornung advises national and international IT service providers and users in the legal structuring and negotiation of IT, project, and outsourcing contracts, as well as in matters of copyright and licensing. He is also regularly involved in distressed projects (dispute management) and advises clients in conciliation and arbitration proceedings and, where necessary, in litigation.

The regulatory environment for the use of data and corresponding technologies is complex and new legal acts are constantly being added by the European Commission. In this dynamic environment, Dr. Oliver Hornung advises his clients on all legal issues, in particular with a focus on AI compliance, Data Act, NIS-2, cyber security, cloud computing and data law.

Another focus of his legal advice is data protection with a focus on digital health and the EU's Digital Decade. If necessary, Dr. Oliver Hornung and his team defend the rights of his clients before supervisory authorities or in court.

Finally, Dr. Oliver Hornung advises start-ups on all questions relating to IT law and data protection law. In addition to his extensive practical work, Dr. Oliver Hornung is also a frequently requested lecturer in IT law and data protection law.

Klaus Jankowski advises on complex investment projects and company settlements, with a focus on public building and planning law.

For several years, he has also been advising the public sector on legislative projects and sensitive infrastructure projects.

He plays a leading role in the international network of lawyers First Law International and has excellent contacts to law firms worldwide.

Dr. Bernd Joch advises on corporate restructuring in employment law and corporate law, conducts balancing of interests and social plan negotiations, and represents his clients in arbitration proceedings.

He has many years of experience in advising companies, executive board members, general managers, and employees, in particular also in the field of dismissal protection matters.

In the area of commercial law, he advises and represents companies, in particular, in the areas pertaining to agencies and representatives.

René M. Kieselmann specializes in EU public procurement law and associated legal fields. Among others he is a member of SKW Schwarz’s IT & Digital Business and Life Sciences & Health Practice Group and has wide-ranging technical expertise in various areas. In addition to IT law, he advises on state aid law, subsidy law/grant law, and on rescue services and civil protection, i.e. the prevention of health hazards. Jointly with his team he is designing complex public procurement projects. René Kieselmann ensures adequate communication between bidders and clients, constructively conducting negotiations. SKW Schwarz advises on major bidding projects, including in the housing, in healthcare/pharmaceuticals and IT/banking sectors. He is also familiar with the structures of rescue services, civil protection, and disaster control as well as the regulatory context (SGB). Here he constructively designs award procedures on a long-term basis (“planning model”). In this connection, he also deals with issues of medical law ranging from emergency physicians to paramedics. While he is not litigating in court or before the Public Procurement Tribunal frequently, he has nevertheless gained considerable forensic experience since 2009, including at the Court of Justice of the European Union.

Norbert Klingner specializes in national and international movie/TV and advertising film production, financing, insurance, and distribution. He represents well-known producers, distributors, global distributors, and movie financing entities. His expertise ranges from negotiating and drafting contracts from the beginning of the material development to all matters related to production and financing up to the strategically correct exploitation and licensing. A selection of the film productions in which Mr. Klingner was involved can be found on the Internet Movie Database IMDb.

Margret Knitter advises her clients in all matters of intellectual property and competition law. This includes not only strategic advice, but also legal disputes. Her practice focuses on the development and defense of trademark and design portfolios, border seizure proceedings and advice on developing marketing campaigns. She advises on labelling obligations, packaging design, marketing strategies and regulatory questions, in particular for cosmetics, detergents, toys, foodstuffs and Cannabis. She represents her clients vis-à-vis authorities, courts and the public prosecutor's office.

In the field of media and entertainment, she mainly advises on questions of advertising law, in particular product placement, branded entertainment and influencer marketing. She is a member of the board of the Branded Content Marketing Association (BCMA) for the DACH region and member of the INTA Non-Traditional Marks Committee.

Dr. Olaf Kreißl is a notary and lawyer specialising in real estate, corporate and inheritance law. He provides support in real estate transactions, property development projects, land and residential property purchase agreements, corporate transactions (M&A) and all corporate law matters (corporate housekeeping, capital increases, conversion and restructuring measures, etc.). In the area of asset management and succession planning or anticipated succession, he drafts and certifies gifts, wills, marriage contracts, divorce agreements, and powers of attorney for precautionary and special purposes.

He also has many years of legal expertise in the field of real estate management and private construction and architectural law.  The focus here is also on advising on legal issues in connection with the management of real estate (commercial leasing, asset management, etc.), the realisation of construction projects and the drafting and negotiation of the corresponding real estate-specific contracts. 

Stefan Kridlo regularly advises national and international companies on all material issues of business law, commercial law, and corporate law, in particular also on corporate acquisitions.

The main focus of his many years of work is the support of real estate investors pertaining to real estate transactions and real estate portfolios, their structuring and administration. Stefan Kridlo worked as a notary until April 2025 in the areas of corporate law, real estate law and inheritance law. He also works as an executor.

Sabine Kröger is a Certified Expert for Commercial and Corporate Law as well as for Banking and Capital Markets Law and advises and represents national and international companies, executives and shareholders comprehensively in the field of corporate law and banking law.

As an experienced litigator, she also comprehensively represents her clients in court (corporate litigation / banking litigation).

Ms. Kröger's activities focus in particular on:

  • advising and representing mid-sized enterprises (SMEs) or their managing directors or shareholders in shareholder disputes and internal company disputes;
  • the assumption of committee representation for shareholders;
  • advising and representing financial investors and credit institutions in the field of credit law and collateral security law and in defending claims of clients/investors, including the representation in mass claim proceedings.

Eberhard Kromer’s traditional focus in media law is entertainment and music. He counsels artists, publishers, labels, internet service providers, managements, as well as tour promoters. He has been active and well-versed in digital commerce issues since the inception of the internet. Eberhard’s practice is constantly affected by rapidly changing e-commerce models, social media platforms and ongoing digitization (Web 4.0, Internet of Things).

Dr. Kromer’s many years of experience as General Counsel and VP Business Affairs for a global media corporation give him the insight to recognize a corporation’s operational strengths and weaknesses. This enables him to find the best solution together with and for the client.

Franziska Ladiges advises clients on all questions of IT and data protection law. Thanks to secondments and many years of experience, she has in-depth knowledge of data protection. In this area, she supports companies (from small businesses to listed companies) from various industries with the implementation of data protection compliance. In addition, she advises on various individual data protection issues, including order processing, data subject rights and international data transfer. Finally, she regularly carries out data protection quick checks for companies on site.

In addition, Franziska Ladiges has experience in drafting contracts regulating the creation, use or transfer of software. She also drafts and reviews general terms and conditions (both purchasing and sales and internet platforms) and advises on the development of online shops and internet platforms. She often represents her clients before state courts in contract disputes or data protection matters.

In the area of private clients, Christoph Meyer has special expertise in establishing and managing family foundations, the creation of succession rules for medium-sized companies and high-net-worth individuals, as well as in all matters pertaining to family law, with a focus on more complex asset situations. The drafting of wills, powers of attorney, and marriage contracts also play an important role, with a considerable proportion of cases having international relevance. Should amicable solutions not be achievable, Mr. Meyer advises the clients, with careful strategic and tactical planning, but also with the required readiness to resolve disputes, through possible legal proceedings before civil and financial courts.

Dr. Ulrich Muth advises companies, in particular banks and financial service providers.

In particular, he specializes in consulting for creditors of loan claims secured by real estate, in the monitoring of credit and reorganization negotiations, in the prevention of damage claims on account of alleged breaches of the duty of disclosure and consultation as well as in the enforcement of creditor interests in the event of the insolvency of the debtor. Based on many years of experience of proceedings in the fields of banking, commercial and company law, as well as in disputes involving competition law, Dr. Muth works together with the clients to develop economic solutions for avoiding legal disputes as well as efficient trial strategies.

Dr. Matthias Nordmann advises international groups, mid cap companies, investors and entrepreneurs on company, commercial and corporate law in particular on structuring and mergers & acquisitions. He has a special focus on transactions in IP/IT driven industries as well as real estate.

Dr. Orthwein was admitted to the bar in 2003 and became a partner at SKW Schwarz in 2011. He received his Master of Laws (LL.M.) in American Law from Boston University (USA) in 2000 and his doctorate from the University Muenster in 2003 with a topic in telecommunications law.

He advises his clients in all areas of IT law, in particular cloud and software contract law using new agile software developing and contract methods, the commercial use of data and artificial intelligence (AI) as well as digital transformation projects. Together with his clients, he develops and brings to life new digital platforms and business models. He is an experienced expert in national and international data protection law issues in particular with regard to the use of cloud services.

The Lexology Index Germany 2025 lists him as a “world's leading practitioner” in the data category. In 2025, Handelsblatt / Best Lawyers again recommends him as a lawyer in the categories “IT law” and “data protection law.” He is once again listed in the JUVE Handbook 2025 as a “frequently recommended lawyer” for IT and data protection law.


Dr. Orthwein is a lecturer for IT and data protection law in applied AI at the Technical University of Rosenheim.

Dr. Orthwein is member of the German Society for Law and Informatics, the International Association of Privacy Professionals, the German Outsourcing Association and the German-American Lawyers Association. He is Senior Vice Chairman of the Technology Law Committee of the International Bar Association.

Dr. Andreas Peschel-Mehner has provided legal counsel to all forms of digital business since the inception of the world wide web. His advisory spans start-ups, multi-channel offerings and international internet companies and focuses on all applicable legal fields with a particular emphasis on data protection and usage, terms and conditions, consumer protection, compliance, advertising, gaming and competition law, among numerous others. Dr. Andreas Peschel-Mehner also commands broad expertise in media and entertainment law, in particular issues touching on the film and television industry and those related to media production finance and the global exploitation thereof, with digital media advisory on changes to utilization models, revenue streams and video on demand platforms composing a significant part of his counsel. 

An excerpt of the projects Dr. Andreas Peschel-Mehner has accompanied can be found on the Internet Movie Database IMDb. His advisory expertise is augmented by decades of involvement with and counsel of national and international computer game publishers and studios. Finally, developments and use of KI technologies across all his expert areas has become a strategic element of his practice.

Ulrich Reber is a certified expert in international business law. Mr. Reber advises and represents German and foreign companies in civil and commercial matters with an emphasis on corporate litigation, for example in commercial and corporate disputes before civil courts and arbitration tribunals. He commands particular expertise in cross-border debt enforcement cases in and out of court. His clients include leading European and non-European companies requiring legal assistance in Germany, to whom he provides corporate legal advice with a special focus on insolvency law. Numerous clients come from the media, entertainment and IT sectors.

Legal expertise – digitally sophisticated

Stefan Schicker has been advising clients at the intersection of law, technology, and innovation for over 20 years. As an experienced and award-winning lawyer specializing in IT and IP law, he assists national and international companies in the legally compliant design of digital business models – from the design of complex internet platforms to the protection of intellectual property.

One of Stefan Schicker's special areas of expertise is the legal structuring of corporate influencer initiatives: with specially developed workshops, he supports companies in setting up corporate LinkedIn communication in a legally compliant and effective manner – in accordance with copyright, personality rights, competition law, etc. – More information.
 

Legal tech & law firm development – with leadership experience

In parallel to his legal practice, Stefan Schicker is one of the most prominent legal tech experts in the German-speaking world. As former COO and CEO of SKW Schwarz, he played a key role in shaping the digital transformation of the law firm – from strategy to operational implementation.

Today, he supports law firms and legal departments in establishing and expanding modern structures:

  • Development and introduction of AI-supported tools
  • Establishing internal teams of experts and training concepts
  • Change processes for the sustainable anchoring of digital working methods
  • Organization of law firms as companies

Stefan Schicker brings a unique combination of legal depth, technological experience, and operational law firm management to the table – recognized, among other things, as one of the “Top 3 Legal Leaders of the Year” (Best of Legal Awards).
 


For companies and law firms that don't want to wait for the future

Whether companies with digital business models or law firms undergoing change: Stefan Schicker combines legal certainty with entrepreneurial foresight – and makes complex transformations understandable, feasible, and effective – More information.

Dr. Tatjana Schroeder has extensive experience in stock corporation law and also accompanies the development of this very specific legal field through regular publications. Stock corporation law also always depends on trends in the capital market and is subject to continuous change.

Mathias Schwarz advises on movie and TV productions, copyright and personality rights, licensing, and media financing. His clients are financial institutions, private investors, movie and TV producers, as well as broadcasting and publishing companies. He also represents a number of renowned individuals in the German media industry. In addition, he has been advising a number of family offices and private clients for a long time.

Marketing Manager
HR assistance
Head of Finance
Head of IT
Head of Marketing & Communication
Head of Business Development
Head of HR
HR Manager
Management Accounting
Senior Legal Tech Advisor
Legal Tech & Innovation Manager
Business Development and Marketing Manager

News

30

How the Digital Interstate Media Treaty regulates media, platforms and AI

With the Digital Interstate Media Treaty (Digitale Medien-Staatsvertrag), the German states intend to adapt the Interstate Media Treaty (Medienstaatsvertrag, MStV) to new European requirements for digital media, political advertising and artificial intelligence. The draft of the first part (Ninth Interstate Media Amendment Treaty, version of 10 June 2026) mainly affects media companies, online platforms, providers of journalistic content and the state media authorities (Landesmedienanstalten) as supervisory authorities. The heads of government of the states approved the draft on 25 June 2026 and intend to sign it by January 2027 at the latest. It is scheduled to enter into force on 1 August 2027; if not all instruments of ratification have been deposited by 31 July 2027, it will become void.

The Interstate Media Treaty primarily contains the provisions required to give effect to the European Media Freedom Act (EMFA), the Regulation on the transparency and targeting of political advertising and the AI Act. The Regulations are, in principle, directly applicable; the Interstate Media Treaty mainly determines who monitors compliance with them. For companies, this means: new transparency, cooperation and compliance obligations meet extended supervisory powers of the state media authorities. For the first time, the draft also brings the press within the scope of the Interstate Media Treaty and defines what is to be regarded as a print product (Druckerzeugnis) and as a periodical print product (periodisches Druckerzeugnis) (Section 1(1) and (2), Section 2(2) nos. 32 and 33 MStV-E; MStV-E refers to the Interstate Media Treaty as amended by the draft).

 

New competences regarding AI

The state media authorities are given an express role as market surveillance authorities for AI applications in the media sector.

This competence builds on the federal AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG), which entered into force on 29 July 2026. Under Section 2(1) KI-MIG, the Federal Network Agency (Bundesnetzagentur) is the market surveillance authority for the AI Act unless the Act provides otherwise. Section 2(8) KI-MIG provides for an exception for media service providers within the meaning of Art. 2(2) EMFA that provide, take into service or use AI systems in operating, offering, distributing and making available media services for journalistic or advertising purposes. For these cases, the federal act leaves market surveillance to the authorities competent under the law of the states. In this area, the Federal Network Agency merely receives complaints and forwards them to the competent authority (Section 8 KI-MIG). The new Section 111(5) MStV-E builds on Section 2(8) KI-MIG and designates the state media authority competent under Section 106 MStV as the market surveillance authority.

The state media authorities are therefore competent only where two conditions are met. The first concerns the provider: only media service providers within the meaning of the EMFA are covered, i.e. providers whose professional activity is to provide a media service, who have editorial responsibility for the choice of the content and who determine the manner in which it is organised. These include private television and radio broadcasters, providers of on-demand services, press publishers, journalistic online services and the public service broadcasters. Online platforms are covered only where, exceptionally, they themselves have editorial responsibility for the choice of their content. Search engines do not fall within the EMFA definition, and providers of AI services such as chatbots are, as a rule, not media service providers because they lack editorial responsibility. For them, the Federal Network Agency remains the market surveillance authority; for general-purpose AI models, it is the European Commission’s AI Office. The second condition concerns the purpose: the AI system must be used for journalistic or advertising purposes. If a publisher uses AI e.g. in recruitment or accounting, the Federal Network Agency remains competent. Depending on the specific use cases, the same media company may therefore be subject to two supervisory authorities.

Section 111(5) MStV-E does not limit supervision to individual provisions of the AI Act. The state media authorities monitor all obligations incumbent on the media service provider as provider or deployer of an AI system; an earlier draft had limited their competence to the enforcement of Art. 50 AI Act. In practice, supervision will mainly concern the transparency obligations under Art. 50 AI Act. Anyone deploying AI to generate or manipulate image, audio or video content constituting a deep fake must disclose this; where the content forms part of an evidently artistic, satirical or fictional work, disclosure in an appropriate manner that does not hamper the display or enjoyment of the work is sufficient (Art. 50(4), first subparagraph, AI Act). The scope of the term “deep fake” is disputed. On 5 June 2026, the Broadcasting Commission of the states (Rundfunkkommission) criticised the broad interpretation in the European Commission’s draft guidelines on Art. 50 AI Act, arguing that press, audio and video content published under editorial responsibility would otherwise be subject to disproportionate labelling obligations. AI-generated text published with the purpose of informing the public on matters of public interest must also be disclosed. This obligation does not apply where the text has undergone a process of human review or editorial control and a person or company holds editorial responsibility for their publication (Art. 50(4), second subparagraph, AI Act). As a rule, the disclosure obligation therefore does not apply to texts published under editorial responsibility; the AI Act provides for no comparable exception for image, audio and video content. Where a media house operates its own AI applications, such as a chatbot on its website, the provider obligations under Art. 50(1) and (2) AI Act apply in addition: human beings must be informed that they are interacting with an AI system, and synthetic content must be marked in a machine-readable format.

Fines for infringements of the AI Act are imposed by the respective market surveillance authority (Section 17(1) KI-MIG), which will in future be the state media authority in the media sector. For infringements of Art. 50 AI Act, Art. 99(4) AI Act provides for administrative fines of up to EUR 15 million or up to 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher. The state media authority may initiate proceedings against public broadcasters and against providers of periodical print products only after consulting the competent supervisory body or the German Press Council (Deutscher Presserat), respectively. Their opinion is binding, provided that the limits of the margin of appreciation have been observed (Section 111(6) MStV-E). For cooperation with the Federal Network Agency, the Digital Services Coordinator and the European Commission, the state media authorities appoint a joint representative.

The period until the Interstate Media Treaty enters into force remains unresolved. The transparency obligations under Art. 50 AI Act have applied since 2 August 2026. Since then, Section 2(8) KI-MIG has assigned market surveillance in the media sector to the authorities competent under the law of the states, but does not itself designate any authority; the Interstate Media Treaty is to designate the state media authorities only with effect from 1 August 2027. Supervision under the Interstate Media Treaty continues irrespective of this: on 14 July 2026, the Commission on Licensing and Supervision (ZAK) for the first time issued decisions against AI services of Google and Perplexity. However, the Interstate Media Treaty does not confer the powers of a market surveillance authority under the AI Act, since Section 109 MStV requires an infringement of the Interstate Media Treaty itself. Neither the KI-MIG nor the Interstate Media Treaty specifies which authority may pursue infringements of Art. 50 AI Act by media service providers until August 2027.

 

Competences and new sanctions under the EMFA

To enforce the European Media Freedom Act, the draft extends the catalogue of administrative offences. Infringements of certain obligations, for example relating to functionalities of online platforms, transparency information, dialogue procedures with media service providers or the visibility of media offerings on user interfaces, may be prosecuted as administrative offences (Section 115(1a) MStV-E). The fine may amount to up to EUR 1.5 million (Section 115(2) MStV-E); the limitation period for prosecution will in future expire only after 24 months instead of six months (Section 115(5) MStV-E).

These obligations include, for example, Art. 18 EMFA, which requires providers of very large online platforms such as Facebook, Instagram, TikTok and YouTube to provide media service providers that have declared themselves as such to the platform with a statement of reasons before suspending the provision of their services in relation to that content or restricting its visibility because the content is incompatible with the platform’s terms and conditions, to give them the opportunity to reply, and to process and decide upon their complaints with priority. In addition, the state media authorities will also monitor compliance with Art. 20 EMFA, which, from 8 May 2027, requires manufacturers, developers and importers of devices and user interfaces controlling or managing access to and use of media services to enable users to change the settings, including the default settings, freely and easily, and to ensure that the visual identity of media service providers is clearly visible.

Art. 24 EMFA applies where a service operates an audience measurement system, for example where data on usage, reach, views, viewing time, interaction or target groups are collected and processed for decisions on advertising, pricing, purchases and sales, planning or distribution. Art. 24 EMFA requires audience measurement methodologies that are transparent, impartial, inclusive, proportionate, non-discriminatory, comparable and verifiable. Providers of proprietary audience measurement systems must, in addition, disclose their methodology, have it audited annually by an independent body and, upon request, provide media service providers with the audience measurement data relating to their offering, including non-aggregated data.

Another focus of the new Digital Interstate Media Treaty is transparency of ownership and shareholding structures in the media sector. The Commission on Concentration in the Media (KEK) is to maintain a publicly accessible and regularly updated database (Section 60(8) MStV-E). It is to contain, in particular, information on the owners and shareholdings of relevant media companies. This is intended to make it easier to understand who is behind a media offering and which economic interconnections exist. 

 

Political advertising under supervision

The draft allocates competences for the new EU Regulation on the transparency and targeting of political advertising. In future, the state media authorities are to monitor the obligations under Arts. 11 and 12 of the Regulation in respect of telemedia providers, and the obligations under Arts. 5, 7 to 17 and 21 in respect of media service providers and of telemedia providers that are not intermediary services within the meaning of the Digital Services Act (Section 111(4) MStV-E). This covers, in particular, requirements relating to the labelling, transparency and delivery of political advertising. Infringements are to be sanctioned under the federal Political Advertising Transparency Act (Politische-Werbung-Transparenz-Gesetz), which is still in the parliamentary process (Section 115(1b) MStV-E). 

 

AI-supported media supervision

Of particular practical relevance is the newly proposed express legal basis for the use of technical means in media supervision (Section 109a MStV-E). In future, the state media authorities may use automated systems that check text, image, audio and video content for possible infringements. This may also include content that is not freely accessible. The use of such systems is intended, among other things, to detect infringements of media law and youth protection in the media. 

At the same time, the draft contains safeguards: a possible infringement detected automatically must be reviewed by a human being without undue delay. If the suspicion is not confirmed, the personal data processed must be deleted; if no review takes place, they must be deleted after 30 days at the latest. Data required for supervisory proceedings after a suspicion has been confirmed are subject to strict purpose limitation and must be deleted after six months at the latest, unless supervisory proceedings are pending by then. In supervisory proceedings, the provider concerned must be informed that technical means were used. 

Online platforms may also be required to provide the state media authorities with suitable technical interfaces, insofar as this is technically and economically reasonable. The details are to be specified by the state media authorities in joint statutes; the main results of the use of technical means are to be reported annually. 

 

Competences at a glance

Area of regulationState media authoritiesFederal Network Agency and other bodies
AI Act: media service providers using AI for journalistic or advertising purposes

Market surveillance and fines once the Interstate Media Treaty enters into force (Section 111(5) MStV-E, Sections 2(8) and 17(1) KI-MIG)

 

Federal Network Agency only as complaints body (Section 8 KI-MIG)
AI Act: all other uses of AI, including in media houses (e.g. HR, accounting)

Federal Network Agency (Section 2(1) KI-MIG); sectoral authorities such as the Federal Financial Supervisory Authority (BaFin)

 

General-purpose AI models

 

AI Office of the European Commission

EMFA: Art. 18 (very large online platforms), Art. 20 (user interfaces), Art. 24 (audience measurement)

 

Supervision and fines (Section 115(1a) MStV-E)
Political advertising (Regulation (EU) 2024/900)Arts. 11 and 12 for telemedia; Arts. 5, 7 to 17 and 21 for media service providers and for telemedia that are not intermediary services (Section 111(4) MStV-E)

Federal authorities under the Political Advertising Transparency Act, in particular for intermediary services (legislative procedure ongoing)

 

Interstate Media Treaty, including in respect of AI search and chatbotsSupervision under Sections 104 et seq. MStV (law already in force)

 

What the draft means for media services

Overall, the draft extends media regulation further into the digital space. Media houses, platform operators and advertising marketers have to prepare for new transparency, organisational and documentation obligations for their services, advertising processes and AI applications. In parallel, the states are deliberating on a second part of the Interstate Media Treaty. According to press reports, it is intended, among other things, to make providers of AI information systems responsible for the content they generate; no consultation draft has been published so far. It also remains unclear how such responsibility relates to the liability rules of the Digital Services Act where AI answers are integrated into search engines and platforms.

09/22/2026, Moritz Mehner, Dr. Anna Kellner

EmpCo: Special rule planned in Germany for certain existing stock – what companies need to know now

Just days before the new EmpCo rules take effect, an important amendment to the German Act Against Unfair Competition (UWG) is taking shape. A special rule is planned for certain goods that were placed on the market before 27 September 2026. However, the proposed amendment would not introduce a general sell-through or grace period. For companies, the key priorities now are to document, prioritise and prepare for potential disputes.

On 27 September 2026, the new rules implementing the Empowering Consumers Directive (EmpCo) will take effect under the German Act Against Unfair Competition (UWG). From that date, environmental and sustainability communications will have to comply with stricter requirements.

One question is particularly pressing for companies: What happens to goods that are already on the market where the packaging contains environmental or sustainability claims that may no longer comply with the new requirements?

So far, the UWG does not provide for a general transition, grace or sell-through period for such goods. Just days before the deadline, however, an important amendment is now taking shape.

Proposed Section 15b UWG: proportionality test for claims for injunctive relief

According to a draft legislative resolution currently available, a new Section 15b UWG is to be introduced into German law.

Under the proposed provision, claims for injunctive relief based on certain EmpCo infringements relating to goods placed on the market before 27 September 2026 would have to be asserted in good faith and in accordance with the principle of proportionality.

As part of a comprehensive balancing of interests, four factors in particular would have to be taken into account:

  1. the seriousness of the infringement
  2. the efforts made by the company to remedy the infringement
  3. the costs associated with remedying the infringement; and 
  4. the environmental impact associated with remedying the infringement

The German Bundestag is expected to vote on the Act to Modernise Design Law on 24 September 2026, in the context of which the amendment to the UWG is, according to the information currently available, expected to be introduced. The proposed new provision has not yet been adopted.

No general sell-through or grace period

For companies, it is important to understand what the proposed rule would not do: based on the wording currently available, it would not introduce a general transition, grace or sell-through period.

Section 15b UWG-E would not automatically make an EmpCo infringement lawful. Instead, the provision is intended to make the enforcement of claims for injunctive relief in relation to certain goods already placed on the market subject to a proportionality test.

In a specific dispute, it could therefore be relevant, for example, whether a contested claim can be corrected by applying stickers or relabelling, what costs this would entail, or whether an immediate stop to distribution would result in the destruction of significant quantities of goods and the associated environmental impact.

Depending on the individual case, this balancing of interests may affect the nature and scope of injunctive relief. How the provision will be applied in practice, however, is likely to become clear only over time and, potentially, through case law.

Key distinction: “placed on the market” does not mean “produced”

One detail of the proposed wording is particularly important.

The special rule would not apply across the board to all goods produced before the deadline. Instead, it expressly refers to goods that were already placed on the market before 27 September 2026.

Companies holding significant quantities of goods or packaging should therefore carefully assess which inventory may fall within the scope of the proposed provision.

In particular, companies should now ensure that they can document when the relevant goods were placed on the market.

What companies should document now

The proposed rule makes documentation even more important. The information companies record today may later prove crucial when assessing whether injunctive relief is proportionate.

Companies should document in particular:

  • Which goods are affected? Which products or packaging contain potentially problematic environmental or sustainability claims? 
  • When were they placed on the market? Delivery records, inventory management data and other relevant evidence should be secured without delay. 
  • What measures have already been taken? For example, changes to future packaging, relabelling, stickers or information provided to retailers and other distribution partners. 
  • What further adjustments are possible? And what organisational and economic effort would they require? 
  • What costs would arise? For example, from relabelling, product recalls, changes to production or, where applicable, destruction of goods.  
  • What would the environmental impact be? This may be particularly relevant where significant quantities of goods or packaging would otherwise have to be destroyed. 

The latter four aspects in particular directly reflect the criteria that, according to the draft currently available, are to be considered as part of the proportionality assessment.

No extension for websites, online shops or social media

The proposed special rule should not be understood as a general extension of the EmpCo implementation deadline.

Based on the wording currently available, Section 15b UWG-E expressly refers to goods placed on the market before the deadline. Other forms of environmental and sustainability communication would not generally benefit from the proposed rule.

Companies should therefore continue to review and, where necessary, adapt websites, online shops, social media communications, digital campaigns and other communications that can be changed at short notice by 27 September.

EmpCo remains a litigation issue

The proposed amendment does not eliminate the risk of legal disputes.

Competitors, associations and qualified entities can take action against unlawful environmental and sustainability communications. The new provision would instead add another question to potential disputes: Is the claim for injunctive relief sought proportionate in the circumstances of the individual case?

In addition to the legal assessment of the claim itself, it may therefore become crucial how well a company has documented its existing inventory, the remedial measures already taken and the associated costs and environmental impact.

Companies should use the remaining days to focus on two areas:

1. Compliance:
Prioritise communications that can still be changed, review claims and secure the necessary supporting evidence.

2. Litigation readiness:
Document affected inventory and when it was placed on the market, assess potential remedial measures and record their economic and environmental impact.

What happens next?

The German Bundestag is expected to vote on the Act to Modernise Design Law on 24 September 2026. It remains to be seen whether the proposed Section 15b UWG will be adopted and, if so, in what final form.

For companies, the message is clear: Monitor developments – but do not wait for them.

The EmpCo deadline remains 27 September 2026. The proposed special rule could provide new arguments in the defence against claims for injunctive relief in relation to certain goods already placed on the market. However, it does not replace the need to review existing claims or to prepare for potential legal disputes.

Prioritise claims. Secure evidence. Document existing stock. Prepare for potential disputes.

EmpCo Compliance & Litigation

SKW Schwarz supports companies in implementing the new EmpCo requirements – from our EmpCo Quick Check and the legal review of environmental and sustainability claims to dealing with packaging and existing stock, as well as defending against cease-and-desist demands, claims for injunctive relief and regulatory fine proceedings.

Find out more about our EmpCo Compliance & Litigation services Click here

 

09/22/2026, Dr. Daniel Kendziur

KI-Flash: Advertising Law and Data Protection as Ads Launch in ChatGPT

Since August 24, 2026, German ChatGPT users have also been seeing ads.

OpenAI has opened the advertising channel for 31 European markets. For users on the free Free and Go plans, ChatGPT’s functions are now available only with ads, while the Plus, Pro, Business, Enterprise and Edu plans remain ad-free according to the provider’s announcement of 18 August 2026. Ads are also shown only to logged-in users who have reached the age of majority.

One week later, on 31 August 2026, OpenAI opened self-service access through the Ads Manager for the same markets in a beta version. Advertisers based in Germany have since been able to book ads without an agency or technology partner. Booking through the provider’s ads solutions team and through agency and technology partners remains available alongside this.

Ad-funded generative AI is therefore no longer an announced plan in the German market but live operation. This article sets out the standards of review under advertising and data protection law. It is addressed to companies that advertise in this environment or deploy AI assistants in their own operations; the provider’s own obligations are described only to the extent that they matter from that perspective. No statements by the competent authorities on this advertising model are available so far. 

This article opens a three-part series on current developments around AI assistants. The second part deals with the designation of ChatGPT as a very large online search engine under the Digital Services Act and the obligations attached to it. The third part asks to what extent advertisers and agencies are responsible for the content of ads placed in AI assistants and liable for the statements they make. The question of when a provider must have AI answers attributed to it as its own content was already covered in our KI-Flash of 2 July 2026.

 

No personalised advertising in the EEA so far

For ads on online platforms, a distinction is drawn between personalised and non-personalised advertising. The legal requirements for the two differ considerably. 

In the first phase, currently implemented in the European Economic Area, ads are selected without personalisation in the sense of profiling. What is used is the topic of the ongoing conversation together with limited contextual information such as approximate location, language, time of day and device type. Earlier chats and stored information are expressly excluded according to the provider. Advertisers receive aggregated performance data only, and no conversation content, no real names and no precise location data.

Personalised advertising requires separate consent. Only then do chat history, stored information and a user’s behaviour in response to earlier ads feed into the selection. Users’ consent is required for this, as OpenAI also expressly describes in the version of its European privacy policy of 2 June 2026. This personalised advertising option has not yet been activated in the EEA.

One point that has largely gone unnoticed deserves attention here: behaviour in response to earlier ads can only feed into the selection if it has been collected beforehand, and, at least according to the provider, that does not happen in the first phase. The change therefore does not consist solely in evaluating existing data but first of all in building up a new set of data. Consent would have to cover that step as well.

 

How must advertising in an AI assistant be labelled?

The provider describes the ads as clearly labelled and visually separated from the answer. Under advertising law, the question is usually discussed under Section 5a(4) UWG. No. 11 of the Annex to Section 3(3) UWG may also apply, which covers the use of editorial content financed by a trader and disguised as information. That provision presupposes, however, that editorial content exists at all, and whether an AI-generated answer qualifies is an open question. For comparison portals and search engines, editorial content is in part affirmed even though there is no editorial team in the traditional sense. What speaks against that classification is precisely the position taken by the ZAK, the joint commission of the German state media authorities, according to which AI answers are the provider’s own content and therefore do not appear as neutral reporting. Added to this are Section 6(1) DDG for commercial communication in digital services and, where the service qualifies as a media intermediary or a media-like offering, Section 22 MStV. Classification as a media intermediary depends on whether the service aggregates third-party content, selects it and determines how easily it can be found. That is exactly what the ZAK relied on in relation to source citations and link lists. A service that generates only its own answers does not meet that test.

The structural risk, however, lies not in the design of the ad block but in the selection logic. An ad selected on the basis of the topic of the ongoing conversation appears at a moment when the user has just articulated a specific concern. In functional terms it works like native advertising, even where it is presented as “formally separated”. Whether a visual separation is enough to address this problem of contextual proximity is a question of the specific implementation. 

 

Are AI answers the provider’s own content?

Against the labelling obligations under Section 22 MStV and Section 6 DDG it could be argued that a chat interface has no editorial part from which advertising would have to be distinguished in the first place. On the line that has emerged so far, that defence does not hold: in its judgment of 28 May 2026 (26 O 869/26), the Regional Court of Munich I treated a search engine’s “AI Overview” function as the provider’s own substantive statement and found that the provider had adopted the content as its own (paras. 33 f.). Three aspects were decisive: the function produces a self-contained running text that summarises, structures and evaluates search results; it forms statements that are not contained in the sources relied on; and, from the perspective of a reasonably informed average user, it appears as an answer for which the provider is responsible rather than as a neutral list of results. On 14 July 2026, in proceedings of the Hamburg/Schleswig-Holstein and Berlin-Brandenburg state media authorities, the ZAK issued its first orders against AI services operated by Google and Perplexity, holding that AI answers are the providers’ own content and that the liability exemption under the DSA does not apply. Neither decision is final and binding yet, and appeals have been announced. For Section 5a(4) UWG this preliminary question is irrelevant. For No. 11 of the Annex it matters, because editorial content is a constituent element there.

 

The promise about the answers

OpenAI promotes the principle that advertising does not influence the answers. Beyond being a product description, this also appears to be a statement about a material characteristic of the service within the meaning of Section 5 UWG. If the actual design departs from it – for instance through influence on ordering, product mentions or shopping integration – a misleading commercial practice would come into consideration. In practice the question of evidence arises immediately: how does a competitor prove a distortion in the model’s behaviour? How the model works lies solely within the provider’s sphere, which speaks in favour of a secondary burden of substantiation: the competitor puts forward tangible indications and the provider then has to respond in substantiated form. It can be countered that a secondary burden of substantiation is ruled out to the extent that the competitor can test the answering behaviour itself. Starting points are offered by the audit obligations under Art. 37, the ad repository under Art. 39 and researcher access under Art. 40 DSA – provisions that now apply as a result of the designation as a very large online search engine of 31 August 2026. More on this in the next article.

 

Who is subject to the consent requirement?

Section 25 TDDDG applies to access to information on terminal equipment through cookies. The OpenAI measurement pixel sets a first-party cookie on the advertiser’s domain. The consent requirement therefore falls not on the platform operator but on the booking party. The provider also makes a server-side interface for conversion measurement available; its use, too, is processing carried out by the booking party itself. 

Section 25 TDDDG does not apply to server-side transmission, because no access to terminal equipment takes place there. The only benchmark in that respect is the GDPR.

 

May chat histories be used to select ads?

This is where the real point of examination lies. Chats are shared for the purpose of completing a task, not for optimising advertising. Drawing on the history for ad selection must therefore be measured against Art. 5(1)(b) and Art. 6(4) GDPR, regardless of whether consent is obtained.

Art. 9 GDPR also comes into play. Conversation histories regularly reveal health data, religious or philosophical beliefs, sexual orientation or political opinions. In Cases C-252/21 and C-446/21 the CJEU applied a broad standard for when special categories of data are involved and set strict requirements for the validity of consent. In Case C-446/21 it also found a breach of the data minimisation principle because personal data had been processed for targeted advertising purposes without any distinction according to their nature. Irrespective of this, Art. 21(2) GDPR provides an unconditional right to object to direct marketing, which is not open to any balancing exercise. The right attaches solely to the purpose of the processing and not to the legal basis. It therefore also covers the delivery of non-personalised ads to the extent that these constitute direct marketing.

 

Self-commitment does not replace a legal basis

The provider has set category exclusions for physical health, mental health and politics; political advertising is currently not permitted at all. Exclusions of this kind are contractual self-commitments. They replace neither a legal basis under Art. 9 GDPR nor an assessment of sector-specific advertising bans. How a prohibition under the law on advertising for medicinal products is to be enforced in an interface in which users are describing their symptoms is an open question. 

The reverse case also arises. Under the provider’s advertising policies, regulated industries, among them legal, health and financial services, are excluded from booking outside the United States. For companies in these sectors, the first question is therefore not one of admissibility but one of access.

The protection of minors, too, operates through a technical self-commitment: ads are not served where the user is presumed to be a minor, as determined by age estimation. That protective measure is itself processing that calls for justification. Section 6 JMStV and No. 28 of the Annex to Section 3(3) UWG have to be taken into account in addition. Section 6 JMStV is a rule governing market conduct within the meaning of Section 3a UWG and can therefore also be enforced under unfair competition law. No. 28 of the Annex covers direct exhortations to children to buy, that is to persons under the age of fourteen. Art. 6(1)(f) GDPR comes into consideration as the legal basis for age estimation. It cannot be based on Art. 6(1)(c) GDPR to the extent that it rests on a voluntary self-commitment rather than on a specific legal obligation.

 

Transparency and labelling

The information obligations under Art. 12 to 14 GDPR are under particular scrutiny in 2026: on 19 March 2026 the EDPB launched a coordinated enforcement action on precisely these provisions, with 25 supervisory authorities taking part. A privacy policy revised shortly beforehand, which for the first time includes advertising as a processing purpose, therefore falls within an ongoing year of review.

Art. 50 AI Act has applied since 2 August 2026 in addition. Digital Omnibus Regulation (EU) 2026/1744 postponed only the machine-readable marking under Art. 50(2) AI Act for systems placed on the market before that date, namely to 2 December 2026. As regards competence, a distinction has to be drawn in Germany: under the KI-MIG, the Federal Network Agency is the central market surveillance authority, but for media services used for journalistic or advertising purposes competence remains, pursuant to Section 2(8) KI-MIG, with the authorities designated under state law.

 

What remains open for the booking party

What remains unresolved above all is which labelling obligations apply to the booking party itself, independently of how the platform operator implements them, and who is the controller under data protection law once the booking party deploys its own measurement tools. The third article in this series addresses both questions. For companies whose staff use ad-funded plans in their day-to-day work, there is the added point that conversation content feeds into ad selection there. What this means for trade secrets and for professionals bound by professional secrecy has barely been examined so far.

We would be glad to support you in reviewing your campaigns in the AI environment, in designing labelling and measurement, and in assessing the allocation of roles under data protection law.

09/21/2026, Helena Kasper, Moritz Mehner

The New EU FDI Screening Regulation – What Companies Should Consider Now

At the beginning of 2026, the European Commission, the Council of the European Union, and the European Parliament reached an agreement on the reform of the European Investment Control Regulation (Regulation (EU) 2019/452). However, the new regulation (EU) 2026/1386, known as the "EU Screening Regulation 2026," will primarily take effect from 2028. Nevertheless, it is advisable for companies to assess the implications of this regulation now and to take early action.

 

When Do the New Rules Take Effect?

The timing of the new rules is particularly significant for companies. The EU Screening Regulation 2026 was published on June 26, 2026, and will come into force on July 16, 2026. After an 18-month transition period, it will apply directly from January 17, 2028. By this date, all EU member states must have investment screening mechanisms that meet at least the requirements set forth in the regulation.

Germany will incorporate these regulations into a standalone Investment Screening Act (IPG), which will consolidate and systematize the existing regulations currently spread across the Foreign Trade Act (AWG) and the Foreign Trade Regulation (AWV). This should facilitate the examination of approval or notification requirements for companies in the future. The IPG is expected to be initiated "in a timely manner" according to previous announcements.

 

What Changes Are Fundamental in the EU?

The most significant structural change is the requirement for all member states to establish an investment screening regime. While the previous regulation allowed member states to decide whether to control foreign investments, the reform now mandates minimum harmonization. The era in which certain countries deliberately opted out of FDI screening, thus providing more attractive "hubs" for foreign investors, is over.

The regulation also establishes a common minimum catalog of sectors that must undergo prior screening for foreign investments and cannot be executed without approval. This includes companies developing, manufacturing, or marketing dual-use goods as defined by the EU Dual-Use Regulation, companies involved with goods or technologies listed on the EU Military Goods List, and companies in particularly sensitive technology sectors such as semiconductors, quantum technology, or certain forms of artificial intelligence. Additionally, operators of critical energy, transport, and digital infrastructure, companies exploring, extracting, processing, or stockpiling strategic raw materials, central financial market infrastructures, and operators of specific systems for conducting and evaluating elections are included.

The regulation introduces a two-stage review process modeled after merger control practices. In the first phase, the competent authority must decide within 45 days of a complete application whether to approve the investment or require a more in-depth review. This standardizes the often heterogeneous duration of the initial review phase across member states. Although the regulation does not set a binding deadline for the second phase, it remains at the discretion of the member states. However, the clearly defined first phase provides companies with greater planning certainty for short-term deal timing.

Another key point is the possibility of ex officio reviews. Even investments that are not subject to reporting can be reviewed within a period of up to five years, depending on the nature of the acquisition, if there are indications of potential impacts on security or public order. This existing regulation in Germany means that even seemingly "small" or "low-risk" transactions will not completely escape the authorities' scrutiny.

The substantive review criteria will also be tightened. While the review standard remains formally unchanged-focusing on potential negative impacts on security and public order-the regulation adds a detailed list of protected goods and investor-related factors that must be considered.

Finally, the cooperation mechanism within the EU will be reformed. The number of cases required to be reported and commented on will be reduced and focused on particularly critical investments. Simultaneously, the accountability of member states will increase: they will now have to explain to the Commission and other states to what extent they have considered opinions and comments and why they may have made different decisions. This increases the likelihood that investment decisions in one member state will also be made under the scrutiny of other states and the Commission.

Additionally, the establishment of a European database is planned to track whether and what measures have been taken against foreign investors.

 

What Does the Reform Mean for German Companies?

Germany is among the member states that have had an extensive investment screening regime for many years. From the perspective of German companies, the new EU regulation is not a completely new instrument but rather a tightening and structuring of what is already established practice.

The German investment review already covers both direct and indirect acquisitions, including investments through EU companies controlled by non-EU entities. Therefore, the explicit inclusion of indirect investments at the EU level is more of a confirmation than a disruption for Germany. The two-stage review process-preliminary review and formal review-is already standard practice in Germany.

Nonetheless, German companies will experience significant changes. Firstly, there will be a comprehensive assessment of all dual-use goods and goods listed in the EU Common Military List, ensuring that security-relevant products and technologies are systematically included in the review. Secondly, the scope of artificial intelligence will explicitly extend to defense and aerospace-appropriate AI systems; simultaneously, the definition of AI will be aligned with the provisions of the EU AI Act to ensure uniform and contemporary regulation. Furthermore, critical infrastructures will be mandatorily considered, particularly in the areas of transport, digital infrastructure, financial services, and election infrastructure, to adequately reflect the sensitivity of these sectors. Finally, the list of critical raw materials will be expanded to better account for supply security and the strategic importance of these materials within the investment review.

A central change also concerns the previous privileging of certain third countries. In the German investment review, investors from EFTA states like Switzerland or Norway were partially treated as EU investors and thus privileged in sensitive areas. The EU Screening Regulation 2026 prohibits discriminatory differences between third countries. For German companies with EFTA investors, this means that transactions previously considered "quasi EU-internal" will now fall fully under the scope of third-country investment control.

The procedural deadlines will also change. The first review phase currently lasts two months under German law; at the EU level, a uniform period of 45 days is now established.

Importantly, the information requirements for applications will be expanded. The documents and information previously specified in a general decree will not suffice to cover all the information required under the cooperation mechanism. Companies will now be expected to disclose their corporate structure in detail, describe activities in other member states, identify participations in EU projects of particular interest, and specify larger EU grants received in the past. Transparency in ownership and control structures will be particularly important: the more complex and opaque a structure is, the more likely authorities will view it as a risk indicator.

 

What Should Companies Do Now?

For companies, the reform means that they can no longer treat investment control as a "post-factum specialty" but must integrate it into their governance and transaction processes. They need to identify early on whether and to what extent they are active in any of the sectors that will be particularly sensitive in the future. This requires a detailed analysis of products, technologies, raw materials, and infrastructure functions. Particularly for dual-use goods, it is insufficient to consider only classic export goods; research, development, and pure marketing activities may also fall within the scope of application.

Simultaneously, companies should critically review their investor and ownership structures. Open questions regarding economic entitlement, potential state influences, or connections to sanctioned or high-risk jurisdictions should be clarified early on. The better these structures are documented and transparent, the lower the risk that they will be perceived as a risk factor in the review.

Additionally, it is advisable to clearly define internal responsibilities. Investment control is not solely a legal issue; it touches on strategy, finance, compliance, IT, and sometimes public policy. Companies are well advised to designate fixed points of contact, establish processes for the preparation and coordination of applications, and harmonize interfaces with other regulatory areas-particularly antitrust law, export controls, and sanctions law. Where complex international transactions are planned, a central "FDI Taskforce" can help synchronize different review regimes and deadlines, thereby avoiding delays.

Finally, German companies should closely monitor the development of the Investment Screening Act. It will be crucial to see how the German legislator implements the EU minimum catalog in detail, whether additional sectors will be voluntarily included, and how threshold values and review standards will be defined. Industries that are mentioned in the regulation as protected goods but not as mandatory review segments-such as manufacturers of critical pharmaceuticals or certain media companies-will have a particular interest in the specific national implementation.

09/21/2026, Maria Rothämel

AI Flash: AI literacy Under Article 4 of the AI Act: A Look at the New (Old) Questions

Following our report on the GEMA v. Suno case in our last AI Flash, we would like to continue providing you with regular legal insights into current developments in AI law.

 

Today’s topic: AI literacy under Article 4 of the AI Act

Hardly any provision of the AI Regulation affects as many companies in practice as Article 4 of the AI Act on so-called “AI literacy.” It applies regardless of risk class or industry and thus to anyone who offers or operates AI systems. This is already relevant simply when using ChatGPT, Copilot, or comparable tools in everyday work. The provision has now been amended by the Digital Omnibus on AI (Regulation (EU) 2026/1744 of July 8, 2026, in effect since July 27, 2026). This is reason enough to take another detailed look at the regulation.

 

I. What Has Changed?

In its original version, Article 4 of the Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence  (AI Act) required providers and operators to ensure, to the best of their ability, that their personnel possessed a sufficient level of AI literacy. This wording faced criticism for implying a success that companies could hardly guarantee reliably.

The Digital Omnibus on AI has made adjustments. Article 4 AI Act now states:

(1) Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual.

(2) The Commission and the Member States shall support and facilitate the efforts of providers and deployers of AI systems, in particular SMEs, in fulfilling their obligation under paragraph 1 of this Article. For that purpose, the Commission shall publish practical examples of how to comply with that obligation on the single information platform referred to in Article 62(3), point (b).

(3) The Board shall adopt recommendations, taking into account European competence frameworks, to support the Commission and Member States in the promotion of AI literacy required under paragraph 1, including by setting out common objectives.

Thus, the obligation has shifted from "ensuring" a level of competence to supporting the development of AI literacy through appropriate measures - explicitly without guaranteeing a specific individual competence level. 

Notably, what was not included in the new version of the regulation is significant: the original Commission proposal aimed to largely shift the responsibility for promoting AI literacy to the EU and the Member States. This fundamental realignment did not prevail in the trilogue. The obligation remains-albeit mitigated-with the providers and operators themselves. The only new aspect is the accompanying support from the Commission, Member States, and the AI Committee (paragraphs 2 and 3).

 

II. What Does "AI literacy" Actually Mean?

The term "AI literacy" is not defined in Article 4 AI Act but is elaborated in the definition provided in Article 3 No. 56 AI Act. According to this, AI literacy refers to the "skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause."

Thus, AI literacy is not merely technical niche knowledge but a bundle of technical understanding, risk awareness, and legal and ethical basic understanding. It addresses all actors along the AI value chain - from developers and operational staff to individuals who use AI systems on behalf of the company, such as external service providers.

Importantly for practice: Article 4 AI Act does not prescribe a specific training format, certification, or a dedicated "AI Officer." Internal training, e-learning, workshops, or external training are all permissible-what matters is that the measures fit the technical knowledge level, experience, context of use, and risk profile of the respective target group. Both the Federal Network Agency and the AI Service Center Austria of the RTR explicitly recommend documenting the measures taken (type of training, content, timing, affected groups) to demonstrate compliance with Article 4 AI Act if necessary, even though no legally mandated proof standard currently exists.

 

III. The (Highly Problematic) Question of Sanctions

The question remains, particularly contentious in practice: What happens if a company fails to promote AI literacy?

1. No Immediate Fine Under Article 99 AI Act

First, the good news: Article 99 AI Act lists the provisions subject to fines exhaustively. Article 4 AI Act is not mentioned there. Therefore, the regulation does not provide for an immediate fine specifically for violations of the AI literacy obligation - this is confirmed by both the Austrian AI Service Center of the RTR and the Federal Network Agency.

However, a violation is not without consequences. Some literature suggests that national market surveillance authorities - in Germany, the Federal Network Agency - can address violations of Article 4 AI Act based on national regulations with other enforcement measures. Moreover, and practically more significant, Article 4 AI Act exerts its effect mainly indirectly, through general civil and corporate law.

2. Employer Liability Under § 278 BGB

If a company uses AI systems, it bears the entrepreneurial risk as an operator and is responsible for the proper organization of operations and work equipment. If damage occurs to customers or business partners - due to incorrect operation of an AI system, unverified adoption of erroneous AI outputs, or inputting business secrets into an external AI system - the employer is liable under § 278 BGB for the fault of its employees as vicarious agents. Article 4 AI Act reinforces an existing duty of care and effectively becomes the benchmark against which the appropriateness of the organizational measures taken is assessed. If there is a complete lack of a traceable training and governance structure, the assumption of a breach of duty of care is likely.

3. Recourse Against Employees

Conversely, a company that suffers damage can seek recourse from responsible employees under the principles of internal damage compensation. Here, an interesting interaction emerges: in cases of slight negligence, the employee is typically not liable; in cases of moderate negligence, only partially; full liability generally only arises in cases of gross negligence or intent. Literature suggests that the success of a recourse claim may depend on whether the employer has fulfilled its training obligation under Article 4 AI Act. A company without a robust training concept may find itself at a disadvantage in a serious case - even with potentially gross negligence on the part of employees.

4. Liability of Management and Board

Finally, the question also concerns the management level itself. Managing directors of a GmbH (§ 43 Abs. 1 GmbHG) and board members of an AG (§§ 76, 93 Abs. 1 AktG) are obliged to take the necessary organizational measures to ensure compliance with legal behavior within the company - such as through a compliance management system that also incorporates the AI literacy obligation. If they violate this obligation culpably and the company suffers damage as a result, internal liability under § 43 Abs. 2 GmbHG or § 93 Abs. 2 S. 1 AktG may apply. The recognized business judgment rule in German law provides only limited assistance here: whether or not to establish a compliance system with a training concept is not a matter of entrepreneurial discretion but is legally mandated. Entrepreneurial discretion exists only regarding the specific design - as long as an appropriate minimum standard is maintained.

Interim Conclusion: While Article 4 AI Act is not subject to fines, it is by no means without consequences. The actual "sanctioning" occurs through the backdoor of general liability law - and this makes the norm more relevant for business practice than the absence of a fine might initially suggest.

 

IV. Looking Beyond the Obligation: Added Value in Practice

While the legal discussion of liability risks is certainly justified, our consulting practice with numerous in-house training sessions and workshops on AI literacy reveals another often underestimated effect: the real value does not arise only in disputes but already in the training room itself. In almost every format we have facilitated, most of the staff's open questions - from responsibility for AI outputs to handling confidential data and copyright issues - could be clarified through direct exchange.

Practical uncertainties in daily interactions with AI tools can often be resolved easily before they become actual problems. Moreover, through shared exchange, a collective awareness within the company is created. AI literacy is then not perceived as an abstract compliance requirement but as a jointly developed standard that the staff supports.

 

V. Conclusion and Outlook

The Digital Omnibus on AI has made Article 4 AI Act more practical without abandoning the obligation itself. The absence of a fine does not change the fact that deficiencies in AI literacy can become relevant under general civil, labor, and corporate law - for the company, for employees in recourse cases, and for the management level alike. Those who take this framework seriously and simultaneously leverage the practical value of training and workshops not only create legal certainty but also foster a sense of shared sovereignty in dealing with AI within the company.

 

SKW Schwarz is happy to assist you in designing suitable training programs and accompanying you in conducting initial workshops on AI literacy in your company. Please feel free to contact us so that we can jointly create the greatest possible value for your business.

09/07/2026, Marius Drabiniok, Dr. Oliver Hornung

Beyond EU Borders: What the Kodak/Fujifilm Decision Means for UPC Patent Litigation

Under certain conditions, the Unified Patent Court (UPC) can also rule on claims concerning the UK part of a classic European patent. This was clarified by the UPC Court of Appeal in its decision of 2 June 2026 in the Kodak/Fujifilm case (UPC_CoA_312/2025).

Following Brexit, the United Kingdom does not participate in the UPC. The UPC therefore has no jurisdiction over purely national UK patents. The situation can be different for the UK part of a classic European patent: Where the UPC has international jurisdiction over the defendant, in particular because the defendant is domiciled in a UPC Contracting Member State, the UPC may, according to the case law in Fujifilm v Kodak, also rule on alleged acts of infringement in the United Kingdom.

The Court of Appeal thus confirms the practical significance of the UPC’s so-called “long-arm jurisdiction”. This may offer considerable advantages for patent proprietors, as cross-border infringement claims can potentially be consolidated before a single court rather than pursued in parallel proceedings across multiple jurisdictions. This can streamline litigation, reduce costs and minimise the risk of conflicting decisions.

At the same time, relying on the UPC’s long-arm jurisdiction requires careful analysis and preparation. International jurisdiction merely provides access to the Court; it does not relieve the patent proprietor of the need to establish both infringement and the individual defendant’s responsibility for the alleged infringing acts. This is precisely where Fujifilm’s case ultimately failed. The Court of Appeal set aside the first-instance decision. In Germany, Kodak was able to rely on a right of prior use. As regards the United Kingdom, Fujifilm had failed to establish that the German Kodak entities named as defendants had themselves committed relevant acts of infringement in the UK or could be held legally responsible for acts committed by a UK group company. The Court’s assessment turned on the specific supply chain, ownership structure and economic control over the products. The mere fact that a German group company manufactured products for a UK company was not sufficient to attribute the latter’s importation or distribution activities in the UK to the German entity.

At the same time, the assessment remains challenging and requires particularly careful preparation: International jurisdiction merely provides access to the court. It neither dispenses with the need to establish patent infringement nor with the requirement to attribute the alleged acts to the specific defendant entity. This was precisely where Fujifilm failed in the case at hand. The Court of Appeal set aside the first-instance decision. In Germany, Kodak was able to rely on a right of prior use. With regard to the United Kingdom, however, it had not been sufficiently established that the German Kodak companies being sued had themselves carried out relevant acts of infringement there or that they were legally liable for such acts by a UK group company. The decisive factors were the specific supply chain, ownership structures and the economic control over the products. The mere fact that a German group company manufactured products for a UK company was not sufficient to hold the German entity responsible for the UK company’s subsequent import and distribution activities in the United Kingdom.

The decision therefore does not provide a carte blanche for cross-border litigation before the UPC. It does, however, demonstrate that, when dealing with classic European patents, companies should not shape their patent and litigation strategies solely around the territorial boundaries of the UPC Contracting Member States.

For defendants, intra-group manufacturing and distribution structures may offer potential lines of defence. For each market concerned, the patent proprietor must specifically plead and prove which group entity is responsible for the relevant acts of infringement; mere membership of the same corporate group is not sufficient. Companies facing infringement claims should therefore ensure that their manufacturing locations, supply chains and contractual arrangements, transfers of title, as well as the entities exercising actual decision-making authority and control over distribution, are clearly documented from an early stage.

Fujifilm v Kodak thus confirms that the UPC’s reach may extend beyond UPC Contracting Member States. Whether a cross-border infringement claim ultimately succeeds, however, will depend on the specific acts of infringement at issue and, crucially, on whether those acts can be attributed to the individual defendant.

 

09/01/2026, Margret Knitter

SKW Schwarz is advising the MM Group on the acquisition of the recycled cardboard plant from the R.D.M. Group

SKW Schwarz advised Mayr-Melnhof Karton AG (MM Group) on the acquisition of the business operations of the recycling cartonboard mill in Arnsberg from the R.D.M. Group. Through the transaction, structured as an asset deal, the MM Group is investing in its core business and expanding its production network. The Arnsberg mill is one of the established production sites for recycled cartonboard in Europe.

The closing of the transaction is still subject to regulatory approval under competition law. The acquisition is expected to be completed by the end of the year.

Based in Vienna, the MM Group is a leading provider of fiber-based packaging solutions, with a focus on recycling and sustainability. The listed company employs around 13,000 people at 60 sites across three continents.

Headquartered in Milan, the R.D.M. Group is a leading European manufacturer of cartonboard for packaging.

Advisers to MM Group:
SKW Schwarz, Munich: Dr. Stephan Morsch (lead), Marion Anzinger, Dr. Thomas Hausbeck, Dr. Angela Poschenrieder (Associated Partner; all Corporate/M&A), Michael Wahl, Sabrina Hochbrückner (Counsel; both Employment Law, Frankfurt), Dr. Klaus Jankowski (Public Law/Real Estate), Maria Rothämel (Counsel; Public Law; both Berlin); Associate: Christine Wärl (Corporate/M&A)

08/27/2026, Dr. Stephan Morsch, Marion Anzinger, Dr. Thomas Hausbeck, Dr. Angela Poschenrieder, Michael Wahl, Sabrina Hochbrückner, Dr. Klaus Jankowski, Maria Rothämel, Christine Wärl

SKW Schwarz advises OverDrive Europe on the acquisition of divibib

SKW Schwarz has advised OverDrive Europe GmbH, the European subsidiary of the leading U.S. digital library platform OverDrive,Inc., on the acquisition of divibib GmbH, the company behind the German digital lending service Onleihe, from ekz.bibliotheksservice GmbH.

Onleihe will be gradually migrated to the Libbyplatform, bringing together the digital catalogs of OverDrive and divibib for libraries and patrons across the DACH region. All other divisions of the ekz Group will not be affected by the transaction.

The acquisition deepens OverDrive’s commitment to libraries and readers in the DACH region.

OverDrive, Inc. is the company behind Libby, Sora, and Kanopy, the leading digital reading, learning, and entertainment apps for libraries and schools. OverDrive serves more than 600 public libraries, schools, and academic partners across Germany, Austria, and Switzerland.

divibib, a subsidiary of ekz.bibliotheksservice based in Reutlingen, has been operating the digital lending platform Onleihe since 2007, serving public libraries across Germany, Austria, Switzerland, and other European markets. ekz Group is a long-standing provider of services and technology for public libraries in the German-speaking countries.

The SKW Schwarz team advising OverDrive was led by Stephan Morsch (Corporate/M&A) and Stefan Peintinger (IT & Digital Business/IP), and included partner Alexander Möller (Employment), associated partner Matthias Pajunk (Procurement), counsel Eva Bonacker (Corporate/M&A), as well as associates Christine Wärl (Corporate/M&A) and Tamara Ulm (Employment).

08/21/2026, Dr. Stephan Morsch, Dr. Stefan Peintinger, Alexander Möller, Dr. Mathias Pajunk, Eva Bonacker, Christine Wärl, Tamara Ulm

Federal Labour Court: No Entitlement to the Full Disclosure or Copies of Compliance Reports

With its judgment of 16 April 2026 (8 AZR 169/25), the Eighth Senate of the German Federal Labour Court (Bundesarbeitsgericht – BAG) handed down a decision of considerable practical relevance for employers: Pursuant to Art. 15 GDPR, employees generally have no right to receive copies of complete compliance investigation reports. This is because the data subject’s right of access under data protection law relates to personal data – and generally not to the document as such.

From a corporate perspective, the judgment provides important clarification regarding the limits of data protection access requests, which employees are increasingly using to challenge internal investigations. It strengthens employers’ position against attempts to use data protection law as a gateway into internal corporate decision-making processes.

What was the case about?

The case concerned a senior employee whose conduct as a manager had been reported to the company’s ombudsperson on several occasions. The company commissioned a compliance report documenting, among other things, the allegations against the manager, statements made by whistleblowers and witnesses, assessments of their credibility, as well as legal assessments by the law firm instructed by the company. The senior employee requested copies of the compliance reports pursuant to Art. 15(1) in conjunction with Art. 15(3) GDPR.

The right to a copy of personal data does not necessarily cover complete documents

In line with the case law of the Court of Justice of the European Union (CJEU), the BAG clarified that Art. 15(1) in conjunction with Art. 15(3) GDPR does not give employees a right to receive a copy of an entire compliance report, even where the report contains personal data.

The “right to a copy” under Art. 15(3) GDPR does not constitute an independent right to obtain a document “as such”. Rather, it governs the manner in which the right of access under Art. 15(1) GDPR is to be exercised. The subject matter of that right is only personal data. Art. 15(3) GDPR, in turn, does not also confer a right to receive the entire document containing such personal data.

Under the GDPR, a right to receive copies of excerpts from documents or even complete documents may arise only where this is “essential” to enable the data subject to effectively exercise their rights. This may be the case, for example, where the processing of the data can only be understood by the employee in its context. As a general rule, the employee concerned bears the burden of demonstrating this necessity.

In the case at hand, the BAG rejected such a necessity, at least with regard to the legal assessments and client-related information contained in the compliance report. In order to understand the personal data stored in relation to the senior employee, she did not need to have access to this content. Consequently, in the BAG’s view, there was no entitlement to a copy of the complete document.

No right to copies of complete documents based on the right of access to personnel files either

The BAG also held that the right of access to personnel files (§ 26(2) SprAuG, § 83(1) BetrVG) does not give rise to a right to receive copies of complete documents.

These provisions grant employees the right to inspect their personnel files, i.e. all documents relating to their personal or professional circumstances that have an internal connection with the employment relationship. While this generally gives rise to a right to make copies to a reasonable extent, that right ends where personnel records are to be copied and disclosed “as a whole”. According to the BAG, extensive documents such as a complete compliance investigation report therefore cannot be requested solely on the basis of the right to inspect personnel files.

Of particular practical relevance is the BAG’s observation that the legal assessments and client-related information contained in such a compliance report may not even form part of the “personnel file”. This means that even if the report is stored in the personnel file, this does not automatically mean that all of its contents – in particular, internal legal assessments and strategic considerations – must be provided in copy.

Practical considerations

The BAG’s decision is consistent with the fundamental principles of data protection law that have already been confirmed by several supreme courts. Art. 15 GDPR does not establish a general right of access to files. Nor can it generally be assumed that the disclosure of documents is necessary to enable data subjects to effectively exercise their rights.

Employers can and should take a restrictive approach to requests for the disclosure of documents contained in compliance files. The obligation to provide copies is generally limited to the context of personal data. From an employer’s perspective, it is therefore advisable to take a closer look at the way personnel files and compliance processes are structured: personal factual information should be clearly separated from legal, internal and business-related content. Accordingly, compliance investigation reports should be structured separately and stored independently.

Standardised processes should also be established for responding to access requests under Art. 15 GDPR in a way that ensures employees receive their personal data completely and in an intelligible form, without requiring the employer to disclose entire compliance reports or its internal legal strategy.

 

 

08/14/2026, Tamara Ulm, Dr. Stefan Peintinger, Ferdinand Schwarz

KI-Flash: GEMA v. Suno – German Court Assesses AI Training not to be Fair Use Under US Law

On 31 July 2026, the 42nd Civil Chamber of the Munich Regional Court (Landgericht München I) issued its final judgment largely upholding GEMA's claims against the AI music generator Suno (case no. 42 O 763/25; oral hearing held on 9 March 2026). We previously reported on this on LinkedIn. The full, 137-page grounds for judgment are now available and go significantly beyond the press release issued the previous week. Below, we set out the central passages of the decision: from the memorization and adaptation of the works in Germany, to the application of US law to the reproduction during training, to the legal consequences ordered by the court.

Stream-Ripping and Open-Ended Prompts

The proceedings concerned six musical works: "Atemlos durch die Nacht" (Kristina Bach), "Rasputin" (Frank Farian, Fred Jay, George Reyam), "Big in Japan" and "Forever Young" (Marian Gold, Bernhard Lloyd, Frank Mertens), the chorus of "Mambo No. 5 A Little Bit of…" (David Lubega, Christian Pletschacher), and "Daddy Cool" (Frank Farian). The dispute did not concern the lyrics, but rather the melody, harmony, rhythm, and arrangement of the compositions. Suno had obtained access to the works by stream-ripping them from YouTube, in the process circumventing the platform's technical copy protection, the so-called Rolling Cipher. To generate the outputs at issue, the claimant used between four and 176 prompts per work, each limited to the original lyrics, the desired musical style, and the title of the work, without any further musical instructions.

Copyright Protection as a Preliminary Question

Before turning to the actual question of infringement, the chamber had to establish, for each of the six works individually, that it met the threshold for copyright protection. The chamber listened to the tracks during the hearing and evaluated the private expert opinions submitted by both parties; it rejected the defendant's request for a court-appointed expert opinion, on the grounds that the members of the chamber themselves belonged to the relevant public familiar with musical matters. For the remainder of the judgment, this examination is more of a preliminary question than the actual focus: the heart of the decision lies in what happened to the protected works during AI training and in the outputs.

Reproduction and Adaptation in Germany

On the question of whether a reproduction occurred in Germany, the chamber relied on the concept of memorization: the works were reproducibly contained within model versions v3.5 and v4, which goes beyond the mere learning of statistical patterns. The court found that both the memorization within the model (Section 16 UrhG) and the public communication of the outputs (Section 15(1), (2) UrhG) constituted an infringement, for which the defendant, not the users, was responsible, because the simple, open-ended prompts did not control the specific content of the outputs. In the chamber's view, the text and data mining exception under Section 44b UrhG did not apply. For outputs that were not identical reproductions but recognizable adaptations of the original works, the chamber additionally relied on Section 23 UrhG: a distinction between reproduction and adaptation was in any event unnecessary, since any adaptation fixed in material form simultaneously constitutes a reproduction.

No Making Available to the Public

Not every claim brought by GEMA succeeded. The claimant had also based its claims regarding public communication, in the alternative, on the right of making available to the public under Section 19a UrhG. The chamber dismissed this part of the claim: making a work available to the public requires that the public can access the work from a place and at a time individually chosen by them. Because retrieving some outputs required up to 176 identical prompts, the chamber did not consider access "at a time of the user's choosing" to have been sufficiently established. GEMA was, however, able to successfully base its claim instead on the right of public communication under Section 15(2) UrhG.

Jurisdiction of German Courts Over AI Training in the US

On the basis of the concentration rule in Section 131(2) VGG, the claimant, as a collecting society, was also able to bring the claims arising from the purely US-based training activities before the same court. This provision allows a collecting society to bundle all claims against the same infringer before a single court with jurisdiction under Section 131(1) VGG, even where different courts would otherwise have jurisdiction over individual infringing acts; the sole requirement is that the infringer is identical, not that the individual infringing acts are identical.

The Path to US Law: Article 8 Rome II and the Court's Own Research

For the reproduction occurring during training in the US, US law applied under Article 8(1) of the Rome II Regulation. The chamber highlights a private international law point that extends beyond the resolution of this particular case: the Rome II Regulation applies as a so-called loi uniforme and therefore refers not only to the law of EU member states, but also to the law of third countries such as the US. The chamber then determined the applicable US law itself, ex officio, under Section 293 ZPO, expressly declining to obtain an expert opinion: it did so on the basis of the text of the U.S. Copyright Act and relevant case law, drawing, among other things, on the library of the Max Planck Institute for Innovation and Competition in Munich. The chamber also had to close a conflict-of-laws gap with respect to the claim for information asserted in this context: while US law addresses requests for information procedurally, through pre-trial discovery, German procedural law has no equivalent instrument. The chamber addressed this by applying Section 242 BGB by analogy, to close the resulting gap in the applicable rules.

Fair Use – The Four Factors Under Warhol

The chamber examined all four factors under 17 U.S.C. § 107 in light of the Supreme Court's decision in Warhol (Andy Warhol Foundation for the Visual Arts, Inc. v. Goldsmith, 598 U.S. 508 (2023)), and found that each individual factor weighed against the defendant.

On the first factor, the purpose and character of the use, the chamber found that Suno had not created new musical works with the outputs at issue, but had instead generated recordings that closely resembled the originals, and had therefore not transformed the works. In addition, the chamber weighed the circumvention of the Rolling Cipher as a violation of the DMCA's anti-circumvention provision (17 U.S.C. § 1201(a)(1)(A)), which it treated as evidence of bad faith conduct feeding into the assessment. The chamber expressly draws a parallel to Bartz v. Anthropic, where the fact that the works originated from pirated copies already weighed against a finding of transformative use, and cites that court's statement that the outcome would have been different had the outputs at issue there been infringing. That was precisely the case with Suno.

The second factor, the nature of the work used, likewise weighed against Suno in the chamber's view, because the outputs drew not merely on facts or ideas but on the creative elements of the works, a parallel the court also drew in Kadrey v. Meta. On the third factor, the amount and substantiality of the portion used, the chamber noted that this did not involve non-public intermediate copies of the kind recognized as fair use in software reverse engineering, but rather works that became publicly accessible through the outputs. On the fourth factor, market effect, the chamber relied on actual market substitution, pointing even to publicly available YouTube tutorials showing users how to create cover versions of well-known songs using Suno. The burden of proving the absence of market harm lay with the defendant, which, in the chamber's view, had not discharged that burden.

Legal Consequences: Information, Damages, and Publication of the Judgment

In addition to the injunctive relief, the chamber awarded GEMA a claim for information regarding the acts of use undertaken since 1 July 2023, as well as a declaration of liability for damages, the latter based on 17 U.S.C. § 504(a) for the reproduction during training in the US. There is also a claim rarely seen in German copyright proceedings: GEMA may publish the operative part of the judgment, at the defendant's expense, in the Süddeutsche Zeitung within six weeks of the judgment becoming final. The defendant was further ordered to pay pre-litigation legal fees of EUR 5,049.70. The chamber rejected the defendant's request to stay the proceedings and refer the matter to the CJEU under Article 267(2) TFEU, holding that the EU law questions concerning reproduction and public communication had already been sufficiently clarified by existing CJEU case law.

Assessment and Outlook

The judgment was issued at first instance and is not yet final. As to timing: the Bartz v. Anthropic proceedings, to which the chamber repeatedly refers, were concluded on 20 July 2026 through a court-approved settlement covering roughly 482,000 books at approximately USD 3,000 each. For providers of AI-based content generators, the new judgment now provides a clear direction: in the Munich Regional Court's view, it is not the abstract transformativeness of a training method that determines the availability of a fair use defense, but the actual similarity between the specific outputs generated and the protected original works. The extent to which German courts will engage substantively with foreign law in future cases where training takes place outside the EU is likely to matter well beyond this individual case.

If you have questions regarding the copyright assessment of AI training data, we would be glad to discuss the concrete implications of this decision for your practice.

08/13/2026, Moritz Mehner, Maximilian Moll de Alba

The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now – Part 2

Part 2: EEVO – Obligations, Deadlines, and Sanctions in Practice

The first part of this publication set out the basic structure of the EEVO: the two new instruments, EPOC and EPOC-PR, the range of service providers concerned, and the conditions under which a connection to the EU within the meaning of the Regulation exists. This second part now turns to the practical implementation that becomes directly relevant to service providers in an actual case: the applicable deadlines for production and preservation, the scope of the review required before execution, and the sanctions and liability consequences of non-compliance.

 

Deadlines: Production and Preservation Compared

The most striking feature is the deadlines, which are considerably shorter than those familiar from classic mutual legal assistance proceedings. For the European Production Order, the standard deadline is ten days from receipt, shortened to eight hours in emergencies (Article 10(2) and (4) EEVO). The logic underlying the European Preservation Order is different: the focus here is not on rapid production, but on freezing the status quo. The obligation to preserve the data concerned arises immediately upon receipt; the preservation itself must be maintained for 60 days and may be extended once, by 30 days, by the issuing authority (Article 11(1) EEVO). If a production order subsequently follows, the preservation obligation continues until the data is actually produced (Article 11(2) EEVO) – the two instruments can therefore be combined.

 

What Review Is Required Before Execution?

How extensive a review a service provider must carry out before execution depends largely on the category of data concerned. For an EPOC: subscriber data and traffic data used solely for user identification must be produced without further review (Article 5(3) EEVO). The position is different for anything going beyond this – for further traffic data and for content data, it must be examined whether the underlying offence falls within the catalogue of serious offences set out in Article 5(4) EEVO. For the EPOC-PR, the scope is deliberately drawn more broadly: it may be issued for any offence for which a corresponding order would be possible in a comparable domestic case under the same conditions (Article 6(3) EEVO), and it covers all categories of data.

Irrespective of the data category, the same formal review applies in both cases: is the person concerned identifiable from the information provided, and is the certificate complete and free of errors? Where there is doubt on this point, this must be indicated using the form set out in Annex III; the issuing authority must then provide clarification within five days – if it fails to do so, the obligation to execute or preserve, as applicable, lapses.

 

When May or Must Execution Be Refused?

Not every order received must actually be executed. The addressee does not have a general power to refuse – the EEVO is too heavily geared towards rapid effectiveness for that. In four narrowly defined cases, however, the addressee may, or must, refuse execution and must notify the issuing authority of this without delay: where the order is formally deficient (Article 10(6), Article 11(5) EEVO); where execution is factually impossible, for example because the person concerned is not a customer of the service provider or the data has already been lawfully deleted (Article 10(7), Article 11(6) EEVO); where there are indications of immunities, privileges, or rules on liability under press law (Article 10(5), Article 11(4) EEVO); and where there is a conflict with an obligation under the law of a third country, such as the United States or the United Kingdom (Article 17 EEVO).

The last case is likely to be the most complex in practice: the objection may be raised within ten days of receipt, and enforcement is then suspended until this procedure has concluded – the data must, however, continue to be preserved in the meantime. In the immunity and press-law cases, by contrast, the addressee does not make its own decision to refuse, but merely triggers a review by the competent authorities.

 

Sanctions and Liability: Who Bears Which Risk?

A service provider that fails, without a valid reason, to comply with an order in breach of its obligations risks fines of up to 2% of total worldwide annual turnover for the preceding financial year (Article 16(1) EEVO) – a framework that companies are likely to find familiar from other pieces of European legislation.

In practice, what is likely to matter most is whether, and how actively, a company communicates with the issuing authority: a company that promptly reports any obstacles is likely to be in a better position to rely on a recognized justification within the meaning of the provision, whereas unexplained silence increases the risk of sanctions.

The picture on liability is somewhat more reassuring: service providers are not liable to their users or third parties for damage arising solely from good-faith compliance with an EPOC or EPOC-PR (Article 15(2) EEVO) – responsibility for the lawfulness of the order remains with the issuing authority. Nor does the service provider necessarily have to bear the costs of responding to an order alone: under certain conditions, reimbursement may be claimed, to the extent that the national law of the issuing state provides for this in respect of comparable domestic orders (Article 14 EEVO).

 

What Companies Need to Do Now

All of this results in a scope of action for affected service providers that is manageable, but time critical. A point of contact ready to receive orders must be designated or appointed, internal workflows for receipt, review, preservation, transmission, and documentation must be established, and the relevant personnel should be familiar with the tight deadlines before an actual case arises. To provide a quick overview, we have summarized the key deadlines and review steps for EPOC and EPOC-PR in this one-pager.

This outlines the practical obligations arising from the EEVO. Service providers falling within the scope of the Regulation should have incorporated the deadlines, review obligations, and response duties described above into their internal processes by 18 August 2026 at the latest, in order to be able to respond in a timely and legally compliant manner in the event of an EPOC or EPOC-PR.

Would you like support in setting up or reviewing your internal processes? We would be glad to assist you in developing workflows that work in practice and to support you in preparing for 18 August 2026.

08/10/2026, Moritz Mehner

The E-Evidence Regulation Is Coming: What Service Providers Need to Know Now - Part 1

What Does the E-Evidence Regulation Cover – And Who Does It Apply To?

From 18 August 2026, Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings – the e-Evidence Regulation, or EEVO for short – will become directly applicable in all Member States, including Germany, following a three-year transitional period. This date is no longer a distant prospect: in Germany, the implementing legislation, the Electronic Evidence Implementation and Enforcement Act (Elektronische-Beweismittel-Umsetzungs- und Durchführungsgesetz, EBewMG), was promulgated in March 2026; the Federal Office of Justice (Bundesamt für Justiz) has been designated as the central authority, while the Federal Network Agency (Bundesnetzagentur) is responsible for technical regulation.

Before turning to the EEVO itself, a look at the position under the law as it currently stands helps put matters into context. With the EEVO, the legislator responds to a state of affairs that has proven increasingly “very difficult” over the years. Cross-border access to electronic evidence has so far been governed by the classic mutual legal assistance procedure: a foreign authority had to submit a request to the competent German authority, which would then examine it and, where appropriate, issue its own order – only at that point was a service provider under any obligation to produce data. Depending on the case, this route could take weeks or months, while the request itself remained without consequence for the service provider in the meantime. A foreign request received directly by a service provider did not, on its own, give rise to any obligation to review or respond – it could, and generally had to, remain unanswered as long as no German order had been issued. 

In this two-part publication, we now present the EEVO, which addresses precisely this point. The first part covers its basic structure – the new instruments EPOC and EPOC-PR, the range of service providers concerned, and the scope of application. The second part will then set out the applicable deadlines, the review obligations that apply, and the sanctions that may follow non-compliance. 

In addition to these two articles, we have created a cheat-sheet that provides a quick overview of the key deadlines and review steps.
>> Read cheat-sheet <<

 

Two New Instruments: EPOC and EPOC-PR

At the heart of the EEVO are two new types of order that allow law enforcement authorities in one Member State to address service providers in another Member State directly in future – without the previously customary detour via mutual legal assistance proceedings. The European Production Order (EPOC) requires a service provider to produce specified electronic evidence, such as content, traffic, or subscriber data. The European Preservation Order (EPOC-PR) operates a step earlier: it merely requires the service provider to preserve data for a specified period so that it is not deleted before a production order, where applicable, follows.

For affected companies, this means one thing above all: both types of order take immediate effect. Unlike before, no separate involvement of a German authority is required – an order issued by another Member State becomes binding as soon as it reaches the designated point of contact within the company. What was previously described as a passive role thus becomes an active obligation to act. Whereas a service provider was previously permitted to leave a foreign request unanswered without consequence, it is now directly obligated in its own right from the moment an EPOC or EPOC-PR is received.

 

Who Is Subject to the EEVO?

The EEVO addresses service providers with a connection to the EU under Article 2(1) EEVO, irrespective of whether they are established in the EU at all. This marks an important difference from many other pieces of European legislation: a cloud provider without any European establishment can be just as affected as a German company. Under Article 3(3) EEVO, this covers in particular providers of electronic communications services (such as messaging or VoIP services), domain name registries and registrars, as well as other information society services – a category under which the Regulation expressly includes platform operators such as social networks and file-hosting services, as well as hosting providers and cloud services.

The addressee of an order is, as a general rule, the controller within the meaning of Article 4(7) GDPR, i.e. whoever determines the purposes and means of the processing. Only exceptionally may an EPOC be addressed directly to a processor: where the controller cannot be identified by the issuing authority despite reasonable efforts, or where the investigation would otherwise be jeopardized (Article 5(6) EEVO).

 

When Is There a “Connection to the EU”?

The Regulation first requires that the services be accessible to persons in a Member State – identifiable, for example, by language, currency, or targeted marketing. That alone, however, is not sufficient. In addition, there must be a substantial connection to one or more Member States, such as an establishment carrying out genuine economic activity, a significant number of users, or activity that is clearly directed at the relevant Member State. Mere technical accessibility of a website is expressly not sufficient for this purpose under Recital 29 EEVO – a service that happens to also be accessible from Germany does not thereby automatically fall within the scope of the Regulation.

 

Who Receives the Orders?

Once the question of whether a provider is covered has been resolved, the practical question remains of where an order is actually to be sent. Under Article 3(1) of Directive (EU) 2023/1544, every service provider must designate an establishment or a legal representative for the receipt of EPOCs and EPOC-PRs – by 18 August 2026 at the latest, or within six months of commencing service provision in the EU. Orders are, as a general rule, addressed exclusively to this designated point of contact (Article 7(1) EEVO). If it fails to respond in time in an emergency, or if no point of contact has yet been designated, the authority may exceptionally address another establishment of the company (Article 7(2) EEVO).

In practice, it is therefore advisable for the function internally responsible for EPOC/EPOC-PR matters – such as Legal or Compliance – to correspond to the externally designated point of contact and to be genuinely reachable. Otherwise, there is a risk that an emergency order with a particularly short deadline ends up with a group entity that is unprepared and consequently unable to respond in time.

This sets out the legal framework. What this looks like in practice – which specific deadlines apply, when an order may be refused, and what consequences follow non-compliance – is the subject of the second and final part of this series.

Would you like to assess whether, and to what extent, your company is subject to the EEVO, or do you need support in designating a point of contact for receiving orders? We would be glad to assist you with the legal assessment and with preparing for 18 August 2026.

08/06/2026, Moritz Mehner

Cyber Resilience Act: The Five Key Takeaways from the European Commission's Guidelines

The Cyber Resilience Act (CRA) introduces extensive new cybersecurity requirements for manufacturers of software, connected devices, and other products with digital elements. While most obligations will apply from 11 December 2027, manufacturers will already be required, from 11 September 2026, to report actively exploited vulnerabilities and severe security incidents.

As companies prepare for the CRA, numerous practical questions arise: When is a new software version considered a new product? What are the consequences of a substantial update? How long must security updates be provided? And do products that have already been developed need to be redesigned to comply with the CRA?

The European Commission has now published guidelines on the application of the CRA. Using practical examples, the Commission explains how it interprets key concepts and obligations under the Regulation. Although the guidelines are not legally binding, they provide important guidance for companies and, likely, for the competent authorities responsible for enforcing the CRA.

Below, we summarize the aspects of the guidelines that are particularly relevant in practice.

 

1. The 24-hour reporting deadline does not start with the first suspicion

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents. The guidelines explain when these short reporting deadlines begin to run.

An unconfirmed indication alone does not trigger the reporting deadline. However, the manufacturer must assess it without undue delay. The reporting period begins once this initial assessment establishes with sufficient certainty that:

  • a vulnerability contained in the product is being actively exploited; or
  • a severe security incident has occurred and has affected the security of the product.

From that point onward, an initial early warning report must generally be submitted within 24 hours. A follow-up notification must be submitted within 72 hours.

For an actively exploited vulnerability, the complete report must generally be submitted within 14 days after a corrective or mitigating measure becomes available. For a severe security incident, the deadline is one month after the 72-hour notification.

Companies therefore need not only a technical reporting mechanism but also clear responsibilities for the initial assessment and escalation of potential incidents. The process should cover both external reports and findings from internal security testing. The guidelines emphasize that the initial assessment must be carried out without undue delay, particularly where the potential vulnerability poses a significant risk. These procedures should be tested in practice before 11 September 2026.

 

2. A software version is generally placed on the market only once

According to the European Commission, software that is offered as a standalone product is placed on the market when the completed version is first made available on the EU market. This applies regardless of when individual customers purchase or download the software.

The guidelines illustrate this with an example: If software version 1.0.0 is first made available for download on 1 January 2028, it is considered to have been placed on the market on that date-even if some customers download it only at a later stage. A later version, such as 1.0.1, is not considered to have been newly placed on the market unless the changes are substantial. Consequently, the original placement-on-the-market date remains decisive.

The situation may differ for different variants of the same software, for example, builds for different operating systems or packages with different functionalities. Such variants may qualify as separate products. A new software version is also considered to be placed on the market again if it has undergone a substantial modification.

This distinction is particularly important for the CRA's transitional provisions. Manufacturers should document when individual versions were first made available, which variants they treat as separate products, and what changes were introduced subsequently.

 

3. Products that have already been developed do not automatically need to be redesigned

Many products that will only be placed on the market after 11 December 2027 are already under development today or have even been fully developed. According to the guidelines, the CRA does not automatically require these products to be redesigned.

However, manufacturers must assess the cybersecurity risks of the product. Based on the technical documentation, they must be able to demonstrate that the product achieves an appropriate level of cybersecurity and complies with the CRA requirements. The required conformity assessment, the EU Declaration of Conformity, and CE marking also remain mandatory.

However, the Commission does not require manufacturers to retrospectively recreate all evidence and testing from earlier development phases. If it is no longer possible to demonstrate how cybersecurity risks were addressed during the original development process, the manufacturer may instead carry out a current risk assessment and explain how the existing product design and security measures mitigate the identified risks.

This clarification is particularly relevant for industrial products with long development cycles. Companies should review which evidence is already available for ongoing product developments and identify any documentation gaps that still need to be closed.

 

4. For software updates, the decisive factor is the cybersecurity risk-not the scope of the update

Not every major update constitutes a "substantial modification" within the meaning of the CRA. Conversely, even a small change may qualify as substantial. The decisive factor is whether the intended use of the product changes or whether new or increased cybersecurity risks arise that were not previously considered.

The Commission provides the example of a system that initially only displays operational data from machines. If the system is later updated to allow it to control those machines, its intended use changes. The update must therefore be regarded as a substantial modification.

The guidelines also set out a non-exhaustive list of assessment criteria. In particular, it should be examined whether the update:

  • introduces additional interfaces, communication channels, execution environments, or external dependencies;
  • enables new attack scenarios; or
  • significantly changes the likelihood or potential impact of attack scenarios that have already been considered.

By contrast, a significant functional enhancement does not necessarily constitute a substantial modification if it was already planned during the original development and taken into account in the risk assessment. Updates that merely remediate vulnerabilities or strengthen existing security measures generally do not constitute a substantial modification, provided that they neither change the intended purpose of the product nor introduce new or increased cybersecurity risks.

Companies should therefore align their product roadmaps with their cybersecurity risk assessments at an early stage. A technical classification as a major or minor release is not sufficient for the legal assessment. It is advisable to establish a documented process for evaluating security-relevant updates against the CRA criteria.

 

5. Five years is not a standard support period

As a general rule, the CRA requires a support period of at least five years. If a product is expected to be used for a shorter period, the support period may also be shorter. Conversely, where a product has a longer expected service life, five years will not automatically be sufficient.

This is particularly relevant for industrial installations, control systems, and other long-life products. For such products, the support period must reflect the realistically expected service life. The guidelines expressly clarify that five years should not be regarded as a universal standard for all products.

A substantial modification also does not automatically trigger a new five-year support period. The decisive question is whether the modification also affects the product's expected service life. For example, if a software update merely introduces new functionalities without extending the lifetime of the hardware or changing users' expectations, the remaining original support period generally continues to apply.

For continuously evolving software, manufacturers may, under certain conditions, limit vulnerability remediation to the most recently placed-on-the-market version. Users must be able to upgrade to that version free of charge and without additional costs. Normal efforts such as testing or configuration changes are generally not regarded as additional costs. However, if users are required to purchase new hardware or fundamentally rebuild their system environment, the manufacturer cannot rely on this simplification.

 

Practical Tip

The guidelines do not create any additional legal obligations. However, they provide important clarification on key issues that companies must address when implementing the CRA.

Manufacturers should, in particular, review whether software versions and updates are documented in a traceable manner, whether the cybersecurity risk assessment is integrated with product planning, whether support periods have been determined realistically, and whether the reporting process will be operational by September 2026.

The guidelines also address, among other topics, free and open-source software, cloud-based functionalities, spare parts, and the interaction of the CRA with vehicle regulation, the Radio Equipment Directive, and the Machinery Regulation.

 

Discover Our CRA Compliance Suite

Our CRA Compliance Suite provides modular, fixed-fee consulting services to help manufacturers, importers, and distributors of digital products implement the requirements of the Cyber Resilience Act (CRA). Contact us for more information.

07/30/2026, Dr. Daniel Meßmer, Martin Schweinoch

Protection of Trade Secrets in Employment Relationships: New Article Published in RüSiR

How can companies effectively protect their trade secrets in employment relationships?

This question is explored by our partners Dr. Rembert Niebel and Alexander Möller in their article "Trade Secret Protection in Employment Relationships", published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.

Trade secrets are among a company's most valuable assets. This is particularly true in the security and defence sector, where employees regularly have access to sensitive information and technical know-how. The article examines the legal framework governing trade secret protection in employment relationships and explains the safeguards already provided by the German Trade Secrets Act (Geschäftsgeheimnisgesetz – GeschGehG), as well as how these can be effectively complemented through employment contract provisions.

The authors also discuss recent case law of the German Federal Labour Court (Bundesarbeitsgericht – BAG) on confidentiality agreements. They explain why broad, generic confidentiality clauses are often insufficient and outline alternative contractual approaches available to employers. Particular attention is given to tiered confidentiality agreements for employees with access to particularly sensitive information, as well as additional legal instruments for protecting confidential business information.

While the article is primarily aimed at companies operating in the security and defence industry, it also provides valuable guidance for employers across all sectors seeking to align their trade secret protection strategies with the latest legal developments.

You can download the full article as a PDF here.

 

07/28/2026, Dr. Rembert Niebel, Alexander Möller

European Commission Publishes Guidance on the Cyber Resilience Act

The European Commission has published guidance on the implementation of the Cyber Resilience Act (CRA). The guidance is intended to support companies in the practical application of the regulation and provides clarification on a wide range of interpretative questions.

Among other topics, it addresses the scope of the Cyber Resilience Act, the classification of remote data processing solutions and open source software, substantial modifications to products, the determination of support periods, cybersecurity risk assessments, and the new reporting obligations. In addition, it includes numerous practical examples and decision-making aids, particularly for small and medium-sized enterprises (SMEs). The guidance therefore provides valuable support for the practical implementation of the new regulatory requirements.

The guidance is not legally binding. Nevertheless, it is expected to play a significant role in the interpretation and application of the Cyber Resilience Act in practice and provides companies with important guidance as they prepare for the new regulatory requirements.

The publication comes at an important point in time. As of 11 September 2026, the reporting obligations under the Cyber Resilience Act will apply. The product-specific requirements will apply to products placed on the market from 11 December 2027 onwards. Companies should use the remaining time to align their products, processes, and compliance structures with the new requirements at an early stage.

Further Information:

07/27/2026, Dr. Daniel Meßmer

Protection of Military Inventions: New Expert Article Published in RüSiR

How can military inventions be effectively protected without disclosing security-sensitive information? Our partner Markus von Fuchs addresses this question in his expert article, “The Protection of Military Inventions through Secrecy During Development, Commercialization and Infringement Proceedings”, published in the latest issue of RüSiR – Journal for Defence, Homeland Security, Cyber & Space.

Against the backdrop of an evolving security landscape and the growing importance of dual-use technologies, the article examines the challenges of protecting military innovations. It explains why traditional patent strategies do not always provide adequate protection in the defence sector and explores the role of secret patents and trade secret protection. The article also discusses how technological developments – particularly in the fields of drone and cyber technologies – influence the choice of appropriate protection strategies.

Another key focus is the legal framework governing secret patents under German law. The article outlines the requirements for classifying an invention as a secret patent, the procedures before the German Patent and Trade Mark Office (DPMA), and the legal implications of secrecy orders. It also examines the impact on patent infringement proceedings, security clearance requirements, and the commercial exploitation and licensing of security-relevant technologies.

Finally, the article demonstrates that the choice between patent protection and confidentiality has become an increasingly strategic decision. Particularly for technologies with short innovation cycles or significant security relevance, a multi-layered protection strategy – combining technical intellectual property rights with a robust confidentiality framework consisting of technical, organisational and contractual measures – may provide the most effective means of safeguarding innovation over the long term.

You can download the full article as a PDF here.

07/27/2026, Markus von Fuchs

CJEU Judgment on Geoblocking: The Limits of the Borderless Internet

While information on the internet is accessible worldwide at any time, its legal regulations and intellectual property rights are always subject to strict territorial limits. Anyone who publishes content online must therefore be aware of the risk of infringing third-party rights abroad. The Court of Justice of the European Union (CJEU) has now ruled that effective geoblocking can prevent such infringements in other countries (judgment of 9 July 2026, Case C-788/24 – Anne Frank Fonds).

 

The Anne Frank Case: Geoblocking as Protection Against Copyright Claims

The legal proceedings involved a dispute between the Anne Frank Fonds and the Anne Frank Stichting regarding the online publication of the diaries of the world-famous Jewish teenager. While the works are already in the public domain in Belgium, they remain partially protected by copyright in the Netherlands until 2037. The defendants published a scientific edition on a Belgian website but blocked access for users from the Netherlands using geoblocking. The Anne Frank Fonds nevertheless considered this an infringement of its copyrights, arguing that users could bypass the restriction via standard VPN services.

The CJEU ruled that an unauthorized "communication to the public" — and thus an infringement of the copyrights still existing in the Netherlands — does not occur, provided that the geographical restriction is effective. To achieve this, the block must primarily correspond to the latest state of the art. Absolute security is not required. A user-side circumvention by means of VPN services does not automatically render the restriction ineffective.

 

Relevance Beyond Copyright Law

At the same time, the CJEU emphasizes conversely that an active duty applies to anyone who knows or ought to know about existing intellectual property rights abroad. Anyone who, with knowledge of such rights, fails to implement effective geoblocking measures is deemed to be targeting their content at the entire global audience (para. 42 of the judgment). The CJEU left open when such knowledge (the duty to know) can be assumed. Previous business relationships or the existence of delimitation agreements could already be sufficient.

This duty by no means affects copyright law alone. Geoblocking is also playing an increasingly important role in trademark law. An infringement of a national trademark on the internet requires that the use of the trademark actually takes place within the domestic territory. In this context, courts examine whether the use of the sign produces a noticeable economic effect in the domestic market—the so-called "commercial effect".

Whether such a domestic nexus exists must generally be assessed based on the specific circumstances of each case. Relevant factors include, among others, the language of the website, the top-level domain, information provided on the website, or—if available—specific delivery options, as well as other circumstances such as economic activity in the country. Now confirmed by the CJEU, the absence of geoblocking measures is at least a strong, if not decisive, indication that the website in question is (also) directed at the domestic public. This is likely to be particularly relevant for global websites.

 

Liability of the Website Operator, Not the VPN Provider

According to the CJEU, it is solely the website operator who is liable for ineffective technical measures — not the VPN provider whose service is used to circumvent them. This applies even if the VPN provider is aware that its service can be used to access protected content without the rights holders’ consent.

 

Conclusion

The CJEU judgment provides much-needed clarity for online business practices. Geoblocking has become a central tool for legally secure market segmentation in intellectual property law. At the same time, the lack of geoblocking measures can indicate that accessing the content from abroad is intentionally desired. Conversely, anyone who deliberately restricts their online activities to specific countries and implements this technically soundly via geoblocking can effectively eliminate liability risks abroad.
 

07/20/2026, Sandra Sophia Redeker, Dr. Thomas Hohendorf

SKW Schwarz Advises IQM Quantum Computers on the Acquisition of Assets from Quantistry GmbH

SKW Schwarz has advised the Finnish quantum computing company IQM Quantum Computers on the acquisition of selected assets from Berlin-based Quantistry GmbH. The transaction strengthens IQM’s software and simulation capabilities and further expands its technology platform for industrial applications of quantum computing.

Through the transaction, IQM is acquiring proprietary software applications, algorithms, and intellectual property from Quantistry. In addition, Quantistry’s core technical and quantum chemistry team will join IQM. The acquisition enhances IQM’s capabilities, particularly for applications in the automotive, aerospace, chemicals, materials science, and pharmaceutical industries.

The transaction was completed shortly after IQM’s business combination with Real Asset Acquisition Corp., through which IQM became Europe’s first publicly listed quantum computing company and is now listed on Nasdaq.

IQM Quantum Computers (Nasdaq: IQMX), headquartered in Espoo, Finland, is a global leader in superconducting full-stack quantum computers. IQM employs more than 400 people and operates across Europe, Asia, and North America.

Quantistry is a Berlin-based developer of a cloud-native simulation workflow platform for chemistry and materials. The company develops software solutions for research and development applications in industries including automotive, aerospace, energy storage, and pharmaceuticals.

With this transaction, SKW Schwarz further strengthens its practice advising companies in the quantum computing sector. SKW Schwarz regularly advises companies in the quantum computing and deep tech sectors on M&A transactions as well as technology and regulatory matters. The firm works closely with an international network of specialized law firms on cross-border mandates.

 

Advisors to IQM Quantum Computers
SKW Schwarz, Munich: Tobias Rodehau (Lead Partner), Dr. Alexander Karst, Eva Bonacker (Counsel; all Corporate/M&A), Dr. Matthias Orthwein (IT & Digital Business), Maria Rothämel (Counsel, Public Law, Berlin), Alexander Möller (Employment, Frankfurt), Tamara Ulm (Associate, Employment)

07/20/2026, Tobias Rodehau, Dr. Alexander Karst, Eva Bonacker, Dr. Matthias Orthwein, Maria Rothämel, Alexander Möller, Tamara Ulm

CJEU: Consumers Cannot Waive Their 14-Day Right of Withdrawal When Signing Up for a Streaming Subscription

Is the supply of a streaming service to be classified as an offer of ‘digital content’ or of a ‘digital service’ within the meaning of Articles 2(11) and (16) of the Consumer Rights Directive 2011/83/EU (hereinafter the ‘CRD’)? With regard to this question, whether a waiver of the right of withdrawal is possible (digital content) or not (digital services), opinions differ sharply.

Austria's Supreme Court sought clarity and referred this question – which ultimately determines when consumers' right of withdrawal lapses and thus goes well beyond a mere semantic distinction – to the Court of Justice of the European Union (CJEU). On July 9, the CJEU ruled in favor of stronger consumer protection (Judgment of 9 July 2026, Case C-234/25).

 

Personalized Streaming Services Constitute ‘Digital Services’

Consumers who wish to access films, series, or live sports on Sky or other streaming platforms before the expiration of the 14-day withdrawal period are typically required to waive their right of withdrawal when concluding the contract. Article 16(1)(m) in conjunction with Article 2(11) CRD provides such an exception to the right of withdrawal laid down in Article 9(1) – but only for ‘digital content’.

Following the view of the European Commission and the Advocate General, which the CJEU has adopted, streaming subscriptions generally do not constitute ‘digital content’, but rather ‘digital services’, to which this exception does not apply. Instead, the consumer's right of withdrawal expires only once the streaming provider has fully performed the contractual service (Article 16(1)(a) in conjunction with Article 2(16) CRD).

Unlike the supply of ‘digital content’, the supply of a ‘digital service’ is ‘necessarily defined by the dynamic nature of the offering proposed by the trader concerned, which goes beyond the mere stable and, as the case may be, continuous provision of specific content.’ According to the CJEU, this is the case, in particular, where ‘the offering is designed to adapt to the consumer’s individual behaviour or expectations, or to influence the manner in which the consumer uses the services concerned, for example by recommending specific content to the consumer.’ Such recommendation systems are an integral part of virtually all modern streaming services, helping users navigate an overwhelming volume of available content.

 

No Risk of Abuse Due to Appropriate Compensation

Sky Österreich Fernsehen GmbH (hereinafter ‘Sky Austria’) was unsuccessful in arguing that such an interpretation would open the door to abuse. Sky Austria pointed out that subscription numbers typically spike when a popular series’ first or final season is released, or when decisive matches in football championships take place. If customers were able to cancel their subscription immediately after viewing such content, they could effectively receive this premium programming for free.

The CJEU held that the legislature had already addressed this concern in Article 14(3) CRD, which entitles the trader to compensation proportionate ‘to what has been provided until the time the consumer has informed the trader of the exercise of the right of withdrawal, in comparison with the full coverage of the contract.’ In this regard, the trader is not required to calculate this compensation purely on a time‑proportionate basis (pro rata temporis); it may instead take the market value of the service provided as a starting point in order to reflect the differences in economic value between the offered content (for example, the final stage of a sporting competition compared with a daily television series). In plain terms, this means the compensation a consumer owes could actually exceed the monthly subscription fee; either way, charging at least a pro-rata (time-proportional) fee remains permissible. Seen in this light, the CJEU ruling is likely to be a theoretical victory for consumers – in practice, not much is likely to change, and probably rightly so.

 

Applicability to German Law

Since the Austrian provision at the centre of this request, Section 18(1)(1) and (11) of the Distance and Off‑Premises Contracts Act (Fern‑ und Auswärtsgeschäfte‑Gesetz), essentially corresponds to Sections 356(5) and (6) of the German Civil Code (Bürgerliches Gesetzbuch), the decision can readily be transposed to German law. In addition, the CRD does not expressly refer to the law of the Member States for the interpretation of the term ‘digital content’, which is why that term must be interpreted autonomously and uniformly under EU law.

 

Outlook

With this decision, the CJEU is significantly shaking up the existing landscape of streaming subscriptions, particularly since, on the one hand, the architecture of streaming services in the form of recommendation systems is affected, and on the other hand, claims for compensation in the event of withdrawal following prior streaming consumption are likely to meet with little acceptance at first.

Indirectly, the decision is also likely to have repercussions for other streaming models – whether the streaming of music tracks and podcasts via Spotify, audiobooks via Audible, or the magazine subscription with the Süddeutsche Zeitung – wherever the provider's performance goes beyond the mere provision of a single digital item. The CJEU has thus cut a dogmatic swath that points far beyond the specific question referred. In economic terms, this swath will be less significant, since compensation fees will become established for the usage that occurred prior to withdrawal.

07/17/2026, Dr. Andreas Peschel-Mehner

KI-Flash: EDPB Publishes Guidelines on Web Scraping in the Context of Generative AI

Web scraping is practically indispensable for training large AI models – and, from a data protection perspective, one of the biggest open questions: who is liable if personal data ends up in a training dataset through the automated harvesting of the open internet? On 7 July 2026, the European Data Protection Board (EDPB) addressed this question in Guidelines 03/2026, presenting a concrete assessment framework for the first time. Having already reported on the EDPB's Opinion 28/2024 on AI models in an earlier KI-Flash, we now turn to this second major development from the same plenary session. We reported separately on the Guidelines on the Anonymization of Personal Data adopted at the same time. The new web scraping guidelines are likewise open for public consultation until 30 October 2026.

 

Web Scraping for AI Training Purposes

More precisely, web scraping refers to the automated extraction of large volumes of data from publicly accessible internet sources – one of the central methods for sourcing training data for generative AI models. Until now, there was no specific, EU-wide guidance on how this practice can be reconciled with the requirements of the GDPR. The new guidelines close this gap and build on the Opinion 28/2024 mentioned above, as well as on Guidelines 1/2024 on Article 6(1)(f) GDPR. They are addressed to private entities that scrape data themselves, engage third parties to do so, or use already-scraped datasets for training or fine-tuning.

 

Controllership: Who Is Responsible for the Scraping Process?

A key question in practice concerns the allocation of roles under data protection law: the EDPB clarifies that the entity carrying out the scraping is not automatically a controller within the meaning of the GDPR. What matters instead is who determines the purposes and means of the processing. If an AI developer engages a service provider to carry out scraping under documented instructions, that provider will generally qualify as a processor, while the developer is treated as the controller. Where an already-scraped dataset is reused by a third party, the scraper and the reusing AI developer are, in principle, separately responsible for their own respective processing. Only where both parties jointly determine the purposes and means does joint controllership come into consideration.

 

Transparency: When Does the Individual Duty to Inform Not Apply?

With controllership clarified, this also raises the question of adequate transparency: the information obligations under Articles 13 and 14 GDPR pose practical difficulties for controllers engaged in web scraping, since data subjects are often not individually identifiable where data is collected indirectly. The EDPB acknowledges that individual information may be dispensed with where it proves impossible or would involve disproportionate effort (Article 14(5)(b) GDPR). This exception, however, does not apply across the board; it requires weighing the effort involved against the impact on the data subjects concerned, considering the volume and age of the data and the safeguards already in place. As a minimum measure, the EDPB requires controllers in such cases to make the information publicly available, for instance through a privacy notice specifying the categories of data, the sources and, where possible, the characteristics of the crawler used.

 

Data Minimisation: Measures Before, During and After Collection

The principle does not rule out training on large volumes of data as such, but it does require that personal data not needed for the purpose should not be collected in the first place. The EDPB proposes a multi-layered set of measures to this end. Before collection, controllers should, among other things, consider using synthetic data, define precise selection criteria, and exclude websites that structurally contain particularly sensitive data or that technically oppose scraping, for example through robots.txt, ai.txt or CAPTCHA. During and after collection, syntax-based filtering, pseudonymization and anonymization come into consideration as well. In addition, the EDPB requires controllers to ensure data quality by relying on reliable sources, timestamping the data and carrying out sample checks, to meet the principle of accuracy.

 

Legitimate Interest as the Key Legal Basis

The question of which legal basis could justify any of this in the first place usually leads, in practice, to Article 6(1)(f) GDPR: consent is practically impossible to obtain in the case of indirect, large-scale collection, which is why web scraping for generative AI is regularly based on legitimate interest instead. The EDPB applies the familiar three-step test: the existence of a legitimate interest, the necessity of the processing, and a balancing of interests. As examples of legitimate interests, it cites the development of chatbots or improvements to threat detection. In the balancing exercise, particular weight is given to data subjects' ability to control their own data, possible chilling effects arising from a sense of being under surveillance, and data subjects' reasonable expectations, for example whether a website technically excludes scraping or whether the data was made recognizably and publicly available.

Where the balancing test comes out against the data subjects, mitigating measures such as opt-out lists, shortened retention periods or enhanced transparency measures can restore the lawfulness of the processing.

 

 

Special Categories of Personal Data

Handling sensitive data also poses a particular challenge: special categories of personal data under Article 9 GDPR are, in principle, subject to a prohibition on processing that can only be lifted where one of the exceptions under Article 9(2) GDPR applies. Because it is difficult to reliably rule out in advance that sensitive data will also be captured when scraping large volumes of data, the EDPB transposes the CJEU's reasoning in GC and Others (C-136/17), concerning the responsibility of search engine operators, to the web scraping context: the prohibition under Article 9(1) GDPR then applies only within the framework of the controller's responsibilities, powers and capabilities, provided the controller takes appropriate measures to prevent and delete such data before, during and after AI development. This transposition is subject to narrow conditions: it applies only where the activity is structurally comparable to that of a search engine, and only to the incidental, unintended capture of sensitive data.

 

Practical Note

Even though the guidelines have not yet been finally adopted, they already provide clear guidance that national supervisory authorities are likely to apply when reviewing existing and future training data pipelines. Companies that scrape data themselves, commission scraping, or purchase already-scraped datasets should promptly review their own documentation on the balancing of interests, data minimization measures and the handling of special categories of data against the criteria set out in the guidelines. The ongoing consultation also offers an opportunity to feed practical experience and concerns directly into the final text.

We would be glad to assist you in reviewing your training data pipelines for compliance with the new EDPB guidelines, as well as in preparing or updating your data protection documentation for AI training processes.

07/16/2026, Moritz Mehner, Marius Drabiniok, Dr. Oliver Hornung

Guidelines on the Anonymisation of Personal Data – European Data Protection Board (EDPB) Launches Public Consultation

On 7 July 2026, the EDPB published its long-awaited Guidelines on the anonymisation of personal data (“Guidelines”). These Guidelines are currently in draft form and are expected to be adopted following the public consultation process, which is open until 30 October 2026.

 

What is this about?

The key criterion for the application of the General Data Protection Regulation (“GDPR”) is the processing of personal data (“PD”). This concept is defined broadly in Article 4(1) GDPR. According to Recital 26, sentence 5 GDPR, the principles of data protection do not apply to anonymous information. Consequently, the GDPR does not apply to information that does not relate to an identified or identifiable natural person. Existing links between information and an identifiable individual can be removed through anonymisation.

Although this fundamental distinction in data protection law already existed before the GDPR came into force, determining when information has been anonymised to a legally sufficient standard remains both a technical and legal challenge in practice.

The former Article 29 Working Party had already addressed this issue in its respective Opinion from 2014. Over the past ten years, the Court of Justice of the European Union (CJEU) has also issued several judgments on the subject (see, for example, most recently the SRB decision).

 

Key Content of the Guidelines

The EDPB aims to provide greater clarity in distinguishing between anonymous information and personal data by establishing a practical assessment framework.

According to the EDPB, the three key criteria are No Record Isolation, No Linkage, and No Inference (see paragraphs 52 et seq. of the Guidelines).

The first criterion, No Record Isolation, requires that a dataset does not contain any attributes capable of identifying an individual. Considered on its own, the data must not constitute personal data.

The second criterion, No Linkage, builds on the first. It requires that the dataset cannot be linked to another dataset in a way that would enable the identification of a natural person.

The third criterion, No Inference, requires that no conclusions about a specific individual can be drawn from the available data. Such conclusions or inferences must also not be possible through the combination of the data with reasonably available additional information. In practical terms, it must not be possible to re-identify a natural person through analysis, linkage, or statistical inference.

These three criteria interact with one another and may be satisfied to varying degrees. What matters is that, when assessed as a whole, the information has been effectively anonymised (see paragraph 53 of the Guidelines).

 

What Happens Next?

The EDPB invites all interested stakeholders to participate in the public consultation until 30 October 2026. As discussions are currently ongoing at EU level regarding the GDPR-related provisions of the Digital Omnibus Act-which also focus (or have focused) on the concept of personal data-we expect a significant number of submissions.

In our view, the Guidelines represent an important step towards making the GDPR's requirements and the relevant case law on anonymisation more practical and easier to apply.

We will also publish an analysis once the final version of the Guidelines has been adopted.

07/15/2026, Dr. Stefan Peintinger, Martin Schweinoch

Youth Protection in Digital Services in the EU: The Commission’s Regulatory Push and What Providers Need to Know

Reddit Shows What Regulation Looks Like in Practice

On 24 June 2026, Reddit announced that it would automatically switch teen accounts in the EU to the most restrictive privacy settings – permanently locked in for 13- to 15-year-olds, set as a changeable default for 16- and 17-year-olds – and tie access to NSFW content to age verification going forward. The announcement came immediately after the European Commission’s third and final meeting of the “Special Panel on child safety online” on 16 June 2026, and coincided with ongoing DSA enforcement proceedings against several adult-content providers.

Reddit is responding to regulatory pressure coming from several directions at once. The European Commission is currently advancing youth protection in digital services not only through legislation and guidelines, but also through active enforcement. This article looks at the role the Digital Services Act (DSA) plays in this, who Article 28 DSA actually applies to, where matters are headed next, and which other rules apply alongside it.

The DSA at a Glance: A Tiered System of Obligations

The Digital Services Act (Regulation (EU) 2022/2065) has been fully applicable since 17 February 2024 and sets out the obligations of intermediary service providers in the EU. Its tiered system of obligations imposes requirements of varying scope depending on the type and size of the service – from basic transparency and reporting rules for all intermediary services, through additional obligations for hosting services and online platforms, up to the strictest requirements for very large online platforms and search engines (VLOPs/VLOSEs).

This tiering matters for correctly gauging the reach of individual provisions, such as Article 28 DSA discussed here: not every obligation applies to every service provider in the same way.

Who Does Article 28 DSA Actually Apply To?

Article 28 DSA is specifically addressed to providers of online platforms that are accessible to minors. What matters is not whether a service is expressly aimed at minors, but whether minors can access and use it at all. This covers, in particular, social networks, video and sharing platforms, and comparable services with user-generated content, such as Reddit. Under Article 19 DSA, micro and small enterprises within the meaning of EU Recommendation 2003/361/EC are exempt from the additional obligations for online platforms (Articles 19–28 DSA) and therefore also from Article 28 DSA. Purely B2B services and platforms without any meaningful accessibility to minors likewise fall outside the scope of the provision.

Nevertheless, this classification is not limited to traditional social networks. Even services that do not primarily function as social-media platforms could be covered, based on specific features typical of such platforms. 

If one or more of these features are present, services that are not traditional social media platforms may also be affected. Not least, this could include online games with public chat features or marketplaces for virtual goods, messaging services with public channels or groups, AI chatbots and virtual companions with personalized interaction, learning platforms with forums or social profiles, livestreaming services with viewer chat, as well as marketplaces and classifieds portals with user-generated listings. 

Whether an obligation under Article 28 DSA actually applies in a given case depends on an overall assessment. The decisive factors are, in particular, the wording of the terms and conditions as well as the actual user structure known to the provider—and not the service’s original target audience alone.

What the Guidelines Specifically Require from Providers

Article 28(1) DSA requires covered platforms to take appropriate and proportionate measures to ensure a high level of privacy, safety and security for minor users. The wording was deliberately left open and required further specification by the Commission.

That specification followed on 14 July 2025 in the form of guidelines containing a non-exhaustive list of risk-appropriate measures against grooming, harmful content, addictive design and cyberbullying. Key recommendations include:

  • Accounts of minors set to private by default, to guard against unwanted contact and data access;
  • Age verification for access to adult content (e.g. pornography, gambling), and age estimation where contractual minimum ages differ;
  • A risk-based approach that takes account of the platform’s nature, size, purpose and user base.

For platform operators, this may mean adjusting default settings, implementing technical age verification or estimation procedures, and documenting a risk assessment of their own service functions – the kind of measures Reddit has now put in place.

Digital Age Verification Is Coming: The EU Wallet on Its Way

In practice, the guidelines are complemented by the age-verification solution developed by the Commission (the “mini wallet”), which allows users to prove their age without disclosing any further personal data. It is technically compatible with the forthcoming EU Digital Identity Wallet and has been “feature ready” since 15 April 2026, meaning Member States and market participants can now build on it. The Commission is aiming for a Union-wide rollout of both solutions by the end of 2026. For platform operators, this points toward a single, EU-wide standard for age verification that is set to replace the patchwork of approaches used by providers so far.

How Old Is Old Enough? The Current EU Debate on Fixed Age Limits

At the same time, a fixed minimum age is under discussion. In a resolution of 26 November 2025, the European Parliament called for an EU-wide age limit of 16 for social media, video platforms and AI companions that pose risks to minors, subject to parental consent, together with a general access ban for children under 13. At national level, the expert commission “Child and Youth Protection in the Digital World,” set up by Federal Minister Karin Prien in September 2025, presented a total of 56 recommendations on 24 June 2026. According to press reports, these are said to include two alternative approaches: a statutory age limit of 13 combined with effective age verification, or service- and function-specific restrictions based on risk assessment. The ministry does not plan to publish the full recommendations until mid-July 2026. Minister Prien herself has already spoken out in favor of the first alternative. Neither approach has yet been implemented into binding law, but both signal that platform operators should prepare for stricter requirements.

Youth Protection: A Regulatory Patchwork

Depending on the specific service, other rules can apply alongside Article 28 DSA, including the German Youth Protection Act (Jugendschutzgesetz, JuSchG) for carrier media and certain gaming platforms, the Interstate Treaty on the Protection of Minors in the Media (Jugendmedienschutz-Staatsvertrag, JMStV) for telemedia with content that may impair development, the Audiovisual Media Services Directive (AVMSD) for video-sharing platforms, and the Unfair Commercial Practices Directive (UCPD) for issues such as loot boxes and manipulative in-game purchases. Which of these provisions apply alongside the DSA in a given case again depends on the specific service and its content.

Finding Your Way Through the Regulatory Jungle

As the example of Reddit shows, youth protection in the digital space is evolving dynamically across several levels at once. For providers, this adds up to an increasingly complex web of DSA rules, national law and consumer-protection requirements. We would be glad to help you navigate this regulatory environment and identify the obligations that specifically apply to your service.

07/09/2026, Moritz Mehner

SKW Schwarz Among the Top 10 Mid-Sized Employers for Career Starters

07/08/2026

Acquisition of Historical Monuments: Understanding the Associated Obligations

Purchasing a historical monument entails not only acquiring a valuable building but also assuming the legal obligations tied to its preservation. This is particularly true when the buyer is aware of the monument's status and the need for restoration - essentially, when the acquisition is made "with open eyes." Recent case law imposes stringent requirements in such instances, emphasizing that preservation, structural alterations, or even demolition of the monument should only be permitted under exceptional circumstances. The ruling by the Administrative Court of Würzburg on April 17, 2026 (Case No. W 5 K 25.782) illustrates that buyers in these situations face significantly heightened obligations to demonstrate compliance and provide evidence.

Historical monuments shape the character of German cities and towns more than any other element of the built environment. Historic town halls, late 19th-century villas, industrial facilities, and half-timbered houses contribute to the unique identity of local centers while documenting the social, economic, and architectural developments of past eras. They serve as vital testimonies to local history and often possess considerable scientific, artisanal, or artistic value. Visitors from countries with relatively young architectural histories may find it surprising that modern office spaces or hotels can be found within buildings several hundred years old. However, the continued use of historical structures is crucial for their preservation.

Under Article 70 of the German Basic Law (GG), monument protection law falls within the legislative competence of the federal states. Consequently, there are 16 state monument protection laws, each with varying regulations but all aimed at the protection and preservation of cultural monuments as witnesses to history, art, and culture. The core principle of all state laws is the obligation to preserve. Owners are required to maintain their monuments within reasonable limits and protect them from harm. This protection typically extends beyond the building itself to include its surroundings, provided they contribute to the monument's overall impact.

For owners, developers, and investors looking to alter or repurpose a monument, this often presents significant temporal, financial, and organizational challenges. Unlike standard building permit procedures, monument protection authorities frequently demand extensive documentation, restoration assessments, conservation concepts, and detailed plans and photographic documentation. Additionally, there are often repeated requests for further information, consultations with various specialized authorities, and lengthy approval processes. The implementation of economically viable repurposing concepts frequently encounters substantial resistance from monument protection authorities. Investors may feel that the principle of "everything remains as it is" is given undue weight over innovative and economically sensible solutions - even when prolonged vacancy threatens.

Particularly stringent requirements apply when an owner acquires a monument with full knowledge of its status and often significant restoration needs. In such cases, they cannot claim that the legal burdens of monument protection were unexpected. Rather, the courts expect that the buyer considers the specific requirements of monument protection law in their investment decision at the time of purchase. The more conscious the acquisition, the higher the demands for later proof of economic unfeasibility.

The extent of these heightened evidentiary obligations is exemplified by the ruling of the Administrative Court of Würzburg on April 17, 2026.

The case involved a former sanatorium built between 1906 and 1913 in Bad Kissingen, classified as a historical monument. The owner purchased the property with knowledge of its status and later applied for a permit to demolish the building. After the relevant monument protection authority denied the application, she filed a lawsuit with the Administrative Court.

The monument protection authority argued that the owner had knowingly acquired the property as a historical monument, thereby assuming the associated preservation obligations. Merely citing substantial renovation costs or failed negotiations with potential operators was insufficient to demonstrate economic unfeasibility. The plaintiff was required to substantiate that a monument-compliant use was permanently excluded and that serious marketing efforts had been unsuccessful over an extended period. However, she failed to provide such evidence.

The Administrative Court upheld this view. The claim of economic unfeasibility was rejected. The court found that the submitted economic viability assessment did not meet the high standards required for such proof. The focus was not on the individual financial situation of the owner but rather on the perspective of a property owner open to monument concerns. The critical question was whether the monument could, considering its unique characteristics, be economically self-sustaining.

This assessment was based on a comprehensible economic viability calculation, where renovation costs - adjusted for deferred maintenance and necessary building code measures - were compared against achievable revenues, potential funding, and tax benefits. A mere comparison of renovation costs with those of new construction was deemed insufficient, as this would typically lead to the economically most attractive solution being the demolition of protected buildings. Furthermore, the court required a usage and restoration concept coordinated with the State Office for Monument Preservation, along with a robust economic forecast covering approximately 15 years. Only the owner could develop realistic usage alternatives and provide the authority with a solid decision-making basis.

This ruling underscores that acquiring a monument "with open eyes" carries significant legal consequences. Those who consciously choose a restoration-needy historical monument also assume the risks associated with the preservation obligations tied to the property. Consequently, the requirements for demonstrating economic unfeasibility increase. Simple assertions of lack of profitability or failed marketing attempts are typically insufficient. Comprehensive documentation of marketing efforts, clear usage analyses, serious consideration of monument-compatible alternatives, and reliable economic calculations - ideally coordinated early with monument authorities - are essential.

For owners and developers, this leads to a clear course of action: the success of a monument protection approval process is often determined long before the actual application is submitted. A thorough inventory, meaningful plans and photographic documentation, robust usage and restoration concepts, and a meticulously documented examination of all monument-compatible alternatives are necessary. Only on this basis can the required economic assessment meet the high standards set by the courts.

However, this ruling is not only directed at owners and investors. Monument authorities are also called upon to support viable and economically feasible usage concepts and to engage constructively in dialogue with project developers. The long-term preservation of historical monuments is typically achievable only when monument protection and economic viability are not viewed as opposing forces. Historical structures can only be sustainably preserved if they can continue to be used meaningfully in the future. Therefore, the preservation of monuments is not a one-way street; it requires the willingness of all parties involved to develop practical and monument-compatible solutions.

07/06/2026, Maria Rothämel

SKW Schwarz recognised in multiple Leaders League Germany 2026 rankings

SKW Schwarz has been recognised in the latest Leaders League Germany 2026 rankings across four practice areas:
 

Germany – Best Law Firms for Data Protection – 2026
Recommended
Matthias Orthwein

Germany – Best Law Firms for IT & Outsourcing – 2026
Excellent
Oliver Hornung, Daniel Meßmer and Matthias Orthwein

Germany – Best Law Firms for Media, Sports & Entertainment – 2026
Highly recommended
Norbert Klingner and Andreas Peschel-Mehner

Germany – Best Law Firms for Trademark Litigation – 2026
Highly recommended
Dorothee Altenburg, Magnus Hirsch, Margret Knitter and Rembert Niebel
 

These rankings reflect SKW Schwarz's expertise in data protection, IT & outsourcing, media law and trademark litigation, and underline the firm's strength in advising clients at the intersection of technology, digital business, intellectual property and media.

We are delighted by this recognition and would like to thank our clients for their continued trust and confidence, as well as all our colleagues whose commitment and expertise contributed to this achievement.

About Leaders League
Leaders League is one of the internationally established legal directories, publishing annual rankings across numerous jurisdictions and practice areas. Its research is based on an independent assessment of market information, references and law firm submissions.

07/03/2026

KI Flash: When AI Answers Are No Longer Privileged

With two recent decisions, the Regional Courts of Munich I and Berlin II have, for the first time, taken a closer look at AI‑supported search and answer formats. Both cases concerned Google’s “AI Overview”.

Although the underlying facts differ, the core legal question in both decisions is essentially the same:

When does a platform have to treat the output of an AI feature as its own statement?

 

Search engines and many platform models typically act as aggregators and “technical tools” for finding third‑party content. As a rule, they benefit from liability privileges: they are usually only liable for third‑party content once they have actual knowledge of a legal violation and then fail to remove or block it (“notice and take‑down”). By contrast, they are generally directly liable for unlawful content that they themselves publish. This is precisely where the courts step in. 

Once platforms “adopt” third‑party content as their own, they are generally treated as if they had published it themselves.

The courts essentially apply this principle to AI‑generated outputs in these two decisions as well: if an AI output is understood as the provider’s own statement, courts no longer treat the service as a neutral intermediary. The special liability privileges enjoyed by classic search engines and host providers then apply only in a limited way, if at all. The provider is, in principle, liable as if it had authored the content itself. The two decisions take different approaches, but together they offer initial guidance on when courts tend in one direction or the other.

 

LG Munich I: “AI Overview” as the Provider’s Own Statement

In the case before the Regional Court of Munich I (judgment of 28 May 2026 – 26 O 869/26), a publishing company brought an action against Google in relation to the “Übersicht mit KI” (AI Overview) feature. When the company name is entered into the Google search bar, the autocomplete function already suggests, among other things, the term “Betrugsmasche” (“scam”). Once this suggestion is selected, an AI Overview appears above the conventional search results.

This overview consists of a continuous text in which the company is explicitly linked to allegations such as “unseriöse Geschäftspraktiken” (“untrustworthy business practices”), “Betrugsmasche” (“scam”) and “Abo‑Fallen” (“subscription traps”). The text is structured into several sections, includes links to third‑party websites, rephrases statements from sources in its own words and even contains concrete recommendations (“If you are dealing with …, be extremely cautious”, “If you have a subscription, try to cancel it in due time”, “If you receive unjustified demands, do not pay”). The overview also contains statements and conclusions that cannot be found in this form in the underlying sources.

The Munich court considers this AI Overview to be Google’s own substantive statement, not merely a technical display of third‑party content (paras. 33 et seq.). In particular, it stresses that:

  • the AI generates a self‑contained narrative text that summarizes, structures and evaluates search results in its own words,
  • it produces statements and links between pieces of information that are not contained in the underlying third‑party sources at all (so‑called “hallucinations”),
  • from the perspective of a reasonable average user, the AI overview appears as an answer provided by Google to the search query, not as a neutral list of results; the advisory elements reinforce this impression.

On this basis, the court assumes that Google has “adopted” the AI content as its own. Google is therefore liable for unlawful AI overviews, in particular for untrue, reputation‑damaging factual allegations about the claimant.

In addition, the court finds that it is not sufficient simply to switch off the specific AI answer. Due to the AI’s “black box” character, similar content may be generated again at any time; in the court’s view, the risk of repetition remains. Overall, the decision shows that for newly generated, chat‑like answers, there is a relatively low threshold for assuming “appropriation” (“Zu‑Eigen‑Machen”) at least where the text does not merely summarize search results, but goes beyond them by creating its own content, giving concrete recommendations and, as in this case, partly relying on technical errors (hallucinations).

 

LG Berlin II: AI Answers as Search/Information Format in Trademark Law

In the case before the Regional Court of Berlin II (judgment of 1 June 2026 – 52 O 62/26), the focus was on AI‑generated texts that mention the claimant’s branded perfumes and at the same time highlight so‑called “scent twins” (“Duftzwillinge”) as cheaper alternatives, including links to the respective sellers. The AI texts described which vendors offer scent twins to the claimant’s branded perfumes and guided users via links straight to the websites of these vendors. In terms of substance, they largely stayed within what was reflected in the regular search results displayed below. The claimant regarded this as use of its trademarks by Google to promote knockoff products.

The court, however, denies that Google used the marks in its own right in the sense of trademark law (Art. 9 UMV). The starting point is the basic trademark use requirement: use only occurs where the sign is employed in the context of the user’s own commercial communication, i.e. to designate or promote that party’s own goods or services.

The court relies again on the user’s perspective: a “reasonably well‑informed and reasonably observant user” perceives the AI texts as a search and information format, not as advertising or Google’s own product communication. Such a user recognizes that the content is based on third‑party websites, that Google operates a search engine aggregating such content, and that Google itself does not sell perfumes. The court further emphasizes that the AI texts merely reflect the actual search results and that each statement in the “Übersicht mit KI” is backed by a link to the corresponding search result; there is no evidence of targeted selection or steering in favor of specific sellers.

Against this background, the court concludes that, although Google does display the marks within the AI answer, this display does not amount to trademark use by Google as part of its own commercial communication. In this context, the court therefore rejects an “appropriation” of the AI outputs.

 

Common Approach and Practical Takeaways

At first glance, the two decisions lead to different outcomes, but they are not necessarily contradictory. Both courts ultimately pose the same question: does the AI output still look like a search/result format that merely improves the user experience, or does it appear as an independent statement by the provider?

The answer depends mainly on the format, structure and content of the respective output. Taken together, these decisions draw an initial, soft line: it is not only “purely fictional” AI content that can trigger direct liability. Even a genuinely independent substantive processing of search results – going beyond a neutral presentation of sources – can already lead courts to treat the content as the provider’s own.

For all providers of AI‑supported search and answer systems, the concept of “appropriation” thus remains a central risk factor: the more an AI output appears as a distinct, evaluative statement and the further it moves beyond the underlying sources, the more likely it is that the provider will be treated as if it had authored the content itself.

Which concrete adjustments are advisable in any given case – whether in product design, answer logic, disclaimers or notice‑and‑action processes – depends on the specific architecture of the system. We would be pleased to support you in assessing existing AI functionalities from a legal perspective and in developing appropriate safeguards.

07/02/2026, Moritz Mehner

Events

30

Focus topics

22

Expertise

30

Mixed

30

Further insights

Explore the latest legal developments, insights, publications and news from our firm.