Skip to content
Back to mrpetzai.de Tuesday, September 22, 2026 Edition 7 · 7 stories
Mr. Petz AI MrPetzAI AI News The weekly briefing for AI decision-makers

AI and the law

Sorted by what is in force, what has been deferred and what is still open – with the source for every statement.

Text size

Few fields carry as much half-knowledge as this one. Deadlines are quoted that have been deferred, duties are declared urgent that do not yet exist, and the one duty that has actually applied since August is barely mentioned. This page separates the three.

Editorial status:

In force Labelling duty for AI content – since 2 August 2026

Article 50 of the AI Act applies. It covers not only the makers of AI systems but also the companies that use them. Four of its points hit ordinary business operations.

Anyone running a chatbot in customer contact must make it recognisable that the person is talking to a machine. AI-generated or altered images, video and audio must be marked in machine-readable form. Deepfakes must be disclosed. And text informing the public on matters of public interest needs a note on how it was produced.

Plain drafting assistance is not covered, as long as a human is responsible for the content and edits it substantially. Nor is internal communication within a closed group.

What this means for you

  • Chatbot on your website: a note at first contact, not buried in the terms of use.
  • AI images in advertising and social media: label them.
  • Put in writing where you draw the line between assistance and generation. You may have to justify that line.

Source: Verordnung (EU) 2026/1744

Deadline running For systems already in use: deadline 2 December 2026

Generative systems placed on the market before 2 August 2026 have a transition period. It ends on 2 December 2026. After that the labelling duty applies to them too.

What this means for you

  • By November, list which AI tools run in your company and what they produce. That list is the starting point for everything else.

Source: Verordnung (EU) 2026/1744

Deadline running High-risk AI: deferred to December 2027

The Digital Omnibus was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers the obligations for high-risk systems under Annex III – including recruitment software – to 2 December 2027. Product-embedded systems under Annex I follow on 2 August 2028.

This is where most half-knowledge starts. What is deferred are the Chapter III duties: risk management, data quality, logging, registration. What is not deferred are the prohibitions in Article 5, in force since 2 February 2025 – among them the ban on emotion recognition in the workplace.

What this means for you

  • If you use AI in recruitment you have more time for the formalities – but none for the ban on emotion recognition and none for anti-discrimination law.
  • Get a written commitment from your vendor that they will meet the high-risk requirements by December 2027.

Source: Verordnung (EU) 2026/1744

In force Data protection: no AI exemptions, but a few hard edges

There is no separate legal basis for AI. Article 6 GDPR applies as everywhere else, and it is assessed separately for each processing step: collection, training, provision, use, exploitation. For companies, legitimate interest is usually the workable route.

The European Data Protection Board clarified in December 2024 that an AI model is not automatically anonymous and that unlawfully collected training data can carry over into later use. So the line "we only use an off-the-shelf model" is no defence.

Under the German supervisory authorities' lists, a data protection impact assessment is regularly required once two criteria coincide. AI on its own already counts as innovative technology. Add any assessment of individuals – applicants, staff, customers – and the second condition is met.

It is open whether large model providers are processors or controllers in their own right. Supervisory authorities do not judge this uniformly.

What this means for you

  • Free consumer accounts are usually unusable for personal data, because inputs are used for training by default. Use a business plan with training contractually excluded, plus a data processing agreement.
  • For each application, record in writing which data categories go in and which legal basis you rely on. Without that record the accountability obligation is not met.

Source: EDSA-Stellungnahme 28/2024 (deutsche Fassung, PDF) · Orientierungshilfen der Datenschutzkonferenz · LfDI Baden-Württemberg: Rechtsgrundlagen beim Einsatz von KI

Open Data transfers to the United States: the wobbly point

The adequacy decision for the EU-US Data Privacy Framework is in force; a challenge was dismissed at first instance in September 2025. The appeal is pending before the Court of Justice; we are not aware of a decision.

A second risk has been added: following a US Supreme Court ruling of 29 June 2026 on the removability of FTC commissioners, the European Data Protection Board asked the Commission in late July 2026 to review the consequences for the framework. That authority's independence was a load-bearing assumption of the decision.

What this means for you

  • Do not wait for a judgment. Keep a list of every US service that receives personal data, and agree standard contractual clauses as a fallback.
  • Anyone who lived through the fall of the Privacy Shield in 2020 knows what an unprepared collapse means.

In force Advertising, reviews, prices

There is no special regime for AI in advertising. Unfair competition law applies: claiming "AI-powered" where no AI is at work is misleading. Anyone displaying customer reviews has had to state since May 2022 whether and how they verify that reviews come from actual buyers. Invented customer voices remain unlawful even when they merely summarise "typical" statements.

If a price is personalised on the basis of automated decision-making, the consumer must be informed. The calculation itself need not be disclosed.

A Digital Fairness Act against manipulative design patterns has been announced but not even published as a proposal. Anyone selling you compliance advice on it today is selling you a law that does not exist.

What this means for you

  • No AI-generated customer testimonials. No silent filtering of negative reviews.

Source: Legislative Train: Digital Fairness Act

Deadline running Liability: who pays when the AI gets it wrong

AI is not a legal person. It does not bear liability. The company that organises its use does – towards customers under contract law, towards third parties under tort law. "The AI wrote it that way" is not a defence.

Towards employees, the usual employee liability rules still apply: no liability for slight negligence, full liability only for gross negligence or intent. Staff must correct obvious errors, not verify every nuance.

The new EU Product Liability Directive expressly treats software as a product, including AI systems, and must be transposed into national law by 9 December 2026. The German process is under way. It affects those who manufacture or brand software or connected products – not those who merely use AI internally. There will be no separate AI Liability Directive; the Commission withdrew the proposal.

What this means for you

  • Your line of defence is organisation: a written policy, documented training, and a second pair of eyes on anything that leaves the building.
  • If you supply software or connected products: talk to your insurance broker before the transposition takes effect.

Source: BMJV: Modernisierung des Produkthaftungsrechts

Open Copyright: your AI content usually belongs to no one

An AI output enjoys copyright only where substantial human creative input can be shown. Choosing among suggestions and writing a general prompt do not suffice. In practice: a competitor may copy your AI image.

Conversely, you can very well infringe the rights of others – through recognisable image elements, trade marks or the personality rights of identifiable people. And the courts disagree: one ruling on training with third-party photos has been admitted to appeal, another against a model provider over song lyrics is under appeal. Neither is final.

If you do not want your own website content used for AI training, a sentence in your terms of use is not enough. The reservation must be machine-readable.

What this means for you

  • Do not generate your logo, brand mark and core motifs purely from AI – there you need protection.
  • Document prompt, tool, version and your own editing. That is your evidence in both directions.

In force Trade secrets: the most expensive click of the day

A trade secret is protected only for as long as it is subject to reasonable steps to keep it secret. Uploading company documents to a service allowed to use them for training can fail exactly that test – and the protection is lost retroactively, against everyone.

For those under professional secrecy – lawyers, doctors, tax advisers – criminal liability is added.

What this means for you

  • Switch off storage and training use in the tool and document that setting with a date. That record is your evidence of the reasonable step.
  • Block design data, formulations, draft contracts and client data from external services entirely.

In force Recruitment and works council

If an AI system discriminates during pre-selection, the employer is liable under German equal treatment law – regardless of who built the software and whether anyone intended to discriminate. The practical risk is proxy features: postcode, gaps in the CV, language patterns.

A fully automated rejection without human involvement is in principle inadmissible under Article 22 GDPR. The human in the loop must genuinely be able to decide, not merely wave things through.

Technical systems capable of monitoring conduct or performance trigger the works council's codetermination rights. Whether monitoring was intended is irrelevant.

What this means for you

  • Conclude a works agreement on AI use before rolling tools out – not afterwards.
  • Review rejection rates regularly by gender and age group. If you do not measure, you notice a skew first in court.

Source: Antidiskriminierungsstelle des Bundes: Rechtsgutachten zu algorithmischer Diskriminierung

In force Where to turn

Since July 2026 the Bundesnetzagentur has been Germany's central coordination and complaints body for the AI Act. It runs an AI service desk and a regulatory sandbox, expressly including small and medium-sized companies. That is the first address, and it is free.

Source: Bundesnetzagentur: KI-Servicedesk

And now the sentence that matters

Everything above is an overview, compiled with care and dated. It is not a substitute for a look at your specific case. Rules change, courts decide differently than expected, and what fits one company is wrong for the next.

So: ask your lawyer. We are happy to prepare the questions with you – that part we can do.

How this paper is made – sources and principles

Free subscription

Get the whole edition by email. Free of charge.

Every Tuesday morning, seven documented stories with what each one means for your decisions. One click to unsubscribe.

Subscribe free of charge

No costs, no advertising, no forwarding of addresses.

Free subscription

The whole edition free of charge by email.

Seven documented stories from research, public authorities and standardisation – and what they mean for executives, marketing, HR and sales. No costs, one click to unsubscribe.

Subscribe free

Double opt-in: nothing is sent before you confirm the link in the email.

Editorial principles

Always the original source

Every story names its source and links to it directly. We do not pass on information we cannot trace.

Interpretation, not excitement

Every story states what it means for decisions in your company – concretely, not as a buzzword.

Organised by country

The United States sets the pace, Germany sets the frame. The other markets follow by actual AI activity.