Our competencies > AI Legal Advisory Services

AI Legal Advisory Services: Using Artificial Intelligence in a Legally Compliant Manner

AI is here – and it comes with new Legal Obligations

Whether it is ChatGPT, Midjourney or automated assistance systems, artificial intelligence (AI) has already become part of day-to-day business operations in many organisations. What many businesses are unaware of is that the EU AI Act has been applicable since February 2025 and has introduced clear requirements governing the use of AI in the workplace. Particularly relevant in practice is the obligation for companies using AI systems to ensure that their employees possess a sufficient level of AI literacy and receive appropriate training.

The image shows an artificial brain.

Legal Risks Associated with AI

The EU AI Act is only one element of the legal framework. The use of AI raises legal questions across several areas of law, including:

  • Data Protection Law: How should personal data be processed when using AI systems?
  • Copyright Law: Under what circumstances may AI-generated content be used?
  • Liability Law: Who bears responsibility for incorrect outputs or AI-assisted decisions?

Uncertainty regarding the use of AI may not only create legal risks but can also slow down innovation and business development.

Our Services: Clear Legal Solutions for the Use of AI

As a law firm specialising in data protection and IT law, we support businesses in the legally compliant implementation and governance of AI systems. Our services include:

  • Drafting and reviewing internal AI policies and guidelines
  • Employee training to promote AI literacy and awareness
  • Legal support for specific AI projects
  • Assessment and selection of external AI tools with regard to
  • data protection & liability risks

 

The image shows a modern paragraph symbol on a blue background.

FAQ

The use of AI within an organisation is lawful where the selection, implementation and operation of AI systems comply with all applicable legal requirements and are supported by clear internal rules and governance structures. Depending on the use case, relevant legal areas may include data protection, intellectual property law, unfair competition law, employment law and the requirements of the EU AI Act.

The legal framework governing the use of AI often includes the General Data Protection Regulation (GDPR), copyright law, patent law, unfair competition law, IT and cybersecurity requirements, employment law and sector-specific regulatory obligations. In addition, the EU AI Act is becoming increasingly important as the first comprehensive regulatory framework for artificial intelligence within the European Union.

An AI risk assessment should be conducted before the deployment of new AI use cases, particularly where AI systems process personal data, involve automated decision-making, or affect critical business processes such as human resources, compliance functions, or customer communications.

The EU AI Act adopts a risk-based approach. Depending on their role (e.g. provider, deployer, or importer), organisations may be subject to obligations relating to risk management, technical documentation, transparency and information requirements, human oversight, and employee training, particularly in relation to high-risk AI systems. In addition, Article 4 of the EU AI Act requires organisations to ensure that employees working with AI systems possess an adequate level of AI literacy and receive appropriate training.

Generative AI tools such as ChatGPT can support employees in their day-to-day work but should only be used in accordance with clear internal policies. These should include, in particular, approved tools, defined use cases, clear approval procedures, rules governing the handling of confidential information and personal data, as well as quality assurance and plausibility checks of AI-generated outputs. Without appropriate AI guidelines, organisations may face risks such as incorrect decision-making, data protection violations, breaches of confidentiality, loss of know-how and reputational damage.

There is no universal answer to this question. Whether certain information may be entered into an AI system depends on the specific tool, the intended use, the applicable contractual arrangements and the organisation’s internal policies. The key consideration is whether the relevant legal, contractual, and organisational requirements for the intended use are met. Particular caution should be exercised when handling personal data, confidential business information, customer data, contracts, trade secrets and other sensitive information.

Trade secrets and confidential information can be protected through a combination of an AI policy defining prohibited content (“no-go” inputs), approved enterprise AI tools, access restrictions, logging, confidentiality requirements, and appropriate contractual safeguards (e.g. ensuring that inputs are not used for model training, together with clear deletion and data protection obligations).

An AI policy or AI guideline should establish the framework for the secure, responsible and legally compliant use of artificial intelligence within the organisation. It should provide guidance on how AI systems are selected, used, reviewed and monitored, while defining key responsibilities and decision-making processes. The specific requirements will depend on the AI applications involved, the types of data processed, the intended use cases and the associated risk profile. An effective AI governance framework complements these policies by ensuring that AI applications are introduced and managed in a controlled manner, risks are appropriately assessed and mitigated, and internal requirements are continuously adapted to legal, technical and organizational developments.

  • We for you
  • Mario Schmieder
    Attorney | Partner
  • Simone Tober
    Attorney
  • Christian Eidenberger
    Attorney

Glossary

AI Act

An EU regulation governing artificial intelligence. It classifies AI systems according to their level of risk, establishes transparency obligations, and requires measures to promote AI literacy.

Compliance

The systematic adherence to applicable legal, regulatory and internal corporate requirements with the aim of mitigating legal, regulatory and ethical risks.