<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>jakub, Autor w serwisie KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/author/kglegal/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/author/kglegal/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Tue, 15 Sep 2026 19:35:31 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Longevity Washing, AI and the Regulatory Fault Lines of the Longevity Industry: A European Perspective</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/longevity-washing-ai-and-the-regulatory-fault-lines-of-the-longevity-industry-a-european-perspective/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/longevity-washing-ai-and-the-regulatory-fault-lines-of-the-longevity-industry-a-european-perspective/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 19:35:31 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[EU Regulatory Law]]></category>
		<category><![CDATA[European Health Data Space]]></category>
		<category><![CDATA[Food Supplements]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[Health Claims]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[Longevity Industry]]></category>
		<category><![CDATA[Longevity Washing]]></category>
		<category><![CDATA[Medical Devices Regulation]]></category>
		<category><![CDATA[Novel Foods]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8913</guid>

					<description><![CDATA[<p>Publication date: September 15, 2026 ABA ILS, Life Sciences and Healthcare Committee, September 2026Prepared by KIELTYKA GLADKOWSKI KG LEGAL I. Introduction The longevity economy is commonly estimated at several hundred billion dollars worldwide and continues to grow rapidly.[1] Venture capital flows into biotechnology companies that promise to slow, halt, or reverse aging. Clinics from Zurich [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/longevity-washing-ai-and-the-regulatory-fault-lines-of-the-longevity-industry-a-european-perspective/">Longevity Washing, AI and the Regulatory Fault Lines of the Longevity Industry: A European Perspective</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: September 15, 2026</strong></mark></p>



<figure class="wp-block-video"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/ABA_Call_Longevity_Presentation-wrzesien.mp4"></video></figure>



<p class="has-luminous-vivid-amber-background-color has-background has-large-font-size">ABA ILS, Life Sciences and Healthcare Committee, September 2026Prepared by KIELTYKA GLADKOWSKI KG LEGAL</p>



<span id="more-8913"></span>



<p class="has-medium-font-size">I. Introduction</p>



<p>The longevity economy is commonly estimated at several hundred billion dollars worldwide and continues to grow rapidly.<a href="#_ftn1" id="_ftnref1">[1]</a> Venture capital flows into biotechnology companies that promise to slow, halt, or reverse aging. Clinics from Zurich to Seoul to Miami sell “longevity programmes.” Supplement brands attach the word “longevity” to products ranging from NAD precursors to collagen powders. And yet the word “longevity” does not exist as a legal category in European Union law. There is no definition, no register, no certification scheme, and no authority empowered to decide what may or may not describe itself as a longevity product, a longevity clinic, or a longevity company.</p>



<p>The gap between an enormous market and a non-existent legal definition is precisely where legal risk accumulates. Where there is no definition, there is classification risk, claims risk, and enforcement risk. There is also a phenomenon that this article, borrowing from the vocabulary of environmental marketing, calls “longevity washing.”</p>



<p>This article examines the longevity industry through the lens of EU regulatory law. The EU framework governs a market of some 450 million consumers and, because it is horizontal, sector-specific, and increasingly enforcement-oriented, it offers a useful point of comparison for practitioners in the United States, Asia, and Latin America. Part II explains why “longevity” is not a legal category and introduces the borderline-product problem that follows from that fact. Part III develops the concept of longevity washing and its consumer-facing, unfair-commercial-practice, and investor-facing dimensions. Part IV addresses the regulation of artificial intelligence in longevity research and diagnostics, including the revised timeline of the AI Act, the position of the European Medicines Agency on AI in the medicinal-product lifecycle, and the data-protection architecture formed by the GDPR and the European Health Data Space. Part V maps the sectoral “hot spots” across pharmaceuticals, medical devices, cosmetics, and food supplements. Part VI draws conclusions for practitioners.</p>



<h3 class="wp-block-heading">II. “Longevity” in the Eyes of the Law: The Borderline-Product Problem</h3>



<p>In EU regulatory law, aging is not a disease. The European Medicines Agency has never approved a medicinal product with “aging” as a therapeutic indication, and under Directive 2001/83/EC a medicinal product is defined by reference to the treatment or prevention of disease or the restoration, correction, or modification of physiological functions.<a href="#_ftn2" id="_ftnref2">[2]</a> The position in the United States is comparable. The long-running debate around the Targeting Aging with Metformin (TAME) trial illustrates the point: its designers had to negotiate a trial protocol with the Food and Drug Administration that targets aging indirectly, through a composite of age-related diseases, precisely because “aging” itself is not an approvable indication.<a href="#_ftn3" id="_ftnref3">[3]</a></p>



<p>The consequence is profound. A company cannot lawfully market a product “to treat aging.” The entire longevity industry therefore operates in the space of indirect claims: “supports healthy aging,” “promotes cellular health,” “extends healthspan.” Each of those phrases pushes the product toward one of several very different regulatory regimes.</p>



<p>This is the borderline-product problem, and it is the single most important legal concept in the sector. The same molecule – an NAD precursor, for example – may be: a medicinal product, if it is presented as treating or preventing disease or exerts a significant pharmacological, immunological, or metabolic effect; a food supplement under Directive 2002/46/EC;<a href="#_ftn4" id="_ftnref4">[4]</a> a novel food requiring pre-market authorisation under Regulation (EU) 2015/2283;<a href="#_ftn5" id="_ftnref5">[5]</a> a cosmetic under Regulation (EC) No 1223/2009, if applied to the skin with a claim limited to appearance;<a href="#_ftn6" id="_ftnref6">[6]</a> or a medical device. The last category is broader than it may appear: since the Medical Device Regulation (MDR) came into application, products listed in its Annex XVI – dermal fillers, certain energy-based aesthetic equipment – are regulated as devices even where they have no medical purpose at all.<a href="#_ftn7" id="_ftnref7">[7]</a></p>



<p>Classification does not follow the label a company chooses. It follows presentation, composition, and route of administration. The Court of Justice of the European Union has held for four decades that a product is a medicinal product “by presentation” where it is described or recommended as having properties for treating or preventing disease, irrespective of whether it actually has those properties; and that classification “by function” turns on a case-by-case scientific assessment of the product’s actual pharmacological, immunological, or metabolic action, not on the manufacturer’s intention.<a href="#_ftn8" id="_ftnref8">[8]</a> Marketing language alone can therefore reclassify a product and, with it, the entire compliance burden: marketing authorisation, good manufacturing practice, pharmacovigilance, and advertising restrictions.</p>



<p>When a client says “we are a longevity company,” the first question counsel should ask is: <em>which regime are you actually in?</em> “Longevity” is a marketing word. The law knows only medicines, devices, foods, and cosmetics.</p>



<h3 class="wp-block-heading">III. Longevity Washing: When the Claim Outruns the Science</h3>



<p>Greenwashing – claiming environmental virtue one does not have – is a familiar concept. Longevity washing is its younger sibling: labelling a product, a clinic, a research programme, or an entire company as “longevity-focused” when the science, the indication, or the business model does not support that description. The practice matters legally for three reasons.</p>



<h2 class="wp-block-heading"><em>A. Consumer-Facing Claims</em></h2>



<p>Under the Health Claims Regulation, any health claim made on a food – and food supplements are foods – must be specifically authorised and listed in the EU register.<a href="#_ftn9" id="_ftnref9">[9]</a> Claims such as “slows aging,” “supports cellular repair,” or “extends lifespan” are not authorised health claims. National authorities in the EU and the United Kingdom have treated phrases such as “cellular repair” and even “healthy aging” as impermissible where they imply a physiological mechanism or a reduction of disease risk. A substantial part of the longevity supplement market is thus operating with claims that would not survive enforcement scrutiny.</p>



<h2 class="wp-block-heading"><em>B. Unfair Commercial Practices and the Greenwashing Template</em></h2>



<p>The second layer is the general prohibition of misleading commercial practices under the Unfair Commercial Practices Directive (UCPD).<a href="#_ftn10" id="_ftnref10">[10]</a> Here the EU has recently built an entire enforcement architecture against greenwashing that repays close study by anyone advising on health claims. The Empowering Consumers for the Green Transition Directive amends the UCPD to prohibit generic environmental claims – “eco-friendly,” “climate-neutral” – unless the trader can demonstrate recognised excellent environmental performance, and it adds a series of specific greenwashing practices to the UCPD’s blacklist. Its provisions apply across the Union from 27 September 2026.<a href="#_ftn11" id="_ftnref11">[11]</a></p>



<p>The Directive should be read as a template. If “climate-neutral” now requires substantiation, it is a very short doctrinal step for regulators and courts to demand the same of “clinically proven to slow biological aging.” The methodology of anti-greenwashing enforcement – generic claim, absence of substantiation, misleading omission – maps directly onto longevity claims. The UCPD’s general clauses on misleading actions and omissions already provide the legal basis; what the green-claims reform supplies is a worked example of how those clauses can be operationalised against vague virtue-signalling.</p>



<h2 class="wp-block-heading"><em>C. Investor-Facing Washing</em></h2>



<p>The third dimension is of particular relevance to transactional lawyers. Start-ups increasingly brand themselves as “longevity biotech” because that is where the capital is, even when the underlying asset is a conventional dermatology product or a wellness application. For investors, this creates due-diligence risk: is the “longevity platform” in fact a regulated medicinal pipeline, with all the timeline and cost that implies, or a supplement business one enforcement letter away from relabelling? Misclassification discovered after investment is a valuation event. For the company, aggressive longevity framing in fundraising materials can generate liability under securities and misrepresentation rules in multiple jurisdictions. In due diligence on a longevity start-up, the regulatory classification memorandum is not an annex to the deal; it <em>is</em> the deal.</p>



<h3 class="wp-block-heading">IV. Artificial Intelligence in Longevity Research and Diagnostics</h3>



<p>The longevity field is arguably the most AI-dependent sector in the life sciences, for a simple reason: aging is not one target but thousands of interacting biological processes. A geroprotective drug cannot be designed the way an antibiotic is designed. The entire aging phenotype must be modelled, and that means machine learning on large multi-omic datasets. AI is not an add-on in longevity; it is the core methodology. That raises three distinct regulatory questions under EU law.</p>



<h2 class="wp-block-heading"><em>A. The AI Act</em></h2>



<p>Regulation (EU) 2024/1689, the AI Act, is the most comprehensive horizontal AI regulation in force anywhere and applies to almost every AI system used in the longevity value chain.<a href="#_ftn12" id="_ftnref12">[12]</a> It adopts a risk-based structure – prohibited practices, high-risk systems, transparency obligations, and minimal-risk systems – and the critical category for this sector is high-risk. An AI system that is itself a medical device, or a safety component of one, under the MDR or the In Vitro Diagnostic Regulation, and that is subject to third-party conformity assessment under those instruments, is high-risk under Article 6(1) and Annex I of the AI Act.<a href="#_ftn13" id="_ftnref13">[13]</a> This captures, for example, an AI tool that estimates a patient’s “biological age” from a blood panel and uses that estimate to guide a clinical intervention; an AI-driven diagnostic that predicts age-related disease risk; and the software layer of many longevity-clinic platforms once it makes a diagnostic or prognostic claim.</p>



<p>High-risk status is not a prohibition; it is a compliance regime. It requires a risk-management system, data governance with representative and bias-tested training data, technical documentation, logging, human oversight, transparency to deployers, accuracy, robustness and cybersecurity, a conformity assessment, and post-market monitoring.<a href="#_ftn14" id="_ftnref14">[14]</a> For most longevity start-ups this is a wholly new compliance layer on top of MDR conformity assessment, and the two must be coordinated.</p>



<p>The timeline has recently changed, and practitioners should update their advice accordingly. The original AI Act applied the high-risk obligations from 2 August 2026 for stand-alone systems listed in Annex III and from 2 August 2027 for AI embedded in products covered by Annex I, including medical devices. The Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744 and in force since 27 July 2026, defers those dates to 2 December 2027 and 2 August 2028 respectively.<a href="#_ftn15" id="_ftnref15">[15]</a> The deferral does not lighten the substantive regime; the prohibitions in Article 5, the obligations of providers of general-purpose AI models, and the transparency obligations of Article 50 (which apply from 2 August 2026) are unaffected. For longevity companies whose AI is a medical device, the practical effect is a compliance window of roughly two years, during which harmonised standards and notified-body capacity are expected to mature. The window is an opportunity to design AI Act compliance into the MDR technical file from the outset rather than to defer the exercise.</p>



<h2 class="wp-block-heading"><em>B. AI in Drug Discovery and the European Medicines Agency</em></h2>



<p>The position for drug discovery is more nuanced. An AI model used purely internally to identify candidate molecules – the classic “AI for drug discovery” use case that dominates longevity-biotech pitch decks – is generally not, in itself, a high-risk AI system under the AI Act, because it does not make or materially influence decisions about individual patients. The regulatory question shifts instead to the European Medicines Agency. The EMA’s Reflection Paper on the use of AI in the medicinal product lifecycle sets out the Agency’s expectations from discovery through pharmacovigilance.<a href="#_ftn16" id="_ftnref16">[16]</a> Its core message is that the burden of proof rests on the sponsor to demonstrate that the AI model is fit for its regulatory purpose. That entails documented data provenance, model validation, a degree of explainability appropriate to the stage of development, and lifecycle management of the model itself.</p>



<p>If a longevity company tells its investors that “our AI discovered this molecule,” the regulator will eventually ask to see the model, the training data, and the validation. Vague AI claims in fundraising materials do not survive regulatory scrutiny and, increasingly, do not survive investor due diligence either.</p>



<h2 class="wp-block-heading"><em>C. Data: The GDPR and the European Health Data Space</em></h2>



<p>The third question concerns data, and it is here that longevity becomes uniquely difficult. Aging research is inherently longitudinal and multi-omic: genomic, epigenetic, and proteomic data, wearable data, and medical records, ideally across decades. Under the General Data Protection Regulation this is special-category data – health, genetic, and biometric data – and the available lawful bases are narrow.<a href="#_ftn17" id="_ftnref17">[17]</a> The scientific-research provisions of Article 9(2)(j) and Article 89 assist, but they are implemented differently in each Member State, which produces real fragmentation for pan-European longevity cohorts.</p>



<p>The European Health Data Space Regulation adds a second layer.<a id="_ftnref18" href="#_ftn18">[18]</a> It creates, for the first time, a mandatory EU-wide framework for the secondary use of electronic health data, administered by health-data-access bodies in each Member State. For longevity research the EHDS is potentially transformative, because it opens access to population-scale health data for research purposes. It also imposes strict conditions: purpose limitation, processing only within secure processing environments, a prohibition on re-identification, and specific prohibitions on using the data for advertising or marketing, for decisions detrimental to individuals such as insurance or employment decisions, or for developing products harmful to health.<a id="_ftnref19" href="#_ftn19">[19]</a> The secondary-use chapter applies from March 2029 for most data categories, but the lead time is short in the context of longitudinal cohorts. Longevity companies that intend to monetise health data – and many do – should be mapping their data flows against the EHDS regime now.</p>



<h3 class="wp-block-heading">V. Sector-by-Sector Regulatory Hot Spots</h3>



<p>Four sectoral silos together make up the longevity industry, and the same start-up frequently straddles two or three of them without realising it. In each silo, specific “hot spots” – advertising, manufacturing standards, registration, and market withdrawal – recur in practice.</p>



<h2 class="wp-block-heading"><em>A. Pharmaceuticals</em></h2>



<p>True longevity drugs – rapamycin analogues, senolytics, geroprotectors – sit squarely within Directive 2001/83/EC and its implementing rules, and will continue to do so under the new pharmaceutical package once it applies. Three practical hot spots stand out. First, off-label prescribing of rapamycin and metformin for longevity indications is widespread in private clinics across Europe. Off-label prescribing as such is a matter of clinical freedom, but off-label <em>promotion</em> by or on behalf of the marketing-authorisation holder is prohibited: advertising must conform to the summary of product characteristics, and advertising of unauthorised products or indications is not permitted.<a href="#_ftn20" id="_ftnref20">[20]</a> Longevity clinics are increasingly the vehicle through which promotional messaging reaches patients, and enforcement authorities have begun to take notice. Second, good manufacturing practice: anything presented as a medicine must be manufactured under an EU manufacturing authorisation and EU GMP, with qualified persons and full traceability; compounding pharmacies producing “longevity peptides” have become a significant enforcement target. Third, unlicensed importation: a large part of the longevity-peptide market operates through personal importation and grey channels, and customs enforcement across the EU has visibly tightened.</p>



<h2 class="wp-block-heading"><em>B. Medical Devices</em></h2>



<p>The MDR has fundamentally reshaped this space. Aesthetic devices – dermal fillers, energy-based devices used in longevity clinics, at-home devices marketed for “cellular rejuvenation” – are caught by Annex XVI even without a medical purpose. Three hot spots follow. Classification: many longevity wearables and applications become software as a medical device once they make a diagnostic or prognostic claim. Advertising: Article 7 of the MDR prohibits misleading claims and specifically prohibits ascribing to a device functions and properties it does not have, which operates in practice as a codified anti-washing rule for devices.<a href="#_ftn21" id="_ftnref21">[21]</a> Registration and vigilance: the first four modules of the EUDAMED database – actor registration, UDI/device registration, notified bodies and certificates, and market surveillance – have been mandatory since 28 May 2026, with legacy devices to be registered by 28 November 2026; the vigilance module is not yet mandatory, so serious incidents and field safety corrective actions continue to be reported to national competent authorities.<a href="#_ftn22" id="_ftnref22">[22]</a> Market withdrawals happen: a device sold as a “cellular biomarker analyser” without valid clinical evidence can be removed from the market by any national competent authority, and the MDR’s market-surveillance coordination means that one withdrawal can cascade across the Union.</p>



<h2 class="wp-block-heading"><em>C. Cosmetics and Aesthetic Products</em></h2>



<p>The Cosmetics Regulation governs anti-aging creams, serums, and topical actives. Two hot spots dominate. The first is the Product Information File: the responsible person must hold a complete file including a safety assessment and substantiation of every claim. The second is the Claims Regulation, Commission Regulation (EU) No 655/2013, with its six common criteria: legal compliance, truthfulness, evidential support, honesty, fairness, and informed decision-making.<a href="#_ftn23" id="_ftnref23">[23]</a> A claim such as “reverses skin aging at the cellular level” fails the evidential-support criterion unless a robust dossier stands behind it. Enforcement is largely national, but the Cosmetic Products Notification Portal is EU-wide, and non-compliant products are routinely notified through the Safety Gate rapid-alert system.</p>



<h2 class="wp-block-heading"><em>D. Food Supplements and Novel Foods</em></h2>



<p>It is in the food and supplement space that the longevity industry is most creative and most exposed. Directive 2002/46/EC governs vitamins and minerals in supplements; everything else falls under the general food law of Regulation (EC) No 178/2002<a href="#_ftn24" id="_ftnref24">[24]</a> and, critically, the Novel Food Regulation. Nicotinamide mononucleotide (NMN), one of the most heavily marketed longevity molecules, is the paradigmatic case. NMN is treated as a novel food in the EU, which means it cannot lawfully be placed on the market as a supplement without pre-market authorisation by the Commission following an EFSA safety assessment. Nicotinamide riboside received such an authorisation in 2020.<a href="#_ftn25" id="_ftnref25">[25]</a> NMN has not – although the picture is now moving. In March 2026 EFSA’s NDA Panel adopted a positive opinion on the safety of β-NMN in food supplements at up to 300 mg per day for adults, and the opinion was published in May 2026.<a href="#_ftn26" id="_ftnref26">[26]</a> An EFSA opinion is a scientific assessment, not an authorisation; the Commission must still adopt an implementing act adding NMN to the Union list, and where the applicant has requested data protection the authorisation will initially be proprietary to that applicant’s specification. Until that act is adopted, NMN products on the shelves of European longevity clinics remain unauthorised novel foods. That is not a grey area; it is a non-compliant market operating in plain sight, and it is the kind of enforcement pipeline that eventually produces high-profile withdrawal actions. Once the Health Claims Regulation is added to the picture, the conclusion is unavoidable: the food and supplement leg of the longevity industry is the most legally exposed part of the entire sector.</p>



<h1 class="wp-block-heading">VI. Conclusions</h1>



<p>The longevity industry is a genuine scientific and commercial phenomenon, and much of the underlying research is serious. But lawyers advising companies, investors, clinicians, and, increasingly, regulators in this space must see it clearly: “longevity” is not a legal category. It is a marketing frame layered on top of four very different regulatory regimes. Three practical conclusions follow for anyone whose product touches European consumers.</p>



<p>First, always begin with classification. The word “longevity” conveys nothing about the applicable regime. Ask what the product is, how it is presented, and what it does, and let the regulatory regime follow from those answers.</p>



<p>Second, treat longevity claims the way green claims are now treated. The direction of enforcement is unmistakable. The Empowering Consumers for the Green Transition Directive, applicable from 27 September 2026, gives regulators a sharpened toolkit that will, sooner or later, be pointed at health and wellness claims. Substantiation is no longer optional.</p>



<p>Third, integrate AI Act compliance with sectoral compliance from the outset. For any longevity venture using AI in diagnostics or patient-facing decision support, the AI Act, the MDR, and the GDPR, soon joined by the European Health Data Space, form a single interlocking compliance architecture. The deferral of the AI Act’s high-risk obligations to 2027 and 2028 is a design window, not a reprieve. Retrofitting is expensive; designing for compliance is not.</p>



<p>The longevity industry will keep growing, and regulators will keep catching up. The lawyers who understand both the science and the sectoral map will be the ones clients call first.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a href="#_ftnref1" id="_ftn1">[1]</a> Longevity economy estimates vary widely by definition; see, e.g., the periodic longevity-market reports of Bank of America Global Research and McKinsey Health Institute. The figure is offered here as an order of magnitude, not a precise valuation.</p>



<p><a href="#_ftnref2" id="_ftn2">[2]</a> Directive 2001/83/EC of the European Parliament and of the Council of 6 November 2001 on the Community Code Relating to Medicinal Products for Human Use, art. 1(2), 2001 O.J. (L 311) 67 [hereinafter Directive 2001/83]. At the time of writing, the new EU pharmaceutical package (a new directive on the Union code for medicinal products for human use and a new regulation on Union authorisation procedures) has been politically agreed and is in the final stage of formal adoption; the substantive rules discussed here are carried over into the new framework, which will apply after a transitional period of approximately two years from entry into force.</p>



<p><a href="#_ftnref3" id="_ftn3">[3]</a> See Nir Barzilai et al., Metformin as a Tool to Target Aging, 23 Cell Metabolism 1060 (2016) (describing the design of the Targeting Aging with Metformin (TAME) trial around a composite of age-related diseases).</p>



<p><a href="#_ftnref4" id="_ftn4">[4]</a> Directive 2002/46/EC of the European Parliament and of the Council of 10 June 2002 on the Approximation of the Laws of the Member States Relating to Food Supplements, 2002 O.J. (L 183) 51.</p>



<p><a href="#_ftnref5" id="_ftn5">[5]</a> Regulation (EU) 2015/2283 of the European Parliament and of the Council of 25 November 2015 on Novel Foods, 2015 O.J. (L 327) 1 [hereinafter Novel Food Regulation].</p>



<p><a href="#_ftnref6" id="_ftn6">[6]</a> Regulation (EC) No 1223/2009 of the European Parliament and of the Council of 30 November 2009 on Cosmetic Products, 2009 O.J. (L 342) 59 [hereinafter Cosmetics Regulation].</p>



<p><a href="#_ftnref7" id="_ftn7">[7]</a> Regulation (EU) 2017/745 of the European Parliament and of the Council of 5 April 2017 on Medical Devices, Annex XVI, 2017 O.J. (L 117) 1 [hereinafter MDR]; Commission Implementing Regulation (EU) 2022/2346 of 1 December 2022 Laying Down Common Specifications for the Groups of Products Without an Intended Medical Purpose Listed in Annex XVI, 2022 O.J. (L 311) 60.</p>



<p><a href="#_ftnref8" id="_ftn8">[8]</a> Case 227/82, Van Bennekom, ECLI:EU:C:1983:354 (establishing that a product is a medicinal product “by presentation” where it is described or recommended as having therapeutic or prophylactic properties, irrespective of its actual efficacy); Case C-319/05, Comm’n v. Germany, ECLI:EU:C:2007:678 (garlic capsules); Case C-140/07, Hecht-Pharma GmbH v. Staatliches Gewerbeaufsichtsamt Luneburg, ECLI:EU:C:2009:5 (classification “by function” requires a case-by-case assessment of pharmacological, immunological or metabolic properties). See also Directive 2001/83, supra note 2, art. 2(2) (in cases of doubt, the medicinal-products regime prevails).</p>



<p><a href="#_ftnref9" id="_ftn9">[9]</a> Regulation (EC) No 1924/2006 of the European Parliament and of the Council of 20 December 2006 on Nutrition and Health Claims Made on Foods, arts. 10, 13, 14, 2006 O.J. (L 404) 9 [hereinafter Health Claims Regulation]. The EU Register of nutrition and health claims is maintained by the European Commission.</p>



<p><a href="#_ftnref10" id="_ftn10">[10]</a> Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 Concerning Unfair Business-to-Consumer Commercial Practices in the Internal Market, 2005 O.J. (L 149) 22 [hereinafter UCPD].</p>



<p><a href="#_ftnref11" id="_ftn11">[11]</a> Directive (EU) 2024/825 of the European Parliament and of the Council of 28 February 2024 Amending Directives 2005/29/EC and 2011/83/EU as Regards Empowering Consumers for the Green Transition, OJ L, 2024/825, 6.3.2024 [hereinafter ECGT Directive]. Member States were required to transpose the Directive by 27 March 2026; its provisions apply from 27 September 2026. The separate Green Claims Directive proposal, which would have introduced ex ante verification of explicit environmental claims, was withdrawn by the Commission in 2025 and is not discussed here.</p>



<p><a href="#_ftnref12" id="_ftn12">[12]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 Laying Down Harmonised Rules on Artificial Intelligence, OJ L, 2024/1689, 12.7.2024 [hereinafter AI Act].</p>



<p><a href="#_ftnref13" id="_ftn13">[13]</a> AI Act, supra note 12, art. 6(1) &amp; Annex I, § A (listing the MDR and Regulation (EU) 2017/746 on in vitro diagnostic medical devices). The Annex I route applies where the AI system is a product, or a safety component of a product, that is itself subject to third-party conformity assessment under the listed Union harmonisation legislation.</p>



<p><a href="#_ftnref14" id="_ftn14">[14]</a> AI Act, supra note 12, arts. 9–15, 17, 43, 72.</p>



<p><a href="#_ftnref15" id="_ftn15">[15]</a> Regulation (EU) 2026/1744 of the European Parliament and of the Council Amending Regulation (EU) 2024/1689 as Regards the Simplification of Certain Obligations (“Digital Omnibus on AI”), OJ L, 2026/1744, 24.7.2026 (in force 27 July 2026). The Regulation defers the high-risk obligations for stand-alone (Annex III) systems to 2 December 2027 and for AI embedded in products covered by Annex I, including medical devices, to 2 August 2028; the Article 50 transparency obligations continue to apply from 2 August 2026.</p>



<p><a href="#_ftnref16" id="_ftn16">[16]</a> Eur. Medicines Agency, Reflection Paper on the Use of Artificial Intelligence (AI) in the Medicinal Product Lifecycle, EMA/CHMP/CVMP/83833/2023 (adopted Sept. 2024).</p>



<p><a href="#_ftnref17" id="_ftn17">[17]</a> Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data, arts. 9(2)(j), 89, 2016 O.J. (L 119) 1 [hereinafter GDPR].</p>



<p><a href="#_ftnref18" id="_ftn18">[18]</a> Regulation (EU) 2025/327 of the European Parliament and of the Council of 11 February 2025 on the European Health Data Space, OJ L, 2025/327, 5.3.2025 [hereinafter EHDS Regulation]. The Regulation entered into force on 26 March 2025 and applies in stages: most provisions from 26 March 2027, and the core secondary-use chapter from 26 March 2029 (2031 for certain data categories). See id. art. 105.</p>



<p><a href="#_ftnref19" id="_ftn19">[19]</a> EHDS Regulation, supra note 18, arts. 50–54 (secure processing environments; permitted and prohibited purposes of secondary use).</p>



<p><a href="#_ftnref20" id="_ftn20">[20]</a> Directive 2001/83, supra note 2, art. 87(2) (all parts of advertising must comply with the particulars listed in the summary of product characteristics), arts. 40–53 (manufacturing authorisation and good manufacturing practice) and art. 87(1) (prohibition of advertising of medicinal products without a marketing authorisation).</p>



<p><a href="#_ftnref21" id="_ftn21">[21]</a> MDR, supra note 7, art. 7.</p>



<p><a href="#_ftnref22" id="_ftn22">[22]</a> Commission Decision (EU) 2025/2371 of 26 November 2025 (declaring the first four EUDAMED modules functional), OJ L, 2025/2371, 27.11.2025; Regulation (EU) 2024/1860 of the European Parliament and of the Council of 13 June 2024, OJ L, 2024/1860, 9.7.2024 (gradual roll-out of EUDAMED). The four modules (actor registration, UDI/device registration, notified bodies and certificates, market surveillance) are mandatory from 28 May 2026; legacy devices remaining on the market must be registered by 28 November 2026. The vigilance and clinical-investigation modules are not yet mandatory, and serious incidents continue to be reported to national competent authorities.</p>



<p><a href="#_ftnref23" id="_ftn23">[23]</a> Cosmetics Regulation, supra note 6, arts. 11, 13, 20; Commission Regulation (EU) No 655/2013 of 10 July 2013 Laying Down Common Criteria for the Justification of Claims Used in Relation to Cosmetic Products, Annex, 2013 O.J. (L 190) 31.</p>



<p><a href="#_ftnref24" id="_ftn24">[24]</a> Regulation (EC) No 178/2002 of the European Parliament and of the Council of 28 January 2002 Laying Down the General Principles and Requirements of Food Law, 2002 O.J. (L 31) 1.</p>



<p><a href="#_ftnref25" id="_ftn25">[25]</a> Commission Implementing Regulation (EU) 2020/16 of 10 January 2020 Authorising the Placing on the Market of Nicotinamide Riboside Chloride as a Novel Food, 2020 O.J. (L 7) 6.</p>



<p><a id="_ftn26" href="#_ftnref26">[26]</a> EFSA Panel on Nutrition, Novel Foods and Food Allergens, Safety of Beta-Nicotinamide Mononucleotide (β-NMN) Pursuant to Regulation (EU) 2015/2283 and the Bioavailability of Nicotinamide from This Source in the Context of Directive 2002/46/EC, 24 EFSA J. e10007 (2026) (opinion adopted 4 March 2026, published 11 May 2026). Authorisation requires a Commission implementing act amending the Union list established by Commission Implementing Regulation (EU) 2017/2470; at the time of writing no such act has been published, and any authorisation granted on the basis of proprietary data will initially benefit only the applicant. See Novel Food Regulation, supra note 5, arts. 12, 26.</p>
<p> </p>



<p>#LongevityIndustry #LongevityWashing #EURegulatoryLaw #ArtificialIntelligence #AIAct #HealthcareLaw #LifeSciencesLaw #HealthTech #MedicalDevices #PharmaceuticalLaw #GDPR #EuropeanHealthDataSpace #EUlaw #HealthClaims #NovelFoods</p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/longevity-washing-ai-and-the-regulatory-fault-lines-of-the-longevity-industry-a-european-perspective/">Longevity Washing, AI and the Regulatory Fault Lines of the Longevity Industry: A European Perspective</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/longevity-washing-ai-and-the-regulatory-fault-lines-of-the-longevity-industry-a-european-perspective/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/ABA_Call_Longevity_Presentation-wrzesien.mp4" length="12991488" type="video/mp4" />

			</item>
		<item>
		<title>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 20:30:11 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Act on Patients Rights]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI cybersecurity]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI-enabled attacks]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anonymisation]]></category>
		<category><![CDATA[anonymization]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[cloud healthcare]]></category>
		<category><![CDATA[controller liability]]></category>
		<category><![CDATA[Cyber Five]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[cyber resilience healthcare]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach response]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data minimisation]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data processing agreement]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection impact assessment]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[digital healthcare]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[e-health]]></category>
		<category><![CDATA[eHealth platforms]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR security]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Article 28]]></category>
		<category><![CDATA[GDPR Article 32]]></category>
		<category><![CDATA[GDPR Article 33]]></category>
		<category><![CDATA[GDPR Article 34]]></category>
		<category><![CDATA[GDPR Article 35]]></category>
		<category><![CDATA[GDPR Article 82]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR compliance healthcare]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare AI]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[healthcare contracts]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[healthcare data security]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[healthcare software]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT supplier contracts]]></category>
		<category><![CDATA[joint and several liability]]></category>
		<category><![CDATA[liability insurance]]></category>
		<category><![CDATA[medical data protection]]></category>
		<category><![CDATA[medical records]]></category>
		<category><![CDATA[medical technology]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[MyDr data breach]]></category>
		<category><![CDATA[National Cybersecurity System]]></category>
		<category><![CDATA[network segmentation]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[patient privacy]]></category>
		<category><![CDATA[patients rights]]></category>
		<category><![CDATA[Personal data breach]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attacks]]></category>
		<category><![CDATA[Poland cybersecurity]]></category>
		<category><![CDATA[Polish GDPR]]></category>
		<category><![CDATA[Polish healthcare law]]></category>
		<category><![CDATA[privacy by design]]></category>
		<category><![CDATA[processor liability]]></category>
		<category><![CDATA[pseudonymisation]]></category>
		<category><![CDATA[pseudonymization]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[special category data]]></category>
		<category><![CDATA[sub-processors]]></category>
		<category><![CDATA[subprocessor management]]></category>
		<category><![CDATA[supplier risk management]]></category>
		<category><![CDATA[technology contracts]]></category>
		<category><![CDATA[telemedicine]]></category>
		<category><![CDATA[third-party liability]]></category>
		<category><![CDATA[UODO]]></category>
		<category><![CDATA[vendor risk]]></category>
		<category><![CDATA[voice deepfake]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8909</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 What happened On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<h2 class="wp-block-heading"><strong>What happened</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:42% auto"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4"></video></figure><div class="wp-block-media-text__content">
<p>On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.</p>
</div></div>



<p>The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.</p>



<span id="more-8909"></span>



<p>To date, the company has not publicly confirmed the full scope and nature of the compromised data, referring instead to a pending forensic analysis. The investigation is being conducted by the Central Bureau for Combating Cybercrime under the supervision of the Warsaw Regional Prosecutor&#8217;s Office, and the President of the Personal Data Protection Office (UODO) has opened an inspection covering the technical and organisational measures applied and the underlying risk analysis. Since 29 August, the dataset from the incident has been available on the government portal bezpiecznedane.gov.pl, where anyone can check whether their data was affected.</p>



<p>The scale of the incident prompted the Ministry of Digital Affairs to announce, within three weeks, a legislative package branded the &#8220;Cyber Five&#8221;. Its key elements include certification of entities processing medical data within the existing national cybersecurity certification framework; a mandatory risk assessment before processing begins and at least every two years thereafter; new obligations for entities serving more than 100 controllers or processing data of more than 100,000 individuals (including rapid transfer of affected persons&#8217; data to CSIRT NASK and a duty to inform client facilities about the level of their own security); and notifications of medical events via the mObywatel and mojeIKP applications. The amendments are to cover the Act on Patients&#8217; Rights and the legislation governing the National Cybersecurity System.</p>



<h2 class="wp-block-heading"><strong>Why roles in the processing chain decide everything</strong></h2>



<p>From a legal standpoint, the critical point is that, in relation to medical records, MyDr acts as a processor, while each facility – from a large clinic network to a single-doctor practice – remains the controller. The consequences of this structure became fully apparent after the incident:</p>



<ul class="wp-block-list">
<li><strong>The obligation to notify UODO (Article 33 GDPR) and to communicate the breach to patients (Article 34 GDPR)</strong> rests with the controller, i.e. the facility. The processor is merely required to inform the controller &#8220;without undue delay&#8221; (Article 33(2) GDPR). In practice, thousands of healthcare providers had to assess risk and communicate with patients on the basis of fragmentary information from the supplier.</li>



<li><strong>Liability for damages (Article 82 GDPR)</strong> is joint and several: a patient may sue the facility, the supplier, or both. The processor is liable where it has failed to comply with obligations specifically imposed on processors by the GDPR or acted contrary to the controller&#8217;s instructions – but the facility is liable for having entrusted data to an entity that did not provide sufficient guarantees (Article 28(1) GDPR).</li>



<li><strong>Sector-specific requirements under the Act on Patients&#8217; Rights</strong> (Article 24(4)) impose on any entity entrusted with the processing of medical records a duty of confidentiality and data security – this is precisely the provision now slated for extension to include certification and minimum technological standards.</li>
</ul>



<p>Deputy Minister of Digital Affairs Dariusz Standerski stated openly that in this case, liability under the contract remained entirely with the controllers, i.e. small medical practices. This is the most important lesson of the incident: a data processing agreement is not a formality but the document that, on the day of a breach, determines who pays.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How a healthcare service provider can protect itself</strong></h2>



<p><strong>1. The data processing agreement and the main contract as risk-allocation tools.</strong> Standard DPA templates offered by software vendors focus on satisfying the minimum requirements of Article 28(3) GDPR. A healthcare provider should negotiate further: a precise deadline and format for incident notification (e.g. 24 hours, with a defined scope of information enabling a risk assessment); audit and penetration-testing rights; an obligation to maintain specified certifications (ISO 27001 and, in future, certification under the National Cybersecurity System Act); a duty to cooperate in communications with patients and the supervisory authority; liability and recourse clauses not capped at the annual fee; and a requirement that the vendor hold cyber insurance with a defined sum insured, with the facility named as a co-insured or beneficiary.</p>



<p><strong>2. Cyber and liability insurance.</strong> Standard professional liability policies for healthcare providers typically do not cover the cost of notifying patients, crisis management, administrative fines or claims arising from data breaches. A dedicated cyber policy covers these elements, but its exclusions must be read carefully: insurers increasingly condition cover on the implementation of MFA, system patching and backups, and an incident at an external supplier (a so-called <em>third-party breach</em>) is often covered only under an express extension. It is also worth verifying whether the software vendor&#8217;s own policy actually exists and what its limit is – given the number of facilities relying on a single system, such amounts may prove illusory.</p>



<p><strong>3. A map of relationships between entities.</strong> In a real-world e-health ecosystem, patient data flows between the facility, the EMR vendor, the hosting or cloud provider, the e-prescription and e-referral operator, laboratories, IT subcontractors and billing companies. Each link is a distinct legal relationship: processing on behalf of the controller, sub-processing (Article 28(2) and (4) GDPR) or joint controllership (Article 26 GDPR). A facility should maintain an up-to-date register of these entities, know where the data is physically located and control the chain of sub-processors – a &#8220;general&#8221; consent to sub-processors without a list and without a right to object is, in practice, an abdication of control.</p>



<p><strong>4. Anonymisation, pseudonymisation and data minimisation.</strong> Data that is not in the system cannot leak. Healthcare providers and vendors should separate identifiers (PESEL numbers, contact details) from clinical data, apply pseudonymisation (Article 4(5) and Article 32(1)(a) GDPR) in test, analytical and research environments, and store statistical data exclusively in anonymised form. It should be remembered that anonymisation is an irreversible process and only such a process removes data from the scope of the GDPR; pseudonymisation remains processing of personal data, but it significantly limits the consequences of a breach and is a valuable argument both in proceedings before UODO and in litigation over damages.</p>



<p><strong>5. Internal obligations and incident readiness.</strong> A breach response procedure should be tested, not merely written down: who decides on notifying UODO within 72 hours, who communicates with patients, who with the media, who secures the evidence. Regular risk analysis and a data protection impact assessment (DPIA) for EMR systems – which, given their scale and the categories of data involved, almost always meet the criteria of Article 35 GDPR – is an obligation already today, and once the &#8220;Cyber Five&#8221; enters into force it will additionally become a sector-specific requirement with a prescribed frequency.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>AI-enabled attacks</strong></h2>



<p>The healthcare sector is particularly exposed to a new generation of AI-supported attacks. Large language models enable the mass generation of credible phishing messages in flawless Polish, personalised on the basis of data from previous breaches – a PESEL number, a surname and information about a prescription are enough to construct a convincing message &#8220;from your clinic&#8221; or &#8220;from the National Health Fund&#8221;. AI tools also automate the discovery of vulnerabilities in systems and the generation of malicious code, shortening the window between disclosure of a vulnerability and its exploitation. There is a growing number of cases involving voice deepfakes used to impersonate medical staff or IT administrators in order to obtain access credentials.</p>



<p>For vendors and facilities, this means that traditional &#8220;don&#8217;t click suspicious links&#8221; training is no longer sufficient. Technical mechanisms are required (phishing-resistant MFA, network segmentation, AI-assisted anomaly monitoring on the defensive side), together with identity verification procedures for every request for data access or a change of permissions. Regulatory risk should also be kept in mind: AI systems deployed in healthcare facilities – including tools supporting diagnostics or triage – fall under the AI Act, and their integration with EMR systems constitutes yet another link in the processing chain that must be reflected in contracts and in the risk analysis.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How we support institutional clients</strong></h2>



<p>KG Legal advises healthcare providers, medical networks, telemedicine platform and e-health software vendors, and investors in this sector on managing liability for data. Our support includes auditing existing data processing agreements and IT supplier contracts for risk allocation; negotiating liability, recourse and insurance clauses; mapping the chain of processors and vetting subcontractors; preparing and testing breach response procedures; handling notifications to UODO and communications with patients; and representation in inspection proceedings and in damages litigation. For medical technology vendors, we prepare documentation and contract templates meeting the requirements of the GDPR, the Act on Patients&#8217; Rights, NIS2 and – once enacted – the &#8220;Cyber Five&#8221; provisions, and we assess the compliance of AI-based solutions with the AI Act and the MDR. Our aim is that, on the day an incident occurs, the client knows exactly who is responsible for what and has evidence of having exercised due diligence.</p>



<p><em>Facts as at 2 September 2026, based on statements by MyDr, the Ministry of Digital Affairs and UODO, and press reports. This article is for information purposes only and does not constitute legal advice.</em></p>
<p>#MyDr #DataBreach #HealthcareCybersecurity #HealthcareData #DataProtection #GDPR #Cybersecurity #HealthTech #eHealth #DigitalHealth #MedicalRecords #EMR #PatientData #PatientPrivacy #UODO #Poland #CyberRisk #CyberInsurance #IncidentResponse #DataPrivacy #NIS2 #CyberFive #ISO27001 #AIAct #AIinHealthcare #AICybersecurity #MedTech #Telemedicine #CyberResilience #DataSecurity</p>
<p> </p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4" length="492961" type="video/mp4" />

			</item>
		<item>
		<title>Influencer Product Placement in Open-World Games and Competition and Consumer Protection Law</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/influencer-marketing-in-minecraft-and-consumer-law/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/influencer-marketing-in-minecraft-and-consumer-law/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 18:58:49 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Blockchain]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[consumer protection law]]></category>
		<category><![CDATA[digital marketing]]></category>
		<category><![CDATA[Digital Regulation]]></category>
		<category><![CDATA[gaming law]]></category>
		<category><![CDATA[hidden advertising]]></category>
		<category><![CDATA[influencer marketing]]></category>
		<category><![CDATA[influencer marketing w Minecraft]]></category>
		<category><![CDATA[kryptoreklama]]></category>
		<category><![CDATA[Loot boxes]]></category>
		<category><![CDATA[MiCA]]></category>
		<category><![CDATA[Minecraft]]></category>
		<category><![CDATA[NFT]]></category>
		<category><![CDATA[nieuczciwe praktyki rynkowe]]></category>
		<category><![CDATA[ochrona konsumentów]]></category>
		<category><![CDATA[ochrona małoletnich]]></category>
		<category><![CDATA[prawo konkurencji]]></category>
		<category><![CDATA[prawo konsumenckie]]></category>
		<category><![CDATA[prawo nowych technologii]]></category>
		<category><![CDATA[prawo reklamy]]></category>
		<category><![CDATA[product placement]]></category>
		<category><![CDATA[product placement in games]]></category>
		<category><![CDATA[reklama influencerów]]></category>
		<category><![CDATA[reklama internetowa]]></category>
		<category><![CDATA[reklama skierowana do dzieci]]></category>
		<category><![CDATA[reklama w grach]]></category>
		<category><![CDATA[social media]]></category>
		<category><![CDATA[Unfair Competition]]></category>
		<category><![CDATA[unfair market practices]]></category>
		<category><![CDATA[uokik]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8907</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 1. Factual background The subject of this analysis is a marketing model for a physical product based on the use of influencer marketing combined with the environment of the game Minecraft. Online creators promote branded toys containing candy, widely available in retail sale, including in popular discount store chains. The [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/influencer-marketing-in-minecraft-and-consumer-law/">Influencer Product Placement in Open-World Games and Competition and Consumer Protection Law</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: September 07, 2026</strong></mark></p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>1. Factual background</strong></p>



<p>The subject of this analysis is a marketing model for a physical product based on the use of influencer marketing combined with the environment of the game Minecraft. Online creators promote branded toys containing candy, widely available in retail sale, including in popular discount store chains. The campaign also involves creating and making available within Minecraft virtual counterparts of the promoted products, which function, inter alia, on servers, on maps and through game modifications.</p>



<span id="more-8907"></span>



<p>Until now, influencer marketing has relied primarily on the publication of sponsored materials on social media, such as posts, stories or live streams. The marketing model under analysis, however, goes beyond traditional forms of product placement, as it uses the open environment of the game as a space for conducting advertising activities. In this case, the advertisement is not merely an element of a video; it becomes an integral component of the game world with which the recipient can interact.</p>



<p>The recipients of such communications are, in particular, minors. Given how well the attractive environment of Minecraft is matched to the preferences and interests of a young audience, the presented content may significantly influence the purchasing decisions of children and adolescents, which in turn may translate into increased sales of the promoted products, measured even in tens of millions of złoty.</p>



<p>Contemporary consumers remain particularly susceptible to the influence of influencer marketing, because the message created by online creators is often perceived as authentic. Influencers combine entertainment with commercial activity, presenting the promoted products as part of their everyday life or as a natural component of the materials they publish. As a result, recipients may perceive the advertised product as a fragment of the creator&#8217;s ordinary activity rather than a commercial communication, which may increase the potential effectiveness of the marketing impact.</p>



<p>The integration of advertising messages with entertainment content may give rise to the risk of exerting undue influence on market decisions, especially where identification of the commercial nature of the message is difficult. The protection of minors takes on particular importance: as market participants with limited experience and a lesser capacity for the critical assessment of advertising messages, they require heightened legal protection.</p>



<p>Another problematic aspect is the regulation of promotional content disseminated in the digital environment, including open-world games and social media. The applicable sectoral regulations on advertising were constructed primarily with traditional media in mind and do not always account for the specific features of modern marketing models. For this reason, the practice of influencer product placement in games has become the subject of increased interest on the part of the Polish Office of Competition and Consumer Protection (UOKiK).</p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>2. Two parallel liability regimes</strong></p>



<p>The practice of influencer product placement in open-world games may give rise to liability on two independent planes &#8211; public-law and civil-law. Both regimes operate in parallel, rest on different legal bases and pursue different objectives; accordingly, the application of one does not preclude pursuing liability under the other.</p>



<p>The basis for public-law liability is provided by the <strong>Act of 16 February 2007 on Competition and Consumer Protection</strong>. Under Article 24 of the Act, practices infringing the collective interests of consumers are prohibited. The competence to conduct proceedings and impose sanctions rests with the President of the Office of Competition and Consumer Protection, whose task is to protect the public interest by eliminating practices capable of infringing the rights of a broad circle of consumers.</p>



<p>In the marketing model under analysis, the potential infringement arises not from the mere fact of promoting a product, but from the manner in which the advertising activities are conducted. The use of the game world as a promotional space, combined with the influencer&#8217;s activity, may blur the line between entertainment content and commercial communication. Consequently, the recipient &#8211; especially a minor &#8211; may be unaware of being exposed to advertising, which hinders the making of an informed purchasing decision. Such conduct may be found contrary to good practices (dobre obyczaje) and in breach of the trader&#8217;s information obligations towards consumers.</p>



<p>Marketing materials whose recipients are minors raise particularly serious doubts on the part of the President of UOKiK, given minors&#8217; greater susceptibility to manipulation and unfair practices. In addition to supervising the proper labelling of advertisements on social media, UOKiK also scrutinises conduct that may qualify as aggressive advertising directed at children. Advertisers may not create content which is simultaneously directed at children, direct in character and expressly exhorts minor recipients to purchase a product or to persuade adults to do so.</p>



<p>A practical example of the enforcement of liability under the above regulations is the proceedings conducted against the influencers Wojan and Palion, who publish content devoted to Minecraft, mainly on YouTube. According to the President of UOKiK, the materials posted by the creators could generate purchasing pressure among children by seamlessly combining gameplay elements with the promotion of their own products, such as clothing, school supplies and beverages<a href="#_ftn1" id="_ftnref1">[1]</a>. For this reason, on 13 July 2026 the influencers were formally charged with conduct capable of infringing the collective interests of consumers. If the infringement is confirmed, UOKiK may impose a fine of up to 10% of the turnover achieved in the financial year preceding the year in which the fine is imposed<a href="#_ftn2" id="_ftnref2">[2]</a>.</p>



<p>Independently of public-law liability, the conduct described may give rise to civil-law liability. In that case, the purpose of the proceedings is not the protection of the public interest, but the protection of the individual interests of parties whose rights have been infringed. An action may be brought both by a competitor and by a consumer, provided the trader&#8217;s conduct qualifies as an act of unfair competition or an unfair market practice.</p>



<p>With respect to advertising conducted within the <em>Minecraft</em> environment, particular importance attaches to Article 16 of the <strong>Act of 16 April 1993 on Combating Unfair Competition</strong>, which governs unfair advertising. If the manner of presenting a product in the game world conceals its commercial character, misleads recipients or exploits the credulity of children, such conduct may qualify as an act of unfair competition. Parties whose interests are thereby threatened or infringed are entitled to the claims provided for in Article 18 of that Act. These include, among others, the right to demand cessation of the prohibited conduct or removal of its effects, compensation for the damage caused, or surrender of unjustly obtained benefits.</p>



<p>Independently of the above, a consumer may also pursue claims under the <strong>Act of 23 August 2007 on Counteracting Unfair Market Practices</strong>. Such practices include, in particular, the dissemination of unfair information, misleading consumers and the use of surreptitious advertising. Under Article 12, the consumer has the right to demand cessation of the unfair practice or removal of its effects, a price reduction, and compensation for the damage caused, in particular through annulment of the contract subject to the mutual return of performances and reimbursement by the trader of the costs incurred by the consumer in connection with the purchase of the product.</p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>3. An act of unfair competition — what does it consist of in this case?</strong></p>



<p>Assessing the marketing model under analysis from the perspective of the Act of 16 April 1993 on Combating Unfair Competition requires, first of all, determining whether the manner of presenting products in the <em>Minecraft</em> environment, through the creation of their virtual counterparts, may qualify as unfair advertising. Under Article 3 of the Act, an act of unfair competition is conduct contrary to the law or to good practices, if it threatens or infringes the interest of another undertaking or of a customer. One form of such an act is unfair advertising, detailed examples of which are set out in Article 16 of the Act.</p>



<p>The essence of the problem presented by the facts at hand is not the promotion of products by influencers as such, but the manner in which the advertising is conducted &#8211; embedding the marketing message into the game&#8217;s storyline and presenting it as a natural element of gameplay. As a result, the average recipient may fail to notice that they are being exposed to commercial content, which they may take for an ordinary element of the game world or a spontaneous recommendation by the online creator.</p>



<p>The infringement described above is classified as surreptitious advertising (kryptoreklama), included on the so-called blacklist of unfair market practices. It consists in presenting advertising content in a manner that conceals its commercial character, preventing the consumer from making an informed assessment of the message<a href="#_ftn3" id="_ftnref3">[3]</a>. With regard to <em>Minecraft</em>, examples of such conduct may include placing the advertised product as an element of the storyline, creating its digital counterpart, or using it as a reward for completing specific tasks. In each of these cases, the advertisement ceases to function as a separate marketing communication and becomes part of the player&#8217;s experience. From a legal standpoint, it is precisely this integration of advertising with gameplay that may make it difficult for the recipient to recognise its true character.</p>



<p>The general clause contained in Article 3 of the Act of 16 April 1993 on Combating Unfair Competition obliges undertakings to act not only in accordance with the law but also with good practices. These primarily require conducting business in an honest and transparent manner. A breach of those standards &#8211; for instance by concealing the advertising character of a publication &#8211; could place undertakings applying higher standards of transparency at a competitive disadvantage and thereby undermine fairness in market competition. With respect to the strategy under analysis, good practices also require the influencer to treat their followers honestly and, accordingly, not to exploit their loyalty and susceptibility to the influence of recommendations.</p>



<p>The possibility of holding a person liable for infringing the above regulations depends, however, on whether the influencer is regarded as an undertaking. Under Article 2 of the Act of 16 April 1993 on Combating Unfair Competition, an undertaking includes, among others, a natural person who participates in economic activity by conducting gainful or professional activity, even as a secondary occupation. Today, the main source of influencers&#8217; income is ceasing to be revenue linked to user engagement with published content; increasingly important are fees earned under advertising contracts, sales of products under their own brands, and the provision of other marketing services. Consequently, given the professional and gainful character of their activity, applying the provisions on combating unfair competition to online creators becomes justified.</p>



<p>Following an analysis of the materials published on the entertainment channels of Wojan and Palion, UOKiK found that their online activity involved practices amounting to hidden and aggressive advertising. The President of UOKiK described the situation as follows: &#8220;<em>Meanwhile, the influencers I have charged promote their businesses through social media content based on popular computer games for children. One moment they are narrating the course of the gameplay, and the next they are encouraging viewers to buy backpacks, beverages or T-shirts. The advertising message is woven into content of an entertainment character.</em><a href="#_ftn4" id="_ftnref4">[4]</a>&#8221; The principal charge concerned the use of marketing strategies blurring the line between entertainment and marketing activities, for example by constructing a storyline in Minecraft featuring virtual counterparts of the Żabka store chain offering an assortment of &#8220;Wojanek&#8221; or &#8220;Palionek&#8221; branded beverages.</p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>4. Why does a recognisable creator become a subject of interest for UOKiK?</strong></p>



<p>The basis for intervention by the President of UOKiK is an infringement by an undertaking of the collective interests of consumers, which include, among others, unfair market practices, acts of unfair competition, and failure to comply with information obligations towards consumers. An important point is that the collective interest of consumers is not the sum of individual interests; the President of UOKiK therefore does not protect a specific consumer, but the entire group of recipients to whom the commercial communication is addressed.</p>



<p>Influencers who have built up substantial popularity and influence are subject to particular scrutiny by UOKiK. Content published by digital creators may simultaneously reach hundreds of thousands or even millions of users. An infringement committed by an influencer in such circumstances therefore does not harm a single individual, but may mislead a broad group of consumers, thereby constituting an infringement of the collective interests of consumers.</p>



<p>The principal objective of UOKiK&#8217;s activity is the protection of the public interest, not the resolution of disputes between specific parties. As a result, proceedings conducted by the President of UOKiK are public-law and administrative in character. For this reason, the imposition of a fine does not depend on the undertaking&#8217;s fault; it is sufficient to demonstrate that the infringement occurred. UOKiK&#8217;s sanctions are intended, in particular, to have a preventive character and to encourage companies to implement legal-conformity mechanisms, i.e. <em>compliance</em>. In light of the above, an influencer conducting professional and gainful advertising activity should verify the conformity of their publications with the applicable provisions and guidelines, bearing in mind that lack of awareness of an infringement does not relieve them of administrative liability.</p>



<p>The President of UOKiK has the competence to issue a decision finding a practice to infringe the collective interests of consumers and ordering its discontinuation, in which measures may be specified to remove the ongoing effects of the infringements, such as the publication of a statement in the form and with the content specified in the decision<a href="#_ftn5" id="_ftnref5">[5]</a>. Such a decision is not issued, however, where the undertaking has already ceased the prohibited practice. To prevent proceedings from being automatically terminated merely by removing the advertising material that breached applicable legal requirements or by subsequently labelling the collaboration, Article 27 introduces a <strong>decision finding a practice to infringe the collective interests of consumers and declaring that it has been discontinued</strong>. On that basis, the President of UOKiK may still order the undertaking to take specific actions to remove the effects of the earlier infringement.</p>



<p>Where a marketing strategy relies on influencers publishing advertising materials using Minecraft, the infringements typically consist in failing to communicate unambiguously that the content is commercial in character. This requirement is set out, among others, in the <strong>Recommendations of the President of UOKiK on the labelling of advertising content by influencers</strong>, in which the President of UOKiK emphasises that every commercial collaboration &#8211; regardless of the form of remuneration (barter, monetary, or a free product) &#8211; should be labelled in a manner comprehensible and clearly legible to the average recipient. Moreover, clearly indicating the advertising character of the message at the recipient&#8217;s very first contact with the material is an obligation resting not only on influencers, but also on advertising agencies and advertisers. Two-level labelling is recommended, consisting in the simultaneous placement of a proper disclosure by the author of the publication and the use of the tools offered by the platform for labelling advertising content. The mere use of hashtags &#8211; especially in abbreviated form, or forms that do not highlight the fact that the influencer received a benefit, such as #ad, #gifted or #współpraca &#8211; may be found insufficient. Preference is given to annotations that are clear to recipients and legibly indicate the commercial character of the content, such as #reklama (#advertisement), #prezent (#gift), #autopromocja (#selfpromotion) or #współpracabarterowa (#bartercollaboration).</p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>5. Directing communications at children &#8211; the strictest regime</strong></p>



<p>The principal problem for businesses interested in using influencer marketing and open-world games for marketing purposes is the rigorously regulated protection of minor recipients. Advertisers creating content that is by design directed particularly at a young group of potential consumers are obliged to exercise exceptional caution and to take into account additional restrictions arising from the law.</p>



<p>The fundamental role of regulations protecting children against prohibited marketing strategies is evidenced by the inclusion, on the blacklist of aggressive market practices, of advertising containing a direct exhortation to children to purchase the promoted products or to persuade adults to buy them for them<a href="#_ftn6" id="_ftnref6">[6]</a>. This means that practices of this kind are deemed unfair in all circumstances. When watching, for example, a television advertising block, a child is usually aware of its commercial character. In the case of product placement carried out by an influencer in the Minecraft environment, however, the marketing message is incorporated into the narrative of the gameplay. The young recipient focuses on the course of the game rather than on assessing the nature of the communication, which increases their susceptibility to the advertising&#8217;s influence. Beyond hidden promotional messages, it is also prohibited to use tactics classified as aggressive, i.e. influencing the consumer&#8217;s behaviour towards a product through pressure or physical or psychological coercion<a href="#_ftn7" id="_ftnref7">[7]</a>.</p>



<p>Examples of communications that raised the doubts of the President of UOKiK and were found to be aggressive are statements made by the influencers Wojan and Palion during their publicly streamed Minecraft gameplay: <em>&#8220;Get down to the Żabka stores while these Wojanki are still around.&#8221; &#8220;Come to Palion Style and order while it lasts, because it&#8217;s selling like hot cakes, and school is just around the corner.&#8221; &#8220;Do you have a box like this? Over 500 people already have one &#8211; and you don&#8217;t? Come on in, hurry, because school is starting any moment.&#8221;</em> These statements are not limited to a neutral presentation of the product. They simultaneously deploy the scarcity mechanism (&#8220;while they last&#8221;), time pressure (&#8220;school is just around the corner&#8221;) and social proof (&#8220;500 people already have one&#8221;), which in the case of minor recipients may lead to manipulation of purchasing decisions that is impermissible under the law.</p>



<p>When publishing advertising content, it must be borne in mind that a child does not possess the capacity for critical analysis of digital content or a level of life experience comparable to the awareness of adults. As a result, conduct which, in relation to adult recipients, could be regarded as a permissible form of marketing communication may, in relation to minors, constitute an unfair market practice.</p>



<p>Owing to the long-term relationships they build with their audiences, influencers commonly come to act as online idols or authority figures. Advertising in the digital environment &#8211; for instance within a game &#8211; frequently relies on psychological mechanisms characteristic of the information and consumer society, described as the FOMO phenomenon (<em>fear of missing out</em>), compounded by the effect of identification with the influencer or their idealisation, and by pressure resulting from a perceived urgency of purchase and group behaviour. These instruments act considerably more strongly on children than on adult consumers, which provides the basis for a stricter standard for assessing the lawfulness of such practices.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Product placement &#8211; the broadcasting regime</strong></p>



<p>In order to reinforce the authenticity of a commercial message, advertisers use product placement, i.e. the natural incorporation of a good, service or trademark into another publication, as an element of the storyline or set design. Product placement is usually better received by consumers than classic advertising, since the promotional message is less intrusive and does not create an impression of direct purchasing pressure. Owing to the greater degree of integration of the advertisement with the presented material, this practice creates conditions conducive to abuse.</p>



<p>The conditions for the admissibility of product placement are set out in Article 17a of the <strong>Act of 29 December 1992 on Broadcasting</strong>. The practice is acceptable in all programmes, subject however to the specific exceptions provided by the legislator, such as programmes for children. Minors, whose cognitive maturity is not yet fully developed, require reinforced protection against marketing content whose form is less obvious to the recipient. A particularly problematic issue has become product placement in games with an open structure, such as Minecraft. Where the principal entertainment offered by the game is the unlimited possibility of building new worlds and creating the elements that compose them, it is exceptionally difficult to determine whether the actions taken by influencers constitute merely part of the gameplay or already take on the character of paid collaboration.</p>



<p>The protection of recipients is reinforced by obligations imposed on broadcasters. It is prohibited, by means of product placement, to give undue prominence to a product or to directly encourage its purchase through promotional actions. It is also necessary to appropriately mark the programme with a graphic symbol<a href="#_ftn8" id="_ftnref8">[8]</a>. Product placement is therefore a lawful strategy, provided its transparency is maintained and excessively direct promotional messages are avoided.</p>



<p>This regime, however, covers above all the activity of broadcasters within the meaning of the <strong>Act of 29 December 1992 on Broadcasting</strong>. An influencer does not, generally speaking, have the status of a &#8220;broadcaster&#8221;, and the content they publish is not covered by the obligations arising under Article 17a of the Act. Under the current legal framework, the high standard of protection of young recipients covers, among others, television and radio materials; yet where the same content is published by a digital creator, for example as a video on YouTube, only soft-law recommendations apply.</p>



<p>Recognising the growing popularity of mass social platforms, the EU introduced <strong>Directive (EU) 2018/1808 of the European Parliament and of the Council of 14 November 2018 amending Directive 2010/13/EU on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services (Audiovisual Media Services Directive, AVMSD) in view of changing market realities</strong>. The act extended the scope of regulation to video-sharing platform providers, which, however, does not mean that the boundary between influencers and broadcasters has been entirely erased. The requirements arising from the Directive focus mainly on platforms&#8217; responsibility for creating mechanisms to protect minors, such as age verification and enabling creators to unambiguously label commercial content. The act does not, however, fully equate online creators with broadcasters in terms of the rights and obligations arising from competition and consumer protection.</p>



<p>A legal gap thus arises which allows influencers to publish content containing product placement directed at children on social media or in the gaming environment discussed here. The very same materials, if presented in the form of a television programme or radio broadcast, would simultaneously be found impermissible and in breach of the Act. The same advertising communication is therefore subject to different standards of scrutiny solely on account of the entity distributing it.</p>



<p>This produces a paradoxical legal situation in which the highest level of protection for minors is provided for content published via traditional media. Under contemporary marketing strategies, by contrast, children and adolescents are most exposed while using online platforms and video games, whose product-placement activity is governed by soft-law instruments such as the guidelines and recommendations of the President of UOKiK or platform terms of service. Article 17a of the <strong>Act of 29 December 1992 on Broadcasting</strong> should nevertheless serve as a normative benchmark illustrating the level of protection of minors that the legislator considers desirable. The legal gap described &#8211; as it reveals the lack of full coherence in protecting children against hidden advertising messages &#8211; should form the basis for further amendment of the provisions relating to influencer marketing and commercial materials published on video-sharing and gaming platforms.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Advertising of food and sweets to children &#8211; a liberal regulatory model and its limitations</strong></p>



<p>The Polish legislator has not decided to introduce a statutory prohibition on the advertising of food &#8211; particularly sweets high in sugar, fat or salt (HFSS &#8211; <em>high fat, sugar, salt</em>) &#8211; directed at children. The protection of minors in this area takes the form of liberal regulation, based on self-regulatory solutions developed by the media market. The state has thus laid down only a general legal framework, leaving detailed restrictions and rules to the will of market participants, chiefly broadcasters.</p>



<p>Provisions in this area are contained in the <strong>Agreement of television broadcasters on the principles of disseminating food advertisements directed at children</strong>, in force since 1 January 2015. This self-regulation came into being through the active cooperation of, among others, the National Broadcasting Council (KRRiT), the Advertising Council, the Polish Federation of Food Producers, the Ministry of Health and the television broadcasters who undertook to sign it voluntarily<a href="#_ftn9" id="_ftnref9">[9]</a>. The Agreement aims to counteract the formation of undesirable eating habits among young audiences and to clarify and extend the duties arising from Article 16a(3a) and (3b) of the <strong>Act of 29 December 1992 on Broadcasting</strong>. Under those provisions, programmes directed at children should not be accompanied by content advertising foodstuffs or beverages whose excessive consumption may be harmful. KRRiT has, moreover, been granted the competence to designate such foods by regulation, after consulting the minister responsible for health. That body may also indicate preferred ways of publishing advertisements for foodstuffs questioned from a health perspective, so that such messages do not accompany children&#8217;s programmes.</p>



<p>Supervision of the operation of this self-regulatory system is exercised by the National Broadcasting Council. The authority analysed the activity of sixteen children&#8217;s channels and eight general-audience channels over the period from July 2020 to June 2023. Its key findings, contained in the report &#8220;Television channels and programmes for children free of advertisements for sweets and salty snacks&#8221;, indicate a high level of compliance with the commitments undertaken by the parties to the agreement. Appropriately constructed self-regulatory mechanisms may therefore sometimes prove equally or even more effective than rigidly imposed hard law. Particularly in relation to a flexible and dynamic media market, greater decision-making autonomy for broadcasters with respect to practical rules may contribute to a more efficiently functioning system.</p>



<p>The protection system is further supplemented by instruments of advertising ethics, in particular the <strong>Code of Advertising Ethics</strong> and the activity of the Advertising Ethics Commission operating within the Advertising Council. The Code contains guidance on responsibly directing marketing communications at children and prohibits advertisers from exploiting their natural trust and lack of experience<a href="#_ftn10" id="_ftnref10">[10]</a>. In assessing the admissibility of food advertisements, the principal reference point is the HFSS criterion (high fat, sugar, salt), on the basis of which products are classified as requiring particular marketing caution owing to their content of ingredients potentially harmful in large quantities.</p>



<p>The effectiveness of the self-regulation flowing from the <strong>Agreement of television broadcasters on the principles of disseminating food advertisements directed at children</strong> is nevertheless limited in both its personal and material scope. The rules bind only the voluntary signatories of the agreement, who are primarily traditional television broadcasters. Moreover, they apply to marketing materials broadcast in television programmes or radio broadcasts falling within the scope of the agreement. Its provisions do not, however, constitute binding guidelines for online creators publishing content on platforms such as YouTube or TikTok, or for persons conducting advertising activity in the computer-game environment. An influencer, remaining essentially outside the reach of the regulations analysed, may thus use Minecraft to present a sponsored toy containing sweets, use it as an element of the gameplay, and so on.</p>



<p>The example described reveals a visible regulatory asymmetry. Advertising of sweets or other foodstuffs questioned from a health perspective, broadcast via traditional media, is subject to a range of extensive restrictions and to the supervision of KRRiT. An analogous communication published by a digital creator using instruments at the frontier of new technologies remains covered only by the general principles of consumer law and the Recommendations of the President of UOKiK.</p>



<p>A model based on the combination of liberal statutory regulation and broadcaster self-regulation therefore does not guarantee full protection of minors, given its mismatch with the way in which the youngest internet users consume content today. Marketing communications concerning food and sweets are increasingly being shifted by advertisers from traditional television to social media and gaming environments, where the existing protective mechanisms have a much narrower scope of application. The resulting regulatory gap constitutes one of the most significant arguments in favour of developing more coherent rules on influencer marketing directed at minors, irrespective of the communication channel used.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Open-world games, crypto and blockchain &#8211; the most rapidly developing layer</strong></p>



<p>A relatively significant regulatory challenge is also posed by the use of blockchain technology and economic mechanisms linked to the environment of digital games. The issues of advertising and product placement are already subject to relatively well-established regulation, but areas based on the use of newer technologies remain at a stage of dynamic legislative development. Under the current legal framework, the prevailing part of the provisions in this area merely indicates the desirable directions in which the law should develop, i.e. takes the form of <em>de lege ferenda</em> postulates.</p>



<p>A subject of particular debate is so-called loot boxes, i.e. in-game elements containing randomly selected items or other mechanisms facilitating gameplay. They can be purchased using in-game currency or by paying with real money. Their similarity to games of chance is contested, in particular because the player pays a fee in order to gain access to a previously unknown reward, the value of which depends on chance rather than skill. This kind of exploitation of psychological propensities &#8211; human susceptibility to addiction to randomised outcomes and variable-ratio reward systems &#8211; provides grounds for the development, among children, who constitute the dominant group of game users, of tendencies towards compulsive and gambling behaviour.</p>



<p>Polish law contains no provision that directly regulates the practice of loot boxes. Of fundamental relevance here is the <strong>Act of 19 November 2009 on Gambling Games</strong>, Article 2 of which defines games of chance as games offering monetary or material prizes whose outcome depends on chance. Loot boxes, however, are not expressly listed among the games falling within that category, which leaves online creators and game producers facing legal uncertainty as to whether their activity might be found to promote gambling.</p>



<p>Increasingly, elements functioning within computer games do not remain merely digital items used during gameplay. Thanks to blockchain technology, they can be transformed into tokens or non-fungible tokens (NFTs), which exist independently of the game itself and can be traded on external platforms. This practice means that activity conducted within the game environment may begin to fall within the scope of Regulation (EU) 2023/1114 of the European Parliament and of the Council on markets in crypto-assets (MiCA). Where a token is not used solely within the game environment but becomes the object of trading on a secondary market or performs an investment function, it may be deemed a crypto-asset within the meaning of MiCA. Consequently, issuers and entities promoting such solutions may become subject to obligations concerning transparency of information, publication of information documents (<em>whitepapers</em>) and the conduct of marketing communications in accordance with the requirements of the Regulation.</p>



<p>A factual situation thus arises in which the same product may function simultaneously as a physical toy available in retail sale, an item used during gameplay in <em>Minecraft</em>, and a token recorded on a blockchain. Each of these forms is subject to different legal regimes, including consumer law, the rules on counteracting unfair market practices, the Gambling Games Act, digital services legislation, and the crypto-asset market rules arising from the MiCA Regulation.</p>



<p>The case under analysis clearly demonstrates that contemporary legal regulation, both national and European, has not been updated sufficiently to provide advertisers and consumers alike with a clear position in relation to the multi-layered commercialisation model that is now widespread. The dynamic impact of new technologies on traditional legal institutions has created a need to develop more coherent solutions encompassing consumer law and the protection of minor participants in the media market, without divisions into different modes of regulation depending on the entity disseminating the advertising content.</p>



<h2 class="wp-block-heading"><strong>Conclusions</strong></h2>



<p>The analysis conducted does not mean that the practice of influencer product placement in the open environment of Minecraft is, under the current legal framework, subject to no regulation at all. Of key importance are, above all, statutes containing general clauses, such as the Act on Combating Unfair Competition, the Act on Counteracting Unfair Market Practices and the Act on Competition and Consumer Protection. The use of the concept of good practices, the prohibition on misleading consumers, and the model of the average recipient of advertising content means that these provisions can impose certain duties even on relatively novel marketing strategies, for instance those employing new technologies. Confirmation of this thesis may be found in the activity of the President of UOKiK, who has brought formal charges against influencers, such as Wojan and Palion, for infringing the legal norms presented above.</p>



<p>Considerably less flexible, by contrast, are the sectoral regulations designed with traditional media in mind. The provisions of the Broadcasting Act, including those on product placement, and the self-regulatory mechanisms relating to food advertising directed at children, are built around the concepts of &#8220;broadcaster&#8221;, &#8220;programme&#8221; and &#8220;transmission&#8221;. These terms correspond to traditional media but do not fit the dynamically growing internet platforms, streaming services and gaming environments of today. As a result, an identical marketing communication may be subject to different standards of protection solely on account of the manner of its dissemination.</p>



<p>A regulatory gap also appears with respect to the protection of minors. Television and radio broadcasters are bound by extensive restrictions, whereas in the social media environment protection rests primarily on self-regulation, guidelines of administrative authorities and platform terms of service. These solutions, though important, do not provide a level of protection comparable to the regulations binding traditional broadcasters.</p>



<p>New monetisation models employing randomised mechanisms, tokenisation of items and blockchain technology in turn create a problematic situation of simultaneous subjection to consumer law, the rules on unfair market practices, the Gambling Games Act, the MiCA Regulation and digital services legislation. What emerges is a multi-layered regulatory system in which a single product or service may be assessed concurrently from the perspective of several separate legal regimes.</p>



<p>Legal change in the areas described could be introduced by extending the sectoral regulations and redefining concepts such as &#8220;broadcaster&#8221;, &#8220;programme&#8221; and &#8220;transmission&#8221; so that they also cover online creators and communications carried out in gaming environments. Alternatively, the less flexible legislative acts could be transformed along the lines of statutes with a broader personal scope, through the use of general clauses.</p>



<p>Given the dynamic development of new technologies, the second path of legislative change appears the more prudent. Statutes based on general clauses display considerably greater durability, as they make it possible to assess new phenomena regardless of the mechanisms employed.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a id="_ftn1" href="#_ftnref1">[1]</a> https://uokik.gov.pl/reklama-skierowana-do-dzieci-uokik-sprawdza-media-spolecznosciowe</p>



<p><a id="_ftn2" href="#_ftnref2">[2]</a> Act of 16 February 2007 on Competition and Consumer Protection, Article 106.</p>



<p><a id="_ftn3" href="#_ftnref3">[3]</a> Act of 23 August 2007 on Counteracting Unfair Market Practices, Article 7.</p>



<p><a id="_ftn4" href="#_ftnref4">[4]</a> https://uokik.gov.pl/presja-zakupowa-na-dzieci-zarzuty-dla-dwoch-influencerow-youtubowych</p>



<p><a id="_ftn5" href="#_ftnref5">[5]</a> Act of 16 February 2007 on Competition and Consumer Protection, Article 26.</p>



<p><a id="_ftn6" href="#_ftnref6">[6]</a> Act of 23 August 2007 on Counteracting Unfair Market Practices, Article 9.</p>



<p><a id="_ftn7" href="#_ftnref7">[7]</a> Ibid., Article 8.</p>



<p><a id="_ftn8" href="#_ftnref8">[8]</a> Act of 29 December 1992 on Broadcasting, Article 17a.</p>



<p><a id="_ftn9" href="#_ftnref9">[9]</a> https://www.gov.pl/web/krrit/krrit-chroni-dzieci-przed-reklamami-tzw-niezdrowej-zywnosci</p>



<p><a id="_ftn10" href="#_ftnref10">[10] </a>Code of Advertising Ethics, Article 24.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/influencer-marketing-in-minecraft-and-consumer-law/">Influencer Product Placement in Open-World Games and Competition and Consumer Protection Law</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/influencer-marketing-in-minecraft-and-consumer-law/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 12:02:57 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Aviation Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[defence financing]]></category>
		<category><![CDATA[Defence Industry]]></category>
		<category><![CDATA[drone industry]]></category>
		<category><![CDATA[Drone Law]]></category>
		<category><![CDATA[Drone Regulation]]></category>
		<category><![CDATA[Dual-Use Technology]]></category>
		<category><![CDATA[export controls]]></category>
		<category><![CDATA[legal landscape]]></category>
		<category><![CDATA[Lexology]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[regulatory landscape]]></category>
		<category><![CDATA[SANCTIONS]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[UAS regulation]]></category>
		<category><![CDATA[UAV Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8904</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 We are pleased to share that our in-depth report on the legal and technological landscape of the drone industry is featured today as the leading content on Lexology&#8217;s homepage. The report examines the rapidly evolving drone ecosystem through nine interconnected legal and regulatory pillars, including aviation law, artificial intelligence, cybersecurity, [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/">Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="602" src="https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-1024x602.png" alt="" class="wp-image-8905" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-1024x602.png 1024w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-300x176.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-768x451.png 768w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-1536x902.png 1536w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY.png 1583w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<span id="more-8904"></span>



<p>We are pleased to share that our in-depth report on the legal and technological landscape of the drone industry is featured today as the leading content on Lexology&#8217;s homepage.</p>



<p>The report examines the rapidly evolving drone ecosystem through nine interconnected legal and regulatory pillars, including aviation law, artificial intelligence, cybersecurity, data protection, sanctions, export controls, dual-use technologies and defence-sector financing.</p>



<p>As drone technologies advance faster than many existing regulatory frameworks, companies, investors and advisers must navigate an increasingly complex environment spanning civilian, dual-use and military applications.</p>



<p>We invite you to read the full report on our blog, available without a paywall:</p>



<p><blockquote class="wp-embedded-content" data-secret="V2PD940UnY"><a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a></blockquote><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8222;Drone Warfare&#8221; &#8212; KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019" src="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/embed/#?secret=LBenNwlEFP#?secret=V2PD940UnY" data-secret="V2PD940UnY" width="500" height="282" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe> </p>



<p>#DroneLaw #DroneTechnology #UAS #ArtificialIntelligence #Cybersecurity #DataProtection #DualUse #DefenceIndustry #AviationLaw #ExportControls #Sanctions #RegulatoryCompliance #TechnologyLaw #Innovation #LegalAnalysis</p>
<p> </p>




<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/">Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Partner of KG Legal KIELTYKA GLADKOWSKI contributes to the 2026 edition of the World Justice Project Rule of Law Index®</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/partner-of-kg-legal-kieltyka-gladkowski-contributes-to-the-2026-edition-of-the-world-justice-project-rule-of-law-index/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/partner-of-kg-legal-kieltyka-gladkowski-contributes-to-the-2026-edition-of-the-world-justice-project-rule-of-law-index/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 14:45:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[ABA]]></category>
		<category><![CDATA[ABA ILS]]></category>
		<category><![CDATA[ABA International Law Section]]></category>
		<category><![CDATA[absence of corruption]]></category>
		<category><![CDATA[access to justice]]></category>
		<category><![CDATA[American Bar Association]]></category>
		<category><![CDATA[arbitrary exercise of power]]></category>
		<category><![CDATA[civil justice]]></category>
		<category><![CDATA[comparative legal research]]></category>
		<category><![CDATA[constraints on government powers]]></category>
		<category><![CDATA[contract enforceability]]></category>
		<category><![CDATA[criminal justice]]></category>
		<category><![CDATA[cross-border law]]></category>
		<category><![CDATA[cross-border litigation]]></category>
		<category><![CDATA[due process]]></category>
		<category><![CDATA[enforcement of judgments]]></category>
		<category><![CDATA[EU jurisdiction]]></category>
		<category><![CDATA[European Union]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[fundamental rights]]></category>
		<category><![CDATA[international businesses]]></category>
		<category><![CDATA[international commerce]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[investment stability]]></category>
		<category><![CDATA[judicial independence]]></category>
		<category><![CDATA[judiciary]]></category>
		<category><![CDATA[justice system]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[KG Legal Kieltyka Gladkowski]]></category>
		<category><![CDATA[kieltyka gladkowski]]></category>
		<category><![CDATA[legal news]]></category>
		<category><![CDATA[legal practitioner]]></category>
		<category><![CDATA[legal profession]]></category>
		<category><![CDATA[legal protection]]></category>
		<category><![CDATA[legal reform]]></category>
		<category><![CDATA[legal remedies]]></category>
		<category><![CDATA[Litigation]]></category>
		<category><![CDATA[open government]]></category>
		<category><![CDATA[order and security]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish courts]]></category>
		<category><![CDATA[Polish judiciary]]></category>
		<category><![CDATA[Polish justice system]]></category>
		<category><![CDATA[press release]]></category>
		<category><![CDATA[public authorities]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[regulatory enforcement]]></category>
		<category><![CDATA[rule of law]]></category>
		<category><![CDATA[Rule of Law Index]]></category>
		<category><![CDATA[Rule of Law Index 2026]]></category>
		<category><![CDATA[WJP]]></category>
		<category><![CDATA[World Justice Project]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8893</guid>

					<description><![CDATA[<p>Publication date: August 26, 2026 KG Legal KIELTYKA GLADKOWSKI is pleased to announce that one of the firm&#8217;s partners has contributed, as a legal practitioner from Poland, to the forthcoming 2026 edition of the World Justice Project Rule of Law Index®. The World Justice Project is an independent, non-partisan and multidisciplinary organisation dedicated to advancing [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/partner-of-kg-legal-kieltyka-gladkowski-contributes-to-the-2026-edition-of-the-world-justice-project-rule-of-law-index/">Partner of KG Legal KIELTYKA GLADKOWSKI contributes to the 2026 edition of the World Justice Project Rule of Law Index®</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: August 26, 2026</strong></mark></p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/WJP.png" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1010" height="714" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/WJP.png" alt="" class="wp-image-8894" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/WJP.png 1010w, https://www.kg-legal.eu/wp-content/uploads/2026/08/WJP-300x212.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/WJP-768x543.png 768w" sizes="(max-width: 1010px) 100vw, 1010px" /></a></figure>



<span id="more-8893"></span>



<p>KG Legal KIELTYKA GLADKOWSKI is pleased to announce that one of the firm&#8217;s partners has contributed, as a legal practitioner from Poland, to the forthcoming 2026 edition of the World Justice Project Rule of Law Index®.</p>



<p>The World Justice Project is an independent, non-partisan and multidisciplinary organisation dedicated to advancing the rule of law worldwide. Its Rule of Law Index is one of the leading global sources of independent data on how the rule of law is experienced and perceived in practice. Drawing on surveys of the general public and of qualified legal practitioners and experts across numerous jurisdictions, the Index examines not merely the laws formally in force, but — crucially — how legal institutions actually operate.</p>



<p>The assessment encompasses eight fundamental dimensions: constraints on government powers, absence of corruption, open government, protection of fundamental rights, order and security, regulatory enforcement, civil justice and criminal justice. These areas are evaluated through detailed questions concerning, among other matters, judicial independence, access to justice, the effectiveness and timeliness of court proceedings, due process, the practical enforcement of judgments and regulations, the operation of public authorities, and the protection of individuals against arbitrary or improper exercises of power.</p>



<p>Contributing to this project from the perspective of the Polish jurisdiction was both a privilege and a significant professional responsibility for our partner. Meaningful assessment of the rule of law requires more than an analysis of legislation or institutional structures. It also requires practical knowledge of how courts, prosecutors, law-enforcement bodies and administrative authorities function in real cases — and how legal safeguards are experienced by individuals and businesses navigating the system.</p>



<p>Together with the team at KG Legal KIELTYKA GLADKOWSKI, our partner works primarily on complex cross-border matters and remains actively involved in civil, commercial, administrative and criminal proceedings. This experience provides a close view of the practical operation of the Polish justice system, including cases involving international businesses, foreign investors and individuals from other jurisdictions seeking the protection of their rights or the resolution of disputes before Polish courts and authorities.</p>



<p>Poland&#8217;s position as a major European Union jurisdiction makes this perspective particularly important. Polish courts and public authorities are increasingly called upon to address cases with international, regulatory and cross-border dimensions. As the movement of people, capital, technology and business activities across borders continues to intensify, the predictability, independence, accessibility and effectiveness of the justice system become matters of significance not only domestically, but also for parties and institutions throughout Europe and beyond.</p>



<p>The rule of law is therefore not an abstract constitutional principle. It directly influences the security of individuals, the protection of fundamental rights, confidence in public institutions, the enforceability of contracts, the stability of investment and the ability of businesses and citizens to obtain effective remedies. Reliable, comparative research such as the World Justice Project Rule of Law Index helps transform professional experience and public perceptions into data that can support informed debate, institutional reflection and meaningful reform.</p>



<p>Our partner&#8217;s involvement in this initiative also reflects a broader professional commitment pursued as an active member of the American Bar Association, particularly its International Law Section: promoting the cross-border exchange of legal knowledge, practical experience and perspectives among colleagues from different jurisdictions. Such dialogue is indispensable. No legal system operates in isolation, and many of the challenges affecting justice today — technological transformation, international commerce, migration, regulatory enforcement and the protection of fundamental rights — require cooperation extending beyond national boundaries.</p>



<p>KG Legal KIELTYKA GLADKOWSKI is sincerely grateful to the World Justice Project for the opportunity afforded to our partner to contribute to this important endeavour. It has been a great honour to share practical insights from Poland and to support a project that strengthens knowledge and awareness of the rule of law worldwide.</p>



<p>#WorldJusticeProject #RuleOfLaw #RuleOfLawIndex #Poland #Justice #Judiciary #InternationalLaw #CrossBorderLaw #AmericanBarAssociation #ABAILS #LegalProfession #KGLegal #KieltykaGladkowski #Litigation</p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/partner-of-kg-legal-kieltyka-gladkowski-contributes-to-the-2026-edition-of-the-world-justice-project-rule-of-law-index/">Partner of KG Legal KIELTYKA GLADKOWSKI contributes to the 2026 edition of the World Justice Project Rule of Law Index®</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/partner-of-kg-legal-kieltyka-gladkowski-contributes-to-the-2026-edition-of-the-world-justice-project-rule-of-law-index/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Drone Warfare</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 13:55:20 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Anti-Drone Technology]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Autonomous Weapon Systems]]></category>
		<category><![CDATA[Aviation Law]]></category>
		<category><![CDATA[BVLOS]]></category>
		<category><![CDATA[Counter-Drone Systems]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Defence Tech]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Drone Compliance]]></category>
		<category><![CDATA[Drone Law]]></category>
		<category><![CDATA[Drone Regulation]]></category>
		<category><![CDATA[Drone Warfare]]></category>
		<category><![CDATA[Dual-Use Export Controls]]></category>
		<category><![CDATA[Dual-Use Regulation]]></category>
		<category><![CDATA[Dual-Use Technology]]></category>
		<category><![CDATA[EU Drone Regulation]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[High-Risk AI Systems]]></category>
		<category><![CDATA[Military AI]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[Polish Drone Law]]></category>
		<category><![CDATA[U-space]]></category>
		<category><![CDATA[UAV Law]]></category>
		<category><![CDATA[Unmanned Aircraft]]></category>
		<category><![CDATA[Unmanned Aircraft Systems]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8874</guid>

					<description><![CDATA[<p>Publication date: August 26, 2026 The Legal Environment and Practical Aspects of Dual-Use Technology – the Ukrainian Conflict as a Lens on the Development of EU Regulation and the Polish Jurisdiction &#8211; Expanded Edition &#8211; Legal status as at 25 August 2026 Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: August 26, 2026</strong></mark></p>



<h3 class="wp-block-heading">The Legal Environment and Practical Aspects of Dual-Use Technology – the Ukrainian Conflict as a Lens on the Development of EU Regulation and the Polish Jurisdiction &#8211; Expanded Edition &#8211; Legal status as at 25 August 2026</h3>



<p><em>Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), attorney-at-law (radca prawny) Małgorzata Kiełtyka (M&amp;A, high-technology and highly regulated sectors) – KG Legal Kiełtyka Gładkowski Spółka Partnerska Kancelaria Radców Prawnych; iSTART1 programme.</em></p>



<p><em>This material is of a popular-science and informational nature. It does not constitute legal advice or a binding opinion. Before citing any specific provision, the current consolidated version in EUR-Lex and the current entry in the Polish Journal of Laws (Dziennik Ustaw) should be verified in each case.</em></p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="980" height="551" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png" alt="" class="wp-image-8875" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png 980w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-300x169.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-768x432.png 768w" sizes="auto, (max-width: 980px) 100vw, 980px" /></a></figure>



<span id="more-8874"></span>



<h4 class="wp-block-heading"><em>Abstract</em></h4>



<p class="has-luminous-vivid-amber-background-color has-background">The Russo-Ukrainian conflict has become a lens in which the future of dual-use unmanned technology is brought into focus – and, at the same time, a barometer of the direction its regulation will take. Within two to three years, technological progress has occurred which, in peacetime conditions, would have taken decades. This article combines two perspectives: a technological taxonomy of drone warfare and a map of the legal environment of the European Union and Poland, encompassing nine mutually interpenetrating regulatory pillars – from product certification and airspace management, through artificial intelligence, export control, defence financing, satellite communications, cybersecurity and personal data protection, to international law and the national regime.</p>



<p class="has-white-color has-vivid-red-background-color has-text-color has-background has-link-color wp-elements-6caed12e936c828f3ed6d240556392b7"><strong>The thesis to be verified is that the legal regime of the UAV sector is structurally dual-track: on the civil track, law operates as a consequence of need and as a risk-dampening factor, whereas on the defence track it operates as a driver of development. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive instruments, while the line of dispute is the increasingly blurred dual-use boundary. We analyse seven concrete points of friction between the tracks and formulate a practical qualification map and a 2026–2028 compliance calendar for manufacturers, operators and investors in this sector.</strong></p>



<p><em><strong>Keywords:</strong> unmanned aircraft, dual use, Artificial Intelligence Act, high-risk systems, autonomous weapon systems, export control, U-space, NIS2, CER, personal data protection, European Drone Defence Initiative.</em></p>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile is-vertically-aligned-center has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-74fa267e46e25de8e613770e79a485db"><div class="wp-block-media-text__content">
<h3 class="wp-block-heading">Part I: the Legal Environment and Practical Aspects of Dual-Use Technology</h3>
</div><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/output.mp4"></video></figure></div>



<h2 class="wp-block-heading">1 Introduction</h2>



<h3 class="wp-block-heading">1.1 Nineteen objects over Poland – the moment when law caught up with reality</h3>



<p>The impulse to look at the drone problem not merely as a tactical phenomenon but as a growing strategic threat to Europe comes from reports circulating in the analytical and milblogger space – based on statements of Ukrainian military intelligence (HUR) – that Russia is already producing more jet-powered variants of the Geran-4 and Geran-5 than piston-engined Geran-2s, with figures in the order of approximately 3,000 jet platforms per month against approximately 2,800 piston variants. Assessments of this kind, even if they call for source-related caution, are of significant analytical importance: they show that the scale of Russian production of unmanned means of aerial attack may exceed the framework of a war of attrition against Ukraine and may be perceived as a capability able to support a broader campaign of pressure or threat directed at European states. In this sense, the drone problem is no longer an exclusively military issue, but also a stimulus for a fresh reading of the legal environment of unmanned technologies in Europe – from aviation law, through export control and AI, to cybersecurity, the protection of critical infrastructure and state security.<a href="#_ftn1" id="_ftnref1">[1]</a></p>



<p>On the night of 9/10 September 2025, a dozen or so unmanned aircraft flew into Polish airspace; some of them were shot down by NATO aircraft. This was not an isolated incident – the Romanian government had reported violations as early as January 2025, and in August of the same year a Russian Geran-2-type platform came down near Osiny in eastern Poland. The September event, however, carried a different weight: it triggered consultations under Article 4 of the Washington Treaty, led to the launch of NATO’s operation _Eastern Sentry_, and, in the EU dimension, to the announcement of a “drone wall”, subsequently transformed into the <strong>European Drone Defence Initiative (EDDI)</strong> and <strong>Eastern Flank Watch</strong>.</p>



<p>The current phase of the Russo-Ukrainian conflict makes it plain that both sides are developing unmanned technologies according to different operational logics and economics of use. The Russian side has to a greater extent expanded the segment of drones performing a function complementary to classic means of aerial attack: decoys, platforms imitating the actual strike assets, and cheap carriers used to saturate air defence and force the expenditure of effectors on the Ukrainian side. The Ukrainian side, conversely, is developing more broadly the segment of long-range drones with a real strike function, whose principal purpose is to strike rear-area infrastructure, including refineries, logistics and other objects of high operational value. This difference matters not only militarily but also in legal-regulatory terms, because it translates into different risk profiles as regards the qualification of dual-use technology, liability for the use of means of aerial attack, the protection of critical infrastructure, and the economics of air defence. In practice, the Russian model relies to a considerable degree on forcing a costly defensive reaction on the adversary’s side, whereas the Ukrainian model aims at the asymmetric striking of rear-area targets using relatively cheap platforms, which further deepens the problem of cost disproportionality between a cheap drone and an expensive defensive effector, such as the missiles of the S-300, S-400, Tor or Pantsir systems. In this sense, the conflict is a lens not only of the development of technology, but also of the transformation of the regulatory logic itself: law must now contend not with a single device, but with entire models of the operational use of unmanned technologies.<a href="#_ftn2" id="_ftnref2">[2]</a></p>



<p>For the lawyer, however, something else is most important. The facts give rise to questions about an asymmetry which is the crux of the entire regulatory problem: against platforms with a unit cost counted in thousands of dollars, systems were used whose single effector should cost hundreds of thousands. This cost asymmetry is not merely a budgetary problem. It forces the burden of defence to be shifted onto solutions that are cheap, mass-produced and increasingly autonomous – and therefore precisely onto that class of technology which European Union law regulates most cautiously on the civil side and almost not at all on the military side.</p>



<p><strong>The new regulatory architecture of drone security: from EU strategy to the obligations of critical infrastructure operators and AI systems</strong></p>



<p>Over the following months, the legislative tempo concerning unmanned systems accelerated in a manner unprecedented for this sector. The existing drone regulations had concentrated primarily on aviation safety, the rules for conducting operations, and technical requirements for operators and manufacturers. In 2026, however, a significant shift of regulatory emphasis took place: the drone began to be treated not only as an aviation device, but also as a potential tool of threat to critical infrastructure and as a system that may be subject to the requirements of artificial intelligence regulation.</p>



<p>The first element of this new architecture was the <strong>Action Plan on Drone and Counter Drone Security</strong> (COM(2026) 81 final) presented by the European Commission on 11 February 2026.<a href="#_ftn3" id="_ftnref3">[3]</a> This document does not constitute a legally binding act within the meaning of Article 288 of the Treaty on the Functioning of the European Union,<a href="#_ftn4" id="_ftnref4">[4]</a> but has the character of a European Commission communication – a political and programmatic instrument belonging to the category of so-called soft law. It does not establish direct obligations for Member States, undertakings or critical infrastructure operators, but it sets the direction of the European Union’s future legislative and organisational actions.</p>



<p>The significance of this document lies above all in a change in the way threats connected with unmanned aircraft are perceived. The Commission indicated that the rapid development of drone technologies, their commercial availability and the possibility of their use by entities conducting hostile activities make it necessary to build a European security system encompassing both protection against unauthorised drone operations (counter-drone) and the strengthening of the resilience of Member States’ infrastructure.</p>



<p>The Action Plan provides for the development of Member States’ capabilities in detecting, identifying and neutralising threats caused by drones, better information exchange between security authorities, and the development of counter-drone technologies. Particular importance was attached to the protection of critical infrastructure, military facilities, the external borders of the European Union, and places particularly exposed to the unlawful use of drones.</p>



<p>The European Commission’s Action Plan should accordingly be treated as the first level of the new regulation – the strategic level. It does not yet impose specific legal obligations, but it creates the political justification for subsequent legislative changes at national and EU level.</p>



<p>The second level was the intervention of the Polish legislator. The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts introduced solutions enabling the use of jamming devices in the protection of critical infrastructure.<a href="#_ftn5" id="_ftnref5">[5]</a></p>



<p>This amendment<a href="#_ftn6" id="_ftnref6">[6]</a> is of particular importance because, for the first time in the Polish legal system, an express basis was created for the application of measures interfering with the communications or control of unmanned aircraft by entities connected with the protection of critical infrastructure. It must, however, be precisely noted that the legislator did not grant critical infrastructure operators an independent right to use jamming devices.<a href="#_ftn7" id="_ftnref7">[7]</a> The legal construction was shaped at two levels.</p>



<p>First, <strong>Article 16c</strong>,<a href="#_ftn8" id="_ftnref8">[8]</a> added to the Act on Crisis Management, grants the critical infrastructure operator the competence to take a decision on the admissibility of the use of specified devices.</p>



<p>That provision reads:</p>



<p>“<em>In order to ensure the protection of critical infrastructure, the critical infrastructure operator (…) may take a decision on the admissibility of the use of the devices referred to in paragraph 1, for the time necessary for the performance of activities by security staff of specialist armed security formations (…)</em>”.</p>



<p>Second, the technical scope of those measures follows from the provisions of the <strong>Aviation Law</strong>, in particular Article 156ze(1), which sets out the possibility of using devices serving to counter unmanned aircraft.</p>



<p>Under that provision, such devices may be used for the purpose of:</p>



<p>“<em>interfering with or taking over control of an unmanned aircraft, interfering with the flight control signal or the navigation signal enabling the flight of that aircraft</em>”.<a id="_ftnref9" href="#_ftn9">[9]</a></p>



<p>In practice, this means that the critical infrastructure operator has obtained a new power of a decision-making character, whereas the physical use of the devices remains tied to the activities of the staff of specialist armed security formations (SUFO). This solution is a compromise between the need for effective protection of strategic facilities and the necessity of limiting the risk of uncontrolled use of devices capable of interfering with communications or navigation systems.</p>



<p>The explanatory memorandum to the bill<a href="#_ftn10" id="_ftnref10">[10]</a> stated that the purpose of the regulation is to increase the resilience of critical infrastructure and to provide operators with tools corresponding to contemporary threats, in particular threats making use of unmanned systems.</p>



<p>The third level of regulation was the modification of the timetable for the application of the provisions of the EU Artificial Intelligence Act.</p>



<p>On 29 June 2026, the Council of the European Union approved an amendment to Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the AI Act).<a href="#_ftn11" id="_ftnref11">[11]</a> This amendment did not change the AI Act’s basic risk-based regulatory model, but postponed the dates on which part of the obligations concerning high-risk systems begin to apply.</p>



<p>The most significant change was the extension of the preparatory period for providers of high-risk AI systems. The regulation was intended to enable undertakings, supervisory authorities and standardisation institutions to prepare the appropriate technical and organisational mechanisms, including conformity standards, risk assessment procedures and quality management systems.</p>



<p>This change is also relevant for the drone sector. Contemporary unmanned systems increasingly use artificial intelligence algorithms for autonomous navigation, object identification, image analysis or operational decision-making. In consequence, particular applications of drones may simultaneously be subject to aviation law regulations, provisions concerning the security of critical infrastructure, and the requirements of the AI Act.</p>



<p>By way of example, Article 113 of Regulation (EU) 2024/1689, which sets out the timetable for the application of the AI Act’s provisions, was amended as regards the dates of applicability of the rules concerning high-risk systems, postponing the full application of part of the obligations to later dates.<a href="#_ftn12" id="_ftnref12">[12]</a></p>



<p>As a result, in 2026 a multi-level regulatory architecture concerning a single device came into being. At European Union level, the European Commission set the strategic direction of the development of drone security policy through the non-binding Action Plan. At national level, Poland created a mechanism for the protection of critical infrastructure enabling the use of counter-drone measures. At the technological level, the AI Act laid down the principles of the responsible use of artificial intelligence systems employed in autonomous devices.</p>



<p><strong>Three different regimes. Three different regulatory logics. And all of them concern the same device.</strong></p>



<h2 class="wp-block-heading">1.2 The paradox of acceleration</h2>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="980" height="551" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png" alt="" class="wp-image-8877" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png 980w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1-300x169.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1-768x432.png 768w" sizes="auto, (max-width: 980px) 100vw, 980px" /></a></figure>



<p>The history of military technology knows few moments in which the development curve breaks as abruptly as in Ukraine after 2022. Commentators<a href="#_ftn13" id="_ftnref13">[13]</a> estimate that the technological leap<a href="#_ftn14" id="_ftnref14">[14]</a> in the field of unmanned aircraft accomplished during two to three years of war would, in the absence of an arms race, have taken 20–30 years.<a href="#_ftn15" id="_ftnref15">[15]</a> As to the period, it must be assessed that the thesis itself is <strong>fundamentally true</strong>, but the formulation “20–30 years” is not a scientific claim easily attributable to a single source. It is rather a <strong>metaphor used by military analysts, representatives of the defence industry and commentators</strong>, who describe a <strong>step-change acceleration of the innovation cycle</strong> under the influence of the war. In the space of only two to three years, drones travelled the road from specialised reconnaissance tools to mass-deployed combat systems, encompassing cheap single-use platforms, unmanned swarms, systems resistant to electronic jamming, and solutions using artificial intelligence. In the view of many military analysts, this conflict has shortened the development cycles of unmanned technologies in a way that, in peacetime conditions, would correspond to a multi-year or even multi-decade process of evolution.<a href="#_ftn16" id="_ftnref16">[16]</a></p>



<p>This paradox of acceleration has its source not in success but in failure.<a href="#_ftn17" id="_ftnref17">[17]</a> The original plan of a lightning resolution – seizing the capital within a week and taking control of the south of the country – collapsed already in the cyber phase, when the operation intended to paralyse the digital administration, banking and state budget did not translate into the country’s military collapse. The result was a positional stalemate in the east – trench warfare reminiscent of the fronts of a hundred years ago.</p>



<p>And it was precisely this stalemate, not manoeuvre, that became the incubator of innovation. Tactical pressure in an environment in which neither side can gain a conventional advantage forced a cascade of technological solutions: from commercial observation drones, through mass-scale FPV drones, to satellite-controlled long-range platforms with elements of autonomy.</p>



<p>It is worth emphasising that this mechanism was to a considerable extent <strong>civilian in its genesis</strong>. The drone revolution did not come out of the laboratories of the great arms concerns, but out of the model-making market, out of commercial consumer electronics and out of open-source software. A manufacturer which in 2021 was selling a platform for power-line inspection was in 2023 delivering the same design with a different payload configuration. The law, which for two decades had been building separate regimes for civil aviation and for armaments, found itself confronted with a product that crosses that boundary without any design modification.</p>



<h2 class="wp-block-heading">1.3 Thesis, research question and structure of the argument</h2>



<p>For a lawyer serving entities in the high-technology sector, the paradox of acceleration has a practical dimension. It gives rise to the question that is the axis of this text: <strong>does law in this area merely react to a technology which the conflict has outpaced, or has it itself become an instrument of acceleration – and perhaps, in some segments, an instrument of its extinguishment.</strong></p>



<p>The answer, which we substantiate in the remainder of this text, is: law performs <strong>three different roles simultaneously</strong> in this sector, and which of them is activated is decided not by the technology but by the qualification of the purpose of use. And that qualification is, in the case of dual-use products, inherently unstable.</p>



<p>The structure of the argument is as follows. Part 2 presents the technological taxonomy of drone warfare – without it, legal analysis operates in a vacuum, because each of the regulatory regimes attaches legal consequences to specific technical features (mass, range, presence of sensors, degree of autonomy, type of link). Part 3 maps the legal environment of the European Union and Poland, divided into nine pillars.</p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="627" height="353" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png" alt="" class="wp-image-8879" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png 627w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2-300x169.png 300w" sizes="auto, (max-width: 627px) 100vw, 627px" /></a></figure>



<p>Part 4 analyses seven points of friction at which these pillars collide with one another – it is there that the undertaking’s real legal risk is concentrated. Part 5 formulates the thesis of the dual-track nature of the regime. Part 6 translates the analysis into transactional and compliance practice, together with a compliance calendar up to 2028.</p>



<h2 class="wp-block-heading">2 · The Anatomy of Drone Warfare – a Technological Taxonomy</h2>



<p>The point of departure for any legal analysis must be the differentiation of categories. It is a fundamental error – also in the regulatory debate – to treat the “drone” as a single class of devices. A more apt analogy here is to optics and photography: there is no single universal lens for every photograph, because each type of shot – macro, portrait, telephoto, wide-angle landscape – requires a different optical construction, a different focal length and a different compromise between reach and field of view. It is exactly the same with drones and counter-drone systems: there is no single “anti-drone system”; there are systems countering specific categories of platforms, matched to their signature, range and mode of communication. This differentiation is not merely descriptive but legal in character – it determines product qualification, the export regime and the scope of compliance obligations.</p>



<p>This differentiation has directly normative consequences. At the level of product qualification, the mass, construction and intended purpose of the platform determine its place in the EU UAV regime, in particular in Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, which treat product classes and the “open”, “specific” and “certified” categories of operations differently; in practice this means that the same aircraft may, as a product, remain in lawful civil circulation while at the same time, with a different mode of use or retrofitting, pass into the area of heightened regulatory risk. At the level of the export regime, the identical differentiation decides whether a component, software, sensor, communications module or navigation system falls within the scope of Regulation (EU) 2021/821 as a dual-use product, which may trigger an authorisation requirement, an end-user assessment and a proliferation risk analysis. At the level of compliance obligations, in turn, what matters are not only the physical features of the drone but also its data and autonomy functions: the presence of cameras, sensors or AI modules may in parallel trigger the requirements of the GDPR, cybersecurity, information security and – outside the scope of the military exclusion – the obligations arising from the AI Act. As a result, in the UAV sector it is not enough to ask “what is the product”; the key question becomes in what chain of use, circulation and liability the product operates.</p>



<p>The importance of this differentiation lies in the fact that, in the UAV sector, technical categories translate into different normative consequences in several overlapping legal regimes at once. First, at the level of product and operational qualification, features such as take-off mass, communications architecture, scope of autonomy or type of payload affect the classification of the platform in the light of Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, and thus the admissibility of its placing on the market and the mode of its lawful operation. Second, at the level of export control, the same features may determine whether specific components, sensors, navigation modules, software or technical documentation are covered by the regime of Regulation (EU) 2021/821, which triggers licensing obligations, end-user assessment and proliferation risk assessment. Third, at the level of functional compliance, what matters is no longer only the material features of the platform itself, but also its data-processing, observation and decision-support functions: the use of optical sensors, thermal-imaging sensors, remote identification systems or image-analysis algorithms may in parallel trigger requirements arising from the GDPR, cybersecurity regulation and – outside the scope of the military exclusion – the obligations laid down in the AI Act. In this sense, the legal qualification of a drone is not a one-off act but a multi-layered process, dependent on construction, function, context of use and the architecture of circulation.<a href="#_ftn18" id="_ftnref18">[18]</a></p>



<p>A separate phenomenon, irreducible to any of the above categories, is the drone swarm. Whereas the existing taxonomy ordered drones according to the features of a single platform – mass, range, mode of communication, degree of autonomy – the swarm is an emergent phenomenon at the level of many platforms operating as one system. Three elements are key here: iteration and coordination between units (drones exchange data on position, target and status in real time, often via a mesh network, with no single point of failure), distributed processing of sensor data (imagery and telemetry from many platforms are aggregated and classified jointly, which increases target-detection effectiveness beyond the sum of individual sensors), and collective control by a single operator or a supervisory algorithm which allocates tasks among the units of the swarm. Ukrainian deployments of this technology – including autonomous swarming systems used since 2025 for mine-laying and target engagement, and large-scale operations combining several dozen to several hundred platforms in a single strike – show that the swarm is no longer an experiment but an operational reality. This has serious legal consequences which remain unresolved to date: whether the swarm should be qualified as a single system subject to a single conformity assessment or as a collection of separate products; who bears responsibility for a decision taken at swarm level when no single platform takes it independently; and how the data protection and radio spectrum management regime is to treat a network whose nodes come into being and disappear in flight.<a href="#_ftn19" id="_ftnref19">[19]</a></p>



<p>This differentiation is not merely terminological or descriptive in character, but produces direct legal effects. The individual technical properties of an unmanned aircraft constitute the triggering conditions for different regulatory regimes of European Union law and national law. In practice, this means that a change in one technical parameter of a drone may lead to a fundamentally different legal qualification of the same device.</p>



<p>The first such parameter is the <strong>Maximum Take-Off Mass (MTOM)</strong>. Commission Delegated Regulation (EU) 2019/945 establishes classes of unmanned aircraft systems (C0–C6), whose assignment takes place, among other things, with regard to technical parameters, in particular mass, speed and system equipment. This classification is not purely technical in character – it determines the possibility of conducting operations in the appropriate subcategories of the “open” category provided for in Commission Implementing Regulation (EU) 2019/947 and affects the manufacturer’s obligations connected with conformity assessment and product class marking.<a href="#_ftn20" id="_ftnref20">[20]</a></p>



<p>The significance of mass is also revealed at the level of the operator’s obligations. Under Article 14 of Implementing Regulation (EU) 2019/947, the operator of an unmanned aircraft system is subject to a registration obligation, inter alia, where it operates an aircraft with a maximum take-off mass of at least <strong>250 g</strong> or – regardless of mass – an aircraft equipped with a sensor capable of capturing personal data, unless the device meets the conditions provided for toys within the meaning of Directive 2009/48/EC. The 250 g mass thus constitutes one of the fundamental legal thresholds in the European drone regulatory system.<a href="#_ftn21" id="_ftnref21">[21]</a></p>



<p>The second parameter of fundamental importance is the <strong>drone’s equipment with sensors enabling the capture of personal data</strong>, above all optical cameras, thermal-imaging cameras, LiDAR scanners or other devices allowing the identification of natural persons. In such a case, the General Data Protection Regulation (GDPR) applies. Data recorded by a drone may constitute personal data within the meaning of Article 4(1) GDPR, which entails the necessity of ensuring a legal basis for processing in accordance with Article 6 GDPR, complying with the principles set out in Article 5 GDPR and – in the case of operations creating a high risk to the rights and freedoms of natural persons – carrying out a data protection impact assessment in accordance with Article 35 GDPR. These obligations arise regardless of the mass of the aircraft, and therefore also in relation to the smallest drones weighing under 250 g, if they are equipped with devices enabling the capture of personal data.<a href="#_ftn22" id="_ftnref22">[22]</a></p>



<p>This approach is confirmed in the case law of the Court of Justice of the European Union. In its judgment of 11 December 2014 in Case <strong>C-212/13, Ryneš</strong>, the Court held that the recording of images enabling the identification of natural persons constitutes the processing of personal data, even if it takes place with the use of devices monitoring the surroundings of private property. Although the case concerned video surveillance, the conclusions flowing from that judgment apply mutatis mutandis also to unmanned systems equipped with cameras or other observation sensors.<a href="#_ftn23" id="_ftnref23">[23]</a></p>



<p>A further feature determining the legal regime is the <strong>character of the equipment and payload</strong>. Regulation (EU) 2021/821 of the European Parliament and of the Council establishes the Union’s system for the control of exports of dual-use items. The qualification of a drone or its components for the list of dual-use items is decided not only by flight parameters but also by the technical capabilities of the device, such as range, autonomy, navigation systems, observation equipment, high-resolution cameras, data transmission systems or specialised sensors. In consequence, two seemingly similar drones may be subject to entirely different export obligations solely on account of differences in their equipment or technical capabilities.<a href="#_ftn24" id="_ftnref24">[24]</a></p>



<p>Even more complex is the legal qualification of systems using <strong>artificial intelligence</strong>. The degree of flight autonomy alone does not automatically determine the applicability of the AI Act. It must first be established whether the given solution constitutes an “AI system” within the meaning of Article 3 of Regulation (EU) 2024/1689. Only at the next stage is it necessary to assess whether the system belongs to the high-risk category in accordance with Article 6 of that regulation and Annexes I and III. This means that two drones with identical flight parameters may be subject to different regulatory obligations solely on account of differences in the software responsible for autonomous navigation, object identification, image analysis or operational decision-making.<a href="#_ftn25" id="_ftnref25">[25]</a></p>



<p>In consequence, the legal qualification of an unmanned aircraft does not follow from a single technical feature, but from the configuration of its constructional, functional and operational properties. The same drone may simultaneously be subject to aviation law regulations, personal data protection provisions, the dual-use item control regime, provisions concerning the protection of critical infrastructure and – in specific cases – Regulation (EU) 2024/1689 (the AI Act). This signifies a transition from the classic model of sectoral regulation to a model of functional regulation, in which different branches of law simultaneously apply to the same device, protecting different legal goods: aviation safety, privacy, state security, control of trade in technologies and the safety of artificial intelligence systems.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.1 · Observation drones – the foundation of situational awareness</strong></h3>



<p>The lowest tier consists of commercial multirotor drones (the Chinese DJI Mavic,<a href="#_ftn26" id="_ftnref26">[26]</a> Ukrainian equivalents of the Zoom class). Their role is to provide <strong>situational awareness</strong> – the category that decides the success of every assault and every defence. A contemporary soldier with an overhead picture operates in an entirely different reality from one who scans the field with his eyes.</p>



<p>In the Ukrainian trade and military-technology discourse,<a href="#_ftn27" id="_ftnref27">[27]</a> the designation ZOOM refers to a specific reconnaissance platform developed by the Ukrainian company Frontline / Frontline Robotics, presented as an alternative to the Chinese DJI Mavic drones. It is a light multirotor observation drone intended for reconnaissance tasks, fire correction and building situational awareness at the tactical level, and therefore for the same operational niche which for a long time was dominantly occupied at the front by Mavic platforms. In this sense, the “Ukrainian equivalent of the Mavic of the ZOOM class” should be understood not as a formal technical category but as the proper name of a domestic platform positioned in the segment of light reconnaissance drones with a substitutive function vis-à-vis DJI. The available sources<a href="#_ftn28" id="_ftnref28">[28]</a> also indicate that ZOOM forms part of a broader Ukrainian trend of building domestic Mavic analogues in order to reduce dependence on foreign civilian commercial systems.</p>



<p>Importantly, despite rapid development these platforms have not disappeared – on both sides of the front, civilian Mavics are still used, whose sole task is to “hang in the air and watch”. This is an observation of primary legal importance: <strong>the most numerous category of platforms used in the conflict consists of mass-produced consumer products, placed on the market under the civil regime, with CE marking, in classes C0–C2.</strong> The same unit which yesterday was subject to Implementing Regulation (EU) 2019/947 as an operation in the open category is today carrying out a reconnaissance task outside any EU regime.</p>



<p>The DJI Mavic constitutes a model example of the detachment of the product from the purpose of use. As a commercial product, it was designed and placed on the market for the needs of the civil market: photography, inspection, surveying, recreation and light professional applications. In that order, its legal status is determined by the classic instruments of EU aviation law and product law – in particular the requirements of CE marking, the product classes under Delegated Regulation (EU) 2019/945, the operating rules under Implementing Regulation (EU) 2019/947, the operator’s obligations, remote identification, geographical zones, registration and – depending on the sensor configuration – data protection requirements. However, the moment that same unit is used on contested territory to build situational awareness, correct fire or conduct military reconnaissance, the logic for which the EU civil aviation regime was built ceases to operate. The product itself as a thing does not change, but its operational function changes, and with it the normative order changes: from the area of product safety and lawful civil operation we pass into the area of military operations, military logistics, the law of armed conflict, export control and state security. It is precisely for this reason that, in the UAV sector, the legal nature of a platform is increasingly determined not by its construction but by the chain of use into which it is incorporated.</p>



<p>A good counterpoint to this transformation is the example of the Ukrainian Mavic equivalents, such as the ZOOM developed by the above-mentioned Frontline Robotics. Where the manufacturer communicates<a href="#_ftn29" id="_ftnref29">[29]</a> that a given complex has been entered in the NATO Codification System (NCS) and has received a NATO Stock Number (NSN), this means not so much the obtaining of civil certification as the product’s entry into the common language of NATO defence logistics: the item is unambiguously identified, classified and prepared to function within the system of supply, storage and military interoperability. The NSN is therefore a catalogue-logistics designation, not a mark of quality or an authorisation for marketing in the sense of consumer law or civil aviation law. The juxtaposition of the Mavic with a platform codified in the NATO system well illustrates the institutional shift: the first product begins its life in the regime of civil commercialisation, while the second is from the outset positioned as an element of the defence architecture and the military supply chain. This difference does not consist solely in technology, but in normative embedding – that is, in whether the product is designed for the civil market or for the order of military logistics and allied interoperability.<a href="#_ftn30" id="_ftnref30">[30]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.2 · FPV drones – a squad weapon and the cost revolution</h3>



<p>The current combat standard in the front-line zone is the FPV (first person view) drone – single-use platforms controlled from a first-person perspective through goggles. This is not, however, a weapon of the individual soldier: the operation of a single drone requires a team of 3–4 persons (pilot, relay operator, sapper, frequently a navigator). The FPV is a squad weapon, like a mortar or a heavy machine gun. One team is able to carry out 25–30 sorties a day, consuming a corresponding number of single-use platforms.<a href="#_ftn31" id="_ftnref31">[31]</a></p>



<p>The scale of this revolution has above all an economic and institutional dimension. It is no accident that industry analyses describe FPV as the “$1,000 revolution”: the essence of the breakthrough lies not solely in the platform itself, but in the relationship between the low unit cost of the means of attack and the high cost of countering it, as well as in the possibility of rapidly scaling production on the basis of a dispersed component market, a simple assembly architecture and short iteration cycles. In this sense, FPV is not merely a new category of drone but a new model of the economics of war – a model in which a relatively cheap, partly standardised and rapidly modifiable platform can generate tactical and operational effects disproportionate to its price. That is precisely why the weight of the analysis shifts from the question of the individual product to the question of the production ecosystem, the capacity for its continuous reproduction, and the institutional conditions that enable the transition from field improvisation to mass production.<a href="#_ftn32" id="_ftnref32">[32]</a></p>



<p>In the case of Ukraine, this capacity is no longer solely the effect of spontaneous industrial mobilisation, but results from the construction of an organised, state-supported defence tech ecosystem, centred on the Brave1 platform.<a href="#_ftn33" id="_ftnref33">[33]</a> Brave1 was launched on 26 April 2023 as a governmental defence tech cluster, co-created by the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries,<a href="#_ftn34" id="_ftnref34">[34]</a> with the implementation layer carried out by the Innovation Development Fund. From a legal perspective, this is not a classic commercial-law company nor a single procurement procedure, but rather a public coordination platform combining grant, testing, matchmaking and acceleration functions. Officially, Brave1 describes its role as supporting the development of defence technologies through organisational, informational and financial support for projects, and the platform’s successive initiatives – including grant programmes, a defence innovation marketplace and projects carried out with international partners – show that it operates as an intermediate layer between the technological idea, the prototype, military testing, IP protection and further implementation into procurement or operational use. It is therefore an institutional mechanism for mobilising defence innovation, not a separate, homogeneous statutory regime.</p>



<p>The significance of Brave1 for the FPV market lies in the fact that this platform aggregates dispersed manufacturers and lowers the threshold of entry into the defence sector, shortening the road from design to implementation. Analytical sources indicate that around 1,500 defence tech companies and start-ups are gathered around Brave1, with some more recent analyses speaking of an even greater number of entities functioning within this ecosystem.<a href="#_ftn35" id="_ftnref35">[35]</a> From the point of view of this report, however, more important than the number itself is that Brave1 produces an architecture of scale: new entities can enter the sector via a grant, testing, validation, contact with the military user, intellectual property protection and entry into the procurement circuit, without having to pass immediately through the classic, heavy model of the armaments industry. It is precisely this institutional model that explains why Ukraine was able to move from the early phase of improvisation and purchases from the commercial market to a phase in which drone production began to be treated as a mass state capability.<a href="#_ftn36" id="_ftnref36">[36]</a></p>



<p>The volumes of this production are unprecedented. Industry analyses and statements by representatives of the Ukrainian authorities cite figures of the order of about 800 thousand drones in 2023, about 2 million in 2024, production capacities reaching 4 million annually, and subsequently procurement plans covering about 4.5 million FPV drones in 2025. In parallel, declared targets for 2026 have also appeared in public circulation, according to which Ukraine would aim for a level of 7 million drones annually, presented as a volume many times exceeding American production. Even if the individual figures must be treated with caution and a distinction must be drawn between actual production, production capacity, procurement plan and political-industrial target, the direction itself is unambiguous: Ukraine has transformed drones – especially FPV – from an auxiliary technology into an industrial strategic resource, whose development depends no longer solely on the technical capability of an individual manufacturer, but on state-supported organisational, grant, testing and procurement infrastructure. In this sense, Brave1 operates as a multiplier of production sovereignty: it not only supports a specific project, but builds the conditions in which the entire sector can reproduce itself, scale and become independent of imports of ready-made platforms.<a href="#_ftn37" id="_ftnref37">[37]</a></p>



<p>In the legal and economic layer, it is particularly significant that Brave1 is not limited to the distribution of public funds from the Ukrainian budget. Over time, this platform has also been opened to international grants, partnerships with Western states and institutions, and channels of cooperation with the NATO procurement and interoperability environment. This means that the Ukrainian FPV market is today developing at the intersection of national law, mechanisms of public support for innovation, defence cooperation with foreign partners, and the wartime logic of rapid testing and deployment. From this perspective, the success of Ukrainian unmanned production should not be described solely as an industrial success, but also as a success in the design of institutional instruments which have made it possible to combine thousands of smaller entities into one functional ecosystem capable of delivering effects at the scale of millions of units annually.</p>



<p>The mass character of FPV production and the dispersal of suppliers in Ukraine are not solely a spontaneous effect of wartime mobilisation, but the result of the institutional ordering of the defence tech ecosystem. The importance of Brave1 lies precisely in the fact that this platform does not replace the individual manufacturer or the classic armaments industry, but creates an organisational framework within which hundreds – and, according to the available sources, around one and a half thousand – entities can function as elements of a single innovation-production system. From a legal and economic perspective, Brave1 is therefore not merely a sectoral cluster, but an instrument of the state ordering of defence innovation: it shortens the road from idea to test, from test to grant, from grant to implementation, and in the longer perspective – to an order or operational use. This architecture can be described most cleanly at three levels: institutional, project and operational.</p>



<p class="has-pale-pink-background-color has-background"><strong>1. The institutional level</strong></p>



<p>At the institutional level, Brave1 functions as a governmental initiative / defence tech cluster of Ukraine, launched on 26 April 2023 and co-created by the key state organs responsible for security, defence and technology policy, in particular the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries. The official description further indicates that the initiative is implemented by the Innovation Development Fund, which allows Brave1 to be treated as an instrument embedded at the interface of public administration, the security sector and state innovation policy. It does not follow from the publicly available materials that Brave1 is a self-standing entity established by a single separate statute or a single specific normative act; it is more accurate to conceive of it as a state coordination platform whose status results from the combination of the competences of public institutions and the implementation mechanisms of the innovation development fund. It is precisely this institutional embedding that explains why Brave1 was able to become a focal point for a broad ecosystem of drone manufacturers, including FPV platforms, instead of remaining merely a grant programme or a sectoral initiative of limited reach.</p>



<p class="has-pale-pink-background-color has-background"><strong>2. The project level</strong></p>



<p>At the project level, the Brave1 cluster has been linked with the European Union-financed undertaking EU4UA Defence Tech, functioning publicly under the title “Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base”. It follows from the available sources that this is not a self-standing act of secondary Union law of the kind of a regulation or directive, but an implementation and grant project, officially announced by the Delegation of the European Union to Ukraine within the EEAS structure, financed by the European Union and implemented by BRDO in cooperation with Brave1. In this architecture, Brave1 plays the role of the Ukrainian cluster and access point to the defence tech ecosystem, while the project layer gives this ecosystem an additional dimension of internationalisation, grant support and linkage with the policy of strengthening the Ukrainian defence technological and industrial base. The formal specification of this layer does not, however, take place through a single “founding act” of statutory or Union rank, but through a set of project and operational documents: the EEAS institutional communication, the BRDO project description and the regulations of the grant programme.</p>



<p>Particularly significant from the point of view of a legal report is that the project layer finds its concrete expression in the draft grant agreement concluded between the Innovation Development Fund and the beneficiary being the developer of a specific technology.<a href="#_ftn38" id="_ftnref38">[38]</a> This means that entry into the Brave1 / EU4UA Defence Tech system does not lead directly to a relationship with a Union institution in the typical model of a European Commission grant, but to a contractual relationship governed by Ukrainian law with a public entity on the Ukrainian side. From this perspective, the project level of Brave1 should be understood as a space in which the dispersed sector of manufacturers – including creators of FPV technology – is drawn into a structured model of public support, but at the price of entering a specific contractual regime. Of particular importance here are the clauses concerning ownership and intellectual property rights: the draft grant agreement provides that ownership rights and rights to IP created with the use of grant funds as a rule remain with the developer, which at first sight may suggest a model friendly to commercialisation and to the retention of private control over the result of the project. At the same time, however, the same draft agreement grants the fund a broad, free-of-charge entitlement to use – at its own discretion – all documents and information obtained in the course of the granting of the grant, insofar as such use remains consistent with existing IP rights. This construction therefore does not lead to a simple takeover of IP by the state, but creates a hybrid model of control in which formal ownership remains with the developer, while the fund secures for itself a strong position of access and use in relation to the documentation and information connected with the project. In legal practice, this means that the key question is no longer only who owns the result, but also how broadly the scope of “documents and information” will be interpreted, what technical material is transferred to the fund, and where the boundary runs between the authorised use of documentation and indirect interference with the developer’s economic exclusivity (in accordance with Article 5(1) and (2) of the grant form: “<em>Ownership rights and property rights to intellectual property created as a result of the use of Grant funds belong to the Developer, unless otherwise specified by the Developer.”; ”The Developer grants the Fund the right to use, free of charge and at its own discretion, all documents and information obtained in the process of providing the Grant, if such use complies with existing intellectual property rights</em>”) (see footnote 38).</p>



<p>This tension is further reinforced by the clause on governing law and disputes, according to which the agreement is to be interpreted under the law of Ukraine, and any disputes are to be resolved first by way of negotiations and then in accordance with the procedure provided for by Ukrainian law and/or before a court. In the functional sense, Brave1 / EU4UA Defence Tech therefore remains an undertaking co-financed and politically legitimised by the European Union, but its contractual core – at least at the level of the relationship with the developer – has a clearly Ukrainian jurisdictional embedding. It is precisely this element that should close the analysis of the project level: Brave1 is not solely a mechanism for stimulating innovation, but also a system in which the Ukrainian state, through the innovation development fund and the contractual template, shapes the rules of access to technology, documentation and the results of R&amp;D work. Thanks to this, the cluster can perform the function of a multiplier of mass and scale of production, but it does so in a formula which combines the retention of private intellectual property with a public safeguarding of informational and operational access. It is precisely this combination – and not the mere number of manufacturers – that explains why the dispersed market of FPV suppliers can be integrated into a single functional ecosystem of state-supported defence capability.<a href="#_ftn39" id="_ftnref39">[39]</a></p>



<p class="has-pale-pink-background-color has-background"><strong>3. The operational level</strong></p>



<p>At the operational level, the basic source document is not a general political communication but the regulations of the grant programme, i.e.&nbsp;the Regulations for the Brave1 EU4UA Defence Tech Grant Program, made available in the Legal Terms section of the programme. It is precisely this document that constitutes the most useful source for practical analysis: it determines the framework of participation, the conditions of application, the function of grant support and the operational rules of the call within the initiative linked with EU4UA Defence Tech. In combination with the EEAS communication and the BRDO project description, this document creates the actual operational basis of the programme: the institutional communication legitimises the project and its financing by the EU, the project description indicates its purpose and place in the architecture of cooperation, while the grant regulations order the manner in which undertakings and technology teams can enter the support system. From the perspective of a legal report, it is precisely this operational layer that is key to understanding how dispersed manufacturers of FPV and other defence technologies have been gathered around a single cluster: not through an abstract political declaration, but through a set of specific procedures, grants, tests, validations and pathways to implementation. As a result, Brave1 operates as an institutional multiplier of production capability – it not only finances innovation but organises its transition into a mass state capability.<a href="#_ftn40" id="_ftnref40">[40]</a></p>



<p>The regulatory consequence of this scale is under-appreciated. Product certification regimes – both aviation and armaments – were built around the assumption of small-series production of goods with a long life cycle and high unit value. A model in which a platform comes into being within a week, is consumed within hours and undergoes continuous design modification in reaction to the adversary’s countermeasures is structurally incompatible with that assumption. No European conformity regime was designed for a product whose iteration cycle is shorter than the conformity assessment cycle.</p>



<p>That is precisely why the Ukrainian mass production of FPV should not be described solely as the result of wartime improvisation or of the cost advantage of a cheap platform over an expensive defensive effector, but also as the result of a consciously built institutional architecture in which Brave1 performs the function of a common node for the state, the military, grant-givers and the dispersed defence tech industry.<a href="#_ftn41" id="_ftnref41">[41]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.3 · Communications, the radio horizon and relays</strong></h3>



<p>The effectiveness of FPV depends on communications to a degree perhaps greater than on the quality of the platform itself, and the absolutely fundamental category here is the <strong>radio horizon</strong>. The radio horizon is not a separate normative concept of EU law or of Polish aviation law, but a technical-operational category describing the limit of effective propagation of a radio signal in communications requiring a line of sight between transmitter and receiver. In practice, this means that the range of control and data transmission depends not only on the power of the devices, but also on antenna height, terrain obstacles, built-up areas, forestation and the shape of the terrain. The legal significance of this category is therefore indirect in character: the concept itself is not regulated as a statutory definition, but the phenomena it describes enter legal analysis through the regime of radio equipment, spectrum management, electronic communications, and the safety and reliability requirements for unmanned operations, especially BVLOS and within U-space.<a href="#_ftn42" id="_ftnref42">[42]</a></p>



<ul class="wp-block-list">
<li><strong>BVLOS – flight beyond visual line of sight, i.e. beyond the operator’s visual range.</strong><br><strong>In practice, it is precisely this category of operations that most needs stable, trusted and legally permissible relay infrastructure.</strong></li>



<li><strong>U-space – simplifying, this is the digital drone traffic management environment, created so that a larger number of drones can fly safely, predictably and in an automated manner, especially in more difficult operations and denser airspace.</strong></li>
</ul>



<p>The control signal and image transmission in classic FPV systems require as clean a line of sight as possible, which is why their propagation is attenuated not only by buildings, forest walls or dense development, but also by the relief of the terrain itself: depressions, escarpments, embankments, forested ridges, rural development and all obstacles that “break” the connection between the operator and the platform. In the realities of the Russo-Ukrainian war, this means that the advantage does not follow solely from the flight parameters of the drone, but from the ability to raise the communications point above terrain obstacles and to maintain a stable transmission channel despite jamming, masking and target movement. Hence the great importance acquired by relays – signal repeaters mounted on masts, on ground vehicles, and most often on separate drones hovering higher than the combat platform. In the simplest variant, such a relay is a separate item of equipment, a kind of “communications superstructure” added to the system; in more advanced solutions, the relay function becomes part of a larger architecture, in which one drone carries the payload, a second observes, a third provides retransmission, and further nodes take over part of the traffic in a network model. This means that the relay need not be understood solely as a single device purchased separately – increasingly it is a separate technological layer, which may take the form of a radio module, an additional aerial platform, a ground set, or a node in a mesh network. It is precisely here that one of the most interesting trends appears: the transition from a single repeater to a layered architecture, and then to dynamic mesh networks, in which every modem or selected platforms can simultaneously transmit and repeat the signal, creating a self-repairing chain of communications. In such an arrangement, the radio horizon problem is no longer solved by a single device, but by a system of systems, functionally approaching a swarm with a division of roles. This in turn means that <strong>the most valuable IP in this segment may not reside in the airframe at all, but in the signal-routing algorithms</strong>, <strong>node switching, jamming resistance, bandwidth management and the integration of the relay function with the combat or reconnaissance role</strong>. Competitive advantage may here be protected as a patent, software, a trade secret or systemic know-how; in practice, value increasingly shifts from “the drone itself” to the communications and control architecture which allows the platform to operate effectively outside the classic line of sight. In this sense, the fight for advantage in the air simultaneously becomes a fight over who will build a higher-elevated, more resilient and more intelligently managed transmission network than the adversary.</p>



<p>This architecture has legal significance extending beyond the battlefield. <strong>Retransmission</strong> is in essence the construction of an <strong>ad hoc, mobile radio communications network</strong> – and thus an activity which, in the civil regime, is subject to electronic communications law, spectrum management and the requirements of Directive 2014/53/EU on radio equipment. The civil equivalent of this architecture – relay networks for BVLOS operations – is one of the fundamental implementation challenges of the U-space framework.</p>



<p><strong>RED 2014/53/EU – this is the radio equipment regime, i.e.&nbsp;not only “does the drone work”, but whether its communications modules:</strong></p>



<ul class="wp-block-list">
<li><strong>lawfully use the spectrum,</strong></li>



<li><strong>do not interfere with other systems,</strong></li>



<li><strong>are safe and electromagnetically compatible.</strong></li>
</ul>



<p>The retransmission architecture has legal significance extending far beyond the battlefield, because from the civil perspective it in essence means the construction of an <strong>ad hoc, mobile electronic communications network for unmanned operations</strong>. What in wartime conditions takes the form of an improvised or semi-improvised radio bridge between operator and drone becomes, in the civil environment, a multi-layered issue: <strong>it concerns not only the aircraft itself, but also radio equipment, frequencies, electromagnetic compatibility, data integrity, network resilience and liability for the continuity of the communications service</strong>. For this reason, at least three legal orders enter here in parallel.<a href="#_ftn43" id="_ftnref43">[43]</a> First, the law of electronic communications and spectrum management, because the relay is no longer merely “part of the drone”, but an element of transmission infrastructure affecting the <strong>radio spectrum and requiring conformity with the rules on the use of bands</strong>. Second, Directive 2014/53/EU (RED), i.e.&nbsp;the radio equipment regime, whose essence is to ensure that equipment uses the spectrum efficiently, does not interfere with the operation of other systems and satisfies safety and compatibility requirements. Third, the U-space framework, which is not “a single drone system” but a regulatory model of highly digitalised and partly automated management of a large number of unmanned operations, in particular also BVLOS (beyond visual line of sight) flights. Relay networks for BVLOS operations therefore in practice mean a model in which the continuity of the flight does not depend on a simple, linear operator-drone connection, but on an entire chain of communications services, identification, data transmission and coordination with the digital airspace. That is precisely why one of the main implementation challenges of U-space is not the mere fact that the drone flies beyond visual range, but who is responsible, and on what terms, for the communications layer sustaining such a flight: for the reliability of the channel, the interoperability of the equipment, information security, jamming resistance, cybersecurity and the technical conformity of the entire transmission chain. In civil conditions, the problem which at the front is solved by an improvised relay or a mesh network therefore becomes a regulatory problem of the highest rank: the question is no longer only whether the drone may fly, but whether there exists a lawful and secure communications infrastructure allowing it to fly outside the simple logic of direct contact.<a href="#_ftn44" id="_ftnref44">[44]</a></p>



<p>If, however, the relay and the mesh network<a href="#_ftn45" id="_ftnref45">[45]</a> are an attempt to solve the radio horizon problem within the logic of radio emission, then fibre-optic drones represent an attempt to step outside that logic altogether. Whereas the relay architecture endeavours to elevate, stabilise and disperse the signal, the optical fibre eliminates the need for its emission in radio space, and thereby undermines a considerable part of the existing assumptions of both counter-drone technologies and regulation based on the detectability and jammability of the signal.</p>



<p><strong>Mesh network, Shahed/Geran and the shift from loitering munition to a networked strike system</strong></p>



<p>One of the most interesting and at the same time most disturbing phenomena of the current phase of the drone war is the transition from a simple point-to-point control model to a mesh network architecture, that is a lattice or grid network. Unlike the classic arrangement in which the operator communicates directly with a single platform or via a single relay, the mesh network consists of many nodes capable of simultaneously receiving, forwarding and amplifying the signal. Each such node can be part of a larger transmission system: a ground modem, an intermediate station, an observation platform or the drone itself. In practice, this means that communications do not depend on one channel and one transmission route, but can be dynamically reconfigured depending on which elements of the network remain active, where the platforms are located and what the jamming environment looks like. That is precisely why the mesh network is an architecture more resilient, flexible and difficult to disable than a classic linear connection. It is no longer a “link to the drone”, but a dispersed operational network.</p>



<p>In relation to heavy platforms of the Shahed/Geran type, such an architecture has breakthrough significance, because it blurs the boundary between a loitering munition and a network-controlled or network-supervised drone. Traditionally, loitering munitions are perceived as an essentially single-use means flying along a route programmed in advance or corrected to a limited extent. Meanwhile, equipping heavy drones with mesh modems, retransmission nodes and external relay points means that the system ceases to be merely a “blind carrier” executing a sequence of commands recorded once. It enters a more flexible model: it can maintain communications deeper over the adversary’s territory, benefit from mutual signal amplification, and in some configurations also from more up-to-date mission supervision. It is precisely for this reason that analysts speak of the blurring of the boundary between the classic loitering munition and the one-way attack UAV with elements of networked command. In other words: if the “Shahed” begins to function as part of a communications system, it ceases to be solely a single-use kinetic effect and begins to resemble a networked means of aerial attack, whose effectiveness depends not only on the airframe and warhead, but on the data transmission architecture.</p>



<p>This is very well illustrated by the Belarusian case from the beginning of 2026, when reports appeared in the analytical space of Russia’s use of relay stations and other network nodes supporting the flights of Shaheds operating from that direction, and subsequently of their elimination by the Ukrainian side.<a href="#_ftn46" id="_ftnref46">[46]</a> Even if part of the details of those events remains based on front-line, technical and media sources rather than on full, open official material, the operational sense of such a solution is itself logical and coherent: if the platform is to fly deep, maintain communications and benefit from the effect of mutual retransmission, then the network cannot end at the drone itself. It must have external nodes sustaining the communications architecture, whether in the form of border stations, relay towers, ground amplification points or other supporting elements. The destruction of such nodes does not mean the destruction of a single drone, but a strike at the network layer which makes the entire system more dangerous. In this sense, Ukraine is not merely destroying the carrier of a warhead, but degrading the communications infrastructure of the attack.</p>



<p>Technologically, the most dangerous aspect is that the mesh network changes the logic of defence. In the classic model, it was enough to cut the connection, destroy the platform or jam a single channel. In the grid model, the adversary can attempt to:</p>



<ul class="wp-block-list">
<li><strong>redirect traffic along another route,</strong></li>



<li><strong>use other drones as relays,</strong></li>



<li><strong>dynamically change the structure of communications,</strong></li>



<li><strong>combine strike, reconnaissance and retransmission platforms into a single arrangement.</strong></li>
</ul>



<p><strong>This in turn naturally brings such a system closer to a swarm with a division of roles</strong>. Not all platforms have to attack. Some may perform the role of:</p>



<ul class="wp-block-list">
<li>communications nodes,</li>



<li>observers,</li>



<li>decoys,</li>



<li>retransmission carriers,</li>



<li>elements building the resilience of the network.</li>
</ul>



<p>This means that advantage increasingly depends not on a “better drone” but on a better systemic architecture. It is precisely here that IP of the highest value is born: not in the airframe itself, but in the modems, transmission protocols, routing algorithms, jamming resistance, throughput management, node authorisation and the integration of the relay role with the combat role. Solutions of this kind may be protected as a patent, software, a trade secret or systemic know-how. In practice, market and military value therefore shifts from the individual product to the network architecture, which may be more difficult to copy than the drone itself.</p>



<p>This shift also has very significant legal consequences. First, the mesh network is not directly a legal category of aviation law or EU drone law; it is above all a technical concept. However, its legal significance is indirectly enormous, because it describes the structure of communications on which the operation of unmanned platforms depends. The moment such a network is analysed outside the theatre of hostilities, we immediately enter the area of electronic communications law, spectrum management and the radio equipment regime. For if the effectiveness of the drone depends on a dispersed arrangement of transmitters, modems and relay nodes, then we are no longer dealing solely with an aircraft, but with regulated communications infrastructure. Here, Directive 2014/53/EU (RED) gains significance, because all radio transmission modules – especially when they form a system of mutual relays – must be analysed from the perspective of the efficient use of the spectrum, electromagnetic compatibility and equipment safety. In such a framing, the mesh network is not only a technical feature but a question of whether the radio network being built conforms to the rules on the use of bands and does not generate new risks for other communications systems.</p>



<p>Second, the mesh network has a cybersecurity and information security dimension. Every additional node means not only greater flexibility of the communications architecture, but also a greater attack surface: more points vulnerable to takeover, impersonation of an authorised element of the system, spoofing, jamming or the injection of false data. The injection of false data should here be understood as the introduction into the network of signals, messages or parameters which appear authentic but are intended to mislead the other nodes, cause an erroneous reconfiguration of connections, direct the platforms along another route or distort the picture of the operational situation. The more the system passes from a simple point-to-point connection to a dispersed lattice network, the more crucial becomes not the mere transmission of the signal, but trust in its source, integrity and authenticity. That is precisely why mesh technology shifts the analysis from the level of simple drone control towards the issues of node authorisation, data integrity and the resilience of the communications architecture to manipulation.</p>



<p>The legal dimension of this phenomenon is multi-layered. First, the more the effectiveness of the system depends on a multi-node transmission architecture, the less sufficient it is to treat it solely as an aircraft, and the more necessary it becomes to conceive of it as an element of regulated radiocommunications infrastructure – and thus also through the prism of the radio equipment regime, spectrum use and electromagnetic compatibility, with which the significance of Directive 2014/53/EU (RED) is indirectly connected. Second, the strategic value of the system shifts from the airframe itself to the modems, antennas, amplifiers, jamming-resistance systems and routing software, which reinforces their significance as dual-use components. Third, the mesh architecture creates the conditions for dispersed functional autonomy: it enables the redirection of the flight during the mission, the use of other platforms as relays, the dynamic alteration of the communications structure and the combination of strike, reconnaissance and retransmission platforms into a single arrangement. In the case of heavy Shahed/Geran drones, this leads to the blurring of the boundary between the classic loitering munition and a network-supported means of aerial attack. The reports of the use of external relay stations on the Belarusian direction and of their elimination by the Ukrainian side show well that the object of the fight is now not only the drone itself, but also the communications layer which sustains its operation. In this sense, the drone war simultaneously becomes a war for control over dispersed data transmission infrastructure.</p>



<p>In a dispersed communications system, security no longer depends on a single link, but on the integrity of the entire arrangement of mutual trust between nodes. This makes the legal analysis of such systems naturally shift also towards questions of:</p>



<ul class="wp-block-list">
<li>signal integrity,</li>



<li>device authorisation,</li>



<li>resistance to manipulation,</li>



<li>the security of data transmitted between nodes,</li>



<li>and, in the civil equivalent, also towards regimes functionally approximating the requirements imposed on high-risk digital infrastructure.</li>
</ul>



<p>Third, mesh technology has an obvious significance for dual-use export control. While the airframe itself may be relatively simple, the true value and strategic sensitivity is concentrated in the communications components: modems, amplifiers, antennas, jamming-resistance systems, routing and network management software. It is precisely these elements that most easily move from the civil market to the military one and vice versa. In consequence, the components building mesh networks may be analysed not only as part of the end product, but as self-standing dual-use components, whose export, technical transfer and integration may be subject to a separate licensing and security assessment.</p>



<p>Fourth, the mesh network leads us to the boundary of the issues of AI and functional autonomy. The lattice network itself is not yet artificial intelligence, but when it begins to support:</p>



<ul class="wp-block-list">
<li>automatic selection of the signal route,</li>



<li>adaptive node switching,</li>



<li>coordination of multiple platforms,</li>



<li>sharing of observations and targeting data,</li>



<li>maintenance of the mission despite the loss of part of the system’s elements,</li>
</ul>



<p>then in practice we approach an architecture in which operational decisions no longer flow solely from a direct human command, but from the dispersed operation of the system. This gives rise to the classic questions of responsibility, predictability and the qualification of such a network as an element of a more autonomous means of warfare. In the European context, this tension is particularly interesting, because civil applications of AI and communications are subject to ever greater regulation, while military applications of networked autonomy remain to a large extent outside the scope of the classic civil conformity regimes.</p>



<p>Finally, from the perspective of the law of armed conflict, the mesh network changes the very object of what is regarded as a significant component of combat capability. If the effectiveness of the system depends on a dispersed layer of relays, modems and relay stations, then the target of military significance becomes not only the drone itself, but also the communications infrastructure sustaining its operation. This shifts the analysis from the level of the individual effector to the level of the entire network architecture. One might say that, in such a model, the drone war is becoming to an ever greater degree a war for control over the aerial and border-zone tactical internet.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.4 · Fibre-optic drones – the end of the jamming era</strong></h3>



<p>The breakthrough proved to be drones controlled by <strong>optical fibre</strong> – a spool of thin glass fibre unwound in flight. The solution has its costs (the mass of the fibre limits range, payload and manoeuvrability), but it eliminates two problems at once: the radio horizon ceases to matter, and the drone cannot be jammed, because it emits no radio signal. It is an electronically “mute” platform – practically undetectable by RF detectors and resistant to electronic warfare.</p>



<p>Fibre-optic drones appeared en masse in August 2024 in the Kursk area,<a href="#_ftn47" id="_ftnref47">[47]</a> where Russian platforms of this type – with a range of over 30 km and a “crystal-clear” image – paralysed Ukrainian logistics along the sole supply route. As one Ukrainian medic put it, logistics simply collapsed, because fibre-optic drones were monitoring all the routes. By January 2026, fibre-optic variants accounted in some sectors for 30–50% of Russian FPV operations and around 15% of Ukrainian ones. In 2025, countering fibre-optic drones became the central theme of the NATO Innovation Challenge.<a href="#_ftn48" id="_ftnref48">[48]</a></p>



<p>The regulatory significance of this category is difficult to overestimate and remains unnoticed in the public debate. <strong>The entire European acquis on countering unauthorised unmanned operations – both technical and normative – rests on the assumption that the drone emits a radio signal</strong>.<a href="#_ftn49" id="_ftnref49">[49]</a> On this assumption were built the remote identification requirement, RF detection systems, the jamming powers granted to the services and, from June 2026, to critical infrastructure operators. The fibre-optic platform invalidates each of those mechanisms simultaneously. Regulation aimed at a specific relay technology ages faster than the legislative process in which it comes into being.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.5 · Electronic warfare and spoofing</h3>



<p>Classic <strong>jamming</strong> consists in generating noise on radio frequencies so that the drone cannot distinguish the operator’s signal from the interference and loses control. For platforms flying to preset coordinates (deep strike), <strong>spoofing</strong> is used instead – the substitution of the satellite navigation signal, as a result of which the drone “thinks” it is somewhere else and corrects its flight in the wrong direction.</p>



<p>This distinction translates directly into the choice of defensive means – but also into legal qualification. <strong>Jamming is an interference with the radio spectrum</strong>, and thus with a good administered by the state and protected by electronic communications provisions; <strong>spoofing is an interference with the integrity of the signal of a satellite navigation system</strong>,<a href="#_ftn50" id="_ftnref50">[50]</a> and thus with infrastructure of a global character, the disruption of which has effects far beyond the target. The side effects of both measures – loss of the GNSS signal by civil aviation, maritime transport, power grids synchronised by satellite time – are a classic example of damage in which establishing the causal link and the responsible entity is exceptionally difficult. We return to this issue in section 4.3.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.6 · Heavy platforms – bombers, wings, loitering munitions</h3>



<ul class="wp-block-list">
<li><strong>Heavy bombers</strong> (Ukr. Vampire,<a id="_ftnref51" href="#_ftn51">[51]</a> colloquially “Baba Yaga”<a id="_ftnref52" href="#_ftn52">[52]</a>) – multirotors carrying anti-tank mines and performing logistics tasks (transport of ammunition, water, medicines). They require heavier means of engagement – 12.7/14.5 mm machine guns with thermal imaging.</li>



<li><strong>Light wings</strong> (Rus. Molniya<a id="_ftnref53" href="#_ftn53">[53]</a>) – cheap long-range airframes, of low precision but mass-produced; they are sometimes armed with incendiary charges.</li>



<li><strong>Loitering munitions</strong> (Rus. Lancet,<a id="_ftnref54" href="#_ftn54">[54]</a> Ukr. Bulava,<a id="_ftnref55" href="#_ftn55">[55]</a> Pol. Warmate<a id="_ftnref56" href="#_ftn56">[56]</a>) – advanced platforms for the elimination of artillery and anti-aircraft systems; difficult to shoot down owing to low-detectability materials and their flight profile.</li>
</ul>



<p>The category of loitering munitions deserves separate legal attention. It is a construction at the boundary between an unmanned aircraft and a missile: a platform which remains in the task area for an extended time, searching for a target, and then carries out the strike. The blurring of the boundary between “aircraft” and “munition” has consequences in each of the regimes analysed – from classification on the control list of dual-use items, through the intra-EU transfer regime, to the question of the character of human control over the use of force.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-b829efbeca099a974d06d935cfe43b95">2.7 · Deep strike and autonomy – Fire Point as a case study</h3>



<p>The highest tier consists of heavy long-range platforms. The model example is the Ukrainian <strong>FP-1.</strong> The Ukrainian FP-1,<a href="#_ftn57" id="_ftnref57">[57]</a> developed by Fire Point, is a one-way strike drone of light construction,<a href="#_ftn58" id="_ftnref58">[58]</a> including fuselage elements made of plywood, powered by a two-cylinder engine; industry and media sources estimate its unit cost at approximately USD 55,000–58,000, i.e.&nbsp;significantly below the level of comparable systems. In mid-2025, a rapid increase in the scale of production was reported, already counted in hundreds of units weekly and over 100 units daily, and in July 2026 drones attributed to the FP-1 family were linked to the strike on the refinery in Omsk, one of the deepest Ukrainian long-range attacks.<a href="#_ftn59" id="_ftnref59">[59]</a></p>



<p>This case study is instructive for three reasons. First, it shows the <strong>inversion of the classic cost curve</strong> of the defence industry: a construction made of commercially available materials achieves an operational effect comparable to systems of many times higher cost. Second, it demonstrates the <strong>scalability of production outside the traditional armaments chain</strong> – growth from 30 to over 100 units daily within a few months is difficult under the regime of classic military certification. Third, this problem illustrates that range is not solely a technical parameter, but also a regulatory category. This follows from the logic of the Missile Technology Control Regime (MTCR), which – although it is not a classic international agreement in treaty form, but an informal export control regime based on common guidelines and a control annex – has long covered not only classic missiles but also unmanned aerial systems capable of carrying a payload over considerable distances. The most restrictive layer, i.e.&nbsp;Category I, encompasses complete rocket systems and unmanned aerial systems capable of delivering a payload of at least 500 kg to a range of at least 300 km, together with specified subsystems and technologies. This means that a platform with a range exceeding 2,500 km – even if it does not always satisfy every historical parameter of a classic missile system – enters the same type of strategic regulatory sensitivity which for decades has triggered the sharpest logic of proliferation control. In European practice, this logic was subsequently absorbed into the dual-use regime, in which references to the MTCR remain an element of the system of control of exports of technology and means of delivery (in EU law, the logic of the Missile Technology Control Regime (MTCR) was taken over into the system of control of exports of dual-use items primarily by Regulation (EU) 2021/821, which in recital 3 refers to the multilateral export control regimes, including expressly the MTCR, and then develops this logic operationally in Annex I, containing the EU dual-use control list). In this sense, great range is not merely an engineering feature, but a legally relevant feature, because from a specified threshold it triggers a normative order closer to proliferation control, export control and strategic security than to the ordinary regulation of a civil UAV.<a href="#_ftn60" id="_ftnref60">[60]</a></p>



<p>The boundary between control and autonomy is blurring. Placing a satellite communications terminal on a drone allows it to be controlled from enormous distances; the use of machine vision algorithms enables autonomous terminal guidance onto the target after loss of communications.<a href="#_ftn61" id="_ftnref61">[61]</a> It is precisely this last feature – <strong>terminal autonomy, i.e.&nbsp;the capability to complete the task without a human in the decision loop</strong> – that is the heart of the legal problem to which we now turn.</p>



<p>Conceptual precision, usually lacking in the public debate, is worth preserving here. Autonomy is not a binary feature but a spectrum encompassing at least: (i) flight stabilisation and route keeping, (ii) navigation without a satellite signal using terrain image correlation, (iii) automatic detection and classification of objects, (iv) automatic tracking of a target designated by the operator in the terminal phase, (v) independent selection of a target within a designated area. Legal regimes – both the EU Artificial Intelligence Act and the discussion of autonomous weapon systems within the framework of the CCW Convention – react differently to each of these levels, and the distinction between (iv) and (v) is in practice the most difficult to prove in evidentiary proceedings and at the same time the most legally momentous.<a href="#_ftn62" id="_ftnref62">[62]</a></p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-c24f92bca5ae43f507f4405514293ee8">2.8 · The countermeasure layer – a C-UAS taxonomy</h3>



<p>Symmetrically to the strike layer, the countermeasure layer (_counter-UAS_, C-UAS) has developed, which for the European civil market today has greater economic significance than the strike layer itself. Its taxonomy comprises two segments.</p>



<p><strong>Detection and identification:</strong> radio sensors (monitoring of control and image-transmission bands), low-power radars, acoustic sensors, optoelectronic systems with a thermal channel, and – increasingly – fusion of data from multiple sensors with machine-learning-based classification. It is precisely in this segment that artificial intelligence performs a critical role, and it is precisely this segment that is fully civil, and therefore covered by the EU regime without exclusions.</p>



<p><strong>Neutralisation:</strong> jamming of the control link and image transmission, spoofing of satellite navigation, taking over control of the platform, mechanical means (nets, including those launched from interceptor platforms), kinetic means (from smoothbore weapons to artillery systems with programmable ammunition), directed energy (lasers, high-power pulse) and interceptor drones.</p>



<p>This distinction is legally significant, because <strong>each of the effectors is subject to a different regime</strong>: jamming and spoofing fall under electronic communications law and spectrum management; kinetic means fall under the law on weapons and ammunition and liability for damage caused by falling debris; taking over control is an interference with an ICT system, and thus potentially an act criminalised under criminal law if it does not have an express statutory basis. A separate problem is that effective detection requires data processing – on which see section 3.7.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-fc4ca7a709b60c51cc6529ffa9fbd3e2">2.9 The kill chain and the place of the human in the loop</h3>



<p>For the legal analysis of autonomy, it is indispensable to break the process down into links. Adopting a simplified model of the kill chain: <strong>a)</strong> <strong>detection b) identification and classification c) prioritisation d) engagement decision e) terminal guidance f) effects assessment</strong>. The debate on “meaningful human control” in essence concerns the question in which of these links the human takes the constitutive decision and whether at that moment he has information and time sufficient for that decision to be real rather than formal in character.</p>



<p>In the practice of contemporary drone operations: the first and second links are increasingly automated (image classifiers), the fourth link remains on the human side, and the fifth link is sometimes autonomous out of technical necessity – after loss of the link. Legally, this means that <strong>the “human in the loop” construction rests on a link of which the adversary consistently tries to deprive it</strong>. The argument that loss of communications is a technical circumstance and not a design decision loses its force at the moment when the manufacturer designs the platform on the assumption of operation in a heavily jammed environment.</p>



<p>An analogous structure – with different consequences – occurs on the civil side. Article 14 of the Artificial Intelligence Act requires that a high-risk system be designed so that natural persons can effectively oversee it, including understanding its limitations, correctly interpreting its output and deciding not to use it or to interrupt its operation. This requirement is technically identical to the postulate of meaningful human control – with the difference that on the civil track it is a legal norm backed by a sanction, while on the military track it remains the subject of unfinished international negotiations.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-2017345879af2cf699291d5c1d972a9a">2.10 · The data layer – the drone as a sensory platform</h3>



<p>The last layer, systematically omitted in technical analyses, is the data layer. Each of the platforms described is above all a <strong>sensor generating a stream of data</strong>: visual and thermal imagery, telemetry, position, radio spectrum parameters. The operational value of an unmanned system today lies to a lesser degree in the platform and to a greater degree in the chain of processing of those data – from transmission, through storage and annotation, to use in training image-recognition models.</p>



<p>From this arises a chain which crosses the civil-military boundary in both directions. Collections of recordings from combat operations constitute training material of a value impossible to obtain in laboratory conditions – and they are used to perfect classifiers, which subsequently find their way into civil systems (infrastructure monitoring, border protection, crisis management). In the other direction: models trained on civil collections of aerial imagery constitute the base for target-recognition systems.</p>



<p>This bidirectional flow is – as we demonstrate in section 4.5 – the area in which the EU data protection and artificial intelligence regimes come into contact with the defence exclusions in the manner that is legally most unclear and practically most momentous.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-b40798181a77e5f0106eeefd5df8d31e">2.11 · The innovation spiral as a law of development</h3>



<p>Drone warfare is a spiral process: each innovation provokes a countermeasure, and that forces the next innovation: the observation Mavic; drops; FPV; jamming; the relay; the optical fibre; satellite communications; satellite jamming; AI autonomy; interceptor drones.</p>



<p>For the regulator, this means that <strong>every norm aimed at a specific technology ages at the pace of that spiral</strong>. This is an argument in favour of regulation based on effects and on the level of risk, rather than on a catalogue of technical solutions – and at the same time an explanation of why acts based on risk classification (the Artificial Intelligence Act) have a greater chance of remaining current than acts based on product catalogues (dual-use control lists, classes C0–C6).</p>



<h2 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-1035e1196f56a434e54324ff2724ae0c"></h2>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile"><div class="wp-block-media-text__content">
<h3 class="wp-block-heading has-vivid-red-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-3a45f71ad483e1cd03cf6eadb1a92188">3 · The Legal Environment – Nine Pillars</h3>
</div><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/output-1-1.mp4"></video></figure></div>



<p>The legal environment of the UAV sector is not one act or one branch. It is a lattice of regimes, which it is worth ordering into nine pillars. Below, we furnish each of them both with its legal basis and with a practical “flavour” relevant to the servicing of entities in the sector.</p>



<p>The original version of this taxonomy comprised seven pillars. The extension by two further ones – personal data protection and data governance, and public international law – is not a tidying-up exercise. It follows from the observation made in section 2.10: since the value of the unmanned system has shifted from the platform to the data, the data regime has ceased to be a side issue and has become one of the two or three pillars determining the business model. International law, in turn, is the only regime which covers the space left by the defence exclusions of EU law – and therefore precisely the space in which the revolution described above is playing out.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>3.1 · Pillar I – UAV categories and airspace</strong></h3>



<p>The core of the civil regime is formed by three related acts founded on the basic Regulation (EU) 2018/1139 (EASA): <strong>Delegated Regulation (EU) 2019/945</strong> (product requirements, classes C0–C6, CE marking) and <strong>Implementing Regulation (EU) 2019/947</strong> (operations in the open, specific and certified categories). The spatial layer is completed by the U-space package: <strong>Implementing Regulation (EU) 2021/664</strong> together with 2021/665 and 2021/666.</p>



<p>The architecture of this pillar rests on two independent axes of qualification, the confusion of which is the most frequent error in the practice of the industry. The first axis – the <strong>product axis</strong> – concerns what the device is: classes C0–C6 lay down construction requirements, including the obligation to be equipped with a remote identification system and a geo-awareness function for the higher classes. The second axis – the <strong>operational axis</strong> – concerns what is done with it: the open category covers low-risk operations within visual range, the specific category requires an authorisation based on a risk assessment (the SORA methodology) or a declaration of conformity with a standard scenario, and the certified category brings the regime close to classic manned aviation.</p>



<p>The U-space layer, in turn, introduces mandatory services in designated airspaces: network identification, geo-awareness, traffic information and flight authorisation, provided by certified service providers.</p>



<p><strong>The practical dimension is therefore that</strong> the regime is not static. Regulation 2019/947 has applied in its consolidated version since 1 May 2025, and the U-space framework was reinforced by <strong>Regulation (EU) 2023/203</strong>, which added information security requirements – risk assessment, management and incident response. Of key interpretative importance is therefore the revision of the Easy Access Rules for UAS of June 2026, consolidating the AMC/GM to Regulation 2019/947 (ED Decision 2025/018/R). From 1 January 2026, flights in standard scenarios require platforms holding a class C5 or C6 certificate. In a broader perspective, this confirms that in the UAV sector law does not end with the text of the regulation itself, but also functions in the executive, interpretative and operational layer. It is precisely at this level – through the AMC, GM and their consolidation in the Easy Access Rules – that general norms are translated into compliance practice, risk assessment, operational documentation and the everyday application of the law by operators, manufacturers, advisers and supervisory authorities. As a result, an analysis of the legal environment of drones requires account to be taken not only of the formally binding provisions, but also of how they are operationalised in executive and interpretative materials, because it is only there that the real regulatory weight of the sector is revealed. <strong>AMC (Acceptable Means of Compliance) and GM (Guidance Material)</strong> do not have the character of independently binding provisions of the rank of a regulation, but they perform a fundamental interpretative and practical function: they show how entities can demonstrate conformity with the requirements arising from Regulation (EU) 2019/947 and how authorities and operators should understand the individual obligations in operational practice. That is precisely why the Easy Access Rules for Unmanned Aircraft Systems are of such great importance for the UAV sector – they do not create new law, but order, consolidate and operationalise the normative material and its interpretation, becoming in practice the basic working tool for operators, manufacturers, advisers and supervisory authorities.<a href="#_ftn63" id="_ftnref63">[63]</a></p>



<p><strong>A systemic remark</strong>: this entire pillar concerns civil aviation exclusively. Article 2(3)(a) of Regulation 2018/1139 excludes from its scope of application aircraft carrying out military, customs, police, search and rescue, firefighting, border control and coastguard operations. The first and most far-reaching defence exclusion therefore appears already at the level of the foundation, and not only in the Artificial Intelligence Act. This means that the boundary between the civil and the defence order is drawn already in the EASA basic regulation itself: it is that regulation which determines that the development, certification and operation of military unmanned systems are not subject to the EU regime of common civil aviation rules, but remain within the domain of the competence of the Member States, their defence policies and the relevant national security regimes. From the perspective of an analysis of the UAV sector, this is of fundamental importance, because it shows that the dual-track nature of the regime does not begin at the stage of AI, autonomy or export control, but already at the level of the most basic question of whether a given aircraft is subject to common European aviation law at all. In practice, this means that identical or nearly identical technology may be covered by the full civil conformity regime if it functions on the commercial market, while at the same time remaining outside that regime if it is incorporated into a military operation or one directly connected with it.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.2 · Pillar II – Artificial intelligence and decision-making autonomy</h3>



<p><strong>Regulation (EU) 2024/1689</strong> (the Artificial Intelligence Act, “AI Act”) introduces a risk-based classification: prohibited practices (Article 5), high-risk systems (Article 6 in conjunction with Annexes I and III), systems subject to transparency obligations (Article 50), general-purpose models (Articles 51–55) and the remainder, not covered by substantive obligations.</p>



<p>For the UAV sector, however, what is decisive is not what the act regulates, but <strong>what it does not regulate</strong>. Article 2(3) provides:</p>



<p>“<em>This Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification <strong><u>exclusively</u></strong> for military, defence or national security purposes</em>.” – Article 2(3) of Regulation (EU) 2024/1689.</p>



<p>The consequence is paradoxical: <strong>a civil drone with AI is subject to the full high-risk regime, while a technologically identical platform used “exclusively” for military purposes remains outside the scope.</strong> The criterion is not the technology, but the purpose of use. Lethal autonomous weapon systems (LAWS) therefore remain outside the EU regime; the matter is the subject of international law and NATO doctrines, and the European Parliament has repeatedly warned against the Union’s regulatory backwardness in this area. The European Parliament was one of the earliest institutional actors to take up the subject of autonomous weapon systems and military AI, adopting already in 2018 a resolution on LAWS, and then in 2021 a resolution relating to artificial intelligence in the military and civil context.<a href="#_ftn64" id="_ftnref64">[64]</a></p>



<p>Key, however, is the word <strong>“exclusively”</strong>. Recital 24 of the preamble specifies that if the system is also used for purposes other than military, defence or national security – even temporarily and even by another entity – the exclusion does not apply to that extent. For a dual-use manufacturer, this means that <strong>the exclusion is not a feature of the product, but a feature of the specific placing on the market or putting into service</strong>. The same product series sold simultaneously to a military purchaser and to a critical infrastructure operator is, in the second case, subject to the full regime – and the manufacturer must be able to document this duality, separate the product lines and demonstrate it in the event of an inspection.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Qualification of a drone system as a high-risk system</h3>



<p>In practice, the classification proceeds along two independent tracks:</p>



<ul class="wp-block-list">
<li><strong>Article 6(1) (Annex I)</strong> – an AI system is high-risk if it constitutes a safety component of a product covered by the Union harmonisation legislation listed in Annex I, and that product is subject to third-party conformity assessment. Section B of Annex I expressly lists Regulation (EU) 2018/1139. <strong>This means that control software performing a safety function in a certified unmanned system may be a high-risk system on precisely this basis</strong> – a circumstance still under-appreciated in market practice, because the discussion concentrates almost exclusively on Annex III.</li>



<li><strong>Article 6(2) (Annex III)</strong> – covers, inter alia, the management of critical infrastructure, law enforcement, and migration management and border control. Drone systems used by border services or critical infrastructure operators fall here directly.</li>
</ul>



<p>The consequence of qualification is the set of obligations under Articles 8–15: a risk management system, data and data quality governance (Article 10), technical documentation (Article 11), automatic recording of events (Article 12), transparency and information for the user (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15) – and, on the procedural side: conformity assessment, the EU declaration, CE marking and registration in the EU database.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">The calendar – amended in June 2026</h3>



<p>Market practice planned compliance for over a year around the date of 2 August 2026. That date has changed. On 19 November 2025, the Commission presented a simplification package (the Digital Omnibus), whose part concerning artificial intelligence – after the unsuccessful trilogue of 28 April 2026 and the political agreement of 6–7 May 2026 – was finally approved by the Council on <strong>29 June 2026</strong> (Parliament: 16 June 2026). The result is a postponement:</p>



<ul class="wp-block-list">
<li>obligations for standalone high-risk systems under Annex III – <strong>2 December 2027</strong>;</li>



<li>obligations for AI embedded in regulated products under Annex I (and thus, inter alia, unmanned systems) – <strong>2 August 2028</strong>;</li>



<li>transparency obligations under Article 50 – <strong>unchanged, 2 August 2026</strong>;</li>



<li>Article 50(2) (marking of generated content) in relation to systems already present on the market, and the new prohibitions – <strong>2 December 2026</strong>.</li>
</ul>



<p>The postponement is conditional in character and is linked to a readiness mechanism: the registration of systems in the EU database and the availability of harmonised standards. The following, by contrast, apply unchanged: the prohibitions under Article 5 (from 2 February 2025), the AI literacy obligation under Article 4 (from 2 February 2025) and the general-purpose model regime (from 2 August 2025).<a href="#_ftn65" id="_ftnref65">[65]</a></p>



<p><strong>In practice,</strong> the postponement is not a relief but a shift. The task which cannot be omitted or accelerated is the inventory of AI systems in the organisation and the assignment of each of them to the appropriate category – work independent of the state of the harmonised standards. In addition, the grandfathering principle applies: systems placed on the market before the date of application are not subject to the obligations until they are substantially modified – which, in a sector with an iteration cycle counted in weeks, is a guarantee of limited value.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><a>3.3 · Pillar III – Dual-use products and export control</a></h3>



<p><strong>Regulation (EU) 2021/821</strong> establishes the Union’s system for the control of exports of dual-use items; it entered into force on 9 September 2021, replacing Regulation (EC) No 428/2009, and has applied in its consolidated version since 15 November 2025. On 8 September 2025,<a href="#_ftn66" id="_ftnref66">[66]</a> the Commission updated Annex I (the control list), covering emerging technologies – which directly affects drone components, electronics and AI software.</p>



<p>Four mechanisms of this regime are significant for the unmanned sector:</p>



<p>1. <strong>The control list (Annex I)</strong> – drone components are dispersed across several categories: electronics (cat. 3), sensors and lasers (cat. 6), navigation and avionics (cat. 7) and aerospace and propulsion (cat. 9). Qualification rarely concerns the platform as a whole – most often a single subassembly is decisive.</p>



<p>2. <strong>Catch-all clauses (Article 4)</strong> – the obligation to obtain an authorisation arises also for items not included in the list, if the exporter has been informed or is aware of an intended use connected with weapons of mass destruction, military purposes in a state subject to an embargo, or parts for armaments exported without authorisation. This is the instrument which in practice covers the largest number of drone transactions, because it operates independently of the list.</p>



<p>3. <strong>Control of intangible technology transfer (ITT)</strong> – the regime covers not only things, but also software and technology, including making them available by electronic means. In practice, this means that granting remote access to a code repository, transferring model weights<a href="#_ftn67" id="_ftnref67">[67]</a> or placing technical documentation in a cloud outside the customs territory of the Union may constitute an export requiring an authorisation.</p>



<p>4. <strong>Cyber-surveillance items (Article 5)</strong> – a control mechanism covering items not included in the list, intended for surveillance, where there is a risk of use for human rights violations; it applies directly to advanced observation systems and image analytics.</p>



<p>The complementary layer is formed by: <strong>Directive 2009/43/EC</strong> on intra-EU transfers of defence-related products (simplified within the framework of the Defence Readiness Omnibus), the international regimes (the Wassenaar Arrangement, the MTCR – whose Category I traditionally covers unmanned systems with specified range and payload parameters) and, at national level, the <strong>Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance</strong>.</p>



<p><strong>IMPORTANT for M&amp;A practice:</strong> in the due diligence of an entity in the drone sector, the qualification of components as dual use determines the export authorisation regime, the end-user and re-export prohibition clauses and – in real terms – the feasibility of the cross-border transaction. The disappearance of the commercial/combat boundary (a mass-produced observation drone converted into a combat platform without design changes) makes this qualification ever broader, and the regulatory risk ever more difficult to price. Particular attention is required in the situation where the purchaser is an entity from outside the Union: the mere transfer of technical documentation in the company examination process may require an authorisation before the agreement is even concluded.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.4 Pillar IV – Defence financing and procurement (the driver)</h3>



<p>This is the pillar in which law performs the function of a <strong>driver</strong>. The EU instruments do not react to technology – they create demand, direct the stream of public funds and establish the framework for joint production and procurement:</p>



<p>•&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>The European Defence Fund (EDF)</strong><a href="#_ftn68" id="_ftnref68">[68]</a> – co-financing of joint defence research and development projects, lowering the industry’s investment risk.</p>



<ul class="wp-block-list">
<li><strong>EDIRPA</strong> (Regulation (EU) 2023/2418) – support for common defence procurement.<a id="_ftnref69" href="#_ftn69">[69]</a></li>



<li><strong>ASAP</strong><a id="_ftnref70" href="#_ftn70">[70]</a> – the regulation on supporting ammunition production: increasing the production capacities of industry; a logic fully transferable to the mass production of loitering munitions and drones.</li>



<li><strong>SAFE</strong> (Security Action for Europe, 2025)<a id="_ftnref71" href="#_ftn71">[71]</a> – a loan instrument with procurement to be carried out by the end of 2030.</li>



<li><strong>EDIP</strong> – the European Defence Industry Programme, together with the construction of <strong>SEAP</strong> (Structure for European Armament Programme) as a voluntary legal framework for the long-term cooperation of Member States across the entire life cycle of a defence product.<a id="_ftnref72" href="#_ftn72">[72]</a></li>
</ul>



<p>The superstructure of these instruments is the <strong>Defence Readiness Omnibus</strong><a href="#_ftn73" id="_ftnref73">[73]</a> of 17 June 2025 – a legislative and non-legislative package intended to remove administrative barriers to defence investment estimated at EUR 800 billion over a four-year perspective. It includes, inter alia, accelerated authorisation procedures for defence projects with a single point of contact, extension of the maximum duration of framework agreements to ten years, simplification of intra-EU transfers of defence products (where delays reached a year), clarification of the defence exclusions in chemicals legislation (REACH, CLP, biocidal products) and – which is particularly significant for financing – a communication clarifying the application of the sustainable finance framework to the defence sector. In June 2026, the co-legislators reached a preliminary agreement on the procurement part of the package, extending the increased EDF financing to actions carried out within the framework of SEAP and permitting the eligibility of the costs of tests conducted in Ukraine.</p>



<p>A separate, younger layer is formed by the <strong>four flagship projects</strong><a href="#_ftn74" id="_ftnref74">[74]</a> of the Readiness Roadmap 2030: the European Drone Defence Initiative, Eastern Flank Watch, the European Air Shield and the European Space Shield. EDDI – originally communicated as the “drone wall” – is to create a multi-layered network capable of detecting, tracking and neutralising hostile platforms, while preserving a dual-use dimension allowing civil applications (border protection, disaster response). The assumed timetable: launch in Q1 2026, initial capability by the end of 2026, full functionality by the end of 2027 (Eastern Flank Watch – by the end of 2028). They are complemented by the <strong>Action Plan on drone and counter-drone security</strong> of 11 February 2026 and the <strong>Drone Alliance with Ukraine</strong>, together with the announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets to support Ukrainian drone production.</p>



<p>The market confirms the direction: over a twelve-month horizon, autonomous drones attracted around USD 6.2 billion in 169 transactions, driving a 139-per-cent increase in defence robotics financing. Analysts at the same time point to the gap between the “battle-tested” Ukrainian ecosystem and the capital actually flowing in – a field in which legal advice and transaction structuring become critical.</p>



<p><strong>The practical dimension:</strong> participation in the driver instruments has a legal price which must be factored in at the stage of structuring the consortium. The EDF and EDIP regimes contain extensive provisions on rights to the results of the project, access to existing knowledge (background) and generated knowledge (foreground), export restrictions on results and requirements of control over the entity (registered office in the Union, absence of third-country control or effective mechanisms for its limitation). For a company with capital from outside the Union, eligibility can be illusory if the ownership structure is not appropriately arranged in advance.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.5 · Pillar V – Satellite communications (IRIS²)</h3>



<p><strong>Regulation (EU) 2023/588</strong> establishes the Union’s secure connectivity programme for 2023–2027 and the <strong>IRIS²</strong> constellation (Infrastructure for Resilience, Interconnectivity and Security by Satellite). It is the sovereign European answer to dependence on commercial satellite systems, whose role in the control of long-range drones was revealed by the conflict.<a href="#_ftn75" id="_ftnref75">[75]</a></p>



<p>Law here builds the physical layer on which the future generation of satellite-controlled platforms will rest – a classic infrastructural driver. The significance of this pillar is, however, deeper than technical: the experience of recent years has shown that <strong>a private satellite operator’s decision on coverage or on refusal to provide the service in a given area may have operational effects comparable to a decision of a state</strong>. The construction of a public capability is the answer to a problem which should be called the privatisation of communications sovereignty.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.6 · Pillar VI – Critical infrastructure, cybersecurity and product resilience</h3>



<p>Since the first phase of the conflict was cyber warfare, the pillar of digital and physical resilience has systemic significance. It is formed by three acts of differing logic:</p>



<ul class="wp-block-list">
<li><strong>Directive (EU) 2022/2555 (NIS2)</strong><a id="_ftnref76" href="#_ftn76">[76]</a> – raises the common level of cybersecurity, extending the circle of essential and important entities and the obligations of risk management, incident reporting and the responsibility of management bodies. It covers, inter alia, air transport, energy, digital infrastructure and – which is significant for the sector under discussion – the manufacture of products, including electronic devices. NIS2 shifts the weight from “IT security” itself to risk management at the level of the entire organisation, including the responsibility of management, incident reporting obligations and the requirement of operational resilience for entities operating in critical and technologically sensitive sectors.</li>



<li><strong>Directive (EU) 2022/2557 (CER)</strong><a id="_ftnref77" href="#_ftn77">[77]</a> – regulates the resilience of critical entities in the physical and organisational dimension: the identification of critical entities, risk assessment, resilience plans, personnel security vetting. The key significance of CER lies in the fact that it concentrates not on cyberspace, but on the physical and organisational resilience of critical entities, and thus on the capability to maintain continuity of operation despite an attack, sabotage, disruption or infrastructural crisis.</li>



<li><strong>Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA)</strong><a id="_ftnref78" href="#_ftn78">[78]</a> – the youngest act and, in practice, the most burdensome for manufacturers. It establishes horizontal cybersecurity requirements for <strong>products with digital elements</strong>, and thus for drones, ground controllers, detection systems and software. It imposes obligations of secure design, vulnerability management throughout the support period, provision of a software bill of materials (SBOM) and reporting of actively exploited vulnerabilities and serious incidents. The reporting obligations apply from September 2026, and the entirety – from December 2027. The most momentous element of the CRA is that, for the first time, it imposes on manufacturers of products with digital elements a continuous cybersecurity obligation throughout the product’s entire life cycle, encompassing secure design, vulnerability management and response obligations also after the product’s placing on the market.</li>
</ul>



<p>Both directive-form acts (NIS2, CER) require national transposition – which shifts the weight to the Polish level, discussed in Pillar IX.</p>



<p><strong>The practical dimension:</strong> the convergence of the three regimes means that a manufacturer of a drone system for a critical infrastructure operator may simultaneously: (i) be subject to the CRA as a manufacturer of a product with digital elements, (ii) be an important entity within the meaning of NIS2 by virtue of its own manufacturing activity, and (iii) be covered by requirements arising from the obligations of its client under CER and NIS2, passed down contractually within the framework of supply chain risk management. Three regimes, three separate calendars, three separate sets of reporting obligations – while the event that triggers them is one.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.7 · Pillar VII – Personal data and data governance</h3>



<p>This is a pillar systematically omitted in analyses of the defence sector, and at the same time the one which in practice most often blocks civil deployments. This follows from the observation made in section 2.10: the drone is above all a sensor, and a sensor turned towards the surface of the earth in an urbanised environment almost always records personal data.</p>



<p><strong>Regulation (EU) 2016/679 (GDPR)</strong> applies to the processing of imagery from an unmanned platform on general principles, whereby in practice four issues are decisive:</p>



<ul class="wp-block-list">
<li><strong>Scope of application.</strong> Article 2(2)(a) and (b) excludes processing in the course of an activity which falls outside the scope of Union law and within the framework of the common foreign and security policy. National security remains the competence of the Member States (Article 4(2) TEU). There thus arises – symmetrically to Article 2(3) of the Artificial Intelligence Act – a second defence exclusion, with differently drawn boundaries.</li>



<li><strong>Legal basis and transparency.</strong> The information obligation under Articles 13–14 is difficult to perform in a real manner in aerial operations; practice relies on area-based information, signage and the publication of flight plans, which the European Data Protection Board analysed in Guidelines 3/2019 on the processing of personal data through video devices.</li>



<li><strong>Data protection impact assessment (Article 35).</strong> Systematic monitoring of public space on a large scale with the use of new technologies falls within the typical criteria of a mandatory impact assessment; in Polish practice, the list of operations requiring a DPIA maintained by the supervisory authority includes monitoring with the use of drones.</li>



<li><strong>Special categories (Article 9).</strong> The processing of facial imagery for the purpose of the unique identification of a natural person constitutes the processing of biometric data; in combination with Article 5 of the Artificial Intelligence Act (the prohibition of real-time remote biometric identification in public space for law enforcement purposes, subject to exceptions), this creates a double barrier for observation systems with facial recognition.</li>
</ul>



<p>For operations conducted by the services, the appropriate regime is <strong>Directive (EU) 2016/680</strong> (the so-called Police Directive), transposed in Poland by the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.</p>



<p>A separate, younger layer is constituted by the <strong>governance of non-personal data</strong>. <strong>Regulation (EU) 2023/2854 (the Data Act)</strong>, applicable from 12 September 2025, covers “connected products” – that is, devices generating data on their use and environment, to which unmanned systems belong directly. It imposes obligations to make data available to the user and to third parties designated by the user, and limits the freedom to shape contracts in this respect. <strong>Regulation (EU) 2022/868 (the Data Governance Act)</strong>, in turn, creates the framework for the re-use of public sector data and data intermediation.</p>



<p>Finally, <strong>Article 10 of the Artificial Intelligence Act</strong> introduces quality requirements for the training, validation and testing data sets of high-risk systems – representativeness, relevance, examination for systematic errors. These requirements overlap with the GDPR regime in a manner which is sometimes a source of practical contradictions: the obligation to examine bias sometimes requires the processing of special-category data, the processing of which the GDPR as a rule prohibits. This issue is the subject of work on the data part of the Digital Omnibus.</p>



<p><strong>Legislative status:</strong> in contrast to the part concerning artificial intelligence, <strong>the part of the simplification package covering the GDPR, the ePrivacy Directive, NIS2, the Data Act and DORA remains at the negotiation stage.</strong> At the end of June 2026, the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority; the file was taken over by the Irish Presidency. The European Data Protection Board and the European Data Protection Supervisor expressed, in Joint Opinion 2/2026 of 11 February 2026, decided opposition to the proposed narrowing of the definition of personal data. <strong>Until formal adoption, the existing state of the law applies</strong> – the contrary assumption is at this moment the most frequent error in compliance planning (The legislative status remains unclosed: in contrast to the part of the simplification package concerning artificial intelligence, the component covering the GDPR, privacy and electronic communications, NIS2, the Data Act and DORA still remains at the negotiation stage. It is officially known that the EDPB and the EDPS, in Joint Opinion 2/2026 of 11 February 2026, expressed substantial reservations about the proposed changes, including the narrowing of the definition of personal data. Expert sources further indicate that at the end of June 2026 the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority, which means that until formal adoption the existing state of the law continues to apply.<a href="#_ftn79" id="_ftnref79">[79]</a>).</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.8 · Pillar VIII – Public international law and autonomous weapon systems</h3>



<p>The space left by the defence exclusions of EU law is not a lawless space. It is filled – with varying effectiveness – by three regimes of international law.</p>



<p><strong>International aviation law.</strong> The Chicago Convention of 1944 excludes state aircraft from its scope (Article 3), requires special authorisation for flights of pilotless aircraft over the territory of another state (Article 8) and – in Article 3 bis, added in 1984 – confirms the obligation to refrain from resorting to the use of weapons against civil aircraft in flight. This construction arose in a world in which the distinction “civil/state aircraft” was possible visually and procedurally. Applying it to an object with a wingspan of two metres, without markings, crossing the border unannounced, is a task for which the treaty was not designed.</p>



<p><strong>International humanitarian law.</strong> The principles of distinction, proportionality and precautions in attack apply regardless of whether the decision on the use of force is taken by a human or assisted by an algorithm. Article 36 of Additional Protocol I of 1977 imposes on the parties the obligation to review new weapons, means and methods of warfare for their compatibility with international law – this provision is today the only universally binding instrument that covers autonomy in armaments, although it does so indirectly.<a href="#_ftn80" id="_ftnref80">[80]</a></p>



<p><strong>The CCW process and the UN forum.</strong> The Group of Governmental Experts on lethal autonomous weapon systems (GGE on LAWS), operating since 2016 within the framework of the Convention on Prohibitions or Restrictions on the Use of Certain Conventional Weapons, has been working since 2024 on the so-called rolling text, encompassing elements of a potential instrument based on a two-tier approach of prohibitions and regulation. At the September 2025 session, a group of 42 states – one third of the parties to the Convention – declared readiness to move to negotiations on the basis of that text. On 6 November 2025, the UN General Assembly adopted, for the third time in succession, a resolution on autonomous weapon systems, supported by 156 states. The UN Secretary-General and the President of the International Committee of the Red Cross jointly called for the conclusion of negotiations on a legally binding instrument <strong>by the end of 2026</strong>. The Seventh CCW Review Conference, planned for November 2026, is the moment at which it will be decided whether a negotiating mandate will come into being – whereby the consensus rule applicable in that forum makes this outcome uncertain.<a href="#_ftn81" id="_ftnref81">[81]</a></p>



<p><strong>The NATO layer</strong> comprises the principles of the responsible use of artificial intelligence in defence adopted in 2021 (lawfulness, accountability, explainability and traceability, reliability, governability, bias mitigation) and the revised AI strategy. These are not legally binding norms, but they constitute a point of reference for contractual requirements in allied procurement – and in this sense they affect industry more strongly than many a legal act.<a href="#_ftn82" id="_ftnref82">[82]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.9 · Pillar IX – The Polish level</h3>



<p>The Polish regime combines directly applicable EU regulations with national statutes and operational provisions. The Regulations (2019/945, 2019/947, 2021/664, 2021/821, 2023/588, 2024/1689, 2024/2847) apply directly; the directives (NIS2, CER) require transposition.</p>



<p><strong>The aviation layer.</strong> The national basis is formed by the <strong>Act of 3 July 2002 – Aviation Law</strong>, substantially amended by the Act of 24 January 2025, which entered into force on 27 February 2025. The amendment adapted national law to the EU regime and introduced, inter alia: a register of operators of unmanned systems (a registration obligation for platforms of at least 250 g <strong>and – regardless of mass – those equipped with sensors capable of collecting personal data</strong>), the statutory empowerment of the Polish Air Navigation Services Agency to designate geographical zones, the extension of the catalogue of services entitled to check pilots, the lowering of the minimum age of a pilot in the open category from 16 to 14 under supervision, and a chapter devoted to the prevention of the unlawful performance of operations with the use of unmanned systems. Notification of the intention to perform an operation takes place through the <strong>DroneTower</strong> application, integrated with the PANSA UTM system and the National Drone Information System (KSID). The legal basis for the neutralisation of a platform remains <strong>Article 156ze of the Aviation Law</strong> (destruction, immobilisation or taking over control of the flight), supplemented by the provisions of the chapter on the prevention of unlawful operations.</p>



<p>Institutionally, this layer is completed by the <strong>Act of 8 December 2006 on the Polish Air Navigation Services Agency</strong> (Journal of Laws of 2025, item 1267), extended by the Agency’s competences in the area of unmanned systems, including the possibility of providing services to operators, supporting the testing of new solutions and creating special-purpose companies. Supervision is exercised by the President of the Civil Aviation Authority.</p>



<p><strong>The resilience and countermeasure layer.</strong> The breakthrough is the <strong>Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815)</strong>, implementing the CER Directive. Its significance for the sector under discussion extends far beyond its declared purpose:</p>



<ul class="wp-block-list">
<li><strong>Critical infrastructure operators have obtained the right to apply countermeasures against unmanned platforms, including jamming devices.</strong> Until now, a private entity managing a strategic facility could only await the intervention of the services; it can now itself interrupt communications with the intruder. The power entered into force on 26 June 2026.</li>



<li>The catalogue of authorised formations (the Police, the Border Guard, the State Protection Service, the Military Gendarmerie) obtained competences to destroy, immobilise or take over control of <strong>unmanned surface/floating objects and robots and autonomous vehicles moving on land</strong>, where they create a threat to critical infrastructure. The new Chapter 6a of the Act, modelled constructionally on the provisions of the Aviation Law concerning aircraft, extends the counter-drone regime to the maritime and land domains.</li>



<li>The Act further introduces an obligation of security audits, mechanisms for the protection of supply chains, and establishes the Maritime Security Centre.</li>
</ul>



<p><strong>The defence layer.</strong> It is formed by the <strong>Act of 11 March 2022 on the Defence of the Homeland</strong> – the national framework for the acquisition and operation of unmanned and counter-drone systems, together with the procurement regime in the fields of defence and security.</p>



<p><strong>The direction of change.</strong> This area is evolving intensively in the years 2024–2026 and requires ongoing verification of the entries in the Journal of Laws and of legislative drafts. After a period of tightening of administrative sanctions, assessed by the operator community as disproportionate, the Civil Aviation Authority transmitted to the Ministry of Infrastructure on 5 May 2026 a draft amendment of a deregulatory and ordering character, covering the system of penalties, insurance, mandatory notifications, the securing of critical infrastructure and counter-drone systems. Entry into force is announced for the turn of 2026 and 2027. In parallel, work is under way on the full transposition of NIS2 within the framework of the amendment of the Act on the National Cybersecurity System.<a href="#_ftn83" id="_ftnref83">[83]</a></p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><a>4 · Seven Points of Friction</a></h2>



<p>The pillars described in Part 3 do not form a coherent system. They come into contact with one another at points where their assumptions are mutually contradictory, and the resolution of the collision does not follow from any of them. It is precisely at these points that the undertaking’s real legal risk is concentrated – and it is they, not the content of the individual acts, that should set the agenda of legal advice.</p>



<h3 class="wp-block-heading">4.1 · The “exclusivity” test – the military exclusion in relation to a dual-use product</h3>



<p>The exclusion in Article 2(3) of the Artificial Intelligence Act operates on the condition of the <strong>exclusivity</strong> of the military, defence or national security purpose. This construction assumes that the purpose can be unambiguously assigned to the placing on the market or the putting into service. In the dual-use sector, this assumption is empirically false: the same machine vision module may be sold to the manufacturer of a power plant perimeter protection system and at the same time integrated into a military platform.</p>



<p>The practical consequences are three. First, <strong>the burden of demonstrating exclusivity rests on the entity that invokes it</strong> – and demonstrating a negative fact (the absence of civil application) requires documented control of the distribution channel and end-user clauses. Second, the exclusion relates to the system, not to the undertaking: a company may simultaneously be a provider of a high-risk system and a provider of an excluded system. Third, <strong>modification of the intended purpose after placing on the market changes the regime</strong> – and in a sector in which the end user routinely modifies the platform, this is a real risk, not a hypothetical one.</p>



<p>The practical recommendation is unambiguous: the separation of product lines at the documentary, contractual and – as far as possible – technical level, before the first mixed contract comes into being. Untangling this situation later is costly, and in the course of a company examination it is sometimes impracticable.</p>



<h3 class="wp-block-heading">4.2 · Human oversight: two regimes, one technical requirement</h3>



<p>Article 14 of the Artificial Intelligence Act and the postulate of meaningful human control in humanitarian law<a href="#_ftn84" id="_ftnref84">[84]</a> describe the same property of a system – the human’s capability to understand, verify and interrupt the operation of the automaton – but have an entirely different normative status. On the civil side, it is a legal obligation with an administrative sanction and a documentation requirement. On the military side – the subject of unfinished negotiations.</p>



<p>From this arises an asymmetry with industrial effects: <strong>a manufacturer that builds one technical platform for both tracks must design to the stricter requirement</strong>, because it cannot foresee in advance in which track a given unit will end up. Consequently, the civil requirement becomes the de facto design standard also for excluded applications – a mechanism worth calling the standard-transfer effect. This is one of the few situations in which the defence exclusion operates to the benefit, rather than to the detriment, of the coherence of the system.</p>



<p>The converse mechanism is, however, equally real: operational pressure to shorten the decision chain in a heavily jammed environment leads to constructions in which human oversight is formally preserved but in fact illusory – the operator approves a decision which he had neither the time nor the data to assess. Demonstrating such a situation in evidentiary proceedings requires access to event logs, which Article 12 of the Artificial Intelligence Act requires only on the civil side.</p>



<h3 class="wp-block-heading">4.3 · Jamming as a legally regulated activity</h3>



<p>The jamming power, granted in Poland to critical infrastructure operators from June 2026, is an example of a norm which solves one problem and opens three further ones.<a href="#_ftn85" id="_ftnref85">[85]</a></p>



<p>Jamming devices are, as a rule, inadmissible for marketing and use: they do not satisfy the essential requirements of Directive 2014/53/EU on radio equipment (harmful interference), and their use violates the spectrum management regime. The grant of a statutory power removes the unlawfulness of the act itself, but <strong>does not settle liability for side effects</strong>. Interference in the bands used by satellite navigation systems affects civil aviation, transport, telecommunications networks and – which is sometimes overlooked – energy infrastructure synchronised by satellite time. Questions therefore arise as to: (i) the compensation liability regime of the facility operator towards third parties, (ii) the delimitation of liability between the operator and the manufacturer of the device, (iii) the documentation obligations allowing the course of the event to be reconstructed.</p>



<p>To this is added a third problem, described in section 2.4: <strong>the legal measure was granted at the moment when the technology against which it is effective is in retreat.</strong> The fibre-optic platform is resistant to jamming by definition. The norm responds to the state of the art of two years ago.</p>



<h3 class="wp-block-heading">4.4 · Kinetic neutralisation and liability for damage</h3>



<p>Shooting down or immobilising a platform does not end the event – it begins the fall of a mass with kinetic energy over terrain which is usually precisely what was to be protected. Polish law provides a basis for neutralisation (Article 156ze of the Aviation Law, the provisions of the chapter on the prevention of unlawful operations, the new powers under the Act of 29 May 2026), but <strong>the regime of liability for damage caused as a result of lawful neutralisation remains dispersed</strong> between the liability of the State Treasury for acts of public authority, the general rules of tortious liability and the special provisions on damage caused by the movement of aircraft.</p>



<p>A separate issue is the qualification of independent neutralisation by an unauthorised entity. The shooting down of a drone by the owner of the property over which it is flying is not the exercise of the right of ownership – it is the destruction of another’s thing and, depending on the circumstances, the creation of a danger. Judicial practice in this area is already taking shape.</p>



<h3 class="wp-block-heading">4.5 · Battlefield data as training material</h3>



<p>This is the most under-defined point of the entire map. Collections of recordings from combat operations – visual and thermal imagery from thousands of sorties – have a training value unattainable in laboratory conditions. They flow, formally and informally, in both directions across the civil-military boundary.</p>



<p>The legal issues arrange themselves in three layers. <strong>Data protection:</strong> material of this kind contains the images of natural persons; processing in the course of hostilities falls within the exclusion of Article 2(2) GDPR, but the use of the same collection by a commercial entity to train a model intended for the civil market no longer does – and determining the moment at which the data “enter” the scope of application of the regulation has no unambiguous normative answer. <strong>Data quality:</strong> Article 10 of the Artificial Intelligence Act requires that the training data sets of high-risk systems be representative and free of systematic errors; a collection originating from one theatre of operations, one season of the year and one type of terrain does not satisfy that requirement, which has a direct bearing on the reliability of classifiers in civil applications. <strong>Export control:</strong> the weights of a model trained on such a collection may constitute controlled technology, and making them available outside the customs territory of the Union – an export requiring authorisation (cf.&nbsp;section 3.3, point 3).</p>



<p>The practical recommendation: in every transaction concerning an entity possessing vision models, the provenance of the training data sets must be established and documented in a manner allowing the lawfulness of the chain to be demonstrated. This is today one of the most frequently omitted – and most difficult to repair after the fact – elements of a company examination.</p>



<h3 class="wp-block-heading">4.6 Intangible technology transfer and the dispersed working model</h3>



<p>The export control regime is not limited to the physical movement of goods across the border. Within the meaning of Regulation (EU) 2021/821, “export” also includes the transmission of software or technology by electronic means – inter alia electronic mail, telephone or other electronic means – to a destination outside the customs territory of the Union. Making such software or technology available in electronic form to natural or legal persons located outside the customs territory of the Union is also deemed to be an export. In consequence, granting a foreign engineer, consultant or potential investor the ability to download controlled files from a repository may constitute an export, even if the data at all times remain saved on the same server and the access was remote and short-lived.<a href="#_ftn86" id="_ftnref86">[86]</a></p>



<p>This does not, however, mean that every making available of source code outside the Union automatically requires an authorisation. It must first be established whether the software or technical information in question has been included in the list of dual-use items in Annex I to Regulation 2021/821, or whether the conditions for the control of unlisted items are met on account of their intended end use or end user. In the unmanned aircraft sector, this assessment may concern both the design of the drone itself, its subassemblies and equipment, and the dedicated software and the technology necessary for their development, production or use. Potentially significant will be, inter alia, design documentation, aerodynamic models and simulations, control system diagrams, autopilot code, solutions concerning autonomous navigation, sensor integration, encrypted communications or jamming resistance. The classification should, however, refer to the parameters and criteria of the specific control entry, and not solely to the fact that the given technology is connected with drones.</p>



<p>The risk of intangible technology transfer arises above all in three configurations: (i) in a geographically dispersed development team including persons working from third countries; (ii) in the due diligence process, if the advisers or technical experts of a potential purchaser from outside the Union receive access to the repository, the design documentation or the test environment; and (iii) in the use of cloud infrastructure, if the data are transmitted to servers located outside the Union or can be accessed from there. The mere decentralisation of infrastructure, the use of blockchain technology or the storage of data in the cloud do not yet determine the occurrence of a controlled export. What matters above all is the content of the data, their export classification, the location of the recipient and whether the entity from outside the Union has obtained a real possibility of acquainting itself with the controlled technology. In the case of dispersed data storage, an additional problem may be the impossibility of reliably establishing in which states the individual nodes or copies of the data are located.</p>



<p>For this reason, control of access to repositories containing drone technologies should be an element of the internal export compliance programme, and not solely a cybersecurity procedure. Such a system should encompass the classification of repositories and documentation, the establishment of the state from which the user actually obtains access, the verification of end users and of the purpose of use of the technology, the segmentation of projects, the principle of least privilege, restrictions on the downloading and copying of files, and the keeping of access logs. For the protection of data against unauthorised access does not itself replace the answer to a separate regulatory question: whether the access of a person who is authorised, but located outside the Union, constitutes an export requiring an authorisation.</p>



<h3 class="wp-block-heading">4.7 Supply chain, components and investment control</h3>



<p>The last point of friction is the tension between strategic autonomy and the structure of the component market. The ecosystem which made possible the cost revolution described in section 2.2 rests to a considerable extent on components of geographically concentrated origin – from cells and motors to integrated circuits and cameras. The policy of reducing dependence collides with the fact that alternative European chains do not exist at a scale corresponding to demand.</p>



<p>Legally, this tension materialises in three instruments: the eligibility mechanisms in the financing programmes (the requirement of component origin and of control over the contractor), <strong>Regulation (EU) 2019/452 on the screening of foreign direct investments</strong> together with the national Act of 24 July 2015 on the control of certain investments,<a href="#_ftn87" id="_ftnref87">[87]</a> and the sanctions regime. For an investor, this means that a transaction in this sector requires a parallel analysis of three consent paths: merger control, investment control and – where the object comprises listed assets – export consents. The transaction timetable must take this into account from day one; the attempt to catch up on these consents after the signing of the preliminary agreement is a typical cause of the failure of the process.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>5 · The Dual-Track Nature of the Regime – an Answer to the Practical Question in the Legal Environment</strong></h2>



<p>The juxtaposition of the nine pillars leads to the conclusion that law simultaneously performs <strong>three different roles</strong> – depending on the track in which we find ourselves – and leaves one area uncovered.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Role of law</strong></td><td><strong>Pillars</strong></td><td><strong>Mechanism</strong></td></tr></thead><tbody><tr><td>Consequence of need</td><td>UAV/EASA, U-space level (civil track)</td><td>National law chases technology outpaced by the conflict; it regulates ex post what has already come into being</td></tr><tr><td>Driver</td><td>EDF, EDIRPA, ASAP, SAFE EDIP/SEAP, Defence Readiness Omnibus, IRIS², EDDI</td><td>Law creates demand, finances development, builds infrastructure and removes administrative barriers</td></tr><tr><td>Dampener</td><td>AI Act (civil track), dual use 2021/821, NIS2/CER/CRA, GDPR and the Data Act</td><td>Law limits the risk of mass dissemination, conditioning access to the market</td></tr><tr><td>Regulatory gap</td><td>LAWS / military AI, Art. 2(3) AI Act, art. 2 (2) GDPR, art. 2(3) (a) Reg. 2018/1139)</td><td>The defence exclusions leave development without a brake; international law fills this space only partially</td></tr></tbody></table></figure>



<p><strong>Law is neither exclusively a consequence nor exclusively a driver – it is dual-track.</strong> On the civil track it operates as a consequence of need and as a dampener; on the defence track as a driver. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive acts – whereby, as we demonstrated in section 3.1, the first of them appears already in the EASA basic regulation, and thus at the level of the foundation of the entire regime, not as a special exception.</p>



<p>The paradox lies in the fact that <strong>the same technology is simultaneously being accelerated on the defence side and dampened on the civil side</strong> – and the dual-use boundary along which this division runs is increasingly indistinct. What is more, in the years 2025–2026 we observe an additional phenomenon, which is worth noting as a fourth mechanism: <strong>simplification as a tool of industrial policy</strong>. Both the Defence Readiness Omnibus and the Digital Omnibus aim to lower regulatory burdens – the first on the defence track, the second on the civil one. The direction is convergent, the justifications different: in the first case defence readiness, in the second competitiveness. The effect is a convergence of the two tracks on the procedural side, while their substantive separateness is preserved.</p>



<h2 class="wp-block-heading">6 · Practical Implications for Entities in the Sector</h2>



<h3 class="wp-block-heading">6.1 · The qualification map – questions which must be answered in this order</h3>



<p>For a client from the UAV sector, one question is key: <strong>on which side of the boundary – dual use, military/civil – is its product or project located.</strong> This qualification determines the entire legal regime that covers it. In practice, it is worth conducting it sequentially:</p>



<p>1. <strong>Is the product intended exclusively for military, defence or national security purposes?</strong> If so – the basis of that assertion and the mechanisms of control over the distribution channel must be documented. If not, or not fully – the civil regime applies in its entirety.</p>



<p>2. <strong>Does the Artificial Intelligence Act apply, and if so, on which basis?</strong> Annex I (a safety component of a certified product) or Annex III (critical infrastructure, law enforcement, borders)? On this depends not only the scope of the obligations, but also the date of their application (2 December 2027 or 2 August 2028).</p>



<p>3. <strong>Which product class and operational category does the platform concern</strong> under the 2019/945 and 2019/947 regime – and do the operations require an authorisation in the specific category?</p>



<p>4. <strong>Is the product or any of its components subject to export control</strong> on the basis of Regulation (EU) 2021/821 and the current control list, including under the regime of the catch-all clauses and intangible technology transfer?</p>



<p>5. <strong>Does the device process personal data</strong> – and if so, has an impact assessment been carried out and is the legal basis of the processing documented? Is the platform a “connected product” within the meaning of the Data Act?</p>



<p>6. <strong>What cybersecurity obligations</strong> (the CRA as manufacturer, NIS2 by virtue of its own activity, CER indirectly through the client) cover the manufacturer and the operator?</p>



<p>7. <strong>Does the project qualify for driver financing</strong> (EDF, EDIRPA, ASAP, SAFE, EDIP/SEAP) – and does the ownership and consortium structure satisfy the eligibility and control requirements?</p>



<h3 class="wp-block-heading"><a>6.2 Due diligence of a drone entity</a></h3>



<p>In M&amp;A practice, this means that the examination of the company must cover not only the classic areas (legal title to intellectual property, contracts, obligations), but also <strong>regulatory positioning</strong>. The checklist covers at least:</p>



<ul class="wp-block-list">
<li>the dual-use classification of every component and product, together with the substantiating documentation and the history of authorisations issued;</li>



<li>the status vis-à-vis the Artificial Intelligence Act: an inventory of systems, assignment to categories, assessment of the existence and effectiveness of the exclusion under Article 2(3);</li>



<li>the provenance of the training data sets and the rights to use them – including the chain of title to data originating from third parties or from real operations;</li>



<li>the history of security incidents and compliance with the reporting regimes;</li>



<li>operator registration, operational authorisations, the history of proceedings before the aviation supervisory authority and of administrative sanctions;</li>



<li>exposure to investment control (Regulation 2019/452, the Act of 24 July 2015) and the eligibility requirements in the financing programmes of which the company is a beneficiary;</li>



<li>compliance with the intangible technology transfer regime in the dispersed working model, including a list of the jurisdictions from which access to the repositories was granted;</li>



<li>rights to the results of projects financed from public funds, including export restrictions and access rights allocated to Member States.</li>
</ul>



<p><strong>A procedural remark of significant practical importance:</strong> the mere conduct of the company examination may trigger export obligations if access to the technical documentation is obtained by advisers from third countries. The sequence of steps in the transaction process is therefore not a matter of convenience – it is an element of compliance.</p>



<h3 class="wp-block-heading"><a>6.3 · Compliance calendar 2026–2028</a></h3>



<figure class="wp-block-table"><table class="has-luminous-vivid-orange-background-color has-background has-fixed-layout"><thead><tr><td><strong>Date</strong></td><td><strong>Event</strong></td></tr></thead><tbody><tr><td>2 August 2026</td><td>Transparency obligations under Article 50 of the Artificial Intelligence Act (unchanged despite the simplification package)</td></tr><tr><td>September 2026</td><td>Manufacturers’ reporting obligations under the Cyber Resilience Act</td></tr><tr><td>November 2026</td><td>The Seventh CCW Review Conference – decision on the negotiating mandate concerning autonomous weapon systems</td></tr><tr><td>2 December 2026</td><td>Article 50(2) of the AI Act in relation to systems already present on the market; the new prohibitions under Article 5</td></tr><tr><td>end of 2026</td><td>Initial capability of the European Drone Defence Initiative and Eastern Flank Watch</td></tr><tr><td>turn of 2026/2027</td><td>Announced entry into force of the Polish deregulatory amendment of the Aviation Law</td></tr><tr><td>&nbsp; end of 2027</td><td>&nbsp; Full functionality of EDDI</td></tr><tr><td>2 December 2027</td><td>Obligations for standalone high-risk systems (Annex III of the AI Act)</td></tr><tr><td>December 2027</td><td>Full application of the Cyber Resilience Act</td></tr><tr><td>2 August 2028</td><td>Obligations for AI embedded in regulated products (Annex I – including unmanned systems)</td></tr><tr><td>end of 2028</td><td>Full functionality of Eastern Flank Watch</td></tr></tbody></table></figure>



<p>The dates concerning the part of the simplification package relating to the GDPR, privacy in electronic communications, NIS2 and the Data Act remain unsettled – the file is in negotiations in the Council, and adoption before the end of 2026 is uncertain.</p>



<h3 class="wp-block-heading">6.4 What cannot be postponed</h3>



<p>The postponement of the obligations for high-risk systems is sometimes read as consent to suspend work. This is an error with a measurable cost. Three tasks have no temporal alternative:</p>



<ul class="wp-block-list">
<li><strong>Inventory and classification.</strong> The most difficult element of compliance with the Artificial Intelligence Act is not the completion of documentation, but the identification of all systems in the organisation and the maintenance of that register as successive versions of the product are introduced. This work does not depend on the state of the harmonised standards.</li>



<li><strong>AI literacy (Article 4).</strong> The obligation to ensure an appropriate level of knowledge of the personnel operating AI systems has applied since 2 February 2025 and has not been postponed.</li>



<li><strong>Data architecture and event logs.</strong> The requirements of Articles 10 and 12 are of a design character – satisfying them after the completion of construction work is many times more costly than taking them into account from the outset.</li>
</ul>



<p>It is precisely here – at the interface of technology and the ever-denser lattice of regimes – that the added value of legal advice specialised in highly regulated sectors lies.</p>



<h2 class="wp-block-heading">7 Conclusion – the Conflict as Lens and Barometer</h2>



<p>The Ukrainian conflict is a lens in which the future of dual-use technology can be seen, and a barometer of the direction of its regulation. It refutes the popular thesis that law by its nature restrains technological development: on the defence track, the legal layer of public financing has proved to be a vector of abrupt acceleration – and the instruments adopted in the years 2025–2026, from the Defence Readiness Omnibus to the flagship projects of the Readiness Roadmap 2030, are proof of this on a scale hitherto unknown in Europe. At the same time, it shows that as drones become widespread, civil law assumes a dampening function – controlling export, autonomy, data processing and access to airspace.</p>



<p>Three observations seem most significant for the further discussion.</p>



<p><strong>First</strong>, the defence exclusions are not an exception to the rule, but a systemic construction repeated at every level of regulation – from the EASA basic regulation, through the GDPR, to the Artificial Intelligence Act. Each time, however, they have differently drawn boundaries, which means that the same platform may simultaneously be excluded from one regime and covered by another. The ordering of those boundaries is a task which the EU legislator has not yet undertaken.</p>



<p><strong>Second</strong>, with the shift of value from the platform to the data and models, the regulatory weight is shifting from aviation law towards data and artificial intelligence law. A manufacturer that in 2019 needed mainly a certificate needs, in 2026, a documented chain of provenance of the training data sets, a vulnerability management system and jurisdiction-based access control.</p>



<p><strong>Third</strong>, the innovation spiral will not slow down – and with it, the pace of the layering of the law will not slow down either. A norm responding to the state of the art of two years ago, adopted in reaction to an incident of a year ago, entering into force in a year’s time, will at the moment of its application relate to a world that no longer exists. This is an argument not against regulation, but for regulation based on effects and on the level of risk, resistant to a change of technical solution.</p>



<p>For lawyers serving this sector, the conclusion is one: <strong>an effective legal strategy begins with the conscious positioning of the product on the right side of each of the boundaries of the regime</strong> – and there are today nine of those boundaries, not one. The ability to move simultaneously in the technological and regulatory layer ceases to be an advantage and becomes a condition of presence on this market.</p>



<h2 class="wp-block-heading">Annex A: Glossary of Technical Terms</h2>



<figure class="wp-block-table"><table class="has-vivid-red-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color has-fixed-layout"><thead><tr><td><strong>Term</strong></td><td><strong>Meaning</strong></td></tr></thead><tbody><tr><td>BSP / UAS / UAV</td><td>Unmanned aircraft; an unmanned aircraft system also includes the control station and the link</td></tr><tr><td>FPV (first person view)</td><td>Control from a first-person perspective, through goggles receiving the image from the on-board camera</td></tr><tr><td>BVLOS</td><td>An operation beyond the operator’s visual line of sight</td></tr><tr><td>ISR</td><td>Intelligence, surveillance and reconnaissance</td></tr><tr><td>Relay</td><td>A repeater of the control signal and imagery, allowing terrain obstacles to be bypassed</td></tr><tr><td>Radio horizon</td><td>The maximum range of signal propagation limited by terrain relief and obstacles</td></tr><tr><td>Jamming</td><td>Emission of noise on the control frequencies with the aim of severing the link</td></tr><tr><td>Spoofing</td><td>Substitution of the satellite navigation signal, causing an erroneous determination of position</td></tr><tr><td>WRE / EW</td><td>Electronic warfare</td></tr><tr><td>Loitering munition</td><td>A platform remaining in the task area and carrying out a strike after detecting a target</td></tr><tr><td>Deep strike</td><td>A strike on targets located deep in the adversary’s territory</td></tr><tr><td>Terminal autonomy</td><td>The platform’s capability to complete the task without communications with the operator</td></tr><tr><td>C-UAS</td><td>Counter-unmanned aircraft systems</td></tr><tr><td>SBOM</td><td>A software bill of materials, required by the Cyber Resilience Act</td></tr><tr><td>U-space</td><td>A set of digital services enabling safe UAV operations in designated airspace</td></tr><tr><td>SORA</td><td>The risk assessment methodology for operations in the specific category</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">About the Authors and the Firm</h2>



<p><strong>KG Legal Kiełtyka Gładkowski. Partnership – Attorneys law firm </strong>advises entities from the high-technology sectors and highly regulated industries.</p>



<p><strong>Attorney-at-law (radca prawny) Kazimierz Jakub Gładkowski</strong> specialises in corporate matters.</p>



<p><strong>Attorney-at-law (radca prawny) Małgorzata Kiełtyka</strong>, entitled to appear before all courts, specialises in M&amp;A transactions for entities from the high-technology and highly regulated sectors.</p>



<p><em>This article is of an informational and popular-science nature; it does not constitute legal advice. In individual matters, we recommend contacting the firm.</em></p>



<p><strong>Additional Footnotes and Sources</strong></p>



<p><strong>1.</strong> Violations of Polish airspace on 9/10 September 2025 and earlier incidents (Romania – January 2025; Osiny – August 2025); launch of NATO’s operation Eastern Sentry; compare: T. Withington, “Europe’s Drone Wall – Ready, EDDI, Go!”, <em>European Security &amp; Defence</em>, 13 March 2026, pp.&nbsp;38–41; <a href="https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/">https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/</a></p>



<p><strong>2.</strong> Expert estimate concerning the pace of development of unmanned technologies in wartime conditions; cf.&nbsp;the analysis systematising drone warfare technology – M. Strzyżewski, “Anti-drone defense &#8211; shotguns, nets, EW, interceptor drones”, Marcin Strzyżewski YouTube channel, 2026 (video material).</p>



<p><strong>3.</strong> The analogy and taxonomy of drone categories and the role of situational awareness; the persistence of commercial observation platforms on the battlefield after: M. Strzyżewski, op. cit.</p>



<p><strong>4.</strong> “FPV Drone Warfare: The $1,000 Revolution Reshaping Modern Combat”, drone-warfare.com, 2026. <a href="https://drone-warfare.com/research/fpv-drone-warfare">https://drone-warfare.com/research/fpv-drone-warfare</a></p>



<p><strong>5.</strong> V. Sutea, “Fiber-optic drones have emerged as critical kit for both Russia and Ukraine”, Atlantic Council – UkraineAlert, 24 February 2026 (the appearance of fibre-optic drones in August 2024 in the Kursk area; range of over 30 km, no susceptibility to jamming); <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/?utm_source=chatgpt.com">https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine</a></p>



<p><strong>6.</strong> NATO Allied Command Transformation, Innovation Challenge devoted to countering fibre-optic drones, 2025 – cf.&nbsp;Atlantic Council, op. cit.</p>



<p><strong>7.</strong> “Fire Point FP-1”, Wikipedia (as at 21 July 2026); cf.&nbsp;“FP-1 vs Shahed: Ukraine Ramps Up Production…”, United24 Media, 20 August 2025 (unit cost approx. USD 55 thousand; plywood fuselage, two-cylinder engine).</p>



<p><strong>8.</strong> “Russian largest oil refinery hit for first time by Ukrainian drones”, Politico Europe, 6 July 2026; cf.&nbsp;Tom’s Hardware, 17 July 2026 (strike on the Omsk refinery after a flight of over 2,500 km). <a href="https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery">https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery</a></p>



<p><strong>9.</strong> Regulation (EU) 2018/1139 (EASA), including Article 2(3)(a) (exclusion of military, customs, police and related operations); Delegated Regulation (EU) 2019/945; Implementing Regulation (EU) 2019/947 (open / specific / certified categories). Source: EUR-Lex.</p>



<p><strong>10.</strong> Implementing Regulation (EU) 2021/664 (the U-space framework) together with 2021/665 and 2021/666. Source: EUR-Lex; EASA.</p>



<p><strong>11.</strong> Regulation (EU) 2023/203 (information security requirements in U-space); the consolidated version of 2019/947 applicable from 1 May 2025. Source: EUR-Lex; SKYbrary.</p>



<p><strong>12.</strong> EASA, Easy Access Rules for Unmanned Aircraft Systems – revision of June 2026 (consolidation of the AMC/GM to 2019/947, ED Decision 2025/018/R).</p>



<p><strong>13.</strong> Regulation (EU) 2024/1689 (the Artificial Intelligence Act), Article 2(3) and recital 24; Articles 4, 5, 6, 8–15, 50, 51–55; Annexes I and III. Source: EUR-Lex; artificialintelligenceact.eu (Article 2: Scope).</p>



<p><strong>14.</strong> European Parliament, EPRS, “Defence and artificial intelligence”, 2025 (LAWS outside the scope of the AI Act by virtue of Article 2(3); calls for international regulation).</p>



<p><strong>15.</strong> Digital Omnibus on AI: Commission proposal of 19 November 2025; unsuccessful trilogue of 28 April 2026; preliminary political agreement of 6–7 May 2026; confirmation by Member State representatives on 13 May 2026; approval by the Parliament on 16 June 2026 and by the Council on 29 June 2026. New dates: 2 December 2027 (Annex III), 2 August 2028 (Annex I), 2 December 2026 (Article 50(2) in relation to existing systems and the new prohibitions). Cf. analyses: Gibson Dunn, May 2026; Travers Smith, May 2026.</p>



<p><strong>16.</strong> Regulation (EU) 2021/821 (dual-use export control); entry into force on 9 September 2021; consolidated version from 15 November 2025; Article 4 (catch-all clauses), Article 5 (cyber-surveillance items), the intangible technology transfer regime. Source: EUR-Lex.</p>



<p><strong>17.</strong> European Commission, update of Annex I to Regulation (EU) 2021/821 of 8 September 2025 (emerging technologies). Cf. Akin, “EU Updates Dual-Use Export Control List”, 16 September 2025.</p>



<p><strong>18.</strong> Directive 2009/43/EC on intra-EU transfers of defence-related products; the Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance.</p>



<p><strong>19.</strong> Regulation (EU) 2023/2418 (EDIRPA – common defence procurement). Source: EUR-Lex; European Commission (DG DEFIS).</p>



<p><strong>20.</strong> The SAFE instrument (Security Action for Europe), 2025; procurement to be carried out by the end of 2030. Cf. European Parliament, EPRS, “EU joint defence procurement”, 2026.</p>



<p><strong>21.</strong> Defence Readiness Omnibus, European Commission, 17 June 2025 (accelerated authorisations, framework agreements up to 10 years, simplification of intra-EU transfers, exclusions in REACH/CLP, communication on sustainable finance); preliminary agreement of the co-legislators on the procurement part, June 2026. Source: European Commission (DG DEFIS); Staff Working Document to the proposal of 17 June 2025.</p>



<p><strong>22.</strong> Readiness Roadmap 2030 and the four flagship projects: European Drone Defence Initiative, Eastern Flank Watch, European Air Shield, European Space Shield; timetable: launch Q1 2026, initial capability end of 2026, full functionality of EDDI end of 2027, Eastern Flank Watch end of 2028. Source: European Commission (DG DEFIS); European Parliament, EPRS, “Eastern Flank Watch and European Drone Wall”, October 2025.</p>



<p><strong>23.</strong> European Commission, Action Plan on drone and counter-drone security, 11 February 2026 (IP/26/364); Drone Alliance with Ukraine; announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets.</p>



<p><strong>24.</strong> “Drone deals fueled VC’s 139% surge into defense robotics”, PitchBook, 19 March 2026 (approx. USD 6.2 billion in 169 transactions; a 139% increase).</p>



<p><strong>25.</strong> “Ukraine 2025 defence tech investment topped $57.2M, but the ‘funded market’ is $6.8B, says PitchBook”, Resilience Media, 9 July 2026.</p>



<p><strong>26.</strong> Regulation (EU) 2023/588 (the secure connectivity programme 2023–2027; the IRIS constellation). Source: EUR-Lex; European Commission (DG DEFIS).</p>



<p><strong>27.</strong> Directive (EU) 2022/2555 (NIS2), repealing Directive 2016/1148. Source: EUR-Lex; European Commission (DG CNECT).</p>



<p><strong>28.</strong> Directive (EU) 2022/2557 (CER – resilience of critical entities). Source: EUR-Lex.</p>



<p><strong>29.</strong> Regulation (EU) 2024/2847 (the Cyber Resilience Act) – reporting obligations from September 2026, full application from December 2027. Source: EUR-Lex.</p>



<p><strong>30.</strong> Regulation (EU) 2016/679 (GDPR), Article 2(2)(a) and (b), Articles 5, 6, 9, 13–14, 35; Article 4(2) TEU. European Data Protection Board, Guidelines 3/2019 on the processing of personal data through video devices. Directive (EU) 2016/680 and the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.</p>



<p><strong>31.</strong> Regulation (EU) 2023/2854 (the Data Act), applicable from 12 September 2025; Regulation (EU) 2022/868 (the Data Governance Act).</p>



<p><strong>32.</strong> The Digital Omnibus – the data part (GDPR, privacy in electronic communications, NIS2, the Data Act, DORA): negotiating status as at July 2026; withdrawal of the Cypriot Presidency’s compromise text from the COREPER II procedure at the end of June 2026. EDPB and EDPS, Joint Opinion 2/2026 of 11 February 2026 (opposition to the narrowing of the definition of personal data); Joint Opinion 1/2026 of 20 January 2026 on the amendments to the Artificial Intelligence Act.</p>



<p><strong>33.</strong> The Convention on International Civil Aviation (Chicago, 1944), Articles 3, 3 bis and 8; Additional Protocol I to the Geneva Conventions (1977), Article 36.</p>



<p><strong>34.</strong> The Group of Governmental Experts on LAWS within the framework of the CCW Convention: rolling text since 2024; joint statement of 42 states, September 2025; resolution of the First Committee of the UN General Assembly of 6 November 2025 (156 states); joint call of the UN Secretary-General and the President of the ICRC for the conclusion of negotiations by the end of 2026; Seventh CCW Review Conference – November 2026. Source: UNODA; Lieber Institute West Point, May 2026.</p>



<p><strong>35.</strong> NATO, principles of the responsible use of artificial intelligence in defence (2021) and the revised AI strategy.</p>



<p><strong>36.</strong> The Act of 8 December 2006 on the Polish Air Navigation Services Agency (Journal of Laws of 2025, item 1267), including the Agency’s extended competences in the area of unmanned systems.</p>



<p><strong>37.</strong> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815) – implementation of the CER Directive; the powers of critical infrastructure operators to use jamming devices (from 26 June 2026); the new Chapter 6a concerning unmanned floating objects; the extension of the powers of the Police, the Border Guard, the State Protection Service and the Military Gendarmerie; security audits; the Maritime Security Centre.</p>



<p><strong>38.</strong> The Act of 11 March 2022 on the Defence of the Homeland.</p>



<p><strong>39.</strong> The draft deregulatory amendment of the Aviation Law, transmitted by the Civil Aviation Authority to the Ministry of Infrastructure on 5 May 2026 (the system of penalties, insurance, notifications, protection of critical infrastructure, counter-drone systems) (at present no publication of the source text – see the footnotes referring to press information sources).</p>



<p><strong>40.</strong> Directive 2014/53/EU on radio equipment (essential requirements, harmful interference).</p>



<p><strong>41.</strong> Regulation (EU) 2019/452 establishing a framework for the screening of foreign direct investments; the Act of 24 July 2015 on the control of certain investments.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a href="#_ftnref1" id="_ftn1">[1]</a> <a href="https://www.youtube.com/watch?v=GCOeO35PQh8">https://www.youtube.com/watch?v=GCOeO35PQh8</a> Cf. the analytical material of a Polish commentator on the war and new technologies, based on accounts attributed to Ukrainian military intelligence (HUR), where it was indicated that Russia is producing “more Shaheds of the Geran 4 and 5 model, i.e.&nbsp;the jet variants, than Geran 2 drones, i.e.&nbsp;the piston ones – 3,000 jet-powered per month and 2,800 piston-powered.”</p>



<p><a href="#_ftnref2" id="_ftn2">[2]</a> Paweł Jeżowski, Rosja 2026: Koniec snu Putina o Imperium [Russia 2026: The End of Putin’s Dream of Empire] – Paweł Jeżowski <a href="https://www.youtube.com/watch?v=JSA9sh44Qj4&amp;t=27s">https://www.youtube.com/watch?v=JSA9sh44Qj4&amp;t=27s</a></p>



<p><a href="#_ftnref3" id="_ftn3">[3]</a> European Commission, <em>Communication from the Commission to the European Parliament and the Council – Action Plan on Drone and Counter Drone Security</em>, COM(2026) 81 final, 11 February 2026.</p>



<p><a href="#_ftnref4" id="_ftn4">[4]</a> Treaty on the Functioning of the European Union, Article 288 – the legal character of regulations, directives and other instruments of EU law.</p>



<p><a href="#_ftnref5" id="_ftn5">[5]</a> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815.</p>



<p><a href="#_ftnref6" id="_ftn6">[6]</a> The governmental bill amending the Act on Crisis Management and certain other acts, Sejm print no. 2355, the explanatory memorandum to the bill.</p>



<p><a href="#_ftnref7" id="_ftn7">[7]</a> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, <strong>Journal of Laws of 2026, item 815</strong>, introducing, inter alia, Article 16c into the Act of 26 April 2007 on Crisis Management. Text of the act: <a href="https://eli.gov.pl/eli/DU/2026/815/ogl/pol?utm_source=chatgpt.com">https://eli.gov.pl/eli/DU/2026/815/ogl/pol</a></p>



<p><a href="#_ftnref8" id="_ftn8">[8]</a> The Act of 26 April 2007 on Crisis Management, Article 16c, added by the Act of 29 May 2026.</p>



<p><a href="#_ftnref9" id="_ftn9">[9]</a> The Act of 3 July 2002 – Aviation Law, Article 156ze(1).</p>



<p><a href="#_ftnref10" id="_ftn10">[10]</a> The governmental bill amending the Act on Crisis Management and certain other acts, <strong>Sejm print no. 2355</strong>, together with the explanatory memorandum, Sejm of the Republic of Poland, 10th term: <a href="https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355"><u>https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355</u></a></p>



<p><a href="#_ftnref11" id="_ftn11">[11]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), Article 6 and Article 113.</p>



<p><a href="#_ftnref12" id="_ftn12">[12]</a> The regulation amending Regulation (EU) 2024/1689 as regards the dates of application of the obligations concerning high-risk AI systems.</p>



<p><a href="#_ftnref13" id="_ftn13">[13]</a> <strong>Council on Foreign Relations (CFR)</strong> The CFR indicates that the war in Ukraine has led to a hitherto unseen pace of innovation in unmanned systems: “the Russia-Ukraine war is driving innovations in autonomous warfare not seen on other battlefields.” Kristen Thompson, <em>How the Drone War in Ukraine Is Transforming Conflict</em>, Council on Foreign Relations, 16 January 2024.</p>



<p><a href="#_ftnref14" id="_ftn14">[14]</a> The <strong>Carnegie Endowment for International Peace</strong> describes the conflict as a “living laboratory” for new doctrines of warfare: “both sides are now engaged in a sustained effort to gain advantage through rapid innovation and adaptation, introducing new types of unmanned systems, countermeasures, and operating methods at unprecedented speed.” Andriy Zagorodnyuk, <em>The New Revolution in Military Affairs</em>, Carnegie Endowment for International Peace, 2026.</p>



<p><a href="#_ftnref15" id="_ftn15">[15]</a> <strong>CSIS – Center for Strategic and International Studies</strong> The CSIS report describes how, after the start of the full-scale invasion, Ukraine created within about three years an entirely new defence technology ecosystem based on drones, shortening development cycles from multi-year military programmes to months. Kateryna Bondar, <em>Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine</em>, Center for Strategic and International Studies (CSIS), 18 July 2025.</p>



<p><a href="#_ftnref16" id="_ftn16">[16]</a> K. Bondar, <em>Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine</em>, Center for Strategic and International Studies (CSIS), 2025. The author indicates that the war in Ukraine has radically shortened the cycles of development and deployment of drone technologies: solutions whose development in classic military programmes took many years are now designed, tested and deployed in periods counted in months. Link: <a href="https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine">https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine</a> , Michael Kofman, Rob Lee, <em>Not Built for Purpose: The Russian Military’s Ill-Fated Force Design</em>, Center for a New American Security / Carnegie Endowment for International Peace, an analysis of the technological adaptation of both sides of the conflict and the role of the rapid iteration of unmanned systems.</p>



<p>Link: <a href="https://carnegieendowment.org">https://carnegieendowment.org</a> International Institute for Strategic Studies (IISS), <em>The Military Balance 2025</em>, chapters on the Russo-Ukrainian war and the development of unmanned systems. The IISS indicates that the conflict in Ukraine has led to the mass use of drones as a basic element of combat operations and has accelerated the development of technologies for countering unmanned systems. Link: <a href="https://www.iiss.org/publications/the-military-balance/">https://www.iiss.org/publications/the-military-balance/</a></p>



<p>Samuel Bendett, <em>Russia’s War in Ukraine: The Role of Unmanned Systems and the Future of Warfare</em>, Center for Naval Analyses (CNA). Bendett’s analyses frequently indicate that the war in Ukraine has become a “laboratory” for the rapid evolution of unmanned systems, in which the innovation cycle has been shortened from years to months.</p>



<p>Link: <a href="https://www.cna.org/">https://www.cna.org/</a></p>



<p><a href="#_ftnref17" id="_ftn17">[17]</a> <a href="https://www.youtube.com/watch?v=vI1W4bYCuNA&amp;t=181s">https://www.youtube.com/watch?v=vI1W4bYCuNA&amp;t=181s</a>; thus General Skrzypczak in the press service: “<em>the 7th day of the offensive operation conducted by the Russians is ending. The Russians have not achieved their main objectives, the objectives of the operation, that is they have not captured and have not managed to carry out the encirclement of Kyiv and have not come out on the Mykolaiv axis towards Odesa in order to encircle it jointly with a naval landing. On the auxiliary axes they achieved limited success; they approached Kharkiv and Mariupol; they took Zaporizhzhia. The problem is that the Russians have lost their momentum; the offensive has been halted essentially along the entire front line; the Russians are preparing, trying to bring up reserves, to reconstitute the forces that are prepared, in order to prepare them for combat, but at this moment they do not have such capabilities.</em>”</p>



<p><a href="#_ftnref18" id="_ftn18">[18]</a> In practice, it is precisely at this point that the real value of legal advice for companies from the UAV and dual-use sector begins. For the same product may simultaneously be subject to the rules of aviation law, export law, data protection, cybersecurity, AI compliance and contractual restrictions connected with its further use by the client or integrator. Effective advice therefore does not consist in the analysis of a single provision in isolation from the rest, but in building a coherent risk map: from the classification of the product and the market entry model, through the assessment of compliance obligations and export restrictions, to the structure of contracts, responsibility for implementation and the security of project financing. In the drone sector, the advantage today is gained not only by those who develop better technology, but also by those who are able to order its legal and transactional status earlier in many jurisdictions simultaneously.</p>



<p><a href="#_ftnref19" id="_ftn19">[19]</a> Lieber Institute at West Point, <em>Whose Decision Was It? Drone Swarms and the Accountability Gap in Ukraine</em>, 25 July 2026.</p>



<p><a href="#_ftnref20" id="_ftn20">[20]</a> Commission Delegated Regulation (EU) 2019/945 of 12 March 2019 on unmanned aircraft systems and on third-country operators of unmanned aircraft systems, OJ EU L 152 of 11.06.2019, p.&nbsp;1.</p>



<p><a href="#_ftnref21" id="_ftn21">[21]</a> Commission Implementing Regulation (EU) 2019/947 of 24 May 2019 on the rules and procedures for the operation of unmanned aircraft, in particular Article 14 (the operator registration obligation). The character of the operator registration obligation, including for drones equipped with sensors capable of capturing personal data, is also explained by EASA.</p>



<p><a href="#_ftnref22" id="_ftn22">[22]</a> Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), in particular Article 4(1), Article 5, Article 6 and Article 35.</p>



<p><a href="#_ftnref23" id="_ftn23">[23]</a> Judgment of the Court of Justice of 11 December 2014, <strong>František Ryneš v Úřad pro ochranu osobních údajů</strong>, C-212/13, EU:C:2014:2428.</p>



<p><a href="#_ftnref24" id="_ftn24">[24]</a> Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items.</p>



<p><a href="#_ftnref25" id="_ftn25">[25]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), in particular Article 3, Article 6 and Annexes I and III.</p>



<p><a href="#_ftnref26" id="_ftn26">[26]</a> DJI (full name: SZ DJI Technology Co., Ltd., also referred to as Shenzhen DJI Sciences and Technologies Ltd.) is a private technology company with its registered office in Shenzhen in the People’s Republic of China, founded in 2006 by Frank Wang. The company specialises in the production of commercial and professional unmanned systems, image stabilisers, cameras, aerial imaging devices and solutions for consumer, industrial and agricultural applications. Its most recognisable product lines include, inter alia, Mavic, Mini, Air, Avata, Matrice, Agras and the Osmo line of handheld devices. In the trade literature and media coverage, DJI is commonly described as the largest manufacturer of consumer drones in the world, whereby, owing to the private character of the company, data on its precise revenues and sales volumes are not fully public; publicly available sources point, however, to the global scale of its activity, employment counted in the thousands, and a dominant position in the segment of civil camera drones; <a href="https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/">https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/</a></p>



<p><a href="#_ftnref27" id="_ftn27">[27]</a> <a href="https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic">https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic</a></p>



<p><a href="#_ftnref28" id="_ftn28">[28]</a> <a href="https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/">https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/</a></p>



<p><a href="#_ftnref29" id="_ftn29">[29]</a> <a href="https://www.frontline-robotics.tech/en#product">https://www.frontline-robotics.tech/en#product</a></p>



<p><a href="#_ftnref30" id="_ftn30">[30]</a> The NATO Codification System (NCS) does not derive from a single statute or regulation, but from NATO’s allied standardisation-logistics system, managed by Allied Committee 135 (AC/135). The basic system document is ACodP-1 (NATO Manual on Codification / AC/135 Codification Manual), which sets out the principles, responsibilities and procedures of codification. The system further rests on a series of NATO standardisation agreements (STANAG), in particular STANAG 3150, STANAG 3151, STANAG 4199 and STANAG 4438.</p>



<p><a href="https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO">https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO</a></p>



<p><a href="#_ftnref31" id="_ftn31">[31]</a> <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/">https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/</a></p>



<p><a href="#_ftnref32" id="_ftn32">[32]</a> <a href="https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/">https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/</a></p>



<p><a href="#_ftnref33" id="_ftn33">[33]</a> <a href="https://brave1.gov.ua/en">https://brave1.gov.ua/en</a></p>



<p><a href="#_ftnref34" id="_ftn34">[34]</a> <a href="https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii">https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii</a></p>



<p><a href="https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems">https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems</a></p>



<p><a href="#_ftnref35" id="_ftn35">[35]</a> <a href="https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/">https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/</a></p>



<p><a href="#_ftnref36" id="_ftn36">[36]</a> <a href="https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy">https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy</a></p>



<p><a href="#_ftnref37" id="_ftn37">[37]</a> <a href="https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation">https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation</a></p>



<p><a href="https://www.reuters.com/business/aerospace-defense/ukraine-sharply-raise-purchases-home-produced-fpv-drones-2025-2025-03-10">https://www.reuters.com/business/aerospace-defense/ukraine-sharply-raise-purchases-home-produced-fpv-drones-2025-2025-03-10</a></p>



<p><a href="https://www.reuters.com/world/europe/ukraine-ramps-up-arms-production-can-produce-4-million-drones-year-zelenskiy-2024-10-02">https://www.reuters.com/world/europe/ukraine-ramps-up-arms-production-can-produce-4-million-drones-year-zelenskiy-2024-10-02</a></p>



<p><a href="https://euromaidanpress.com/2026/01/26/ukraine-aims-to-build-7-million-drones-in-2026-70-times-more-than-the-us">https://euromaidanpress.com/2026/01/26/ukraine-aims-to-build-7-million-drones-in-2026-70-times-more-than-the-us</a></p>



<p><a href="#_ftnref38" id="_ftn38">[38]</a> <a href="https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c">https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c</a></p>



<p><a href="#_ftnref39" id="_ftn39">[39]</a> <a href="https://usf.com.ua/en/about-usf">https://usf.com.ua/en/about-usf</a></p>



<p><a href="#_ftnref40" id="_ftn40">[40]</a> <a href="https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en">https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en</a></p>



<p><a href="#_ftnref41" id="_ftn41">[41]</a> See Cabinet of Ministers of Ukraine, <em>Ukraine launches BRAVE1 defence tech cluster to stimulate development of military innovations and defence technologies</em>; cf.&nbsp;also Brave1, <em>About Brave1</em>, where it is indicated that Brave1 is a governmental initiative directed at the development of defence technologies, implemented by the Innovation Development Fund and initiated by the competent state organs and the components of Ukraine’s security and defence sector.</p>



<p><a href="https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii">https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii</a></p>



<p>See EEAS / Delegation of the European Union to Ukraine, <em>EU4UA Defence Tech: EU and Ukraine launch new EUR 3.3 million BRAVE1 grant programme</em>, indicating that the project is financed by the European Union and implemented by BRDO in cooperation with Brave1; cf.&nbsp;also BRDO, <em>Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base</em>, where the title of the implementation project linked with the EU4UA Defence Tech initiative was disclosed.</p>



<p><a href="https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en">https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en</a></p>



<p>See Regulations for the Brave1 EU4UA Defence Tech Grant Program, available in the Legal Terms section of the programme <em>Grant for the development of components for unmanned systems</em> on the eGrants platform; cf.&nbsp;also the Digital State communication, indicating that EU4UA Defence Tech is financed by the European Union and implemented by BRDO in cooperation with Brave1.</p>



<p><a href="https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems">https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems</a></p>



<p><a href="#_ftnref42" id="_ftn42">[42]</a> The concept of the radio horizon should be treated as a technical, not a normative, term. It does not function as a legal definition in the EASA regime, in U-space or in the classic acts of electronic communications law. Its legal significance is, however, obvious, because it describes a material limitation of communications on which the possibility of conducting unmanned operations beyond the direct line of sight depends, and thus it indirectly affects the assessment of the conformity of radio equipment, the safety of operations, the design of BVLOS architecture and liability for the continuity and reliability of transmission.</p>



<p><a href="#_ftnref43" id="_ftn43">[43]</a> <a href="https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0">https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0</a></p>



<p><a href="#_ftnref44" id="_ftn44">[44]</a> <a href="https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/">https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/</a>;</p>



<p><a href="#_ftnref45" id="_ftn45">[45]</a> <strong>Mesh modems turn Shaheds into FPV drones: how enemy technology works:</strong></p>



<p><a href="https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495">https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495</a></p>



<p><a href="#_ftnref46" id="_ftn46">[46]</a> <a href="https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/">https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/</a></p>



<p><a href="#_ftnref47" id="_ftn47">[47]</a> <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/">https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/</a>, <a href="https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/">https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/</a></p>



<p><a href="#_ftnref48" id="_ftn48">[48]</a> <a href="https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/">https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/</a></p>



<p><a href="#_ftnref49" id="_ftn49">[49]</a> European Commission, Joint Research Centre, <em>C-UAS detection, tracking and identification technology</em>.</p>



<p><a href="https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf">https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf</a></p>



<p>Alex Braszko, Center for Army Lessons Learned, August 12, 2025; Fiber Optic Drones: Posing a Significant C-UAS Challenge &#8211; <a href="https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge">https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge</a></p>



<p><a href="#_ftnref50" id="_ftn50">[50]</a> <a href="https://csrc.nist.gov/glossary/term/spoofing">https://csrc.nist.gov/glossary/term/spoofing</a>, <a href="https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf">https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf</a></p>



<p><a href="#_ftnref51" id="_ftn51">[51]</a> <a href="https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying">https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying</a></p>



<p><a href="#_ftnref52" id="_ftn52">[52]</a> <a href="https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371">https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371</a></p>



<p><a href="#_ftnref53" id="_ftn53">[53]</a> <a href="https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/">https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/</a> ; <a href="https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647">https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647</a></p>



<p><a href="#_ftnref54" id="_ftn54">[54]</a> <a href="https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md">https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md</a></p>



<p><a href="#_ftnref55" id="_ftn55">[55]</a> <a href="https://defence-blog.com/ukraine-fields-new-recon-strike-drone/">https://defence-blog.com/ukraine-fields-new-recon-strike-drone/</a></p>



<p><a href="#_ftnref56" id="_ftn56">[56]</a> <a href="https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/">https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/</a>, <a href="https://en.wikipedia.org/wiki/WB_Electronics_Warmate">https://en.wikipedia.org/wiki/WB_Electronics_Warmate</a></p>



<p><a href="#_ftnref57" id="_ftn57">[57]</a> <a href="https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html">https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html</a>;</p>



<p><a href="#_ftnref58" id="_ftn58">[58]</a> <a href="https://bavovna.ai/uav/fp-1/">https://bavovna.ai/uav/fp-1/</a>;</p>



<p><a href="#_ftnref59" id="_ftn59">[59]</a> See NV, How Ukraine-made FP-1 drone reshapes long-range strikes; Militarnyi, Ukrainian Fire Point Establishes In-House Production of Engines for Long-Range Drones; Reuters, Ukrainian drones hit Russia’s largest refinery, in one of deepest strikes yet; cf.&nbsp;also UNN and RBC-Ukraine in relation to the attack on Omsk and the scale of FP-1 production <a href="https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html"><u>NV</u></a> <a href="https://militarnyi.com/en/news/ukrainian-fire-point-establishes-in-house-production-of-engines-for-long-range-drones"><u>Militarnyi</u></a> <a href="https://www.reuters.com/business/energy/ukrainian-drones-hit-russias-largest-refinery-one-deepest-strikes-yet-2026-07-06/"><u>Reuters</u></a> <a href="https://unn.ua/en/amp/siberia-is-also-within-reach-of-ukrainian-precision-president-on-the-fp-1-drone-strike-on-the-omsk-refinery"><u>UNN</u></a> <a href="https://newsukraine.rbc.ua/news/ukraine-s-fp-1-drones-fly-3-400-km-to-strike-1783345876.html"><u>RBC-Ukraine</u></a>.</p>



<p><a href="#_ftnref60" id="_ftn60">[60]</a> See the MTCR Guidelines, the official MTCR website, indicating the division of the control annex into Category I and Category II; cf.&nbsp;also U.S. Department of State, <em>Missile Technology Control Regime (MTCR) Frequently Asked Questions</em>, where it is indicated that Category I covers complete rocket systems and unmanned aerial vehicle systems capable of delivering a payload of at least 500 kg to a range of at least 300 km; as regards the absorption of this logic into EU law, see Regulation (EU) 2021/821 setting up a Union regime for the control of exports of dual-use items. <a href="https://www.mtcr.info/en/mtcr-guidelines"><u>MTCR</u></a> <a href="https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions"><u>U.S. Department of State</u></a> <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L:2021:338:FULL&amp;from=EN"><u>EUR-Lex</u></a>; <a href="https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions">https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions</a></p>



<p><a href="#_ftnref61" id="_ftn61">[61]</a> On the significance of long-range communications for modern drone operations, see Atlantic Council, <em>The coming compute war in Ukraine</em>; on terminal guidance / machine vision enabling autonomous terminal-phase homing, see Modern War Institute, <em>Battlefield Drones and the Accelerating Autonomous Arms Race in Ukraine</em> and Defense Express, <em>How Ukrainian FPV Drones With Automated Terminal Guidance Work</em>; <a href="https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/">https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/</a></p>



<p><a href="#_ftnref62" id="_ftn62">[62]</a> See Article 2(3) and recital 24 of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), which exclude from the regulation’s scope AI systems used exclusively for military, defence or national security purposes; cf.&nbsp;also the discussions on autonomous weapon systems (LAWS) conducted within the framework of the Convention on Certain Conventional Weapons (CCW), in particular the work of the Group of Governmental Experts on Lethal Autonomous Weapons Systems (GGE on LAWS).</p>



<p><a href="#_ftnref63" id="_ftn63">[63]</a> See EASA, <em>Easy Access Rules for Unmanned Aircraft Systems</em>, revision from June 2026, indicating that this revision incorporates the AMC and GM to Regulation (EU) 2019/947 stemming from ED Decision 2025/018/R; cf.&nbsp;also the online version of the publication of 30 June 2026. <a href="https://www.easa.europa.eu/en/document-library/easy-access-rules/easy-access-rules-unmanned-aircraft-systems">EASA</a> <a href="https://www.easa.europa.eu/en/document-library/easy-access-rules/online-publications/easy-access-rules-unmanned-aircraft-systems">EASA online publication</a>.</p>



<p><a href="#_ftnref64" id="_ftn64">[64]</a> See European Parliamentary Research Service, <em>Defence and artificial intelligence</em> (2025), indicating that the European Parliament adopted two main resolutions concerning LAWS and military AI – in 2018 and 2021; cf.&nbsp;also EEAS, <em>Autonomous weapons must remain under human control, Mogherini says at European Parliament</em>. <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/769580/EPRS_BRI(2025)769580_EN.pdf"><u>EPRS PDF</u></a> <a href="https://www.eeas.europa.eu/eeas/autonomous-weapons-must-remain-under-human-control-mogherini-says-european-parliament_en"><u>EEAS</u></a></p>



<p><a href="#_ftnref65" id="_ftn65">[65]</a> See European Parliament Legislative Train, <em>Digital Omnibus on AI</em>, indicating that the proposal formed part of the package published on 19 November 2025; cf.&nbsp;also EPRS, <em>Digital Omnibus on AI</em>, where it is indicated that the co-legislators reached agreement in the trilogue on 7 May 2026, and the Parliament approved it on 16 June 2026; on the final adoption by the Council, see Consilium, <em>Artificial Intelligence: Council gives final green light to simplify and streamline rules</em>, 29 June 2026; the final act: Regulation (EU) 2026/1744. <a href="https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai">Legislative Train</a> <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/782651/EPRS_BRI%282026%29782651_EN.pdf">EPRS PDF</a> <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules">Consilium</a> <a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">EUR-Lex</a>;</p>



<p><a href="#_ftnref66" id="_ftn66">[66]</a> Regulation (EU) 2021/821 entered into force on 9 September 2021 as the new basic act of the Union’s system for the control of exports of dual-use items, replacing the earlier Regulation (EC) No 428/2009. The reference to 15 November 2025 does not mean that the act “ends” in 2025, but that from that day the cited consolidated version applies, taking account of the amendments to the text so far. The date of 8 September 2025, in turn, refers to one of the updates of the control lists / annexes. In August 2026, the regulation still remains an act in force.</p>



<p><a href="#_ftnref67" id="_ftn67">[67]</a> The transfer of model weights means the transfer of the trained parameters of the AI model themselves – that is, the numbers which the model “carries within itself” after training and on the basis of which it operates.</p>



<p><a href="#_ftnref68" id="_ftn68">[68]</a> See Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund; cf.&nbsp;also the European Defence Fund (2021–2027) on EUR-Lex and the European Commission’s official website concerning the EDF. <a href="http://eur-lex.europa.eu/eli/reg/2021/697/oj/eng">EUR-Lex</a> <a href="https://eur-lex.europa.eu/EN/legal-content/summary/european-defence-fund-2021-2027.html">EUR-Lex summary</a> <a href="https://commission.europa.eu/funding-and-tenders/find-funding/eu-funding-programmes/european-defence-fund_en">European Commission</a>;</p>



<p><a href="#_ftnref69" id="_ftn69">[69]</a> See Regulation (EU) 2023/2418 of the European Parliament and of the Council of 18 October 2023 establishing an instrument for the reinforcement of the European defence industry through common procurement (EDIRPA); cf.&nbsp;also the EUR-Lex summary and the European Commission’s official website concerning EDIRPA. <a href="https://eur-lex.europa.eu/eli/reg/2023/2418/oj/eng">EUR-Lex</a> <a href="https://eur-lex.europa.eu/EN/legal-content/summary/strengthening-the-european-defence-industry-through-common-procurement.html">EUR-Lex summary</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/edirpa_en">European Commission</a>;</p>



<p><a href="#_ftnref70" id="_ftn70">[70]</a> ASAP was established by Regulation (EU) 2023/1525 of the European Parliament and of the Council of 20 July 2023 as an instrument supporting the increase of the production capacities of European industry in the field of ammunition and missiles; the logic of this act – consisting in the public strengthening of the production capabilities of the defence industry – is functionally transferable also to the mass production of loitering munitions and drones. <a href="https://eur-lex.europa.eu/eli/reg/2023/1525/oj/eng">EUR-Lex</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/asap_en">European Commission</a>;</p>



<p><a href="#_ftnref71" id="_ftn71">[71]</a> SAFE (Security Action for Europe) was established by Council Regulation (EU) 2025/1106 of 27 May 2025 as a new instrument strengthening European defence capabilities and the defence industry through financial mechanisms and the support of coordinated actions of the Member States; it remains a current element of the EU defence architecture also in 2026. <a href="https://eur-lex.europa.eu/eli/reg/2025/1106/oj/eng">EUR-Lex</a> <a href="https://www.consilium.europa.eu/en/press/press-releases/2025/05/27/safe-council-adopts-new-financial-instrument-to-boost-eu-defence-capabilities/">Consilium</a>;</p>



<p><a href="#_ftnref72" id="_ftn72">[72]</a> See Regulation (EU) 2025/2643 of the European Parliament and of the Council of 16 December 2025 establishing the European Defence Industry Programme (EDIP); cf.&nbsp;also the European Commission’s official website concerning EDIP. <a href="https://eur-lex.europa.eu/eli/reg/2025/2643/oj/eng">EUR-Lex</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/edip-forging-europes-defence_en">European Commission</a>;</p>



<p><a href="#_ftnref73" id="_ftn73">[73]</a> This is a broader European Commission package, adopted on 17 June 2025, intended to create a “defence-readiness mindset” and to simplify the regulatory environment for defence investment. The Commission itself describes it as a comprehensive package and a simplification proposal, and the Parliament in the Legislative Train speaks outright of a Communication on the Defence Readiness Omnibus. It is therefore not simply “the same as EDIP”, but rather a deregulatory-simplification package and the political-legislative environment for faster action by the defence sector. <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/defence-readiness-omnibus_en">European Commission</a> <a href="https://www.europarl.europa.eu/legislative-train/theme-a-new-era-for-european-defence-and-security/file-defence-omnibus">Legislative Train</a></p>



<p><a href="#_ftnref74" id="_ftn74">[74]</a> See European Commission, <em>Readiness Roadmap 2030</em> and <em>White Paper for European Defence &#8211; Readiness 2030</em>, indicating the four flagship projects: Eastern Flank Watch, the European Drone Defence Initiative, the European Air Shield and the European Space Shield. <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/readiness-roadmap-2030_en">European Commission</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/white-paper-european-defence-readiness-2030_en">White Paper</a>.</p>



<p><a href="#_ftnref75" id="_ftn75">[75]</a> Regulation (EU) 2023/588 of the European Parliament and of the Council of 15 March 2023 establishing the Union Secure Connectivity Programme for the period 2023–2027. <a href="https://eur-lex.europa.eu/eli/reg/2023/588/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref76" id="_ftn76">[76]</a> Directive (EU) 2022/2555 (NIS2) of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. <a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref77" id="_ftn77">[77]</a> Directive (EU) 2022/2557 (CER) of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities. <a href="https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref78" id="_ftn78">[78]</a> Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements. <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref79" id="_ftn79">[79]</a> See EDPB/EDPS Joint Opinion 2/2026 of 11 February 2026 on the Digital Omnibus and the EDPB communication of the same day; as to the further negotiating stage and the withdrawal of the text from COREPER II at the end of June 2026, cf.&nbsp;the expert source: Privacy Next, Digital Omnibus Negotiations (GDPR) &#8211; July 2026 Update. <a href="https://www.edpb.europa.eu/news/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while-raising-key_en">EDPB</a> <a href="https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22026-on-the-proposal-for-a-regulation-as_en">Joint Opinion 2/2026</a> <a href="https://www.privacynext.eu/resources/digital-omnibus-negotiations-gdpr-july-2026-update/">Privacy Next</a>.</p>



<p><a href="#_ftnref80" id="_ftn80">[80]</a> See Article 36 of Additional Protocol I of 1977 to the Geneva Conventions; cf.&nbsp;also ICRC, <em>A Guide to the Legal Review of New Weapons, Means and Methods of Warfare</em>. <a href="https://ihl-databases.icrc.org/en/ihl-treaties/api-1977/article-36">ICRC art. 36</a> <a href="https://www.icrc.org/en/publication/0902-guide-legal-review-new-weapons-means-and-methods-warfare-measures-implement-article">ICRC Guide</a>.</p>



<p><a href="#_ftnref81" id="_ftn81">[81]</a> See CCW/MSP/2023/7, para. 20, in which the mandate of the Group of Governmental Experts (GGE) on emerging technologies in the area of lethal autonomous weapons systems (LAWS) was defined as the further consideration and formulation, “by consensus”, of a set of elements of an instrument, without prejudging its character; see also CCW/GGE.1/2026/WP.2, paras. 3–5, 76–78. The Seventh CCW Review Conference has been scheduled for 16–20 November 2026 in Geneva (CCW/MSP/2025/8, para. 19(g); see also UN Secretary-General, Letter convening the Seventh Review Conference of the CCW, April 2026).</p>



<p><a href="#_ftnref82" id="_ftn82">[82]</a> NATO, <em>Summary of the NATO Artificial Intelligence Strategy</em>, 22 October 2021, paras. 7–10, in particular para. 9, containing the six Principles of Responsible Use for AI in Defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability and Bias Mitigation; NATO, <em>Summary of NATO’s revised Artificial Intelligence (AI) strategy</em>, 10 July 2024, paras. 2, 5-10. The revised strategy of 2024 confirms the applicability of the six principles of the responsible use of AI and provides for their further operationalisation, inter alia through standards, assessment and testing procedures (TEV&amp;V) and certification mechanisms.</p>



<p><a href="#_ftnref83" id="_ftn83">[83]</a> <a href="https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r">https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r</a>; Record of the proceedings of the Standing Subcommittee on Civil Aviation (no. 10) of 10 June 2026, Sejm of the Republic of Poland, in particular the statement of the Director of the Unmanned Aircraft Department of the Civil Aviation Authority, Paweł Szymański, who indicated that the draft amendment concerning unmanned aircraft systems prepared by the Civil Aviation Authority was transmitted to the Ministry of Infrastructure on 5 May 2026, constituting a response to the postulates of civil society and the problems revealed in the practice of applying the new provisions; the draft was described as being of a deregulatory, clarifying and ordering character, covering, inter alia, a change of the regulations concerning mandatory third-party liability insurance and sanctions. <a href="https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&amp;documentId=2AEF7DEF0751F54BC1258E22003E5D23&amp;utm">https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&amp;documentId=2AEF7DEF0751F54BC1258E22003E5D23&amp;utm</a></p>



<p><a href="#_ftnref84" id="_ftn84">[84]</a> The postulate of meaningful human control does not currently constitute a separate, binding norm of international law. It is a concept developed within the framework of the negotiations concerning autonomous weapon systems, whose purpose is to ensure that the human retains real control over the application of force. Its legal justification is connected above all with the obligation to comply with the existing norms of international humanitarian law, in particular the principles of distinction, proportionality and the taking of precautionary measures, and the obligation to review new means and methods of warfare on the basis of Article 36 of Additional Protocol I.</p>



<p><a href="#_ftnref85" id="_ftn85">[85]</a> Article 6zj(1)–(4) of the Act of 26 April 2007 on Crisis Management, in the wording given by the Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815, in conjunction with Article 156ze(1) of the Act of 3 July 2002 – Aviation Law, consolidated text: Journal of Laws of 2025, item 1431, as amended.</p>



<p><a href="#_ftnref86" id="_ftn86">[86]</a> Article 2(2)(d) and Article 2(3) of Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, in the current consolidated text; see also Commission Recommendation (EU) 2021/1700 of 15 September 2021 on internal compliance programmes for controls of research involving dual-use items: <a href="https://eur-lex.europa.eu/eli/reg/2021/821/2025-11-15/eng?utm_source=chatgpt.com">Regulation 2021/821</a> and Recommendation 2021/1700.</p>



<p><a id="_ftn87" href="#_ftnref87">[87]</a> The Act of 24 July 2015 on the control of certain investments (consolidated text: Journal of Laws of 2026, item 47, as amended).</p>
<p> </p>






<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/output.mp4" length="1532791" type="video/mp4" />
<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/output-1-1.mp4" length="1247152" type="video/mp4" />

			</item>
		<item>
		<title>The evolution of the Polish investment support system: From SEZ to new changes in PSI</title>
		<link>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/the-evolution-of-the-polish-investment-support-system-from-sez-to-new-changes-in-psi/</link>
					<comments>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/the-evolution-of-the-polish-investment-support-system-from-sez-to-new-changes-in-psi/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 14:50:58 +0000</pubDate>
				<category><![CDATA[INVESTMENT LAW AND PROCESSES IN POLAND]]></category>
		<category><![CDATA[15% minimum tax]]></category>
		<category><![CDATA[CIT exemption]]></category>
		<category><![CDATA[corporate income tax]]></category>
		<category><![CDATA[decyzja o wsparciu]]></category>
		<category><![CDATA[duże przedsiębiorstwa]]></category>
		<category><![CDATA[Foreign Investment]]></category>
		<category><![CDATA[global minimum tax]]></category>
		<category><![CDATA[globalny podatek minimalny]]></category>
		<category><![CDATA[investment climate in Poland]]></category>
		<category><![CDATA[investment decision]]></category>
		<category><![CDATA[investment in Poland]]></category>
		<category><![CDATA[investment incentives]]></category>
		<category><![CDATA[investment support]]></category>
		<category><![CDATA[inwestycje w Polsce]]></category>
		<category><![CDATA[inwestycje zagraniczne]]></category>
		<category><![CDATA[large enterprises]]></category>
		<category><![CDATA[minimum tax]]></category>
		<category><![CDATA[new investments]]></category>
		<category><![CDATA[nowe inwestycje]]></category>
		<category><![CDATA[Pillar Two]]></category>
		<category><![CDATA[podatek CIT]]></category>
		<category><![CDATA[podatek minimalny 15%]]></category>
		<category><![CDATA[podatek wyrównawczy]]></category>
		<category><![CDATA[Polish investment policy]]></category>
		<category><![CDATA[Polish Investment Zone]]></category>
		<category><![CDATA[Polish special Economic Zones]]></category>
		<category><![CDATA[Polska Strefa Inwestycji (PSI)]]></category>
		<category><![CDATA[pomoc publiczna]]></category>
		<category><![CDATA[przedsiębiorcy]]></category>
		<category><![CDATA[public aid]]></category>
		<category><![CDATA[regional aid]]></category>
		<category><![CDATA[Special Economic Zones]]></category>
		<category><![CDATA[specjalne strefy ekonomiczne (SSE)]]></category>
		<category><![CDATA[SSE]]></category>
		<category><![CDATA[state aid]]></category>
		<category><![CDATA[support decision]]></category>
		<category><![CDATA[tax exemption]]></category>
		<category><![CDATA[tax incentives]]></category>
		<category><![CDATA[tax relief]]></category>
		<category><![CDATA[UD391]]></category>
		<category><![CDATA[ulgi podatkowe]]></category>
		<category><![CDATA[wsparcie inwestycji]]></category>
		<category><![CDATA[zwolnienie z CIT]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8872</guid>

					<description><![CDATA[<p>Publication date: August 25, 2026 The development of the Polish investment support system began in the mid-1990s, when Special Economic Zones (hereinafter referred to as SEZs) were established under the Act of 20 October 1994. According to Article 2 of this Act, the system was limited solely to designated, uninhabited areas of the territory of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/the-evolution-of-the-polish-investment-support-system-from-sez-to-new-changes-in-psi/">The evolution of the Polish investment support system: From SEZ to new changes in PSI</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: August 25, 2026</mark></strong></p>



<p>The development of the Polish investment support system began in the mid-1990s, when Special Economic Zones (hereinafter referred to as SEZs) were established under the Act of 20 October 1994. According to Article 2 of this Act, the system was limited solely to designated, uninhabited areas of the territory of the Republic of Poland, where business activity could be conducted on preferential terms. However, a real breakthrough in this approach occurred in 2018 with the entry into force of the Act on Supporting New Investments. This introduced a completely new model – the support system was no longer limited to closed sectors. The resulting Polish Investment Zone effectively recognized the entire territory of Poland as a single large area where entrepreneurs could apply for aid for new projects. The primary support tool in both regimes remained the income tax exemption. In this respect, the Acts refer directly to the Corporate Income Tax Act of 15 February 1992 (CIT Act) – and in particular to Article 17, paragraph 1, item 34 (regarding exemptions within SEZs) and Article 17, paragraph 1, item 34a (regarding new investments within PSIs). We are currently at a key, transitional moment in this evolution. The historical SEZ system has a strictly defined expiry date – it will expire irrevocably at the end of 2026, giving way only to new regulations. This study outlines the framework for this transformation, from the zones being phased out to the current challenges and simplifications in the investment support system.</p>



<span id="more-8872"></span>



<p><strong>Current regulations relating and changes pursuant to the regulation</strong></p>



<p>The main tool stimulating development under the 2018 Act on Supporting New Investments (PSI) is the exemption from corporate income tax (CIT). This mechanism is based on the implementation of a historically proven solution known from Special Economic Zones (SEZs). This exemption is treated directly as regional public aid from the state. Although in both regimes – the old SEZ Act and the new WNI Act – the exemption mechanism itself is based on general provisions (lex generalis), namely the Corporate Income Tax Act, the scope of this aid is not unlimited. The fixed, maximum level of support an investor can expect is defined directly by the zone regulations and specified in the relevant implementing regulations of the Council of Ministers. In the case of SEZs, the amount of support granted cannot exceed the maximum permissible amount specified in these acts.</p>



<p>A crucial element of the current system is significantly facilitating access to support for large businesses. Under the new regulations, in the enumerated counties (located primarily in the eastern and northern regions, including Suwałki, Białystok, and Chełm counties), minimum investment costs have been reduced from PLN 60 million or PLN 40 million to just PLN 10 million. Furthermore, in accordance with the zone rules, if an investor decides to reinvest (e.g., expand an existing plant), this threshold is further reduced by half. As a result, a large business requires just PLN 5 million to enter the support system. This solution is intended to provide a powerful incentive for private capital to invest in less developed regions of Poland.</p>



<p>The aforementioned mechanisms are detailed in the Regulation of the Council of Ministers of December 27, 2022, which was amended on June 13, 2025. This Act precisely defines the list of excluded activities, i.e., those that cannot apply for support under the Act. According to the new wording of the regulations (§ 2, paragraph 1, point 2), ineligible activities include, among others, the production of tobacco products and the production, bottling, and processing of alcoholic beverages (with the exception of biocomponents). On the other hand, the amendment brought a significant opening for the defense sector – by repealing § 2, paragraph 1, point 1, the production of weapons, ammunition, and explosives was removed from the current list of exclusions. As a result, entities in the defense industry can now apply for tax relief under the terms of the Act.</p>



<h3 class="wp-block-heading"><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Changes to the Act in WNI and the reasons for the change.</mark></strong></h3>



<p>The culmination of changes to the new investment support system is an amendment scheduled for 2026 (Council of Ministers bill no. UD391). To compensate entrepreneurs for the new fiscal burden, the government proposes, among other things, relaxing the investment timeframe. A key element of the amendment is extending the validity of the Support Decision ( DoW ) for all areas to 20 years. It is important to note that the DoW is a key administrative act issued within the Polish Investment Zone, formally granting the right to corporate income tax exemption. While this change does not de jure affect the amount of public aid, it de facto increases the effectiveness of this mechanism. Investors will gain a stable, 20-year time buffer, allowing for more flexible management of the effective tax rate.</p>



<p>An analysis of the official assumptions for the UD391 project, available on government websites, allows us to clearly understand the legislator&#8217;s intentions. As indicated in the recitals, the main goal of the planned legislative change is to reverse the negative trend and ensure that support instruments in Poland remain attractive to large businesses (both domestic and foreign). This is a direct and necessary response to new international regulations that have drastically reduced the attractiveness of traditional tax exemptions for the largest capital groups.</p>



<p>The need to introduce these simplifications stems directly from the adoption in 2024 of the Act on Equalization Taxation of Component Entities of International and Domestic Groups. This Act implements EU Council Directive (EU) 2022/2523. It imposes a new obligation on component entities of international groups and large domestic groups whose consolidated revenues exceed the threshold of €750 million. The overarching goal of these regulations—the minimum tax rate set at 15%—introduces significant restrictions for entities benefiting from national regional support instruments. Pursuant to Article 1, Section 2 of the Polish Act, revenues from the new tax (comprising the global and domestic equalization tax) constitute state budget revenue.</p>



<p>To fully understand the reasons for introducing the top-up tax, it&#8217;s necessary to refer to the recitals of the EU directive. Recitals 1 and 2 clearly express concerns about tax avoidance by giant corporate groups (MNEs). The European Union aims to ensure that they pay fair tax where they actually generate profits. Recital 4, in turn, explains the need for coherent and coordinated action in the form of a directive – this is intended to prevent fragmentation of the internal market while giving Member States the freedom to integrate these mechanisms into their national systems.</p>



<p>However, when imposing the new tax, the legislator provided certain protective mechanisms, crucial for entities operating in SEZs and PSIs. As explicitly noted in recital 14 of the directive, in situations where an SEZ conducts genuine economic activity requiring a physical presence (investing in production facilities and employing workers), the risk of artificial profit transfer is minimal. This has a direct impact on Polish law (generally in force since 1 January 2025). Article 101 introduces the so-called &#8220;capital and personal income tax exemption,&#8221; which mitigates the effects of the new tax proportionally to the wage costs and value of tangible fixed assets incurred in the zones.</p>



<p><strong>SSE what will happen after December 31, 2026</strong></p>



<p>The draft amendment to the Act on Supporting New Investments (No. UD391) does not introduce provisions extending the validity of historical SEZ permits. This represents a final acceptance that, as of December 31, 2026, the Special Economic Zone system will irrevocably expire, and the SEZ Act itself will cease to apply. Consequently, entrepreneurs using the old permits will lose the right to continue to apply the CIT exemption after this date, and their unused public aid limits will simply be forfeited. It should be emphasized, however, that the tax exemption will apply to all income actually generated (obtained) by December 31, 2026, even if it is formally reported in the annual CIT return after the SEZs expire. The overarching goal of the proposed amendment is, therefore, to encourage investors to smoothly transition to the reformed Polish Investment Zone regulations.</p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/the-evolution-of-the-polish-investment-support-system-from-sez-to-new-changes-in-psi/">The evolution of the Polish investment support system: From SEZ to new changes in PSI</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/investment-law-and-processes-in-poland/the-evolution-of-the-polish-investment-support-system-from-sez-to-new-changes-in-psi/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Can AI Diagnose Patients? Medical Law and the Artificial Intelligence Revolution</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 12:48:06 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[diagnostic liability]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[doctor responsibility]]></category>
		<category><![CDATA[future of medicine]]></category>
		<category><![CDATA[health law]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[informed consent]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[medical ethics]]></category>
		<category><![CDATA[medical law]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[patient safety]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8868</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The development of artificial intelligence in medicine is no longer just a futuristic vision. Algorithms now support diagnostics, test result analysis, and disease prevention, and Polish medical law is beginning to address the challenges involved. The 2025 amendment to the Code of Medical Ethics explicitly addresses the use of AI [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/">Can AI Diagnose Patients? Medical Law and the Artificial Intelligence Revolution</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<figure class="wp-block-video"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/generated-video-5.mp4"></video></figure>



<p>The development of artificial intelligence in medicine is no longer just a futuristic vision. Algorithms now support diagnostics, test result analysis, and disease prevention, and Polish medical law is beginning to address the challenges involved. The 2025 amendment to the Code of Medical Ethics explicitly addresses the use of AI by physicians for the first time, imposing obligations regarding patient information, obtaining informed consent, and the use of certified systems. However, the question arises: where does the role of technology end and the physician&#8217;s responsibility begin?</p>



<span id="more-8868"></span>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Amendment to the Code of Medical Ethics from 2025</strong></p>



<p>The 2025 amendment to the Code of Medical Ethics addressed the use of artificial intelligence in medical practice for the first time in the history of Polish medical law. Because AI systems are defined as high-risk systems in the EU regulation on artificial intelligence, necessary procedural steps are identified before their practical application. The Code of Medical Ethics stipulates that four criteria must be met: informing the patient about the use of AI in the therapeutic process or when making a diagnosis; obtaining the patient&#8217;s informed consent to the use of AI. According to the AI Act, algorithms approved for medical use and holding appropriate certificates should be used. It is recommended that AI systems support physicians in their work rather than replace them. Therefore, the final decision regarding the use of AI algorithms in medicine rests with the physician. This emphasizes the need for continuous improvement in medical knowledge and the ability to adapt to new technologies.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The obligation to inform the patient that artificial intelligence will be used in the diagnosis or therapeutic process</strong></p>



<p>Properly informing a patient about the use of artificial intelligence is understood as providing accurate information about the fact and characteristics of the AI system being used. This obligation also involves obtaining the patient&#8217;s informed consent to the use of AI systems, which means informing the patient about the possible benefits and risks of the proposed actions and the possibility of using other actions, as well as ensuring the patient knows and understands how the AI system being used works. Physicians should consider the circumstances and personality traits of the individual patient, ensuring that information is provided in an appropriate manner that allows for understanding the content of the message being communicated. The essence of the need for information is that AI systems are not infallible, and although the physician makes the final decision, the patient is aware of the potential risks arising from the use of AI systems. It is fundamentally crucial to respect two important patient rights: the right to information and the right to consent to healthcare services.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The obligation to obtain informed consent from the patient to use artificial intelligence in the diagnostic or therapeutic process</strong></p>



<p>A written declaration of intent is not necessary to obtain patient consent; an oral statement or conduct that leaves no doubt as to the expression of intent is sufficient, although this can pose numerous evidentiary challenges in the event of a lawsuit against the doctor. If patients have been informed of the use of artificial intelligence in the diagnostic or therapeutic process, their consent to the provision of healthcare services will also include consent to the use of AI to provide these services, without the need for separate consent for the initial use of AI. When using AI systems in clinical practice, a distinction must be made between situations where the algorithm is crucial to the service being provided, for example, influencing the patient&#8217;s subsequent decisions without the doctor&#8217;s consent or with minimal consent. In such cases, informing the patient and obtaining their consent is essential. However, when algorithms merely support the doctor&#8217;s work, patient consent is not strictly required, but it is recommended to inform them about the use of AI systems.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The obligation to use artificial intelligence algorithms that are approved for medical use and have appropriate certificates</strong></p>



<p>According to the AI Act, algorithms approved for medical use and with appropriate certificates must be used, given that medical practice may impact the health or life of the patient. The European system for the safety and market approval of products meeting EU requirements requires testing products using AI systems for compliance with standards and obtaining a certificate of conformity with the CE marking. Most medical software produced in the European Union requires external auditing and certification. A medical device can be software whose manufacturer has intended for use in at least one of the specific medical applications specified in the Medical Devices Regulation. The use of scientifically unverified therapeutic methods is prohibited. Software can be used for various purposes, for example, to control other medical devices, provide information that supports further therapeutic or diagnostic decisions, or assist in the interpretation of results generated by other devices.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size">The final diagnostic and therapeutic decision is always made by the doctor</p>



<p>The fourth regulation, Article 12 of the Code of Medical Ethics, aims to emphasize that artificial intelligence supports physicians in their work, rather than replaces them. Because scientific considerations about artificial intelligence are relatively new, societies still harbor many doubts about increasing the use of artificial intelligence, especially in classified high-risk systems. Furthermore, it is currently impossible for artificial intelligence to replace certain traits that physicians are capable of exercising, such as empathy and intuition.</p>



<p class="has-luminous-vivid-amber-background-color has-background">Prospects and forecasts for the use of artificial intelligence in the work of doctors</p>



<p>The use of artificial intelligence in preventive medicine offers broad prospects thanks to the rapid analysis of millions of data points, which aims to enable early detection of disease. In such cases, the same conditions specified in Article 12 of the Code of Medical Ethics must be met as for treatment and diagnostic procedures. Currently, AI algorithms are increasingly equal to or even superior to qualified physicians in their preventive care. However, the novelty of the technology and the suggestion that AI is solely intended to facilitate physicians&#8217; work contribute to many people&#8217;s skepticism about the further development of AI in preventive medicine. According to researchers, AI is ideal for preventing cardiovascular disease through remote monitoring of hypertension, and the algorithms can analyze, in addition to individual parameters, medical history, genetic predisposition, and lifestyle factors.</p>



<p>Legal status of Code of Medical Ethics</p>



<p>The Code of Medical Ethics was adopted in 1991 during the Extraordinary Second National Congress of Physicians. It is adopted and amended by the Supreme Medical Chamber. Although it is an important act for the medical profession, it does not have the status of a statute and, within the meaning of the Constitution, is not a legal act; instead, it is based on the Act on Medical Chambers. Physicians, as a professional group, have professional self-government, which influences regulations related to professional ethics. Resolutions in the Polish legal system are internal acts, regulating, among other things, the ethical principles of individual professions. The resolution addresses general ethical standards, respect for human rights, and upholding the dignity of the medical profession, which is further defined as physician conduct that does not undermine trust in the profession.</p>



<h2 class="wp-block-heading">Liability for diagnostic errors of artificial intelligence systems</h2>



<p>The dynamic development of artificial intelligence systems in medicine raises significant questions regarding liability for erroneous diagnostic or therapeutic decisions made using AI algorithms. This issue remains one of the most challenging in contemporary medical law, as current regulations do not yet provide a uniform model for liability for damages caused by AI systems.</p>



<p>Generally, according to Article 12 of the Code of Medical Ethics, the final diagnostic and therapeutic decision rests with the physician. This means that even when using advanced AI algorithms, the physician is not released from the obligation to exercise due diligence and critically evaluate the obtained results. If a physician thoughtlessly bases a diagnosis solely on the AI system&#8217;s indications, they may be subject to civil, professional, and in certain cases criminal liability for harm caused to the patient.</p>



<p>However, liability may also apply to healthcare providers, especially when the damage results from improper organization of the treatment process, the use of an uncertified AI system, or a lack of appropriate oversight procedures for the software used. The hospital or clinic is responsible for ensuring the organizational security of the healthcare services provided and for using tools that meet legal requirements and safety standards.</p>



<p>In certain situations, the manufacturer or supplier of an AI system may also be liable. This applies primarily to software malfunctions, design errors, improper model training, or the product&#8217;s noncompliance with the requirements of the AI Act and medical device regulations. In such cases, product liability or contractual liability provisions may apply.</p>



<p>Particular difficulties arise, however, when an incorrect diagnosis results from the so-called autonomous learning process of an AI system. Artificial intelligence systems lack legal personality and therefore cannot be held accountable independently. This necessitates determining which of the participants in the process &#8211; the doctor, the medical facility, the manufacturer, or the technology provider &#8211; actually contributed to the damage.</p>



<p>The doctrine emphasizes that with the further development of artificial intelligence, it will be necessary to create clearer regulations regarding liability for damage caused by AI systems in healthcare. The current legal framework relies primarily on the application of provisions analogous to traditional medical liability and product liability.</p>



<h2 class="wp-block-heading">Other legal acts supplementing the issues of artificial intelligence in medicine</h2>



<h4 class="wp-block-heading">Act on Patients&#8217; Rights and the Patient Ombudsman</h4>



<p>The 2008 Act on Patients&#8217; Rights and the Patient Ombudsman contains regulations complementary to the Code of Medical Ethics, but without addressing the topic of artificial intelligence. Patients have the right to information regarding, among other things, diagnosis, proposed diagnostic and treatment methods, and the foreseeable consequences of their use or omission, as well as the right to information about the type and scope of healthcare services provided by the healthcare provider.</p>



<h2 class="wp-block-heading">Act on the Professions of Physician and Dentist</h2>



<p>The 1996 Act on the Profession of Physicians and Dentists regulates the obligation to practice the profession in accordance with current medical knowledge, available methods and means of preventing, diagnosing, and treating diseases, in accordance with the principles of professional ethics, and with due diligence. In the case of the use of artificial intelligence in medicine as a high-risk system, this means the obligation, stipulated in the KEL, to use certified and approved systems.</p>



<h2 class="wp-block-heading">Other legal acts relating to the issue of artificial intelligence in medicine</h2>



<p>Because the field of artificial intelligence is a relatively new field of study and few legal acts have been created to date to regulate its operation, the vast majority of clinic and hospital regulations still do not directly address the use of artificial intelligence systems in healthcare services. However, indirect references can be found, such as specifying the institution&#8217;s purpose as, among other things, teaching and research activities in connection with the provision of healthcare services and health promotion, including the implementation of new treatment methods and medical technologies, which include artificial intelligence systems.</p>



<h2 class="wp-block-heading">Summary</h2>



<p>The dynamic development of artificial intelligence in healthcare means that existing legal regulations may prove insufficient in the coming years. Developing clear rules of accountability for AI-supported decisions and maintaining a balance between innovation and patient safety will be crucial. Despite technological advances, humans – physicians &#8211; should continue to play a central role in the diagnostic and therapeutic process, bearing responsibility for the patient&#8217;s well-being.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/">Can AI Diagnose Patients? Medical Law and the Artificial Intelligence Revolution</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/generated-video-5.mp4" length="3082353" type="video/mp4" />

			</item>
		<item>
		<title>Drone Warfare, Dual-Use Technologies, and Legal Risk: The Russo-Ukrainian Conflict as a Lens for EU and Polish Regulation</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare-dual-use-technologies-and-legal-risk-the-russo-ukrainian-conflict-as-a-lens-for-eu-and-polish-regulation/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare-dual-use-technologies-and-legal-risk-the-russo-ukrainian-conflict-as-a-lens-for-eu-and-polish-regulation/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 03 Aug 2026 11:23:54 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8866</guid>

					<description><![CDATA[<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare-dual-use-technologies-and-legal-risk-the-russo-ukrainian-conflict-as-a-lens-for-eu-and-polish-regulation/">Drone Warfare, Dual-Use Technologies, and Legal Risk: The Russo-Ukrainian Conflict as a Lens for EU and Polish Regulation</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare-dual-use-technologies-and-legal-risk-the-russo-ukrainian-conflict-as-a-lens-for-eu-and-polish-regulation/">Drone Warfare, Dual-Use Technologies, and Legal Risk: The Russo-Ukrainian Conflict as a Lens for EU and Polish Regulation</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare-dual-use-technologies-and-legal-risk-the-russo-ukrainian-conflict-as-a-lens-for-eu-and-polish-regulation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Lootboxes in Computer Games – Between Gambling Law and Consumer Protection. Regulatory Analysis Against the Background of Polish and European Union Law.</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 18:26:30 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[behavioural design]]></category>
		<category><![CDATA[children online protection]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital fairness]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[eSports law]]></category>
		<category><![CDATA[EU digital regulation]]></category>
		<category><![CDATA[EU gaming law]]></category>
		<category><![CDATA[gacha games]]></category>
		<category><![CDATA[gambling law]]></category>
		<category><![CDATA[gaming compliance]]></category>
		<category><![CDATA[gaming compliance Europe]]></category>
		<category><![CDATA[gaming industry regulation]]></category>
		<category><![CDATA[gaming law]]></category>
		<category><![CDATA[gaming legal advice]]></category>
		<category><![CDATA[gaming taxation]]></category>
		<category><![CDATA[international gaming law]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kieltyka gladkowski]]></category>
		<category><![CDATA[loot box regulation]]></category>
		<category><![CDATA[Loot boxes]]></category>
		<category><![CDATA[microtransactions]]></category>
		<category><![CDATA[online gaming regulation]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Polish gaming law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[skin gambling]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[video game law]]></category>
		<category><![CDATA[video game monetisation]]></category>
		<category><![CDATA[virtual assets]]></category>
		<category><![CDATA[virtual economy]]></category>
		<category><![CDATA[virtual items]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8861</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 The dynamic development of the computer games market has led to a significant change in the monetization models used by game producers and publishers. The traditional sales model, based on a one-time purchase of a product by the consumer, has been largely replaced by solutions based on long-term user engagement [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/">Lootboxes in Computer Games – Between Gambling Law and Consumer Protection. Regulatory Analysis Against the Background of Polish and European Union Law.</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 24, 2026</strong></mark></p>



<p>The dynamic development of the computer games market has led to a significant change in the monetization models used by game producers and publishers. The traditional sales model, based on a one-time purchase of a product by the consumer, has been largely replaced by solutions based on long-term user engagement and generating revenue through micropayments (microtransactions). Mechanisms known as loot boxes, consisting in the paid purchase of virtual packages with random content.</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="692" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-1024x692.jpg" alt="" class="wp-image-8863" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-1024x692.jpg 1024w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-300x203.jpg 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-768x519.jpg 768w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-1536x1038.jpg 1536w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-2048x1385.jpg 2048w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<span id="more-8861"></span>



<p>Although initially perceived as a means of enhancing gameplay, this mechanism is currently the subject of intense legal, economic, and social debate. It is increasingly being pointed out that the design of loot boxes utilizes psychological mechanisms similar to those that have been present in traditional gambling games for many years. The random nature of the reward, the uncertainty of the outcome, the &#8220;near miss&#8221; effect, the limited availability of certain items, and the use of dynamic animations intended to enhance the user&#8217;s emotional engagement all contribute to the blurring of the line between entertainment and gambling mechanisms.</p>



<p>Additional controversy stems from the fact that the vast majority of modern games using loot boxes are also aimed at minors. Unlike traditional gambling games, participation in these mechanisms does not require a specific age or meeting specific formal requirements. In practice, this means that random monetization mechanisms are also used by children and adolescents, who, due to their stage of psychological development, are particularly susceptible to the influence of behavioral design techniques and so-called dark patterns).</p>



<p>In recent years, the issue of loot boxes has ceased to be analyzed solely through the prism of gambling law. Regulations concerning consumer protection, digital services, and child safety in the online environment are gaining increasing importance. Discussions at the European Union level indicate that the future legal framework may be based not only on classic definitions of games of chance but also on instruments to combat manipulative practices and ensure a high level of protection for consumers using digital services.</p>



<p>At the national level, the problem remains equally relevant. Polish lawmakers have not yet decided to introduce a separate definition of loot boxes into <strong>the Gambling Ac</strong>t of 19 November 2009. This does not mean, however, that these mechanisms remain entirely outside the scope of existing regulations. In practice, administrative bodies assess each specific business model on a case-by-case basis, analyzing whether its design meets the statutory definition of gambling. At the same time, the development of the secondary market for trading in virtual items, particularly so-called skin gambling , is creating new interpretative challenges that the legislature did not anticipate when enacting the current regulations.</p>



<p>The changes introduced by the <strong>PEGI rating system in 2026</strong> provided an additional impetus for reassessing the current regulations. The revised rules for classifying games with paid random mechanisms confirm the growing awareness of the risks associated with the use of loot boxes, especially for underage users. Although the PEGI rating is not a source of generally applicable law, its practical importance for the European market remains significant and may influence both the distribution of games and the future direction of legislative changes.</p>



<p>The purpose of this article is to analyze the current legal status of loot boxes under Polish and European Union law, taking into account recent regulatory changes, the practices of administrative bodies, and the experiences of selected European countries. Particular attention will be paid to whether the current regulations effectively protect consumers from mechanisms based on randomness and whether the current regulatory model meets the challenges of the modern digital economy.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The essence of loot boxes and their functioning models</strong></p>



<p>The concept <em>of a lootbox </em>has not yet been defined in either Polish or European Union law. However, in the literature and by public institutions, it is generally accepted that a lootbox is a mechanism whereby the user obtains, for a fee or free of charge, a virtual package containing items whose contents remain unknown until opened. A characteristic element of this solution is randomness – the user has no influence on the item they receive, and the probability of obtaining individual rewards is determined by the game developer or platform operator.</p>



<p>At the definitional level, however, it should be emphasized that the term &#8220;lootbox&#8221; encompasses a wide variety of business models, the legal assessment of which cannot be uniform. Public debate often equates all mechanisms based on randomness with gambling, while from a legal perspective, individual solutions differ in both their economic structure and the degree of risk to the consumer. It is precisely this diversity that means that assessing the compliance of lootboxes with applicable regulations requires an analysis of the specific operational model, not just the presence of a random element.</p>



<p>The most classic model occurs in games where lootbox content is limited solely to cosmetic items, such as skins , animations, character outfits, or visual effects. These items do not affect gameplay or increase the player&#8217;s chances of success. They are intended solely for aesthetic purposes, allowing the user to personalize the appearance of their character or equipment. Such solutions were long considered relatively safe from a consumer protection perspective, but the development of secondary markets for trading virtual items has significantly changed their economic significance.</p>



<p>A good example is the <em>Counter-Strike series</em>, where weapon skins initially served only a visual purpose. Over time, however, a robust secondary market developed around these items, allowing them to be sold for real money. Consequently, the value of some virtual items began to reach several thousand, or even several dozen thousand, and in exceptional cases, several hundred thousand euros. In practice, this means that a randomly acquired item can have a tangible financial value, even though the game developer itself does not officially allow for its sale. The existence of an external market is one of the main arguments raised in the discussion on the classification of such mechanisms as potentially akin to gambling.</p>



<p>Loot boxes used in sports games, such as <em>EA SPORTS FC Ultimate Team, </em>are of a different nature. In this model, users purchase virtual packs containing player cards, coaches, or other team items. Unlike skins in games like <em>Counter-Strike</em>, acquired items directly impact gameplay. Acquiring rare players can increase a team&#8217;s competitiveness and improve player performance. Although the developer publishes information regarding the probability of receiving rewards in a given category, the user still doesn&#8217;t know the contents of a specific pack at the time of purchase, and the decision to purchase is based on a random mechanism.</p>



<p>Yet another model is found in so-called <em>gacha games</em>, extremely popular, especially in Asian markets and in the mobile gaming segment. This mechanism is based on randomization of characters, equipment, or other items necessary for further progression in the game. A characteristic feature of <em>gacha systems </em>is their close connection to long-term user monetization. Players are encouraged to repeatedly make micropayments to obtain exceptionally rare characters or items, the probability of obtaining which can be extremely low. The literature indicates that these solutions most fully utilize the mechanisms of behavioral economics and the psychology of addiction.</p>



<p>However, the most controversial are third-party platforms that enable the trading of virtual items and participation in games of chance that use items from video games as a form of currency. These services operate independently of game developers, leveraging the existing market for skins or other digital goods to organize mechanisms reminiscent of classic casino games. Users deposit funds or use their virtual items to participate in lotteries, roulette, duels, or other games based on chance. Unlike traditional loot boxes offered by game producers, the participant&#8217;s goal is not only to obtain a specific item but often to achieve a tangible economic benefit resulting from the possibility of reselling it.</p>



<p>From a legal perspective, the differences between the presented models are crucial. Not every mechanism employing an element of randomness automatically leads to its classification as gambling. Factors that should be assessed include, first and foremost, the potential for financial gain, the existence of a secondary market, the method of financing participation, the possibility of withdrawing funds, and the actual impact of randomness on achieving a specific outcome. In practice, this means a case-by-case analysis of the specific business model, rather than adopting a uniform classification for all types of loot boxes .</p>



<p>This approach is also reflected in the practice of many European countries. Both administrative bodies and courts are increasingly moving away from abstract assessments of the lootbox mechanism itself, focusing instead on analyzing their actual operation and impact on consumer interests. Consequently, the current legal debate no longer revolves around the question of whether lootboxes as a category should be considered gambling, but rather which monetization models justify their inclusion in a specific regulatory regime.</p>



<h2 class="wp-block-heading has-pale-cyan-blue-background-color has-background"><strong>Loot boxes and the definition of gambling in Polish law</strong></h2>



<p>Assessing the compliance of lootbox mechanisms with Polish law requires, above all, an analysis of the provisions of the Gambling Act of 19 November 2009. Although the legislature has not yet decided to introduce a separate definition of lootboxes, this does not mean that these mechanisms remain outside the scope of applicable regulations. On the contrary, in practice, their legal classification depends on whether the specific operating model meets the criteria for one of the games specified in the Act.</p>



<p>The basic premise of the Gambling Act is to subject activities in which the outcome depends on chance to a specific regime, and the participant gains the opportunity to obtain a specific financial or material benefit. The Act does not use the term &#8220;lootbox&#8221; because it was enacted at a time when modern computer game monetization models were practically nonexistent. This necessitates a functional interpretation, taking into account the economic nature of the mechanism in question, not just its name or the technical solutions adopted by the game developer.</p>



<p>A key element of most loot boxes is undoubtedly randomness. The user making the purchase neither knows the contents of the package nor has the ability to influence the outcome of the drawing. However, the mere presence of a random element is not sufficient to classify a given mechanism as gambling. In practice, the nature of the prize received by the participant and the ability to assign it a real economic value are equally important.</p>



<p>This is where a fundamental difference between classic loot boxes offered by game developers and the mechanisms used by third-party platforms for trading virtual items becomes apparent. If the item obtained through a draw has a purely aesthetic function and cannot be legally exchanged for cash or used outside of the game environment, the arguments for classifying such a mechanism as gambling are significantly weaker. The situation is different when the item is de facto a property that can be freely traded on the secondary market, yielding a real financial benefit.</p>



<p>In practice, the greatest controversy surrounds so-called <em>skin gambling</em>. In this model, users use items obtained in-game as a means of participating in subsequent games of chance organized by third parties. Skins, which were originally purely cosmetic, are beginning to function as a kind of digital currency with measurable economic value. This mechanism leads to a situation in which participants risk losing items of real-world value in exchange for the opportunity to win an even more valuable reward. This structure bears a much greater resemblance to classic gambling games than the traditional <strong>micropayment systems used by game developers.</strong></p>



<p>At the same time, caution should be exercised before drawing too far-reaching conclusions. The mere existence of a secondary market does not automatically mean that every loot box should be classified as gambling. From a legal perspective, a case-by-case analysis of the entire business model is necessary, including, among other things, the method of acquiring virtual items, the possibility of their resale, the role of the game producer, the scope of control over the trade in digital assets, and the actual economic significance of the rewards. Consequently, two mechanisms utilizing an identical element of randomness may be subject to entirely different legal assessments.</p>



<p>This position is also reflected in the practice of <strong>Polish administrative bodies</strong>. To date, there has been no established practice of automatically classifying all loot boxes as gambling. Authorities focus instead on analyzing specific business models and assessing whether they meet the requirements of applicable regulations. This approach reflects the nature of the Gambling Act, which uses functional definitions, leaving authorities considerable scope for assessing individual factual circumstances.</p>



<p>In this context, the practice of entering certain online platforms into<strong> the Register of Domains Used to Offer Gambling Games</strong> <strong>in Contravention of the Act</strong> has become particularly significant. However, such an entry does not mean that all platforms utilizing the element of randomness conduct illegal activities. Each decision is preceded by an assessment of the specific operational model of the given service. Consequently, it cannot be assumed that the lootbox mechanism itself has been deemed illegal in Poland. It is not the abstract technical structure that is being assessed, but rather its practical application.</p>



<p>Under current law, it seems more appropriate to ask not whether loot boxes per se constitute gambling, but which of their numerous operating models demonstrate characteristics that justify the application of the provisions of the Gambling Act. This approach avoids oversimplification and better reflects the reality of the digital market, where solutions with widely varying levels of risk to consumers coexist.</p>



<p>At the same time, it should be noted that even if a given mechanism does not meet the criteria for gambling within the meaning of the Act, this does not mean there is a lack of legal oversight. Modern regulations increasingly refer to consumer protection instruments, counteracting manipulative practices, and ensuring the safety of children using digital services. Therefore, analysis of loot boxes cannot be limited solely to gambling law. Regulations regarding consumer protection, digital services, and designing interfaces in accordance with fair trading principles are gaining increasing importance, and in many cases, they may prove to be a more effective tool for protecting users than traditional gambling law instruments.</p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>Loot boxes as a challenge to consumer protection law and the regulation of digital services</strong></p>



<p>Although the debate surrounding loot boxes has for many years focused primarily on gambling law, a shift in regulatory direction is now becoming increasingly apparent, both at the national and European Union levels. Contemporary challenges related to random mechanisms in computer games concern not only the classification of specific models as gambling, but also the compliance of the practices employed with the principles of consumer protection, the protection of minors, and the fair design of digital services.</p>



<p>This change is primarily due to the development of the digital economy. The mechanisms used by game producers are increasingly based not on traditional product sales, but on long-term user engagement and gradual increase in spending through appropriately designed psychological solutions. This phenomenon is referred to in the literature as <em>behavioral monetization</em>, or monetization that leverages knowledge from cognitive psychology and behavioral economics. The goal of such mechanisms is not simply to facilitate a purchase, but to create an environment that encourages users to make subsequent purchasing decisions impulsively or emotionally.</p>



<p>Of particular importance in this regard are so-called <em>dark patterns</em>, <strong>referred to in Polish literature as manipulative or deceptive design patterns</strong>. These design solutions exploit the workings of human perception and decision-making processes to induce behaviors that are beneficial to the entrepreneur, but not necessarily aligned with the consumer&#8217;s true interests. In the case of loot boxes, these can take a variety of forms – from counters counting down the time until the end of a promotion, through messages about the limited availability of specific rewards, to elaborate animations that enhance the emotional experience of opening the packages.</p>



<p>These mechanisms are not coincidental. Psychological research indicates that a reward system based on a <strong>variable ratio reinforcement</strong> schedule is one of the most effective ways to maintain long-term user engagement. This same mechanism has been used for many years in classic gambling games, where the unpredictability of rewards maintains a high level of motivation for subsequent attempts. In the case of loot boxes, this mechanism is transferred to the computer gaming environment and combined with an attractive audiovisual setting and the ability to immediately make another purchase.</p>



<p>From the perspective of <strong>consumer protection law</strong>, a crucial question is whether the use of such solutions could lead to a violation of traders&#8217; obligations arising from provisions on fair market practices. It should be noted that contemporary EU regulations increasingly place greater emphasis not only on the content of information provided to consumers, but also on the design of digital interfaces. Therefore, the subject of assessment is increasingly not the product or service itself, but rather the architecture of the purchasing process and the impact of the interface on the user&#8217;s freedom of decision-making.</p>



<p>Underage users are particularly important here. Both the European Commission and the European Parliament have repeatedly stated that children using digital services require a higher level of protection than the average consumer. This stems from their limited ability to assess economic risk and their greater susceptibility to persuasive techniques used by businesses. In practice, this means that solutions acceptable to adult users may be deemed disproportionate or unfair if they are primarily targeted at children and adolescents.</p>



<p>The importance of this issue has increased following the entry into force of <strong>Regulation (EU) 2022/2065 on the Digital Single Market (Digital Services Act – DSA)</strong>. Although this act does not explicitly regulate lootbox mechanisms, <strong>it establishes a number of obligations regarding the design of digital services</strong> and the protection of users from practices that may negatively impact their decision-making autonomy. In particular, the DSA emphasizes the need to ensure a high level of protection for minors and limit the use of solutions that exploit the vulnerabilities of specific user groups. This trend indicates that future assessments of the legality of lootboxes will increasingly be conducted not only through the lens of gambling law but also taking into account consumer protection standards applicable in the digital environment.</p>



<p>In parallel, the European Commission is working on a legislative package known as <strong>Digital Fairness</strong>, which aims to adapt EU consumer protection regulations to the realities of the digital economy. Issues under review include manipulative design patterns, interface design that exploits user vulnerability, and mechanisms that exert excessive psychological pressure during purchasing decisions. Although the legislative work has not yet been completed, the direction of the proposed changes clearly indicates that future regulations may also cover monetization mechanisms used in video games.</p>



<p>The European Parliament also highlighted the need to enhance the protection of minors in its resolution of 26 November 2025 on the protection of children online. The document indicated that mechanisms such as loot boxes, in-game currencies, and other systems based on chance should be subject to special scrutiny from the perspective of protecting children from addictive and manipulative digital practices. While the resolution is non-binding, it provides an important political signal indicating the direction of future legislative action at the European Union level.</p>



<p>A separate but crucial element of the modern user protection system is the <strong>PEGI age rating</strong>. Starting in 2026, this system will adopt a more stringent approach to games featuring paid random mechanisms, recognizing them as solutions requiring a higher age rating. While the PEGI rating is not a source of law and does not in itself determine the legality of specific monetization models, it reflects a growing consensus on the need to provide greater protection for minors from mechanisms that utilize randomness and behavioral design techniques.</p>



<p>The above circumstances lead to the conclusion that the future of loot box regulation will likely be shaped primarily by regulations concerning consumer protection and digital services, rather than solely by traditional gambling law instruments. While the Gambling Act focuses on the qualification of specific business models, contemporary EU regulations increasingly assess the design of digital services and their impact on the autonomy of user decisions. Consequently, assessing the legality of loot boxes in the future will require comprehensive consideration of both gambling law and regulations concerning consumer protection, digital services, and children&#8217;s rights.</p>



<h3 class="wp-block-heading"><strong>Approach of selected European countries to regulating loot boxes – a comparative analysis</strong></h3>



<p>The lack of a uniform definition of loot boxes in European Union law has led individual member states to develop different models for regulating this phenomenon. These differences concern not only the legal classification of random-based mechanisms but, above all, the assessment of the risks loot boxes pose to consumers, especially minors. As a result, the European Union currently boasts both countries adopting a very restrictive approach and jurisdictions that prefer to analyze individual business models rather than create separate statutory regulations.</p>



<p>Belgium has taken the most stringent stance for many years. The Belgian Gaming Commission <em>has determined that </em>certain lootbox mechanisms meet the criteria for gambling if the participant pays a fee, the outcome depends on chance, and the reward represents a specific economic value. Consequently, some game producers have decided to remove paid lootboxes from the Belgian market or significantly limit their functionality. This solution was primarily preventative in nature and aimed at limiting children and adolescents&#8217; exposure to mechanisms that utilize randomness as a monetization tool .</p>



<p>The Dutch experience was different. For many years, the Dutch supervisory authority took a similar stance to the Belgian one, deeming certain lootbox models to be in violation of gambling regulations. The dispute concerned one of the most popular monetization models used by Electronic Arts became the subject of years of administrative and court proceedings. However, the final rulings demonstrated that the classification of loot boxes cannot be based solely on the presence of an element of randomness, but requires consideration of the overall economic structure of the game, the method of trading virtual goods, and the actual potential for financial gain for the user. The Dutch experience thus highlighted the difficulties associated with applying traditional definitions of gambling law to new business models operating in the digital economy.</p>



<p>At the opposite extreme is the approach adopted <strong>in Poland. To date, Polish lawmakers have not decided to create separate regulations regarding loot boxes or introduce a statutory definition</strong>. This means that the assessment of individual models is based on applicable gambling regulations and an analysis of the specific factual circumstances. This approach provides administrative bodies with significant interpretative flexibility, but also limits predictability for businesses operating in the digital market.</p>



<p>The practice of Polish authorities indicates that a functional assessment of the specific business model is crucial. In the case of platforms enabling the use of virtual items as a means of participating in games of chance, authorities may apply the instruments provided for in the Gambling Act, including entry into the Register of Domains Used to Offer Gambling Games Contrary to the Act. However, this does not automatically mean that all loot boxes used in computer games are illegal. The Polish model is therefore based on an analysis of the economic impact of a given solution, not on an abstract assessment of the randomness mechanism itself.</p>



<p>An analysis of the solutions adopted in individual countries leads to the conclusion that what is becoming increasingly important is not simply classifying loot boxes as gambling, but rather protecting consumers from the psychological mechanisms that lead to excessive spending or compulsive behavior. Therefore, many countries are beginning to perceive the loot box problem as an issue that goes beyond traditional gambling law and requires the use of instruments appropriate to consumer law and digital market regulation.</p>



<p>This approach also aligns with actions undertaken at the European Union level. The European Commission and the European Parliament increasingly point out that the fragmentation of national regulatory models can lead to uneven levels of user protection in the digital single market. The global nature of game producers&#8217; operations means that businesses operate simultaneously in multiple markets, adapting their business models to the most stringent requirements in force in individual countries. In practice, this means that future legal solutions will likely aim for greater harmonization of consumer protection standards at the EU level.</p>



<p>However, this doesn&#8217;t mean a complete ban on loot boxes is necessary. A much more likely approach would be to introduce requirements regarding the transparency of random mechanisms, the publication of actual reward probabilities, more effective age verification of users, and restrictions on the use of solutions that exploit the vulnerability of children and adolescents to persuasive techniques. Such a regulatory model would preserve the possibility of using micropayments as a legal method of financing computer games while simultaneously strengthening consumer protection.</p>



<p>From the perspective of Polish law, the experiences of other European countries have significant interpretative significance. They demonstrate that mechanisms operating at the intersection of gambling and digital services cannot be assessed solely through the lens of classic legal constructs developed for traditional casinos or lotteries. The development of the digital economy requires a more comprehensive approach, taking into account both the economic significance of virtual goods and the impact of interface design on consumer decisions. Consequently, the future model for regulating loot boxes will likely be based on a combination of instruments from gambling law, consumer protection law, and regulations governing digital services, rather than the exclusive application of one of these legal regimes.</p>



<h2 class="wp-block-heading"><strong>Conclusions <em>de lege lata </em>and postulates <em>de lege ferenda</em></strong></h2>



<p>The analysis leads to the conclusion that current Polish law does not allow for a uniform legal classification of all lootbox mechanisms. Despite the growing number of voices calling for the recognition of lootboxes as a form of gambling, the current legal status does not provide a basis for automatically subjecting this entire product category to the provisions of the Gambling Act of 19 November 2009. Each assessment requires consideration of the actual operation of the specific business model, the nature of the prize, the potential for further turnover, and the economic impact of user participation in the random mechanism.</p>



<p>This doesn&#8217;t mean, however, that the current regulations remain entirely insufficient. With respect to some models operating on the market &#8211; particularly platforms that use virtual items as a means of participating in games of chance or enabling their exchange for cash &#8211; current regulations may be applicable. The practice of administrative bodies to date demonstrates that the Gambling Act remains an instrument that helps counteract the riskiest forms of activity, especially when virtual goods begin to function as an equivalent of money or property.</p>



<p>At the same time, it&#8217;s important to note that the vast majority of modern loot boxes don&#8217;t pose a classic gambling law problem. Their primary purpose isn&#8217;t to organize games of chance in the traditional sense, but to create a monetization model that leverages psychological mechanisms that increase user propensity to make subsequent purchases. For this reason, the current regulatory debate is increasingly shifting from gambling law toward consumer protection law and the regulation of digital services.</p>



<p>It seems that this is precisely the direction that Polish lawmakers should also adopt. Attempting to classify all loot boxes as gambling would oversimplify the extremely diverse digital market. A much more rational solution seems to be creating separate regulatory obligations for mechanisms that utilize randomness, without the need for automatic application of the entire gambling law regime.</p>



<p>First and foremost, it seems reasonable to introduce full transparency into random mechanisms. Before making a purchase, users should be able to familiarize themselves with the actual probability of winning individual prizes, how the randomization algorithm works, and whether this probability remains constant for all participants. Such solutions already exist in some computer games, but currently they are primarily driven by voluntary decisions by businesses or requirements in specific foreign markets.</p>



<p>The second direction of change should be to strengthen the protection of underage users. In light of current psychological knowledge and the positions of EU institutions, there is little doubt that children are particularly susceptible to the influence of mechanisms based on a variable reward system. Therefore, it seems reasonable to consider limiting the ability of people under a certain age to purchase paid loot boxes or introducing mandatory parental control mechanisms to effectively manage minors&#8217; expenses.</p>



<p>Regardless of the above, legislators should consider introducing more detailed regulations regarding third-party platforms enabling the trading of virtual items. It is this market segment that currently raises the greatest concerns from the perspective of consumer protection and compliance with the Gambling Act. In particular, situations in which items obtained in-game become a means of participation in subsequent games of chance or can be directly converted into cash require analysis. In such cases, the line between a digital service and gambling activity becomes significantly blurred, justifying the application of more restrictive oversight measures.</p>



<p>Obligations regarding marketing activities should also be a crucial element of future regulations. In practice, loot boxes are primarily promoted through influencers and online creators, whose audiences often include minors. While advertising collaborations in and of themselves cannot be deemed unacceptable, situations in which marketing messages exclusively emphasize the possibility of winning exceptionally valuable prizes, disregarding the actual probability of winning them, or employing techniques that could create unreasonable expectations among recipients regarding potential benefits, require special consideration. In this regard, both consumer protection regulations and regulations regarding the integrity of advertising messages may apply.</p>



<p>The issues presented demonstrate that the issue of loot boxes is not limited to gambling law. In fact, it exemplifies a much broader phenomenon involving the use of advanced digital design techniques to influence users&#8217; economic decisions. Technological advancements increasingly render traditional private and public law frameworks inadequate for assessing new business models based on user behavior analysis and interface design that maximizes consumer engagement and spending.</p>



<p>Consequently, the future of loot box regulation will likely depend less on further expansion of the definition of gambling than on the development of European consumer protection standards in the digital environment. Regulations on the transparency of digital services, countering manipulative design patterns, and ensuring a high level of protection for children using the internet are becoming increasingly important . These instruments may become the primary tool for mitigating the risks associated with loot box operations in the coming years.</p>



<p>It should therefore be assumed that effective regulation of this phenomenon requires a multifaceted approach, combining instruments of gambling law, consumer protection law, and digital market regulation. Only such a comprehensive solution will achieve the right balance between the freedom of game producers to conduct business and the need to ensure a high level of protection for users, particularly children and adolescents, who remain most vulnerable to the negative effects of random-based mechanisms.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/">Lootboxes in Computer Games – Between Gambling Law and Consumer Protection. Regulatory Analysis Against the Background of Polish and European Union Law.</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
