<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AI Compliance - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/ai-compliance/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/ai-compliance/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Fri, 24 Jul 2026 18:27:14 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Lootboxes in Computer Games – Between Gambling Law and Consumer Protection. Regulatory Analysis Against the Background of Polish and European Union Law.</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 18:26:30 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[behavioural design]]></category>
		<category><![CDATA[children online protection]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital fairness]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[eSports law]]></category>
		<category><![CDATA[EU digital regulation]]></category>
		<category><![CDATA[EU gaming law]]></category>
		<category><![CDATA[gacha games]]></category>
		<category><![CDATA[gambling law]]></category>
		<category><![CDATA[gaming compliance]]></category>
		<category><![CDATA[gaming compliance Europe]]></category>
		<category><![CDATA[gaming industry regulation]]></category>
		<category><![CDATA[gaming law]]></category>
		<category><![CDATA[gaming legal advice]]></category>
		<category><![CDATA[gaming taxation]]></category>
		<category><![CDATA[international gaming law]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kieltyka gladkowski]]></category>
		<category><![CDATA[loot box regulation]]></category>
		<category><![CDATA[Loot boxes]]></category>
		<category><![CDATA[microtransactions]]></category>
		<category><![CDATA[online gaming regulation]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Polish gaming law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[skin gambling]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[video game law]]></category>
		<category><![CDATA[video game monetisation]]></category>
		<category><![CDATA[virtual assets]]></category>
		<category><![CDATA[virtual economy]]></category>
		<category><![CDATA[virtual items]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8861</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 The dynamic development of the computer games market has led to a significant change in the monetization models used by game producers and publishers. The traditional sales model, based on a one-time purchase of a product by the consumer, has been largely replaced by solutions based on long-term user engagement [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/">Lootboxes in Computer Games – Between Gambling Law and Consumer Protection. Regulatory Analysis Against the Background of Polish and European Union Law.</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 24, 2026</strong></mark></p>



<p>The dynamic development of the computer games market has led to a significant change in the monetization models used by game producers and publishers. The traditional sales model, based on a one-time purchase of a product by the consumer, has been largely replaced by solutions based on long-term user engagement and generating revenue through micropayments (microtransactions). Mechanisms known as loot boxes, consisting in the paid purchase of virtual packages with random content.</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="692" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-1024x692.jpg" alt="" class="wp-image-8863" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-1024x692.jpg 1024w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-300x203.jpg 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-768x519.jpg 768w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-1536x1038.jpg 1536w, https://www.kg-legal.eu/wp-content/uploads/2026/07/waszyngton-1-2048x1385.jpg 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<span id="more-8861"></span>



<p>Although initially perceived as a means of enhancing gameplay, this mechanism is currently the subject of intense legal, economic, and social debate. It is increasingly being pointed out that the design of loot boxes utilizes psychological mechanisms similar to those that have been present in traditional gambling games for many years. The random nature of the reward, the uncertainty of the outcome, the &#8220;near miss&#8221; effect, the limited availability of certain items, and the use of dynamic animations intended to enhance the user&#8217;s emotional engagement all contribute to the blurring of the line between entertainment and gambling mechanisms.</p>



<p>Additional controversy stems from the fact that the vast majority of modern games using loot boxes are also aimed at minors. Unlike traditional gambling games, participation in these mechanisms does not require a specific age or meeting specific formal requirements. In practice, this means that random monetization mechanisms are also used by children and adolescents, who, due to their stage of psychological development, are particularly susceptible to the influence of behavioral design techniques and so-called dark patterns).</p>



<p>In recent years, the issue of loot boxes has ceased to be analyzed solely through the prism of gambling law. Regulations concerning consumer protection, digital services, and child safety in the online environment are gaining increasing importance. Discussions at the European Union level indicate that the future legal framework may be based not only on classic definitions of games of chance but also on instruments to combat manipulative practices and ensure a high level of protection for consumers using digital services.</p>



<p>At the national level, the problem remains equally relevant. Polish lawmakers have not yet decided to introduce a separate definition of loot boxes into <strong>the Gambling Ac</strong>t of 19 November 2009. This does not mean, however, that these mechanisms remain entirely outside the scope of existing regulations. In practice, administrative bodies assess each specific business model on a case-by-case basis, analyzing whether its design meets the statutory definition of gambling. At the same time, the development of the secondary market for trading in virtual items, particularly so-called skin gambling , is creating new interpretative challenges that the legislature did not anticipate when enacting the current regulations.</p>



<p>The changes introduced by the <strong>PEGI rating system in 2026</strong> provided an additional impetus for reassessing the current regulations. The revised rules for classifying games with paid random mechanisms confirm the growing awareness of the risks associated with the use of loot boxes, especially for underage users. Although the PEGI rating is not a source of generally applicable law, its practical importance for the European market remains significant and may influence both the distribution of games and the future direction of legislative changes.</p>



<p>The purpose of this article is to analyze the current legal status of loot boxes under Polish and European Union law, taking into account recent regulatory changes, the practices of administrative bodies, and the experiences of selected European countries. Particular attention will be paid to whether the current regulations effectively protect consumers from mechanisms based on randomness and whether the current regulatory model meets the challenges of the modern digital economy.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The essence of loot boxes and their functioning models</strong></p>



<p>The concept <em>of a lootbox </em>has not yet been defined in either Polish or European Union law. However, in the literature and by public institutions, it is generally accepted that a lootbox is a mechanism whereby the user obtains, for a fee or free of charge, a virtual package containing items whose contents remain unknown until opened. A characteristic element of this solution is randomness – the user has no influence on the item they receive, and the probability of obtaining individual rewards is determined by the game developer or platform operator.</p>



<p>At the definitional level, however, it should be emphasized that the term &#8220;lootbox&#8221; encompasses a wide variety of business models, the legal assessment of which cannot be uniform. Public debate often equates all mechanisms based on randomness with gambling, while from a legal perspective, individual solutions differ in both their economic structure and the degree of risk to the consumer. It is precisely this diversity that means that assessing the compliance of lootboxes with applicable regulations requires an analysis of the specific operational model, not just the presence of a random element.</p>



<p>The most classic model occurs in games where lootbox content is limited solely to cosmetic items, such as skins , animations, character outfits, or visual effects. These items do not affect gameplay or increase the player&#8217;s chances of success. They are intended solely for aesthetic purposes, allowing the user to personalize the appearance of their character or equipment. Such solutions were long considered relatively safe from a consumer protection perspective, but the development of secondary markets for trading virtual items has significantly changed their economic significance.</p>



<p>A good example is the <em>Counter-Strike series</em>, where weapon skins initially served only a visual purpose. Over time, however, a robust secondary market developed around these items, allowing them to be sold for real money. Consequently, the value of some virtual items began to reach several thousand, or even several dozen thousand, and in exceptional cases, several hundred thousand euros. In practice, this means that a randomly acquired item can have a tangible financial value, even though the game developer itself does not officially allow for its sale. The existence of an external market is one of the main arguments raised in the discussion on the classification of such mechanisms as potentially akin to gambling.</p>



<p>Loot boxes used in sports games, such as <em>EA SPORTS FC Ultimate Team, </em>are of a different nature. In this model, users purchase virtual packs containing player cards, coaches, or other team items. Unlike skins in games like <em>Counter-Strike</em>, acquired items directly impact gameplay. Acquiring rare players can increase a team&#8217;s competitiveness and improve player performance. Although the developer publishes information regarding the probability of receiving rewards in a given category, the user still doesn&#8217;t know the contents of a specific pack at the time of purchase, and the decision to purchase is based on a random mechanism.</p>



<p>Yet another model is found in so-called <em>gacha games</em>, extremely popular, especially in Asian markets and in the mobile gaming segment. This mechanism is based on randomization of characters, equipment, or other items necessary for further progression in the game. A characteristic feature of <em>gacha systems </em>is their close connection to long-term user monetization. Players are encouraged to repeatedly make micropayments to obtain exceptionally rare characters or items, the probability of obtaining which can be extremely low. The literature indicates that these solutions most fully utilize the mechanisms of behavioral economics and the psychology of addiction.</p>



<p>However, the most controversial are third-party platforms that enable the trading of virtual items and participation in games of chance that use items from video games as a form of currency. These services operate independently of game developers, leveraging the existing market for skins or other digital goods to organize mechanisms reminiscent of classic casino games. Users deposit funds or use their virtual items to participate in lotteries, roulette, duels, or other games based on chance. Unlike traditional loot boxes offered by game producers, the participant&#8217;s goal is not only to obtain a specific item but often to achieve a tangible economic benefit resulting from the possibility of reselling it.</p>



<p>From a legal perspective, the differences between the presented models are crucial. Not every mechanism employing an element of randomness automatically leads to its classification as gambling. Factors that should be assessed include, first and foremost, the potential for financial gain, the existence of a secondary market, the method of financing participation, the possibility of withdrawing funds, and the actual impact of randomness on achieving a specific outcome. In practice, this means a case-by-case analysis of the specific business model, rather than adopting a uniform classification for all types of loot boxes .</p>



<p>This approach is also reflected in the practice of many European countries. Both administrative bodies and courts are increasingly moving away from abstract assessments of the lootbox mechanism itself, focusing instead on analyzing their actual operation and impact on consumer interests. Consequently, the current legal debate no longer revolves around the question of whether lootboxes as a category should be considered gambling, but rather which monetization models justify their inclusion in a specific regulatory regime.</p>



<h2 class="wp-block-heading has-pale-cyan-blue-background-color has-background"><strong>Loot boxes and the definition of gambling in Polish law</strong></h2>



<p>Assessing the compliance of lootbox mechanisms with Polish law requires, above all, an analysis of the provisions of the Gambling Act of 19 November 2009. Although the legislature has not yet decided to introduce a separate definition of lootboxes, this does not mean that these mechanisms remain outside the scope of applicable regulations. On the contrary, in practice, their legal classification depends on whether the specific operating model meets the criteria for one of the games specified in the Act.</p>



<p>The basic premise of the Gambling Act is to subject activities in which the outcome depends on chance to a specific regime, and the participant gains the opportunity to obtain a specific financial or material benefit. The Act does not use the term &#8220;lootbox&#8221; because it was enacted at a time when modern computer game monetization models were practically nonexistent. This necessitates a functional interpretation, taking into account the economic nature of the mechanism in question, not just its name or the technical solutions adopted by the game developer.</p>



<p>A key element of most loot boxes is undoubtedly randomness. The user making the purchase neither knows the contents of the package nor has the ability to influence the outcome of the drawing. However, the mere presence of a random element is not sufficient to classify a given mechanism as gambling. In practice, the nature of the prize received by the participant and the ability to assign it a real economic value are equally important.</p>



<p>This is where a fundamental difference between classic loot boxes offered by game developers and the mechanisms used by third-party platforms for trading virtual items becomes apparent. If the item obtained through a draw has a purely aesthetic function and cannot be legally exchanged for cash or used outside of the game environment, the arguments for classifying such a mechanism as gambling are significantly weaker. The situation is different when the item is de facto a property that can be freely traded on the secondary market, yielding a real financial benefit.</p>



<p>In practice, the greatest controversy surrounds so-called <em>skin gambling</em>. In this model, users use items obtained in-game as a means of participating in subsequent games of chance organized by third parties. Skins, which were originally purely cosmetic, are beginning to function as a kind of digital currency with measurable economic value. This mechanism leads to a situation in which participants risk losing items of real-world value in exchange for the opportunity to win an even more valuable reward. This structure bears a much greater resemblance to classic gambling games than the traditional <strong>micropayment systems used by game developers.</strong></p>



<p>At the same time, caution should be exercised before drawing too far-reaching conclusions. The mere existence of a secondary market does not automatically mean that every loot box should be classified as gambling. From a legal perspective, a case-by-case analysis of the entire business model is necessary, including, among other things, the method of acquiring virtual items, the possibility of their resale, the role of the game producer, the scope of control over the trade in digital assets, and the actual economic significance of the rewards. Consequently, two mechanisms utilizing an identical element of randomness may be subject to entirely different legal assessments.</p>



<p>This position is also reflected in the practice of <strong>Polish administrative bodies</strong>. To date, there has been no established practice of automatically classifying all loot boxes as gambling. Authorities focus instead on analyzing specific business models and assessing whether they meet the requirements of applicable regulations. This approach reflects the nature of the Gambling Act, which uses functional definitions, leaving authorities considerable scope for assessing individual factual circumstances.</p>



<p>In this context, the practice of entering certain online platforms into<strong> the Register of Domains Used to Offer Gambling Games</strong> <strong>in Contravention of the Act</strong> has become particularly significant. However, such an entry does not mean that all platforms utilizing the element of randomness conduct illegal activities. Each decision is preceded by an assessment of the specific operational model of the given service. Consequently, it cannot be assumed that the lootbox mechanism itself has been deemed illegal in Poland. It is not the abstract technical structure that is being assessed, but rather its practical application.</p>



<p>Under current law, it seems more appropriate to ask not whether loot boxes per se constitute gambling, but which of their numerous operating models demonstrate characteristics that justify the application of the provisions of the Gambling Act. This approach avoids oversimplification and better reflects the reality of the digital market, where solutions with widely varying levels of risk to consumers coexist.</p>



<p>At the same time, it should be noted that even if a given mechanism does not meet the criteria for gambling within the meaning of the Act, this does not mean there is a lack of legal oversight. Modern regulations increasingly refer to consumer protection instruments, counteracting manipulative practices, and ensuring the safety of children using digital services. Therefore, analysis of loot boxes cannot be limited solely to gambling law. Regulations regarding consumer protection, digital services, and designing interfaces in accordance with fair trading principles are gaining increasing importance, and in many cases, they may prove to be a more effective tool for protecting users than traditional gambling law instruments.</p>



<p class="has-luminous-vivid-amber-background-color has-background"><strong>Loot boxes as a challenge to consumer protection law and the regulation of digital services</strong></p>



<p>Although the debate surrounding loot boxes has for many years focused primarily on gambling law, a shift in regulatory direction is now becoming increasingly apparent, both at the national and European Union levels. Contemporary challenges related to random mechanisms in computer games concern not only the classification of specific models as gambling, but also the compliance of the practices employed with the principles of consumer protection, the protection of minors, and the fair design of digital services.</p>



<p>This change is primarily due to the development of the digital economy. The mechanisms used by game producers are increasingly based not on traditional product sales, but on long-term user engagement and gradual increase in spending through appropriately designed psychological solutions. This phenomenon is referred to in the literature as <em>behavioral monetization</em>, or monetization that leverages knowledge from cognitive psychology and behavioral economics. The goal of such mechanisms is not simply to facilitate a purchase, but to create an environment that encourages users to make subsequent purchasing decisions impulsively or emotionally.</p>



<p>Of particular importance in this regard are so-called <em>dark patterns</em>, <strong>referred to in Polish literature as manipulative or deceptive design patterns</strong>. These design solutions exploit the workings of human perception and decision-making processes to induce behaviors that are beneficial to the entrepreneur, but not necessarily aligned with the consumer&#8217;s true interests. In the case of loot boxes, these can take a variety of forms – from counters counting down the time until the end of a promotion, through messages about the limited availability of specific rewards, to elaborate animations that enhance the emotional experience of opening the packages.</p>



<p>These mechanisms are not coincidental. Psychological research indicates that a reward system based on a <strong>variable ratio reinforcement</strong> schedule is one of the most effective ways to maintain long-term user engagement. This same mechanism has been used for many years in classic gambling games, where the unpredictability of rewards maintains a high level of motivation for subsequent attempts. In the case of loot boxes, this mechanism is transferred to the computer gaming environment and combined with an attractive audiovisual setting and the ability to immediately make another purchase.</p>



<p>From the perspective of <strong>consumer protection law</strong>, a crucial question is whether the use of such solutions could lead to a violation of traders&#8217; obligations arising from provisions on fair market practices. It should be noted that contemporary EU regulations increasingly place greater emphasis not only on the content of information provided to consumers, but also on the design of digital interfaces. Therefore, the subject of assessment is increasingly not the product or service itself, but rather the architecture of the purchasing process and the impact of the interface on the user&#8217;s freedom of decision-making.</p>



<p>Underage users are particularly important here. Both the European Commission and the European Parliament have repeatedly stated that children using digital services require a higher level of protection than the average consumer. This stems from their limited ability to assess economic risk and their greater susceptibility to persuasive techniques used by businesses. In practice, this means that solutions acceptable to adult users may be deemed disproportionate or unfair if they are primarily targeted at children and adolescents.</p>



<p>The importance of this issue has increased following the entry into force of <strong>Regulation (EU) 2022/2065 on the Digital Single Market (Digital Services Act – DSA)</strong>. Although this act does not explicitly regulate lootbox mechanisms, <strong>it establishes a number of obligations regarding the design of digital services</strong> and the protection of users from practices that may negatively impact their decision-making autonomy. In particular, the DSA emphasizes the need to ensure a high level of protection for minors and limit the use of solutions that exploit the vulnerabilities of specific user groups. This trend indicates that future assessments of the legality of lootboxes will increasingly be conducted not only through the lens of gambling law but also taking into account consumer protection standards applicable in the digital environment.</p>



<p>In parallel, the European Commission is working on a legislative package known as <strong>Digital Fairness</strong>, which aims to adapt EU consumer protection regulations to the realities of the digital economy. Issues under review include manipulative design patterns, interface design that exploits user vulnerability, and mechanisms that exert excessive psychological pressure during purchasing decisions. Although the legislative work has not yet been completed, the direction of the proposed changes clearly indicates that future regulations may also cover monetization mechanisms used in video games.</p>



<p>The European Parliament also highlighted the need to enhance the protection of minors in its resolution of 26 November 2025 on the protection of children online. The document indicated that mechanisms such as loot boxes, in-game currencies, and other systems based on chance should be subject to special scrutiny from the perspective of protecting children from addictive and manipulative digital practices. While the resolution is non-binding, it provides an important political signal indicating the direction of future legislative action at the European Union level.</p>



<p>A separate but crucial element of the modern user protection system is the <strong>PEGI age rating</strong>. Starting in 2026, this system will adopt a more stringent approach to games featuring paid random mechanisms, recognizing them as solutions requiring a higher age rating. While the PEGI rating is not a source of law and does not in itself determine the legality of specific monetization models, it reflects a growing consensus on the need to provide greater protection for minors from mechanisms that utilize randomness and behavioral design techniques.</p>



<p>The above circumstances lead to the conclusion that the future of loot box regulation will likely be shaped primarily by regulations concerning consumer protection and digital services, rather than solely by traditional gambling law instruments. While the Gambling Act focuses on the qualification of specific business models, contemporary EU regulations increasingly assess the design of digital services and their impact on the autonomy of user decisions. Consequently, assessing the legality of loot boxes in the future will require comprehensive consideration of both gambling law and regulations concerning consumer protection, digital services, and children&#8217;s rights.</p>



<h3 class="wp-block-heading"><strong>Approach of selected European countries to regulating loot boxes – a comparative analysis</strong></h3>



<p>The lack of a uniform definition of loot boxes in European Union law has led individual member states to develop different models for regulating this phenomenon. These differences concern not only the legal classification of random-based mechanisms but, above all, the assessment of the risks loot boxes pose to consumers, especially minors. As a result, the European Union currently boasts both countries adopting a very restrictive approach and jurisdictions that prefer to analyze individual business models rather than create separate statutory regulations.</p>



<p>Belgium has taken the most stringent stance for many years. The Belgian Gaming Commission <em>has determined that </em>certain lootbox mechanisms meet the criteria for gambling if the participant pays a fee, the outcome depends on chance, and the reward represents a specific economic value. Consequently, some game producers have decided to remove paid lootboxes from the Belgian market or significantly limit their functionality. This solution was primarily preventative in nature and aimed at limiting children and adolescents&#8217; exposure to mechanisms that utilize randomness as a monetization tool .</p>



<p>The Dutch experience was different. For many years, the Dutch supervisory authority took a similar stance to the Belgian one, deeming certain lootbox models to be in violation of gambling regulations. The dispute concerned one of the most popular monetization models used by Electronic Arts became the subject of years of administrative and court proceedings. However, the final rulings demonstrated that the classification of loot boxes cannot be based solely on the presence of an element of randomness, but requires consideration of the overall economic structure of the game, the method of trading virtual goods, and the actual potential for financial gain for the user. The Dutch experience thus highlighted the difficulties associated with applying traditional definitions of gambling law to new business models operating in the digital economy.</p>



<p>At the opposite extreme is the approach adopted <strong>in Poland. To date, Polish lawmakers have not decided to create separate regulations regarding loot boxes or introduce a statutory definition</strong>. This means that the assessment of individual models is based on applicable gambling regulations and an analysis of the specific factual circumstances. This approach provides administrative bodies with significant interpretative flexibility, but also limits predictability for businesses operating in the digital market.</p>



<p>The practice of Polish authorities indicates that a functional assessment of the specific business model is crucial. In the case of platforms enabling the use of virtual items as a means of participating in games of chance, authorities may apply the instruments provided for in the Gambling Act, including entry into the Register of Domains Used to Offer Gambling Games Contrary to the Act. However, this does not automatically mean that all loot boxes used in computer games are illegal. The Polish model is therefore based on an analysis of the economic impact of a given solution, not on an abstract assessment of the randomness mechanism itself.</p>



<p>An analysis of the solutions adopted in individual countries leads to the conclusion that what is becoming increasingly important is not simply classifying loot boxes as gambling, but rather protecting consumers from the psychological mechanisms that lead to excessive spending or compulsive behavior. Therefore, many countries are beginning to perceive the loot box problem as an issue that goes beyond traditional gambling law and requires the use of instruments appropriate to consumer law and digital market regulation.</p>



<p>This approach also aligns with actions undertaken at the European Union level. The European Commission and the European Parliament increasingly point out that the fragmentation of national regulatory models can lead to uneven levels of user protection in the digital single market. The global nature of game producers&#8217; operations means that businesses operate simultaneously in multiple markets, adapting their business models to the most stringent requirements in force in individual countries. In practice, this means that future legal solutions will likely aim for greater harmonization of consumer protection standards at the EU level.</p>



<p>However, this doesn&#8217;t mean a complete ban on loot boxes is necessary. A much more likely approach would be to introduce requirements regarding the transparency of random mechanisms, the publication of actual reward probabilities, more effective age verification of users, and restrictions on the use of solutions that exploit the vulnerability of children and adolescents to persuasive techniques. Such a regulatory model would preserve the possibility of using micropayments as a legal method of financing computer games while simultaneously strengthening consumer protection.</p>



<p>From the perspective of Polish law, the experiences of other European countries have significant interpretative significance. They demonstrate that mechanisms operating at the intersection of gambling and digital services cannot be assessed solely through the lens of classic legal constructs developed for traditional casinos or lotteries. The development of the digital economy requires a more comprehensive approach, taking into account both the economic significance of virtual goods and the impact of interface design on consumer decisions. Consequently, the future model for regulating loot boxes will likely be based on a combination of instruments from gambling law, consumer protection law, and regulations governing digital services, rather than the exclusive application of one of these legal regimes.</p>



<h2 class="wp-block-heading"><strong>Conclusions <em>de lege lata </em>and postulates <em>de lege ferenda</em></strong></h2>



<p>The analysis leads to the conclusion that current Polish law does not allow for a uniform legal classification of all lootbox mechanisms. Despite the growing number of voices calling for the recognition of lootboxes as a form of gambling, the current legal status does not provide a basis for automatically subjecting this entire product category to the provisions of the Gambling Act of 19 November 2009. Each assessment requires consideration of the actual operation of the specific business model, the nature of the prize, the potential for further turnover, and the economic impact of user participation in the random mechanism.</p>



<p>This doesn&#8217;t mean, however, that the current regulations remain entirely insufficient. With respect to some models operating on the market &#8211; particularly platforms that use virtual items as a means of participating in games of chance or enabling their exchange for cash &#8211; current regulations may be applicable. The practice of administrative bodies to date demonstrates that the Gambling Act remains an instrument that helps counteract the riskiest forms of activity, especially when virtual goods begin to function as an equivalent of money or property.</p>



<p>At the same time, it&#8217;s important to note that the vast majority of modern loot boxes don&#8217;t pose a classic gambling law problem. Their primary purpose isn&#8217;t to organize games of chance in the traditional sense, but to create a monetization model that leverages psychological mechanisms that increase user propensity to make subsequent purchases. For this reason, the current regulatory debate is increasingly shifting from gambling law toward consumer protection law and the regulation of digital services.</p>



<p>It seems that this is precisely the direction that Polish lawmakers should also adopt. Attempting to classify all loot boxes as gambling would oversimplify the extremely diverse digital market. A much more rational solution seems to be creating separate regulatory obligations for mechanisms that utilize randomness, without the need for automatic application of the entire gambling law regime.</p>



<p>First and foremost, it seems reasonable to introduce full transparency into random mechanisms. Before making a purchase, users should be able to familiarize themselves with the actual probability of winning individual prizes, how the randomization algorithm works, and whether this probability remains constant for all participants. Such solutions already exist in some computer games, but currently they are primarily driven by voluntary decisions by businesses or requirements in specific foreign markets.</p>



<p>The second direction of change should be to strengthen the protection of underage users. In light of current psychological knowledge and the positions of EU institutions, there is little doubt that children are particularly susceptible to the influence of mechanisms based on a variable reward system. Therefore, it seems reasonable to consider limiting the ability of people under a certain age to purchase paid loot boxes or introducing mandatory parental control mechanisms to effectively manage minors&#8217; expenses.</p>



<p>Regardless of the above, legislators should consider introducing more detailed regulations regarding third-party platforms enabling the trading of virtual items. It is this market segment that currently raises the greatest concerns from the perspective of consumer protection and compliance with the Gambling Act. In particular, situations in which items obtained in-game become a means of participation in subsequent games of chance or can be directly converted into cash require analysis. In such cases, the line between a digital service and gambling activity becomes significantly blurred, justifying the application of more restrictive oversight measures.</p>



<p>Obligations regarding marketing activities should also be a crucial element of future regulations. In practice, loot boxes are primarily promoted through influencers and online creators, whose audiences often include minors. While advertising collaborations in and of themselves cannot be deemed unacceptable, situations in which marketing messages exclusively emphasize the possibility of winning exceptionally valuable prizes, disregarding the actual probability of winning them, or employing techniques that could create unreasonable expectations among recipients regarding potential benefits, require special consideration. In this regard, both consumer protection regulations and regulations regarding the integrity of advertising messages may apply.</p>



<p>The issues presented demonstrate that the issue of loot boxes is not limited to gambling law. In fact, it exemplifies a much broader phenomenon involving the use of advanced digital design techniques to influence users&#8217; economic decisions. Technological advancements increasingly render traditional private and public law frameworks inadequate for assessing new business models based on user behavior analysis and interface design that maximizes consumer engagement and spending.</p>



<p>Consequently, the future of loot box regulation will likely depend less on further expansion of the definition of gambling than on the development of European consumer protection standards in the digital environment. Regulations on the transparency of digital services, countering manipulative design patterns, and ensuring a high level of protection for children using the internet are becoming increasingly important . These instruments may become the primary tool for mitigating the risks associated with loot box operations in the coming years.</p>



<p>It should therefore be assumed that effective regulation of this phenomenon requires a multifaceted approach, combining instruments of gambling law, consumer protection law, and digital market regulation. Only such a comprehensive solution will achieve the right balance between the freedom of game producers to conduct business and the need to ensure a high level of protection for users, particularly children and adolescents, who remain most vulnerable to the negative effects of random-based mechanisms.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/">Lootboxes in Computer Games – Between Gambling Law and Consumer Protection. Regulatory Analysis Against the Background of Polish and European Union Law.</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/lootboxes-in-computer-games-between-gambling-law-and-consumer-protection-regulatory-analysis-against-the-background-of-polish-and-european-union-law/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 11:29:19 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[algorithmic decision-making]]></category>
		<category><![CDATA[algorithmic transparency]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[automated moderation]]></category>
		<category><![CDATA[Central Eastern Europe legal services]]></category>
		<category><![CDATA[compliance by design]]></category>
		<category><![CDATA[consumer protection law]]></category>
		<category><![CDATA[consumer reviews verification]]></category>
		<category><![CDATA[dark patterns]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[digital platforms]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[e-commerce regulation]]></category>
		<category><![CDATA[European Union Law]]></category>
		<category><![CDATA[fake reviews]]></category>
		<category><![CDATA[fake reviews in e-commerce]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[international legal cooperation]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[marketplace regulation]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[online consumer protection]]></category>
		<category><![CDATA[online marketplaces]]></category>
		<category><![CDATA[online reputation management]]></category>
		<category><![CDATA[platform liability]]></category>
		<category><![CDATA[Poland technology law]]></category>
		<category><![CDATA[Polish e-commerce law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[review authenticity]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[unfair commercial practices]]></category>
		<category><![CDATA[uokik]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8830</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 10, 2026</mark></strong></p>



<p>The phenomenon of fake reviews in the digital space has evolved from a marginal image issue to a central focus of market supervision authorities and EU legislators. The contemporary ontology of this phenomenon extends beyond primitive content fabrication to encompass any form of communication that, by distorting the actual consumer experience, misleads the recipient, directly influencing their decision-making process. Legally, a fake review is considered not only a completely false message, but also one that, by omitting important facts or manipulating context, creates a false impression of the quality of a product or the reliability of a seller. This practice is classified as unfair commercial activity if its nature causes or is likely to cause the average consumer to make a transactional decision they would not otherwise make, thus violating the fundamental principles of fair dealing.</p>



<span id="more-8830"></span>



<p>The typology of activities considered unfair rests on several fundamental pillars, the most blatant of which is direct fabrication. This involves posting or commissioning the creation of false recommendations from specialized external entities, such as marketing agencies, which directly violates regulations on combating unfair market practices. Another mechanism is selective manipulation, in which a business intentionally manages the visibility of reviews by removing, concealing, or delaying the publication of negative reviews while favoring positive ones. Such action distorts the image of actual customer satisfaction and is considered misleading regarding the essential characteristics of a product or service. An equally significant aspect is feigned verification, i.e., declaring that reviews come from real buyers without implementing proportionate and reasonable steps to verify their authenticity, which constitutes a direct violation of the disclosure obligations imposed by the Omnibus Directive.</p>



<p>Contemporary market practices have also evolved more subtle forms of manipulation, such as astroturfing, which involves creating artificial social support through employees or store owners posing as independent consumers. These activities often involve the manipulation of user profiles, where images generated by artificial intelligence algorithms are used to authenticate fictitious accounts, creating false social proof. Each of these practices, regardless of their technological sophistication, is subject to strict scrutiny by competition and consumer protection authorities.</p>



<p><strong>The role of the President of the Office of Competition and Consumer Protection and the responsibility of management boards</strong></p>



<p>The President of the Polish Office of Competition and Consumer Protection (UOKiK) serves as a central regulator in the legal system, endowed with rigorous powers to counteract violations of collective consumer interests. The main disciplinary instrument at the authority&#8217;s disposal is an administrative fine, which can be imposed in the amount of 10% of the turnover achieved by the entrepreneur in the financial year preceding the year of issuance of the decision. The amount of the fine is not determined arbitrarily, but rather results from precisely defined criteria, which include, above all, the scale of the violation, its duration, and the degree of intentionality of the perpetrator. Importantly, this fine is intended to serve not only a repressive function but, above all, a preventive and deterrent one, discouraging other market participants from engaging in similar unfair practices involving the manipulation of reviews or misleading as to the authenticity of reviews.</p>



<p>The enforcement procedure in consumer matters is designed to ensure high effectiveness of supervisory activities. A business subject to a sanction is obligated to settle the fine within 14 days of the decision becoming final, which directly contributes to the state budget. A crucial procedural element is the prejudicial nature of the decisions of the President of the Office of Competition and Consumer Protection (UOKiK), which means that the authority&#8217;s findings regarding violations of the law are binding on common courts in compensation cases brought by injured customers. This legal structure significantly facilitates consumers in pursuing civil claims, as they do not have to prove the illegality of the store&#8217;s actions, focusing solely on demonstrating the damage suffered. The office&#8217;s activity in recent years, reflected in numerous proceedings against e-commerce leaders, confirms that protecting the transparency of reviews has become a regulatory priority, translating into real and severe financial consequences for violators.</p>



<p>The contemporary model of liability in consumer protection law departs from a concept focused solely on the business entity, shifting the burden of sanctions also to individuals who actually manage the enterprise. The President of the Office of Competition and Consumer Protection (UOKiK) has the authority to impose a personal fine of up to PLN 2,000,000 on a manager. This liability is triggered by demonstrating that the manager has intentionally allowed – through their actions or conscious omissions – the company to violate collective consumer interests. In case law, the degree of management involvement in decision-making processes regarding marketing and communications is crucial. This liability may therefore affect a management board member who approves a budget for obtaining reviews from external opinion farms or ignores the lack of implementation of verification procedures under the Omnibus Directive, despite being aware of such deficiencies.</p>



<p>It should be emphasized that the responsibility of managers is autonomous and independent of any penalty imposed directly on the entrepreneur. This is intended to provide a strong incentive for management to build internal compliance structures and actively oversee the entity&#8217;s operational ethics. In the era of digitalization of trade, where algorithms and automation of marketing processes can generate violations on a massive scale, the personal financial risk of managers is intended to compel prioritizing compliance as the foundation of business strategy. Therefore, the systemic fight against false reviews is implemented not only through sanctions against corporate structures but also by disciplining those who actually shape companies&#8217; market policies. This, according to the legislature, is intended to ensure long-term improvement in integrity standards in electronic trading.</p>



<p><strong>The Omnibus Directive and the blacklist of market practices</strong></p>



<p>The implementation of the Omnibus Directive into the Polish legal system significantly redefined transparency standards in e-commerce, introducing mechanisms that directly address the systemic manipulation of consumer reviews. A key instrument in this regard is the so-called blacklist of market practices, which constitutes a catalog of behaviors considered unfair in all circumstances, eliminating the need for supervisory authorities to conduct a case-by-case analysis of the consequences of a given action. Classifying these market torts as unfair practices aims to eliminate evidentiary difficulties, as their mere existence exaggerates the entrepreneur&#8217;s wrongdoing. This legal framework not only strengthens the consumer&#8217;s position but, above all, simplifies the evidentiary process, making the fight against e-commerce abuse more effective and predictable for market participants. The foundation of the new regulations is an absolute prohibition on manipulating the verification and authenticity of product recommendations, which imposes an active obligation on sellers to implement procedures to verify the origin of reviews.</p>



<p>Under the current wording of the regulations, it is considered an unfair market practice for a trader to claim that product reviews were posted by consumers who actually used or purchased the product, in situations where reasonable and proportionate steps were not taken to verify their authenticity. This practice violates the consumer&#8217;s right to reliable information, which is essential for making an informed decision about purchasing the product, and violating it constitutes conduct contrary to good practice. The law prohibits not only posting completely false reviews, but also commissioning third parties to create them, or transferring recommendations between products with different parameters, which is referred to as review hijacking. Other offenses listed in the catalog are treated equally severely, such as using false quality certificates without appropriate authorization or using surreptitious advertising, which involves using editorial content to promote a product without clearly identifying the paid nature of the communication. Aggressive techniques are also considered particularly burdensome, including mass spamming and forced selling, which involves demanding payment for products delivered to the consumer without their prior order.</p>



<p>The blacklist also eliminates techniques <strong>such as bait advertising and direct persuasion of children to purchase</strong>, which aims to protect the integrity of the consumer decision-making process from manipulation. This protection of minors stems from their particular vulnerability to advertising messages and their inability to critically assess the persuasive nature of commercial offers. Expanding the list to include a ban on posting or commissioning another person to post false reviews for the purpose of promoting products significantly complements the system, preventing brands from using agencies that fabricate social evidence. It is emphasized that any form of distortion of the actual image of a product&#8217;s popularity constitutes a violation of the collective interests of consumers, which entitles the President of the Office of Competition and Consumer Protection (UOKiK) to intervene under public law as soon as a threat to the interests of all market users arises.</p>



<p>A particularly significant and painful consequence of these unfair techniques for entrepreneurs is a specific civil law sanction in the form of an extended right of withdrawal from the contract. If an e-store engages in practices listed in the prohibited catalog or fails to comply with information obligations regarding review verification, the statutory return period granted to the buyers is extended from 14 days to a full 12 months. This mechanism is a direct consequence of the assumption that, in the absence of reliable information, the consumer could not have expressed a fully informed intention to purchase, which suspends the running of standard mandatory deadlines. Systematic combating of review fraud and the use of black market practices is therefore becoming not only a matter of business ethics but the foundation of legal security and stability for every entity operating in the e-commerce sector. Neglect in transparency can lead to mass claims for refunds, posing a real threat to the operational liquidity of the company.</p>



<p><strong>Manipulation Architecture and Platform Obligations under the Digital Services Act (DSA)</strong></p>



<p>The phenomenon known as dark patterns constitutes a sophisticated form of interference in the user&#8217;s decision-making process, based on the deliberate use of interface architecture to distort their autonomy of will. Manipulative design patterns are not merely a manifestation of aggressive marketing, but a systematic designer&#8217;s action aimed at inducing a specific cognitive bias in the consumer, which ultimately leads to a purchase decision they would not have made in conditions of full transparency. The psychological foundation of these actions is the use of heuristics, i.e., simplified rules of reasoning and automatic thinking, which in the fast-paced environment of e-commerce transactions make the user susceptible to subliminal suggestions. This phenomenon has evolved from simple forms of persuasion to advanced interface manipulation, where the line between inducement and fraud is deliberately blurred to maximize conversion at the expense of the interests of the weaker party in the legal relationship.</p>



<p>A particularly significant area of application of these practices is the system for <strong>presenting reviews and suggesting their authenticity</strong>, where manipulation takes the form of so-called interface interference. Businesses often employ patterns involving selective content display, which in practice means deliberately hiding negative reviews on subsequent pages of the website while simultaneously highlighting only enthusiastic reviews on the product&#8217;s home page. This practice violates the model of the average consumer, who has the right to expect that the image presented of a product&#8217;s popularity and quality is reliable and has not been subjected to arbitrary filtering. Manipulation in the sphere of social evidence also includes fabricating popularity indicators, such as false messages about the number of people viewing a given product at a given time or false offer duration counters, which create an artificial sense of scarcity in the user and pressure them to immediately close the transaction. Under the Polish Act on Combating Unfair Market Practices, these activities may be classified as misleading because they distort the actual market conditions, preventing a rational comparison of offers.</p>



<p>Another dimension of manipulation is the technique known as confirmation shaming, which in the sphere of opinion writing involves the use of evaluative and emotional language to coerce users into specific behaviors, for example, through unsubscribe buttons suggesting a lack of consumer awareness. These practices are closely related to the &#8220;<strong>roach motel model</strong>”, where the process of issuing a favorable review is simplified to the maximum extent, while editing, reporting an error, or deleting content requires navigating a complex subpage structure, which is intended to discourage users from correcting false information. In the legal context, such procedural barriers are considered burdensome impediments that violate good practice and the principle of commercial fairness. An analysis of case law and the positions of supervisory authorities indicates that an interface that deliberately hinders users from exercising their rights or changing their minds loses its neutrality and becomes a tool for harming consumer interests.</p>



<p>A fundamental change in the regulatory sphere was brought about by the entry into force of the <strong>EU Digital Services Act (DSA), which, in Article 25, explicitly prohibits online platform providers from designing, organizing, and operating interfaces in a way that misleads or manipulates service users</strong>. This regulation is overarching and complements the existing consumer protection framework by introducing a direct obligation to maintain neutrality in choice architecture and prohibiting structures that significantly impede users&#8217; ability to make free and informed decisions. Violation of this prohibition entails not only civil law risks but also severe administrative sanctions, which can amount to a significant percentage of the business&#8217;s global turnover.</p>



<p>In the sphere of law enforcement, the key role is played by the model design of the average consumer, who is observant and cautious but lacks specialized knowledge of the psychological mechanisms used in interface design. This protection is preventative and abstract in nature, meaning the President of the Office of Competition and Consumer Protection (UOKiK) can intervene in situations where the mere existence of a manipulative pattern poses a real risk of distorting market behavior, without having to wait for measurable financial damage to a specific individual. Effectively combating dark patterns requires businesses not only to comply with the law but, above all, to shift to a design model focused on reliability, where all product information, including opinions, is presented free from coercive mechanisms. Ultimately, interface transparency is becoming a prerequisite for maintaining trust in the digital economy, and the use of sophisticated forms of manipulation is perceived as highly harmful to society, subject to strict assessment in light of the principles of social coexistence.</p>



<p><strong>New obligations for marketplaces regarding moderation and transparency</strong></p>



<p>The entry into force of Regulation 2022/2065, known as the Digital Services Act (DSA), represents a fundamental shift in the liability paradigm for intermediary service providers, particularly marketplaces. This regulation shifts the emphasis from passive content hosting to active oversight of the transparency and security of the digital system, introducing rigorous operational standards aimed at eliminating illegal content while respecting users&#8217; fundamental rights. A key pillar of this reform is the formalization of moderation processes, which until now were often subject to arbitrary internal platform decisions and are now subject to strict procedural rigors contained in the notice-and-action mechanism. Under the DSA, each platform is required to provide easily accessible and user-friendly tools for identifying potentially illegal content, including fake reviews or infringing offers. The mere receipt of a report obliges the provider to promptly and objectively address it.</p>



<p>The evolution of moderation obligations is inextricably linked to the <strong>requirement for transparency in decisions</strong>, which is achieved through the justification mechanism provided for in the EU regulation. When a marketplace decides to remove content, limit its visibility, or suspend a user&#8217;s account, the user is absolutely obligated to provide clear and specific reasons for such action, which is intended to prevent abuse by blocking reliable reviews that are unfavorable to the seller. This system is complemented by a<strong> mandatory internal complaint handling system</strong>, which allows users to appeal moderation decisions free of charge within a period of at least six months. <strong>This constitutes an important procedural guarantee and allows for the correction of potential algorithmic errors</strong>. It is indicated that such a legal framework is necessary to counteract the fragmentation of consumer protection, which previously relied primarily on general national clauses that were unsuitable for the scale of operations of global digital entities.</p>



<p>A significant innovation introduced specifically for trading platforms is the &#8220;Know Your Business Customer&#8221; (KYBC) principle, regulated in the chapter on marketplace transparency. These entities are charged with collecting and verifying information about traders offering their products through their interfaces, including registration data, payment account numbers, and declarations of commitment to offer goods in compliance with EU law. This mechanism aims to eliminate the phenomenon of anonymous sellers, who often promote defective products using fabricated reviews and, after raising capital, disappear from the market, avoiding legal liability. The platform is obligated to suspend services for sellers who fail to submit the required documents, making the marketplace an active guardian of the legality of trade, rather than merely a passive intermediary in trade.</p>



<p>The scope of transparency obligations extends beyond relationships with individual users to include public reporting through the periodic publication of transparency reports. These documents must include detailed data on the number of orders received from national authorities, statistics on content moderation initiated by the platform itself, and information on the use of automated tools in verification processes. For very large online platforms, these rigors are even stricter, including the obligation to conduct annual audits and systemic risk assessments, including analysis of the interface&#8217;s vulnerability to manipulation that could negatively impact public safety or consumer protection. The systemic fight against disinformation and unfair market practices is therefore anchored in the full transparency of operational processes, which allows supervisory authorities to continuously monitor the effectiveness of implemented security measures.</p>



<p>Supervision of compliance with these obligations is based on a new institutional architecture, in which national digital services coordinators, working closely with the European Commission, play a central role. The enforcement system for the adopted regulations is based on fines of up to 6% of a provider&#8217;s global turnover, which compels compliance with specific cybersecurity standards. This control system is designed to ensure that marketplaces not only implement the required procedures but also apply them reliably and uniformly across the European Union, which is crucial for building consumer confidence in cross-border trade. The introduction of these standards ends the phase of full regulatory freedom for platforms, imposing on them real responsibility for shaping the environment in which the modern exchange of goods and services takes place.</p>



<h2 class="wp-block-heading"><strong>Technological verification mechanisms and modern operating models</strong></h2>



<p><strong>Authenticity Suggestion and Pressure Mechanisms</strong></p>



<p>The evolution of digital market oversight has led to the development of mechanisms in which traditional legal instruments are increasingly being replaced by algorithmic jurisdictions based on advanced artificial intelligence systems. The phenomenon known as AI exclusion is a modern form of sanction that, for e-commerce entities, can prove more severe than traditional financial penalties imposed by administrative bodies. The foundation of this process is the integration of data on the credibility of reviews directly with positioning parameters in ranking systems, which means that transparency is no longer merely an ethical obligation but a condition for the technical visibility of an offer. Recommendation algorithms operating within platforms such as Google and Amazon constantly analyze behavioral and linguistic patterns to identify anomalies suggesting manipulation of social evidence. These systems are currently capable of recognizing the structure of texts generated by LLM language models, which are characterized by a specific repetition of phrases and a lack of emotional details typical of authentic consumer experiences. An additional risk factor subject to automatic verification is the so-called review growth rate, where a sudden jump in the number of positive ratings without correlation with actual website traffic or sales volume is interpreted by AI as a warning signal initiating restrictive procedures.</p>



<p>The consequences of an online store being classified by AI systems as posing a high risk of manipulation are immediate and often irreversible in the short term. This mechanism, known in market practice as <strong>shadow banning or de-indexing</strong>, leads to a drastic decline in visibility in search results and the blocking of offers in advertising systems, effectively cutting the entrepreneur off from key customer acquisition channels. Under the provisions of the Digital Services Act, providers of very large online platforms are required to maintain particular transparency regarding the parameters used in recommendation systems. Article 27 of the aforementioned regulation requires platforms to clearly define in their regulations the key parameters determining information ranking, which aims to limit <strong>algorithmic arbitrage</strong> and enable entrepreneurs to understand the reasons for a potential decline in their market exposure. It is worth noting that modern risk assessment systems may be classified as high-risk systems within the meaning of the Artificial Intelligence Regulation, which imposes strict requirements on their creators regarding human oversight and the prevention of <strong>algorithmic discrimination</strong>.</p>



<p>In parallel to restrictive systems, a paradigm known as agentic commerce is developing, in which purchasing processes are carried out by autonomous AI assistants acting directly on behalf of the consumer. In this model, traditional product reviews cease to serve as persuasive texts for humans and become raw input data for machines that filter the market in search of offers with the highest level of verified trust. A key element of this new commerce architecture is the so-called trust layer, built on protocols such as the Universal Commerce Protocol promoted by Google or the Agentic Commerce Protocol developed by OpenAI. These systems are guided not only by price or availability of goods but above all by the certified credibility of the seller&#8217;s data, automatically rejecting offers from entities that lack a clear digital traceability of their recommendations. The collaboration of AI assistants with secure payment systems, such as the Agent Payments Protocol, creates a closed ecosystem in which offers at risk of manipulation are excluded at the initial algorithmic selection stage, before they are even presented to the user.</p>



<p>In the era of agent-based commerce, the role of modern shopping assistants is becoming dominant, forcing businesses to redefine their credibility-building strategies. The Context Protocol model and other open-source solutions enable the exchange of context between various AI models and commerce systems, allowing information about unfair practices by a single store to be instantly shared across the entire assistant network. The doctrine suggests that this systematic approach to eliminating abuse is a natural response to the technological ease of fabricating content online. For an e-commerce store, losing its trustworthy status in the eyes of Google or OpenAI algorithms means the modern equivalent of server shutdown, as AI assistants, protecting the interests of their users, will systematically bypass offers that generate manipulative signals. Thus, the fight for authenticity is no longer a mere compliance issue but an existential foundation in the new, automated e-commerce environment, where barriers to entry into the trust layer are becoming increasingly difficult for entities employing pressure mechanisms and suggesting false authenticity.</p>



<p><strong>Compliance as a Service and the Digital Feedback Path</strong></p>



<p>The rapid evolution of the e-commerce market and the increasing professionalization of unfair market practices have forced entrepreneurs to abandon a reactive reputation management model in favor of proactively building a digital immune system. The scale of the challenge facing modern e-commerce is illustrated by analyses of the systematic erosion of trust in the digital sector, pointing to the prevalence of fake reviews and consumer concerns about the mass implementation of generative artificial intelligence for opinion fabrication. This state of affairs creates decision paralysis, where an overabundance of unreliable information, instead of supporting the purchasing process, becomes an insurmountable barrier.</p>



<p>The economic impact of the lack of reliable content verification is directly measurable and translates into tangible operational losses for businesses. The literature emphasizes that exposure to manipulated reviews drastically reduces purchase intentions and brand trust, generating measurable financial losses. The information vacuum filled with false enthusiasm also leads to a phenomenon known as post-purchase dissonance, in which a product that fails to meet expectations is returned to the seller as a complaint or contract withdrawal. Consequently, the lack of investment in transparent review processes generates hidden logistical and operational costs that, in the long run, may outweigh the gains achieved through the temporary increase in conversions driven by manipulation.</p>



<p>In response to increasing regulatory rigor, including the Omnibus Directive, the Digital Services Act (DSA), and the AI Act framework, an operational model known as <strong>Compliance as a Service (CaaS)</strong> has emerged in market practice. It involves fully outsourcing compliance processes to specialized technology providers who take over the burden of monitoring and verifying content in accordance with current regulations. CaaS allows for the automation of data oversight, which is essential in an environment where the volume of incoming reviews precludes manual oversight without risking accusations of disproportionality. In this approach, compliance ceases to be merely an administrative cost and becomes a component of a strategy for building brand value by guaranteeing the authenticity of every customer touchpoint.</p>



<p>The foundation of the Compliance as a Service model is the maintenance of clean data and the generation of an indisputable digital trace of the review&#8217;s provenance. Every published review should be accompanied by a log containing metadata regarding the specific transaction, a unique order number, and delivery status, creating auditable proof of authenticity that can be presented during inspections by supervisory authorities such as the President of the Office of Competition and Consumer Protection. This digital reconstruction of the review process provides the most effective legal shield for businesses, eliminating the risk of allegations of unfair market practices. In the era of algorithmic jurisdiction, where ranking systems favor content supported by digital evidence, having a certified trace of data provenance is becoming a prerequisite for maintaining the market visibility of an offer.</p>



<p>Parallel to technical verification, modern review management systems integrate mediation mechanisms that allow for the amicable resolution of disputes before they are publicly expressed. Market experience suggests that implementing structured review processes allows for the amicable resolution of a significant portion of consumer disputes, effectively preventing the publication of negative reviews resulting from logistical errors. This approach aligns with the principles of reliability and good market practices, building customer relationships based on dialogue rather than solely on the one-way transmission of ratings.</p>



<p>Transaction verification is now becoming the market standard, replacing open, abuse-prone review sections with a system of unique invitations sent only after a purchase is completed. The literature emphasizes that restricting the review process to those who actually purchased the product is the simplest and most effective way to comply with the obligations imposed by the Omnibus Directive. This not only minimizes the risk of severe financial penalties, but above all, provides AI shopping assistants with reliable input data, which, in the new agent-based commerce paradigm, will determine the viability of each entity in the e-commerce ecosystem.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/">Faking reviews in e-commerce &#8211; analysis of new legal regulations, algorithmic mechanisms and market practices in the e-commerce sector</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/faking-reviews-in-e-commerce-analysis-of-new-legal-regulations-algorithmic-mechanisms-and-market-practices-in-the-e-commerce-sector/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 10 Jul 2026 10:31:49 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Lawyer Europe]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[CADA]]></category>
		<category><![CDATA[Cloud and AI Development Act]]></category>
		<category><![CDATA[Cloud Compliance]]></category>
		<category><![CDATA[Cloud Computing Law]]></category>
		<category><![CDATA[Cloud Computing Lawyer]]></category>
		<category><![CDATA[Cross-Border Legal Services]]></category>
		<category><![CDATA[Cybersecurity Law]]></category>
		<category><![CDATA[Data Act]]></category>
		<category><![CDATA[Data Governance Act]]></category>
		<category><![CDATA[Data Protection Law]]></category>
		<category><![CDATA[Digital Infrastructure]]></category>
		<category><![CDATA[Digital Sovereignty]]></category>
		<category><![CDATA[EU Cloud Regulation]]></category>
		<category><![CDATA[EU Regulatory Law]]></category>
		<category><![CDATA[EU Technology Law]]></category>
		<category><![CDATA[European Tech Regulation]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[Kiełtyka Gładkowski KG Legal]]></category>
		<category><![CDATA[public procurement law]]></category>
		<category><![CDATA[Sovereign Cloud]]></category>
		<category><![CDATA[Technology Law Firm]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8827</guid>

					<description><![CDATA[<p>Publication date: July 10, 2026 I. Introduction On June 3, 2026, the European Commission adopted a proposal for the Cloud and AI Development Act (hereinafter: CADA or the draft), which is the centerpiece of the broader European Technological Sovereignty Package. This draft seeks to translate the political concept of digital sovereignty into binding legal standards [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/">NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 10, 2026</strong></mark></p>



<h2 class="wp-block-heading">I. Introduction</h2>



<p>On June 3, 2026, the European Commission adopted a proposal for the Cloud and AI Development Act (hereinafter: CADA or the draft), which is the centerpiece of the broader European Technological Sovereignty Package. This draft seeks to translate the political concept of digital sovereignty into binding legal standards governing public procurement, the certification of cloud computing providers, and artificial intelligence infrastructure.</p>



<span id="more-8827"></span>



<p>CADA focuses on 3 goals:</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 1 &#8211; Research and Innovation: Support for next-generation technologies, frontier, industrial and physical AI; introduction of &#8220;grand challenges&#8221;; implementation of Experience and Acceleration Centres for AI.</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 2 &#8211; Capacity: target to triple EU data centre capacity within 5-7 years; simplify and speed up construction permitting.</p>



<p>• &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Pillar 3 &#8211; autonomy (core of regulation): a single EU framework for assessing cloud and AI sovereignty, a public sector adoption mechanism; an open source-first principle; and a common public procurement framework.</p>



<p>CADA fits into the broader EU digital policy framework, which includes the AI Act, Data Act, Data Governance Act, Digital Markets Act (DMA) and Digital Services Act (DSA), as well as soft law initiatives such as Gaia-X and the 2020 European Data Strategy. CADA takes a coordinated “ecosystem approach” as it combines supply-side actions to strengthen national capabilities, demand-side actions to drive deployment, and enablers for innovation and investment in cloud computing and AI.</p>



<p>“This initiative will connect networks, cloud, artificial intelligence, and software into cohesive ecosystems to address the following:</p>



<p>(1) future challenges related to energy-efficient computing infrastructure;</p>



<p>(2) autonomy across the entire cloud stack;</p>



<p>(3) advanced EU capabilities in advanced AI technologies, such as frontier AI, physical AI and industrial AI;</p>



<p>(4) implementing cloud and artificial intelligence in the public and private sectors.”</p>



<h1 class="wp-block-heading">II. The concept of digital sovereignty and the &#8220;sovereign cloud&#8221; in EU documents</h1>



<h2 class="wp-block-heading">1. Origin of the concept</h2>



<p>The concept of digital sovereignty (technological sovereignty) entered the vocabulary of the European Commission and the Council of the EU around 2020-2021 as a reaction to three phenomena: (1) the ongoing consolidation of the global cloud market in the hands of hyperscalers from the United States. à&#8221;The current situation in the cloud computing and artificial intelligence sector is characterized by a clear dependence on a limited group of third-country providers. Although the EU cloud computing market is growing significantly, the share of EU providers fell from 29% in 2017 to 15% in 2022 and has remained unchanged since then. Currently, three non-EU cloud computing providers control over 70% of the European cloud computing market&#8230; This dependency also exposes European users to the risk of disruptions, especially in situations where unilateral decisions by third-country entities could disrupt service provision.”</p>



<p>(2) legal risks related to the extraterritorial application of the US CLOUD Act of 2018, which allows US authorities to access data stored by US-based companies regardless of the location of the servers, and</p>



<p>(3) the CJEU judgments in Schrems I (2015) and Schrems II (2020), questioning the legal basis for transatlantic transfers of personal data. The Court of Justice of the EU (CJEU) invalidated the <em>Privacy Shield Agreement</em>, finding that US regulations did not guarantee EU citizens adequate protection of their personal data against surveillance. This forced the processing of sensitive data in Europe.</p>



<p>The Gaia-X initiative, launched in 2019 by Germany and France, was the first attempt to operationalize cloud sovereignty. The project&#8217;s main goals are:</p>



<ul class="wp-block-list">
<li>reducing Europe&#8217;s dependence on American and Chinese cloud providers (such as AWS, Google Cloud, Azure, Alibaba)</li>



<li>Gaia-X does not build its own cloud, but creates rules, standards and trust mechanisms that allow different providers (small and large) to offer interoperable, compatible services.</li>



<li>companies and institutions must maintain control over where and how their data is stored and processed, in accordance with European regulations (e.g. GDPR)</li>



<li>common certification rules, trust labels (&#8220;Gaia-X Trust Framework&#8221;) and open API</li>
</ul>



<p>However, the project was criticized for its slow pace and the influence of large American technology companies, which raised doubts about the sovereign nature of the undertaking.</p>



<h2 class="wp-block-heading">&nbsp;</h2>



<h2 class="wp-block-heading">2. Components of digital sovereignty according to the CADA project</h2>



<p>The CADA project does not have a single, closed dictionary definition of &#8220;cloud/digital sovereignty.&#8221; Instead, the project develops the concept through a system of levels and assessment criteria.</p>



<p><strong>Recital 51 of the Preamble</strong><strong>à</strong><strong> </strong>&#8220;it is necessary to establish a Union cloud computing sovereignty framework determining criteria for trusted cloud computing services. To cater for the <strong>nuanced and layered nature of sovereignty</strong>, the framework should provide for four different levels of trusted offers (&#8216;Union assurance levels&#8217;).&#8221;</p>



<p><strong>Recital 50 of the Preamble</strong><strong>à</strong><strong> </strong>“The Union and Member States being critically dependent on a limited number of cloud computing service providers subject to the control of a third country or a legal entity established in a third-country may lead to risks such as misuse (ie manipulation, remote access and control, sabotage, weaponization), access to information (ie access to sensitive information, unauthorized communication, technology leakage, data manipulation or exfiltration, espionage) and dependency vulnerabilities (ie political and/or economic coercion, for example by using vendor or technology lock-ins, embargos or sanctions, monopoly pricing damaging the financial interest of the Union and Member States).” – risks to sovereignty</p>



<p><strong>Article 16</strong><strong>à</strong><strong> </strong>&#8220;This Chapter establishes a Union cloud computing sovereignty framework comprising four Union assurance levels, the criteria for which are set out in Annex II, that cloud computing service providers shall meet in order to provide their cloud computing services to Union entities and public sector bodies&#8221;</p>



<p><strong>Annex II</strong><strong>à</strong><strong> </strong>contains four cumulative sets of technical, legal and organisational criteria. &#8220;Software&#8221; within the meaning of the Annex includes Regulation 2024/2847 (Cyber Resilience Act). CADA in Annex II defines sovereignty in the field of cloud computing and artificial intelligence, comprising four levels of guarantees that public sector bodies will benefit from based on their risk assessments. Cloud service providers can be recognised by Member States under this framework after passing an audit. The Commission retains the competence to issue implementing acts identifying third countries whose providers would be subject to audits under the above system.</p>



<p>Level 1 (Basic) &#8211; &nbsp;pt. 1</p>



<p>The lowest threshold, covering all public sector services:</p>



<ul class="wp-block-list">
<li>supplier&#8217;s registered office in the EU; infrastructure and assets in the EU (unless the customer expressly agrees otherwise);</li>



<li>customer data (including metadata, telemetry) remains exclusively within the EU, unless a public authority decides otherwise;</li>



<li>when outsourcing technical support outside the EU, the requirement of traceability and safeguards that do not undermine operational autonomy;</li>



<li>compliance with current cybersecurity standards;</li>



<li>full transparency regarding subcontractors;</li>



<li>if the supplier is controlled by an entity from a third country – a guarantee of no obligation to report security vulnerabilities to the authorities of that country before their disclosure.</li>
</ul>



<p>Level 2 (Standard) &#8211; point 2</p>



<p>It requires an audit (not just a declaration) and adds:</p>



<ul class="wp-block-list">
<li>mandatory location of infrastructure, assets and personnel in the EU;</li>



<li>the possibility of requesting EU citizenship of staff (at the client&#8217;s request);</li>



<li>cybersecurity certificate of at least &#8220;substantial&#8221; level (EUCS or national equivalent);</li>



<li>prohibition on using customer data to train AI models operated by a third-country entity;</li>



<li>if the supplier is subject to third-country control – requirement to demonstrate safeguards against: limiting the ability to provide the service, access to data, disruption of service continuity, enforcement of sanctions/embargoes;</li>



<li>technical support only from the EU;</li>



<li>transparency of the software supply chain (SBOM &#8211; Software Bill of Materials), control of components from third-country suppliers, source code audit;</li>



<li>legal and technical separation between the EU parent company and the subsidiary in a third country.</li>
</ul>



<p>Level 3 (Enhanced) &#8211; point 3</p>



<p>Adds important refinements:</p>



<ul class="wp-block-list">
<li>staff must be EU citizens and, when handling classified information, have a national security clearance;</li>



<li>&#8220;substantial&#8221; cybersecurity certificate;</li>



<li>as a rule, a ban on control by a third-country entity – except where the Commission issues an implementing act under Article 19 authorising such a supplier (in which case additional safeguards apply, including &#8220;reasonable access to the code&#8221;);</li>



<li>technical support provided exclusively by EU residents and entities not subject to third-country control.</li>
</ul>



<p>Level 4 (Sovereign) &#8211; point 4</p>



<p>Highest, most restrictive threshold:</p>



<ul class="wp-block-list">
<li>complete lack of control by a third country entity (without any exception authorised by the Commission, as opposed to Level 3);</li>



<li>cybersecurity certificate at least &#8220;high&#8221;;</li>



<li>staff – EU citizens with appropriate security clearances;</li>



<li>for software components: requirement of effective control over design, development and maintenance &#8211; no third-country entity may have the ability to materially influence the technical development, maintenance priorities or continuity of the component</li>
</ul>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Level</strong></td><td><strong>Name</strong></td><td><strong>Key criterion</strong></td><td><strong>Accessibility for non-EU entities</strong></td></tr></thead><tbody><tr><td>1</td><td>Basic Date of residency</td><td>Data localization in the EU, GDPR</td><td>Accessible &#8211; meeting basic data protection requirements</td></tr><tr><td>2</td><td>Standard Supply-chain independence</td><td>EUCS certification, operational independence</td><td>Conditionally available &#8211; requires ENISA/EUCS certification</td></tr><tr><td>3</td><td>Enhanced EU ownership &amp; control</td><td>Supply chain control, no non-EU law</td><td>Limited &#8211; Commission recognition required; US CLOUD Act disqualifies</td></tr><tr><td>4</td><td>Sovereign Defence-grade</td><td>Full transparency, technical autonomy, EU ownership</td><td>Essentially unavailable to non-EU hyperscalers without restructuring</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">III. EU Cloud Sovereignty Framework</h2>



<p>The EU Cloud Sovereignty Framework is also a key document defining the &#8220;sovereign cloud.&#8221; This document <strong>is not part of the CADA regulation itself</strong>, but a separate DG DIGIT methodological tool used in specific procurement procedures. Compared to the four-level <strong>Union Assurance Levels scale </strong>in CADA Annex II (levels 1–4, based on cumulative binary criteria—pass/fail), the SEAL framework is more detailed. According to it, digital sovereignty consists of eight elements.</p>



<p><strong>Eight Components of Digital Sovereignty (SOV-1 to SOV-8)</strong></p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>#</strong></td><td><strong>Component</strong></td><td></td></tr></thead><tbody><tr><td><strong>SOV-1</strong></td><td><strong>Strategic sovereignty</strong></td><td>The supplier&#8217;s embeddedness in the EU legal, financial and industrial ecosystem – ownership stability, influence on governance, compliance with EU strategic priorities</td></tr><tr><td><strong>SOV-2</strong></td><td><strong>Legal and jurisdictional sovereignty</strong></td><td>The legal environment of the service, exposure to foreign authorities, the possibility of pursuing rights in EU jurisdiction – including resistance to extraterritorial acts such as <strong>the US CLOUD Act </strong>or the Chinese cybersecurity law</td></tr><tr><td><strong>SOV-3</strong></td><td><strong>Data Sovereignty and AI</strong></td><td>Protection, control, and independence of data resources and AI services – where data is processed and what degree of autonomy the customer retains over AI capabilities</td></tr><tr><td><strong>SOV-4</strong></td><td><strong>Operational sovereignty</strong></td><td>Practical ability of EU entities to independently conduct, support and develop technologies without dependence on foreign control &#8211; business continuity, availability of competences</td></tr><tr><td><strong>SOV-5</strong></td><td><strong>Supply chain sovereignty</strong></td><td>Geographical origin, transparency and resilience of the technology supply chain – the extent to which key components remain under EU control</td></tr><tr><td><strong>SOV-6</strong></td><td><strong>Technological sovereignty</strong></td><td>The degree of openness, transparency and independence of the technology stack – the ability to interoperate, audit and develop solutions without dependence on closed systems from third-party vendors</td></tr><tr><td><strong>SOV-7</strong></td><td><strong>Security and Compliance Sovereignty</strong></td><td>The extent to which security operations, compliance obligations and resilience activities remain controlled within the EU – independence from foreign jurisdictions</td></tr><tr><td><strong>SOV-8</strong></td><td><strong>Environmental sustainability</strong></td><td>Long-term autonomy and resilience of cloud services in the context of energy consumption, resource dependencies, and material scarcity</td></tr></tbody></table></figure>



<p><strong>Rating scale: Sovereignty Effectiveness Assurance Levels (SEAL)</strong></p>



<p>Independently of the eight components, the document introduces <strong>a five-level maturity scale </strong>(SEAL-0 to SEAL-4) used to assess each of the eight objectives separately:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Level</strong></td><td><strong>Name</strong></td><td><strong>Description</strong></td></tr></thead><tbody><tr><td><strong>SEAL-0</strong></td><td>Lack of sovereignty</td><td>A service entirely controlled by a non-EU entity, managed in a foreign jurisdiction</td></tr><tr><td><strong>SEAL-1</strong></td><td>Jurisdictional sovereignty</td><td>EU law formally applies but has limited enforceability; exclusive control by a non-EU entity</td></tr><tr><td><strong>SEAL-2</strong></td><td>Data sovereignty</td><td>EU law is in force and enforceable, but significant dependencies on non-EU entities remain; indirect control</td></tr><tr><td><strong>SEAL-3</strong></td><td>Digital resilience</td><td>EU law fully enforceable, EU entities have significant but limited influence; non-EU entities have marginal control</td></tr><tr><td><strong>SEAL-4</strong></td><td>Full digital sovereignty</td><td>Technology and operations entirely under EU control, subject only to EU law, with no critical dependencies from outside the EU</td></tr></tbody></table></figure>



<p><strong>Sovereignty Score</strong></p>



<p>The document also introduces <strong>percentage weightings </strong>for each of the eight components when calculating the aggregate sovereignty score in the tender process:</p>



<ul class="wp-block-list">
<li><strong>Supply Chain (SOV-5): 20% </strong>&#8211; Highest Weight</li>



<li><strong>Strategic sovereignty (SOV-1) and operational sovereignty (SOV-4): 15% each</strong></li>



<li><strong>Technological Sovereignty (SOV-6): 15%</strong></li>



<li><strong>Legal/Jurisdictional (SOV-2), Data/AI (SOV-3), Security (SOV-7): 10% each</strong></li>



<li><strong>Environmental Sustainability (SOV-8): 5% </strong>&#8211; Lowest Weight</li>
</ul>



<p>The lower weights for SOV-2 and SOV-7 were justified by the fact that these areas are already covered by separate procedural safeguards in the procurement procedure itself.</p>



<h2 class="wp-block-heading">IV. Impact of the CADA project on public procurement</h2>



<p>One of the central mechanisms of CADA is the common EU-level procurement framework.</p>



<p><strong>Recital 64 of the Preamble</strong><strong>à</strong><strong> </strong>The free flow of data within the EU is a prerequisite for the functioning of the internal market – data cannot be artificially limited to the territory of a single Member State. The EU pledges, in principle, open, non-discriminatory market access in accordance with the TFEU and international obligations (including the WTO GPA on Government Procurement).</p>



<p>However, the EU invokes Article III:2(a) of the WTO GPA, which allows for measures necessary to protect public order, public morality, or security. This justifies proportionate restrictions on access to public procurement based on the risk of critical dependencies, unauthorized access to EU data, technology leakage, sabotage, and espionage by third-country entities. Contracting entities whose activities are identified as relevant to public order are required to procure cloud services <strong>only at levels 2-4</strong>. At the same time, <strong>level 1 becomes the mandatory minimum for the entire </strong>EU public sector, providing a consistent baseline level of security.</p>



<p><strong>Motif 65</strong><strong>à</strong><strong> </strong>To reduce vendor dependency, EU entities and Member States should consider a multi-vendor/multi-cloud strategy in their procurement processes, based on a contextual risk assessment that takes into account operational, regulatory and resilience circumstances.</p>



<p><strong>Motif 66</strong><strong>à</strong><strong> </strong>Public procurement is treated as a directional signal for the entire market – requirements imposed on the public sector regarding levels of assurance tend to be imitated by the private sector in regulated industries. Article 31 allows private entities from sectors covered by Annex I of the NIS2 Directive to carry out similar assessments.</p>



<p><strong>Article 29 </strong><strong>à</strong>Member States and EU entities are required (annually or biannually) to carry out risk assessments that:</p>



<ul class="wp-block-list">
<li>identify public sector activities using cloud services in areas covered by Annexes I/II of the NIS2 Directive and in the spheres of national security, defence, justice and law enforcement;</li>



<li>determine which <strong>assurance level (Union assurance level 2, 3 or 4) </strong>is appropriate for a given activity.</li>
</ul>



<p>The Commission has the power to impose the methodology for this assessment by means of implementing acts and, if it considers the Member State&#8217;s assessment to be inadequate, to determine the required level itself (Article 29(5)).</p>



<p><strong>Article 30</strong><strong>à</strong><strong></strong></p>



<p><strong>Paragraph 2: </strong>entities whose activities are <strong>not </strong>classified as important for public order must use at least <strong>level 1 cloud services</strong>.</p>



<p><strong>Paragraph 3: </strong>contracting entities whose activities <strong>have been </strong>so qualified (NIS2, national security, defence, justice sectors) <strong>may only procure </strong>cloud services classified as <strong>level 2, 3 or 4 </strong>.</p>



<p><strong>Paragraph 4: </strong>allows for derogations in exceptional, justified cases (lack of available services on the market, lack of offers in the previous procedure, grossly disproportionate cost).</p>



<p><strong>Art. 32 </strong><strong>à</strong>In procurement procedures for innovative cloud services and AI systems, contracting authorities must take into account <strong>non-price criteria for the evaluation of offers </strong>, including:</p>



<ul class="wp-block-list">
<li>the contractor&#8217;s contribution to strengthening the EU digital technology supply chain,</li>



<li>the use of technologies developed in the EU (including the results of EU R&amp;D programmes),</li>



<li>providing the service using hardware components designed/manufactured in the EU.</li>
</ul>



<p><strong>Recital 67 </strong>clarifies that this criterion <strong>cannot be decisive </strong>and suggests an indicative maximum weighting of <strong>15 points out of 120 </strong>in the tender evaluation methodology – it is intended to be subsidiary to the technical and financial criteria.</p>



<p><strong>Article 33</strong><strong>à</strong><strong> </strong>Member States are to aim to ensure that at least 25% of procurement for cloud services and AI systems goes to innovative SMEs, and report annual data on SME participation in procurement to the Commission.</p>



<h1 class="wp-block-heading">V. Relationship of the CADA project with existing EU legal acts</h1>



<h2 class="wp-block-heading">1. AI Act (Regulation 2024/1689)</h2>



<p>The AI Act governs the security and fundamental rights of AI systems; the CADA governs the sovereignty of the infrastructure that supports these systems.</p>



<p>Art. 2 point 3 of CADA <strong>does not create its own definition </strong>of an AI system, but refers directly to the AI Act à&#8221;&#8216;AI system&#8217; means an AI system as defined in Article 3, point (1), of Regulation (EU) 2024/1689&#8243;</p>



<p><strong>Explanatory memorandum</strong><strong>à</strong><strong> </strong>&#8220;The proposal also reinforces key objectives of the AI Act. The AI Act harmonises rules for AI systems and general-purpose AI models to be placed on the EU market, improving the functioning of the internal market and promoting the uptake of human-centric and trustworthy AI along the value chain. The AI Act ensures a high level of protection of health, safety and fundamental rights. It does not cover aspects of sovereignty.&#8221; &#8211; The Commission <strong>explicitly states that the AI Act does not cover the issue of sovereignty </strong>&#8211; this is the very gap that CADA aims to fill.</p>



<p>CADA entrusts the AI Board (the body established under the AI Act) with a coordinating role beyond its original mandate:</p>



<ul class="wp-block-list">
<li><strong>Motif 33</strong><strong>à</strong> <em>&#8220;As cloud computing underpins and enables AI, the AI Board should serve as a platform to facilitate cooperation and coordination of AI adoption-related activities between the Union and the Member States.&#8221;</em></li>



<li><strong>Article 7(6) </strong>gives the AI Board a specific operational responsibility: to advise and support Member States in coordinating national cloud and AI strategies required by CADA, and to facilitate the exchange of good practices between Member States.</li>
</ul>



<p>This is an important institutional arrangement: CADA does not create a new, parallel body for AI issues, but extends the remit of the existing body from the AI Act to a new area (cloud as an infrastructure supporting AI).</p>



<h2 class="wp-block-heading">2. Data Act (Regulation 2023/2854)</h2>



<p>The Data Act, effective from September 2025, imposes obligations on cloud service providers to facilitate data portability and switching. CADA builds on this foundation by adding a dimension of sovereignty: it&#8217;s no longer just about data portability, but also about ensuring that data remains under the sole jurisdiction of the EU throughout its time in the cloud. The two acts create a complementary layer of protection: the Data Act allows for switching providers, and CADA establishes criteria for which alternative cloud services are considered sufficiently sovereign. Without CADA, the Data Act&#8217;s switching mechanism would be &#8220;blind&#8221; to the quality or sovereignty of the target provider.</p>



<p>&#8220;&#8221;The proposal is consistent with the rules on switching between data processing services introduced by the Data Act. By enabling switching and removing key sources of vendor lock-in, the Data Act seeks to ensure that cloud computing service providers in the EU compete on quality, innovation, and price. It seeks to enable cloud users to freely choose the provider that best meets their needs and combine offers of different providers in a multi-cloud approach.&#8221;</p>



<p><em>&#8220;However, the Data Act does not contain elements to shape up a more competitive offer of European cloud computing services or encourage the entry into the market of a more diverse set of cloud computing service providers.&#8221;</em></p>



<p><em>&#8220;The Data Act opens the path towards a possible reduction of dependencies on non-EU providers but does not build the road towards a more sovereign and trusted EU cloud computing sector. [&#8230;] <strong>The Data Act is thus an enabler for the proposal.</strong>&#8220;</em></p>



<h2 class="wp-block-heading">3. Data Governance Act (Regulation 2022/868)</h2>



<p>The Data Governance Act, effective from September 2023, establishes a framework for neutral data intermediaries and the reuse of public sector data. The CADA does not explicitly address the DGA in its text. However, it imposes sovereign certification requirements on the infrastructure storing this data, which in practice limits the range of providers deemed suitable for handling data covered by the DGA.</p>



<h2 class="wp-block-heading">4. Digital Markets Act</h2>



<p>The DMA, effective from May 2023, imposes obligations on gatekeepers, including interoperability requirements and prohibition of self-preferential services. CADA and DMA operate under different logics: DMA regulates market behavior ex ante, while CADA creates positive eligibility criteria for the public sector. There is a risk of conflict between the interoperability obligations with the DMA and the closed architectures required by the highest levels of CADA sovereignty.</p>



<h2 class="wp-block-heading">5. Digital Services Act and the general regulatory context</h2>



<p>The DSA, fully applicable since February 2024, governs the liability of online intermediaries. Although it does not directly address cloud infrastructure, it contributes to a regulatory climate characterized by high levels of EU intervention in the digital market and increasing assertiveness towards global technology providers.</p>



<p>&#8220;While certain providers of cloud computing services could be regulated under both this proposal and the DMA, <strong>the DMA has different objectives and does not contain measures that would actively promote the uptake of sovereign cloud computing services </strong>. The DMA only aims at maintaining and promoting a fair and contestable cloud market in the Union, regulating specific behaviors of companies designated as gatekeepers and <strong>thus intervenes at a different level than the proposal</strong>, which focuses on the uptake and use of the services provided.&#8221;</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td>Dimension</td><td>DMA</td><td>CADA</td></tr></thead><tbody><tr><td>The Logic of Intervention</td><td>Ex post / behavioral — corrects the market behavior of already dominated entities (gatekeepers)</td><td>Ex ante/structural &#8211; shapes demand and supply towards trusted/sovereign services</td></tr><tr><td>Subject of regulation</td><td>Fairness and contestability of the market</td><td>Uptake and utilization of sovereign services</td></tr><tr><td>Recipients</td><td>Only entities formally designated as gatekeepers</td><td>All cloud providers seeking certification at levels 1-4</td></tr></tbody></table></figure>



<h1 class="wp-block-heading">VI. Arguments in favor of introducing CADA regulations</h1>



<ul class="wp-block-list">
<li><strong>Security and strategic independence: </strong>AWS, Microsoft Azure, and Google Cloud control approximately 70-80% of the EU cloud computing market. This concentration means that key EU administrative, banking, and healthcare systems are de jure accessible to US authorities under the US CLOUD Act (the CLOUD Act gives <strong>US law enforcement and intelligence agencies </strong>the right to demand access to data from US service providers (including cloud computing providers) <strong>&nbsp;&#8211; regardless of the physical location of the servers </strong>on which that data is stored.) &#8211; which EU authorities classify as a security risk. CADA will help mitigate this risk by introducing a complex system of vendor evaluation criteria.</li>



<li><strong>Risk of service interruption</strong><strong>à</strong><strong> </strong>&#8220;This dependence also exposes European users to the risks related to operational discontinuity, particularly in scenarios where unilateral decisions by third-country actors could disrupt service provision.&#8221;</li>



<li><strong>Critical loss of market position for European providers &#8211; </strong>&#8220;While the EU market for cloud computing services is growing significantly, the market share of EU providers decreased from 29% in 2017 to 15% in 2022 and has remained stagnant since then.&#8221; CADA will help them regain their strategic position.</li>



<li><strong>Industrial and investment goal: </strong>The project assumes tripling the capacity of data centers in the EU within 5–7 years, which will significantly improve the efficiency and functionality of the AI system in the EU àtoday: &#8220;The EU&#8217;s limited data center capacity poses a significant threat to its ability to benefit from the digital transformation and adopt AI-driven solutions, notably those requiring low-latency compute capacity.&#8221; The lack of appropriate infrastructure also hinders the EU&#8217;s economic growth: &#8220;the lack of data center capacity in the EU forces European enterprises to route critical workloads through foreign hyperscaler infrastructure. This makes <strong>the EU a less attractive destination for tech investment </strong>than regions with more abundant, lower-cost compute resources.&#8221;</li>



<li><strong>Enabling the use of the EU&#8217;s own potential &#8211; </strong>&#8220;Europe has world-class research and development capabilities, vibrant open-source communities and a strong industrial base in cloud and AI, <strong>which however remain largely untapped.</strong>&#8220;</li>
</ul>



<h1 class="wp-block-heading">VII. Tensions with Single Market Principles and Competition Law</h1>



<p>The CADA project, whose legal basis is <strong>Article 114 and Article 173(3) TFEU </strong>(harmonisation of the internal market and strengthening of the EU’s industrial competitiveness), is consciously constructed by the Commission as a means of removing internal market barriers – the argument justifying the intervention is precisely the divergence of national sovereignty criteria and procurement practices, which hinders suppliers from operating freely between Member States.</p>



<p>Despite this declared harmonisation logic, the practical effect of the sovereignty criteria at levels 3-4 (complete lack of control by a third-country entity, EU citizenship of staff, location of the entire infrastructure in the EU) may in fact restrict the freedom to provide services by non-EU suppliers in the EU internal market. However, the Act itself does not explicitly address this potential tension with Article 56 TFEU – the Commission locates the justification for procurement restrictions not in primary EU law, but in the <strong>public policy exception in Article III:2(a) of the WTO GPA </strong>(recital 64), consistently using the category of &#8220;<strong>public order</strong>&#8221; as the substantive basis for the restrictions (recitals 49-53).</p>



<p>The question whether the criteria thus constructed – despite their declared technological neutrality – in fact constitute a measure having an effect equivalent to a quantitative restriction or infringe the principle of proportionality required for derogations from the internal market freedoms remains open and not determined by the text of the act itself – this would require an assessment by the Court of Justice of the EU in a possible preliminary ruling procedure or an action for annulment.</p>



<p><strong>Application</strong></p>



<p>It is believed that despite the weaknesses identified earlier, the CADA project offers more benefits than threats – especially in the context of growing cyber warfare, where information, not just physical critical infrastructure, becomes the primary weapon.</p>



<p>Data collected by healthcare providers, the banking sector, and digital service providers is strategic in nature &#8211; its confidentiality and integrity today determine the security of citizens to a degree comparable to energy or military security. As the Schrems II case demonstrated, no contractual safeguards effectively protect against a situation in which an infrastructure provider is legally obligated to disclose data to third-party authorities &#8211; regardless of the physical location of the servers. CADA addresses precisely this gap: it no longer regulates only <em>the method </em>of data processing, but also <em>the structure of control </em>over the entity that manages it. This seems to me a necessary step, not an unnecessary one.</p>



<p>The complete dependence of the European digital economy on external infrastructure providers would limit its ability to fully develop &#8211; particularly in the field of artificial intelligence, where control over training data and computing infrastructure is becoming a key factor in competitiveness. The European Union possesses significant research and development resources, which currently remain largely untapped due to the lack of coherent institutional and regulatory support to fully develop their potential. CADA, by combining infrastructure investments with preferential procurement criteria, is attempting to fill this gap.</p>



<p>A mechanism to level the playing field for smaller European providers is also crucial. Automatic recognition of compliance for SMEs at the basic assurance level and the goal of at least a quarter of cloud and AI service contracts going to innovative SMEs create a real stimulus for development—not just a barrier for large entities. Such a competitive boost could, in the long run, motivate European providers to continually improve the quality and innovation of their services, rather than remain permanently in the shadow of foreign hyperscalers.</p>



<p>Finally, the planned tripling of data centre capacity in the EU over the next 5-7 years is an investment not only in sovereignty, but also in the security of the data itself – a distributed, redundant infrastructure located within the EU reduces the risk of systemic failures, service interruptions or abuses resulting from unilateral decisions by foreign entities.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/">NOTE &#8211; EU Cloud and AI Development Act (CADA) project and the concept of the sovereign cloud in the European Union&#8217;s digital policy</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/note-eu-cloud-and-ai-development-act-cada-projectand-the-concept-of-the-sovereign-cloud-in-the-european-unions-digital-policy/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:33:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy;]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Ecommerce]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[Foreign Investment]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Marketplace]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[Online Retail]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8813</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 Just a few years ago, online store owners primarily had to ensure terms and conditions, privacy policies, and efficient order processing. Today, this is clearly not enough. EU regulations such as the Omnibus Directive and the Digital Services Act (DSA), as well as the increasing role of artificial intelligence in [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/">Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>Just a few years ago, online store owners primarily had to ensure terms and conditions, privacy policies, and efficient order processing. Today, this is clearly not enough. EU regulations such as the Omnibus Directive and the Digital Services Act (DSA), as well as the increasing role of artificial intelligence in assessing store credibility, force businesses to consider their platforms much more broadly. It is no longer just about regulatory compliance, but also about building digital trust, which influences a store&#8217;s visibility, legal security, and customer purchasing decisions. Below, we present a practical checklist of the most important actions to implement to reduce the risk of sanctions and increase the credibility of an online store.</p>



<span id="more-8813"></span>



<h2 class="wp-block-heading" id="ember4228">Practical guidelines for online store owners</h2>



<h2 class="wp-block-heading" id="ember4229">I.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Avoiding UOKiK fines and compliance with the Omnibus Directive</h2>



<p id="ember4230">a. <strong>Implement transactional verification</strong>: You should configure your feedback system so that each review you post is technically linked to the unique order number and email address of the customer who actually completed the purchase.</p>



<p id="ember4231">b. <strong>Updating the content of the regulations</strong>: In the &#8220;Rules for publishing opinions&#8221; section, the verification procedure should be described in detail, whether all opinions (including critical ones) are published and how the average product rating is calculated.</p>



<p id="ember4232">c. <strong>Transparent labeling</strong>: Each review should have a clear status indication (e.g., &#8220;Purchase confirmed&#8221;). If a benefit is provided in exchange for reviews (e.g., a discount code), this information must be clearly and prominently displayed within the review text.</p>



<p id="ember4233">d. <strong>Lowest price mechanism</strong>: In accordance with the requirements of price transparency, each discount must display the lowest price of the product that was valid in the 30 days prior to the introduction of the discount.</p>



<p id="ember4234"><strong>Legal basis</strong>: Act of 30 May 2014 on consumer rights ( Journal of Laws of 2024, item 1796, as amended); Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (OJ EU L 328 of 2019, No. 328, p. 7, as amended); Act of 23 August 2007 on counteracting unfair market practices ( i.e. Journal of Laws of 2023, item 845).</p>



<h2 class="wp-block-heading" id="ember4235">II.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring compliance with the Digital Services Act (DSA)</h2>



<p id="ember4236">a. <strong>Implementing a &#8220;report content&#8221; mechanism</strong>: Every review or user-generated content must have an easily accessible button to report suspected illegality or manipulation of the content.</p>



<p id="ember4237">b. <strong>Procedure for justifying decisions</strong>: In the event of deletion of an opinion or blocking of a user account, the platform is obliged to send the author a detailed justification indicating a specific violation of the regulations or legal provisions.</p>



<p id="ember4238">c. <strong>Internal Complaints Process</strong>: Users must be able to appeal moderation decisions for a period of at least 6 months from the date the platform takes action.</p>



<p id="ember4239">d. <strong>Designation of a contact point</strong>: The entrepreneur must designate an electronic contact point for supervisory authorities and users, enabling efficient communication on matters relating to digital security.</p>



<p id="ember4240"><strong>Legal basis:</strong> Regulation<strong> </strong>(EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, No. 277, p. 1, as amended), in particular Articles 16, 17 and 20.</p>



<h2 class="wp-block-heading" id="ember4241">III.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reducing the risk of “algorithmic exclusion”</h2>



<p id="ember4242">a. <strong>Design Patterns (UX) Audit</strong>: Eliminate so-called dark patterns, such as asymmetric selector buttons, hard-to-close pop-ups, or mechanisms that make it difficult to unsubscribe. Supervisory algorithms treat such practices as signals of poor interface quality.</p>



<p id="ember4243">b. <strong>Data Certification for AI</strong>: Ensure structured review data is provided, allowing shopping assistants and crawlers to properly verify the “digital provenance” of the data.</p>



<p id="ember4244">c. <strong>Filtering synthetically generated content</strong>: It is worth implementing tools that monitor review language for bot-like patterns (unnatural correctness, lack of detail) to avoid indexing false enthusiasm that results in lower trust rankings.</p>



<p id="ember4245"><strong>Legal basis</strong>: REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, p. 1, as amended) – Article 25 (prohibition of deceptive interfaces)</p>



<h2 class="wp-block-heading" id="ember4246">IV.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Proper management of data and opinions (CaaS model)</h2>



<p id="ember4247">a. <strong>Digital</strong> <strong>Audit</strong> <strong>Trail</strong>: It is recommended to store logs containing transaction metadata related to opinions for a period enabling verification of data reliability (e.g. 12-24 months).</p>



<p id="ember4248">b. <strong>Active mediation systems</strong>: Instead of deleting negative feedback, use complaint management systems that document the process of resolving customer disputes. Resolving a problem is treated by ranking systems as evidence of high-quality service.</p>



<p id="ember4249"><strong>c.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; “Know Your Business Customer” principle</strong>: When running a marketplace model, it is essential to verify the identity of sellers before allowing them to offer goods, collecting registration numbers and contact details.</p>



<p id="ember4250"><strong>Legal basis</strong>: REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L of 2022, No. 277, p. 1, as amended) – Article 30; Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L of 2016, No. 119, p. 1, as amended).</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/">Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>KG Legal Contributes to techUK’s Tech &#038; Innovation Focus Week 2026: Agentic AI, Governance and Responsible Adoption</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 02 Jun 2026 12:46:40 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Risk Management]]></category>
		<category><![CDATA[Autonomous AI Systems]]></category>
		<category><![CDATA[Public Sector AI]]></category>
		<category><![CDATA[Responsible AI]]></category>
		<category><![CDATA[UK AI Regulation]]></category>
		<category><![CDATA[UK GDPR]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8798</guid>

					<description><![CDATA[<p>Publication date: June 2, 2026 We are pleased to announce that KG Legal Kiełtyka Gładkowski contributes to techUK’s annual Tech &#38; Innovation Focus Week, taking place from 15–19 June 2026. The initiative brings together industry leaders, technology experts and innovators to discuss the transformative technologies shaping the future of the UK economy. LINK: https://www.techuk.org/resource/call-for-contributions-techuk-s-2026-tech-innovation-focus-week.html For [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/">KG Legal Contributes to techUK’s Tech &#038; Innovation Focus Week 2026: Agentic AI, Governance and Responsible Adoption</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>Publication date: June 2, 2026</strong></p>



<p>We are pleased to announce that KG Legal Kiełtyka Gładkowski contributes to techUK’s annual Tech &amp; Innovation Focus Week, taking place from 15–19 June 2026. The initiative brings together industry leaders, technology experts and innovators to discuss the transformative technologies shaping the future of the UK economy.</p>



<p>LINK: <a href="https://www.techuk.org/resource/call-for-contributions-techuk-s-2026-tech-innovation-focus-week.html" target="_blank" rel="noreferrer noopener">https://www.techuk.org/resource/call-for-contributions-techuk-s-2026-tech-innovation-focus-week.html</a></p>



<span id="more-8798"></span>



<p>For this year&#8217;s focus week, we submitted a contribution under the Agentic AI theme, exploring both the opportunities and challenges associated with the deployment of increasingly autonomous AI systems across public and private sectors.</p>



<p>Drawing on our experience at the intersection of technology, law and regulatory compliance, our article examines how organisations can move beyond experimentation and implement AI agents in a practical, secure and accountable manner. Particular attention is given to the role of Agentic AI in the public sector, where intelligent automation has the potential to improve administrative efficiency, service delivery and decision-support processes.</p>



<p>The article goes beyond the discussion of technological capabilities alone. It highlights the legal and governance frameworks that are essential for responsible AI adoption, including UK GDPR compliance, AI governance structures, accountability mechanisms and regulatory obligations that organisations must address when deploying AI-driven systems.</p>



<p>We also discuss the growing importance of internationally recognised standards and frameworks, including ISO/IEC 42001 and the NIST AI Risk Management Framework, which provide organisations with practical tools for managing AI-related risks and building trustworthy systems.</p>



<p>A central theme of our contribution is the importance of data security, auditability, traceability and meaningful human oversight. As AI agents become increasingly capable of taking actions autonomously and interacting with multiple digital environments, organisations need robust governance mechanisms to ensure transparency, control and accountability.</p>



<p>In our view, the future of Agentic AI depends not only on technological innovation but also on the ability to balance innovation with responsibility. Sustainable adoption requires practical governance frameworks that enable organisations to realise the benefits of AI while maintaining trust, compliance and effective risk management.</p>



<p>We are delighted to contribute to this important conversation and look forward to supporting organisations as they navigate the evolving legal and regulatory landscape surrounding AI technologies.</p>



<p>KG Legal Kiełtyka Gładkowski</p>



<p>Technology, AI &amp; Digital Regulation Practice Group</p>



<p><em>See the full text of the contribution here:</em></p>



<h2 class="wp-block-heading"><strong>Agentic AI in the UK: Unlocking Sectoral Opportunities While Building the Foundations for Responsible Adoption</strong></h2>



<p>Artificial intelligence is entering a new phase of development. While recent years have been dominated by generative AI systems capable of producing text, images, and code, the next wave of innovation is increasingly focused on agentic AI &#8211; systems that can plan, reason, take actions, and interact with digital tools to achieve defined objectives with varying degrees of autonomy. Rather than merely responding to prompts, AI agents can execute multi-step tasks, coordinate workflows, and support decision-making processes across organisations.</p>



<p>For the United Kingdom, agentic AI represents a significant opportunity to improve productivity, strengthen public services, and enhance competitiveness across strategically important sectors. However, the successful deployment of these technologies at scale will depend not only on technological progress but also on the development of appropriate governance frameworks, organisational capabilities, and regulatory safeguards.</p>



<p>One of the most promising areas for adoption is <strong>the public sector</strong>. Government departments, local authorities, and public agencies manage large volumes of administrative processes that are often repetitive, time-consuming, and highly procedural. Agentic AI systems could support public servants by processing applications, managing case files, drafting correspondence, coordinating information across departments, and responding to routine citizen enquiries. In healthcare, AI agents could assist with patient triage, clinical documentation, appointment scheduling, and care coordination, helping to reduce administrative burdens and allowing healthcare professionals to focus on activities that require human expertise and judgement. At a time when public services face increasing demand and resource constraints, such efficiencies could have a meaningful impact on service delivery.</p>



<p>The financial and professional services sector, one of the UK&#8217;s most important economic strengths, also presents substantial opportunities. Banks, insurers, law firms, accounting practices, and consulting businesses rely heavily on information-intensive workflows that are often governed by detailed regulatory requirements. Agentic AI could automate compliance monitoring, support anti-money laundering investigations, review contracts, process insurance claims, conduct due diligence exercises, and assist with regulatory reporting. By reducing the time spent on routine analysis and documentation, organisations could improve operational efficiency while enabling skilled professionals to focus on higher-value strategic work.</p>



<p>Significant potential also exists in life sciences and healthcare innovation. Drug discovery, clinical research, pharmacovigilance, and regulatory compliance involve complex processes requiring the analysis and management of vast amounts of information. AI agents could help researchers identify relevant scientific literature, support clinical trial management, monitor safety data, and streamline documentation requirements. Given the UK&#8217;s strong research institutions and established life sciences ecosystem, agentic AI could contribute to both improved healthcare outcomes and economic growth.</p>



<p>Beyond knowledge-intensive industries, agentic systems could support manufacturing, infrastructure, transport, and energy. Applications may include predictive maintenance, supply chain optimisation, resource allocation, operational planning, and infrastructure monitoring. In the energy sector, AI agents could assist in balancing increasingly complex electricity networks, improving efficiency and supporting the integration of renewable energy sources. As the UK continues to modernise critical infrastructure and pursue net-zero objectives, intelligent automation may become an increasingly valuable tool.</p>



<p>While the opportunities are substantial, the widespread adoption of agentic AI will depend on overcoming a range of technical and organisational challenges. Autonomous systems must be reliable, secure, and capable of operating within clearly defined boundaries. Organisations will need robust mechanisms for evaluating agent performance, monitoring behaviour, identifying failures, and ensuring that human oversight remains available when necessary. The quality, accessibility, and interoperability of data will also be critical, as AI agents are only as effective as the information and systems with which they interact.</p>



<p>However, technology alone will not determine success. Many organisations continue to view AI as a standalone innovation initiative rather than a catalyst for broader transformation. Effective adoption will require the redesign of workflows, investment in workforce skills, and the establishment of clear governance structures. Employees must understand how AI systems operate, where their limitations lie, and when human intervention is required. Equally important is the allocation of responsibility for decisions made or influenced by AI systems. As autonomy increases, organisations must ensure that accountability remains clearly defined.</p>



<p>These governance considerations are becoming increasingly important as agentic AI systems move from experimentation to operational deployment. Although the UK has generally adopted a flexible and innovation-oriented approach to AI regulation, organisations deploying AI agents are already subject to a range of existing legal and regulatory obligations.</p>



<p>Unlike the European Union, which has introduced a dedicated regulatory framework through the EU AI Act, the United Kingdom has largely favoured a principles-based approach that relies on existing regulators and legal frameworks. This means that organisations deploying AI agents must consider how established laws apply to new technological capabilities rather than expecting a single comprehensive AI statute to provide all the answers.</p>



<p>Data protection law is particularly relevant where agentic systems process personal information. Under the UK GDPR and the Data Protection Act 2018, organisations must ensure lawful processing, transparency, accountability, and appropriate safeguards for automated decision-making. As AI agents increasingly influence decisions affecting individuals, issues such as explainability, fairness, and meaningful human oversight become more significant. Depending on the sector and use case, organisations may also need to consider obligations arising under consumer protection law, financial services regulation, employment law, equality legislation, cyber security requirements, and professional conduct rules.</p>



<p>Alongside formal regulation, an increasingly influential body of soft law is shaping expectations around responsible AI deployment. Guidance issued by the Information Commissioner&#8217;s Office (ICO), the Alan Turing Institute, the Centre for Data Ethics and Innovation (CDEI), and government bodies has helped establish practical principles relating to transparency, fairness, accountability, and human-centred design. While these instruments do not carry the same legal force as legislation, they are increasingly used as benchmarks by regulators, procurement authorities, and stakeholders when assessing whether organisations have deployed AI responsibly.</p>



<p>International standards are also beginning to play an important role. Frameworks such as ISO/IEC 42001, the first international management system standard specifically designed for AI governance, provide organisations with structured approaches to managing AI-related risks and responsibilities. Similarly, the NIST AI Risk Management Framework has emerged as an influential reference point for identifying, assessing, and mitigating risks throughout the AI lifecycle. Together, these frameworks are contributing to the development of a common governance language that may facilitate trust, interoperability, and regulatory compliance across jurisdictions.</p>



<p>For agentic AI specifically, governance challenges are amplified by the ability of systems to take actions, access external tools, and interact with multiple digital environments. Organisations will therefore need mechanisms that support auditability, traceability, incident management, and human escalation. Comprehensive logging, approval workflows, access controls, and continuous monitoring are likely to become essential features of responsible deployment. In practice, successful adoption may depend as much on governance design as on technical capability.</p>



<p>Ultimately, the UK&#8217;s opportunity lies not simply in adopting more AI, but in deploying increasingly capable systems in ways that generate measurable economic and societal value. The greatest benefits are likely to emerge where agentic AI is embedded within complex, high-volume workflows across both public and private sectors. Yet sustainable adoption will require more than innovation alone. It will depend on a careful balance between technological ambition, organisational readiness, and robust governance. Those organisations that invest early in accountability, risk management, and trust-building measures are likely to be best positioned to capture the benefits of agentic AI while navigating an increasingly complex regulatory and ethical landscape.</p>



<p>Prepared by KG LEGAL KIELTYKA GLADKOWSKI, iSTART1</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/">KG Legal Contributes to techUK’s Tech &#038; Innovation Focus Week 2026: Agentic AI, Governance and Responsible Adoption</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/kg-legal-contributes-to-techuks-tech-innovation-focus-week-2026-agentic-ai-governance-and-responsible-adoption/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
