
We assist companies with the legal implementation and use of AI systems. In doing so, we review data protection, contractual relationships, governance, responsibilities, and regulatory requirements, and help ensure that the deployment of AI—from the initial idea through to full-scale operation—is legally sound and organizationally viable.
Unclear Legal Classification
AI projects combine technology, data processing, contract law, and governance. It is often unclear at the outset which obligations actually apply. We classify the specific use case and distinguish between mandatory requirements, reasonable safeguards, and purely theoretical risks.
Handling Personal and Business Data
Many AI systems process internal documents, customer data, or other confidential information. We review which data may be used, how data flows are structured, and what technical and organizational requirements are necessary for data input, storage, training, and further use.
Responsibility for AI Outcomes
Companies must determine who reviews, approves, and takes responsibility for AI-generated results. A purely technical process is not sufficient, especially when it comes to decisions with legal, financial, or operational implications. We help define appropriate control and escalation mechanisms.
Contracts with AI Providers
Standard terms and conditions from AI providers often address data usage, liability, availability, intellectual property, and subcontractors. We review these points and assess whether they align with the intended use and the company's risk profile.
We support companies, executive management, legal and compliance teams, and business units that are introducing AI applications for the first time or seeking to deploy existing solutions in a production environment as they implement AI systems. Our consulting services combine legal analysis with a pragmatic understanding of technology, data, contracts, and internal processes. Depending on the project, we conduct individual reviews or provide support throughout multiple project phases.
We analyze the specific use case, the data being used, the user groups, and the role of external providers. Based on this analysis, we identify the relevant legal requirements and outline which measures are necessary or recommended prior to the rollout.
We review legal bases, transparency, order processing, international data transfers, and the handling of confidential information. If necessary, we also provide support with data protection impact assessments and the documentation of data flows.
We review or negotiate license, SaaS, cloud, and contract manufacturing agreements for AI solutions. Our focus is particularly on data usage, training rights, intellectual property, liability, information security, subcontractors, and exit provisions.
We develop guidelines, approval processes, and role models for the use of AI. In doing so, we ensure that the rules are not only legally sound but also understandable and practical for employees and departments in their day-to-day work.
We provide support during the pilot phase, implementation, and ongoing operations. This allows new use cases, changes to provider terms, or additional data sources to be evaluated from a legal perspective and integrated into the existing governance framework.
We evaluate the specific application, not “AI” in the abstract. What matters are function, data, impacts, and actual risk.
Not every AI application requires the same governance. We distinguish between simple applications and use cases that require a more in-depth legal review.
We do not view AI applications in isolation; rather, we also examine vendor terms, data flows, confidentiality, and existing contractual relationships.
We work directly with senior management, Legal, Compliance, Product, IT, and external vendors, thereby avoiding unnecessary translation loops.