<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI Act - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/ai-act/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/ai-act/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 24 Jul 2026 15:15:26 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 10:31:49 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Lawyer Europe]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[CADA]]></category>
		<category><![CDATA[Cloud and AI Development Act]]></category>
		<category><![CDATA[Cloud Compliance]]></category>
		<category><![CDATA[Cloud Computing Law]]></category>
		<category><![CDATA[Cloud Computing Lawyer]]></category>
		<category><![CDATA[Cross-Border Legal Services]]></category>
		<category><![CDATA[Cybersecurity Law]]></category>
		<category><![CDATA[Data Act]]></category>
		<category><![CDATA[Data Governance Act]]></category>
		<category><![CDATA[Data Protection Law]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Sovereignty]]></category>
		<category><![CDATA[EU Cloud Regulation]]></category>
		<category><![CDATA[EU Regulatory Law]]></category>
		<category><![CDATA[EU Technology Law]]></category>
		<category><![CDATA[European Tech Regulation]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[Kiełtyka Gładkowski KG Legal]]></category>
		<category><![CDATA[public procurement law]]></category>
		<category><![CDATA[Sovereign Cloud]]></category>
		<category><![CDATA[Technology Law Firm]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8827</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 I. Introduction On June 3, 2026, the European Commission adopted a proposal for the Cloud and AI Development Act (hereinafter: CADA or the draft), which is the centerpiece of the broader European Technological Sovereignty Package. This draft seeks to translate the political concept of digital sovereignty into binding legal standards [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/">NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 10, 2026</strong></mark></p>



<h2 class="wp-block-heading">I. Introduction</h2>



<p>On June 3, 2026, the European Commission adopted a proposal for the Cloud and AI Development Act (hereinafter: CADA or the draft), which is the centerpiece of the broader European Technological Sovereignty Package. This draft seeks to translate the political concept of digital sovereignty into binding legal standards governing public procurement, the certification of cloud computing providers, and artificial intelligence infrastructure.</p>



<span id="more-8827"></span>



<p>CADA focuses on 3 goals:</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 1 &#8211; Research and Innovation: Support for next-generation technologies, frontier, industrial and physical AI; introduction of &#8220;grand challenges&#8221;; implementation of Experience and Acceleration Centres for AI.</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 2 &#8211; Capacity: target to triple EU data centre capacity within 5-7 years; simplify and speed up construction permitting.</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 3 &#8211; autonomy (core of regulation): a single EU framework for assessing cloud and AI sovereignty, a public sector adoption mechanism; an open source-first principle; and a common public procurement framework.</p>



<p>CADA fits into the broader EU digital policy framework, which includes the AI Act, Data Act, Data Governance Act, Digital Markets Act (DMA) and Digital Services Act (DSA), as well as soft law initiatives such as Gaia-X and the 2020 European Data Strategy. CADA takes a coordinated “ecosystem approach” as it combines supply-side actions to strengthen national capabilities, demand-side actions to drive deployment, and enablers for innovation and investment in cloud computing and AI.</p>



<p>“This initiative will connect networks, cloud, artificial intelligence, and software into cohesive ecosystems to address the following:</p>



<p>(1) future challenges related to energy-efficient computing infrastructure;</p>



<p>(2) autonomy across the entire cloud stack;</p>



<p>(3) advanced EU capabilities in advanced AI technologies, such as frontier AI, physical AI and industrial AI;</p>



<p>(4) implementing cloud and artificial intelligence in the public and private sectors.”</p>



<h1 class="wp-block-heading">II. The concept of digital sovereignty and the &#8220;sovereign cloud&#8221; in EU documents</h1>



<h2 class="wp-block-heading">1. Origin of the concept</h2>



<p>The concept of digital sovereignty (technological sovereignty) entered the vocabulary of the European Commission and the Council of the EU around 2020-2021 as a reaction to three phenomena: (1) the ongoing consolidation of the global cloud market in the hands of hyperscalers from the United States. à&#8221;The current situation in the cloud computing and artificial intelligence sector is characterized by a clear dependence on a limited group of third-country providers. Although the EU cloud computing market is growing significantly, the share of EU providers fell from 29% in 2017 to 15% in 2022 and has remained unchanged since then. Currently, three non-EU cloud computing providers control over 70% of the European cloud computing market&#8230; This dependency also exposes European users to the risk of disruptions, especially in situations where unilateral decisions by third-country entities could disrupt service provision.”</p>



<p>(2) legal risks related to the extraterritorial application of the US CLOUD Act of 2018, which allows US authorities to access data stored by US-based companies regardless of the location of the servers, and</p>



<p>(3) the CJEU judgments in Schrems I (2015) and Schrems II (2020), questioning the legal basis for transatlantic transfers of personal data. The Court of Justice of the EU (CJEU) invalidated the <em>Privacy Shield Agreement</em>, finding that US regulations did not guarantee EU citizens adequate protection of their personal data against surveillance. This forced the processing of sensitive data in Europe.</p>



<p>The Gaia-X initiative, launched in 2019 by Germany and France, was the first attempt to operationalize cloud sovereignty. The project&#8217;s main goals are:</p>



<ul class="wp-block-list">
<li>reducing Europe&#8217;s dependence on American and Chinese cloud providers (such as AWS, Google Cloud, Azure, Alibaba)</li>



<li>Gaia-X does not build its own cloud, but creates rules, standards and trust mechanisms that allow different providers (small and large) to offer interoperable, compatible services.</li>



<li>companies and institutions must maintain control over where and how their data is stored and processed, in accordance with European regulations (e.g. GDPR)</li>



<li>common certification rules, trust labels (&#8220;Gaia-X Trust Framework&#8221;) and open API</li>
</ul>



<p>However, the project was criticized for its slow pace and the influence of large American technology companies, which raised doubts about the sovereign nature of the undertaking.</p>



<h2 class="wp-block-heading">&nbsp;</h2>



<h2 class="wp-block-heading">2. Components of digital sovereignty according to the CADA project</h2>



<p>The CADA project does not have a single, closed dictionary definition of &#8220;cloud/digital sovereignty.&#8221; Instead, the project develops the concept through a system of levels and assessment criteria.</p>



<p><strong>Recital 51 of the Preamble</strong><strong>à</strong><strong> </strong>&#8220;it is necessary to establish a Union cloud computing sovereignty framework determining criteria for trusted cloud computing services. To cater for the <strong>nuanced and layered nature of sovereignty</strong>, the framework should provide for four different levels of trusted offers (&#8216;Union assurance levels&#8217;).&#8221;</p>



<p><strong>Recital 50 of the Preamble</strong><strong>à</strong><strong> </strong>“The Union and Member States being critically dependent on a limited number of cloud computing service providers subject to the control of a third country or a legal entity established in a third-country may lead to risks such as misuse (ie manipulation, remote access and control, sabotage, weaponization), access to information (ie access to sensitive information, unauthorized communication, technology leakage, data manipulation or exfiltration, espionage) and dependency vulnerabilities (ie political and/or economic coercion, for example by using vendor or technology lock-ins, embargos or sanctions, monopoly pricing damaging the financial interest of the Union and Member States).” – risks to sovereignty</p>



<p><strong>Article 16</strong><strong>à</strong><strong> </strong>&#8220;This Chapter establishes a Union cloud computing sovereignty framework comprising four Union assurance levels, the criteria for which are set out in Annex II, that cloud computing service providers shall meet in order to provide their cloud computing services to Union entities and public sector bodies&#8221;</p>



<p><strong>Annex II</strong><strong>à</strong><strong> </strong>contains four cumulative sets of technical, legal and organisational criteria. &#8220;Software&#8221; within the meaning of the Annex includes Regulation 2024/2847 (Cyber Resilience Act). CADA in Annex II defines sovereignty in the field of cloud computing and artificial intelligence, comprising four levels of guarantees that public sector bodies will benefit from based on their risk assessments. Cloud service providers can be recognised by Member States under this framework after passing an audit. The Commission retains the competence to issue implementing acts identifying third countries whose providers would be subject to audits under the above system.</p>



<p>Level 1 (Basic) &#8211; &nbsp;pt. 1</p>



<p>The lowest threshold, covering all public sector services:</p>



<ul class="wp-block-list">
<li>supplier&#8217;s registered office in the EU; infrastructure and assets in the EU (unless the customer expressly agrees otherwise);</li>



<li>customer data (including metadata, telemetry) remains exclusively within the EU, unless a public authority decides otherwise;</li>



<li>when outsourcing technical support outside the EU, the requirement of traceability and safeguards that do not undermine operational autonomy;</li>



<li>compliance with current cybersecurity standards;</li>



<li>full transparency regarding subcontractors;</li>



<li>if the supplier is controlled by an entity from a third country – a guarantee of no obligation to report security vulnerabilities to the authorities of that country before their disclosure.</li>
</ul>



<p>Level 2 (Standard) &#8211; point 2</p>



<p>It requires an audit (not just a declaration) and adds:</p>



<ul class="wp-block-list">
<li>mandatory location of infrastructure, assets and personnel in the EU;</li>



<li>the possibility of requesting EU citizenship of staff (at the client&#8217;s request);</li>



<li>cybersecurity certificate of at least &#8220;substantial&#8221; level (EUCS or national equivalent);</li>



<li>prohibition on using customer data to train AI models operated by a third-country entity;</li>



<li>if the supplier is subject to third-country control – requirement to demonstrate safeguards against: limiting the ability to provide the service, access to data, disruption of service continuity, enforcement of sanctions/embargoes;</li>



<li>technical support only from the EU;</li>



<li>transparency of the software supply chain (SBOM &#8211; Software Bill of Materials), control of components from third-country suppliers, source code audit;</li>



<li>legal and technical separation between the EU parent company and the subsidiary in a third country.</li>
</ul>



<p>Level 3 (Enhanced) &#8211; point 3</p>



<p>Adds important refinements:</p>



<ul class="wp-block-list">
<li>staff must be EU citizens and, when handling classified information, have a national security clearance;</li>



<li>&#8220;substantial&#8221; cybersecurity certificate;</li>



<li>as a rule, a ban on control by a third-country entity – except where the Commission issues an implementing act under Article 19 authorising such a supplier (in which case additional safeguards apply, including &#8220;reasonable access to the code&#8221;);</li>



<li>technical support provided exclusively by EU residents and entities not subject to third-country control.</li>
</ul>



<p>Level 4 (Sovereign) &#8211; point 4</p>



<p>Highest, most restrictive threshold:</p>



<ul class="wp-block-list">
<li>complete lack of control by a third country entity (without any exception authorised by the Commission, as opposed to Level 3);</li>



<li>cybersecurity certificate at least &#8220;high&#8221;;</li>



<li>staff – EU citizens with appropriate security clearances;</li>



<li>for software components: requirement of effective control over design, development and maintenance &#8211; no third-country entity may have the ability to materially influence the technical development, maintenance priorities or continuity of the component</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Level</strong></td><td><strong>Name</strong></td><td><strong>Key criterion</strong></td><td><strong>Accessibility for non-EU entities</strong></td></tr></thead><tbody><tr><td>1</td><td>Basic Date of residency</td><td>Data localization in the EU, GDPR</td><td>Accessible &#8211; meeting basic data protection requirements</td></tr><tr><td>2</td><td>Standard Supply-chain independence</td><td>EUCS certification, operational independence</td><td>Conditionally available &#8211; requires ENISA/EUCS certification</td></tr><tr><td>3</td><td>Enhanced EU ownership &amp; control</td><td>Supply chain control, no non-EU law</td><td>Limited &#8211; Commission recognition required; US CLOUD Act disqualifies</td></tr><tr><td>4</td><td>Sovereign Defence-grade</td><td>Full transparency, technical autonomy, EU ownership</td><td>Essentially unavailable to non-EU hyperscalers without restructuring</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">III. EU Cloud Sovereignty Framework</h2>



<p>The EU Cloud Sovereignty Framework is also a key document defining the &#8220;sovereign cloud.&#8221; This document <strong>is not part of the CADA regulation itself</strong>, but a separate DG DIGIT methodological tool used in specific procurement procedures. Compared to the four-level <strong>Union Assurance Levels scale </strong>in CADA Annex II (levels 1–4, based on cumulative binary criteria—pass/fail), the SEAL framework is more detailed. According to it, digital sovereignty consists of eight elements.</p>



<p><strong>Eight Components of Digital Sovereignty (SOV-1 to SOV-8)</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>#</strong></td><td><strong>Component</strong></td><td></td></tr></thead><tbody><tr><td><strong>SOV-1</strong></td><td><strong>Strategic sovereignty</strong></td><td>The supplier&#8217;s embeddedness in the EU legal, financial and industrial ecosystem – ownership stability, influence on governance, compliance with EU strategic priorities</td></tr><tr><td><strong>SOV-2</strong></td><td><strong>Legal and jurisdictional sovereignty</strong></td><td>The legal environment of the service, exposure to foreign authorities, the possibility of pursuing rights in EU jurisdiction – including resistance to extraterritorial acts such as <strong>the US CLOUD Act </strong>or the Chinese cybersecurity law</td></tr><tr><td><strong>SOV-3</strong></td><td><strong>Data Sovereignty and AI</strong></td><td>Protection, control, and independence of data resources and AI services – where data is processed and what degree of autonomy the customer retains over AI capabilities</td></tr><tr><td><strong>SOV-4</strong></td><td><strong>Operational sovereignty</strong></td><td>Practical ability of EU entities to independently conduct, support and develop technologies without dependence on foreign control &#8211; business continuity, availability of competences</td></tr><tr><td><strong>SOV-5</strong></td><td><strong>Supply chain sovereignty</strong></td><td>Geographical origin, transparency and resilience of the technology supply chain – the extent to which key components remain under EU control</td></tr><tr><td><strong>SOV-6</strong></td><td><strong>Technological sovereignty</strong></td><td>The degree of openness, transparency and independence of the technology stack – the ability to interoperate, audit and develop solutions without dependence on closed systems from third-party vendors</td></tr><tr><td><strong>SOV-7</strong></td><td><strong>Security and Compliance Sovereignty</strong></td><td>The extent to which security operations, compliance obligations and resilience activities remain controlled within the EU – independence from foreign jurisdictions</td></tr><tr><td><strong>SOV-8</strong></td><td><strong>Environmental sustainability</strong></td><td>Long-term autonomy and resilience of cloud services in the context of energy consumption, resource dependencies, and material scarcity</td></tr></tbody></table></figure>



<p><strong>Rating scale: Sovereignty Effectiveness Assurance Levels (SEAL)</strong></p>



<p>Independently of the eight components, the document introduces <strong>a five-level maturity scale </strong>(SEAL-0 to SEAL-4) used to assess each of the eight objectives separately:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Level</strong></td><td><strong>Name</strong></td><td><strong>Description</strong></td></tr></thead><tbody><tr><td><strong>SEAL-0</strong></td><td>Lack of sovereignty</td><td>A service entirely controlled by a non-EU entity, managed in a foreign jurisdiction</td></tr><tr><td><strong>SEAL-1</strong></td><td>Jurisdictional sovereignty</td><td>EU law formally applies but has limited enforceability; exclusive control by a non-EU entity</td></tr><tr><td><strong>SEAL-2</strong></td><td>Data sovereignty</td><td>EU law is in force and enforceable, but significant dependencies on non-EU entities remain; indirect control</td></tr><tr><td><strong>SEAL-3</strong></td><td>Digital resilience</td><td>EU law fully enforceable, EU entities have significant but limited influence; non-EU entities have marginal control</td></tr><tr><td><strong>SEAL-4</strong></td><td>Full digital sovereignty</td><td>Technology and operations entirely under EU control, subject only to EU law, with no critical dependencies from outside the EU</td></tr></tbody></table></figure>



<p><strong>Sovereignty Score</strong></p>



<p>The document also introduces <strong>percentage weightings </strong>for each of the eight components when calculating the aggregate sovereignty score in the tender process:</p>



<ul class="wp-block-list">
<li><strong>Supply Chain (SOV-5): 20% </strong>&#8211; Highest Weight</li>



<li><strong>Strategic sovereignty (SOV-1) and operational sovereignty (SOV-4): 15% each</strong></li>



<li><strong>Technological Sovereignty (SOV-6): 15%</strong></li>



<li><strong>Legal/Jurisdictional (SOV-2), Data/AI (SOV-3), Security (SOV-7): 10% each</strong></li>



<li><strong>Environmental Sustainability (SOV-8): 5% </strong>&#8211; Lowest Weight</li>
</ul>



<p>The lower weights for SOV-2 and SOV-7 were justified by the fact that these areas are already covered by separate procedural safeguards in the procurement procedure itself.</p>



<h2 class="wp-block-heading">IV. Impact of the CADA project on public procurement</h2>



<p>One of the central mechanisms of CADA is the common EU-level procurement framework.</p>



<p><strong>Recital 64 of the Preamble</strong><strong>à</strong><strong> </strong>The free flow of data within the EU is a prerequisite for the functioning of the internal market – data cannot be artificially limited to the territory of a single Member State. The EU pledges, in principle, open, non-discriminatory market access in accordance with the TFEU and international obligations (including the WTO GPA on Government Procurement).</p>



<p>However, the EU invokes Article III:2(a) of the WTO GPA, which allows for measures necessary to protect public order, public morality, or security. This justifies proportionate restrictions on access to public procurement based on the risk of critical dependencies, unauthorized access to EU data, technology leakage, sabotage, and espionage by third-country entities. Contracting entities whose activities are identified as relevant to public order are required to procure cloud services <strong>only at levels 2-4</strong>. At the same time, <strong>level 1 becomes the mandatory minimum for the entire </strong>EU public sector, providing a consistent baseline level of security.</p>



<p><strong>Motif 65</strong><strong>à</strong><strong> </strong>To reduce vendor dependency, EU entities and Member States should consider a multi-vendor/multi-cloud strategy in their procurement processes, based on a contextual risk assessment that takes into account operational, regulatory and resilience circumstances.</p>



<p><strong>Motif 66</strong><strong>à</strong><strong> </strong>Public procurement is treated as a directional signal for the entire market – requirements imposed on the public sector regarding levels of assurance tend to be imitated by the private sector in regulated industries. Article 31 allows private entities from sectors covered by Annex I of the NIS2 Directive to carry out similar assessments.</p>



<p><strong>Article 29 </strong><strong>à</strong>Member States and EU entities are required (annually or biannually) to carry out risk assessments that:</p>



<ul class="wp-block-list">
<li>identify public sector activities using cloud services in areas covered by Annexes I/II of the NIS2 Directive and in the spheres of national security, defence, justice and law enforcement;</li>



<li>determine which <strong>assurance level (Union assurance level 2, 3 or 4) </strong>is appropriate for a given activity.</li>
</ul>



<p>The Commission has the power to impose the methodology for this assessment by means of implementing acts and, if it considers the Member State&#8217;s assessment to be inadequate, to determine the required level itself (Article 29(5)).</p>



<p><strong>Article 30</strong><strong>à</strong><strong></strong></p>



<p><strong>Paragraph 2: </strong>entities whose activities are <strong>not </strong>classified as important for public order must use at least <strong>level 1 cloud services</strong>.</p>



<p><strong>Paragraph 3: </strong>contracting entities whose activities <strong>have been </strong>so qualified (NIS2, national security, defence, justice sectors) <strong>may only procure </strong>cloud services classified as <strong>level 2, 3 or 4 </strong>.</p>



<p><strong>Paragraph 4: </strong>allows for derogations in exceptional, justified cases (lack of available services on the market, lack of offers in the previous procedure, grossly disproportionate cost).</p>



<p><strong>Art. 32 </strong><strong>à</strong>In procurement procedures for innovative cloud services and AI systems, contracting authorities must take into account <strong>non-price criteria for the evaluation of offers </strong>, including:</p>



<ul class="wp-block-list">
<li>the contractor&#8217;s contribution to strengthening the EU digital technology supply chain,</li>



<li>the use of technologies developed in the EU (including the results of EU R&amp;D programmes),</li>



<li>providing the service using hardware components designed/manufactured in the EU.</li>
</ul>



<p><strong>Recital 67 </strong>clarifies that this criterion <strong>cannot be decisive </strong>and suggests an indicative maximum weighting of <strong>15 points out of 120 </strong>in the tender evaluation methodology – it is intended to be subsidiary to the technical and financial criteria.</p>



<p><strong>Article 33</strong><strong>à</strong><strong> </strong>Member States are to aim to ensure that at least 25% of procurement for cloud services and AI systems goes to innovative SMEs, and report annual data on SME participation in procurement to the Commission.</p>



<h1 class="wp-block-heading">V. Relationship of the CADA project with existing EU legal acts</h1>



<h2 class="wp-block-heading">1. AI Act (Regulation 2024/1689)</h2>



<p>The AI Act governs the security and fundamental rights of AI systems; the CADA governs the sovereignty of the infrastructure that supports these systems.</p>



<p>Art. 2 point 3 of CADA <strong>does not create its own definition </strong>of an AI system, but refers directly to the AI Act à&#8221;&#8216;AI system&#8217; means an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689&#8243;</p>



<p><strong>Explanatory memorandum</strong><strong>à</strong><strong> </strong>&#8220;The proposal also reinforces key objectives of the AI Act. The AI Act harmonises rules for AI systems and general-purpose AI models to be placed on the EU market, improving the functioning of the internal market and promoting the uptake of human-centric and trustworthy AI along the value chain. The AI Act ensures a high level of protection of health, safety and fundamental rights. It does not cover aspects of sovereignty.&#8221; &#8211; The Commission <strong>explicitly states that the AI Act does not cover the issue of sovereignty </strong>&#8211; this is the very gap that CADA aims to fill.</p>



<p>CADA entrusts the AI Board (the body established under the AI Act) with a coordinating role beyond its original mandate:</p>



<ul class="wp-block-list">
<li><strong>Motif 33</strong><strong>à</strong> <em>&#8220;As cloud computing underpins and enables AI, the AI Board should serve as a platform to facilitate cooperation and coordination of AI adoption-related activities between the Union and the Member States.&#8221;</em></li>



<li><strong>Article 7(6) </strong>gives the AI Board a specific operational responsibility: to advise and support Member States in coordinating national cloud and AI strategies required by CADA, and to facilitate the exchange of good practices between Member States.</li>
</ul>



<p>This is an important institutional arrangement: CADA does not create a new, parallel body for AI issues, but extends the remit of the existing body from the AI Act to a new area (cloud as an infrastructure supporting AI).</p>



<h2 class="wp-block-heading">2. Data Act (Regulation 2023/2854)</h2>



<p>The Data Act, effective from September 2025, imposes obligations on cloud service providers to facilitate data portability and switching. CADA builds on this foundation by adding a dimension of sovereignty: it&#8217;s no longer just about data portability, but also about ensuring that data remains under the sole jurisdiction of the EU throughout its time in the cloud. The two acts create a complementary layer of protection: the Data Act allows for switching providers, and CADA establishes criteria for which alternative cloud services are considered sufficiently sovereign. Without CADA, the Data Act&#8217;s switching mechanism would be &#8220;blind&#8221; to the quality or sovereignty of the target provider.</p>



<p>&#8220;&#8221;The proposal is consistent with the rules on switching between data processing services introduced by the Data Act. By enabling switching and removing key sources of vendor lock-in, the Data Act seeks to ensure that cloud computing service providers in the EU compete on quality, innovation, and price. It seeks to enable cloud users to freely choose the provider that best meets their needs and combine offers of different providers in a multi-cloud approach.&#8221;</p>



<p><em>&#8220;However, the Data Act does not contain elements to shape up a more competitive offer of European cloud computing services or encourage the entry into the market of a more diverse set of cloud computing service providers.&#8221;</em></p>



<p><em>&#8220;The Data Act opens the path towards a possible reduction of dependencies on non-EU providers but does not build the road towards a more sovereign and trusted EU cloud computing sector. [&#8230;] <strong>The Data Act is thus an enabler for the proposal.</strong>&#8220;</em></p>



<h2 class="wp-block-heading">3. Data Governance Act (Regulation 2022/868)</h2>



<p>The Data Governance Act, effective from September 2023, establishes a framework for neutral data intermediaries and the reuse of public sector data. The CADA does not explicitly address the DGA in its text. However, it imposes sovereign certification requirements on the infrastructure storing this data, which in practice limits the range of providers deemed suitable for handling data covered by the DGA.</p>



<h2 class="wp-block-heading">4. Digital Markets Act</h2>



<p>The DMA, effective from May 2023, imposes obligations on gatekeepers, including interoperability requirements and prohibition of self-preferential services. CADA and DMA operate under different logics: DMA regulates market behavior ex ante, while CADA creates positive eligibility criteria for the public sector. There is a risk of conflict between the interoperability obligations with the DMA and the closed architectures required by the highest levels of CADA sovereignty.</p>



<h2 class="wp-block-heading">5. Digital Services Act and the general regulatory context</h2>



<p>The DSA, fully applicable since February 2024, governs the liability of online intermediaries. Although it does not directly address cloud infrastructure, it contributes to a regulatory climate characterized by high levels of EU intervention in the digital market and increasing assertiveness towards global technology providers.</p>



<p>&#8220;While certain providers of cloud computing services could be regulated under both this proposal and the DMA, <strong>the DMA has different objectives and does not contain measures that would actively promote the uptake of sovereign cloud computing services </strong>. The DMA only aims at maintaining and promoting a fair and contestable cloud market in the Union, regulating specific behaviors of companies designated as gatekeepers and <strong>thus intervenes at a different level than the proposal</strong>, which focuses on the uptake and use of the services provided.&#8221;</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td>Dimension</td><td>DMA</td><td>CADA</td></tr></thead><tbody><tr><td>The Logic of Intervention</td><td>Ex post / behavioral — corrects the market behavior of already dominated entities (gatekeepers)</td><td>Ex ante/structural &#8211; shapes demand and supply towards trusted/sovereign services</td></tr><tr><td>Subject of regulation</td><td>Fairness and contestability of the market</td><td>Uptake and utilization of sovereign services</td></tr><tr><td>Recipients</td><td>Only entities formally designated as gatekeepers</td><td>All cloud providers seeking certification at levels 1-4</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">VI. Arguments in favor of introducing CADA regulations</h1>



<ul class="wp-block-list">
<li><strong>Security and strategic independence: </strong>AWS, Microsoft Azure, and Google Cloud control approximately 70-80% of the EU cloud computing market. This concentration means that key EU administrative, banking, and healthcare systems are de jure accessible to US authorities under the US CLOUD Act (the CLOUD Act gives <strong>US law enforcement and intelligence agencies </strong>the right to demand access to data from US service providers (including cloud computing providers) <strong>&nbsp;&#8211; regardless of the physical location of the servers </strong>on which that data is stored.) &#8211; which EU authorities classify as a security risk. CADA will help mitigate this risk by introducing a complex system of vendor evaluation criteria.</li>



<li><strong>Risk of service interruption</strong><strong>à</strong><strong> </strong>&#8220;This dependence also exposes European users to the risks related to operational discontinuity, particularly in scenarios where unilateral decisions by third-country actors could disrupt service provision.&#8221;</li>



<li><strong>Critical loss of market position for European providers &#8211; </strong>&#8220;While the EU market for cloud computing services is growing significantly, the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.&#8221; CADA will help them regain their strategic position.</li>



<li><strong>Industrial and investment goal: </strong>The project assumes tripling the capacity of data centers in the EU within 5–7 years, which will significantly improve the efficiency and functionality of the AI system in the EU àtoday: &#8220;The EU&#8217;s limited data center capacity poses a significant threat to its ability to benefit from the digital transformation and adopt AI-driven solutions, notably those requiring low-latency compute capacity.&#8221; The lack of appropriate infrastructure also hinders the EU&#8217;s economic growth: &#8220;the lack of data center capacity in the EU forces European enterprises to route critical workloads through foreign hyperscaler infrastructure. This makes <strong>the EU a less attractive destination for tech investment </strong>than regions with more abundant, lower-cost compute resources.&#8221;</li>



<li><strong>Enabling the use of the EU&#8217;s own potential &#8211; </strong>&#8220;Europe has world-class research and development capabilities, vibrant open-source communities and a strong industrial base in cloud and AI, <strong>which however remain largely untapped.</strong>&#8220;</li>
</ul>



<h1 class="wp-block-heading">VII. Tensions with Single Market Principles and Competition Law</h1>



<p>The CADA project, whose legal basis is <strong>Article 114 and Article 173(3) TFEU </strong>(harmonisation of the internal market and strengthening of the EU’s industrial competitiveness), is consciously constructed by the Commission as a means of removing internal market barriers – the argument justifying the intervention is precisely the divergence of national sovereignty criteria and procurement practices, which hinders suppliers from operating freely between Member States.</p>



<p>Despite this declared harmonisation logic, the practical effect of the sovereignty criteria at levels 3-4 (complete lack of control by a third-country entity, EU citizenship of staff, location of the entire infrastructure in the EU) may in fact restrict the freedom to provide services by non-EU suppliers in the EU internal market. However, the Act itself does not explicitly address this potential tension with Article 56 TFEU – the Commission locates the justification for procurement restrictions not in primary EU law, but in the <strong>public policy exception in Article III:2(a) of the WTO GPA </strong>(recital 64), consistently using the category of &#8220;<strong>public order</strong>&#8221; as the substantive basis for the restrictions (recitals 49-53).</p>



<p>The question whether the criteria thus constructed – despite their declared technological neutrality – in fact constitute a measure having an effect equivalent to a quantitative restriction or infringe the principle of proportionality required for derogations from the internal market freedoms remains open and not determined by the text of the act itself – this would require an assessment by the Court of Justice of the EU in a possible preliminary ruling procedure or an action for annulment.</p>



<p><strong>Application</strong></p>



<p>It is believed that despite the weaknesses identified earlier, the CADA project offers more benefits than threats – especially in the context of growing cyber warfare, where information, not just physical critical infrastructure, becomes the primary weapon.</p>



<p>Data collected by healthcare providers, the banking sector, and digital service providers is strategic in nature &#8211; its confidentiality and integrity today determine the security of citizens to a degree comparable to energy or military security. As the Schrems II case demonstrated, no contractual safeguards effectively protect against a situation in which an infrastructure provider is legally obligated to disclose data to third-party authorities &#8211; regardless of the physical location of the servers. CADA addresses precisely this gap: it no longer regulates only <em>the method </em>of data processing, but also <em>the structure of control </em>over the entity that manages it. This seems to me a necessary step, not an unnecessary one.</p>



<p>The complete dependence of the European digital economy on external infrastructure providers would limit its ability to fully develop &#8211; particularly in the field of artificial intelligence, where control over training data and computing infrastructure is becoming a key factor in competitiveness. The European Union possesses significant research and development resources, which currently remain largely untapped due to the lack of coherent institutional and regulatory support to fully develop their potential. CADA, by combining infrastructure investments with preferential procurement criteria, is attempting to fill this gap.</p>



<p>A mechanism to level the playing field for smaller European providers is also crucial. Automatic recognition of compliance for SMEs at the basic assurance level and the goal of at least a quarter of cloud and AI service contracts going to innovative SMEs create a real stimulus for development—not just a barrier for large entities. Such a competitive boost could, in the long run, motivate European providers to continually improve the quality and innovation of their services, rather than remain permanently in the shadow of foreign hyperscalers.</p>



<p>Finally, the planned tripling of data centre capacity in the EU over the next 5-7 years is an investment not only in sovereignty, but also in the security of the data itself – a distributed, redundant infrastructure located within the EU reduces the risk of systemic failures, service interruptions or abuses resulting from unilateral decisions by foreign entities.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/">NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</title>
		<link>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/</link>
					<comments>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:20:43 +0000</pubDate>
				<category><![CDATA[CROSS BORDER CASES]]></category>
		<category><![CDATA[Administrative Law]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[Corporate Counsel;]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Markets]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Ecommerce]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[Foreign direct investment]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Investigations]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8811</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The dynamic development of artificial intelligence-based technologies is revolutionizing not only the commercial sector but also the area of state oversight of the digital market. The implementation of multi-agent systems by the Office of Competition and Consumer Protection (UOKiK) opens a new era in consumer rights enforcement, enabling the mass [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/">Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The dynamic development of artificial intelligence-based technologies is revolutionizing not only the commercial sector but also the area of state oversight of the digital market. The implementation of multi-agent systems by the Office of Competition and Consumer Protection (UOKiK) opens a new era in consumer rights enforcement, enabling the mass and automated identification of unfair market practices. With the Digital Services Act (DSA) and the Omnibus Directive in force, traditional control methods are giving way to algorithmic interface analysis aimed at eliminating so-called dark patterns and price manipulation. However, the use of &#8220;digital controllers&#8221; raises fundamental questions for legal science and business practice about the limits of automated decision-making processes in public administration. Although AI agents significantly improve the effectiveness of detecting violations, their legal status as a source of evidence remains the subject of heated debate. The main thesis is that while AI can be a powerful auxiliary tool for regulatory bodies, the ultimate responsibility for determining the facts and assessing the legitimate interests of a party must rest with humans, which is the foundation of a fair procedure in a state governed by the rule of law.</p>



<span id="more-8811"></span>



<h2 class="wp-block-heading" id="ember3873">Dark Patterns: Legal and Ethical Aspects of Prohibiting Manipulation in Digital Interfaces</h2>



<p id="ember3874">A key obligation of internet platform providers in light of modern regulations is to design interfaces in a transparent and ethical manner. The prohibition of manipulation, formulated, among others, in the Digital Services Act (Article 25), directly affects the structure of so-called deceptive interfaces (dark patterns). Websites and applications cannot be designed in a way that limits the recipient&#8217;s cognitive autonomy, interferes with their ability to rationally assess the situation, or forces them to make a purchasing decision that they would not have made under other circumstances.</p>



<p id="ember3875">One of the most glaring examples of such violations is the asymmetry in the contract conclusion and termination process, <strong>particularly evident in subscription models</strong>. This mechanism relies on extreme simplification of the purchase path while simultaneously mounting procedural barriers when attempting to cancel the service. Visual techniques are used here, among other things: payment activation buttons are highlighted with bright colors and a central location, while contract termination options are deliberately hidden at the bottom of the page, written in small font or masked with colors that blend with the background. Furthermore, canceling a subscription on online platforms often requires multiple selections or confirmation of the desire to cancel, despite the consumer&#8217;s prior explicit choice. Artificial intelligence algorithms, analyzing the page structure and visual hierarchy of elements, can pinpoint these disparities with mathematical precision, creating a list of violations that serves as hard evidence.</p>



<p id="ember3876">In the context of the Omnibus Directive, the obligation to disclose the lowest price 30 days before the discount has become a market standard, but its implementation is open to abuse. The practice of &#8220;empty promotions&#8221; involves artificially inflating the base price just before a planned discount or providing a false reference amount. In this area, AI agents demonstrate particular effectiveness, acting as real-time monitoring systems; they can archive the price history of each product, creating an independent database. Comparing this information with the entrepreneur&#8217;s declaration visible on the website allows for immediate detection of manipulation of the promotional algorithm.</p>



<p id="ember3877">An equally important area of control is the phenomenon of drip pricing , or hiding the real costs of a transaction until the final stage of the shopping cart. Businesses often employ a &#8220;decoy&#8221; strategy, presenting an attractive unit price, which, at the time of order finalization, is increased by mandatory, previously undisclosed costs, such as service fees, packaging costs, or payment processing fees. Pursuant to Article 12 of the Consumer Rights Act, businesses are obligated to clearly and understandably inform consumers about, among other things, the total price for the proposed service. Automated control systems are capable of conducting a full simulation of the purchasing process, from product selection to the payment gateway. Any discrepancy between the price presented in the product list and the amount required to complete the contract is reported by AI as an attempt to circumvent disclosure obligations and a direct violation of the collective interests of consumers.</p>



<p id="ember3878">According to Article 5 of the Act on Combating Unfair Market Practices, the key criterion for assessing a trader&#8217;s behavior is the impact of their actions on the recipient&#8217;s decision-making process. A <strong>market practice is considered misleading</strong> if &#8220;this action in any way causes or is likely to cause the average consumer to make a transactional decision that they would not otherwise have made&#8221;. The legislator specifies that both &#8220;spreading false information&#8221; and &#8220;spreading true information in a manner that is likely to be misleading&#8221; can constitute an infringement. In the digital environment, these manipulations most often focus on the &#8220;existence of a product, its type, or availability.&#8221; A common method of exerting unjustified pressure on consumers is the use of social proof mechanisms and an artificial sense of scarcity. This manifests itself in messages such as: &#8220;this product is now being viewed by x people,&#8221; &#8220;x items have already been purchased today,&#8221; or displaying timers indicating that &#8220;only 30 minutes left until the end of the promotion.&#8221; Particularly problematic from the perspective of trade ethics is the use of so-called false advertising. Timers – clocks counting down to the finale of a supposedly unique price opportunity. In reality, these are fake mechanisms, as after the specified deadline, the offer remains active and the product price remains unchanged or becomes even more favorable. This type of activity, a classic example of dark patterns, is designed to induce fear of missing out (FOMO) in customers and induce them to rush into a transaction. Using AI agents allows regulators to serially monitor such counters and prove their cyclical recurrence, providing direct evidence of deceptive practices.</p>



<h2 class="wp-block-heading" id="ember3879">The algorithm as a controller</h2>



<p id="ember3880">With millions of transactions taking place across the country in just a few minutes or hours, standard order verification procedures prove insufficient to effectively fulfill the statutory responsibilities of supervisory authorities. Technological advancements in the form of AI algorithms come to the rescue. These algorithms can automatically monitor numerous commercial transactions simultaneously, generating preliminary opinions that are ultimately subject to human review. Such systems not only save significant processing time but, above all, enable oversight of a much broader range of businesses and their online platforms. The AI multi-agents used in this process are virtual &#8220;consumer robots&#8221; capable of mass-auditing e-commerce websites, simulating the natural behavior of online users to detect irregularities that a human controller would be unable to detect on such a large scale.</p>



<p id="ember3881">To conduct reliable and effective inspections, Polish law already offers supervisory authorities a toolkit in the form of the &#8220;mystery shopper&#8221; institution. Traditionally, this involves a person unrelated to the inspected company or the inspecting authority making a purchase and then completing a survey regarding specific activities they observe during standard shopping. The implementation of AI technology by the Office of Competition and Consumer Protection (UOKiK) aims to entrust AI multi-agents with the role of such digital &#8220;mystery shoppers.&#8221; Their task is to interact with the website interface, add a product to the cart, and complete the entire purchasing process without disclosing that this activity is being performed by an algorithm or that it is part of an official inspection procedure. This approach allows for direct verification of whether the entrepreneur is not using prohibited manipulative practices, known as dark patterns. However, it should be emphasized that <strong>the activity of AI multi-agents is strictly regulated by legal procedures and cannot be arbitrary</strong>. The algorithm operates under the strict supervision of the President of the Office of Competition and Consumer Protection, who, pursuant to Article 105ia of the Act on Competition and Consumer Protection, must always obtain prior consent from the Court of Competition and Consumer Protection. This mechanism serves as a key safeguard against abuse of power. Furthermore, after completing the inspection, the office is obligated to immediately provide the entrepreneur with an official ID and authorization for the inspection. In the age of digital administration, this obligation can be fulfilled electronically immediately after the AI multi-agents withdraw from the sales platform.</p>



<p id="ember3882">The key legal framework for the operation of algorithms commissioned by the regulator is provided by the EU AI Act. According to its provisions, AI systems used by public authorities for control and supervisory purposes should be considered high-risk AI systems. This entails a strict requirement to design them with appropriate transparency, which allows both the controlling and the controlled entities to properly interpret the system&#8217;s results and use them fairly. In practice, this means that algorithms must be built in an &#8220;explainable&#8221; model. A business subject to allegations based on an algorithmic audit has the statutory right to request full insight into the operation of AI tools. This transparency is essential for the controlled entity to understand the basis and criteria on which the authority deemed its online platform unfair or infringing on the collective interests of consumers (Article 24). This balance between the effectiveness of digital supervision and the right to defense is the foundation of a modern rule of law in the age of algorithms.</p>



<h2 class="wp-block-heading" id="ember3883">The opinion of AI multi-agents as evidence in the case</h2>



<p id="ember3884">After completing the inspection activities on the entrepreneur&#8217;s online platform, the AI algorithm&#8217;s role evolves towards an analytical function, consisting of preparing an opinion indicating detected violations. In the context of potential proceedings against an entity employing unfair market practices, the admissibility of using such an analysis as valid evidence becomes a key issue. Pursuant to Article 7 of the Code of Administrative Procedure (hereinafter referred to as the Code of Administrative Procedure), which establishes the principle of objective truth, a public administration body is obligated to take all steps necessary to thoroughly clarify the factual circumstances. This obligation is consistent with Article 75 § 1 of the Code of Administrative Procedure, which introduces an open catalog of evidence, allowing as evidence anything that may contribute to the clarification of the case, provided it is not contrary to the law.</p>



<p id="ember3885">Under these regulations, the results of AI multi-agent work &#8211; taking the form of reports, opinions, or analyses generated after conducting an audit with court approval &#8211; fully fall within the statutory definition of evidence. However, it should be clearly stated that an AI opinion cannot be equated with an expert opinion within the meaning of Article 84 of the Code of Administrative Procedure. This stems from the fact that an algorithm does not possess the status of a natural person equipped with specialized knowledge, which is a statutory requirement for appointing an expert. Instead, documentation generated by an AI agent should be classified as a private document or so-called &#8220;unnamed evidence.&#8221;</p>



<p id="ember3886">Practical justification for this position can be found in the case law concerning digital evidence. The judgment of the Court of Appeal in Szczecin of September 19, 2016, I ACa 364/15, LEX no. 2147337 aptly describes this issue, pointing out that evidence in a case may include official and private documents, but also means other than those listed in Articles 305-308 of the Code of Civil Procedure. Electronic evidence, currently increasingly used in civil proceedings, is not explicitly listed in the catalog of means of evidence. However, the Code of Civil Procedure does not contain a closed list of evidence sources; anything relevant to the case may constitute evidence. Although the above ruling was issued in the context of civil procedure, due to the identical approach to the openness of the evidence system, it remains fully applicable to administrative proceedings conducted by the President of the Office of Competition and Consumer Protection.</p>



<p id="ember3887">The key element of algorithmic evidence remains the human factor, which serves as a primary safeguard over the autonomous operation of technology. It&#8217;s important to note that AI multi-agents, despite their high sophistication, operate based on statistical probability models, which carries the risk of misinterpreting dynamic website elements. For example, the system may incorrectly classify a standard technical error as intentional dark web activity. patterns or misinterpret the interface&#8217;s intentions in a specific cultural or linguistic context. Therefore, opinions generated by AI agents cannot constitute a standalone and final basis for a decision, but should be subjected to thorough, critical review by an official. Only such a comparison of the &#8220;raw&#8221; algorithmic result with human knowledge and experience allows for avoiding errors that could lead to unjustified penalties. This approach is directly supported by Article 80 of the Code of Administrative Procedure, according to which a public administration body assesses whether a given circumstance has been proven based on the entirety of the evidence. In this process, the &#8220;AI opinion&#8221; is only one of many components that must be weighed against other evidence and evaluated through the prism of principles of logic and life experience, ultimately guaranteeing the implementation of the principle of objective truth and protecting the entrepreneur from the automaticity of decisions made by the algorithm.</p>



<h2 class="wp-block-heading" id="ember3888">Summary</h2>



<p id="ember3889">Multi-agent system implemented by the Office of Competition and Consumer Protection for automatic control of the e-commerce sector poses a significant challenge for entrepreneurs, forcing strict compliance with regulations regarding dark patterns, price transparency (Omnibus Directive, Art. 6a) and information obligations (Consumer Rights Act, Art. 12). These tools are used to mass detect manipulative practices such as drip pricing, fake timers or making it difficult to unsubscribe. Although AI agents perform a function similar to &#8220;mystery shoppers,&#8221; their activity must meet the rigors of Article 105ia of the Act on Competition and Consumer Protection, including the requirement to obtain court consent for a controlled purchase. What is crucial from a procedural perspective is that the findings made by the algorithm do not have the status of an expert opinion within the meaning of Article 84 of the Code of Administrative Procedure (lack of the status of a natural person with specialist knowledge), but constitute only a private document or &#8220;other evidence&#8221; subject to the authority&#8217;s free assessment (Article 80 of the Code of Administrative Procedure).</p>



<p id="ember3890">Consequently, the official is required to subject AI reports to thorough human review to eliminate the risk of misclassification resulting from so-called &#8220;AI hallucinations&#8221; or technical errors in the interpretation of the website&#8217;s code. The entrepreneur has full rights of defense based on the principle of active participation of the party (Article 10 of the Code of Administrative Procedure) and the principle of objective truth (Article 7 of the Code of Administrative Procedure), which means the right to question the bot&#8217;s logic and to access the instructions and parameters of the AI system, in accordance with the &#8220;explainability&#8221; requirement enshrined in the AI Act (Article 13). Any decision based solely on the automated generation of conclusions, without providing the party with an opportunity to comment on the evidence (Article 81 of the Code of Administrative Procedure), constitutes a gross violation of administrative procedure and may constitute an effective basis for challenging the authority&#8217;s decision.</p>



<h2 class="wp-block-heading" id="ember3891">Sources:</h2>



<p id="ember3892">Regulation 2022/2065 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, No. 277, p. 1, as amended).</p>



<p id="ember3893">Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (OJ L 328, 2019, p. 7, as amended).</p>



<p id="ember3894">Act of 30 May 2014 on consumer rights (consolidated text: Journal of Laws of 2024, item 1796, as amended).</p>



<p id="ember3895">Act of 23 August 2007 on counteracting unfair market practices (consolidated text: Journal of Laws of 2023, item 845).</p>



<p id="ember3896">Act of 16 February 2007 on competition and consumer protection (consolidated text: Journal of Laws of 2025, item 1714).</p>



<p id="ember3897">Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) Text with EEA relevance (OJ L 1689, 2024).</p>



<p id="ember3898">Act of 14 June 1960, the Code of Administrative Procedure (consolidated text: Journal of Laws of 2025, item 1691).</p>



<p id="ember3899">Judgment of the Court of Appeal in Szczecin of 19 September 2016, I ACa 364/15, LEX no. 2147337.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/">Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 17:54:28 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[3D Scanning]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI in Defence]]></category>
		<category><![CDATA[Armed Forces]]></category>
		<category><![CDATA[Arms Trade]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[ASAP]]></category>
		<category><![CDATA[B2B]]></category>
		<category><![CDATA[B2G]]></category>
		<category><![CDATA[Civil Defence]]></category>
		<category><![CDATA[Classified Information]]></category>
		<category><![CDATA[Crisis Preparedness]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Defence Conference]]></category>
		<category><![CDATA[Defence Expo]]></category>
		<category><![CDATA[Defence Industry]]></category>
		<category><![CDATA[Defence IP]]></category>
		<category><![CDATA[Defence Procurement]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Defense Expo]]></category>
		<category><![CDATA[Defense Industry]]></category>
		<category><![CDATA[Defense Tech]]></category>
		<category><![CDATA[Drones]]></category>
		<category><![CDATA[Dual Use Technology]]></category>
		<category><![CDATA[EDF]]></category>
		<category><![CDATA[Emergency Preparedness]]></category>
		<category><![CDATA[European Defence Fund]]></category>
		<category><![CDATA[EXPO XXI]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[Firearms Law]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[Infrastructure Protection]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[Military Innovation]]></category>
		<category><![CDATA[Military Modernization]]></category>
		<category><![CDATA[Military Technology]]></category>
		<category><![CDATA[Mini MSPO]]></category>
		<category><![CDATA[MON RP]]></category>
		<category><![CDATA[MSWiA]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Personal Protective Equipment]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish Armed Forces]]></category>
		<category><![CDATA[Polish Defence Industry]]></category>
		<category><![CDATA[Public Procurement]]></category>
		<category><![CDATA[Range Safety]]></category>
		<category><![CDATA[Resilience]]></category>
		<category><![CDATA[Security Conference]]></category>
		<category><![CDATA[Shooting Sports]]></category>
		<category><![CDATA[Sport Shooting]]></category>
		<category><![CDATA[State Resilience]]></category>
		<category><![CDATA[Tactical Communications]]></category>
		<category><![CDATA[Territorial Defence]]></category>
		<category><![CDATA[UAV]]></category>
		<category><![CDATA[Unmanned Systems]]></category>
		<category><![CDATA[WARSAW]]></category>
		<category><![CDATA[Warsaw Defence Expo]]></category>
		<category><![CDATA[Warszawa]]></category>
		<category><![CDATA[Warszawskie Targi Obronne]]></category>
		<category><![CDATA[Weapons Permits]]></category>
		<category><![CDATA[WOT]]></category>
		<category><![CDATA[WTO2026]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8803</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 – the first edition of a new nationwide event dedicated to the defence, security and resilience of the state On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-1 wp-block-group-is-layout-flex">
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>


</div>



<h3 class="wp-block-heading">– the first edition of a new nationwide event dedicated to the defence, security and resilience of the state</h3>



<p id="ember53">On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. This is the first edition of a completely new trade fair and conference event, created in response to the growing importance of the defense sector, national security, and technologies supporting Poland&#8217;s institutional, economic, and social resilience. The fair is held under the honorary patronage of the Ministry of Interior and Administration and the Minister of National Defense. The event is informally referred to as a &#8220;mini-MSPO in Warsaw&#8221; – a capital city-based, intimate alternative to the September International Defense Industry Fair in Kielce, open not only to professionals but also – on the second day – to the general public.</p>



<span id="more-8803"></span>



<p id="ember54">The goal of the Warsaw Defense Fair is to integrate key groups responsible for national security and to create a space for dialogue, collaboration, and exchange of experiences between public administration, the military, uniformed services, the defense industry, the technology sector, the investor community, and military universities. The event combines exhibition, conference, and networking elements , creating a platform for showcasing modern technologies, exchanging expert knowledge, and building business relationships in one of the fastest-growing sectors of the Polish economy.</p>



<p id="ember55">The trade fair program is divided into two complementary days, representing one of the most distinctive solutions adopted by the organizers. Friday, June 19, 2026, will be an industry day (B2B/B2G), intended exclusively for companies, institutions, and business partners. Industry registration is required. This day will be a platform for meetings and discussions between individuals and entities interested in establishing cooperation in the defense and security sector, including representatives of public administration and local governments, soldiers and uniformed services, representatives of companies in the defense and technology sectors, investors, industry advisors, and representatives of military universities. The program focuses on key challenges facing the defense and national security sectors, including conferences, panel discussions, and business and institutional meetings concerning the development of the Polish defense industry, modernization of the Armed Forces, public procurement in the defense sector, and cross-sectoral cooperation.</p>



<p id="ember56">Saturday, June 20, 2026, will be an open day (B2B/B2G/B2C), also open to the public interested in security, defense, and shooting. The second day significantly complements the industry portion and expands the event to include the general public, as well as educational and outreach communities. It will feature demonstrations of equipment and technologies in near-operational settings, demonstration zones by exhibitors and manufacturers, presentations of solutions in cybersecurity, drones, communications, and critical infrastructure protection, as well as numerous lectures for enthusiasts. Topics covered include firearms licenses – myths and legal realities, training and shooting sports, hearing and eye protection, safety and ergonomics at the shooting range, and civic preparedness for crisis situations.</p>



<h2 class="wp-block-heading" id="ember57">Exhibitors and thematic scope</h2>



<p id="ember58">Over 100 exhibitors will be present at the fair, representing a full cross-section of entities active in the Polish defense and security sector. Exhibitors include military units such as the 1st Warsaw Armored Brigade and the 18th Capital Territorial Defense Brigade, international technology companies, including 3M Poland, which presents personal protection solutions for the defense sector, and Artec 3D with 3D scanners used in military applications. The shooting and equipment segment will be strongly represented, with companies such as House of Guns , Hubertus Pro Hunting , Kaliber, 4HUNTING, Kolba, 4SHOOTER, Son of Gun , Jammas , and Wolfer. Group and Works11. The event is also partnered by the Legia Warsaw Central Military Sports Club – Shooting Section.</p>



<p id="ember59">The exhibition covers cutting-edge weapons, equipment, facilities and technologies used in the defense and security sector: unmanned systems and drones, cybersecurity solutions, tactical communications and communication technologies, critical infrastructure protection, personal protective equipment, 3D scanning and simulation technologies, individual soldier equipment, as well as solutions in the area of civil defense and population protection.</p>



<h2 class="wp-block-heading" id="ember60">Three conference stages and a substantive agenda</h2>



<p id="ember61">The WTO 2026 program will unfold simultaneously across three conference stages. The industry day will be dedicated to the most important strategic challenges facing the defense sector – the technical modernization of the Polish Armed Forces, the development of the domestic arms industry, cooperation with foreign partners, public procurement in the defense sector, new dual-use technologies , and the role of the private sector in building national resilience. The second day, open to the public, will feature lectures and discussions covering a much broader range of topics – from legal issues concerning access to weapons and individual security, through shooting sports and defense training, to preparing society for crisis situations and disseminating knowledge about modern defense technologies.</p>



<p id="ember62">The significance of the event from a legal perspective</p>



<p id="ember63">The establishment of the Warsaw Defense Fair is part of the broader context of the dynamic development of the Polish defense sector, which in recent years has become one of the most important areas of public and private investment, generating significant demand for legal services. From the firm&#8217;s perspective, issues related to public procurement in the defense sector, regulations regarding trade in arms and dual-use technologies, export controls, protection of classified information, cybersecurity in the context of the NIS2 directive, intellectual property rights in defense technology projects, and financing of projects from European funds (including the European Defense Fund and ASAP), as well as the development of regulations regarding artificial intelligence in military applications in light of the European AI Act . The participation of representatives of the KG LEGAL KIEŁTYKA GŁADKOWSKI law firm in this event is a natural element of tracking the development of one of the fastest-growing sectors of the Polish economy and building competences in the area of law related to new defense technologies.</p>



<p id="ember64">The Warsaw Defense Fair 2026 demonstrates that security and defense are no longer the exclusive domain of the military and state administration. They have become an area of broad cross-sectoral cooperation, with technology companies, investors, academia, non-governmental organizations, and informed citizens playing key roles. The development of this sector today requires not only advanced technological competencies but also an appropriate legal, regulatory, and institutional environment.</p>



<p id="ember65">Link to the event: <a href="https://wto26.exposupport.pl/program">https://wto26.exposupport.pl/program</a></p>



<p id="ember66">#WarsawDefenceExpo #WTO2026 #WarszawskieTargiObronne #DefenceIndustry #DefenseIndustry #DefenceExpo #DefenseExpo #PolishDefenceIndustry #PolishArmedForces #NationalSecurity #StateResilience #CivilDefence #HomelandSecurity #DefenceTechnology #DefenseTech #MilitaryTechnology #MilitaryInnovation #DualUseTechnology #DefenceProcurement #PublicProcurement #ArmsTrade #ExportControl #ClassifiedInformation #CyberSecurity #NIS2 #CriticalInfrastructure #InfrastructureProtection #UnmannedSystems #Drones #UAV #TacticalCommunications #PersonalProtectiveEquipment #3DScanning #AIinDefence #AIAct #ArtificialIntelligence #EuropeanDefenceFund #EDF #ASAP #IntellectualProperty #DefenceIP #TerritorialDefence #WOT #ArmedForces #MilitaryModernization #SportShooting #FirearmsLaw #WeaponsPermits #ShootingSports #RangeSafety #CrisisPreparedness #EmergencyPreparedness #Resilience #B2B #B2G #EXPOXXI #Warsaw #Warszawa #Poland #MONRP #MSWiA #MiniMSPO #DefenceConference #SecurityConference #LegalTech #LawFirm #KGLegal #KieltykaGladkowski</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Digital Omnibus</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-omnibus/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-omnibus/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 05 Jan 2026 20:16:00 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Digital Omnibus]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8521</guid>

					<description><![CDATA[<p>Publication date: January 05, 2026 The Digital Omnibus is a comprehensive draft of two regulations of the European Parliament and Council, the most important part of a broader package of changes to data regulations (especially personal data) and those regulating the digital market in the EU. The changes aim to stimulate innovation and the development [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-omnibus/">Digital Omnibus</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: January 05, 2026</strong></mark></p>



<p>The Digital Omnibus is a comprehensive draft of two regulations of the European Parliament and Council, the most important part of a broader package of changes to data regulations (especially personal data) and those regulating the digital market in the EU. The changes aim to stimulate innovation and the development of the European artificial intelligence market, and to introduce solutions that could save businesses capital (estimated at up to €4 billion in total by 2029). The changes aim to ensure that businesses of all types, from factories to start-ups, spend less time and money on administration and maintaining the documentation required by current EU regulations.</p>



<span id="more-8521"></span>



<p>The draft amendments consist of two regulations:</p>



<ul class="wp-block-list">
<li><strong>Digital Omnibus,</strong> which introduces changes to many important EU regulations already in force, such as:</li>
</ul>



<p>Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General<strong> Data Protection Regulation</strong>) (OJ EU L. of 2016, No. 119, p. 1, as amended).</p>



<p>Regulation (EU) 2018/1724 of the European Parliament and of the Council of 2 October 2018 <strong>on establishing a single digital gateway to provide access to information, procedures and assistance and problem-solving services </strong>and amending Regulation (EU) No 1024/2012 (OJ EU L 295, 2018, p. 1, as amended).</p>



<p>Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on <strong>the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies</strong> <strong>and the free movement of such data </strong>, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (OJ EU L 295, 2018, p. 39).</p>



<p>Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (&#8221; <strong>Data Act </strong>&#8220;) (OJ L 2854, 2023, item 2854, as amended).</p>



<p>Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (<strong>Directive on privacy and electronic communications</strong>) (OJ L 201, 2002, p. 37–47)</p>



<p>Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 concerning <strong>measures for a high common level of cybersecurity across the Union</strong>, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 and repealing Directive (EU) 2016/1148 (<strong>NIS Directive 2</strong>) (OJ L 333, 2022, p. 80, as amended).</p>



<p>Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on <strong>the resilience of critical entities </strong>and repealing Council Directive 2008/114/EC (OJ EU L 333, 2022, p. 164).</p>



<ul class="wp-block-list">
<li>Digital Omnibus on AI, which amends:</li>
</ul>



<p>Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (&#8220;<strong>Artificial Intelligence Act</strong>&#8220;) (OJ L 1689, 2024).</p>



<p>Regulation (EU) 2018/1139 of the European Parliament and of the Council of 4 July 2018 on <strong>common rules in the field of civil aviation and establishing a European Union Aviation Safety Agency</strong>, and amending Regulations (EC) No 2111/2005, (EC) No 1008/2008, (EU) No 996/2010, (EU) No 376/2014 and Directives 2014/30/EU and 2014/53/EU of the European Parliament and of the Council, and repealing Regulations (EC) No 552/2004 and (EC) No 216/2008 of the European Parliament and of the Council and Council Regulation (EEC) No 3922/91 (OJ L 212, 2018, p. 1, as amended).</p>



<p>The bill also assumes the repeal of the following acts:</p>



<ol class="wp-block-list">
<li>Regulation (EU) 2018/1807 of the European Parliament and of the Council of 14 November 2018 on a framework for the free flow of non-personal data in the European Union (OJ L 303, 2018, p. 59).</li>



<li>Regulation (EU) 2019/1150 of the European Parliament and of the Council of 20 June 2019 on promoting fairness and transparency for business users of online intermediation services (OJ L 186, 2019, p. 57).</li>



<li>Regulation (EU) 2022/868 of the European Parliament and of the Council of 30 May 2022 on European Data Governance and amending Regulation (EU) 2018/1724 (Data Governance Act) (OJ L 152, 2022, p. 1, as amended).</li>



<li>Directive (EU) 2019/1024 of the European Parliament and of the Council of 20 June 2019 on open data and the re-use of public sector information (OJ L 172, 2019, p. 56)</li>
</ol>



<p>In theory, all these changes are purely technical: they unify processes and obligations occurring simultaneously under various acts, simplify definitions and procedures, and simultaneously maintain the level of protection of fundamental rights. How? The justifications for both projects only state that they do not violate the fundamental rights of EU citizens. In practice, the presented projects introduce numerous solutions that will be significantly different from those previously implemented, primarily in terms of privacy and data protection for individuals. The overarching goal of the changes is to increase the competitiveness of the European digital market by introducing solutions that enable artificial intelligence to train on larger datasets, including personal data.</p>



<p class="has-medium-font-size"><strong>AI Act</strong></p>



<p>The changes proposed in the draft amendment to this act are intended to improve the implementation of its individual elements and counteract problems that have already occurred – some provisions have already entered into force, while others are yet to be replaced.</p>



<p>The most significant change is the introduction of a new Article 4a, which replaces the previous Article 10(5). The repealed provision provided the legal basis for providers of high-risk AI systems to exceptionally process special categories of personal data to ensure the detection and correction of bias in specific circumstances. In principle, the new regulation is identical to the previous one, but paragraph 2 significantly expands its scope, as: &#8220;Paragraph 1 may apply to <strong>providers and implementers <u>of other AI systems and models </u>, and implementers of high-risk AI systems </strong>, if necessary and proportionate, provided that the processing is carried out for the purposes specified in that paragraph and subject to compliance with the conditions set out in the safeguards set out in that paragraph.&#8221; Consequently, this provision allows for the processing of personal data to a broader extent for AI training purposes.</p>



<p>In general, significant changes are expected to occur within high-risk systems. These are systems that have a significant impact on society and the lives of individuals. Examples include systems used to diagnose diseases, predict treatment outcomes, or assist in the recruitment process. These systems may be used provided they meet the requirements of the AI Act.</p>



<p>First, the powers granted to small and medium-sized enterprises (SMEs) in many regulations have been expanded, including the right to prepare simplified technical documentation for high-risk systems. As a result of the changes, small mid-cap companies (SMCs) will also have this power.</p>



<p>The European Commission also wants to link the entry into force of the regulations on high-risk systems to the availability of support tools. Therefore, the entry into force of the regulations on high-risk systems is to be postponed for a maximum of 16 months, so that it takes place after the support tools are available.</p>



<p>Changes are also taking place in the scope of the AI Authority&#8217;s powers under Article 75 to supervise and control general-purpose AI systems. The Authority will be the exclusive authority responsible for supervising and enforcing the obligations arising from the AI Act in relation to AI systems that constitute or are integrated with a designated very large online platform or very large online search engine within the meaning of Regulation (EU) 2022/2065.</p>



<p>A number of new regulations are also intended to enable greater use of regulatory sandboxes and real-world testing.</p>



<p>The bill also extends the deadline for AI systems and general-purpose models already on the market or put into service to meet the requirements of the AI Act for labeling and watermarking AI-generated content until February 2, 2027, giving companies more time to adapt their technology.</p>



<p class="has-medium-font-size"><strong>GDPR</strong></p>



<p>The justification for the GDPR amendments states that &#8220;Targeted changes to the GDPR will harmonize, clarify, and simplify certain rules to increase innovation and make it easier for organizations to comply, while preserving the essence of the GDPR and ensuring the highest level of personal data protection.&#8221; This is an interesting statement, considering that one of the first changes introduced is <strong>a narrowing of the definition of personal data.</strong> The new definition introduces <strong>a subjective approach to personal data,</strong> focusing on whether an entity has &#8220;likely means of identifying a natural person.&#8221; This approach to personal data has been presented in the case law of the CJEU (including case number C-413/23 P). Introducing this definition would mean that if an entity claims that it cannot or does not intend to identify natural persons based on the data it possesses, the provisions of the regulation would cease to apply. The greatest impact of such a change would be in sectors that use pseudonymization and identification numbers to build consumer profiles (e.g., online advertising). As a result, individual data could be considered personal or not, depending on whether a specific entity has the means to legitimately identify an individual based on that data.</p>



<p>Recital 32 of the draft regulation clearly states that &#8220;the development and operation of artificial intelligence systems or models constitutes a &#8216;legitimate interest&#8217; of the controller pursuant to Article 6(1)(f) of the GDPR.&#8221; This statement provides <strong>a legal basis for the processing of personal data for AI training purposes,</strong> provided that the requirements set out in the aforementioned provision are met. Further limitations on the rights of data subjects result from the addition of paragraph 5 to Article 13, according to which the information obligations under Article 13 need not be complied with if the data are processed for scientific research purposes (including AI development) if this proves impossible or would involve a disproportionate effort.</p>



<p>Changes are also to be made to the processing of special categories of data (Article 9). Two new exceptions are introduced:</p>



<ul class="wp-block-list">
<li>an exception to the general prohibition on processing biometric data, which will be permitted for identity verification purposes, provided that the data remains under the user&#8217;s control (e.g. FaceID verification taking place only on the device)</li>



<li>an exception for the processing of special categories of personal data for the development and operation of an artificial intelligence system or model, subject to certain conditions, including appropriate organisational and technical measures to avoid the collection of special categories of personal data and the deletion of such data.</li>
</ul>



<p>The draft also excludes the application of the information obligation under Article 13 if there are reasonable grounds to believe that the data subject already has the information that must be provided under that provision. This exception will not apply if the data subject transfers data to other recipients or categories of recipients, transfers data to a third country, engages in automated decision-making, or the processing is likely to result in a high risk to the rights of data subjects.</p>



<p>The amendment also includes Article 33 on reporting personal data breaches to the supervisory authority. This obligation would apply only to breaches &#8220;likely to result in a high risk to the rights and freedoms of natural persons,&#8221; aligning its threshold with the information obligation towards data subjects under Article 34. The period within which notification must be made has also been extended to 96 hours.</p>



<p>Significant changes may also occur in the area of data processing on end devices. Article 88a is proposed, which introduces the possibility of using grounds other than consent for the processing of personal data and for the specific purposes listed in this provision. With regard to consent to the processing of personal data on end devices, data subjects must be able to easily and understandably refuse requests for consent by means of a single click or equivalent means. Article 88b, in turn, requires controllers to adapt their web interfaces to the automated and machine-readable indication of data subjects&#8217; choices regarding consent or refusal to the processing of personal data on end devices. These changes will have significant implications for cookies and are intended to reduce the number of cookie notifications and allow users to express consent and save preferences through central preference settings in browsers and operating systems.</p>



<p><strong>Access to data</strong></p>



<p>The proposed changes to data access should be viewed positively. Significant and still relevant provisions from the four repealed EU acts are to be implemented in the Data Act . This move aims to increase transparency regarding the regulation of data management and circulation in the EU by consolidating all relevant provisions into a single act.</p>



<p>The remaining changes to the Data Act will not be revolutionary. It is intended to enable entities covered by the regulation to comply with the Act&#8217;s guidelines through model contractual terms and clauses regarding data access and use. Furthermore, a rule will be introduced according to which data owners may refuse to disclose trade secrets to a user if there is a significant risk of unlawful acquisition, use, or disclosure of the data to third countries or entities under their control that are subject to jurisdictions with weaker protection than that available in the EU.</p>



<p><strong>Cybersecurity reporting</strong></p>



<p>The most important change in streamlining procedures and standardizing obligations under various EU acts is the proposal to create a single, common interface, known as a &#8220;contact point,&#8221; where entities required to report various types of incidents under various legal acts can fulfill their obligations. Currently, such obligations arise from, among others, the GDPR, the NIS2 Directive, and the AI Act, which necessitates the preparation of multiple reports on the same incident. The changes assume a single report submitted through a single system, which will be forwarded to the appropriate authorities.</p>



<p><strong>Summary</strong></p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size">The European Commission&#8217;s goal in creating these projects was to increase innovation and competitiveness in the European digital market, primarily in relation to the development of artificial intelligence. The changes were intended to simplify procedures and remove restrictions that hinder the faster development of AI. As can be seen, the proposed changes could significantly limit the protection of individuals in terms of their privacy and personal data, which could be used to train systems, not only high-risk ones. Many groups in the European Parliament do not support the proposed changes, believing that they will not bring real benefits to European entities and will instead facilitate the work of foreign technology giants. The changes to the GDPR are the most criticized, as member states requested that they remain outside the scope of the Digital Omnibus, as in the original draft.</p>



<p>Sources:</p>



<ol class="wp-block-list">
<li>Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework , and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus) {SWD(2025) 836 final }</li>



<li>Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulations (EU) 2024/1689 and (EU) 2018/1139 as regards the simplification of the implementation of harmonized rules on artificial intelligence (Digital Omnibus on AI) {SWD(2025) 836 final }</li>



<li><a href="https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2718">https://ec.europa.eu/commission/presscorner/detail/en/ip_25_2718</a></li>
</ol>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-omnibus/">Digital Omnibus</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-omnibus/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Optical Illusions in AI Systems, the Danger of Adversarial Attacks, Biological Technologies, Explainable AI – topics discussed during Futurology Congress 2025</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/optical-illusions-in-ai-systems-the-danger-of-adversarial-attacks-biological-technologies-explainable-ai-topics-discussed-during-futurology-congress-2025/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/optical-illusions-in-ai-systems-the-danger-of-adversarial-attacks-biological-technologies-explainable-ai-topics-discussed-during-futurology-congress-2025/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 16 Sep 2025 12:29:23 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[ai ac]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Biological Technologies]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Explainable AI – topics discussed during Futurology Congress 2025]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[Optical Illusions in AI Systems]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[the Danger of Adversarial Attacks]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8324</guid>

					<description><![CDATA[<p>Publication date: September 15, 2025 On September 12-14, 2025, lawyers from KIELTYKA GLADKOWSKI KG LEGAL participated in the annual Futurology Congress in Krakow. The participants, among which there was AGH University of Science and Technology&#8217;s Artificial Intelligence Center of Excellence discussed aspects of new technologies, including: • Optical Illusions in AI Systems: The Danger of [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/optical-illusions-in-ai-systems-the-danger-of-adversarial-attacks-biological-technologies-explainable-ai-topics-discussed-during-futurology-congress-2025/">Optical Illusions in AI Systems, the Danger of Adversarial Attacks, Biological Technologies, Explainable AI – topics discussed during Futurology Congress 2025</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 15, 2025</mark></strong></p>



<figure class="wp-block-image size-large"><a href="https://kongres.pffn.org.pl/nauka/" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="1024" height="536" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/wydarzenie-FB-1024x536.png" alt="" class="wp-image-8325" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/wydarzenie-FB-1024x536.png 1024w, https://www.kg-legal.eu/wp-content/uploads/2025/09/wydarzenie-FB-300x157.png 300w, https://www.kg-legal.eu/wp-content/uploads/2025/09/wydarzenie-FB-768x402.png 768w, https://www.kg-legal.eu/wp-content/uploads/2025/09/wydarzenie-FB-1536x804.png 1536w, https://www.kg-legal.eu/wp-content/uploads/2025/09/wydarzenie-FB.png 1920w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure>



<p>On September 12-14, 2025, lawyers from KIELTYKA GLADKOWSKI KG LEGAL participated in the annual Futurology Congress in Krakow.</p>



<span id="more-8324"></span>



<p>The participants, among which there was AGH University of Science and Technology&#8217;s Artificial Intelligence Center of Excellence discussed aspects of new technologies, including:</p>



<p>• Optical Illusions in AI Systems: The Danger of Adversarial Attacks. Adversarial attacks on vision systems are a topic of growing interest in both science and the technology industry – not only due to autonomous vehicles but also medical systems. The panelists demonstrated how subtle, almost invisible image modifications can completely confuse AI algorithms, leading to situations where the algorithm fails to recognize a STOP road sign or makes an error when analyzing medical images. Examples of such attacks from both transportation and medicine were presented, highlighting their impact on everyday life and safety. There were explained the mechanisms behind these phenomena and their consequences for machine learning-based systems. In this area, there is a constant race between the creators of such attacks and the engineers developing protection methods, and ensuring complete security remains a major challenge for the AI industry.</p>



<p>• The development of the Polish space sector, combining engineering, science, and modern technologies. Domestic entities are among the leaders building Poland&#8217;s position in the global space industry supply chain. During the panel, there were discussed the most important achievements and participation of Polish teams in prestigious international missions. Representatives of key companies discussed their projects, challenges, and role in the global space ecosystem. There were also considered barriers to sector development and legislative and financial needs. The panel was an opportunity to look to the future and attempt to answer the question of Poland&#8217;s potential role in the exploration and use of space. Participants shared their experiences collaborating with the European Space Agency and other international partners.</p>



<p>• Modern biotechnology. Biotechnology is becoming one of the pillars of modern civilization, offering breakthrough solutions in medicine, diagnostics, agriculture, and environmental protection. Faced with global challenges such as aging societies, the growing number of lifestyle diseases, and the need for sustainable development, the dynamic development of biotechnology is opening up new opportunities to improve the quality of life. The panel discussed the potential of gene and cell therapies, the importance of innovative drugs in the fight against cancer, and the role of collaboration between science, the investment sector, and industry. Guests addressed ethical, regulatory, and social issues related to the implementation of new biological technologies. The discussion explored how biotechnology can truly benefit humanity in the coming decades.</p>



<p>The Congress lectures are related to specific examples and problems that scientists are struggling with in daily lives – for example, how to easily delude artificial intelligence in software in an unmanned vehicle resulting in a failure to recognize a STOP sign</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="483" src="https://www.kg-legal.eu/wp-content/uploads/2025/09/17mzrsqhz99v3xkgvk2gwyzoxvvm-1024x483.png" alt="" class="wp-image-8326" srcset="https://www.kg-legal.eu/wp-content/uploads/2025/09/17mzrsqhz99v3xkgvk2gwyzoxvvm-1024x483.png 1024w, https://www.kg-legal.eu/wp-content/uploads/2025/09/17mzrsqhz99v3xkgvk2gwyzoxvvm-300x142.png 300w, https://www.kg-legal.eu/wp-content/uploads/2025/09/17mzrsqhz99v3xkgvk2gwyzoxvvm-768x362.png 768w, https://www.kg-legal.eu/wp-content/uploads/2025/09/17mzrsqhz99v3xkgvk2gwyzoxvvm.png 1034w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>source: <a href="https://www.drmalinowski.edu.pl/posts/2824-adwersarialne-ataki-na-sztuczna-inteligencje">https://www.drmalinowski.edu.pl/posts/2824-adwersarialne-ataki-na-sztuczna-inteligencje</a></p>



<p></p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/optical-illusions-in-ai-systems-the-danger-of-adversarial-attacks-biological-technologies-explainable-ai-topics-discussed-during-futurology-congress-2025/">Optical Illusions in AI Systems, the Danger of Adversarial Attacks, Biological Technologies, Explainable AI – topics discussed during Futurology Congress 2025</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/optical-illusions-in-ai-systems-the-danger-of-adversarial-attacks-biological-technologies-explainable-ai-topics-discussed-during-futurology-congress-2025/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybersecurity and GDPR Compliance in 2025</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 20 Aug 2025 16:11:16 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[CRA]]></category>
		<category><![CDATA[eIDAS]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8192</guid>

					<description><![CDATA[<p>Publication date: August 20, 2025 In an era of dynamic digital technology development and a growing number of cyberthreats, cybersecurity and personal data protection are becoming key aspects of how organizations operate in the European Union. New regulations, such as NIS2, DORA, AI Act, CRA, and eIDAS 2.0, combined with the current GDPR, create a [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/">Cybersecurity and GDPR Compliance in 2025</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: August 20, 2025</mark></strong></p>



<p>In an era of dynamic digital technology development and a growing number of cyberthreats, cybersecurity and personal data protection are becoming key aspects of how organizations operate in the European Union. New regulations, such as NIS2, DORA, AI Act, CRA, and eIDAS 2.0, combined with the current GDPR, create a comprehensive security system aimed at raising protection standards and ensuring greater transparency in data processing.</p>



<span id="more-8192"></span>



<p><strong>NIS2 and GDPR: Strengthening Data Protection and Incident Response</strong></p>



<p>The Network and Information Security Directive (NIS2) is another step towards increasing the cyber resilience of entities operating in key economic sectors. In 2025, its implementation will require organizations to take a number of actions, including:</p>



<ul class="wp-block-list">
<li>Expanding security measures against cyberattacks,</li>



<li>Introducing more rigorous incident reporting procedures,</li>



<li>Strengthening cooperation between supervisory authorities and the private sector.</li>
</ul>



<p>NIS2, in conjunction with GDPR (Regulation 2016/679), means that businesses will not only have to protect personal data more effectively, but also implement new procedures for risk management and auditing of IT security activities.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>5 Things You Need to Know About NIS2</strong></p>



<p><strong>01 </strong>– Fines up to <strong>€10 million or 2% of total annual global turnover</strong></p>



<p><strong>02 </strong>– <strong>Expanded scope </strong>compared to NIS1, changing the way companies are classified and requiring more of them to comply with the directives</p>



<p><strong>03 </strong>– Management staff <strong>is liable for violations </strong>and the authorities may <strong>suspend activities or functions</strong></p>



<p><strong>04 </strong>– Broad <strong>security risk management measures </strong>and shift to a risk-based approach</p>



<p><strong>05 </strong>– Initial reporting <strong>of security incidents within 24 hours</strong>, further action within <strong>72 hours</strong>, and final summary <strong>within 1 month</strong></p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>DORA: Cyber Resilience and Personal Data Security in Finance</strong></p>



<p>DORA is the Regulation of the European Parliament and of the Council (EU) of 14 December 2022 on the digital operational resilience of the financial sector. This is another of many recent regulations concerning cybersecurity and the broadly defined security of information technology.</p>



<p>The Digital Operational Resilience Act (DORA) focuses on the financial sector, which is particularly vulnerable to cyberattacks. Key requirements imposed by DORA include:</p>



<ul class="wp-block-list">
<li>Testing the operational resilience of IT systems,</li>



<li>Implementing risk management strategies based on threat analysis,</li>



<li>Obligation to monitor and report digital incidents.</li>
</ul>



<p>DORA applies to:</p>



<ol style="list-style-type:lower-alpha" class="wp-block-list">
<li>credit institutions;</li>



<li>payment institutions, including payment institutions exempted under <a href="https://sip-1lex-1pl-18l00itm9016d.extranet.rajska.info/#/document/68589670?cm=DOCUMENT">Directive </a>(EU) 2015/2366;</li>



<li>providers of account information access services;</li>



<li>electronic money institutions, including electronic money institutions exempted under <a href="https://sip-1lex-1pl-18l00itm9016d.extranet.rajska.info/#/document/67903621?cm=DOCUMENT">Directive </a>2009/110/EC;</li>



<li>investment companies;</li>



<li>crypto-asset service providers,</li>



<li>central securities depositories;</li>



<li>central counterparties;</li>



<li>trading systems;</li>



<li>transaction repositories;</li>



<li>alternative investment fund managers;</li>



<li>management companies;</li>



<li>information sharing service providers;</li>



<li>insurance and reinsurance undertakings;</li>



<li>insurance intermediaries, reinsurance intermediaries and ancillary insurance intermediaries;</li>



<li>institutions of occupational pension programs;</li>



<li>rating agencies;</li>



<li>administrators of critical benchmarks;</li>



<li>crowdfunding service providers;</li>



<li>securitization repositories;</li>



<li>external ICT service providers.</li>
</ol>



<p>In the context of GDPR compliance, financial institutions must ensure adequate security measures to protect customer data against unauthorized access and information leakage. GDPR also mandates cooperation with cloud service providers and external IT operators, which requires thorough verification of their security standards.</p>



<p>Article 33 of the DORA Directive requires personal data breaches to be reported without undue delay, and within 72 hours where possible. In the event of a delay, an explanation of the reason for the delay must be included.</p>



<p class="has-vivid-cyan-blue-background-color has-background has-medium-font-size"><strong><mark>AI Act and GDPR: Managing Artificial Intelligence and Data Protection</mark></strong></p>



<p>The AI Act regulations classify AI systems according to risk level and impose obligations on entities that implement them. In the context of data protection, the AI Act requires:</p>



<ul class="wp-block-list">
<li>Transparency of artificial intelligence algorithms and mechanisms,</li>



<li>Possibilities of controlling and auditing decisions made by AI,</li>



<li>Compliance with the principles of data minimization and limitation of the processing purpose.</li>
</ul>



<p>Companies that use AI to process personal data will have to meet stringent GDPR requirements, giving users greater control over their information and minimizing the risk of abuse.</p>



<p><strong>CRA: Cyber Resilience Act – Security of Digital Products</strong></p>



<p>The Cyber Resilience Act (CRA) introduces obligations related to the security of digital software and hardware. Its key requirements include:</p>



<ul class="wp-block-list">
<li>Designing secure digital products,</li>



<li>Monitoring vulnerabilities and updating them regularly,</li>



<li>Manufacturers&#8217; responsibility to ensure continued safety throughout the product life cycle.</li>
</ul>



<p>CRA aims to increase cybersecurity across the entire digital ecosystem, minimizing the risk of attacks based on device and application vulnerabilities.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>eIDAS 2.0: Strengthening digital identification</strong></p>



<p>The amendment to the eIDAS (electronic IDentification, Authentication and trust Services) regulation – known as eIDAS 2.0 – introduces a European digital identity wallet that:</p>



<ul class="wp-block-list">
<li>Allows citizens to securely store and share their identity data,</li>



<li>It enables public and private institutions to provide secure online services,</li>



<li>Strengthens authentication standards in digital transactions.</li>
</ul>



<p>In conjunction with GDPR, eIDAS 2.0 improves users&#8217; control over their identity data and increases the security of online transactions.</p>



<p><strong>Challenges and benefits of new regulations</strong></p>



<p>Adapting to new regulations poses numerous challenges for companies, including:</p>



<ul class="wp-block-list">
<li>The need to invest in modern security systems,</li>



<li>Employee training in cybersecurity and data protection,</li>



<li>Implementation of effective incident monitoring and reporting mechanisms.</li>
</ul>



<p>However, the new regulations also bring numerous benefits, such as:</p>



<ul class="wp-block-list">
<li>Better protection of customer data and greater trust in the organization,</li>



<li>Increased resistance to cyber attacks,</li>



<li>Possibility to avoid high fines for violating data protection regulations.</li>
</ul>



<p><strong>The impact of new regulations on small and medium-sized enterprises (SMEs)</strong></p>



<p>New regulations such as NIS2, DORA, AI Act, CRA, and eIDAS 2.0 can pose challenges for small and medium-sized enterprises (SMEs). Implementing these regulations requires investment in modern security systems and employee training in cybersecurity and data protection. SMEs may face challenges related to limited financial and human resources, which can make it difficult to fully comply with the new requirements.</p>



<p>However, compliance with these regulations also brings benefits, such as better protection of customer data, increased trust in the organization, and the ability to avoid significant fines for violating data protection regulations. Therefore, it is worthwhile for SMEs to consider partnering with external IT service providers and cybersecurity specialists to effectively implement the required security measures.</p>



<p><strong>The future of cybersecurity in the EU</strong></p>



<p>In the coming years, we can expect further development of regulations regarding cybersecurity and personal data protection. The European Union will continue to work on strengthening the legal framework to address growing cyber threats and ensure a high level of data protection. Organizations will need to be prepared to continuously adapt to new requirements and invest in modern security technologies and procedures.</p>



<p><strong>Summary</strong></p>



<p>In 2025, organizations will have to comply with a range of regulations regarding cybersecurity and personal data protection. NIS2, DORA, AI Act, CRA, and eIDAS 2.0, combined with the GDPR, create a modern legal framework aimed at improving data protection and increasing resilience to cyber threats across various economic sectors. Implementing these regulations will be a challenge, but also an opportunity, to build a more secure and digitally resilient business environment in the EU.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/">Cybersecurity and GDPR Compliance in 2025</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/cybersecurity-and-gdpr-compliance-in-2025/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
