<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Artificial intelligence - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/artificial-intelligence/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/artificial-intelligence/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Mon, 07 Sep 2026 20:31:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 20:30:11 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Act on Patients Rights]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI cybersecurity]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI-enabled attacks]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anonymisation]]></category>
		<category><![CDATA[anonymization]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[cloud healthcare]]></category>
		<category><![CDATA[controller liability]]></category>
		<category><![CDATA[Cyber Five]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[cyber resilience healthcare]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach response]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data minimisation]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data processing agreement]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection impact assessment]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[digital healthcare]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[e-health]]></category>
		<category><![CDATA[eHealth platforms]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR security]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Article 28]]></category>
		<category><![CDATA[GDPR Article 32]]></category>
		<category><![CDATA[GDPR Article 33]]></category>
		<category><![CDATA[GDPR Article 34]]></category>
		<category><![CDATA[GDPR Article 35]]></category>
		<category><![CDATA[GDPR Article 82]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR compliance healthcare]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare AI]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[healthcare contracts]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[healthcare data security]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[healthcare software]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT supplier contracts]]></category>
		<category><![CDATA[joint and several liability]]></category>
		<category><![CDATA[liability insurance]]></category>
		<category><![CDATA[medical data protection]]></category>
		<category><![CDATA[medical records]]></category>
		<category><![CDATA[medical technology]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[MyDr data breach]]></category>
		<category><![CDATA[National Cybersecurity System]]></category>
		<category><![CDATA[network segmentation]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[patient privacy]]></category>
		<category><![CDATA[patients rights]]></category>
		<category><![CDATA[Personal data breach]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attacks]]></category>
		<category><![CDATA[Poland cybersecurity]]></category>
		<category><![CDATA[Polish GDPR]]></category>
		<category><![CDATA[Polish healthcare law]]></category>
		<category><![CDATA[privacy by design]]></category>
		<category><![CDATA[processor liability]]></category>
		<category><![CDATA[pseudonymisation]]></category>
		<category><![CDATA[pseudonymization]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[special category data]]></category>
		<category><![CDATA[sub-processors]]></category>
		<category><![CDATA[subprocessor management]]></category>
		<category><![CDATA[supplier risk management]]></category>
		<category><![CDATA[technology contracts]]></category>
		<category><![CDATA[telemedicine]]></category>
		<category><![CDATA[third-party liability]]></category>
		<category><![CDATA[UODO]]></category>
		<category><![CDATA[vendor risk]]></category>
		<category><![CDATA[voice deepfake]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8909</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 What happened On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<h2 class="wp-block-heading"><strong>What happened</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:42% auto"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4"></video></figure><div class="wp-block-media-text__content">
<p>On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.</p>
</div></div>



<p>The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.</p>



<span id="more-8909"></span>



<p>To date, the company has not publicly confirmed the full scope and nature of the compromised data, referring instead to a pending forensic analysis. The investigation is being conducted by the Central Bureau for Combating Cybercrime under the supervision of the Warsaw Regional Prosecutor&#8217;s Office, and the President of the Personal Data Protection Office (UODO) has opened an inspection covering the technical and organisational measures applied and the underlying risk analysis. Since 29 August, the dataset from the incident has been available on the government portal bezpiecznedane.gov.pl, where anyone can check whether their data was affected.</p>



<p>The scale of the incident prompted the Ministry of Digital Affairs to announce, within three weeks, a legislative package branded the &#8220;Cyber Five&#8221;. Its key elements include certification of entities processing medical data within the existing national cybersecurity certification framework; a mandatory risk assessment before processing begins and at least every two years thereafter; new obligations for entities serving more than 100 controllers or processing data of more than 100,000 individuals (including rapid transfer of affected persons&#8217; data to CSIRT NASK and a duty to inform client facilities about the level of their own security); and notifications of medical events via the mObywatel and mojeIKP applications. The amendments are to cover the Act on Patients&#8217; Rights and the legislation governing the National Cybersecurity System.</p>



<h2 class="wp-block-heading"><strong>Why roles in the processing chain decide everything</strong></h2>



<p>From a legal standpoint, the critical point is that, in relation to medical records, MyDr acts as a processor, while each facility – from a large clinic network to a single-doctor practice – remains the controller. The consequences of this structure became fully apparent after the incident:</p>



<ul class="wp-block-list">
<li><strong>The obligation to notify UODO (Article 33 GDPR) and to communicate the breach to patients (Article 34 GDPR)</strong> rests with the controller, i.e. the facility. The processor is merely required to inform the controller &#8220;without undue delay&#8221; (Article 33(2) GDPR). In practice, thousands of healthcare providers had to assess risk and communicate with patients on the basis of fragmentary information from the supplier.</li>



<li><strong>Liability for damages (Article 82 GDPR)</strong> is joint and several: a patient may sue the facility, the supplier, or both. The processor is liable where it has failed to comply with obligations specifically imposed on processors by the GDPR or acted contrary to the controller&#8217;s instructions – but the facility is liable for having entrusted data to an entity that did not provide sufficient guarantees (Article 28(1) GDPR).</li>



<li><strong>Sector-specific requirements under the Act on Patients&#8217; Rights</strong> (Article 24(4)) impose on any entity entrusted with the processing of medical records a duty of confidentiality and data security – this is precisely the provision now slated for extension to include certification and minimum technological standards.</li>
</ul>



<p>Deputy Minister of Digital Affairs Dariusz Standerski stated openly that in this case, liability under the contract remained entirely with the controllers, i.e. small medical practices. This is the most important lesson of the incident: a data processing agreement is not a formality but the document that, on the day of a breach, determines who pays.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How a healthcare service provider can protect itself</strong></h2>



<p><strong>1. The data processing agreement and the main contract as risk-allocation tools.</strong> Standard DPA templates offered by software vendors focus on satisfying the minimum requirements of Article 28(3) GDPR. A healthcare provider should negotiate further: a precise deadline and format for incident notification (e.g. 24 hours, with a defined scope of information enabling a risk assessment); audit and penetration-testing rights; an obligation to maintain specified certifications (ISO 27001 and, in future, certification under the National Cybersecurity System Act); a duty to cooperate in communications with patients and the supervisory authority; liability and recourse clauses not capped at the annual fee; and a requirement that the vendor hold cyber insurance with a defined sum insured, with the facility named as a co-insured or beneficiary.</p>



<p><strong>2. Cyber and liability insurance.</strong> Standard professional liability policies for healthcare providers typically do not cover the cost of notifying patients, crisis management, administrative fines or claims arising from data breaches. A dedicated cyber policy covers these elements, but its exclusions must be read carefully: insurers increasingly condition cover on the implementation of MFA, system patching and backups, and an incident at an external supplier (a so-called <em>third-party breach</em>) is often covered only under an express extension. It is also worth verifying whether the software vendor&#8217;s own policy actually exists and what its limit is – given the number of facilities relying on a single system, such amounts may prove illusory.</p>



<p><strong>3. A map of relationships between entities.</strong> In a real-world e-health ecosystem, patient data flows between the facility, the EMR vendor, the hosting or cloud provider, the e-prescription and e-referral operator, laboratories, IT subcontractors and billing companies. Each link is a distinct legal relationship: processing on behalf of the controller, sub-processing (Article 28(2) and (4) GDPR) or joint controllership (Article 26 GDPR). A facility should maintain an up-to-date register of these entities, know where the data is physically located and control the chain of sub-processors – a &#8220;general&#8221; consent to sub-processors without a list and without a right to object is, in practice, an abdication of control.</p>



<p><strong>4. Anonymisation, pseudonymisation and data minimisation.</strong> Data that is not in the system cannot leak. Healthcare providers and vendors should separate identifiers (PESEL numbers, contact details) from clinical data, apply pseudonymisation (Article 4(5) and Article 32(1)(a) GDPR) in test, analytical and research environments, and store statistical data exclusively in anonymised form. It should be remembered that anonymisation is an irreversible process and only such a process removes data from the scope of the GDPR; pseudonymisation remains processing of personal data, but it significantly limits the consequences of a breach and is a valuable argument both in proceedings before UODO and in litigation over damages.</p>



<p><strong>5. Internal obligations and incident readiness.</strong> A breach response procedure should be tested, not merely written down: who decides on notifying UODO within 72 hours, who communicates with patients, who with the media, who secures the evidence. Regular risk analysis and a data protection impact assessment (DPIA) for EMR systems – which, given their scale and the categories of data involved, almost always meet the criteria of Article 35 GDPR – is an obligation already today, and once the &#8220;Cyber Five&#8221; enters into force it will additionally become a sector-specific requirement with a prescribed frequency.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>AI-enabled attacks</strong></h2>



<p>The healthcare sector is particularly exposed to a new generation of AI-supported attacks. Large language models enable the mass generation of credible phishing messages in flawless Polish, personalised on the basis of data from previous breaches – a PESEL number, a surname and information about a prescription are enough to construct a convincing message &#8220;from your clinic&#8221; or &#8220;from the National Health Fund&#8221;. AI tools also automate the discovery of vulnerabilities in systems and the generation of malicious code, shortening the window between disclosure of a vulnerability and its exploitation. There is a growing number of cases involving voice deepfakes used to impersonate medical staff or IT administrators in order to obtain access credentials.</p>



<p>For vendors and facilities, this means that traditional &#8220;don&#8217;t click suspicious links&#8221; training is no longer sufficient. Technical mechanisms are required (phishing-resistant MFA, network segmentation, AI-assisted anomaly monitoring on the defensive side), together with identity verification procedures for every request for data access or a change of permissions. Regulatory risk should also be kept in mind: AI systems deployed in healthcare facilities – including tools supporting diagnostics or triage – fall under the AI Act, and their integration with EMR systems constitutes yet another link in the processing chain that must be reflected in contracts and in the risk analysis.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How we support institutional clients</strong></h2>



<p>KG Legal advises healthcare providers, medical networks, telemedicine platform and e-health software vendors, and investors in this sector on managing liability for data. Our support includes auditing existing data processing agreements and IT supplier contracts for risk allocation; negotiating liability, recourse and insurance clauses; mapping the chain of processors and vetting subcontractors; preparing and testing breach response procedures; handling notifications to UODO and communications with patients; and representation in inspection proceedings and in damages litigation. For medical technology vendors, we prepare documentation and contract templates meeting the requirements of the GDPR, the Act on Patients&#8217; Rights, NIS2 and – once enacted – the &#8220;Cyber Five&#8221; provisions, and we assess the compliance of AI-based solutions with the AI Act and the MDR. Our aim is that, on the day an incident occurs, the client knows exactly who is responsible for what and has evidence of having exercised due diligence.</p>



<p><em>Facts as at 2 September 2026, based on statements by MyDr, the Ministry of Digital Affairs and UODO, and press reports. This article is for information purposes only and does not constitute legal advice.</em></p>
<p>#MyDr #DataBreach #HealthcareCybersecurity #HealthcareData #DataProtection #GDPR #Cybersecurity #HealthTech #eHealth #DigitalHealth #MedicalRecords #EMR #PatientData #PatientPrivacy #UODO #Poland #CyberRisk #CyberInsurance #IncidentResponse #DataPrivacy #NIS2 #CyberFive #ISO27001 #AIAct #AIinHealthcare #AICybersecurity #MedTech #Telemedicine #CyberResilience #DataSecurity</p>
<p> </p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4" length="492961" type="video/mp4" />

			</item>
		<item>
		<title>Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 12:02:57 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Aviation Law]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[defence financing]]></category>
		<category><![CDATA[Defence Industry]]></category>
		<category><![CDATA[drone industry]]></category>
		<category><![CDATA[Drone Law]]></category>
		<category><![CDATA[Drone Regulation]]></category>
		<category><![CDATA[Dual-Use Technology]]></category>
		<category><![CDATA[export controls]]></category>
		<category><![CDATA[legal landscape]]></category>
		<category><![CDATA[Lexology]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[regulatory landscape]]></category>
		<category><![CDATA[SANCTIONS]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[UAS regulation]]></category>
		<category><![CDATA[UAV Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8904</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 We are pleased to share that our in-depth report on the legal and technological landscape of the drone industry is featured today as the leading content on Lexology&#8217;s homepage. The report examines the rapidly evolving drone ecosystem through nine interconnected legal and regulatory pillars, including aviation law, artificial intelligence, cybersecurity, [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/">Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="1024" height="602" src="https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-1024x602.png" alt="" class="wp-image-8905" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-1024x602.png 1024w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-300x176.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-768x451.png 768w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY-1536x902.png 1536w, https://www.kg-legal.eu/wp-content/uploads/2026/09/AI-DRONE-WARFARE-LEXOLOGY.png 1583w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<span id="more-8904"></span>



<p>We are pleased to share that our in-depth report on the legal and technological landscape of the drone industry is featured today as the leading content on Lexology&#8217;s homepage.</p>



<p>The report examines the rapidly evolving drone ecosystem through nine interconnected legal and regulatory pillars, including aviation law, artificial intelligence, cybersecurity, data protection, sanctions, export controls, dual-use technologies and defence-sector financing.</p>



<p>As drone technologies advance faster than many existing regulatory frameworks, companies, investors and advisers must navigate an increasingly complex environment spanning civilian, dual-use and military applications.</p>



<p>We invite you to read the full report on our blog, available without a paywall:</p>



<p><blockquote class="wp-embedded-content" data-secret="V2PD940UnY"><a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a></blockquote><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8222;Drone Warfare&#8221; &#8212; KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019" src="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/embed/#?secret=LBenNwlEFP#?secret=V2PD940UnY" data-secret="V2PD940UnY" width="500" height="282" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe> </p>



<p>#DroneLaw #DroneTechnology #UAS #ArtificialIntelligence #Cybersecurity #DataProtection #DualUse #DefenceIndustry #AviationLaw #ExportControls #Sanctions #RegulatoryCompliance #TechnologyLaw #Innovation #LegalAnalysis</p>
<p> </p>




<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/">Our Report on the Legal Landscape of the Drone Industry Is Today’s Main Feature on Lexology</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/our-report-on-the-legal-landscape-of-the-drone-industry-is-todays-main-feature-on-lexology/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Drone Warfare</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 13:55:20 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Anti-Drone Technology]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Autonomous Weapon Systems]]></category>
		<category><![CDATA[Aviation Law]]></category>
		<category><![CDATA[BVLOS]]></category>
		<category><![CDATA[Counter-Drone Systems]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Defence Tech]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Drone Compliance]]></category>
		<category><![CDATA[Drone Law]]></category>
		<category><![CDATA[Drone Regulation]]></category>
		<category><![CDATA[Drone Warfare]]></category>
		<category><![CDATA[Dual-Use Export Controls]]></category>
		<category><![CDATA[Dual-Use Regulation]]></category>
		<category><![CDATA[Dual-Use Technology]]></category>
		<category><![CDATA[EU Drone Regulation]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[High-Risk AI Systems]]></category>
		<category><![CDATA[Military AI]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[Polish Drone Law]]></category>
		<category><![CDATA[U-space]]></category>
		<category><![CDATA[UAV Law]]></category>
		<category><![CDATA[Unmanned Aircraft]]></category>
		<category><![CDATA[Unmanned Aircraft Systems]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8874</guid>

					<description><![CDATA[<p>Publication date: August 26, 2026 The Legal Environment and Practical Aspects of Dual-Use Technology – the Ukrainian Conflict as a Lens on the Development of EU Regulation and the Polish Jurisdiction &#8211; Expanded Edition &#8211; Legal status as at 25 August 2026 Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: August 26, 2026</strong></mark></p>



<h3 class="wp-block-heading">The Legal Environment and Practical Aspects of Dual-Use Technology – the Ukrainian Conflict as a Lens on the Development of EU Regulation and the Polish Jurisdiction &#8211; Expanded Edition &#8211; Legal status as at 25 August 2026</h3>



<p><em>Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), attorney-at-law (radca prawny) Małgorzata Kiełtyka (M&amp;A, high-technology and highly regulated sectors) – KG Legal Kiełtyka Gładkowski Spółka Partnerska Kancelaria Radców Prawnych; iSTART1 programme.</em></p>



<p><em>This material is of a popular-science and informational nature. It does not constitute legal advice or a binding opinion. Before citing any specific provision, the current consolidated version in EUR-Lex and the current entry in the Polish Journal of Laws (Dziennik Ustaw) should be verified in each case.</em></p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="980" height="551" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png" alt="" class="wp-image-8875" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png 980w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-300x169.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-768x432.png 768w" sizes="(max-width: 980px) 100vw, 980px" /></a></figure>



<span id="more-8874"></span>



<h4 class="wp-block-heading"><em>Abstract</em></h4>



<p class="has-luminous-vivid-amber-background-color has-background">The Russo-Ukrainian conflict has become a lens in which the future of dual-use unmanned technology is brought into focus – and, at the same time, a barometer of the direction its regulation will take. Within two to three years, technological progress has occurred which, in peacetime conditions, would have taken decades. This article combines two perspectives: a technological taxonomy of drone warfare and a map of the legal environment of the European Union and Poland, encompassing nine mutually interpenetrating regulatory pillars – from product certification and airspace management, through artificial intelligence, export control, defence financing, satellite communications, cybersecurity and personal data protection, to international law and the national regime.</p>



<p class="has-white-color has-vivid-red-background-color has-text-color has-background has-link-color wp-elements-6caed12e936c828f3ed6d240556392b7"><strong>The thesis to be verified is that the legal regime of the UAV sector is structurally dual-track: on the civil track, law operates as a consequence of need and as a risk-dampening factor, whereas on the defence track it operates as a driver of development. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive instruments, while the line of dispute is the increasingly blurred dual-use boundary. We analyse seven concrete points of friction between the tracks and formulate a practical qualification map and a 2026–2028 compliance calendar for manufacturers, operators and investors in this sector.</strong></p>



<p><em><strong>Keywords:</strong> unmanned aircraft, dual use, Artificial Intelligence Act, high-risk systems, autonomous weapon systems, export control, U-space, NIS2, CER, personal data protection, European Drone Defence Initiative.</em></p>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile is-vertically-aligned-center has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-74fa267e46e25de8e613770e79a485db"><div class="wp-block-media-text__content">
<h3 class="wp-block-heading">Part I: the Legal Environment and Practical Aspects of Dual-Use Technology</h3>
</div><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/output.mp4"></video></figure></div>



<h2 class="wp-block-heading">1 Introduction</h2>



<h3 class="wp-block-heading">1.1 Nineteen objects over Poland – the moment when law caught up with reality</h3>



<p>The impulse to look at the drone problem not merely as a tactical phenomenon but as a growing strategic threat to Europe comes from reports circulating in the analytical and milblogger space – based on statements of Ukrainian military intelligence (HUR) – that Russia is already producing more jet-powered variants of the Geran-4 and Geran-5 than piston-engined Geran-2s, with figures in the order of approximately 3,000 jet platforms per month against approximately 2,800 piston variants. Assessments of this kind, even if they call for source-related caution, are of significant analytical importance: they show that the scale of Russian production of unmanned means of aerial attack may exceed the framework of a war of attrition against Ukraine and may be perceived as a capability able to support a broader campaign of pressure or threat directed at European states. In this sense, the drone problem is no longer an exclusively military issue, but also a stimulus for a fresh reading of the legal environment of unmanned technologies in Europe – from aviation law, through export control and AI, to cybersecurity, the protection of critical infrastructure and state security.<a href="#_ftn1" id="_ftnref1">[1]</a></p>



<p>On the night of 9/10 September 2025, a dozen or so unmanned aircraft flew into Polish airspace; some of them were shot down by NATO aircraft. This was not an isolated incident – the Romanian government had reported violations as early as January 2025, and in August of the same year a Russian Geran-2-type platform came down near Osiny in eastern Poland. The September event, however, carried a different weight: it triggered consultations under Article 4 of the Washington Treaty, led to the launch of NATO’s operation _Eastern Sentry_, and, in the EU dimension, to the announcement of a “drone wall”, subsequently transformed into the <strong>European Drone Defence Initiative (EDDI)</strong> and <strong>Eastern Flank Watch</strong>.</p>



<p>The current phase of the Russo-Ukrainian conflict makes it plain that both sides are developing unmanned technologies according to different operational logics and economics of use. The Russian side has to a greater extent expanded the segment of drones performing a function complementary to classic means of aerial attack: decoys, platforms imitating the actual strike assets, and cheap carriers used to saturate air defence and force the expenditure of effectors on the Ukrainian side. The Ukrainian side, conversely, is developing more broadly the segment of long-range drones with a real strike function, whose principal purpose is to strike rear-area infrastructure, including refineries, logistics and other objects of high operational value. This difference matters not only militarily but also in legal-regulatory terms, because it translates into different risk profiles as regards the qualification of dual-use technology, liability for the use of means of aerial attack, the protection of critical infrastructure, and the economics of air defence. In practice, the Russian model relies to a considerable degree on forcing a costly defensive reaction on the adversary’s side, whereas the Ukrainian model aims at the asymmetric striking of rear-area targets using relatively cheap platforms, which further deepens the problem of cost disproportionality between a cheap drone and an expensive defensive effector, such as the missiles of the S-300, S-400, Tor or Pantsir systems. In this sense, the conflict is a lens not only of the development of technology, but also of the transformation of the regulatory logic itself: law must now contend not with a single device, but with entire models of the operational use of unmanned technologies.<a href="#_ftn2" id="_ftnref2">[2]</a></p>



<p>For the lawyer, however, something else is most important. The facts give rise to questions about an asymmetry which is the crux of the entire regulatory problem: against platforms with a unit cost counted in thousands of dollars, systems were used whose single effector should cost hundreds of thousands. This cost asymmetry is not merely a budgetary problem. It forces the burden of defence to be shifted onto solutions that are cheap, mass-produced and increasingly autonomous – and therefore precisely onto that class of technology which European Union law regulates most cautiously on the civil side and almost not at all on the military side.</p>



<p><strong>The new regulatory architecture of drone security: from EU strategy to the obligations of critical infrastructure operators and AI systems</strong></p>



<p>Over the following months, the legislative tempo concerning unmanned systems accelerated in a manner unprecedented for this sector. The existing drone regulations had concentrated primarily on aviation safety, the rules for conducting operations, and technical requirements for operators and manufacturers. In 2026, however, a significant shift of regulatory emphasis took place: the drone began to be treated not only as an aviation device, but also as a potential tool of threat to critical infrastructure and as a system that may be subject to the requirements of artificial intelligence regulation.</p>



<p>The first element of this new architecture was the <strong>Action Plan on Drone and Counter Drone Security</strong> (COM(2026) 81 final) presented by the European Commission on 11 February 2026.<a href="#_ftn3" id="_ftnref3">[3]</a> This document does not constitute a legally binding act within the meaning of Article 288 of the Treaty on the Functioning of the European Union,<a href="#_ftn4" id="_ftnref4">[4]</a> but has the character of a European Commission communication – a political and programmatic instrument belonging to the category of so-called soft law. It does not establish direct obligations for Member States, undertakings or critical infrastructure operators, but it sets the direction of the European Union’s future legislative and organisational actions.</p>



<p>The significance of this document lies above all in a change in the way threats connected with unmanned aircraft are perceived. The Commission indicated that the rapid development of drone technologies, their commercial availability and the possibility of their use by entities conducting hostile activities make it necessary to build a European security system encompassing both protection against unauthorised drone operations (counter-drone) and the strengthening of the resilience of Member States’ infrastructure.</p>



<p>The Action Plan provides for the development of Member States’ capabilities in detecting, identifying and neutralising threats caused by drones, better information exchange between security authorities, and the development of counter-drone technologies. Particular importance was attached to the protection of critical infrastructure, military facilities, the external borders of the European Union, and places particularly exposed to the unlawful use of drones.</p>



<p>The European Commission’s Action Plan should accordingly be treated as the first level of the new regulation – the strategic level. It does not yet impose specific legal obligations, but it creates the political justification for subsequent legislative changes at national and EU level.</p>



<p>The second level was the intervention of the Polish legislator. The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts introduced solutions enabling the use of jamming devices in the protection of critical infrastructure.<a href="#_ftn5" id="_ftnref5">[5]</a></p>



<p>This amendment<a href="#_ftn6" id="_ftnref6">[6]</a> is of particular importance because, for the first time in the Polish legal system, an express basis was created for the application of measures interfering with the communications or control of unmanned aircraft by entities connected with the protection of critical infrastructure. It must, however, be precisely noted that the legislator did not grant critical infrastructure operators an independent right to use jamming devices.<a href="#_ftn7" id="_ftnref7">[7]</a> The legal construction was shaped at two levels.</p>



<p>First, <strong>Article 16c</strong>,<a href="#_ftn8" id="_ftnref8">[8]</a> added to the Act on Crisis Management, grants the critical infrastructure operator the competence to take a decision on the admissibility of the use of specified devices.</p>



<p>That provision reads:</p>



<p>“<em>In order to ensure the protection of critical infrastructure, the critical infrastructure operator (…) may take a decision on the admissibility of the use of the devices referred to in paragraph 1, for the time necessary for the performance of activities by security staff of specialist armed security formations (…)</em>”.</p>



<p>Second, the technical scope of those measures follows from the provisions of the <strong>Aviation Law</strong>, in particular Article 156ze(1), which sets out the possibility of using devices serving to counter unmanned aircraft.</p>



<p>Under that provision, such devices may be used for the purpose of:</p>



<p>“<em>interfering with or taking over control of an unmanned aircraft, interfering with the flight control signal or the navigation signal enabling the flight of that aircraft</em>”.<a id="_ftnref9" href="#_ftn9">[9]</a></p>



<p>In practice, this means that the critical infrastructure operator has obtained a new power of a decision-making character, whereas the physical use of the devices remains tied to the activities of the staff of specialist armed security formations (SUFO). This solution is a compromise between the need for effective protection of strategic facilities and the necessity of limiting the risk of uncontrolled use of devices capable of interfering with communications or navigation systems.</p>



<p>The explanatory memorandum to the bill<a href="#_ftn10" id="_ftnref10">[10]</a> stated that the purpose of the regulation is to increase the resilience of critical infrastructure and to provide operators with tools corresponding to contemporary threats, in particular threats making use of unmanned systems.</p>



<p>The third level of regulation was the modification of the timetable for the application of the provisions of the EU Artificial Intelligence Act.</p>



<p>On 29 June 2026, the Council of the European Union approved an amendment to Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the AI Act).<a href="#_ftn11" id="_ftnref11">[11]</a> This amendment did not change the AI Act’s basic risk-based regulatory model, but postponed the dates on which part of the obligations concerning high-risk systems begin to apply.</p>



<p>The most significant change was the extension of the preparatory period for providers of high-risk AI systems. The regulation was intended to enable undertakings, supervisory authorities and standardisation institutions to prepare the appropriate technical and organisational mechanisms, including conformity standards, risk assessment procedures and quality management systems.</p>



<p>This change is also relevant for the drone sector. Contemporary unmanned systems increasingly use artificial intelligence algorithms for autonomous navigation, object identification, image analysis or operational decision-making. In consequence, particular applications of drones may simultaneously be subject to aviation law regulations, provisions concerning the security of critical infrastructure, and the requirements of the AI Act.</p>



<p>By way of example, Article 113 of Regulation (EU) 2024/1689, which sets out the timetable for the application of the AI Act’s provisions, was amended as regards the dates of applicability of the rules concerning high-risk systems, postponing the full application of part of the obligations to later dates.<a href="#_ftn12" id="_ftnref12">[12]</a></p>



<p>As a result, in 2026 a multi-level regulatory architecture concerning a single device came into being. At European Union level, the European Commission set the strategic direction of the development of drone security policy through the non-binding Action Plan. At national level, Poland created a mechanism for the protection of critical infrastructure enabling the use of counter-drone measures. At the technological level, the AI Act laid down the principles of the responsible use of artificial intelligence systems employed in autonomous devices.</p>



<p><strong>Three different regimes. Three different regulatory logics. And all of them concern the same device.</strong></p>



<h2 class="wp-block-heading">1.2 The paradox of acceleration</h2>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="980" height="551" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png" alt="" class="wp-image-8877" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png 980w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1-300x169.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1-768x432.png 768w" sizes="auto, (max-width: 980px) 100vw, 980px" /></a></figure>



<p>The history of military technology knows few moments in which the development curve breaks as abruptly as in Ukraine after 2022. Commentators<a href="#_ftn13" id="_ftnref13">[13]</a> estimate that the technological leap<a href="#_ftn14" id="_ftnref14">[14]</a> in the field of unmanned aircraft accomplished during two to three years of war would, in the absence of an arms race, have taken 20–30 years.<a href="#_ftn15" id="_ftnref15">[15]</a> As to the period, it must be assessed that the thesis itself is <strong>fundamentally true</strong>, but the formulation “20–30 years” is not a scientific claim easily attributable to a single source. It is rather a <strong>metaphor used by military analysts, representatives of the defence industry and commentators</strong>, who describe a <strong>step-change acceleration of the innovation cycle</strong> under the influence of the war. In the space of only two to three years, drones travelled the road from specialised reconnaissance tools to mass-deployed combat systems, encompassing cheap single-use platforms, unmanned swarms, systems resistant to electronic jamming, and solutions using artificial intelligence. In the view of many military analysts, this conflict has shortened the development cycles of unmanned technologies in a way that, in peacetime conditions, would correspond to a multi-year or even multi-decade process of evolution.<a href="#_ftn16" id="_ftnref16">[16]</a></p>



<p>This paradox of acceleration has its source not in success but in failure.<a href="#_ftn17" id="_ftnref17">[17]</a> The original plan of a lightning resolution – seizing the capital within a week and taking control of the south of the country – collapsed already in the cyber phase, when the operation intended to paralyse the digital administration, banking and state budget did not translate into the country’s military collapse. The result was a positional stalemate in the east – trench warfare reminiscent of the fronts of a hundred years ago.</p>



<p>And it was precisely this stalemate, not manoeuvre, that became the incubator of innovation. Tactical pressure in an environment in which neither side can gain a conventional advantage forced a cascade of technological solutions: from commercial observation drones, through mass-scale FPV drones, to satellite-controlled long-range platforms with elements of autonomy.</p>



<p>It is worth emphasising that this mechanism was to a considerable extent <strong>civilian in its genesis</strong>. The drone revolution did not come out of the laboratories of the great arms concerns, but out of the model-making market, out of commercial consumer electronics and out of open-source software. A manufacturer which in 2021 was selling a platform for power-line inspection was in 2023 delivering the same design with a different payload configuration. The law, which for two decades had been building separate regimes for civil aviation and for armaments, found itself confronted with a product that crosses that boundary without any design modification.</p>



<h2 class="wp-block-heading">1.3 Thesis, research question and structure of the argument</h2>



<p>For a lawyer serving entities in the high-technology sector, the paradox of acceleration has a practical dimension. It gives rise to the question that is the axis of this text: <strong>does law in this area merely react to a technology which the conflict has outpaced, or has it itself become an instrument of acceleration – and perhaps, in some segments, an instrument of its extinguishment.</strong></p>



<p>The answer, which we substantiate in the remainder of this text, is: law performs <strong>three different roles simultaneously</strong> in this sector, and which of them is activated is decided not by the technology but by the qualification of the purpose of use. And that qualification is, in the case of dual-use products, inherently unstable.</p>



<p>The structure of the argument is as follows. Part 2 presents the technological taxonomy of drone warfare – without it, legal analysis operates in a vacuum, because each of the regulatory regimes attaches legal consequences to specific technical features (mass, range, presence of sensors, degree of autonomy, type of link). Part 3 maps the legal environment of the European Union and Poland, divided into nine pillars.</p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png" target="_blank" rel=" noreferrer noopener"><img loading="lazy" decoding="async" width="627" height="353" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png" alt="" class="wp-image-8879" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png 627w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2-300x169.png 300w" sizes="auto, (max-width: 627px) 100vw, 627px" /></a></figure>



<p>Part 4 analyses seven points of friction at which these pillars collide with one another – it is there that the undertaking’s real legal risk is concentrated. Part 5 formulates the thesis of the dual-track nature of the regime. Part 6 translates the analysis into transactional and compliance practice, together with a compliance calendar up to 2028.</p>



<h2 class="wp-block-heading">2 · The Anatomy of Drone Warfare – a Technological Taxonomy</h2>



<p>The point of departure for any legal analysis must be the differentiation of categories. It is a fundamental error – also in the regulatory debate – to treat the “drone” as a single class of devices. A more apt analogy here is to optics and photography: there is no single universal lens for every photograph, because each type of shot – macro, portrait, telephoto, wide-angle landscape – requires a different optical construction, a different focal length and a different compromise between reach and field of view. It is exactly the same with drones and counter-drone systems: there is no single “anti-drone system”; there are systems countering specific categories of platforms, matched to their signature, range and mode of communication. This differentiation is not merely descriptive but legal in character – it determines product qualification, the export regime and the scope of compliance obligations.</p>



<p>This differentiation has directly normative consequences. At the level of product qualification, the mass, construction and intended purpose of the platform determine its place in the EU UAV regime, in particular in Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, which treat product classes and the “open”, “specific” and “certified” categories of operations differently; in practice this means that the same aircraft may, as a product, remain in lawful civil circulation while at the same time, with a different mode of use or retrofitting, pass into the area of heightened regulatory risk. At the level of the export regime, the identical differentiation decides whether a component, software, sensor, communications module or navigation system falls within the scope of Regulation (EU) 2021/821 as a dual-use product, which may trigger an authorisation requirement, an end-user assessment and a proliferation risk analysis. At the level of compliance obligations, in turn, what matters are not only the physical features of the drone but also its data and autonomy functions: the presence of cameras, sensors or AI modules may in parallel trigger the requirements of the GDPR, cybersecurity, information security and – outside the scope of the military exclusion – the obligations arising from the AI Act. As a result, in the UAV sector it is not enough to ask “what is the product”; the key question becomes in what chain of use, circulation and liability the product operates.</p>



<p>The importance of this differentiation lies in the fact that, in the UAV sector, technical categories translate into different normative consequences in several overlapping legal regimes at once. First, at the level of product and operational qualification, features such as take-off mass, communications architecture, scope of autonomy or type of payload affect the classification of the platform in the light of Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, and thus the admissibility of its placing on the market and the mode of its lawful operation. Second, at the level of export control, the same features may determine whether specific components, sensors, navigation modules, software or technical documentation are covered by the regime of Regulation (EU) 2021/821, which triggers licensing obligations, end-user assessment and proliferation risk assessment. Third, at the level of functional compliance, what matters is no longer only the material features of the platform itself, but also its data-processing, observation and decision-support functions: the use of optical sensors, thermal-imaging sensors, remote identification systems or image-analysis algorithms may in parallel trigger requirements arising from the GDPR, cybersecurity regulation and – outside the scope of the military exclusion – the obligations laid down in the AI Act. In this sense, the legal qualification of a drone is not a one-off act but a multi-layered process, dependent on construction, function, context of use and the architecture of circulation.<a href="#_ftn18" id="_ftnref18">[18]</a></p>



<p>A separate phenomenon, irreducible to any of the above categories, is the drone swarm. Whereas the existing taxonomy ordered drones according to the features of a single platform – mass, range, mode of communication, degree of autonomy – the swarm is an emergent phenomenon at the level of many platforms operating as one system. Three elements are key here: iteration and coordination between units (drones exchange data on position, target and status in real time, often via a mesh network, with no single point of failure), distributed processing of sensor data (imagery and telemetry from many platforms are aggregated and classified jointly, which increases target-detection effectiveness beyond the sum of individual sensors), and collective control by a single operator or a supervisory algorithm which allocates tasks among the units of the swarm. Ukrainian deployments of this technology – including autonomous swarming systems used since 2025 for mine-laying and target engagement, and large-scale operations combining several dozen to several hundred platforms in a single strike – show that the swarm is no longer an experiment but an operational reality. This has serious legal consequences which remain unresolved to date: whether the swarm should be qualified as a single system subject to a single conformity assessment or as a collection of separate products; who bears responsibility for a decision taken at swarm level when no single platform takes it independently; and how the data protection and radio spectrum management regime is to treat a network whose nodes come into being and disappear in flight.<a href="#_ftn19" id="_ftnref19">[19]</a></p>



<p>This differentiation is not merely terminological or descriptive in character, but produces direct legal effects. The individual technical properties of an unmanned aircraft constitute the triggering conditions for different regulatory regimes of European Union law and national law. In practice, this means that a change in one technical parameter of a drone may lead to a fundamentally different legal qualification of the same device.</p>



<p>The first such parameter is the <strong>Maximum Take-Off Mass (MTOM)</strong>. Commission Delegated Regulation (EU) 2019/945 establishes classes of unmanned aircraft systems (C0–C6), whose assignment takes place, among other things, with regard to technical parameters, in particular mass, speed and system equipment. This classification is not purely technical in character – it determines the possibility of conducting operations in the appropriate subcategories of the “open” category provided for in Commission Implementing Regulation (EU) 2019/947 and affects the manufacturer’s obligations connected with conformity assessment and product class marking.<a href="#_ftn20" id="_ftnref20">[20]</a></p>



<p>The significance of mass is also revealed at the level of the operator’s obligations. Under Article 14 of Implementing Regulation (EU) 2019/947, the operator of an unmanned aircraft system is subject to a registration obligation, inter alia, where it operates an aircraft with a maximum take-off mass of at least <strong>250 g</strong> or – regardless of mass – an aircraft equipped with a sensor capable of capturing personal data, unless the device meets the conditions provided for toys within the meaning of Directive 2009/48/EC. The 250 g mass thus constitutes one of the fundamental legal thresholds in the European drone regulatory system.<a href="#_ftn21" id="_ftnref21">[21]</a></p>



<p>The second parameter of fundamental importance is the <strong>drone’s equipment with sensors enabling the capture of personal data</strong>, above all optical cameras, thermal-imaging cameras, LiDAR scanners or other devices allowing the identification of natural persons. In such a case, the General Data Protection Regulation (GDPR) applies. Data recorded by a drone may constitute personal data within the meaning of Article 4(1) GDPR, which entails the necessity of ensuring a legal basis for processing in accordance with Article 6 GDPR, complying with the principles set out in Article 5 GDPR and – in the case of operations creating a high risk to the rights and freedoms of natural persons – carrying out a data protection impact assessment in accordance with Article 35 GDPR. These obligations arise regardless of the mass of the aircraft, and therefore also in relation to the smallest drones weighing under 250 g, if they are equipped with devices enabling the capture of personal data.<a href="#_ftn22" id="_ftnref22">[22]</a></p>



<p>This approach is confirmed in the case law of the Court of Justice of the European Union. In its judgment of 11 December 2014 in Case <strong>C-212/13, Ryneš</strong>, the Court held that the recording of images enabling the identification of natural persons constitutes the processing of personal data, even if it takes place with the use of devices monitoring the surroundings of private property. Although the case concerned video surveillance, the conclusions flowing from that judgment apply mutatis mutandis also to unmanned systems equipped with cameras or other observation sensors.<a href="#_ftn23" id="_ftnref23">[23]</a></p>



<p>A further feature determining the legal regime is the <strong>character of the equipment and payload</strong>. Regulation (EU) 2021/821 of the European Parliament and of the Council establishes the Union’s system for the control of exports of dual-use items. The qualification of a drone or its components for the list of dual-use items is decided not only by flight parameters but also by the technical capabilities of the device, such as range, autonomy, navigation systems, observation equipment, high-resolution cameras, data transmission systems or specialised sensors. In consequence, two seemingly similar drones may be subject to entirely different export obligations solely on account of differences in their equipment or technical capabilities.<a href="#_ftn24" id="_ftnref24">[24]</a></p>



<p>Even more complex is the legal qualification of systems using <strong>artificial intelligence</strong>. The degree of flight autonomy alone does not automatically determine the applicability of the AI Act. It must first be established whether the given solution constitutes an “AI system” within the meaning of Article 3 of Regulation (EU) 2024/1689. Only at the next stage is it necessary to assess whether the system belongs to the high-risk category in accordance with Article 6 of that regulation and Annexes I and III. This means that two drones with identical flight parameters may be subject to different regulatory obligations solely on account of differences in the software responsible for autonomous navigation, object identification, image analysis or operational decision-making.<a href="#_ftn25" id="_ftnref25">[25]</a></p>



<p>In consequence, the legal qualification of an unmanned aircraft does not follow from a single technical feature, but from the configuration of its constructional, functional and operational properties. The same drone may simultaneously be subject to aviation law regulations, personal data protection provisions, the dual-use item control regime, provisions concerning the protection of critical infrastructure and – in specific cases – Regulation (EU) 2024/1689 (the AI Act). This signifies a transition from the classic model of sectoral regulation to a model of functional regulation, in which different branches of law simultaneously apply to the same device, protecting different legal goods: aviation safety, privacy, state security, control of trade in technologies and the safety of artificial intelligence systems.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.1 · Observation drones – the foundation of situational awareness</strong></h3>



<p>The lowest tier consists of commercial multirotor drones (the Chinese DJI Mavic,<a href="#_ftn26" id="_ftnref26">[26]</a> Ukrainian equivalents of the Zoom class). Their role is to provide <strong>situational awareness</strong> – the category that decides the success of every assault and every defence. A contemporary soldier with an overhead picture operates in an entirely different reality from one who scans the field with his eyes.</p>



<p>In the Ukrainian trade and military-technology discourse,<a href="#_ftn27" id="_ftnref27">[27]</a> the designation ZOOM refers to a specific reconnaissance platform developed by the Ukrainian company Frontline / Frontline Robotics, presented as an alternative to the Chinese DJI Mavic drones. It is a light multirotor observation drone intended for reconnaissance tasks, fire correction and building situational awareness at the tactical level, and therefore for the same operational niche which for a long time was dominantly occupied at the front by Mavic platforms. In this sense, the “Ukrainian equivalent of the Mavic of the ZOOM class” should be understood not as a formal technical category but as the proper name of a domestic platform positioned in the segment of light reconnaissance drones with a substitutive function vis-à-vis DJI. The available sources<a href="#_ftn28" id="_ftnref28">[28]</a> also indicate that ZOOM forms part of a broader Ukrainian trend of building domestic Mavic analogues in order to reduce dependence on foreign civilian commercial systems.</p>



<p>Importantly, despite rapid development these platforms have not disappeared – on both sides of the front, civilian Mavics are still used, whose sole task is to “hang in the air and watch”. This is an observation of primary legal importance: <strong>the most numerous category of platforms used in the conflict consists of mass-produced consumer products, placed on the market under the civil regime, with CE marking, in classes C0–C2.</strong> The same unit which yesterday was subject to Implementing Regulation (EU) 2019/947 as an operation in the open category is today carrying out a reconnaissance task outside any EU regime.</p>



<p>The DJI Mavic constitutes a model example of the detachment of the product from the purpose of use. As a commercial product, it was designed and placed on the market for the needs of the civil market: photography, inspection, surveying, recreation and light professional applications. In that order, its legal status is determined by the classic instruments of EU aviation law and product law – in particular the requirements of CE marking, the product classes under Delegated Regulation (EU) 2019/945, the operating rules under Implementing Regulation (EU) 2019/947, the operator’s obligations, remote identification, geographical zones, registration and – depending on the sensor configuration – data protection requirements. However, the moment that same unit is used on contested territory to build situational awareness, correct fire or conduct military reconnaissance, the logic for which the EU civil aviation regime was built ceases to operate. The product itself as a thing does not change, but its operational function changes, and with it the normative order changes: from the area of product safety and lawful civil operation we pass into the area of military operations, military logistics, the law of armed conflict, export control and state security. It is precisely for this reason that, in the UAV sector, the legal nature of a platform is increasingly determined not by its construction but by the chain of use into which it is incorporated.</p>



<p>A good counterpoint to this transformation is the example of the Ukrainian Mavic equivalents, such as the ZOOM developed by the above-mentioned Frontline Robotics. Where the manufacturer communicates<a href="#_ftn29" id="_ftnref29">[29]</a> that a given complex has been entered in the NATO Codification System (NCS) and has received a NATO Stock Number (NSN), this means not so much the obtaining of civil certification as the product’s entry into the common language of NATO defence logistics: the item is unambiguously identified, classified and prepared to function within the system of supply, storage and military interoperability. The NSN is therefore a catalogue-logistics designation, not a mark of quality or an authorisation for marketing in the sense of consumer law or civil aviation law. The juxtaposition of the Mavic with a platform codified in the NATO system well illustrates the institutional shift: the first product begins its life in the regime of civil commercialisation, while the second is from the outset positioned as an element of the defence architecture and the military supply chain. This difference does not consist solely in technology, but in normative embedding – that is, in whether the product is designed for the civil market or for the order of military logistics and allied interoperability.<a href="#_ftn30" id="_ftnref30">[30]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.2 · FPV drones – a squad weapon and the cost revolution</h3>



<p>The current combat standard in the front-line zone is the FPV (first person view) drone – single-use platforms controlled from a first-person perspective through goggles. This is not, however, a weapon of the individual soldier: the operation of a single drone requires a team of 3–4 persons (pilot, relay operator, sapper, frequently a navigator). The FPV is a squad weapon, like a mortar or a heavy machine gun. One team is able to carry out 25–30 sorties a day, consuming a corresponding number of single-use platforms.<a href="#_ftn31" id="_ftnref31">[31]</a></p>



<p>The scale of this revolution has above all an economic and institutional dimension. It is no accident that industry analyses describe FPV as the “$1,000 revolution”: the essence of the breakthrough lies not solely in the platform itself, but in the relationship between the low unit cost of the means of attack and the high cost of countering it, as well as in the possibility of rapidly scaling production on the basis of a dispersed component market, a simple assembly architecture and short iteration cycles. In this sense, FPV is not merely a new category of drone but a new model of the economics of war – a model in which a relatively cheap, partly standardised and rapidly modifiable platform can generate tactical and operational effects disproportionate to its price. That is precisely why the weight of the analysis shifts from the question of the individual product to the question of the production ecosystem, the capacity for its continuous reproduction, and the institutional conditions that enable the transition from field improvisation to mass production.<a href="#_ftn32" id="_ftnref32">[32]</a></p>



<p>In the case of Ukraine, this capacity is no longer solely the effect of spontaneous industrial mobilisation, but results from the construction of an organised, state-supported defence tech ecosystem, centred on the Brave1 platform.<a href="#_ftn33" id="_ftnref33">[33]</a> Brave1 was launched on 26 April 2023 as a governmental defence tech cluster, co-created by the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries,<a href="#_ftn34" id="_ftnref34">[34]</a> with the implementation layer carried out by the Innovation Development Fund. From a legal perspective, this is not a classic commercial-law company nor a single procurement procedure, but rather a public coordination platform combining grant, testing, matchmaking and acceleration functions. Officially, Brave1 describes its role as supporting the development of defence technologies through organisational, informational and financial support for projects, and the platform’s successive initiatives – including grant programmes, a defence innovation marketplace and projects carried out with international partners – show that it operates as an intermediate layer between the technological idea, the prototype, military testing, IP protection and further implementation into procurement or operational use. It is therefore an institutional mechanism for mobilising defence innovation, not a separate, homogeneous statutory regime.</p>



<p>The significance of Brave1 for the FPV market lies in the fact that this platform aggregates dispersed manufacturers and lowers the threshold of entry into the defence sector, shortening the road from design to implementation. Analytical sources indicate that around 1,500 defence tech companies and start-ups are gathered around Brave1, with some more recent analyses speaking of an even greater number of entities functioning within this ecosystem.<a href="#_ftn35" id="_ftnref35">[35]</a> From the point of view of this report, however, more important than the number itself is that Brave1 produces an architecture of scale: new entities can enter the sector via a grant, testing, validation, contact with the military user, intellectual property protection and entry into the procurement circuit, without having to pass immediately through the classic, heavy model of the armaments industry. It is precisely this institutional model that explains why Ukraine was able to move from the early phase of improvisation and purchases from the commercial market to a phase in which drone production began to be treated as a mass state capability.<a href="#_ftn36" id="_ftnref36">[36]</a></p>



<p>The volumes of this production are unprecedented. Industry analyses and statements by representatives of the Ukrainian authorities cite figures of the order of about 800 thousand drones in 2023, about 2 million in 2024, production capacities reaching 4 million annually, and subsequently procurement plans covering about 4.5 million FPV drones in 2025. In parallel, declared targets for 2026 have also appeared in public circulation, according to which Ukraine would aim for a level of 7 million drones annually, presented as a volume many times exceeding American production. Even if the individual figures must be treated with caution and a distinction must be drawn between actual production, production capacity, procurement plan and political-industrial target, the direction itself is unambiguous: Ukraine has transformed drones – especially FPV – from an auxiliary technology into an industrial strategic resource, whose development depends no longer solely on the technical capability of an individual manufacturer, but on state-supported organisational, grant, testing and procurement infrastructure. In this sense, Brave1 operates as a multiplier of production sovereignty: it not only supports a specific project, but builds the conditions in which the entire sector can reproduce itself, scale and become independent of imports of ready-made platforms.<a href="#_ftn37" id="_ftnref37">[37]</a></p>



<p>In the legal and economic layer, it is particularly significant that Brave1 is not limited to the distribution of public funds from the Ukrainian budget. Over time, this platform has also been opened to international grants, partnerships with Western states and institutions, and channels of cooperation with the NATO procurement and interoperability environment. This means that the Ukrainian FPV market is today developing at the intersection of national law, mechanisms of public support for innovation, defence cooperation with foreign partners, and the wartime logic of rapid testing and deployment. From this perspective, the success of Ukrainian unmanned production should not be described solely as an industrial success, but also as a success in the design of institutional instruments which have made it possible to combine thousands of smaller entities into one functional ecosystem capable of delivering effects at the scale of millions of units annually.</p>



<p>The mass character of FPV production and the dispersal of suppliers in Ukraine are not solely a spontaneous effect of wartime mobilisation, but the result of the institutional ordering of the defence tech ecosystem. The importance of Brave1 lies precisely in the fact that this platform does not replace the individual manufacturer or the classic armaments industry, but creates an organisational framework within which hundreds – and, according to the available sources, around one and a half thousand – entities can function as elements of a single innovation-production system. From a legal and economic perspective, Brave1 is therefore not merely a sectoral cluster, but an instrument of the state ordering of defence innovation: it shortens the road from idea to test, from test to grant, from grant to implementation, and in the longer perspective – to an order or operational use. This architecture can be described most cleanly at three levels: institutional, project and operational.</p>



<p class="has-pale-pink-background-color has-background"><strong>1. The institutional level</strong></p>



<p>At the institutional level, Brave1 functions as a governmental initiative / defence tech cluster of Ukraine, launched on 26 April 2023 and co-created by the key state organs responsible for security, defence and technology policy, in particular the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries. The official description further indicates that the initiative is implemented by the Innovation Development Fund, which allows Brave1 to be treated as an instrument embedded at the interface of public administration, the security sector and state innovation policy. It does not follow from the publicly available materials that Brave1 is a self-standing entity established by a single separate statute or a single specific normative act; it is more accurate to conceive of it as a state coordination platform whose status results from the combination of the competences of public institutions and the implementation mechanisms of the innovation development fund. It is precisely this institutional embedding that explains why Brave1 was able to become a focal point for a broad ecosystem of drone manufacturers, including FPV platforms, instead of remaining merely a grant programme or a sectoral initiative of limited reach.</p>



<p class="has-pale-pink-background-color has-background"><strong>2. The project level</strong></p>



<p>At the project level, the Brave1 cluster has been linked with the European Union-financed undertaking EU4UA Defence Tech, functioning publicly under the title “Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base”. It follows from the available sources that this is not a self-standing act of secondary Union law of the kind of a regulation or directive, but an implementation and grant project, officially announced by the Delegation of the European Union to Ukraine within the EEAS structure, financed by the European Union and implemented by BRDO in cooperation with Brave1. In this architecture, Brave1 plays the role of the Ukrainian cluster and access point to the defence tech ecosystem, while the project layer gives this ecosystem an additional dimension of internationalisation, grant support and linkage with the policy of strengthening the Ukrainian defence technological and industrial base. The formal specification of this layer does not, however, take place through a single “founding act” of statutory or Union rank, but through a set of project and operational documents: the EEAS institutional communication, the BRDO project description and the regulations of the grant programme.</p>



<p>Particularly significant from the point of view of a legal report is that the project layer finds its concrete expression in the draft grant agreement concluded between the Innovation Development Fund and the beneficiary being the developer of a specific technology.<a href="#_ftn38" id="_ftnref38">[38]</a> This means that entry into the Brave1 / EU4UA Defence Tech system does not lead directly to a relationship with a Union institution in the typical model of a European Commission grant, but to a contractual relationship governed by Ukrainian law with a public entity on the Ukrainian side. From this perspective, the project level of Brave1 should be understood as a space in which the dispersed sector of manufacturers – including creators of FPV technology – is drawn into a structured model of public support, but at the price of entering a specific contractual regime. Of particular importance here are the clauses concerning ownership and intellectual property rights: the draft grant agreement provides that ownership rights and rights to IP created with the use of grant funds as a rule remain with the developer, which at first sight may suggest a model friendly to commercialisation and to the retention of private control over the result of the project. At the same time, however, the same draft agreement grants the fund a broad, free-of-charge entitlement to use – at its own discretion – all documents and information obtained in the course of the granting of the grant, insofar as such use remains consistent with existing IP rights. This construction therefore does not lead to a simple takeover of IP by the state, but creates a hybrid model of control in which formal ownership remains with the developer, while the fund secures for itself a strong position of access and use in relation to the documentation and information connected with the project. In legal practice, this means that the key question is no longer only who owns the result, but also how broadly the scope of “documents and information” will be interpreted, what technical material is transferred to the fund, and where the boundary runs between the authorised use of documentation and indirect interference with the developer’s economic exclusivity (in accordance with Article 5(1) and (2) of the grant form: “<em>Ownership rights and property rights to intellectual property created as a result of the use of Grant funds belong to the Developer, unless otherwise specified by the Developer.”; ”The Developer grants the Fund the right to use, free of charge and at its own discretion, all documents and information obtained in the process of providing the Grant, if such use complies with existing intellectual property rights</em>”) (see footnote 38).</p>



<p>This tension is further reinforced by the clause on governing law and disputes, according to which the agreement is to be interpreted under the law of Ukraine, and any disputes are to be resolved first by way of negotiations and then in accordance with the procedure provided for by Ukrainian law and/or before a court. In the functional sense, Brave1 / EU4UA Defence Tech therefore remains an undertaking co-financed and politically legitimised by the European Union, but its contractual core – at least at the level of the relationship with the developer – has a clearly Ukrainian jurisdictional embedding. It is precisely this element that should close the analysis of the project level: Brave1 is not solely a mechanism for stimulating innovation, but also a system in which the Ukrainian state, through the innovation development fund and the contractual template, shapes the rules of access to technology, documentation and the results of R&amp;D work. Thanks to this, the cluster can perform the function of a multiplier of mass and scale of production, but it does so in a formula which combines the retention of private intellectual property with a public safeguarding of informational and operational access. It is precisely this combination – and not the mere number of manufacturers – that explains why the dispersed market of FPV suppliers can be integrated into a single functional ecosystem of state-supported defence capability.<a href="#_ftn39" id="_ftnref39">[39]</a></p>



<p class="has-pale-pink-background-color has-background"><strong>3. The operational level</strong></p>



<p>At the operational level, the basic source document is not a general political communication but the regulations of the grant programme, i.e.&nbsp;the Regulations for the Brave1 EU4UA Defence Tech Grant Program, made available in the Legal Terms section of the programme. It is precisely this document that constitutes the most useful source for practical analysis: it determines the framework of participation, the conditions of application, the function of grant support and the operational rules of the call within the initiative linked with EU4UA Defence Tech. In combination with the EEAS communication and the BRDO project description, this document creates the actual operational basis of the programme: the institutional communication legitimises the project and its financing by the EU, the project description indicates its purpose and place in the architecture of cooperation, while the grant regulations order the manner in which undertakings and technology teams can enter the support system. From the perspective of a legal report, it is precisely this operational layer that is key to understanding how dispersed manufacturers of FPV and other defence technologies have been gathered around a single cluster: not through an abstract political declaration, but through a set of specific procedures, grants, tests, validations and pathways to implementation. As a result, Brave1 operates as an institutional multiplier of production capability – it not only finances innovation but organises its transition into a mass state capability.<a href="#_ftn40" id="_ftnref40">[40]</a></p>



<p>The regulatory consequence of this scale is under-appreciated. Product certification regimes – both aviation and armaments – were built around the assumption of small-series production of goods with a long life cycle and high unit value. A model in which a platform comes into being within a week, is consumed within hours and undergoes continuous design modification in reaction to the adversary’s countermeasures is structurally incompatible with that assumption. No European conformity regime was designed for a product whose iteration cycle is shorter than the conformity assessment cycle.</p>



<p>That is precisely why the Ukrainian mass production of FPV should not be described solely as the result of wartime improvisation or of the cost advantage of a cheap platform over an expensive defensive effector, but also as the result of a consciously built institutional architecture in which Brave1 performs the function of a common node for the state, the military, grant-givers and the dispersed defence tech industry.<a href="#_ftn41" id="_ftnref41">[41]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.3 · Communications, the radio horizon and relays</strong></h3>



<p>The effectiveness of FPV depends on communications to a degree perhaps greater than on the quality of the platform itself, and the absolutely fundamental category here is the <strong>radio horizon</strong>. The radio horizon is not a separate normative concept of EU law or of Polish aviation law, but a technical-operational category describing the limit of effective propagation of a radio signal in communications requiring a line of sight between transmitter and receiver. In practice, this means that the range of control and data transmission depends not only on the power of the devices, but also on antenna height, terrain obstacles, built-up areas, forestation and the shape of the terrain. The legal significance of this category is therefore indirect in character: the concept itself is not regulated as a statutory definition, but the phenomena it describes enter legal analysis through the regime of radio equipment, spectrum management, electronic communications, and the safety and reliability requirements for unmanned operations, especially BVLOS and within U-space.<a href="#_ftn42" id="_ftnref42">[42]</a></p>



<ul class="wp-block-list">
<li><strong>BVLOS – flight beyond visual line of sight, i.e. beyond the operator’s visual range.</strong><br><strong>In practice, it is precisely this category of operations that most needs stable, trusted and legally permissible relay infrastructure.</strong></li>



<li><strong>U-space – simplifying, this is the digital drone traffic management environment, created so that a larger number of drones can fly safely, predictably and in an automated manner, especially in more difficult operations and denser airspace.</strong></li>
</ul>



<p>The control signal and image transmission in classic FPV systems require as clean a line of sight as possible, which is why their propagation is attenuated not only by buildings, forest walls or dense development, but also by the relief of the terrain itself: depressions, escarpments, embankments, forested ridges, rural development and all obstacles that “break” the connection between the operator and the platform. In the realities of the Russo-Ukrainian war, this means that the advantage does not follow solely from the flight parameters of the drone, but from the ability to raise the communications point above terrain obstacles and to maintain a stable transmission channel despite jamming, masking and target movement. Hence the great importance acquired by relays – signal repeaters mounted on masts, on ground vehicles, and most often on separate drones hovering higher than the combat platform. In the simplest variant, such a relay is a separate item of equipment, a kind of “communications superstructure” added to the system; in more advanced solutions, the relay function becomes part of a larger architecture, in which one drone carries the payload, a second observes, a third provides retransmission, and further nodes take over part of the traffic in a network model. This means that the relay need not be understood solely as a single device purchased separately – increasingly it is a separate technological layer, which may take the form of a radio module, an additional aerial platform, a ground set, or a node in a mesh network. It is precisely here that one of the most interesting trends appears: the transition from a single repeater to a layered architecture, and then to dynamic mesh networks, in which every modem or selected platforms can simultaneously transmit and repeat the signal, creating a self-repairing chain of communications. In such an arrangement, the radio horizon problem is no longer solved by a single device, but by a system of systems, functionally approaching a swarm with a division of roles. This in turn means that <strong>the most valuable IP in this segment may not reside in the airframe at all, but in the signal-routing algorithms</strong>, <strong>node switching, jamming resistance, bandwidth management and the integration of the relay function with the combat or reconnaissance role</strong>. Competitive advantage may here be protected as a patent, software, a trade secret or systemic know-how; in practice, value increasingly shifts from “the drone itself” to the communications and control architecture which allows the platform to operate effectively outside the classic line of sight. In this sense, the fight for advantage in the air simultaneously becomes a fight over who will build a higher-elevated, more resilient and more intelligently managed transmission network than the adversary.</p>



<p>This architecture has legal significance extending beyond the battlefield. <strong>Retransmission</strong> is in essence the construction of an <strong>ad hoc, mobile radio communications network</strong> – and thus an activity which, in the civil regime, is subject to electronic communications law, spectrum management and the requirements of Directive 2014/53/EU on radio equipment. The civil equivalent of this architecture – relay networks for BVLOS operations – is one of the fundamental implementation challenges of the U-space framework.</p>



<p><strong>RED 2014/53/EU – this is the radio equipment regime, i.e.&nbsp;not only “does the drone work”, but whether its communications modules:</strong></p>



<ul class="wp-block-list">
<li><strong>lawfully use the spectrum,</strong></li>



<li><strong>do not interfere with other systems,</strong></li>



<li><strong>are safe and electromagnetically compatible.</strong></li>
</ul>



<p>The retransmission architecture has legal significance extending far beyond the battlefield, because from the civil perspective it in essence means the construction of an <strong>ad hoc, mobile electronic communications network for unmanned operations</strong>. What in wartime conditions takes the form of an improvised or semi-improvised radio bridge between operator and drone becomes, in the civil environment, a multi-layered issue: <strong>it concerns not only the aircraft itself, but also radio equipment, frequencies, electromagnetic compatibility, data integrity, network resilience and liability for the continuity of the communications service</strong>. For this reason, at least three legal orders enter here in parallel.<a href="#_ftn43" id="_ftnref43">[43]</a> First, the law of electronic communications and spectrum management, because the relay is no longer merely “part of the drone”, but an element of transmission infrastructure affecting the <strong>radio spectrum and requiring conformity with the rules on the use of bands</strong>. Second, Directive 2014/53/EU (RED), i.e.&nbsp;the radio equipment regime, whose essence is to ensure that equipment uses the spectrum efficiently, does not interfere with the operation of other systems and satisfies safety and compatibility requirements. Third, the U-space framework, which is not “a single drone system” but a regulatory model of highly digitalised and partly automated management of a large number of unmanned operations, in particular also BVLOS (beyond visual line of sight) flights. Relay networks for BVLOS operations therefore in practice mean a model in which the continuity of the flight does not depend on a simple, linear operator-drone connection, but on an entire chain of communications services, identification, data transmission and coordination with the digital airspace. That is precisely why one of the main implementation challenges of U-space is not the mere fact that the drone flies beyond visual range, but who is responsible, and on what terms, for the communications layer sustaining such a flight: for the reliability of the channel, the interoperability of the equipment, information security, jamming resistance, cybersecurity and the technical conformity of the entire transmission chain. In civil conditions, the problem which at the front is solved by an improvised relay or a mesh network therefore becomes a regulatory problem of the highest rank: the question is no longer only whether the drone may fly, but whether there exists a lawful and secure communications infrastructure allowing it to fly outside the simple logic of direct contact.<a href="#_ftn44" id="_ftnref44">[44]</a></p>



<p>If, however, the relay and the mesh network<a href="#_ftn45" id="_ftnref45">[45]</a> are an attempt to solve the radio horizon problem within the logic of radio emission, then fibre-optic drones represent an attempt to step outside that logic altogether. Whereas the relay architecture endeavours to elevate, stabilise and disperse the signal, the optical fibre eliminates the need for its emission in radio space, and thereby undermines a considerable part of the existing assumptions of both counter-drone technologies and regulation based on the detectability and jammability of the signal.</p>



<p><strong>Mesh network, Shahed/Geran and the shift from loitering munition to a networked strike system</strong></p>



<p>One of the most interesting and at the same time most disturbing phenomena of the current phase of the drone war is the transition from a simple point-to-point control model to a mesh network architecture, that is a lattice or grid network. Unlike the classic arrangement in which the operator communicates directly with a single platform or via a single relay, the mesh network consists of many nodes capable of simultaneously receiving, forwarding and amplifying the signal. Each such node can be part of a larger transmission system: a ground modem, an intermediate station, an observation platform or the drone itself. In practice, this means that communications do not depend on one channel and one transmission route, but can be dynamically reconfigured depending on which elements of the network remain active, where the platforms are located and what the jamming environment looks like. That is precisely why the mesh network is an architecture more resilient, flexible and difficult to disable than a classic linear connection. It is no longer a “link to the drone”, but a dispersed operational network.</p>



<p>In relation to heavy platforms of the Shahed/Geran type, such an architecture has breakthrough significance, because it blurs the boundary between a loitering munition and a network-controlled or network-supervised drone. Traditionally, loitering munitions are perceived as an essentially single-use means flying along a route programmed in advance or corrected to a limited extent. Meanwhile, equipping heavy drones with mesh modems, retransmission nodes and external relay points means that the system ceases to be merely a “blind carrier” executing a sequence of commands recorded once. It enters a more flexible model: it can maintain communications deeper over the adversary’s territory, benefit from mutual signal amplification, and in some configurations also from more up-to-date mission supervision. It is precisely for this reason that analysts speak of the blurring of the boundary between the classic loitering munition and the one-way attack UAV with elements of networked command. In other words: if the “Shahed” begins to function as part of a communications system, it ceases to be solely a single-use kinetic effect and begins to resemble a networked means of aerial attack, whose effectiveness depends not only on the airframe and warhead, but on the data transmission architecture.</p>



<p>This is very well illustrated by the Belarusian case from the beginning of 2026, when reports appeared in the analytical space of Russia’s use of relay stations and other network nodes supporting the flights of Shaheds operating from that direction, and subsequently of their elimination by the Ukrainian side.<a href="#_ftn46" id="_ftnref46">[46]</a> Even if part of the details of those events remains based on front-line, technical and media sources rather than on full, open official material, the operational sense of such a solution is itself logical and coherent: if the platform is to fly deep, maintain communications and benefit from the effect of mutual retransmission, then the network cannot end at the drone itself. It must have external nodes sustaining the communications architecture, whether in the form of border stations, relay towers, ground amplification points or other supporting elements. The destruction of such nodes does not mean the destruction of a single drone, but a strike at the network layer which makes the entire system more dangerous. In this sense, Ukraine is not merely destroying the carrier of a warhead, but degrading the communications infrastructure of the attack.</p>



<p>Technologically, the most dangerous aspect is that the mesh network changes the logic of defence. In the classic model, it was enough to cut the connection, destroy the platform or jam a single channel. In the grid model, the adversary can attempt to:</p>



<ul class="wp-block-list">
<li><strong>redirect traffic along another route,</strong></li>



<li><strong>use other drones as relays,</strong></li>



<li><strong>dynamically change the structure of communications,</strong></li>



<li><strong>combine strike, reconnaissance and retransmission platforms into a single arrangement.</strong></li>
</ul>



<p><strong>This in turn naturally brings such a system closer to a swarm with a division of roles</strong>. Not all platforms have to attack. Some may perform the role of:</p>



<ul class="wp-block-list">
<li>communications nodes,</li>



<li>observers,</li>



<li>decoys,</li>



<li>retransmission carriers,</li>



<li>elements building the resilience of the network.</li>
</ul>



<p>This means that advantage increasingly depends not on a “better drone” but on a better systemic architecture. It is precisely here that IP of the highest value is born: not in the airframe itself, but in the modems, transmission protocols, routing algorithms, jamming resistance, throughput management, node authorisation and the integration of the relay role with the combat role. Solutions of this kind may be protected as a patent, software, a trade secret or systemic know-how. In practice, market and military value therefore shifts from the individual product to the network architecture, which may be more difficult to copy than the drone itself.</p>



<p>This shift also has very significant legal consequences. First, the mesh network is not directly a legal category of aviation law or EU drone law; it is above all a technical concept. However, its legal significance is indirectly enormous, because it describes the structure of communications on which the operation of unmanned platforms depends. The moment such a network is analysed outside the theatre of hostilities, we immediately enter the area of electronic communications law, spectrum management and the radio equipment regime. For if the effectiveness of the drone depends on a dispersed arrangement of transmitters, modems and relay nodes, then we are no longer dealing solely with an aircraft, but with regulated communications infrastructure. Here, Directive 2014/53/EU (RED) gains significance, because all radio transmission modules – especially when they form a system of mutual relays – must be analysed from the perspective of the efficient use of the spectrum, electromagnetic compatibility and equipment safety. In such a framing, the mesh network is not only a technical feature but a question of whether the radio network being built conforms to the rules on the use of bands and does not generate new risks for other communications systems.</p>



<p>Second, the mesh network has a cybersecurity and information security dimension. Every additional node means not only greater flexibility of the communications architecture, but also a greater attack surface: more points vulnerable to takeover, impersonation of an authorised element of the system, spoofing, jamming or the injection of false data. The injection of false data should here be understood as the introduction into the network of signals, messages or parameters which appear authentic but are intended to mislead the other nodes, cause an erroneous reconfiguration of connections, direct the platforms along another route or distort the picture of the operational situation. The more the system passes from a simple point-to-point connection to a dispersed lattice network, the more crucial becomes not the mere transmission of the signal, but trust in its source, integrity and authenticity. That is precisely why mesh technology shifts the analysis from the level of simple drone control towards the issues of node authorisation, data integrity and the resilience of the communications architecture to manipulation.</p>



<p>The legal dimension of this phenomenon is multi-layered. First, the more the effectiveness of the system depends on a multi-node transmission architecture, the less sufficient it is to treat it solely as an aircraft, and the more necessary it becomes to conceive of it as an element of regulated radiocommunications infrastructure – and thus also through the prism of the radio equipment regime, spectrum use and electromagnetic compatibility, with which the significance of Directive 2014/53/EU (RED) is indirectly connected. Second, the strategic value of the system shifts from the airframe itself to the modems, antennas, amplifiers, jamming-resistance systems and routing software, which reinforces their significance as dual-use components. Third, the mesh architecture creates the conditions for dispersed functional autonomy: it enables the redirection of the flight during the mission, the use of other platforms as relays, the dynamic alteration of the communications structure and the combination of strike, reconnaissance and retransmission platforms into a single arrangement. In the case of heavy Shahed/Geran drones, this leads to the blurring of the boundary between the classic loitering munition and a network-supported means of aerial attack. The reports of the use of external relay stations on the Belarusian direction and of their elimination by the Ukrainian side show well that the object of the fight is now not only the drone itself, but also the communications layer which sustains its operation. In this sense, the drone war simultaneously becomes a war for control over dispersed data transmission infrastructure.</p>



<p>In a dispersed communications system, security no longer depends on a single link, but on the integrity of the entire arrangement of mutual trust between nodes. This makes the legal analysis of such systems naturally shift also towards questions of:</p>



<ul class="wp-block-list">
<li>signal integrity,</li>



<li>device authorisation,</li>



<li>resistance to manipulation,</li>



<li>the security of data transmitted between nodes,</li>



<li>and, in the civil equivalent, also towards regimes functionally approximating the requirements imposed on high-risk digital infrastructure.</li>
</ul>



<p>Third, mesh technology has an obvious significance for dual-use export control. While the airframe itself may be relatively simple, the true value and strategic sensitivity is concentrated in the communications components: modems, amplifiers, antennas, jamming-resistance systems, routing and network management software. It is precisely these elements that most easily move from the civil market to the military one and vice versa. In consequence, the components building mesh networks may be analysed not only as part of the end product, but as self-standing dual-use components, whose export, technical transfer and integration may be subject to a separate licensing and security assessment.</p>



<p>Fourth, the mesh network leads us to the boundary of the issues of AI and functional autonomy. The lattice network itself is not yet artificial intelligence, but when it begins to support:</p>



<ul class="wp-block-list">
<li>automatic selection of the signal route,</li>



<li>adaptive node switching,</li>



<li>coordination of multiple platforms,</li>



<li>sharing of observations and targeting data,</li>



<li>maintenance of the mission despite the loss of part of the system’s elements,</li>
</ul>



<p>then in practice we approach an architecture in which operational decisions no longer flow solely from a direct human command, but from the dispersed operation of the system. This gives rise to the classic questions of responsibility, predictability and the qualification of such a network as an element of a more autonomous means of warfare. In the European context, this tension is particularly interesting, because civil applications of AI and communications are subject to ever greater regulation, while military applications of networked autonomy remain to a large extent outside the scope of the classic civil conformity regimes.</p>



<p>Finally, from the perspective of the law of armed conflict, the mesh network changes the very object of what is regarded as a significant component of combat capability. If the effectiveness of the system depends on a dispersed layer of relays, modems and relay stations, then the target of military significance becomes not only the drone itself, but also the communications infrastructure sustaining its operation. This shifts the analysis from the level of the individual effector to the level of the entire network architecture. One might say that, in such a model, the drone war is becoming to an ever greater degree a war for control over the aerial and border-zone tactical internet.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.4 · Fibre-optic drones – the end of the jamming era</strong></h3>



<p>The breakthrough proved to be drones controlled by <strong>optical fibre</strong> – a spool of thin glass fibre unwound in flight. The solution has its costs (the mass of the fibre limits range, payload and manoeuvrability), but it eliminates two problems at once: the radio horizon ceases to matter, and the drone cannot be jammed, because it emits no radio signal. It is an electronically “mute” platform – practically undetectable by RF detectors and resistant to electronic warfare.</p>



<p>Fibre-optic drones appeared en masse in August 2024 in the Kursk area,<a href="#_ftn47" id="_ftnref47">[47]</a> where Russian platforms of this type – with a range of over 30 km and a “crystal-clear” image – paralysed Ukrainian logistics along the sole supply route. As one Ukrainian medic put it, logistics simply collapsed, because fibre-optic drones were monitoring all the routes. By January 2026, fibre-optic variants accounted in some sectors for 30–50% of Russian FPV operations and around 15% of Ukrainian ones. In 2025, countering fibre-optic drones became the central theme of the NATO Innovation Challenge.<a href="#_ftn48" id="_ftnref48">[48]</a></p>



<p>The regulatory significance of this category is difficult to overestimate and remains unnoticed in the public debate. <strong>The entire European acquis on countering unauthorised unmanned operations – both technical and normative – rests on the assumption that the drone emits a radio signal</strong>.<a href="#_ftn49" id="_ftnref49">[49]</a> On this assumption were built the remote identification requirement, RF detection systems, the jamming powers granted to the services and, from June 2026, to critical infrastructure operators. The fibre-optic platform invalidates each of those mechanisms simultaneously. Regulation aimed at a specific relay technology ages faster than the legislative process in which it comes into being.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.5 · Electronic warfare and spoofing</h3>



<p>Classic <strong>jamming</strong> consists in generating noise on radio frequencies so that the drone cannot distinguish the operator’s signal from the interference and loses control. For platforms flying to preset coordinates (deep strike), <strong>spoofing</strong> is used instead – the substitution of the satellite navigation signal, as a result of which the drone “thinks” it is somewhere else and corrects its flight in the wrong direction.</p>



<p>This distinction translates directly into the choice of defensive means – but also into legal qualification. <strong>Jamming is an interference with the radio spectrum</strong>, and thus with a good administered by the state and protected by electronic communications provisions; <strong>spoofing is an interference with the integrity of the signal of a satellite navigation system</strong>,<a href="#_ftn50" id="_ftnref50">[50]</a> and thus with infrastructure of a global character, the disruption of which has effects far beyond the target. The side effects of both measures – loss of the GNSS signal by civil aviation, maritime transport, power grids synchronised by satellite time – are a classic example of damage in which establishing the causal link and the responsible entity is exceptionally difficult. We return to this issue in section 4.3.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.6 · Heavy platforms – bombers, wings, loitering munitions</h3>



<ul class="wp-block-list">
<li><strong>Heavy bombers</strong> (Ukr. Vampire,<a id="_ftnref51" href="#_ftn51">[51]</a> colloquially “Baba Yaga”<a id="_ftnref52" href="#_ftn52">[52]</a>) – multirotors carrying anti-tank mines and performing logistics tasks (transport of ammunition, water, medicines). They require heavier means of engagement – 12.7/14.5 mm machine guns with thermal imaging.</li>



<li><strong>Light wings</strong> (Rus. Molniya<a id="_ftnref53" href="#_ftn53">[53]</a>) – cheap long-range airframes, of low precision but mass-produced; they are sometimes armed with incendiary charges.</li>



<li><strong>Loitering munitions</strong> (Rus. Lancet,<a id="_ftnref54" href="#_ftn54">[54]</a> Ukr. Bulava,<a id="_ftnref55" href="#_ftn55">[55]</a> Pol. Warmate<a id="_ftnref56" href="#_ftn56">[56]</a>) – advanced platforms for the elimination of artillery and anti-aircraft systems; difficult to shoot down owing to low-detectability materials and their flight profile.</li>
</ul>



<p>The category of loitering munitions deserves separate legal attention. It is a construction at the boundary between an unmanned aircraft and a missile: a platform which remains in the task area for an extended time, searching for a target, and then carries out the strike. The blurring of the boundary between “aircraft” and “munition” has consequences in each of the regimes analysed – from classification on the control list of dual-use items, through the intra-EU transfer regime, to the question of the character of human control over the use of force.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-b829efbeca099a974d06d935cfe43b95">2.7 · Deep strike and autonomy – Fire Point as a case study</h3>



<p>The highest tier consists of heavy long-range platforms. The model example is the Ukrainian <strong>FP-1.</strong> The Ukrainian FP-1,<a href="#_ftn57" id="_ftnref57">[57]</a> developed by Fire Point, is a one-way strike drone of light construction,<a href="#_ftn58" id="_ftnref58">[58]</a> including fuselage elements made of plywood, powered by a two-cylinder engine; industry and media sources estimate its unit cost at approximately USD 55,000–58,000, i.e.&nbsp;significantly below the level of comparable systems. In mid-2025, a rapid increase in the scale of production was reported, already counted in hundreds of units weekly and over 100 units daily, and in July 2026 drones attributed to the FP-1 family were linked to the strike on the refinery in Omsk, one of the deepest Ukrainian long-range attacks.<a href="#_ftn59" id="_ftnref59">[59]</a></p>



<p>This case study is instructive for three reasons. First, it shows the <strong>inversion of the classic cost curve</strong> of the defence industry: a construction made of commercially available materials achieves an operational effect comparable to systems of many times higher cost. Second, it demonstrates the <strong>scalability of production outside the traditional armaments chain</strong> – growth from 30 to over 100 units daily within a few months is difficult under the regime of classic military certification. Third, this problem illustrates that range is not solely a technical parameter, but also a regulatory category. This follows from the logic of the Missile Technology Control Regime (MTCR), which – although it is not a classic international agreement in treaty form, but an informal export control regime based on common guidelines and a control annex – has long covered not only classic missiles but also unmanned aerial systems capable of carrying a payload over considerable distances. The most restrictive layer, i.e.&nbsp;Category I, encompasses complete rocket systems and unmanned aerial systems capable of delivering a payload of at least 500 kg to a range of at least 300 km, together with specified subsystems and technologies. This means that a platform with a range exceeding 2,500 km – even if it does not always satisfy every historical parameter of a classic missile system – enters the same type of strategic regulatory sensitivity which for decades has triggered the sharpest logic of proliferation control. In European practice, this logic was subsequently absorbed into the dual-use regime, in which references to the MTCR remain an element of the system of control of exports of technology and means of delivery (in EU law, the logic of the Missile Technology Control Regime (MTCR) was taken over into the system of control of exports of dual-use items primarily by Regulation (EU) 2021/821, which in recital 3 refers to the multilateral export control regimes, including expressly the MTCR, and then develops this logic operationally in Annex I, containing the EU dual-use control list). In this sense, great range is not merely an engineering feature, but a legally relevant feature, because from a specified threshold it triggers a normative order closer to proliferation control, export control and strategic security than to the ordinary regulation of a civil UAV.<a href="#_ftn60" id="_ftnref60">[60]</a></p>



<p>The boundary between control and autonomy is blurring. Placing a satellite communications terminal on a drone allows it to be controlled from enormous distances; the use of machine vision algorithms enables autonomous terminal guidance onto the target after loss of communications.<a href="#_ftn61" id="_ftnref61">[61]</a> It is precisely this last feature – <strong>terminal autonomy, i.e.&nbsp;the capability to complete the task without a human in the decision loop</strong> – that is the heart of the legal problem to which we now turn.</p>



<p>Conceptual precision, usually lacking in the public debate, is worth preserving here. Autonomy is not a binary feature but a spectrum encompassing at least: (i) flight stabilisation and route keeping, (ii) navigation without a satellite signal using terrain image correlation, (iii) automatic detection and classification of objects, (iv) automatic tracking of a target designated by the operator in the terminal phase, (v) independent selection of a target within a designated area. Legal regimes – both the EU Artificial Intelligence Act and the discussion of autonomous weapon systems within the framework of the CCW Convention – react differently to each of these levels, and the distinction between (iv) and (v) is in practice the most difficult to prove in evidentiary proceedings and at the same time the most legally momentous.<a href="#_ftn62" id="_ftnref62">[62]</a></p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-c24f92bca5ae43f507f4405514293ee8">2.8 · The countermeasure layer – a C-UAS taxonomy</h3>



<p>Symmetrically to the strike layer, the countermeasure layer (_counter-UAS_, C-UAS) has developed, which for the European civil market today has greater economic significance than the strike layer itself. Its taxonomy comprises two segments.</p>



<p><strong>Detection and identification:</strong> radio sensors (monitoring of control and image-transmission bands), low-power radars, acoustic sensors, optoelectronic systems with a thermal channel, and – increasingly – fusion of data from multiple sensors with machine-learning-based classification. It is precisely in this segment that artificial intelligence performs a critical role, and it is precisely this segment that is fully civil, and therefore covered by the EU regime without exclusions.</p>



<p><strong>Neutralisation:</strong> jamming of the control link and image transmission, spoofing of satellite navigation, taking over control of the platform, mechanical means (nets, including those launched from interceptor platforms), kinetic means (from smoothbore weapons to artillery systems with programmable ammunition), directed energy (lasers, high-power pulse) and interceptor drones.</p>



<p>This distinction is legally significant, because <strong>each of the effectors is subject to a different regime</strong>: jamming and spoofing fall under electronic communications law and spectrum management; kinetic means fall under the law on weapons and ammunition and liability for damage caused by falling debris; taking over control is an interference with an ICT system, and thus potentially an act criminalised under criminal law if it does not have an express statutory basis. A separate problem is that effective detection requires data processing – on which see section 3.7.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-fc4ca7a709b60c51cc6529ffa9fbd3e2">2.9 The kill chain and the place of the human in the loop</h3>



<p>For the legal analysis of autonomy, it is indispensable to break the process down into links. Adopting a simplified model of the kill chain: <strong>a)</strong> <strong>detection b) identification and classification c) prioritisation d) engagement decision e) terminal guidance f) effects assessment</strong>. The debate on “meaningful human control” in essence concerns the question in which of these links the human takes the constitutive decision and whether at that moment he has information and time sufficient for that decision to be real rather than formal in character.</p>



<p>In the practice of contemporary drone operations: the first and second links are increasingly automated (image classifiers), the fourth link remains on the human side, and the fifth link is sometimes autonomous out of technical necessity – after loss of the link. Legally, this means that <strong>the “human in the loop” construction rests on a link of which the adversary consistently tries to deprive it</strong>. The argument that loss of communications is a technical circumstance and not a design decision loses its force at the moment when the manufacturer designs the platform on the assumption of operation in a heavily jammed environment.</p>



<p>An analogous structure – with different consequences – occurs on the civil side. Article 14 of the Artificial Intelligence Act requires that a high-risk system be designed so that natural persons can effectively oversee it, including understanding its limitations, correctly interpreting its output and deciding not to use it or to interrupt its operation. This requirement is technically identical to the postulate of meaningful human control – with the difference that on the civil track it is a legal norm backed by a sanction, while on the military track it remains the subject of unfinished international negotiations.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-2017345879af2cf699291d5c1d972a9a">2.10 · The data layer – the drone as a sensory platform</h3>



<p>The last layer, systematically omitted in technical analyses, is the data layer. Each of the platforms described is above all a <strong>sensor generating a stream of data</strong>: visual and thermal imagery, telemetry, position, radio spectrum parameters. The operational value of an unmanned system today lies to a lesser degree in the platform and to a greater degree in the chain of processing of those data – from transmission, through storage and annotation, to use in training image-recognition models.</p>



<p>From this arises a chain which crosses the civil-military boundary in both directions. Collections of recordings from combat operations constitute training material of a value impossible to obtain in laboratory conditions – and they are used to perfect classifiers, which subsequently find their way into civil systems (infrastructure monitoring, border protection, crisis management). In the other direction: models trained on civil collections of aerial imagery constitute the base for target-recognition systems.</p>



<p>This bidirectional flow is – as we demonstrate in section 4.5 – the area in which the EU data protection and artificial intelligence regimes come into contact with the defence exclusions in the manner that is legally most unclear and practically most momentous.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-b40798181a77e5f0106eeefd5df8d31e">2.11 · The innovation spiral as a law of development</h3>



<p>Drone warfare is a spiral process: each innovation provokes a countermeasure, and that forces the next innovation: the observation Mavic; drops; FPV; jamming; the relay; the optical fibre; satellite communications; satellite jamming; AI autonomy; interceptor drones.</p>



<p>For the regulator, this means that <strong>every norm aimed at a specific technology ages at the pace of that spiral</strong>. This is an argument in favour of regulation based on effects and on the level of risk, rather than on a catalogue of technical solutions – and at the same time an explanation of why acts based on risk classification (the Artificial Intelligence Act) have a greater chance of remaining current than acts based on product catalogues (dual-use control lists, classes C0–C6).</p>



<h2 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-1035e1196f56a434e54324ff2724ae0c"></h2>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile"><div class="wp-block-media-text__content">
<h3 class="wp-block-heading has-vivid-red-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-3a45f71ad483e1cd03cf6eadb1a92188">3 · The Legal Environment – Nine Pillars</h3>
</div><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/output-1-1.mp4"></video></figure></div>



<p>The legal environment of the UAV sector is not one act or one branch. It is a lattice of regimes, which it is worth ordering into nine pillars. Below, we furnish each of them both with its legal basis and with a practical “flavour” relevant to the servicing of entities in the sector.</p>



<p>The original version of this taxonomy comprised seven pillars. The extension by two further ones – personal data protection and data governance, and public international law – is not a tidying-up exercise. It follows from the observation made in section 2.10: since the value of the unmanned system has shifted from the platform to the data, the data regime has ceased to be a side issue and has become one of the two or three pillars determining the business model. International law, in turn, is the only regime which covers the space left by the defence exclusions of EU law – and therefore precisely the space in which the revolution described above is playing out.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>3.1 · Pillar I – UAV categories and airspace</strong></h3>



<p>The core of the civil regime is formed by three related acts founded on the basic Regulation (EU) 2018/1139 (EASA): <strong>Delegated Regulation (EU) 2019/945</strong> (product requirements, classes C0–C6, CE marking) and <strong>Implementing Regulation (EU) 2019/947</strong> (operations in the open, specific and certified categories). The spatial layer is completed by the U-space package: <strong>Implementing Regulation (EU) 2021/664</strong> together with 2021/665 and 2021/666.</p>



<p>The architecture of this pillar rests on two independent axes of qualification, the confusion of which is the most frequent error in the practice of the industry. The first axis – the <strong>product axis</strong> – concerns what the device is: classes C0–C6 lay down construction requirements, including the obligation to be equipped with a remote identification system and a geo-awareness function for the higher classes. The second axis – the <strong>operational axis</strong> – concerns what is done with it: the open category covers low-risk operations within visual range, the specific category requires an authorisation based on a risk assessment (the SORA methodology) or a declaration of conformity with a standard scenario, and the certified category brings the regime close to classic manned aviation.</p>



<p>The U-space layer, in turn, introduces mandatory services in designated airspaces: network identification, geo-awareness, traffic information and flight authorisation, provided by certified service providers.</p>



<p><strong>The practical dimension is therefore that</strong> the regime is not static. Regulation 2019/947 has applied in its consolidated version since 1 May 2025, and the U-space framework was reinforced by <strong>Regulation (EU) 2023/203</strong>, which added information security requirements – risk assessment, management and incident response. Of key interpretative importance is therefore the revision of the Easy Access Rules for UAS of June 2026, consolidating the AMC/GM to Regulation 2019/947 (ED Decision 2025/018/R). From 1 January 2026, flights in standard scenarios require platforms holding a class C5 or C6 certificate. In a broader perspective, this confirms that in the UAV sector law does not end with the text of the regulation itself, but also functions in the executive, interpretative and operational layer. It is precisely at this level – through the AMC, GM and their consolidation in the Easy Access Rules – that general norms are translated into compliance practice, risk assessment, operational documentation and the everyday application of the law by operators, manufacturers, advisers and supervisory authorities. As a result, an analysis of the legal environment of drones requires account to be taken not only of the formally binding provisions, but also of how they are operationalised in executive and interpretative materials, because it is only there that the real regulatory weight of the sector is revealed. <strong>AMC (Acceptable Means of Compliance) and GM (Guidance Material)</strong> do not have the character of independently binding provisions of the rank of a regulation, but they perform a fundamental interpretative and practical function: they show how entities can demonstrate conformity with the requirements arising from Regulation (EU) 2019/947 and how authorities and operators should understand the individual obligations in operational practice. That is precisely why the Easy Access Rules for Unmanned Aircraft Systems are of such great importance for the UAV sector – they do not create new law, but order, consolidate and operationalise the normative material and its interpretation, becoming in practice the basic working tool for operators, manufacturers, advisers and supervisory authorities.<a href="#_ftn63" id="_ftnref63">[63]</a></p>



<p><strong>A systemic remark</strong>: this entire pillar concerns civil aviation exclusively. Article 2(3)(a) of Regulation 2018/1139 excludes from its scope of application aircraft carrying out military, customs, police, search and rescue, firefighting, border control and coastguard operations. The first and most far-reaching defence exclusion therefore appears already at the level of the foundation, and not only in the Artificial Intelligence Act. This means that the boundary between the civil and the defence order is drawn already in the EASA basic regulation itself: it is that regulation which determines that the development, certification and operation of military unmanned systems are not subject to the EU regime of common civil aviation rules, but remain within the domain of the competence of the Member States, their defence policies and the relevant national security regimes. From the perspective of an analysis of the UAV sector, this is of fundamental importance, because it shows that the dual-track nature of the regime does not begin at the stage of AI, autonomy or export control, but already at the level of the most basic question of whether a given aircraft is subject to common European aviation law at all. In practice, this means that identical or nearly identical technology may be covered by the full civil conformity regime if it functions on the commercial market, while at the same time remaining outside that regime if it is incorporated into a military operation or one directly connected with it.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.2 · Pillar II – Artificial intelligence and decision-making autonomy</h3>



<p><strong>Regulation (EU) 2024/1689</strong> (the Artificial Intelligence Act, “AI Act”) introduces a risk-based classification: prohibited practices (Article 5), high-risk systems (Article 6 in conjunction with Annexes I and III), systems subject to transparency obligations (Article 50), general-purpose models (Articles 51–55) and the remainder, not covered by substantive obligations.</p>



<p>For the UAV sector, however, what is decisive is not what the act regulates, but <strong>what it does not regulate</strong>. Article 2(3) provides:</p>



<p>“<em>This Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification <strong><u>exclusively</u></strong> for military, defence or national security purposes</em>.” – Article 2(3) of Regulation (EU) 2024/1689.</p>



<p>The consequence is paradoxical: <strong>a civil drone with AI is subject to the full high-risk regime, while a technologically identical platform used “exclusively” for military purposes remains outside the scope.</strong> The criterion is not the technology, but the purpose of use. Lethal autonomous weapon systems (LAWS) therefore remain outside the EU regime; the matter is the subject of international law and NATO doctrines, and the European Parliament has repeatedly warned against the Union’s regulatory backwardness in this area. The European Parliament was one of the earliest institutional actors to take up the subject of autonomous weapon systems and military AI, adopting already in 2018 a resolution on LAWS, and then in 2021 a resolution relating to artificial intelligence in the military and civil context.<a href="#_ftn64" id="_ftnref64">[64]</a></p>



<p>Key, however, is the word <strong>“exclusively”</strong>. Recital 24 of the preamble specifies that if the system is also used for purposes other than military, defence or national security – even temporarily and even by another entity – the exclusion does not apply to that extent. For a dual-use manufacturer, this means that <strong>the exclusion is not a feature of the product, but a feature of the specific placing on the market or putting into service</strong>. The same product series sold simultaneously to a military purchaser and to a critical infrastructure operator is, in the second case, subject to the full regime – and the manufacturer must be able to document this duality, separate the product lines and demonstrate it in the event of an inspection.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Qualification of a drone system as a high-risk system</h3>



<p>In practice, the classification proceeds along two independent tracks:</p>



<ul class="wp-block-list">
<li><strong>Article 6(1) (Annex I)</strong> – an AI system is high-risk if it constitutes a safety component of a product covered by the Union harmonisation legislation listed in Annex I, and that product is subject to third-party conformity assessment. Section B of Annex I expressly lists Regulation (EU) 2018/1139. <strong>This means that control software performing a safety function in a certified unmanned system may be a high-risk system on precisely this basis</strong> – a circumstance still under-appreciated in market practice, because the discussion concentrates almost exclusively on Annex III.</li>



<li><strong>Article 6(2) (Annex III)</strong> – covers, inter alia, the management of critical infrastructure, law enforcement, and migration management and border control. Drone systems used by border services or critical infrastructure operators fall here directly.</li>
</ul>



<p>The consequence of qualification is the set of obligations under Articles 8–15: a risk management system, data and data quality governance (Article 10), technical documentation (Article 11), automatic recording of events (Article 12), transparency and information for the user (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15) – and, on the procedural side: conformity assessment, the EU declaration, CE marking and registration in the EU database.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">The calendar – amended in June 2026</h3>



<p>Market practice planned compliance for over a year around the date of 2 August 2026. That date has changed. On 19 November 2025, the Commission presented a simplification package (the Digital Omnibus), whose part concerning artificial intelligence – after the unsuccessful trilogue of 28 April 2026 and the political agreement of 6–7 May 2026 – was finally approved by the Council on <strong>29 June 2026</strong> (Parliament: 16 June 2026). The result is a postponement:</p>



<ul class="wp-block-list">
<li>obligations for standalone high-risk systems under Annex III – <strong>2 December 2027</strong>;</li>



<li>obligations for AI embedded in regulated products under Annex I (and thus, inter alia, unmanned systems) – <strong>2 August 2028</strong>;</li>



<li>transparency obligations under Article 50 – <strong>unchanged, 2 August 2026</strong>;</li>



<li>Article 50(2) (marking of generated content) in relation to systems already present on the market, and the new prohibitions – <strong>2 December 2026</strong>.</li>
</ul>



<p>The postponement is conditional in character and is linked to a readiness mechanism: the registration of systems in the EU database and the availability of harmonised standards. The following, by contrast, apply unchanged: the prohibitions under Article 5 (from 2 February 2025), the AI literacy obligation under Article 4 (from 2 February 2025) and the general-purpose model regime (from 2 August 2025).<a href="#_ftn65" id="_ftnref65">[65]</a></p>



<p><strong>In practice,</strong> the postponement is not a relief but a shift. The task which cannot be omitted or accelerated is the inventory of AI systems in the organisation and the assignment of each of them to the appropriate category – work independent of the state of the harmonised standards. In addition, the grandfathering principle applies: systems placed on the market before the date of application are not subject to the obligations until they are substantially modified – which, in a sector with an iteration cycle counted in weeks, is a guarantee of limited value.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><a>3.3 · Pillar III – Dual-use products and export control</a></h3>



<p><strong>Regulation (EU) 2021/821</strong> establishes the Union’s system for the control of exports of dual-use items; it entered into force on 9 September 2021, replacing Regulation (EC) No 428/2009, and has applied in its consolidated version since 15 November 2025. On 8 September 2025,<a href="#_ftn66" id="_ftnref66">[66]</a> the Commission updated Annex I (the control list), covering emerging technologies – which directly affects drone components, electronics and AI software.</p>



<p>Four mechanisms of this regime are significant for the unmanned sector:</p>



<p>1. <strong>The control list (Annex I)</strong> – drone components are dispersed across several categories: electronics (cat. 3), sensors and lasers (cat. 6), navigation and avionics (cat. 7) and aerospace and propulsion (cat. 9). Qualification rarely concerns the platform as a whole – most often a single subassembly is decisive.</p>



<p>2. <strong>Catch-all clauses (Article 4)</strong> – the obligation to obtain an authorisation arises also for items not included in the list, if the exporter has been informed or is aware of an intended use connected with weapons of mass destruction, military purposes in a state subject to an embargo, or parts for armaments exported without authorisation. This is the instrument which in practice covers the largest number of drone transactions, because it operates independently of the list.</p>



<p>3. <strong>Control of intangible technology transfer (ITT)</strong> – the regime covers not only things, but also software and technology, including making them available by electronic means. In practice, this means that granting remote access to a code repository, transferring model weights<a href="#_ftn67" id="_ftnref67">[67]</a> or placing technical documentation in a cloud outside the customs territory of the Union may constitute an export requiring an authorisation.</p>



<p>4. <strong>Cyber-surveillance items (Article 5)</strong> – a control mechanism covering items not included in the list, intended for surveillance, where there is a risk of use for human rights violations; it applies directly to advanced observation systems and image analytics.</p>



<p>The complementary layer is formed by: <strong>Directive 2009/43/EC</strong> on intra-EU transfers of defence-related products (simplified within the framework of the Defence Readiness Omnibus), the international regimes (the Wassenaar Arrangement, the MTCR – whose Category I traditionally covers unmanned systems with specified range and payload parameters) and, at national level, the <strong>Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance</strong>.</p>



<p><strong>IMPORTANT for M&amp;A practice:</strong> in the due diligence of an entity in the drone sector, the qualification of components as dual use determines the export authorisation regime, the end-user and re-export prohibition clauses and – in real terms – the feasibility of the cross-border transaction. The disappearance of the commercial/combat boundary (a mass-produced observation drone converted into a combat platform without design changes) makes this qualification ever broader, and the regulatory risk ever more difficult to price. Particular attention is required in the situation where the purchaser is an entity from outside the Union: the mere transfer of technical documentation in the company examination process may require an authorisation before the agreement is even concluded.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.4 Pillar IV – Defence financing and procurement (the driver)</h3>



<p>This is the pillar in which law performs the function of a <strong>driver</strong>. The EU instruments do not react to technology – they create demand, direct the stream of public funds and establish the framework for joint production and procurement:</p>



<p>•&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>The European Defence Fund (EDF)</strong><a href="#_ftn68" id="_ftnref68">[68]</a> – co-financing of joint defence research and development projects, lowering the industry’s investment risk.</p>



<ul class="wp-block-list">
<li><strong>EDIRPA</strong> (Regulation (EU) 2023/2418) – support for common defence procurement.<a id="_ftnref69" href="#_ftn69">[69]</a></li>



<li><strong>ASAP</strong><a id="_ftnref70" href="#_ftn70">[70]</a> – the regulation on supporting ammunition production: increasing the production capacities of industry; a logic fully transferable to the mass production of loitering munitions and drones.</li>



<li><strong>SAFE</strong> (Security Action for Europe, 2025)<a id="_ftnref71" href="#_ftn71">[71]</a> – a loan instrument with procurement to be carried out by the end of 2030.</li>



<li><strong>EDIP</strong> – the European Defence Industry Programme, together with the construction of <strong>SEAP</strong> (Structure for European Armament Programme) as a voluntary legal framework for the long-term cooperation of Member States across the entire life cycle of a defence product.<a id="_ftnref72" href="#_ftn72">[72]</a></li>
</ul>



<p>The superstructure of these instruments is the <strong>Defence Readiness Omnibus</strong><a href="#_ftn73" id="_ftnref73">[73]</a> of 17 June 2025 – a legislative and non-legislative package intended to remove administrative barriers to defence investment estimated at EUR 800 billion over a four-year perspective. It includes, inter alia, accelerated authorisation procedures for defence projects with a single point of contact, extension of the maximum duration of framework agreements to ten years, simplification of intra-EU transfers of defence products (where delays reached a year), clarification of the defence exclusions in chemicals legislation (REACH, CLP, biocidal products) and – which is particularly significant for financing – a communication clarifying the application of the sustainable finance framework to the defence sector. In June 2026, the co-legislators reached a preliminary agreement on the procurement part of the package, extending the increased EDF financing to actions carried out within the framework of SEAP and permitting the eligibility of the costs of tests conducted in Ukraine.</p>



<p>A separate, younger layer is formed by the <strong>four flagship projects</strong><a href="#_ftn74" id="_ftnref74">[74]</a> of the Readiness Roadmap 2030: the European Drone Defence Initiative, Eastern Flank Watch, the European Air Shield and the European Space Shield. EDDI – originally communicated as the “drone wall” – is to create a multi-layered network capable of detecting, tracking and neutralising hostile platforms, while preserving a dual-use dimension allowing civil applications (border protection, disaster response). The assumed timetable: launch in Q1 2026, initial capability by the end of 2026, full functionality by the end of 2027 (Eastern Flank Watch – by the end of 2028). They are complemented by the <strong>Action Plan on drone and counter-drone security</strong> of 11 February 2026 and the <strong>Drone Alliance with Ukraine</strong>, together with the announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets to support Ukrainian drone production.</p>



<p>The market confirms the direction: over a twelve-month horizon, autonomous drones attracted around USD 6.2 billion in 169 transactions, driving a 139-per-cent increase in defence robotics financing. Analysts at the same time point to the gap between the “battle-tested” Ukrainian ecosystem and the capital actually flowing in – a field in which legal advice and transaction structuring become critical.</p>



<p><strong>The practical dimension:</strong> participation in the driver instruments has a legal price which must be factored in at the stage of structuring the consortium. The EDF and EDIP regimes contain extensive provisions on rights to the results of the project, access to existing knowledge (background) and generated knowledge (foreground), export restrictions on results and requirements of control over the entity (registered office in the Union, absence of third-country control or effective mechanisms for its limitation). For a company with capital from outside the Union, eligibility can be illusory if the ownership structure is not appropriately arranged in advance.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.5 · Pillar V – Satellite communications (IRIS²)</h3>



<p><strong>Regulation (EU) 2023/588</strong> establishes the Union’s secure connectivity programme for 2023–2027 and the <strong>IRIS²</strong> constellation (Infrastructure for Resilience, Interconnectivity and Security by Satellite). It is the sovereign European answer to dependence on commercial satellite systems, whose role in the control of long-range drones was revealed by the conflict.<a href="#_ftn75" id="_ftnref75">[75]</a></p>



<p>Law here builds the physical layer on which the future generation of satellite-controlled platforms will rest – a classic infrastructural driver. The significance of this pillar is, however, deeper than technical: the experience of recent years has shown that <strong>a private satellite operator’s decision on coverage or on refusal to provide the service in a given area may have operational effects comparable to a decision of a state</strong>. The construction of a public capability is the answer to a problem which should be called the privatisation of communications sovereignty.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.6 · Pillar VI – Critical infrastructure, cybersecurity and product resilience</h3>



<p>Since the first phase of the conflict was cyber warfare, the pillar of digital and physical resilience has systemic significance. It is formed by three acts of differing logic:</p>



<ul class="wp-block-list">
<li><strong>Directive (EU) 2022/2555 (NIS2)</strong><a id="_ftnref76" href="#_ftn76">[76]</a> – raises the common level of cybersecurity, extending the circle of essential and important entities and the obligations of risk management, incident reporting and the responsibility of management bodies. It covers, inter alia, air transport, energy, digital infrastructure and – which is significant for the sector under discussion – the manufacture of products, including electronic devices. NIS2 shifts the weight from “IT security” itself to risk management at the level of the entire organisation, including the responsibility of management, incident reporting obligations and the requirement of operational resilience for entities operating in critical and technologically sensitive sectors.</li>



<li><strong>Directive (EU) 2022/2557 (CER)</strong><a id="_ftnref77" href="#_ftn77">[77]</a> – regulates the resilience of critical entities in the physical and organisational dimension: the identification of critical entities, risk assessment, resilience plans, personnel security vetting. The key significance of CER lies in the fact that it concentrates not on cyberspace, but on the physical and organisational resilience of critical entities, and thus on the capability to maintain continuity of operation despite an attack, sabotage, disruption or infrastructural crisis.</li>



<li><strong>Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA)</strong><a id="_ftnref78" href="#_ftn78">[78]</a> – the youngest act and, in practice, the most burdensome for manufacturers. It establishes horizontal cybersecurity requirements for <strong>products with digital elements</strong>, and thus for drones, ground controllers, detection systems and software. It imposes obligations of secure design, vulnerability management throughout the support period, provision of a software bill of materials (SBOM) and reporting of actively exploited vulnerabilities and serious incidents. The reporting obligations apply from September 2026, and the entirety – from December 2027. The most momentous element of the CRA is that, for the first time, it imposes on manufacturers of products with digital elements a continuous cybersecurity obligation throughout the product’s entire life cycle, encompassing secure design, vulnerability management and response obligations also after the product’s placing on the market.</li>
</ul>



<p>Both directive-form acts (NIS2, CER) require national transposition – which shifts the weight to the Polish level, discussed in Pillar IX.</p>



<p><strong>The practical dimension:</strong> the convergence of the three regimes means that a manufacturer of a drone system for a critical infrastructure operator may simultaneously: (i) be subject to the CRA as a manufacturer of a product with digital elements, (ii) be an important entity within the meaning of NIS2 by virtue of its own manufacturing activity, and (iii) be covered by requirements arising from the obligations of its client under CER and NIS2, passed down contractually within the framework of supply chain risk management. Three regimes, three separate calendars, three separate sets of reporting obligations – while the event that triggers them is one.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.7 · Pillar VII – Personal data and data governance</h3>



<p>This is a pillar systematically omitted in analyses of the defence sector, and at the same time the one which in practice most often blocks civil deployments. This follows from the observation made in section 2.10: the drone is above all a sensor, and a sensor turned towards the surface of the earth in an urbanised environment almost always records personal data.</p>



<p><strong>Regulation (EU) 2016/679 (GDPR)</strong> applies to the processing of imagery from an unmanned platform on general principles, whereby in practice four issues are decisive:</p>



<ul class="wp-block-list">
<li><strong>Scope of application.</strong> Article 2(2)(a) and (b) excludes processing in the course of an activity which falls outside the scope of Union law and within the framework of the common foreign and security policy. National security remains the competence of the Member States (Article 4(2) TEU). There thus arises – symmetrically to Article 2(3) of the Artificial Intelligence Act – a second defence exclusion, with differently drawn boundaries.</li>



<li><strong>Legal basis and transparency.</strong> The information obligation under Articles 13–14 is difficult to perform in a real manner in aerial operations; practice relies on area-based information, signage and the publication of flight plans, which the European Data Protection Board analysed in Guidelines 3/2019 on the processing of personal data through video devices.</li>



<li><strong>Data protection impact assessment (Article 35).</strong> Systematic monitoring of public space on a large scale with the use of new technologies falls within the typical criteria of a mandatory impact assessment; in Polish practice, the list of operations requiring a DPIA maintained by the supervisory authority includes monitoring with the use of drones.</li>



<li><strong>Special categories (Article 9).</strong> The processing of facial imagery for the purpose of the unique identification of a natural person constitutes the processing of biometric data; in combination with Article 5 of the Artificial Intelligence Act (the prohibition of real-time remote biometric identification in public space for law enforcement purposes, subject to exceptions), this creates a double barrier for observation systems with facial recognition.</li>
</ul>



<p>For operations conducted by the services, the appropriate regime is <strong>Directive (EU) 2016/680</strong> (the so-called Police Directive), transposed in Poland by the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.</p>



<p>A separate, younger layer is constituted by the <strong>governance of non-personal data</strong>. <strong>Regulation (EU) 2023/2854 (the Data Act)</strong>, applicable from 12 September 2025, covers “connected products” – that is, devices generating data on their use and environment, to which unmanned systems belong directly. It imposes obligations to make data available to the user and to third parties designated by the user, and limits the freedom to shape contracts in this respect. <strong>Regulation (EU) 2022/868 (the Data Governance Act)</strong>, in turn, creates the framework for the re-use of public sector data and data intermediation.</p>



<p>Finally, <strong>Article 10 of the Artificial Intelligence Act</strong> introduces quality requirements for the training, validation and testing data sets of high-risk systems – representativeness, relevance, examination for systematic errors. These requirements overlap with the GDPR regime in a manner which is sometimes a source of practical contradictions: the obligation to examine bias sometimes requires the processing of special-category data, the processing of which the GDPR as a rule prohibits. This issue is the subject of work on the data part of the Digital Omnibus.</p>



<p><strong>Legislative status:</strong> in contrast to the part concerning artificial intelligence, <strong>the part of the simplification package covering the GDPR, the ePrivacy Directive, NIS2, the Data Act and DORA remains at the negotiation stage.</strong> At the end of June 2026, the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority; the file was taken over by the Irish Presidency. The European Data Protection Board and the European Data Protection Supervisor expressed, in Joint Opinion 2/2026 of 11 February 2026, decided opposition to the proposed narrowing of the definition of personal data. <strong>Until formal adoption, the existing state of the law applies</strong> – the contrary assumption is at this moment the most frequent error in compliance planning (The legislative status remains unclosed: in contrast to the part of the simplification package concerning artificial intelligence, the component covering the GDPR, privacy and electronic communications, NIS2, the Data Act and DORA still remains at the negotiation stage. It is officially known that the EDPB and the EDPS, in Joint Opinion 2/2026 of 11 February 2026, expressed substantial reservations about the proposed changes, including the narrowing of the definition of personal data. Expert sources further indicate that at the end of June 2026 the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority, which means that until formal adoption the existing state of the law continues to apply.<a href="#_ftn79" id="_ftnref79">[79]</a>).</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.8 · Pillar VIII – Public international law and autonomous weapon systems</h3>



<p>The space left by the defence exclusions of EU law is not a lawless space. It is filled – with varying effectiveness – by three regimes of international law.</p>



<p><strong>International aviation law.</strong> The Chicago Convention of 1944 excludes state aircraft from its scope (Article 3), requires special authorisation for flights of pilotless aircraft over the territory of another state (Article 8) and – in Article 3 bis, added in 1984 – confirms the obligation to refrain from resorting to the use of weapons against civil aircraft in flight. This construction arose in a world in which the distinction “civil/state aircraft” was possible visually and procedurally. Applying it to an object with a wingspan of two metres, without markings, crossing the border unannounced, is a task for which the treaty was not designed.</p>



<p><strong>International humanitarian law.</strong> The principles of distinction, proportionality and precautions in attack apply regardless of whether the decision on the use of force is taken by a human or assisted by an algorithm. Article 36 of Additional Protocol I of 1977 imposes on the parties the obligation to review new weapons, means and methods of warfare for their compatibility with international law – this provision is today the only universally binding instrument that covers autonomy in armaments, although it does so indirectly.<a href="#_ftn80" id="_ftnref80">[80]</a></p>



<p><strong>The CCW process and the UN forum.</strong> The Group of Governmental Experts on lethal autonomous weapon systems (GGE on LAWS), operating since 2016 within the framework of the Convention on Prohibitions or Restrictions on the Use of Certain Conventional Weapons, has been working since 2024 on the so-called rolling text, encompassing elements of a potential instrument based on a two-tier approach of prohibitions and regulation. At the September 2025 session, a group of 42 states – one third of the parties to the Convention – declared readiness to move to negotiations on the basis of that text. On 6 November 2025, the UN General Assembly adopted, for the third time in succession, a resolution on autonomous weapon systems, supported by 156 states. The UN Secretary-General and the President of the International Committee of the Red Cross jointly called for the conclusion of negotiations on a legally binding instrument <strong>by the end of 2026</strong>. The Seventh CCW Review Conference, planned for November 2026, is the moment at which it will be decided whether a negotiating mandate will come into being – whereby the consensus rule applicable in that forum makes this outcome uncertain.<a href="#_ftn81" id="_ftnref81">[81]</a></p>



<p><strong>The NATO layer</strong> comprises the principles of the responsible use of artificial intelligence in defence adopted in 2021 (lawfulness, accountability, explainability and traceability, reliability, governability, bias mitigation) and the revised AI strategy. These are not legally binding norms, but they constitute a point of reference for contractual requirements in allied procurement – and in this sense they affect industry more strongly than many a legal act.<a href="#_ftn82" id="_ftnref82">[82]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.9 · Pillar IX – The Polish level</h3>



<p>The Polish regime combines directly applicable EU regulations with national statutes and operational provisions. The Regulations (2019/945, 2019/947, 2021/664, 2021/821, 2023/588, 2024/1689, 2024/2847) apply directly; the directives (NIS2, CER) require transposition.</p>



<p><strong>The aviation layer.</strong> The national basis is formed by the <strong>Act of 3 July 2002 – Aviation Law</strong>, substantially amended by the Act of 24 January 2025, which entered into force on 27 February 2025. The amendment adapted national law to the EU regime and introduced, inter alia: a register of operators of unmanned systems (a registration obligation for platforms of at least 250 g <strong>and – regardless of mass – those equipped with sensors capable of collecting personal data</strong>), the statutory empowerment of the Polish Air Navigation Services Agency to designate geographical zones, the extension of the catalogue of services entitled to check pilots, the lowering of the minimum age of a pilot in the open category from 16 to 14 under supervision, and a chapter devoted to the prevention of the unlawful performance of operations with the use of unmanned systems. Notification of the intention to perform an operation takes place through the <strong>DroneTower</strong> application, integrated with the PANSA UTM system and the National Drone Information System (KSID). The legal basis for the neutralisation of a platform remains <strong>Article 156ze of the Aviation Law</strong> (destruction, immobilisation or taking over control of the flight), supplemented by the provisions of the chapter on the prevention of unlawful operations.</p>



<p>Institutionally, this layer is completed by the <strong>Act of 8 December 2006 on the Polish Air Navigation Services Agency</strong> (Journal of Laws of 2025, item 1267), extended by the Agency’s competences in the area of unmanned systems, including the possibility of providing services to operators, supporting the testing of new solutions and creating special-purpose companies. Supervision is exercised by the President of the Civil Aviation Authority.</p>



<p><strong>The resilience and countermeasure layer.</strong> The breakthrough is the <strong>Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815)</strong>, implementing the CER Directive. Its significance for the sector under discussion extends far beyond its declared purpose:</p>



<ul class="wp-block-list">
<li><strong>Critical infrastructure operators have obtained the right to apply countermeasures against unmanned platforms, including jamming devices.</strong> Until now, a private entity managing a strategic facility could only await the intervention of the services; it can now itself interrupt communications with the intruder. The power entered into force on 26 June 2026.</li>



<li>The catalogue of authorised formations (the Police, the Border Guard, the State Protection Service, the Military Gendarmerie) obtained competences to destroy, immobilise or take over control of <strong>unmanned surface/floating objects and robots and autonomous vehicles moving on land</strong>, where they create a threat to critical infrastructure. The new Chapter 6a of the Act, modelled constructionally on the provisions of the Aviation Law concerning aircraft, extends the counter-drone regime to the maritime and land domains.</li>



<li>The Act further introduces an obligation of security audits, mechanisms for the protection of supply chains, and establishes the Maritime Security Centre.</li>
</ul>



<p><strong>The defence layer.</strong> It is formed by the <strong>Act of 11 March 2022 on the Defence of the Homeland</strong> – the national framework for the acquisition and operation of unmanned and counter-drone systems, together with the procurement regime in the fields of defence and security.</p>



<p><strong>The direction of change.</strong> This area is evolving intensively in the years 2024–2026 and requires ongoing verification of the entries in the Journal of Laws and of legislative drafts. After a period of tightening of administrative sanctions, assessed by the operator community as disproportionate, the Civil Aviation Authority transmitted to the Ministry of Infrastructure on 5 May 2026 a draft amendment of a deregulatory and ordering character, covering the system of penalties, insurance, mandatory notifications, the securing of critical infrastructure and counter-drone systems. Entry into force is announced for the turn of 2026 and 2027. In parallel, work is under way on the full transposition of NIS2 within the framework of the amendment of the Act on the National Cybersecurity System.<a href="#_ftn83" id="_ftnref83">[83]</a></p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><a>4 · Seven Points of Friction</a></h2>



<p>The pillars described in Part 3 do not form a coherent system. They come into contact with one another at points where their assumptions are mutually contradictory, and the resolution of the collision does not follow from any of them. It is precisely at these points that the undertaking’s real legal risk is concentrated – and it is they, not the content of the individual acts, that should set the agenda of legal advice.</p>



<h3 class="wp-block-heading">4.1 · The “exclusivity” test – the military exclusion in relation to a dual-use product</h3>



<p>The exclusion in Article 2(3) of the Artificial Intelligence Act operates on the condition of the <strong>exclusivity</strong> of the military, defence or national security purpose. This construction assumes that the purpose can be unambiguously assigned to the placing on the market or the putting into service. In the dual-use sector, this assumption is empirically false: the same machine vision module may be sold to the manufacturer of a power plant perimeter protection system and at the same time integrated into a military platform.</p>



<p>The practical consequences are three. First, <strong>the burden of demonstrating exclusivity rests on the entity that invokes it</strong> – and demonstrating a negative fact (the absence of civil application) requires documented control of the distribution channel and end-user clauses. Second, the exclusion relates to the system, not to the undertaking: a company may simultaneously be a provider of a high-risk system and a provider of an excluded system. Third, <strong>modification of the intended purpose after placing on the market changes the regime</strong> – and in a sector in which the end user routinely modifies the platform, this is a real risk, not a hypothetical one.</p>



<p>The practical recommendation is unambiguous: the separation of product lines at the documentary, contractual and – as far as possible – technical level, before the first mixed contract comes into being. Untangling this situation later is costly, and in the course of a company examination it is sometimes impracticable.</p>



<h3 class="wp-block-heading">4.2 · Human oversight: two regimes, one technical requirement</h3>



<p>Article 14 of the Artificial Intelligence Act and the postulate of meaningful human control in humanitarian law<a href="#_ftn84" id="_ftnref84">[84]</a> describe the same property of a system – the human’s capability to understand, verify and interrupt the operation of the automaton – but have an entirely different normative status. On the civil side, it is a legal obligation with an administrative sanction and a documentation requirement. On the military side – the subject of unfinished negotiations.</p>



<p>From this arises an asymmetry with industrial effects: <strong>a manufacturer that builds one technical platform for both tracks must design to the stricter requirement</strong>, because it cannot foresee in advance in which track a given unit will end up. Consequently, the civil requirement becomes the de facto design standard also for excluded applications – a mechanism worth calling the standard-transfer effect. This is one of the few situations in which the defence exclusion operates to the benefit, rather than to the detriment, of the coherence of the system.</p>



<p>The converse mechanism is, however, equally real: operational pressure to shorten the decision chain in a heavily jammed environment leads to constructions in which human oversight is formally preserved but in fact illusory – the operator approves a decision which he had neither the time nor the data to assess. Demonstrating such a situation in evidentiary proceedings requires access to event logs, which Article 12 of the Artificial Intelligence Act requires only on the civil side.</p>



<h3 class="wp-block-heading">4.3 · Jamming as a legally regulated activity</h3>



<p>The jamming power, granted in Poland to critical infrastructure operators from June 2026, is an example of a norm which solves one problem and opens three further ones.<a href="#_ftn85" id="_ftnref85">[85]</a></p>



<p>Jamming devices are, as a rule, inadmissible for marketing and use: they do not satisfy the essential requirements of Directive 2014/53/EU on radio equipment (harmful interference), and their use violates the spectrum management regime. The grant of a statutory power removes the unlawfulness of the act itself, but <strong>does not settle liability for side effects</strong>. Interference in the bands used by satellite navigation systems affects civil aviation, transport, telecommunications networks and – which is sometimes overlooked – energy infrastructure synchronised by satellite time. Questions therefore arise as to: (i) the compensation liability regime of the facility operator towards third parties, (ii) the delimitation of liability between the operator and the manufacturer of the device, (iii) the documentation obligations allowing the course of the event to be reconstructed.</p>



<p>To this is added a third problem, described in section 2.4: <strong>the legal measure was granted at the moment when the technology against which it is effective is in retreat.</strong> The fibre-optic platform is resistant to jamming by definition. The norm responds to the state of the art of two years ago.</p>



<h3 class="wp-block-heading">4.4 · Kinetic neutralisation and liability for damage</h3>



<p>Shooting down or immobilising a platform does not end the event – it begins the fall of a mass with kinetic energy over terrain which is usually precisely what was to be protected. Polish law provides a basis for neutralisation (Article 156ze of the Aviation Law, the provisions of the chapter on the prevention of unlawful operations, the new powers under the Act of 29 May 2026), but <strong>the regime of liability for damage caused as a result of lawful neutralisation remains dispersed</strong> between the liability of the State Treasury for acts of public authority, the general rules of tortious liability and the special provisions on damage caused by the movement of aircraft.</p>



<p>A separate issue is the qualification of independent neutralisation by an unauthorised entity. The shooting down of a drone by the owner of the property over which it is flying is not the exercise of the right of ownership – it is the destruction of another’s thing and, depending on the circumstances, the creation of a danger. Judicial practice in this area is already taking shape.</p>



<h3 class="wp-block-heading">4.5 · Battlefield data as training material</h3>



<p>This is the most under-defined point of the entire map. Collections of recordings from combat operations – visual and thermal imagery from thousands of sorties – have a training value unattainable in laboratory conditions. They flow, formally and informally, in both directions across the civil-military boundary.</p>



<p>The legal issues arrange themselves in three layers. <strong>Data protection:</strong> material of this kind contains the images of natural persons; processing in the course of hostilities falls within the exclusion of Article 2(2) GDPR, but the use of the same collection by a commercial entity to train a model intended for the civil market no longer does – and determining the moment at which the data “enter” the scope of application of the regulation has no unambiguous normative answer. <strong>Data quality:</strong> Article 10 of the Artificial Intelligence Act requires that the training data sets of high-risk systems be representative and free of systematic errors; a collection originating from one theatre of operations, one season of the year and one type of terrain does not satisfy that requirement, which has a direct bearing on the reliability of classifiers in civil applications. <strong>Export control:</strong> the weights of a model trained on such a collection may constitute controlled technology, and making them available outside the customs territory of the Union – an export requiring authorisation (cf.&nbsp;section 3.3, point 3).</p>



<p>The practical recommendation: in every transaction concerning an entity possessing vision models, the provenance of the training data sets must be established and documented in a manner allowing the lawfulness of the chain to be demonstrated. This is today one of the most frequently omitted – and most difficult to repair after the fact – elements of a company examination.</p>



<h3 class="wp-block-heading">4.6 Intangible technology transfer and the dispersed working model</h3>



<p>The export control regime is not limited to the physical movement of goods across the border. Within the meaning of Regulation (EU) 2021/821, “export” also includes the transmission of software or technology by electronic means – inter alia electronic mail, telephone or other electronic means – to a destination outside the customs territory of the Union. Making such software or technology available in electronic form to natural or legal persons located outside the customs territory of the Union is also deemed to be an export. In consequence, granting a foreign engineer, consultant or potential investor the ability to download controlled files from a repository may constitute an export, even if the data at all times remain saved on the same server and the access was remote and short-lived.<a href="#_ftn86" id="_ftnref86">[86]</a></p>



<p>This does not, however, mean that every making available of source code outside the Union automatically requires an authorisation. It must first be established whether the software or technical information in question has been included in the list of dual-use items in Annex I to Regulation 2021/821, or whether the conditions for the control of unlisted items are met on account of their intended end use or end user. In the unmanned aircraft sector, this assessment may concern both the design of the drone itself, its subassemblies and equipment, and the dedicated software and the technology necessary for their development, production or use. Potentially significant will be, inter alia, design documentation, aerodynamic models and simulations, control system diagrams, autopilot code, solutions concerning autonomous navigation, sensor integration, encrypted communications or jamming resistance. The classification should, however, refer to the parameters and criteria of the specific control entry, and not solely to the fact that the given technology is connected with drones.</p>



<p>The risk of intangible technology transfer arises above all in three configurations: (i) in a geographically dispersed development team including persons working from third countries; (ii) in the due diligence process, if the advisers or technical experts of a potential purchaser from outside the Union receive access to the repository, the design documentation or the test environment; and (iii) in the use of cloud infrastructure, if the data are transmitted to servers located outside the Union or can be accessed from there. The mere decentralisation of infrastructure, the use of blockchain technology or the storage of data in the cloud do not yet determine the occurrence of a controlled export. What matters above all is the content of the data, their export classification, the location of the recipient and whether the entity from outside the Union has obtained a real possibility of acquainting itself with the controlled technology. In the case of dispersed data storage, an additional problem may be the impossibility of reliably establishing in which states the individual nodes or copies of the data are located.</p>



<p>For this reason, control of access to repositories containing drone technologies should be an element of the internal export compliance programme, and not solely a cybersecurity procedure. Such a system should encompass the classification of repositories and documentation, the establishment of the state from which the user actually obtains access, the verification of end users and of the purpose of use of the technology, the segmentation of projects, the principle of least privilege, restrictions on the downloading and copying of files, and the keeping of access logs. For the protection of data against unauthorised access does not itself replace the answer to a separate regulatory question: whether the access of a person who is authorised, but located outside the Union, constitutes an export requiring an authorisation.</p>



<h3 class="wp-block-heading">4.7 Supply chain, components and investment control</h3>



<p>The last point of friction is the tension between strategic autonomy and the structure of the component market. The ecosystem which made possible the cost revolution described in section 2.2 rests to a considerable extent on components of geographically concentrated origin – from cells and motors to integrated circuits and cameras. The policy of reducing dependence collides with the fact that alternative European chains do not exist at a scale corresponding to demand.</p>



<p>Legally, this tension materialises in three instruments: the eligibility mechanisms in the financing programmes (the requirement of component origin and of control over the contractor), <strong>Regulation (EU) 2019/452 on the screening of foreign direct investments</strong> together with the national Act of 24 July 2015 on the control of certain investments,<a href="#_ftn87" id="_ftnref87">[87]</a> and the sanctions regime. For an investor, this means that a transaction in this sector requires a parallel analysis of three consent paths: merger control, investment control and – where the object comprises listed assets – export consents. The transaction timetable must take this into account from day one; the attempt to catch up on these consents after the signing of the preliminary agreement is a typical cause of the failure of the process.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>5 · The Dual-Track Nature of the Regime – an Answer to the Practical Question in the Legal Environment</strong></h2>



<p>The juxtaposition of the nine pillars leads to the conclusion that law simultaneously performs <strong>three different roles</strong> – depending on the track in which we find ourselves – and leaves one area uncovered.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Role of law</strong></td><td><strong>Pillars</strong></td><td><strong>Mechanism</strong></td></tr></thead><tbody><tr><td>Consequence of need</td><td>UAV/EASA, U-space level (civil track)</td><td>National law chases technology outpaced by the conflict; it regulates ex post what has already come into being</td></tr><tr><td>Driver</td><td>EDF, EDIRPA, ASAP, SAFE EDIP/SEAP, Defence Readiness Omnibus, IRIS², EDDI</td><td>Law creates demand, finances development, builds infrastructure and removes administrative barriers</td></tr><tr><td>Dampener</td><td>AI Act (civil track), dual use 2021/821, NIS2/CER/CRA, GDPR and the Data Act</td><td>Law limits the risk of mass dissemination, conditioning access to the market</td></tr><tr><td>Regulatory gap</td><td>LAWS / military AI, Art. 2(3) AI Act, art. 2 (2) GDPR, art. 2(3) (a) Reg. 2018/1139)</td><td>The defence exclusions leave development without a brake; international law fills this space only partially</td></tr></tbody></table></figure>



<p><strong>Law is neither exclusively a consequence nor exclusively a driver – it is dual-track.</strong> On the civil track it operates as a consequence of need and as a dampener; on the defence track as a driver. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive acts – whereby, as we demonstrated in section 3.1, the first of them appears already in the EASA basic regulation, and thus at the level of the foundation of the entire regime, not as a special exception.</p>



<p>The paradox lies in the fact that <strong>the same technology is simultaneously being accelerated on the defence side and dampened on the civil side</strong> – and the dual-use boundary along which this division runs is increasingly indistinct. What is more, in the years 2025–2026 we observe an additional phenomenon, which is worth noting as a fourth mechanism: <strong>simplification as a tool of industrial policy</strong>. Both the Defence Readiness Omnibus and the Digital Omnibus aim to lower regulatory burdens – the first on the defence track, the second on the civil one. The direction is convergent, the justifications different: in the first case defence readiness, in the second competitiveness. The effect is a convergence of the two tracks on the procedural side, while their substantive separateness is preserved.</p>



<h2 class="wp-block-heading">6 · Practical Implications for Entities in the Sector</h2>



<h3 class="wp-block-heading">6.1 · The qualification map – questions which must be answered in this order</h3>



<p>For a client from the UAV sector, one question is key: <strong>on which side of the boundary – dual use, military/civil – is its product or project located.</strong> This qualification determines the entire legal regime that covers it. In practice, it is worth conducting it sequentially:</p>



<p>1. <strong>Is the product intended exclusively for military, defence or national security purposes?</strong> If so – the basis of that assertion and the mechanisms of control over the distribution channel must be documented. If not, or not fully – the civil regime applies in its entirety.</p>



<p>2. <strong>Does the Artificial Intelligence Act apply, and if so, on which basis?</strong> Annex I (a safety component of a certified product) or Annex III (critical infrastructure, law enforcement, borders)? On this depends not only the scope of the obligations, but also the date of their application (2 December 2027 or 2 August 2028).</p>



<p>3. <strong>Which product class and operational category does the platform concern</strong> under the 2019/945 and 2019/947 regime – and do the operations require an authorisation in the specific category?</p>



<p>4. <strong>Is the product or any of its components subject to export control</strong> on the basis of Regulation (EU) 2021/821 and the current control list, including under the regime of the catch-all clauses and intangible technology transfer?</p>



<p>5. <strong>Does the device process personal data</strong> – and if so, has an impact assessment been carried out and is the legal basis of the processing documented? Is the platform a “connected product” within the meaning of the Data Act?</p>



<p>6. <strong>What cybersecurity obligations</strong> (the CRA as manufacturer, NIS2 by virtue of its own activity, CER indirectly through the client) cover the manufacturer and the operator?</p>



<p>7. <strong>Does the project qualify for driver financing</strong> (EDF, EDIRPA, ASAP, SAFE, EDIP/SEAP) – and does the ownership and consortium structure satisfy the eligibility and control requirements?</p>



<h3 class="wp-block-heading"><a>6.2 Due diligence of a drone entity</a></h3>



<p>In M&amp;A practice, this means that the examination of the company must cover not only the classic areas (legal title to intellectual property, contracts, obligations), but also <strong>regulatory positioning</strong>. The checklist covers at least:</p>



<ul class="wp-block-list">
<li>the dual-use classification of every component and product, together with the substantiating documentation and the history of authorisations issued;</li>



<li>the status vis-à-vis the Artificial Intelligence Act: an inventory of systems, assignment to categories, assessment of the existence and effectiveness of the exclusion under Article 2(3);</li>



<li>the provenance of the training data sets and the rights to use them – including the chain of title to data originating from third parties or from real operations;</li>



<li>the history of security incidents and compliance with the reporting regimes;</li>



<li>operator registration, operational authorisations, the history of proceedings before the aviation supervisory authority and of administrative sanctions;</li>



<li>exposure to investment control (Regulation 2019/452, the Act of 24 July 2015) and the eligibility requirements in the financing programmes of which the company is a beneficiary;</li>



<li>compliance with the intangible technology transfer regime in the dispersed working model, including a list of the jurisdictions from which access to the repositories was granted;</li>



<li>rights to the results of projects financed from public funds, including export restrictions and access rights allocated to Member States.</li>
</ul>



<p><strong>A procedural remark of significant practical importance:</strong> the mere conduct of the company examination may trigger export obligations if access to the technical documentation is obtained by advisers from third countries. The sequence of steps in the transaction process is therefore not a matter of convenience – it is an element of compliance.</p>



<h3 class="wp-block-heading"><a>6.3 · Compliance calendar 2026–2028</a></h3>



<figure class="wp-block-table"><table class="has-luminous-vivid-orange-background-color has-background has-fixed-layout"><thead><tr><td><strong>Date</strong></td><td><strong>Event</strong></td></tr></thead><tbody><tr><td>2 August 2026</td><td>Transparency obligations under Article 50 of the Artificial Intelligence Act (unchanged despite the simplification package)</td></tr><tr><td>September 2026</td><td>Manufacturers’ reporting obligations under the Cyber Resilience Act</td></tr><tr><td>November 2026</td><td>The Seventh CCW Review Conference – decision on the negotiating mandate concerning autonomous weapon systems</td></tr><tr><td>2 December 2026</td><td>Article 50(2) of the AI Act in relation to systems already present on the market; the new prohibitions under Article 5</td></tr><tr><td>end of 2026</td><td>Initial capability of the European Drone Defence Initiative and Eastern Flank Watch</td></tr><tr><td>turn of 2026/2027</td><td>Announced entry into force of the Polish deregulatory amendment of the Aviation Law</td></tr><tr><td>&nbsp; end of 2027</td><td>&nbsp; Full functionality of EDDI</td></tr><tr><td>2 December 2027</td><td>Obligations for standalone high-risk systems (Annex III of the AI Act)</td></tr><tr><td>December 2027</td><td>Full application of the Cyber Resilience Act</td></tr><tr><td>2 August 2028</td><td>Obligations for AI embedded in regulated products (Annex I – including unmanned systems)</td></tr><tr><td>end of 2028</td><td>Full functionality of Eastern Flank Watch</td></tr></tbody></table></figure>



<p>The dates concerning the part of the simplification package relating to the GDPR, privacy in electronic communications, NIS2 and the Data Act remain unsettled – the file is in negotiations in the Council, and adoption before the end of 2026 is uncertain.</p>



<h3 class="wp-block-heading">6.4 What cannot be postponed</h3>



<p>The postponement of the obligations for high-risk systems is sometimes read as consent to suspend work. This is an error with a measurable cost. Three tasks have no temporal alternative:</p>



<ul class="wp-block-list">
<li><strong>Inventory and classification.</strong> The most difficult element of compliance with the Artificial Intelligence Act is not the completion of documentation, but the identification of all systems in the organisation and the maintenance of that register as successive versions of the product are introduced. This work does not depend on the state of the harmonised standards.</li>



<li><strong>AI literacy (Article 4).</strong> The obligation to ensure an appropriate level of knowledge of the personnel operating AI systems has applied since 2 February 2025 and has not been postponed.</li>



<li><strong>Data architecture and event logs.</strong> The requirements of Articles 10 and 12 are of a design character – satisfying them after the completion of construction work is many times more costly than taking them into account from the outset.</li>
</ul>



<p>It is precisely here – at the interface of technology and the ever-denser lattice of regimes – that the added value of legal advice specialised in highly regulated sectors lies.</p>



<h2 class="wp-block-heading">7 Conclusion – the Conflict as Lens and Barometer</h2>



<p>The Ukrainian conflict is a lens in which the future of dual-use technology can be seen, and a barometer of the direction of its regulation. It refutes the popular thesis that law by its nature restrains technological development: on the defence track, the legal layer of public financing has proved to be a vector of abrupt acceleration – and the instruments adopted in the years 2025–2026, from the Defence Readiness Omnibus to the flagship projects of the Readiness Roadmap 2030, are proof of this on a scale hitherto unknown in Europe. At the same time, it shows that as drones become widespread, civil law assumes a dampening function – controlling export, autonomy, data processing and access to airspace.</p>



<p>Three observations seem most significant for the further discussion.</p>



<p><strong>First</strong>, the defence exclusions are not an exception to the rule, but a systemic construction repeated at every level of regulation – from the EASA basic regulation, through the GDPR, to the Artificial Intelligence Act. Each time, however, they have differently drawn boundaries, which means that the same platform may simultaneously be excluded from one regime and covered by another. The ordering of those boundaries is a task which the EU legislator has not yet undertaken.</p>



<p><strong>Second</strong>, with the shift of value from the platform to the data and models, the regulatory weight is shifting from aviation law towards data and artificial intelligence law. A manufacturer that in 2019 needed mainly a certificate needs, in 2026, a documented chain of provenance of the training data sets, a vulnerability management system and jurisdiction-based access control.</p>



<p><strong>Third</strong>, the innovation spiral will not slow down – and with it, the pace of the layering of the law will not slow down either. A norm responding to the state of the art of two years ago, adopted in reaction to an incident of a year ago, entering into force in a year’s time, will at the moment of its application relate to a world that no longer exists. This is an argument not against regulation, but for regulation based on effects and on the level of risk, resistant to a change of technical solution.</p>



<p>For lawyers serving this sector, the conclusion is one: <strong>an effective legal strategy begins with the conscious positioning of the product on the right side of each of the boundaries of the regime</strong> – and there are today nine of those boundaries, not one. The ability to move simultaneously in the technological and regulatory layer ceases to be an advantage and becomes a condition of presence on this market.</p>



<h2 class="wp-block-heading">Annex A: Glossary of Technical Terms</h2>



<figure class="wp-block-table"><table class="has-vivid-red-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color has-fixed-layout"><thead><tr><td><strong>Term</strong></td><td><strong>Meaning</strong></td></tr></thead><tbody><tr><td>BSP / UAS / UAV</td><td>Unmanned aircraft; an unmanned aircraft system also includes the control station and the link</td></tr><tr><td>FPV (first person view)</td><td>Control from a first-person perspective, through goggles receiving the image from the on-board camera</td></tr><tr><td>BVLOS</td><td>An operation beyond the operator’s visual line of sight</td></tr><tr><td>ISR</td><td>Intelligence, surveillance and reconnaissance</td></tr><tr><td>Relay</td><td>A repeater of the control signal and imagery, allowing terrain obstacles to be bypassed</td></tr><tr><td>Radio horizon</td><td>The maximum range of signal propagation limited by terrain relief and obstacles</td></tr><tr><td>Jamming</td><td>Emission of noise on the control frequencies with the aim of severing the link</td></tr><tr><td>Spoofing</td><td>Substitution of the satellite navigation signal, causing an erroneous determination of position</td></tr><tr><td>WRE / EW</td><td>Electronic warfare</td></tr><tr><td>Loitering munition</td><td>A platform remaining in the task area and carrying out a strike after detecting a target</td></tr><tr><td>Deep strike</td><td>A strike on targets located deep in the adversary’s territory</td></tr><tr><td>Terminal autonomy</td><td>The platform’s capability to complete the task without communications with the operator</td></tr><tr><td>C-UAS</td><td>Counter-unmanned aircraft systems</td></tr><tr><td>SBOM</td><td>A software bill of materials, required by the Cyber Resilience Act</td></tr><tr><td>U-space</td><td>A set of digital services enabling safe UAV operations in designated airspace</td></tr><tr><td>SORA</td><td>The risk assessment methodology for operations in the specific category</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">About the Authors and the Firm</h2>



<p><strong>KG Legal Kiełtyka Gładkowski. Partnership – Attorneys law firm </strong>advises entities from the high-technology sectors and highly regulated industries.</p>



<p><strong>Attorney-at-law (radca prawny) Kazimierz Jakub Gładkowski</strong> specialises in corporate matters.</p>



<p><strong>Attorney-at-law (radca prawny) Małgorzata Kiełtyka</strong>, entitled to appear before all courts, specialises in M&amp;A transactions for entities from the high-technology and highly regulated sectors.</p>



<p><em>This article is of an informational and popular-science nature; it does not constitute legal advice. In individual matters, we recommend contacting the firm.</em></p>



<p><strong>Additional Footnotes and Sources</strong></p>



<p><strong>1.</strong> Violations of Polish airspace on 9/10 September 2025 and earlier incidents (Romania – January 2025; Osiny – August 2025); launch of NATO’s operation Eastern Sentry; compare: T. Withington, “Europe’s Drone Wall – Ready, EDDI, Go!”, <em>European Security &amp; Defence</em>, 13 March 2026, pp.&nbsp;38–41; <a href="https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/">https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/</a></p>



<p><strong>2.</strong> Expert estimate concerning the pace of development of unmanned technologies in wartime conditions; cf.&nbsp;the analysis systematising drone warfare technology – M. Strzyżewski, “Anti-drone defense &#8211; shotguns, nets, EW, interceptor drones”, Marcin Strzyżewski YouTube channel, 2026 (video material).</p>



<p><strong>3.</strong> The analogy and taxonomy of drone categories and the role of situational awareness; the persistence of commercial observation platforms on the battlefield after: M. Strzyżewski, op. cit.</p>



<p><strong>4.</strong> “FPV Drone Warfare: The $1,000 Revolution Reshaping Modern Combat”, drone-warfare.com, 2026. <a href="https://drone-warfare.com/research/fpv-drone-warfare">https://drone-warfare.com/research/fpv-drone-warfare</a></p>



<p><strong>5.</strong> V. Sutea, “Fiber-optic drones have emerged as critical kit for both Russia and Ukraine”, Atlantic Council – UkraineAlert, 24 February 2026 (the appearance of fibre-optic drones in August 2024 in the Kursk area; range of over 30 km, no susceptibility to jamming); <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/?utm_source=chatgpt.com">https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine</a></p>



<p><strong>6.</strong> NATO Allied Command Transformation, Innovation Challenge devoted to countering fibre-optic drones, 2025 – cf.&nbsp;Atlantic Council, op. cit.</p>



<p><strong>7.</strong> “Fire Point FP-1”, Wikipedia (as at 21 July 2026); cf.&nbsp;“FP-1 vs Shahed: Ukraine Ramps Up Production…”, United24 Media, 20 August 2025 (unit cost approx. USD 55 thousand; plywood fuselage, two-cylinder engine).</p>



<p><strong>8.</strong> “Russian largest oil refinery hit for first time by Ukrainian drones”, Politico Europe, 6 July 2026; cf.&nbsp;Tom’s Hardware, 17 July 2026 (strike on the Omsk refinery after a flight of over 2,500 km). <a href="https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery">https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery</a></p>



<p><strong>9.</strong> Regulation (EU) 2018/1139 (EASA), including Article 2(3)(a) (exclusion of military, customs, police and related operations); Delegated Regulation (EU) 2019/945; Implementing Regulation (EU) 2019/947 (open / specific / certified categories). Source: EUR-Lex.</p>



<p><strong>10.</strong> Implementing Regulation (EU) 2021/664 (the U-space framework) together with 2021/665 and 2021/666. Source: EUR-Lex; EASA.</p>



<p><strong>11.</strong> Regulation (EU) 2023/203 (information security requirements in U-space); the consolidated version of 2019/947 applicable from 1 May 2025. Source: EUR-Lex; SKYbrary.</p>



<p><strong>12.</strong> EASA, Easy Access Rules for Unmanned Aircraft Systems – revision of June 2026 (consolidation of the AMC/GM to 2019/947, ED Decision 2025/018/R).</p>



<p><strong>13.</strong> Regulation (EU) 2024/1689 (the Artificial Intelligence Act), Article 2(3) and recital 24; Articles 4, 5, 6, 8–15, 50, 51–55; Annexes I and III. Source: EUR-Lex; artificialintelligenceact.eu (Article 2: Scope).</p>



<p><strong>14.</strong> European Parliament, EPRS, “Defence and artificial intelligence”, 2025 (LAWS outside the scope of the AI Act by virtue of Article 2(3); calls for international regulation).</p>



<p><strong>15.</strong> Digital Omnibus on AI: Commission proposal of 19 November 2025; unsuccessful trilogue of 28 April 2026; preliminary political agreement of 6–7 May 2026; confirmation by Member State representatives on 13 May 2026; approval by the Parliament on 16 June 2026 and by the Council on 29 June 2026. New dates: 2 December 2027 (Annex III), 2 August 2028 (Annex I), 2 December 2026 (Article 50(2) in relation to existing systems and the new prohibitions). Cf. analyses: Gibson Dunn, May 2026; Travers Smith, May 2026.</p>



<p><strong>16.</strong> Regulation (EU) 2021/821 (dual-use export control); entry into force on 9 September 2021; consolidated version from 15 November 2025; Article 4 (catch-all clauses), Article 5 (cyber-surveillance items), the intangible technology transfer regime. Source: EUR-Lex.</p>



<p><strong>17.</strong> European Commission, update of Annex I to Regulation (EU) 2021/821 of 8 September 2025 (emerging technologies). Cf. Akin, “EU Updates Dual-Use Export Control List”, 16 September 2025.</p>



<p><strong>18.</strong> Directive 2009/43/EC on intra-EU transfers of defence-related products; the Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance.</p>



<p><strong>19.</strong> Regulation (EU) 2023/2418 (EDIRPA – common defence procurement). Source: EUR-Lex; European Commission (DG DEFIS).</p>



<p><strong>20.</strong> The SAFE instrument (Security Action for Europe), 2025; procurement to be carried out by the end of 2030. Cf. European Parliament, EPRS, “EU joint defence procurement”, 2026.</p>



<p><strong>21.</strong> Defence Readiness Omnibus, European Commission, 17 June 2025 (accelerated authorisations, framework agreements up to 10 years, simplification of intra-EU transfers, exclusions in REACH/CLP, communication on sustainable finance); preliminary agreement of the co-legislators on the procurement part, June 2026. Source: European Commission (DG DEFIS); Staff Working Document to the proposal of 17 June 2025.</p>



<p><strong>22.</strong> Readiness Roadmap 2030 and the four flagship projects: European Drone Defence Initiative, Eastern Flank Watch, European Air Shield, European Space Shield; timetable: launch Q1 2026, initial capability end of 2026, full functionality of EDDI end of 2027, Eastern Flank Watch end of 2028. Source: European Commission (DG DEFIS); European Parliament, EPRS, “Eastern Flank Watch and European Drone Wall”, October 2025.</p>



<p><strong>23.</strong> European Commission, Action Plan on drone and counter-drone security, 11 February 2026 (IP/26/364); Drone Alliance with Ukraine; announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets.</p>



<p><strong>24.</strong> “Drone deals fueled VC’s 139% surge into defense robotics”, PitchBook, 19 March 2026 (approx. USD 6.2 billion in 169 transactions; a 139% increase).</p>



<p><strong>25.</strong> “Ukraine 2025 defence tech investment topped $57.2M, but the ‘funded market’ is $6.8B, says PitchBook”, Resilience Media, 9 July 2026.</p>



<p><strong>26.</strong> Regulation (EU) 2023/588 (the secure connectivity programme 2023–2027; the IRIS constellation). Source: EUR-Lex; European Commission (DG DEFIS).</p>



<p><strong>27.</strong> Directive (EU) 2022/2555 (NIS2), repealing Directive 2016/1148. Source: EUR-Lex; European Commission (DG CNECT).</p>



<p><strong>28.</strong> Directive (EU) 2022/2557 (CER – resilience of critical entities). Source: EUR-Lex.</p>



<p><strong>29.</strong> Regulation (EU) 2024/2847 (the Cyber Resilience Act) – reporting obligations from September 2026, full application from December 2027. Source: EUR-Lex.</p>



<p><strong>30.</strong> Regulation (EU) 2016/679 (GDPR), Article 2(2)(a) and (b), Articles 5, 6, 9, 13–14, 35; Article 4(2) TEU. European Data Protection Board, Guidelines 3/2019 on the processing of personal data through video devices. Directive (EU) 2016/680 and the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.</p>



<p><strong>31.</strong> Regulation (EU) 2023/2854 (the Data Act), applicable from 12 September 2025; Regulation (EU) 2022/868 (the Data Governance Act).</p>



<p><strong>32.</strong> The Digital Omnibus – the data part (GDPR, privacy in electronic communications, NIS2, the Data Act, DORA): negotiating status as at July 2026; withdrawal of the Cypriot Presidency’s compromise text from the COREPER II procedure at the end of June 2026. EDPB and EDPS, Joint Opinion 2/2026 of 11 February 2026 (opposition to the narrowing of the definition of personal data); Joint Opinion 1/2026 of 20 January 2026 on the amendments to the Artificial Intelligence Act.</p>



<p><strong>33.</strong> The Convention on International Civil Aviation (Chicago, 1944), Articles 3, 3 bis and 8; Additional Protocol I to the Geneva Conventions (1977), Article 36.</p>



<p><strong>34.</strong> The Group of Governmental Experts on LAWS within the framework of the CCW Convention: rolling text since 2024; joint statement of 42 states, September 2025; resolution of the First Committee of the UN General Assembly of 6 November 2025 (156 states); joint call of the UN Secretary-General and the President of the ICRC for the conclusion of negotiations by the end of 2026; Seventh CCW Review Conference – November 2026. Source: UNODA; Lieber Institute West Point, May 2026.</p>



<p><strong>35.</strong> NATO, principles of the responsible use of artificial intelligence in defence (2021) and the revised AI strategy.</p>



<p><strong>36.</strong> The Act of 8 December 2006 on the Polish Air Navigation Services Agency (Journal of Laws of 2025, item 1267), including the Agency’s extended competences in the area of unmanned systems.</p>



<p><strong>37.</strong> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815) – implementation of the CER Directive; the powers of critical infrastructure operators to use jamming devices (from 26 June 2026); the new Chapter 6a concerning unmanned floating objects; the extension of the powers of the Police, the Border Guard, the State Protection Service and the Military Gendarmerie; security audits; the Maritime Security Centre.</p>



<p><strong>38.</strong> The Act of 11 March 2022 on the Defence of the Homeland.</p>



<p><strong>39.</strong> The draft deregulatory amendment of the Aviation Law, transmitted by the Civil Aviation Authority to the Ministry of Infrastructure on 5 May 2026 (the system of penalties, insurance, notifications, protection of critical infrastructure, counter-drone systems) (at present no publication of the source text – see the footnotes referring to press information sources).</p>



<p><strong>40.</strong> Directive 2014/53/EU on radio equipment (essential requirements, harmful interference).</p>



<p><strong>41.</strong> Regulation (EU) 2019/452 establishing a framework for the screening of foreign direct investments; the Act of 24 July 2015 on the control of certain investments.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a href="#_ftnref1" id="_ftn1">[1]</a> <a href="https://www.youtube.com/watch?v=GCOeO35PQh8">https://www.youtube.com/watch?v=GCOeO35PQh8</a> Cf. the analytical material of a Polish commentator on the war and new technologies, based on accounts attributed to Ukrainian military intelligence (HUR), where it was indicated that Russia is producing “more Shaheds of the Geran 4 and 5 model, i.e.&nbsp;the jet variants, than Geran 2 drones, i.e.&nbsp;the piston ones – 3,000 jet-powered per month and 2,800 piston-powered.”</p>



<p><a href="#_ftnref2" id="_ftn2">[2]</a> Paweł Jeżowski, Rosja 2026: Koniec snu Putina o Imperium [Russia 2026: The End of Putin’s Dream of Empire] – Paweł Jeżowski <a href="https://www.youtube.com/watch?v=JSA9sh44Qj4&amp;t=27s">https://www.youtube.com/watch?v=JSA9sh44Qj4&amp;t=27s</a></p>



<p><a href="#_ftnref3" id="_ftn3">[3]</a> European Commission, <em>Communication from the Commission to the European Parliament and the Council – Action Plan on Drone and Counter Drone Security</em>, COM(2026) 81 final, 11 February 2026.</p>



<p><a href="#_ftnref4" id="_ftn4">[4]</a> Treaty on the Functioning of the European Union, Article 288 – the legal character of regulations, directives and other instruments of EU law.</p>



<p><a href="#_ftnref5" id="_ftn5">[5]</a> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815.</p>



<p><a href="#_ftnref6" id="_ftn6">[6]</a> The governmental bill amending the Act on Crisis Management and certain other acts, Sejm print no. 2355, the explanatory memorandum to the bill.</p>



<p><a href="#_ftnref7" id="_ftn7">[7]</a> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, <strong>Journal of Laws of 2026, item 815</strong>, introducing, inter alia, Article 16c into the Act of 26 April 2007 on Crisis Management. Text of the act: <a href="https://eli.gov.pl/eli/DU/2026/815/ogl/pol?utm_source=chatgpt.com">https://eli.gov.pl/eli/DU/2026/815/ogl/pol</a></p>



<p><a href="#_ftnref8" id="_ftn8">[8]</a> The Act of 26 April 2007 on Crisis Management, Article 16c, added by the Act of 29 May 2026.</p>



<p><a href="#_ftnref9" id="_ftn9">[9]</a> The Act of 3 July 2002 – Aviation Law, Article 156ze(1).</p>



<p><a href="#_ftnref10" id="_ftn10">[10]</a> The governmental bill amending the Act on Crisis Management and certain other acts, <strong>Sejm print no. 2355</strong>, together with the explanatory memorandum, Sejm of the Republic of Poland, 10th term: <a href="https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355"><u>https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355</u></a></p>



<p><a href="#_ftnref11" id="_ftn11">[11]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), Article 6 and Article 113.</p>



<p><a href="#_ftnref12" id="_ftn12">[12]</a> The regulation amending Regulation (EU) 2024/1689 as regards the dates of application of the obligations concerning high-risk AI systems.</p>



<p><a href="#_ftnref13" id="_ftn13">[13]</a> <strong>Council on Foreign Relations (CFR)</strong> The CFR indicates that the war in Ukraine has led to a hitherto unseen pace of innovation in unmanned systems: “the Russia-Ukraine war is driving innovations in autonomous warfare not seen on other battlefields.” Kristen Thompson, <em>How the Drone War in Ukraine Is Transforming Conflict</em>, Council on Foreign Relations, 16 January 2024.</p>



<p><a href="#_ftnref14" id="_ftn14">[14]</a> The <strong>Carnegie Endowment for International Peace</strong> describes the conflict as a “living laboratory” for new doctrines of warfare: “both sides are now engaged in a sustained effort to gain advantage through rapid innovation and adaptation, introducing new types of unmanned systems, countermeasures, and operating methods at unprecedented speed.” Andriy Zagorodnyuk, <em>The New Revolution in Military Affairs</em>, Carnegie Endowment for International Peace, 2026.</p>



<p><a href="#_ftnref15" id="_ftn15">[15]</a> <strong>CSIS – Center for Strategic and International Studies</strong> The CSIS report describes how, after the start of the full-scale invasion, Ukraine created within about three years an entirely new defence technology ecosystem based on drones, shortening development cycles from multi-year military programmes to months. Kateryna Bondar, <em>Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine</em>, Center for Strategic and International Studies (CSIS), 18 July 2025.</p>



<p><a href="#_ftnref16" id="_ftn16">[16]</a> K. Bondar, <em>Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine</em>, Center for Strategic and International Studies (CSIS), 2025. The author indicates that the war in Ukraine has radically shortened the cycles of development and deployment of drone technologies: solutions whose development in classic military programmes took many years are now designed, tested and deployed in periods counted in months. Link: <a href="https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine">https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine</a> , Michael Kofman, Rob Lee, <em>Not Built for Purpose: The Russian Military’s Ill-Fated Force Design</em>, Center for a New American Security / Carnegie Endowment for International Peace, an analysis of the technological adaptation of both sides of the conflict and the role of the rapid iteration of unmanned systems.</p>



<p>Link: <a href="https://carnegieendowment.org">https://carnegieendowment.org</a> International Institute for Strategic Studies (IISS), <em>The Military Balance 2025</em>, chapters on the Russo-Ukrainian war and the development of unmanned systems. The IISS indicates that the conflict in Ukraine has led to the mass use of drones as a basic element of combat operations and has accelerated the development of technologies for countering unmanned systems. Link: <a href="https://www.iiss.org/publications/the-military-balance/">https://www.iiss.org/publications/the-military-balance/</a></p>



<p>Samuel Bendett, <em>Russia’s War in Ukraine: The Role of Unmanned Systems and the Future of Warfare</em>, Center for Naval Analyses (CNA). Bendett’s analyses frequently indicate that the war in Ukraine has become a “laboratory” for the rapid evolution of unmanned systems, in which the innovation cycle has been shortened from years to months.</p>



<p>Link: <a href="https://www.cna.org/">https://www.cna.org/</a></p>



<p><a href="#_ftnref17" id="_ftn17">[17]</a> <a href="https://www.youtube.com/watch?v=vI1W4bYCuNA&amp;t=181s">https://www.youtube.com/watch?v=vI1W4bYCuNA&amp;t=181s</a>; thus General Skrzypczak in the press service: “<em>the 7th day of the offensive operation conducted by the Russians is ending. The Russians have not achieved their main objectives, the objectives of the operation, that is they have not captured and have not managed to carry out the encirclement of Kyiv and have not come out on the Mykolaiv axis towards Odesa in order to encircle it jointly with a naval landing. On the auxiliary axes they achieved limited success; they approached Kharkiv and Mariupol; they took Zaporizhzhia. The problem is that the Russians have lost their momentum; the offensive has been halted essentially along the entire front line; the Russians are preparing, trying to bring up reserves, to reconstitute the forces that are prepared, in order to prepare them for combat, but at this moment they do not have such capabilities.</em>”</p>



<p><a href="#_ftnref18" id="_ftn18">[18]</a> In practice, it is precisely at this point that the real value of legal advice for companies from the UAV and dual-use sector begins. For the same product may simultaneously be subject to the rules of aviation law, export law, data protection, cybersecurity, AI compliance and contractual restrictions connected with its further use by the client or integrator. Effective advice therefore does not consist in the analysis of a single provision in isolation from the rest, but in building a coherent risk map: from the classification of the product and the market entry model, through the assessment of compliance obligations and export restrictions, to the structure of contracts, responsibility for implementation and the security of project financing. In the drone sector, the advantage today is gained not only by those who develop better technology, but also by those who are able to order its legal and transactional status earlier in many jurisdictions simultaneously.</p>



<p><a href="#_ftnref19" id="_ftn19">[19]</a> Lieber Institute at West Point, <em>Whose Decision Was It? Drone Swarms and the Accountability Gap in Ukraine</em>, 25 July 2026.</p>



<p><a href="#_ftnref20" id="_ftn20">[20]</a> Commission Delegated Regulation (EU) 2019/945 of 12 March 2019 on unmanned aircraft systems and on third-country operators of unmanned aircraft systems, OJ EU L 152 of 11.06.2019, p.&nbsp;1.</p>



<p><a href="#_ftnref21" id="_ftn21">[21]</a> Commission Implementing Regulation (EU) 2019/947 of 24 May 2019 on the rules and procedures for the operation of unmanned aircraft, in particular Article 14 (the operator registration obligation). The character of the operator registration obligation, including for drones equipped with sensors capable of capturing personal data, is also explained by EASA.</p>



<p><a href="#_ftnref22" id="_ftn22">[22]</a> Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), in particular Article 4(1), Article 5, Article 6 and Article 35.</p>



<p><a href="#_ftnref23" id="_ftn23">[23]</a> Judgment of the Court of Justice of 11 December 2014, <strong>František Ryneš v Úřad pro ochranu osobních údajů</strong>, C-212/13, EU:C:2014:2428.</p>



<p><a href="#_ftnref24" id="_ftn24">[24]</a> Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items.</p>



<p><a href="#_ftnref25" id="_ftn25">[25]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), in particular Article 3, Article 6 and Annexes I and III.</p>



<p><a href="#_ftnref26" id="_ftn26">[26]</a> DJI (full name: SZ DJI Technology Co., Ltd., also referred to as Shenzhen DJI Sciences and Technologies Ltd.) is a private technology company with its registered office in Shenzhen in the People’s Republic of China, founded in 2006 by Frank Wang. The company specialises in the production of commercial and professional unmanned systems, image stabilisers, cameras, aerial imaging devices and solutions for consumer, industrial and agricultural applications. Its most recognisable product lines include, inter alia, Mavic, Mini, Air, Avata, Matrice, Agras and the Osmo line of handheld devices. In the trade literature and media coverage, DJI is commonly described as the largest manufacturer of consumer drones in the world, whereby, owing to the private character of the company, data on its precise revenues and sales volumes are not fully public; publicly available sources point, however, to the global scale of its activity, employment counted in the thousands, and a dominant position in the segment of civil camera drones; <a href="https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/">https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/</a></p>



<p><a href="#_ftnref27" id="_ftn27">[27]</a> <a href="https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic">https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic</a></p>



<p><a href="#_ftnref28" id="_ftn28">[28]</a> <a href="https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/">https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/</a></p>



<p><a href="#_ftnref29" id="_ftn29">[29]</a> <a href="https://www.frontline-robotics.tech/en#product">https://www.frontline-robotics.tech/en#product</a></p>



<p><a href="#_ftnref30" id="_ftn30">[30]</a> The NATO Codification System (NCS) does not derive from a single statute or regulation, but from NATO’s allied standardisation-logistics system, managed by Allied Committee 135 (AC/135). The basic system document is ACodP-1 (NATO Manual on Codification / AC/135 Codification Manual), which sets out the principles, responsibilities and procedures of codification. The system further rests on a series of NATO standardisation agreements (STANAG), in particular STANAG 3150, STANAG 3151, STANAG 4199 and STANAG 4438.</p>



<p><a href="https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO">https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO</a></p>



<p><a href="#_ftnref31" id="_ftn31">[31]</a> <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/">https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/</a></p>



<p><a href="#_ftnref32" id="_ftn32">[32]</a> <a href="https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/">https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/</a></p>



<p><a href="#_ftnref33" id="_ftn33">[33]</a> <a href="https://brave1.gov.ua/en">https://brave1.gov.ua/en</a></p>



<p><a href="#_ftnref34" id="_ftn34">[34]</a> <a href="https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii">https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii</a></p>



<p><a href="https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems">https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems</a></p>



<p><a href="#_ftnref35" id="_ftn35">[35]</a> <a href="https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/">https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/</a></p>



<p><a href="#_ftnref36" id="_ftn36">[36]</a> <a href="https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy">https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy</a></p>



<p><a href="#_ftnref37" id="_ftn37">[37]</a> <a href="https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation">https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation</a></p>



<p><a href="https://www.reuters.com/business/aerospace-defense/ukraine-sharply-raise-purchases-home-produced-fpv-drones-2025-2025-03-10">https://www.reuters.com/business/aerospace-defense/ukraine-sharply-raise-purchases-home-produced-fpv-drones-2025-2025-03-10</a></p>



<p><a href="https://www.reuters.com/world/europe/ukraine-ramps-up-arms-production-can-produce-4-million-drones-year-zelenskiy-2024-10-02">https://www.reuters.com/world/europe/ukraine-ramps-up-arms-production-can-produce-4-million-drones-year-zelenskiy-2024-10-02</a></p>



<p><a href="https://euromaidanpress.com/2026/01/26/ukraine-aims-to-build-7-million-drones-in-2026-70-times-more-than-the-us">https://euromaidanpress.com/2026/01/26/ukraine-aims-to-build-7-million-drones-in-2026-70-times-more-than-the-us</a></p>



<p><a href="#_ftnref38" id="_ftn38">[38]</a> <a href="https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c">https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c</a></p>



<p><a href="#_ftnref39" id="_ftn39">[39]</a> <a href="https://usf.com.ua/en/about-usf">https://usf.com.ua/en/about-usf</a></p>



<p><a href="#_ftnref40" id="_ftn40">[40]</a> <a href="https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en">https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en</a></p>



<p><a href="#_ftnref41" id="_ftn41">[41]</a> See Cabinet of Ministers of Ukraine, <em>Ukraine launches BRAVE1 defence tech cluster to stimulate development of military innovations and defence technologies</em>; cf.&nbsp;also Brave1, <em>About Brave1</em>, where it is indicated that Brave1 is a governmental initiative directed at the development of defence technologies, implemented by the Innovation Development Fund and initiated by the competent state organs and the components of Ukraine’s security and defence sector.</p>



<p><a href="https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii">https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii</a></p>



<p>See EEAS / Delegation of the European Union to Ukraine, <em>EU4UA Defence Tech: EU and Ukraine launch new EUR 3.3 million BRAVE1 grant programme</em>, indicating that the project is financed by the European Union and implemented by BRDO in cooperation with Brave1; cf.&nbsp;also BRDO, <em>Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base</em>, where the title of the implementation project linked with the EU4UA Defence Tech initiative was disclosed.</p>



<p><a href="https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en">https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en</a></p>



<p>See Regulations for the Brave1 EU4UA Defence Tech Grant Program, available in the Legal Terms section of the programme <em>Grant for the development of components for unmanned systems</em> on the eGrants platform; cf.&nbsp;also the Digital State communication, indicating that EU4UA Defence Tech is financed by the European Union and implemented by BRDO in cooperation with Brave1.</p>



<p><a href="https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems">https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems</a></p>



<p><a href="#_ftnref42" id="_ftn42">[42]</a> The concept of the radio horizon should be treated as a technical, not a normative, term. It does not function as a legal definition in the EASA regime, in U-space or in the classic acts of electronic communications law. Its legal significance is, however, obvious, because it describes a material limitation of communications on which the possibility of conducting unmanned operations beyond the direct line of sight depends, and thus it indirectly affects the assessment of the conformity of radio equipment, the safety of operations, the design of BVLOS architecture and liability for the continuity and reliability of transmission.</p>



<p><a href="#_ftnref43" id="_ftn43">[43]</a> <a href="https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0">https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0</a></p>



<p><a href="#_ftnref44" id="_ftn44">[44]</a> <a href="https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/">https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/</a>;</p>



<p><a href="#_ftnref45" id="_ftn45">[45]</a> <strong>Mesh modems turn Shaheds into FPV drones: how enemy technology works:</strong></p>



<p><a href="https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495">https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495</a></p>



<p><a href="#_ftnref46" id="_ftn46">[46]</a> <a href="https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/">https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/</a></p>



<p><a href="#_ftnref47" id="_ftn47">[47]</a> <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/">https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/</a>, <a href="https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/">https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/</a></p>



<p><a href="#_ftnref48" id="_ftn48">[48]</a> <a href="https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/">https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/</a></p>



<p><a href="#_ftnref49" id="_ftn49">[49]</a> European Commission, Joint Research Centre, <em>C-UAS detection, tracking and identification technology</em>.</p>



<p><a href="https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf">https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf</a></p>



<p>Alex Braszko, Center for Army Lessons Learned, August 12, 2025; Fiber Optic Drones: Posing a Significant C-UAS Challenge &#8211; <a href="https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge">https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge</a></p>



<p><a href="#_ftnref50" id="_ftn50">[50]</a> <a href="https://csrc.nist.gov/glossary/term/spoofing">https://csrc.nist.gov/glossary/term/spoofing</a>, <a href="https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf">https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf</a></p>



<p><a href="#_ftnref51" id="_ftn51">[51]</a> <a href="https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying">https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying</a></p>



<p><a href="#_ftnref52" id="_ftn52">[52]</a> <a href="https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371">https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371</a></p>



<p><a href="#_ftnref53" id="_ftn53">[53]</a> <a href="https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/">https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/</a> ; <a href="https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647">https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647</a></p>



<p><a href="#_ftnref54" id="_ftn54">[54]</a> <a href="https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md">https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md</a></p>



<p><a href="#_ftnref55" id="_ftn55">[55]</a> <a href="https://defence-blog.com/ukraine-fields-new-recon-strike-drone/">https://defence-blog.com/ukraine-fields-new-recon-strike-drone/</a></p>



<p><a href="#_ftnref56" id="_ftn56">[56]</a> <a href="https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/">https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/</a>, <a href="https://en.wikipedia.org/wiki/WB_Electronics_Warmate">https://en.wikipedia.org/wiki/WB_Electronics_Warmate</a></p>



<p><a href="#_ftnref57" id="_ftn57">[57]</a> <a href="https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html">https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html</a>;</p>



<p><a href="#_ftnref58" id="_ftn58">[58]</a> <a href="https://bavovna.ai/uav/fp-1/">https://bavovna.ai/uav/fp-1/</a>;</p>



<p><a href="#_ftnref59" id="_ftn59">[59]</a> See NV, How Ukraine-made FP-1 drone reshapes long-range strikes; Militarnyi, Ukrainian Fire Point Establishes In-House Production of Engines for Long-Range Drones; Reuters, Ukrainian drones hit Russia’s largest refinery, in one of deepest strikes yet; cf.&nbsp;also UNN and RBC-Ukraine in relation to the attack on Omsk and the scale of FP-1 production <a href="https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html"><u>NV</u></a> <a href="https://militarnyi.com/en/news/ukrainian-fire-point-establishes-in-house-production-of-engines-for-long-range-drones"><u>Militarnyi</u></a> <a href="https://www.reuters.com/business/energy/ukrainian-drones-hit-russias-largest-refinery-one-deepest-strikes-yet-2026-07-06/"><u>Reuters</u></a> <a href="https://unn.ua/en/amp/siberia-is-also-within-reach-of-ukrainian-precision-president-on-the-fp-1-drone-strike-on-the-omsk-refinery"><u>UNN</u></a> <a href="https://newsukraine.rbc.ua/news/ukraine-s-fp-1-drones-fly-3-400-km-to-strike-1783345876.html"><u>RBC-Ukraine</u></a>.</p>



<p><a href="#_ftnref60" id="_ftn60">[60]</a> See the MTCR Guidelines, the official MTCR website, indicating the division of the control annex into Category I and Category II; cf.&nbsp;also U.S. Department of State, <em>Missile Technology Control Regime (MTCR) Frequently Asked Questions</em>, where it is indicated that Category I covers complete rocket systems and unmanned aerial vehicle systems capable of delivering a payload of at least 500 kg to a range of at least 300 km; as regards the absorption of this logic into EU law, see Regulation (EU) 2021/821 setting up a Union regime for the control of exports of dual-use items. <a href="https://www.mtcr.info/en/mtcr-guidelines"><u>MTCR</u></a> <a href="https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions"><u>U.S. Department of State</u></a> <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L:2021:338:FULL&amp;from=EN"><u>EUR-Lex</u></a>; <a href="https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions">https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions</a></p>



<p><a href="#_ftnref61" id="_ftn61">[61]</a> On the significance of long-range communications for modern drone operations, see Atlantic Council, <em>The coming compute war in Ukraine</em>; on terminal guidance / machine vision enabling autonomous terminal-phase homing, see Modern War Institute, <em>Battlefield Drones and the Accelerating Autonomous Arms Race in Ukraine</em> and Defense Express, <em>How Ukrainian FPV Drones With Automated Terminal Guidance Work</em>; <a href="https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/">https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/</a></p>



<p><a href="#_ftnref62" id="_ftn62">[62]</a> See Article 2(3) and recital 24 of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), which exclude from the regulation’s scope AI systems used exclusively for military, defence or national security purposes; cf.&nbsp;also the discussions on autonomous weapon systems (LAWS) conducted within the framework of the Convention on Certain Conventional Weapons (CCW), in particular the work of the Group of Governmental Experts on Lethal Autonomous Weapons Systems (GGE on LAWS).</p>



<p><a href="#_ftnref63" id="_ftn63">[63]</a> See EASA, <em>Easy Access Rules for Unmanned Aircraft Systems</em>, revision from June 2026, indicating that this revision incorporates the AMC and GM to Regulation (EU) 2019/947 stemming from ED Decision 2025/018/R; cf.&nbsp;also the online version of the publication of 30 June 2026. <a href="https://www.easa.europa.eu/en/document-library/easy-access-rules/easy-access-rules-unmanned-aircraft-systems">EASA</a> <a href="https://www.easa.europa.eu/en/document-library/easy-access-rules/online-publications/easy-access-rules-unmanned-aircraft-systems">EASA online publication</a>.</p>



<p><a href="#_ftnref64" id="_ftn64">[64]</a> See European Parliamentary Research Service, <em>Defence and artificial intelligence</em> (2025), indicating that the European Parliament adopted two main resolutions concerning LAWS and military AI – in 2018 and 2021; cf.&nbsp;also EEAS, <em>Autonomous weapons must remain under human control, Mogherini says at European Parliament</em>. <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/769580/EPRS_BRI(2025)769580_EN.pdf"><u>EPRS PDF</u></a> <a href="https://www.eeas.europa.eu/eeas/autonomous-weapons-must-remain-under-human-control-mogherini-says-european-parliament_en"><u>EEAS</u></a></p>



<p><a href="#_ftnref65" id="_ftn65">[65]</a> See European Parliament Legislative Train, <em>Digital Omnibus on AI</em>, indicating that the proposal formed part of the package published on 19 November 2025; cf.&nbsp;also EPRS, <em>Digital Omnibus on AI</em>, where it is indicated that the co-legislators reached agreement in the trilogue on 7 May 2026, and the Parliament approved it on 16 June 2026; on the final adoption by the Council, see Consilium, <em>Artificial Intelligence: Council gives final green light to simplify and streamline rules</em>, 29 June 2026; the final act: Regulation (EU) 2026/1744. <a href="https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai">Legislative Train</a> <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/782651/EPRS_BRI%282026%29782651_EN.pdf">EPRS PDF</a> <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules">Consilium</a> <a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">EUR-Lex</a>;</p>



<p><a href="#_ftnref66" id="_ftn66">[66]</a> Regulation (EU) 2021/821 entered into force on 9 September 2021 as the new basic act of the Union’s system for the control of exports of dual-use items, replacing the earlier Regulation (EC) No 428/2009. The reference to 15 November 2025 does not mean that the act “ends” in 2025, but that from that day the cited consolidated version applies, taking account of the amendments to the text so far. The date of 8 September 2025, in turn, refers to one of the updates of the control lists / annexes. In August 2026, the regulation still remains an act in force.</p>



<p><a href="#_ftnref67" id="_ftn67">[67]</a> The transfer of model weights means the transfer of the trained parameters of the AI model themselves – that is, the numbers which the model “carries within itself” after training and on the basis of which it operates.</p>



<p><a href="#_ftnref68" id="_ftn68">[68]</a> See Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund; cf.&nbsp;also the European Defence Fund (2021–2027) on EUR-Lex and the European Commission’s official website concerning the EDF. <a href="http://eur-lex.europa.eu/eli/reg/2021/697/oj/eng">EUR-Lex</a> <a href="https://eur-lex.europa.eu/EN/legal-content/summary/european-defence-fund-2021-2027.html">EUR-Lex summary</a> <a href="https://commission.europa.eu/funding-and-tenders/find-funding/eu-funding-programmes/european-defence-fund_en">European Commission</a>;</p>



<p><a href="#_ftnref69" id="_ftn69">[69]</a> See Regulation (EU) 2023/2418 of the European Parliament and of the Council of 18 October 2023 establishing an instrument for the reinforcement of the European defence industry through common procurement (EDIRPA); cf.&nbsp;also the EUR-Lex summary and the European Commission’s official website concerning EDIRPA. <a href="https://eur-lex.europa.eu/eli/reg/2023/2418/oj/eng">EUR-Lex</a> <a href="https://eur-lex.europa.eu/EN/legal-content/summary/strengthening-the-european-defence-industry-through-common-procurement.html">EUR-Lex summary</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/edirpa_en">European Commission</a>;</p>



<p><a href="#_ftnref70" id="_ftn70">[70]</a> ASAP was established by Regulation (EU) 2023/1525 of the European Parliament and of the Council of 20 July 2023 as an instrument supporting the increase of the production capacities of European industry in the field of ammunition and missiles; the logic of this act – consisting in the public strengthening of the production capabilities of the defence industry – is functionally transferable also to the mass production of loitering munitions and drones. <a href="https://eur-lex.europa.eu/eli/reg/2023/1525/oj/eng">EUR-Lex</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/asap_en">European Commission</a>;</p>



<p><a href="#_ftnref71" id="_ftn71">[71]</a> SAFE (Security Action for Europe) was established by Council Regulation (EU) 2025/1106 of 27 May 2025 as a new instrument strengthening European defence capabilities and the defence industry through financial mechanisms and the support of coordinated actions of the Member States; it remains a current element of the EU defence architecture also in 2026. <a href="https://eur-lex.europa.eu/eli/reg/2025/1106/oj/eng">EUR-Lex</a> <a href="https://www.consilium.europa.eu/en/press/press-releases/2025/05/27/safe-council-adopts-new-financial-instrument-to-boost-eu-defence-capabilities/">Consilium</a>;</p>



<p><a href="#_ftnref72" id="_ftn72">[72]</a> See Regulation (EU) 2025/2643 of the European Parliament and of the Council of 16 December 2025 establishing the European Defence Industry Programme (EDIP); cf.&nbsp;also the European Commission’s official website concerning EDIP. <a href="https://eur-lex.europa.eu/eli/reg/2025/2643/oj/eng">EUR-Lex</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/edip-forging-europes-defence_en">European Commission</a>;</p>



<p><a href="#_ftnref73" id="_ftn73">[73]</a> This is a broader European Commission package, adopted on 17 June 2025, intended to create a “defence-readiness mindset” and to simplify the regulatory environment for defence investment. The Commission itself describes it as a comprehensive package and a simplification proposal, and the Parliament in the Legislative Train speaks outright of a Communication on the Defence Readiness Omnibus. It is therefore not simply “the same as EDIP”, but rather a deregulatory-simplification package and the political-legislative environment for faster action by the defence sector. <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/defence-readiness-omnibus_en">European Commission</a> <a href="https://www.europarl.europa.eu/legislative-train/theme-a-new-era-for-european-defence-and-security/file-defence-omnibus">Legislative Train</a></p>



<p><a href="#_ftnref74" id="_ftn74">[74]</a> See European Commission, <em>Readiness Roadmap 2030</em> and <em>White Paper for European Defence &#8211; Readiness 2030</em>, indicating the four flagship projects: Eastern Flank Watch, the European Drone Defence Initiative, the European Air Shield and the European Space Shield. <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/readiness-roadmap-2030_en">European Commission</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/white-paper-european-defence-readiness-2030_en">White Paper</a>.</p>



<p><a href="#_ftnref75" id="_ftn75">[75]</a> Regulation (EU) 2023/588 of the European Parliament and of the Council of 15 March 2023 establishing the Union Secure Connectivity Programme for the period 2023–2027. <a href="https://eur-lex.europa.eu/eli/reg/2023/588/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref76" id="_ftn76">[76]</a> Directive (EU) 2022/2555 (NIS2) of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. <a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref77" id="_ftn77">[77]</a> Directive (EU) 2022/2557 (CER) of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities. <a href="https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref78" id="_ftn78">[78]</a> Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements. <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref79" id="_ftn79">[79]</a> See EDPB/EDPS Joint Opinion 2/2026 of 11 February 2026 on the Digital Omnibus and the EDPB communication of the same day; as to the further negotiating stage and the withdrawal of the text from COREPER II at the end of June 2026, cf.&nbsp;the expert source: Privacy Next, Digital Omnibus Negotiations (GDPR) &#8211; July 2026 Update. <a href="https://www.edpb.europa.eu/news/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while-raising-key_en">EDPB</a> <a href="https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22026-on-the-proposal-for-a-regulation-as_en">Joint Opinion 2/2026</a> <a href="https://www.privacynext.eu/resources/digital-omnibus-negotiations-gdpr-july-2026-update/">Privacy Next</a>.</p>



<p><a href="#_ftnref80" id="_ftn80">[80]</a> See Article 36 of Additional Protocol I of 1977 to the Geneva Conventions; cf.&nbsp;also ICRC, <em>A Guide to the Legal Review of New Weapons, Means and Methods of Warfare</em>. <a href="https://ihl-databases.icrc.org/en/ihl-treaties/api-1977/article-36">ICRC art. 36</a> <a href="https://www.icrc.org/en/publication/0902-guide-legal-review-new-weapons-means-and-methods-warfare-measures-implement-article">ICRC Guide</a>.</p>



<p><a href="#_ftnref81" id="_ftn81">[81]</a> See CCW/MSP/2023/7, para. 20, in which the mandate of the Group of Governmental Experts (GGE) on emerging technologies in the area of lethal autonomous weapons systems (LAWS) was defined as the further consideration and formulation, “by consensus”, of a set of elements of an instrument, without prejudging its character; see also CCW/GGE.1/2026/WP.2, paras. 3–5, 76–78. The Seventh CCW Review Conference has been scheduled for 16–20 November 2026 in Geneva (CCW/MSP/2025/8, para. 19(g); see also UN Secretary-General, Letter convening the Seventh Review Conference of the CCW, April 2026).</p>



<p><a href="#_ftnref82" id="_ftn82">[82]</a> NATO, <em>Summary of the NATO Artificial Intelligence Strategy</em>, 22 October 2021, paras. 7–10, in particular para. 9, containing the six Principles of Responsible Use for AI in Defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability and Bias Mitigation; NATO, <em>Summary of NATO’s revised Artificial Intelligence (AI) strategy</em>, 10 July 2024, paras. 2, 5-10. The revised strategy of 2024 confirms the applicability of the six principles of the responsible use of AI and provides for their further operationalisation, inter alia through standards, assessment and testing procedures (TEV&amp;V) and certification mechanisms.</p>



<p><a href="#_ftnref83" id="_ftn83">[83]</a> <a href="https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r">https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r</a>; Record of the proceedings of the Standing Subcommittee on Civil Aviation (no. 10) of 10 June 2026, Sejm of the Republic of Poland, in particular the statement of the Director of the Unmanned Aircraft Department of the Civil Aviation Authority, Paweł Szymański, who indicated that the draft amendment concerning unmanned aircraft systems prepared by the Civil Aviation Authority was transmitted to the Ministry of Infrastructure on 5 May 2026, constituting a response to the postulates of civil society and the problems revealed in the practice of applying the new provisions; the draft was described as being of a deregulatory, clarifying and ordering character, covering, inter alia, a change of the regulations concerning mandatory third-party liability insurance and sanctions. <a href="https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&amp;documentId=2AEF7DEF0751F54BC1258E22003E5D23&amp;utm">https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&amp;documentId=2AEF7DEF0751F54BC1258E22003E5D23&amp;utm</a></p>



<p><a href="#_ftnref84" id="_ftn84">[84]</a> The postulate of meaningful human control does not currently constitute a separate, binding norm of international law. It is a concept developed within the framework of the negotiations concerning autonomous weapon systems, whose purpose is to ensure that the human retains real control over the application of force. Its legal justification is connected above all with the obligation to comply with the existing norms of international humanitarian law, in particular the principles of distinction, proportionality and the taking of precautionary measures, and the obligation to review new means and methods of warfare on the basis of Article 36 of Additional Protocol I.</p>



<p><a href="#_ftnref85" id="_ftn85">[85]</a> Article 6zj(1)–(4) of the Act of 26 April 2007 on Crisis Management, in the wording given by the Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815, in conjunction with Article 156ze(1) of the Act of 3 July 2002 – Aviation Law, consolidated text: Journal of Laws of 2025, item 1431, as amended.</p>



<p><a href="#_ftnref86" id="_ftn86">[86]</a> Article 2(2)(d) and Article 2(3) of Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, in the current consolidated text; see also Commission Recommendation (EU) 2021/1700 of 15 September 2021 on internal compliance programmes for controls of research involving dual-use items: <a href="https://eur-lex.europa.eu/eli/reg/2021/821/2025-11-15/eng?utm_source=chatgpt.com">Regulation 2021/821</a> and Recommendation 2021/1700.</p>



<p><a id="_ftn87" href="#_ftnref87">[87]</a> The Act of 24 July 2015 on the control of certain investments (consolidated text: Journal of Laws of 2026, item 47, as amended).</p>
<p> </p>






<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/output.mp4" length="1532791" type="video/mp4" />
<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/output-1-1.mp4" length="1247152" type="video/mp4" />

			</item>
		<item>
		<title>Can AI Diagnose Patients? Medical Law and the Artificial Intelligence Revolution</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 12:48:06 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[diagnostic liability]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[doctor responsibility]]></category>
		<category><![CDATA[future of medicine]]></category>
		<category><![CDATA[health law]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[informed consent]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[medical ethics]]></category>
		<category><![CDATA[medical law]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[patient safety]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8868</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The development of artificial intelligence in medicine is no longer just a futuristic vision. Algorithms now support diagnostics, test result analysis, and disease prevention, and Polish medical law is beginning to address the challenges involved. The 2025 amendment to the Code of Medical Ethics explicitly addresses the use of AI [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/">Can AI Diagnose Patients? Medical Law and the Artificial Intelligence Revolution</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<figure class="wp-block-video"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/generated-video-5.mp4"></video></figure>



<p>The development of artificial intelligence in medicine is no longer just a futuristic vision. Algorithms now support diagnostics, test result analysis, and disease prevention, and Polish medical law is beginning to address the challenges involved. The 2025 amendment to the Code of Medical Ethics explicitly addresses the use of AI by physicians for the first time, imposing obligations regarding patient information, obtaining informed consent, and the use of certified systems. However, the question arises: where does the role of technology end and the physician&#8217;s responsibility begin?</p>



<span id="more-8868"></span>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Amendment to the Code of Medical Ethics from 2025</strong></p>



<p>The 2025 amendment to the Code of Medical Ethics addressed the use of artificial intelligence in medical practice for the first time in the history of Polish medical law. Because AI systems are defined as high-risk systems in the EU regulation on artificial intelligence, necessary procedural steps are identified before their practical application. The Code of Medical Ethics stipulates that four criteria must be met: informing the patient about the use of AI in the therapeutic process or when making a diagnosis; obtaining the patient&#8217;s informed consent to the use of AI. According to the AI Act, algorithms approved for medical use and holding appropriate certificates should be used. It is recommended that AI systems support physicians in their work rather than replace them. Therefore, the final decision regarding the use of AI algorithms in medicine rests with the physician. This emphasizes the need for continuous improvement in medical knowledge and the ability to adapt to new technologies.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The obligation to inform the patient that artificial intelligence will be used in the diagnosis or therapeutic process</strong></p>



<p>Properly informing a patient about the use of artificial intelligence is understood as providing accurate information about the fact and characteristics of the AI system being used. This obligation also involves obtaining the patient&#8217;s informed consent to the use of AI systems, which means informing the patient about the possible benefits and risks of the proposed actions and the possibility of using other actions, as well as ensuring the patient knows and understands how the AI system being used works. Physicians should consider the circumstances and personality traits of the individual patient, ensuring that information is provided in an appropriate manner that allows for understanding the content of the message being communicated. The essence of the need for information is that AI systems are not infallible, and although the physician makes the final decision, the patient is aware of the potential risks arising from the use of AI systems. It is fundamentally crucial to respect two important patient rights: the right to information and the right to consent to healthcare services.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The obligation to obtain informed consent from the patient to use artificial intelligence in the diagnostic or therapeutic process</strong></p>



<p>A written declaration of intent is not necessary to obtain patient consent; an oral statement or conduct that leaves no doubt as to the expression of intent is sufficient, although this can pose numerous evidentiary challenges in the event of a lawsuit against the doctor. If patients have been informed of the use of artificial intelligence in the diagnostic or therapeutic process, their consent to the provision of healthcare services will also include consent to the use of AI to provide these services, without the need for separate consent for the initial use of AI. When using AI systems in clinical practice, a distinction must be made between situations where the algorithm is crucial to the service being provided, for example, influencing the patient&#8217;s subsequent decisions without the doctor&#8217;s consent or with minimal consent. In such cases, informing the patient and obtaining their consent is essential. However, when algorithms merely support the doctor&#8217;s work, patient consent is not strictly required, but it is recommended to inform them about the use of AI systems.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>The obligation to use artificial intelligence algorithms that are approved for medical use and have appropriate certificates</strong></p>



<p>According to the AI Act, algorithms approved for medical use and with appropriate certificates must be used, given that medical practice may impact the health or life of the patient. The European system for the safety and market approval of products meeting EU requirements requires testing products using AI systems for compliance with standards and obtaining a certificate of conformity with the CE marking. Most medical software produced in the European Union requires external auditing and certification. A medical device can be software whose manufacturer has intended for use in at least one of the specific medical applications specified in the Medical Devices Regulation. The use of scientifically unverified therapeutic methods is prohibited. Software can be used for various purposes, for example, to control other medical devices, provide information that supports further therapeutic or diagnostic decisions, or assist in the interpretation of results generated by other devices.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size">The final diagnostic and therapeutic decision is always made by the doctor</p>



<p>The fourth regulation, Article 12 of the Code of Medical Ethics, aims to emphasize that artificial intelligence supports physicians in their work, rather than replaces them. Because scientific considerations about artificial intelligence are relatively new, societies still harbor many doubts about increasing the use of artificial intelligence, especially in classified high-risk systems. Furthermore, it is currently impossible for artificial intelligence to replace certain traits that physicians are capable of exercising, such as empathy and intuition.</p>



<p class="has-luminous-vivid-amber-background-color has-background">Prospects and forecasts for the use of artificial intelligence in the work of doctors</p>



<p>The use of artificial intelligence in preventive medicine offers broad prospects thanks to the rapid analysis of millions of data points, which aims to enable early detection of disease. In such cases, the same conditions specified in Article 12 of the Code of Medical Ethics must be met as for treatment and diagnostic procedures. Currently, AI algorithms are increasingly equal to or even superior to qualified physicians in their preventive care. However, the novelty of the technology and the suggestion that AI is solely intended to facilitate physicians&#8217; work contribute to many people&#8217;s skepticism about the further development of AI in preventive medicine. According to researchers, AI is ideal for preventing cardiovascular disease through remote monitoring of hypertension, and the algorithms can analyze, in addition to individual parameters, medical history, genetic predisposition, and lifestyle factors.</p>



<p>Legal status of Code of Medical Ethics</p>



<p>The Code of Medical Ethics was adopted in 1991 during the Extraordinary Second National Congress of Physicians. It is adopted and amended by the Supreme Medical Chamber. Although it is an important act for the medical profession, it does not have the status of a statute and, within the meaning of the Constitution, is not a legal act; instead, it is based on the Act on Medical Chambers. Physicians, as a professional group, have professional self-government, which influences regulations related to professional ethics. Resolutions in the Polish legal system are internal acts, regulating, among other things, the ethical principles of individual professions. The resolution addresses general ethical standards, respect for human rights, and upholding the dignity of the medical profession, which is further defined as physician conduct that does not undermine trust in the profession.</p>



<h2 class="wp-block-heading">Liability for diagnostic errors of artificial intelligence systems</h2>



<p>The dynamic development of artificial intelligence systems in medicine raises significant questions regarding liability for erroneous diagnostic or therapeutic decisions made using AI algorithms. This issue remains one of the most challenging in contemporary medical law, as current regulations do not yet provide a uniform model for liability for damages caused by AI systems.</p>



<p>Generally, according to Article 12 of the Code of Medical Ethics, the final diagnostic and therapeutic decision rests with the physician. This means that even when using advanced AI algorithms, the physician is not released from the obligation to exercise due diligence and critically evaluate the obtained results. If a physician thoughtlessly bases a diagnosis solely on the AI system&#8217;s indications, they may be subject to civil, professional, and in certain cases criminal liability for harm caused to the patient.</p>



<p>However, liability may also apply to healthcare providers, especially when the damage results from improper organization of the treatment process, the use of an uncertified AI system, or a lack of appropriate oversight procedures for the software used. The hospital or clinic is responsible for ensuring the organizational security of the healthcare services provided and for using tools that meet legal requirements and safety standards.</p>



<p>In certain situations, the manufacturer or supplier of an AI system may also be liable. This applies primarily to software malfunctions, design errors, improper model training, or the product&#8217;s noncompliance with the requirements of the AI Act and medical device regulations. In such cases, product liability or contractual liability provisions may apply.</p>



<p>Particular difficulties arise, however, when an incorrect diagnosis results from the so-called autonomous learning process of an AI system. Artificial intelligence systems lack legal personality and therefore cannot be held accountable independently. This necessitates determining which of the participants in the process &#8211; the doctor, the medical facility, the manufacturer, or the technology provider &#8211; actually contributed to the damage.</p>



<p>The doctrine emphasizes that with the further development of artificial intelligence, it will be necessary to create clearer regulations regarding liability for damage caused by AI systems in healthcare. The current legal framework relies primarily on the application of provisions analogous to traditional medical liability and product liability.</p>



<h2 class="wp-block-heading">Other legal acts supplementing the issues of artificial intelligence in medicine</h2>



<h4 class="wp-block-heading">Act on Patients&#8217; Rights and the Patient Ombudsman</h4>



<p>The 2008 Act on Patients&#8217; Rights and the Patient Ombudsman contains regulations complementary to the Code of Medical Ethics, but without addressing the topic of artificial intelligence. Patients have the right to information regarding, among other things, diagnosis, proposed diagnostic and treatment methods, and the foreseeable consequences of their use or omission, as well as the right to information about the type and scope of healthcare services provided by the healthcare provider.</p>



<h2 class="wp-block-heading">Act on the Professions of Physician and Dentist</h2>



<p>The 1996 Act on the Profession of Physicians and Dentists regulates the obligation to practice the profession in accordance with current medical knowledge, available methods and means of preventing, diagnosing, and treating diseases, in accordance with the principles of professional ethics, and with due diligence. In the case of the use of artificial intelligence in medicine as a high-risk system, this means the obligation, stipulated in the KEL, to use certified and approved systems.</p>



<h2 class="wp-block-heading">Other legal acts relating to the issue of artificial intelligence in medicine</h2>



<p>Because the field of artificial intelligence is a relatively new field of study and few legal acts have been created to date to regulate its operation, the vast majority of clinic and hospital regulations still do not directly address the use of artificial intelligence systems in healthcare services. However, indirect references can be found, such as specifying the institution&#8217;s purpose as, among other things, teaching and research activities in connection with the provision of healthcare services and health promotion, including the implementation of new treatment methods and medical technologies, which include artificial intelligence systems.</p>



<h2 class="wp-block-heading">Summary</h2>



<p>The dynamic development of artificial intelligence in healthcare means that existing legal regulations may prove insufficient in the coming years. Developing clear rules of accountability for AI-supported decisions and maintaining a balance between innovation and patient safety will be crucial. Despite technological advances, humans – physicians &#8211; should continue to play a central role in the diagnostic and therapeutic process, bearing responsibility for the patient&#8217;s well-being.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/">Can AI Diagnose Patients? Medical Law and the Artificial Intelligence Revolution</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/can-ai-diagnose-patients-medical-law-and-the-artificial-intelligence-revolution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/generated-video-5.mp4" length="3082353" type="video/mp4" />

			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:33:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy;]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Ecommerce]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[Foreign Investment]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Marketplace]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[Online Retail]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8813</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 Just a few years ago, online store owners primarily had to ensure terms and conditions, privacy policies, and efficient order processing. Today, this is clearly not enough. EU regulations such as the Omnibus Directive and the Digital Services Act (DSA), as well as the increasing role of artificial intelligence in [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/">Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>Just a few years ago, online store owners primarily had to ensure terms and conditions, privacy policies, and efficient order processing. Today, this is clearly not enough. EU regulations such as the Omnibus Directive and the Digital Services Act (DSA), as well as the increasing role of artificial intelligence in assessing store credibility, force businesses to consider their platforms much more broadly. It is no longer just about regulatory compliance, but also about building digital trust, which influences a store&#8217;s visibility, legal security, and customer purchasing decisions. Below, we present a practical checklist of the most important actions to implement to reduce the risk of sanctions and increase the credibility of an online store.</p>



<span id="more-8813"></span>



<h2 class="wp-block-heading" id="ember4228">Practical guidelines for online store owners</h2>



<h2 class="wp-block-heading" id="ember4229">I.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Avoiding UOKiK fines and compliance with the Omnibus Directive</h2>



<p id="ember4230">a. <strong>Implement transactional verification</strong>: You should configure your feedback system so that each review you post is technically linked to the unique order number and email address of the customer who actually completed the purchase.</p>



<p id="ember4231">b. <strong>Updating the content of the regulations</strong>: In the &#8220;Rules for publishing opinions&#8221; section, the verification procedure should be described in detail, whether all opinions (including critical ones) are published and how the average product rating is calculated.</p>



<p id="ember4232">c. <strong>Transparent labeling</strong>: Each review should have a clear status indication (e.g., &#8220;Purchase confirmed&#8221;). If a benefit is provided in exchange for reviews (e.g., a discount code), this information must be clearly and prominently displayed within the review text.</p>



<p id="ember4233">d. <strong>Lowest price mechanism</strong>: In accordance with the requirements of price transparency, each discount must display the lowest price of the product that was valid in the 30 days prior to the introduction of the discount.</p>



<p id="ember4234"><strong>Legal basis</strong>: Act of 30 May 2014 on consumer rights ( Journal of Laws of 2024, item 1796, as amended); Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (OJ EU L 328 of 2019, No. 328, p. 7, as amended); Act of 23 August 2007 on counteracting unfair market practices ( i.e. Journal of Laws of 2023, item 845).</p>



<h2 class="wp-block-heading" id="ember4235">II.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ensuring compliance with the Digital Services Act (DSA)</h2>



<p id="ember4236">a. <strong>Implementing a &#8220;report content&#8221; mechanism</strong>: Every review or user-generated content must have an easily accessible button to report suspected illegality or manipulation of the content.</p>



<p id="ember4237">b. <strong>Procedure for justifying decisions</strong>: In the event of deletion of an opinion or blocking of a user account, the platform is obliged to send the author a detailed justification indicating a specific violation of the regulations or legal provisions.</p>



<p id="ember4238">c. <strong>Internal Complaints Process</strong>: Users must be able to appeal moderation decisions for a period of at least 6 months from the date the platform takes action.</p>



<p id="ember4239">d. <strong>Designation of a contact point</strong>: The entrepreneur must designate an electronic contact point for supervisory authorities and users, enabling efficient communication on matters relating to digital security.</p>



<p id="ember4240"><strong>Legal basis:</strong> Regulation<strong> </strong>(EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, No. 277, p. 1, as amended), in particular Articles 16, 17 and 20.</p>



<h2 class="wp-block-heading" id="ember4241">III.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Reducing the risk of “algorithmic exclusion”</h2>



<p id="ember4242">a. <strong>Design Patterns (UX) Audit</strong>: Eliminate so-called dark patterns, such as asymmetric selector buttons, hard-to-close pop-ups, or mechanisms that make it difficult to unsubscribe. Supervisory algorithms treat such practices as signals of poor interface quality.</p>



<p id="ember4243">b. <strong>Data Certification for AI</strong>: Ensure structured review data is provided, allowing shopping assistants and crawlers to properly verify the “digital provenance” of the data.</p>



<p id="ember4244">c. <strong>Filtering synthetically generated content</strong>: It is worth implementing tools that monitor review language for bot-like patterns (unnatural correctness, lack of detail) to avoid indexing false enthusiasm that results in lower trust rankings.</p>



<p id="ember4245"><strong>Legal basis</strong>: REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, p. 1, as amended) – Article 25 (prohibition of deceptive interfaces)</p>



<h2 class="wp-block-heading" id="ember4246">IV.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Proper management of data and opinions (CaaS model)</h2>



<p id="ember4247">a. <strong>Digital</strong> <strong>Audit</strong> <strong>Trail</strong>: It is recommended to store logs containing transaction metadata related to opinions for a period enabling verification of data reliability (e.g. 12-24 months).</p>



<p id="ember4248">b. <strong>Active mediation systems</strong>: Instead of deleting negative feedback, use complaint management systems that document the process of resolving customer disputes. Resolving a problem is treated by ranking systems as evidence of high-quality service.</p>



<p id="ember4249"><strong>c.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; “Know Your Business Customer” principle</strong>: When running a marketplace model, it is essential to verify the identity of sellers before allowing them to offer goods, collecting registration numbers and contact details.</p>



<p id="ember4250"><strong>Legal basis</strong>: REGULATION (EU) 2022/2065 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L of 2022, No. 277, p. 1, as amended) – Article 30; Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ EU L of 2016, No. 119, p. 1, as amended).</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/">Is Your Online Store Ready for the New Era of Control? A Practical Guide to E-Commerce Responsibilities in 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/is-your-online-store-ready-for-the-new-era-of-control-a-practical-guide-to-e-commerce-responsibilities-in-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</title>
		<link>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/</link>
					<comments>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:20:43 +0000</pubDate>
				<category><![CDATA[CROSS BORDER CASES]]></category>
		<category><![CDATA[Administrative Law]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Competition Law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[Corporate Counsel;]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Markets]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[Ecommerce]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[Foreign direct investment]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Omnibus Directive]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Regulatory Investigations]]></category>
		<category><![CDATA[Technology Law]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8811</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The dynamic development of artificial intelligence-based technologies is revolutionizing not only the commercial sector but also the area of state oversight of the digital market. The implementation of multi-agent systems by the Office of Competition and Consumer Protection (UOKiK) opens a new era in consumer rights enforcement, enabling the mass [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/">Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The dynamic development of artificial intelligence-based technologies is revolutionizing not only the commercial sector but also the area of state oversight of the digital market. The implementation of multi-agent systems by the Office of Competition and Consumer Protection (UOKiK) opens a new era in consumer rights enforcement, enabling the mass and automated identification of unfair market practices. With the Digital Services Act (DSA) and the Omnibus Directive in force, traditional control methods are giving way to algorithmic interface analysis aimed at eliminating so-called dark patterns and price manipulation. However, the use of &#8220;digital controllers&#8221; raises fundamental questions for legal science and business practice about the limits of automated decision-making processes in public administration. Although AI agents significantly improve the effectiveness of detecting violations, their legal status as a source of evidence remains the subject of heated debate. The main thesis is that while AI can be a powerful auxiliary tool for regulatory bodies, the ultimate responsibility for determining the facts and assessing the legitimate interests of a party must rest with humans, which is the foundation of a fair procedure in a state governed by the rule of law.</p>



<span id="more-8811"></span>



<h2 class="wp-block-heading" id="ember3873">Dark Patterns: Legal and Ethical Aspects of Prohibiting Manipulation in Digital Interfaces</h2>



<p id="ember3874">A key obligation of internet platform providers in light of modern regulations is to design interfaces in a transparent and ethical manner. The prohibition of manipulation, formulated, among others, in the Digital Services Act (Article 25), directly affects the structure of so-called deceptive interfaces (dark patterns). Websites and applications cannot be designed in a way that limits the recipient&#8217;s cognitive autonomy, interferes with their ability to rationally assess the situation, or forces them to make a purchasing decision that they would not have made under other circumstances.</p>



<p id="ember3875">One of the most glaring examples of such violations is the asymmetry in the contract conclusion and termination process, <strong>particularly evident in subscription models</strong>. This mechanism relies on extreme simplification of the purchase path while simultaneously mounting procedural barriers when attempting to cancel the service. Visual techniques are used here, among other things: payment activation buttons are highlighted with bright colors and a central location, while contract termination options are deliberately hidden at the bottom of the page, written in small font or masked with colors that blend with the background. Furthermore, canceling a subscription on online platforms often requires multiple selections or confirmation of the desire to cancel, despite the consumer&#8217;s prior explicit choice. Artificial intelligence algorithms, analyzing the page structure and visual hierarchy of elements, can pinpoint these disparities with mathematical precision, creating a list of violations that serves as hard evidence.</p>



<p id="ember3876">In the context of the Omnibus Directive, the obligation to disclose the lowest price 30 days before the discount has become a market standard, but its implementation is open to abuse. The practice of &#8220;empty promotions&#8221; involves artificially inflating the base price just before a planned discount or providing a false reference amount. In this area, AI agents demonstrate particular effectiveness, acting as real-time monitoring systems; they can archive the price history of each product, creating an independent database. Comparing this information with the entrepreneur&#8217;s declaration visible on the website allows for immediate detection of manipulation of the promotional algorithm.</p>



<p id="ember3877">An equally important area of control is the phenomenon of drip pricing , or hiding the real costs of a transaction until the final stage of the shopping cart. Businesses often employ a &#8220;decoy&#8221; strategy, presenting an attractive unit price, which, at the time of order finalization, is increased by mandatory, previously undisclosed costs, such as service fees, packaging costs, or payment processing fees. Pursuant to Article 12 of the Consumer Rights Act, businesses are obligated to clearly and understandably inform consumers about, among other things, the total price for the proposed service. Automated control systems are capable of conducting a full simulation of the purchasing process, from product selection to the payment gateway. Any discrepancy between the price presented in the product list and the amount required to complete the contract is reported by AI as an attempt to circumvent disclosure obligations and a direct violation of the collective interests of consumers.</p>



<p id="ember3878">According to Article 5 of the Act on Combating Unfair Market Practices, the key criterion for assessing a trader&#8217;s behavior is the impact of their actions on the recipient&#8217;s decision-making process. A <strong>market practice is considered misleading</strong> if &#8220;this action in any way causes or is likely to cause the average consumer to make a transactional decision that they would not otherwise have made&#8221;. The legislator specifies that both &#8220;spreading false information&#8221; and &#8220;spreading true information in a manner that is likely to be misleading&#8221; can constitute an infringement. In the digital environment, these manipulations most often focus on the &#8220;existence of a product, its type, or availability.&#8221; A common method of exerting unjustified pressure on consumers is the use of social proof mechanisms and an artificial sense of scarcity. This manifests itself in messages such as: &#8220;this product is now being viewed by x people,&#8221; &#8220;x items have already been purchased today,&#8221; or displaying timers indicating that &#8220;only 30 minutes left until the end of the promotion.&#8221; Particularly problematic from the perspective of trade ethics is the use of so-called false advertising. Timers – clocks counting down to the finale of a supposedly unique price opportunity. In reality, these are fake mechanisms, as after the specified deadline, the offer remains active and the product price remains unchanged or becomes even more favorable. This type of activity, a classic example of dark patterns, is designed to induce fear of missing out (FOMO) in customers and induce them to rush into a transaction. Using AI agents allows regulators to serially monitor such counters and prove their cyclical recurrence, providing direct evidence of deceptive practices.</p>



<h2 class="wp-block-heading" id="ember3879">The algorithm as a controller</h2>



<p id="ember3880">With millions of transactions taking place across the country in just a few minutes or hours, standard order verification procedures prove insufficient to effectively fulfill the statutory responsibilities of supervisory authorities. Technological advancements in the form of AI algorithms come to the rescue. These algorithms can automatically monitor numerous commercial transactions simultaneously, generating preliminary opinions that are ultimately subject to human review. Such systems not only save significant processing time but, above all, enable oversight of a much broader range of businesses and their online platforms. The AI multi-agents used in this process are virtual &#8220;consumer robots&#8221; capable of mass-auditing e-commerce websites, simulating the natural behavior of online users to detect irregularities that a human controller would be unable to detect on such a large scale.</p>



<p id="ember3881">To conduct reliable and effective inspections, Polish law already offers supervisory authorities a toolkit in the form of the &#8220;mystery shopper&#8221; institution. Traditionally, this involves a person unrelated to the inspected company or the inspecting authority making a purchase and then completing a survey regarding specific activities they observe during standard shopping. The implementation of AI technology by the Office of Competition and Consumer Protection (UOKiK) aims to entrust AI multi-agents with the role of such digital &#8220;mystery shoppers.&#8221; Their task is to interact with the website interface, add a product to the cart, and complete the entire purchasing process without disclosing that this activity is being performed by an algorithm or that it is part of an official inspection procedure. This approach allows for direct verification of whether the entrepreneur is not using prohibited manipulative practices, known as dark patterns. However, it should be emphasized that <strong>the activity of AI multi-agents is strictly regulated by legal procedures and cannot be arbitrary</strong>. The algorithm operates under the strict supervision of the President of the Office of Competition and Consumer Protection, who, pursuant to Article 105ia of the Act on Competition and Consumer Protection, must always obtain prior consent from the Court of Competition and Consumer Protection. This mechanism serves as a key safeguard against abuse of power. Furthermore, after completing the inspection, the office is obligated to immediately provide the entrepreneur with an official ID and authorization for the inspection. In the age of digital administration, this obligation can be fulfilled electronically immediately after the AI multi-agents withdraw from the sales platform.</p>



<p id="ember3882">The key legal framework for the operation of algorithms commissioned by the regulator is provided by the EU AI Act. According to its provisions, AI systems used by public authorities for control and supervisory purposes should be considered high-risk AI systems. This entails a strict requirement to design them with appropriate transparency, which allows both the controlling and the controlled entities to properly interpret the system&#8217;s results and use them fairly. In practice, this means that algorithms must be built in an &#8220;explainable&#8221; model. A business subject to allegations based on an algorithmic audit has the statutory right to request full insight into the operation of AI tools. This transparency is essential for the controlled entity to understand the basis and criteria on which the authority deemed its online platform unfair or infringing on the collective interests of consumers (Article 24). This balance between the effectiveness of digital supervision and the right to defense is the foundation of a modern rule of law in the age of algorithms.</p>



<h2 class="wp-block-heading" id="ember3883">The opinion of AI multi-agents as evidence in the case</h2>



<p id="ember3884">After completing the inspection activities on the entrepreneur&#8217;s online platform, the AI algorithm&#8217;s role evolves towards an analytical function, consisting of preparing an opinion indicating detected violations. In the context of potential proceedings against an entity employing unfair market practices, the admissibility of using such an analysis as valid evidence becomes a key issue. Pursuant to Article 7 of the Code of Administrative Procedure (hereinafter referred to as the Code of Administrative Procedure), which establishes the principle of objective truth, a public administration body is obligated to take all steps necessary to thoroughly clarify the factual circumstances. This obligation is consistent with Article 75 § 1 of the Code of Administrative Procedure, which introduces an open catalog of evidence, allowing as evidence anything that may contribute to the clarification of the case, provided it is not contrary to the law.</p>



<p id="ember3885">Under these regulations, the results of AI multi-agent work &#8211; taking the form of reports, opinions, or analyses generated after conducting an audit with court approval &#8211; fully fall within the statutory definition of evidence. However, it should be clearly stated that an AI opinion cannot be equated with an expert opinion within the meaning of Article 84 of the Code of Administrative Procedure. This stems from the fact that an algorithm does not possess the status of a natural person equipped with specialized knowledge, which is a statutory requirement for appointing an expert. Instead, documentation generated by an AI agent should be classified as a private document or so-called &#8220;unnamed evidence.&#8221;</p>



<p id="ember3886">Practical justification for this position can be found in the case law concerning digital evidence. The judgment of the Court of Appeal in Szczecin of September 19, 2016, I ACa 364/15, LEX no. 2147337 aptly describes this issue, pointing out that evidence in a case may include official and private documents, but also means other than those listed in Articles 305-308 of the Code of Civil Procedure. Electronic evidence, currently increasingly used in civil proceedings, is not explicitly listed in the catalog of means of evidence. However, the Code of Civil Procedure does not contain a closed list of evidence sources; anything relevant to the case may constitute evidence. Although the above ruling was issued in the context of civil procedure, due to the identical approach to the openness of the evidence system, it remains fully applicable to administrative proceedings conducted by the President of the Office of Competition and Consumer Protection.</p>



<p id="ember3887">The key element of algorithmic evidence remains the human factor, which serves as a primary safeguard over the autonomous operation of technology. It&#8217;s important to note that AI multi-agents, despite their high sophistication, operate based on statistical probability models, which carries the risk of misinterpreting dynamic website elements. For example, the system may incorrectly classify a standard technical error as intentional dark web activity. patterns or misinterpret the interface&#8217;s intentions in a specific cultural or linguistic context. Therefore, opinions generated by AI agents cannot constitute a standalone and final basis for a decision, but should be subjected to thorough, critical review by an official. Only such a comparison of the &#8220;raw&#8221; algorithmic result with human knowledge and experience allows for avoiding errors that could lead to unjustified penalties. This approach is directly supported by Article 80 of the Code of Administrative Procedure, according to which a public administration body assesses whether a given circumstance has been proven based on the entirety of the evidence. In this process, the &#8220;AI opinion&#8221; is only one of many components that must be weighed against other evidence and evaluated through the prism of principles of logic and life experience, ultimately guaranteeing the implementation of the principle of objective truth and protecting the entrepreneur from the automaticity of decisions made by the algorithm.</p>



<h2 class="wp-block-heading" id="ember3888">Summary</h2>



<p id="ember3889">Multi-agent system implemented by the Office of Competition and Consumer Protection for automatic control of the e-commerce sector poses a significant challenge for entrepreneurs, forcing strict compliance with regulations regarding dark patterns, price transparency (Omnibus Directive, Art. 6a) and information obligations (Consumer Rights Act, Art. 12). These tools are used to mass detect manipulative practices such as drip pricing, fake timers or making it difficult to unsubscribe. Although AI agents perform a function similar to &#8220;mystery shoppers,&#8221; their activity must meet the rigors of Article 105ia of the Act on Competition and Consumer Protection, including the requirement to obtain court consent for a controlled purchase. What is crucial from a procedural perspective is that the findings made by the algorithm do not have the status of an expert opinion within the meaning of Article 84 of the Code of Administrative Procedure (lack of the status of a natural person with specialist knowledge), but constitute only a private document or &#8220;other evidence&#8221; subject to the authority&#8217;s free assessment (Article 80 of the Code of Administrative Procedure).</p>



<p id="ember3890">Consequently, the official is required to subject AI reports to thorough human review to eliminate the risk of misclassification resulting from so-called &#8220;AI hallucinations&#8221; or technical errors in the interpretation of the website&#8217;s code. The entrepreneur has full rights of defense based on the principle of active participation of the party (Article 10 of the Code of Administrative Procedure) and the principle of objective truth (Article 7 of the Code of Administrative Procedure), which means the right to question the bot&#8217;s logic and to access the instructions and parameters of the AI system, in accordance with the &#8220;explainability&#8221; requirement enshrined in the AI Act (Article 13). Any decision based solely on the automated generation of conclusions, without providing the party with an opportunity to comment on the evidence (Article 81 of the Code of Administrative Procedure), constitutes a gross violation of administrative procedure and may constitute an effective basis for challenging the authority&#8217;s decision.</p>



<h2 class="wp-block-heading" id="ember3891">Sources:</h2>



<p id="ember3892">Regulation 2022/2065 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act) (OJ EU L 277, 2022, No. 277, p. 1, as amended).</p>



<p id="ember3893">Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 amending Council Directive 93/13/EEC and Directives 98/6/EC, 2005/29/EC and 2011/83/EU of the European Parliament and of the Council as regards the better enforcement and modernisation of Union consumer protection rules (OJ L 328, 2019, p. 7, as amended).</p>



<p id="ember3894">Act of 30 May 2014 on consumer rights (consolidated text: Journal of Laws of 2024, item 1796, as amended).</p>



<p id="ember3895">Act of 23 August 2007 on counteracting unfair market practices (consolidated text: Journal of Laws of 2023, item 845).</p>



<p id="ember3896">Act of 16 February 2007 on competition and consumer protection (consolidated text: Journal of Laws of 2025, item 1714).</p>



<p id="ember3897">Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) Text with EEA relevance (OJ L 1689, 2024).</p>



<p id="ember3898">Act of 14 June 1960, the Code of Administrative Procedure (consolidated text: Journal of Laws of 2025, item 1691).</p>



<p id="ember3899">Judgment of the Court of Appeal in Szczecin of 19 September 2016, I ACa 364/15, LEX no. 2147337.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/">Multi-agent system in the service of the Polish Office of Competition and Consumer Protection &#8211; a new era of e-commerce control and the limits</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/cross-border-cases/multi-agent-system-in-the-service-of-the-polish-office-of-competition-and-consumer-protection-a-new-era-of-e-commerce-control-and-the-limits/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Digital evidence bundle as a modern means of organizing evidence</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-evidence-bundle-as-a-modern-means-of-organizing-evidence/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-evidence-bundle-as-a-modern-means-of-organizing-evidence/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 18:15:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Business Law]]></category>
		<category><![CDATA[Civil Litigation]]></category>
		<category><![CDATA[Civil Procedure]]></category>
		<category><![CDATA[Commercial Law]]></category>
		<category><![CDATA[Commercial Litigation]]></category>
		<category><![CDATA[corporate law]]></category>
		<category><![CDATA[Cross Border Litigation]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Digital Evidence]]></category>
		<category><![CDATA[Digital Forensics]]></category>
		<category><![CDATA[Dispute Resolution]]></category>
		<category><![CDATA[E Discovery]]></category>
		<category><![CDATA[Electronic Evidence]]></category>
		<category><![CDATA[ESI]]></category>
		<category><![CDATA[Evidence Law]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law]]></category>
		<category><![CDATA[International Litigation]]></category>
		<category><![CDATA[Law Tech]]></category>
		<category><![CDATA[Lawyers Of LinkedIn]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Litigation]]></category>
		<category><![CDATA[Metadata]]></category>
		<category><![CDATA[Online Disputes]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Unfair Competition]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8809</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 The contemporary economic and social reality is undergoing an irreversible process of digitalization. Business activity, commercial communication, and marketing have largely shifted to the internet, e-commerce platforms, and social media. As a consequence, key legal events, infringements of entrepreneurs&#8217; personal rights, acts of unfair competition, and unlawful actions affecting the [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-evidence-bundle-as-a-modern-means-of-organizing-evidence/">Digital evidence bundle as a modern means of organizing evidence</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: July 07, 2026</strong></mark></p>



<p>The contemporary economic and social reality is undergoing an irreversible process of digitalization. Business activity, commercial communication, and marketing have largely shifted to the internet, e-commerce platforms, and social media. As a consequence, key legal events, infringements of entrepreneurs&#8217; personal rights, acts of unfair competition, and unlawful actions affecting the goodwill and reputation of companies now leave traces almost exclusively in the digital sphere. Consequently, the traditional perception of evidence through the prism of paper documents bearing handwritten signatures has become insufficient in the realities of business transactions. Polish civil procedure meets these needs through the fundamental assumption of an open catalog of evidence. However, the dynamic development of technology forces the constant evolution of judicial practice and a full openness to next-generation evidence. In addition to traditional text files, today&#8217;s multifaceted economic processes require the management of complex data structures, such as metadata, advanced web analytics, system logs, and screenshots from social media platforms.</p>



<span id="more-8809"></span>



<p id="ember3370">Presenting such complex, non-linear evidence, which often encompasses many gigabytes of data, requires the implementation of modern procedural information management tools. The concept of a &#8220;digital evidence folder&#8221; emerges as a key tool for structuring, selecting, and correlating digital data directly with precisely formulated evidentiary theses.</p>



<h2 class="wp-block-heading" id="ember3371">The concept of electronic evidence</h2>



<h3 class="wp-block-heading" id="ember3372">Legal status before the 2016 amendment to the Code of Civil Procedure.</h3>



<p id="ember3373">To fully understand the revolution that has taken place in the Polish legal system regarding electronic evidence, it is necessary to refer to the legal status prior to the entry into force of the Act of 10 July 2015. The civil law system at that time lacked a legal definition of a document. Consequently, doctrine and case law equated this term exclusively with the written form of legal acts within the meaning of Article 78 of the Civil Code. The constitutive elements of a document were considered to be its written form and the handwritten signature of the issuer. A document was defined as human thoughts conveyed through graphic symbols arranged in a logical sequence of concepts on a material basis. This legal structure resulted in procedural limitations regarding electronic evidence. Any information transmitted electronically, e.g., in emails or text messages, that bore only a simple electronic signature, could not be accepted as documentary evidence (see, among others, Supreme Court judgments I CK 32/04, I CKN 1280/00). Photocopies, scans, blueprints, and computer printouts were treated as so-called secondary documents. According to the then-established Supreme Court case law, such reproductions did not constitute a document within the meaning of the Code of Civil Procedure. Although the Code of Civil Procedure did not contain a closed catalog of evidence, allowing computer printouts to be considered &#8220;other evidence&#8221; under Articles 308 and 309 of the Code of Civil Procedure, errors occurred in court practice. Some courts took the erroneous position that since a printout or photocopy was not a document, it did not constitute evidence at all and was beyond the court&#8217;s jurisdiction.</p>



<h2 class="wp-block-heading" id="ember3374">Legal definition of a document and its form</h2>



<p id="ember3375">A breakthrough in the approach to electronic evidence occurred on September 8, 2016, when a legal definition of a document was introduced, along with a new form of legal act: the documentary form (Article 77 § 2, Article 73 § 1, Article 74 of the Civil Code). These changes were complemented by a broad amendment to the Code of Civil Procedure of November 7, 2019, which reformulated the rules of evidence (including Article 243 § 2 of the Code of Civil Procedure). Under the current wording of Article 77 § 3 of the Civil Code, a document is content (information constituting a human thought) contained on a medium enabling its review. A key element of this definition is the complete separation of the concept of a document from its physical, paper medium. Nowadays, a medium can be traditional or electronic. All devices and technical spaces used for collective data storage and reading, such as a flash drive, computer disk, server, or cloud computing, are permissible. The introduced amendment to the Code of Civil Procedure explicitly requires that the provisions on documentary evidence apply to all documents containing text that allow for the identification of their issuers. This change removed obstacles to treating digital data as full-fledged documents. However, the mere existence of a medium and the text recorded on it does not automatically allow for the recognition that the documentary form requirements have been met. A necessary premise and minimum condition for granting such evidence material validity is the ability to establish the identity of the person (issuer) from whom the declaration of will or knowledge originated. The act does not impose a rigid catalog of identification methods, meaning that the issuer&#8217;s identity can be proven in any objective manner, adapted to the technical realities of the given tool. Identification may result directly from the document&#8217;s content or from the circumstances surrounding its creation, for example, based on the mobile number from which the text message was sent or the email address from which the email was sent. As a consequence of the changes introduced by the amendment, the distinction between document evidence containing text and documentary evidence in other forms (e.g., audio recording, image recording, or image and sound recording) has become more important. Depending on the form in which the document&#8217;s content is expressed, the procedural system provides for completely different procedures. Article 2341 of the Code of Civil Procedure applies to documents containing text if they meet the conditions (they contain text and their issuers can be identified). If these conditions are met, the provisions on documentary evidence apply to documents in written, electronic, and documentary form. Differences in application include, for example, the appropriate application of Article 244 of the Code of Civil Procedure to documents containing text. Article 308 of the Code of Civil Procedure applies to documents in other forms (consisting of image, sound, or image and sound recordings). When examining them, the court will apply the provisions on visual inspection and documentary evidence, as appropriate.</p>



<p id="ember3376">Although the amended provisions of Polish civil procedure, through a technologically neutral definition of a document, have paved the way for the widespread use of electronic data in proceedings, generally applicable legal provisions still do not provide a legal definition of &#8220;digital evidence&#8221; itself. Such a concept is hard to find not only in the Civil Procedure Code, but also in criminal or administrative procedures. Consequently, the burden of developing a conceptual framework has fallen on legal doctrine and case law. Among the existing definitions used in international trade, the one adopted by the US Department of Justice is worth citing as the most clear and precise. It states that &#8220;digital evidence should be treated as information or data recorded in the form of digital data, of value to ongoing proceedings, and stored, downloaded, or sent using an electronic device. Analyzing the subject matter of digital evidence, it should be noted that this phenomenon can only be discussed when the information useful for evidentiary proceedings is in the form of digital data. From a technical perspective, &#8220;digital data&#8221; constitutes an ordered logical sequence of characters recorded on appropriate media, which, after decoding by an IT system, can take the form of human-readable content. Consequently, the evidence itself (understood as specific information) is highly immaterial, even abstract. This characteristic occurs even when the data is stored using the most tangible objects, such as hard drives or CDs. Therefore, the evidence in a case is solely the content of the digital recording, while the digital evidence carrier itself becomes, in essence, merely a &#8220;piece of plastic&#8221; and a physical medium. From the perspective of evidence theory, data recorded on a computer medium is not a thing. The essence of this distinction is best captured by a forensic analogy: evidence in a case is the information contained on the disk, not the disk itself – just as evidence is a secured fingerprint, not the entire door along with the doorknob on which the fingerprint was left. This information, hidden in a digital structure, can take two forms. On the one hand, these are forms visible to the naked eye to the average system user, such as photos, text files, or programs on a computer. On the other hand, full-fledged digital evidence requires specialized knowledge, as it is found, for example, in system logs, command history, print traces, or metadata. The lack of a legal definition does not constitute any obstacle to the jurisdictional admissibility of digital evidence in the Polish legal system. This fact is confirmed in all key court proceedings. In civil proceedings, the implementation of Article 77 § 3 of the Civil Code neutralizes the technological barrier.</p>



<h2 class="wp-block-heading" id="ember3377">Digital evidence bundle</h2>



<p id="ember3378">A digital evidence bundle is a structured collection of evidence stored on an electronic medium. It is organized according to a predetermined evidentiary logic (evidence theses). It differs from a standard set of electronic files in that each file is marked to enable its identification during the hearing, and there is a documented link between the theses and specific files. A digital evidence bundle is not a separate legal institution in the Polish legal system. The situation is different in the British legal system. In that system, the bundle (e- bundle) is regulated by general court guidelines for e- bundles, designed to ensure a uniform standard of preparation. In the UK, the bundle must be submitted in PDF format, all pages must be numbered, and the file name must include the case reference number. Furthermore, the UK Supreme Court requires that the bundle index be hyperlinked to the pages or documents to which it refers, and attorneys should refer to the bundle numbering rather than the original page numbers during the hearing. In the Polish digital process, a digital file is not a new, separate means of evidence, but a structured collection of many text and non-text documents, logically and technically linked into one coherent information system, subject to the provisions on documentary evidence (and evidence from other documents.</p>



<h2 class="wp-block-heading" id="ember3379">Creating a digital evidence bundle</h2>



<h3 class="wp-block-heading" id="ember3380">1. The method of presenting the file to the court</h3>



<p id="ember3381">In the practice of Polish civil courts, the digital file can be presented in two ways</p>



<p id="ember3382">Transfer on a physical data carrier – in light of the analyzed technological neutrality of the document definition, the evidence file may (and, if larger, must) be transferred on a physical carrier such as a flash drive, portable external drive, or DVD. This carrier will be attached to the procedural document (e.g., an evidentiary motion).</p>



<p id="ember3383">Transmission via teleinformatics – e.g. via an information portal (smaller size)</p>



<p id="ember3384">A necessary condition is to maintain the integrity and durability of the data and to provide the opposing party with full access to the same version of the file.</p>



<h3 class="wp-block-heading" id="ember3385">2. Construction of the Digital Evidence Bundle</h3>



<p id="ember3386">To ensure clarity, the portfolio should have a rigorous and transparent structure. A key element will be an interactive table of contents, modeled after the British e-bundle. This should be a PDF file located in the root directory of the medium. Each item in the table of contents must be a hyperlink, which, when clicked, takes the user to the appropriate source file stored on the medium. The table of contents must also include metadata to facilitate orientation, such as a unique serial number, file name, date of creation, and description.</p>



<p id="ember3387">Effective implementation of a digital evidence folder requires assigning each digital trace to a predefined directory subgroup:</p>



<h3 class="wp-block-heading" id="ember3388">text documents (group code: TXT)</h3>



<p id="ember3389">&#8211; Includes, among others, digital contracts, general terms and conditions, regulations and other documents in electronic form</p>



<p id="ember3390">&#8211; Files in .pdf/ .docx /.txt formats</p>



<p id="ember3391">&#8211; Basis: Evidence from a document containing text</p>



<h3 class="wp-block-heading" id="ember3392">email messages (EML)</h3>



<p id="ember3393">&#8211; Business correspondence between the parties, commercial threats, offer arrangements, order confirmations</p>



<p id="ember3394">&#8211; eml / .msg format (source files) and export of the thread to a searchable .pdf file</p>



<p id="ember3395">&#8211; Evidence from a document containing text</p>



<h3 class="wp-block-heading" id="ember3396">instant messaging (MSG) correspondence</h3>



<p id="ember3397">&#8211; Conversations from applications such as WhatsApp, Messenger, Telegram, Signal, Teams documenting operational arrangements, attempts to induce unfair competition</p>



<p id="ember3398">&#8211; Full, non-editable export of chat history to PDF with timestamps, and raw .csv or .json files for IT backup</p>



<p id="ember3399">&#8211; Evidence from a document containing text</p>



<h3 class="wp-block-heading" id="ember3400">Screenshots (SCR)</h3>



<p id="ember3401">&#8211; Screenshots showing, for example, defamatory social media posts, unlawful use of trademarks</p>



<p id="ember3402">&#8211; Format . png /.jpg/. tiff . The screenshot should be made with the URL, system date and time visible.</p>



<p id="ember3403">&#8211; Requires metadata enhancement and metadata verification (as to date)</p>



<p id="ember3404">&#8211; Depending on what the evidence shows, either from a document containing text or from another document containing an image</p>



<h3 class="wp-block-heading" id="ember3405">Graphic materials (IMG)</h3>



<p id="ember3406">&#8211; E.g. packaging designs, logos, advertising graphics</p>



<p id="ember3407">&#8211; Format: .jpg/ .png / .tiff</p>



<p id="ember3408">&#8211; Evidence from other documents (Article 308 of the Code of Civil Procedure)</p>



<h3 class="wp-block-heading" id="ember3409">Audio Recordings (AUD)</h3>



<p id="ember3410">&#8211; Telephone conversation records, dictaphone recordings of negotiations</p>



<p id="ember3411">&#8211; Format: .mp3/.wav and text transcription in PDF format</p>



<p id="ember3412">&#8211; Evidence from other documents</p>



<h3 class="wp-block-heading" id="ember3413">Video Recordings (VID)</h3>



<p id="ember3414">&#8211; E.g. Materials from YouTube and TikTok platforms</p>



<p id="ember3415">&#8211; Format: .mp4/ .mkv / .avi</p>



<p id="ember3416">&#8211; Evidence from other documents</p>



<h3 class="wp-block-heading" id="ember3417">Analytical Reports (ANL)</h3>



<p id="ember3418">E.g. Official reports from CRM and SAP systems</p>



<p id="ember3419">Format: PDF with a qualified electronic signature of the issuer</p>



<h3 class="wp-block-heading" id="ember3420">Documentary evidence</h3>



<p id="ember3421">Statistical data (DAT)</p>



<p id="ember3422">For example, raw data from analytical tools</p>



<p id="ember3423">Formats: .xlsx / .csv</p>



<p id="ember3424">If they contain only numbers and tables, they are evidence from other documents</p>



<p id="ember3425">Internet Archives (ARC)</p>



<h2 class="wp-block-heading" id="ember3426">Complete copies of the defendant&#8217;s websites, the status of websites secured through tools</h2>



<p id="ember3427">Format: .html / .warc</p>



<p id="ember3428">Evidence from other documents</p>



<p id="ember3429">Metadata (MET)</p>



<p id="ember3430">&#8220;Data about data&#8221; is crucial for authenticity: technical email headers (establishing the true sending server IP), EXIF photo data (indicating the exact camera model, GPS coordinates, and time the photo was taken), and PDF file properties (revealing the author and the legality of the software).</p>



<p id="ember3431">Formats: .txt/.xml / .json or extracts generated by programs</p>



<p id="ember3432">Metadata is an integral part of the digital document from which it originates.</p>



<p id="ember3433">Evidence theses should be linked by headings in the table of contents (PDF):</p>



<p id="ember3434">E.g. TD-1 (Evidence Thesis No. 1) as a result of the defendant&#8217;s breach of contract, the plaintiff suffered damage (LINK) &#8212;&#8212;&gt; subfolder [TXT] &#8212;-&gt; agreement.docx</p>



<h2 class="wp-block-heading" id="ember3435">Examples of formulated evidentiary theses:</h2>



<h3 class="wp-block-heading" id="ember3436">Sample Thesis on the Dissemination of Information on the Internet</h3>



<p id="ember3437">Pursuant to Article 235 § 1 of the Code of Civil Procedure, I request the admission and taking of evidence from materials collected in section TD-1 of the Digital Evidence Folder filed on a data carrier constituting Annex No. [no.] to this letter, including, according to the table of contents of the folder, the following categories of evidence: analytical documents (TD-1/ANL), screenshots (TD-1/SCR), internet archives (TD-1/ARC) and a metadata and checksum report (TD-1/MET) regarding the scope of dissemination of the information contained in the publication [exact designation: title, URL, date], posted by the defendant via the [name] platform, including: the total number of views of this publication in the period from [date] to [date]; the number of websites that reprinted, quoted or linked to this publication; the secondary reach resulting from sharing by users within and outside the same platform; as well as the persistence of accessibility of the challenged content, as measured by its presence in the search engine index after [number] months from its initial publication. A detailed list of the files comprising section TD-1, along with a description of each, SHA-256 checksums, and hyperlinks to individual documents, is included in the table of contents of the Digital Evidence Folder.</p>



<h2 class="wp-block-heading" id="ember3438">Regarding the number of interactions</h2>



<p id="ember3439">Pursuant to Article 235¹ of the Code of Civil Procedure, I request the admission and taking of evidence from materials collected in section TD-2 of the Digital Evidence Folder filed on a data carrier constituting Annex No. [no.] to this letter, which includes, in accordance with the table of contents of the folder, video files from screen recordings (TD-2/VID), screenshots of interaction sections (TD-2/SCR) and exported comment databases in text/JSON format (TD-2/DAT), regarding the scale and nature of internet users’ interaction with the disputed video material/post [exact designation, URL], posted by the defendant on the [name] platform, including: the total number and dynamics of growth of public reactions (likes, shares, retweets); the number, content and tone of comments posted under the material, in particular those repeating the defendant’s narrative; the degree of audience engagement measured by ER (Engagement Rate) indicators; and the fact and date of the defendant&#8217;s modification or deletion of selected comments in order to manipulate public perception, as evidenced by discrepancies in the checksums and metadata of files secured at intervals.</p>



<h3 class="wp-block-heading" id="ember3440">For the purpose of conducting paid promotional campaigns</h3>



<p id="ember3441">Pursuant to Article 235¹ of the Code of Civil Procedure, I request the admission and taking of evidence from materials collected in section TD-3 of the Digital Evidence Folder submitted on a data carrier constituting Annex No. [No.] to this letter, including extracts from the public Meta Advertising Library (TD- 3/ANL), raw analytical reports in CSV/XLSX format generated from the Meta Ads Manager panel and related settlement invoices (TD-3/TXT), in the event of deliberate, organized and paid increase in the market reach of the defendant&#8217;s message, including: the precise period of broadcasting of paid advertising campaigns, the amount of the budget involved and the profit generated; the artificial multiplication of the number of views and unique recipients obtained in this way); geotargeting criteria and demographic targeting aimed at the plaintiff&#8217;s market; and, above all, the circumstance of intentional selection of behavioral targeting criteria and interests based on the plaintiff&#8217;s brand and customers, which, in the light of Article 3 et seq. UZNK constitutes an action contrary to good practice aimed at unfairly taking over customers.</p>



<h3 class="wp-block-heading" id="ember3442">Documenting the extent of interaction</h3>



<p id="ember3443">Internet reach (Reach) is the total number of unique users who have viewed a given piece of content at least once. It is measured using advanced telemetry systems, tracking scripts, and server logs that record unique queries sent by user browsers and applications to the servers storing the content. Reach should be distinguished from Impressions, which define the total number of times content is played or appears on device screens, regardless of whether it was generated by the same person. In summary, the main difference between reach and impressions comes down to the group of people – reach counts unique users (meaning the same person is not counted twice), while impressions count the total number of impressions (which includes impressions generated multiple times by the same person). Engagement is a separate category, requiring active action on the part of the user, such as clicking, liking, or commenting.</p>



<p id="ember3444">With regard to market practice, it should be noted that for the marketing industry, the above-mentioned indicators are among the basic instruments of ongoing analytics, used to evaluate the effectiveness of campaigns and optimize advertising budgets. Passive indicators, such as reach and impressions, allow marketing agencies to determine the upper limits of the sales funnel and estimate brand awareness among the selected target group (audience active metrics, in turn, range from raw engagement, through click -through rates, to advanced metrics such as virality (the ability of information to rapidly spread online through reciprocal shares) and amplification (an indicator measuring how widely content is shared beyond the author&#8217;s original audience). They are interpreted as a direct measure of the quality and appeal of the advertising creative. High levels of these parameters mean that the message effectively resonates with audience needs, prompting them to interact and organically distribute the content further. Importantly, in business realities, the marketing industry treats this data as a currency of account, as it is based on them, for example, the market value of influencers. The widespread use and high methodological sophistication of these measurements in marketing give the reports generated by advertising systems a strong mandate of objectivity.</p>



<p id="ember3445">In court practice, these indicators can serve as evidence. The reach indicated by the number of unique users can determine the scale and prevalence of infringements of personal rights. In the context of infringement of personal rights, indicators such as virality can be useful to demonstrate the irreversibility of the effects of the infringement.</p>



<h3 class="wp-block-heading" id="ember3446">Proving your social media activity</h3>



<p id="ember3447">When assessing the scale of a tort and estimating the amount of damages or compensation (Article 233 § 1 of the Code of Civil Procedure), a court cannot rely on general statements. It requires hard metrics that illustrate the strength, reach, and dynamics of the unlawful communication. Each leading internet platform operates its own unique data architecture. For digital evidence to be fully understandable and legible to the adjudicating panel, it is necessary to precisely identify and name indicators native to a given online environment. Each of the most popular social media platforms differs in which indicators are most relevant.</p>



<h3 class="wp-block-heading" id="ember3448">Measurable metrics for each platform</h3>



<p id="ember3449">X (formerly Twitter) – a text and information platform.</p>



<p id="ember3450">Number of publications – the number of posts (tweets) posted by a given person</p>



<p id="ember3451">Number of mentions – the number of posts that quote a given person&#8217;s post</p>



<p id="ember3452">Number of views – an indicator visible under each post, used to show how many times the information appeared on users&#8217; screens</p>



<p id="ember3453">Number of interactions – number of likes, retweets, and bookmarks of the tweet</p>



<p id="ember3454">Number of comments – number of replies to a tweet</p>



<p id="ember3455">Number of followers – determines the size of a person&#8217;s profile and may determine the basic reach of the entry</p>



<p id="ember3456">Facebook</p>



<p id="ember3457">Number of views, audiences and unique users</p>



<p id="ember3458">Number of reactions (like, great, haha, etc.) – important for demonstrating the engagement rate and social reception of a given post</p>



<p id="ember3459">Number of comments and shares</p>



<p id="ember3460">Instagram – a visual and audiovisual platform – is crucial in cases of unfair competition committed by influencers (e.g., failure to indicate collaboration).</p>



<p id="ember3461">Number of views, audience, reach – for stories measured within 24 hours of publication (before it is automatically archived)</p>



<p id="ember3462">Number of interactions, reactions</p>



<p id="ember3463">Number of followers</p>



<p id="ember3464">YouTube is a video platform. As a result, disputes mainly concern defamatory videos or unlawful product placement.</p>



<p id="ember3465">Number of views and total watch time (watch time) is crucial for showing whether the audience watched the entire video or turned it off after a few seconds</p>



<p id="ember3466">Number of interactions or comments (thumbs up and down)</p>



<p id="ember3467">Number of channel subscribers</p>



<p id="ember3468">Tik Tok – short video content based on a recommendation algorithm. Currently, this is crucial when it comes to the virality of a given video or topic.</p>



<p id="ember3469">Number of views</p>



<p id="ember3470">Number of interactions – likes, favorites, shares</p>



<p id="ember3471">Video completion rate – how many users watched the video to the end</p>



<p id="ember3472">LinkedIn – a business platform. Any posts that violate the personal rights of entrepreneurs are of a serious nature due to the greater potential for reaching business partners.</p>



<p id="ember3473">Number of publications, mentions, views</p>



<p id="ember3474">Number of interactions and reactions</p>



<p id="ember3475">Recipient structure – identification of positions, industries, and company sizes</p>



<p id="ember3476">Reddit and other forums of this type, e.g. Wykop – platforms based on threaded structure and user anonymity</p>



<p id="ember3477">The number of interactions and reactions – up or down votes (Upvotes or Downvotes) – determine the position of the thread on the main page of the website and the time of its visibility</p>



<p id="ember3478">Number of comments &#8211; entries in the thread</p>



<p id="ember3479">Number of unique users</p>



<p id="ember3480">Blogs and news portals, e.g. Onet, WP, Interia – violations concern in particular press articles or unlawful use of graphics.</p>



<p id="ember3481">Number of publications</p>



<p id="ember3482">Number of unique users and number of views</p>



<p id="ember3483">Time spent on the site</p>



<p id="ember3484">Number of comments under articles</p>



<p id="ember3485">With respect to analytical tools for measuring and verifying metrics in the virtual space, three categories of tools are used in litigation, providing objective evidence with a high level of credibility. The first are native social media platform panels, such as Meta Business Suite, YouTube Studio, X Analytics, and LinkedIn Page Analytics. These, as internal statistical systems of service providers, provide direct insight into relational databases and enable the generation of official analytical reports (filed in the ANL subfolder of the digital file) containing precise structure of views, reach, and audience demographics. In situations where the infringement occurred on third-party profiles or external portals to which the plaintiff does not have administrative access, professional media and internet monitoring systems, such as Brand24, SentiOne, the Institute of Media Monitoring (IMM), and Press-Service, are used. These systems aggregate public mentions in real time, measure the total algorithmic reach, and automatically qualify the sentiment of statements, creating reports that resemble private documents. This set of instruments is complemented by specialized web analytics and market intelligence tools (SEO Tools), including Google Analytics 4, Similarweb, Semrush, Ahrefs and Senuto; they allow for the examination of the number of unique users and page views on the defendant&#8217;s external blogs or news portals, proving the intensity of unfair advertising campaigns by a competitor, and demonstrating the dynamics of traffic decline on the plaintiff&#8217;s website.</p>



<h2 class="wp-block-heading" id="ember3486">MetaAds advertising campaigns</h2>



<p id="ember3487">Within the Meta Ads Manager advertising system, system reports and the public Meta Ad Library (powered by extended data under the EU Digital Services Act DSA), you can prove key campaign parameters, such as the exact broadcast period and creative activity status, campaign budget supported by invoices from Meta Platforms , total number of impressions, unique audience (reach), click statistics (including CTR and CPC), as well as precise geotargeting criteria (countries, cities or radii around specific points) and advanced parameters of demographic (age, gender) and behavioral targeting, including interests, Lookalike lists and Custom groups. Audiences are created based on, among other things, email databases and Pixel Meta code. To effectively present this data to a Polish court as digital evidence (e.g., under Article 308 of the Code of Civil Procedure), you must export raw, certified reports from the ad manager panel in .xlsx or .csv formats containing unique Campaign IDs or Ad IDs, create a secure screencast of the login and statistics generation process with a visible URL, SSL certificate, and system time, submit official financial documentation corresponding to the ad account ID, and notarize a public extract from the Ad Library.</p>



<p id="ember3488">Ads data is crucial evidence in unfair competition cases, as it helps demonstrate the scale, intent, content, and target audience of unlawful market activities. In the context of misleading designations of companies, goods, or imitations of products listed in Articles 5, 10, and 13 of the Act on Combating Unfair Competition (UZNK), and unfair advertising under Article 16 of the UZNK, statistics on the number of views and audiences demonstrate the mass nature of the infringement and the degree to which it has caused confusion in the market. Secured graphic and video materials illustrate the very fact of unlawfully copying a product&#8217;s external appearance or using a competitor&#8217;s trademarks. In turn, precisely demonstrating behavioral targeting based on a competitor&#8217;s company or brand name exposes intentional bad faith, involving parasitizing another&#8217;s reputation and aggressively acquiring customers, which directly violates good practices and the interests of another entrepreneur, pursuant to the general clause of Article 3 of the UZNK. Moreover, detailed emission parameters, prices, campaign budgets and click statistics constitute a solid basis for demonstrating the dissemination of false information about prices or the legal situation (Article 14 of the Advertising Law), and also allow for a precise estimation of the amount of damage suffered, lost profits or the degree of unjust enrichment of the perpetrator.</p>



<h2 class="wp-block-heading" id="ember3489">Video materials</h2>



<p id="ember3490">Video materials constitute an independent piece of evidence in contemporary civil and commercial proceedings, classified under the Code of Civil Procedure as evidence from devices recording or transmitting images and sounds, to which the provisions on evidence from visual inspection apply accordingly. As with screenshots, raw video recordings are subject to the principle of limited trust due to the risk of manipulation. Therefore, to maintain full procedural immunity and rebuttal, they must be properly recorded along with their network environment. This, in the event of technological disputes, paves the way for specialized verification of their metadata by a computer forensics expert.</p>



<p id="ember3491">Securing and verifying YouTube recordings for legal purposes requires immediate capture of the material in its entirety and without any editing, which is best achieved through screen recording (including audio and visible page context) or using external download tools. For evidence to be credible in court, the circumstances of its recording (who recorded it, when, and on what device) must be precisely described in an evidence log, and the number of file transfers must be minimized, protecting the original metadata. The author&#8217;s identity and the authenticity of the video itself are confirmed through content analysis, witness testimony, and, in cases of risk of disinformation and manipulation, using tools such as DataViewer for reverse image search of video thumbnails (which allows for detection of old videos) and geolocation. Because view, reaction, and comment statistics can be deleted or modified by the author at any time, it is crucial to capture them by smoothly scrolling through the interaction section during the screen recording. They can also be demonstrated using external tools such as SocialBlade (if they haven&#8217;t been deleted by then). You should also prepare a written transcript of the dialogue in case of technical problems in the courtroom.</p>



<p id="ember3492">Securing and verifying evidence from live streams and disappearing content (such as Instagram Stories, TikTok Live, or streams on Twitch and Kick) requires instant, real-time data capture. For live streams, it&#8217;s crucial to simultaneously record the raw stream using command-line tools (e.g., yt-dlp, which will automatically save the recording to disk in real time) and full screen recording (e.g., in OBS Studio) along with dynamic chat. If broadcasts on Twitch and Kick haven&#8217;t been deleted, the platforms provide tools for creating clips during the broadcast or from the live stream recording. For time-sensitive content, immediate screen recording with system audio or using mobile certification apps (e.g., TrueScreen ) is the priority, which generate evidence with a qualified timestamp that prevents editing. To ensure the integrity of the chain of custody, secured files must be immediately provided with a SHA-256 checksum (a sequence of numbers and letters that serves as a &#8220;<strong>cryptographic fingerprint</strong>&#8221; of a file or document) and the technical parameters of the recording must be precisely described in the protocol, including full URLs and UTC time zones. <strong>Due to frequent changes in usernames and pseudonyms, the author&#8217;s identity is determined by extracting persistent, unique network identifiers from the source code</strong> (such as TikTok &#8216;s authorId), as well as by analyzing voice, facial, and background characteristics. Identifying the exact publication time of disappearing materials requires finding UNIX timestamps in the browser cache or mathematically reconstructing the time by comparing the relative application time (e.g., &#8220;3 hours ago&#8221;) with the certified atomic time (e.g., from the <a href="http://time.is/">time.is</a> website) visible in the recording. Finally, because reach statistics and interaction sections can be deleted at any time, and the publicly invisible view counts of the story prevent direct measurement, it is crucial to capture peak moments of viewership, public reactions and shares by smoothly scrolling the screen or exporting the chat database to structured text files with precise timestamps for each comment.</p>



<h2 class="wp-block-heading" id="ember3493">Metadata and computer forensics</h2>



<p id="ember3494">Metadata, or &#8220;data about data,&#8221; is structured, precisely defined, and uniformly named information used to describe, identify, organize, and access a specific object, digital resource, or research dataset. It operates based on sets of information units arranged in a structure with definitions and usage rules. Institutions can create these themselves or adopt ready-made standards developed by internationally recognized organizations such as ISO, ANSI, RDA, OpenAire, or Metadata 2020. Within this framework, three main types of metadata are distinguished: descriptive metadata, which provides information necessary to identify or locate a resource (e.g., title, author, keywords, production technique, or history of the object). Structural metadata, which describes relationships and dependencies between collection elements to facilitate navigation. Administrative metadata, on the other hand, assists in resource management (e.g., storage location or insurance premium). Administrative metadata also includes technical metadata, typically created automatically in files such as EXIF (containing, for example, creation date, file type, and resolution), intellectual property rights management metadata, and preservation metadata necessary for archiving and maintaining the resource. From the user&#8217;s perspective, consistent application of the schema according to the instructions is crucial, as complete metadata provides information about the structure and limitations of the data, explains its meaning, indicates how to cite it, and is a necessary condition for its understanding and reuse. Digital forensics plays a significant role in analyzing metadata and using it as evidence in proceedings. The process of data analysis in computer forensics is based on methodologies focused on identifying, securing, examining, and presenting digital traces in a manner acceptable to law enforcement. In the context of digital forensics, raw content (e.g., document text, an image in a screenshot) constitutes only the surface layer of evidence. Its full value is achieved only by combining this layer with deep analysis, encompassing metadata, system logs, file change history, user identifiers, as well as location, server, and analytical data. Defining the individual components of the data layer is crucial; in practice, they constitute the essence of computer forensics. The first and most common group are timestamps, precisely defined chronological reference points automatically generated by operating systems or applications, recording the date and time of a specific event. This most often occurs in the form of so-called MAC attributes, documenting the moment of creation, content modification, and last file opening (Access). Their direct extension are system logs, called event logs. They take the form of automatically created, chronological text files or databases. They contain all critical activities, process errors, and correct or incorrect user login attempts recorded by the operating system and running programs. These logs are inextricably linked to the file change history, a sequence of digital traces illustrating the entire evolution and modifications to which a given resource has been subjected throughout its lifecycle. This history reveals sequences of overwriting, deletion, or addition of data sections, allowing for the reconstruction of the original file content before editing. To assign these operations to a specific entity, digital experts forensics examine user identifiers, which are unique alphanumeric, numeric, or address strings permanently assigned to a specific account in a system, corporate network, or online platform. These identifiers are used for authorization and are automatically associated with every action performed by a given profile. Location data (geolocation) provides additional physical and geographical context. This information identifies the physical geographic location of a device based on raw GPS coordinates, cellular base station (BTS) identifiers, or Wi-Fi MAC addresses. These data are often automatically embedded in the structure of multimedia files. All these operations are embedded in the network architecture, recorded by server data, including HTTP server Access Logs and DNS records, which record the client&#8217;s IP address, the exact date of the request, the HTTP method, the URL, and the User-Agent string identifying the user&#8217;s browser type and operating system. The final link in this structure is analytical data generated by external tracking systems and scripts (e.g., Google Analytics, Meta Pixel), which aggregate the behavior of thousands of unique users online, measuring parameters such as the number of unique users, page views, click-through rates, etc. Only such a comprehensive approach to these seven technical components allows computer forensics to go beyond the layer of raw, visual description of data and reach its digital foundation.</p>



<p id="ember3495">In civil and commercial cases, where key evidence consists of digital traces, statistical reports, or screenshots, expert witness testimony becomes a key instrument for fact-checking. The main advantage of engaging an expert witness is that it gives the collected network traces substantive, indisputable probative value. Pursuant to Article 278 § 1 of the Code of Civil Procedure, expert witness testimony is conducted when the assessment of a specific issue requires specialized knowledge, beyond the knowledge of an average person. This procedure is formally initiated by filing an application meeting the requirements of a procedural document (Article 126 of the Code of Civil Procedure), in which the party identifies the facts to be ascertained and specifies the expert&#8217;s desired specialization. After hearing the parties&#8217; submissions, the court issues a decision on the admission of evidence, appointing an expert from the list of the president of the district court or appointing an ad hoc expert, formulating an evidentiary thesis, and setting a deadline for preparing the expert&#8217;s opinion. After receiving the decision and possibly reviewing the case files or the subject of the inspection, the expert, acting under penalty of perjury and pursuant to an oath, begins research activities, culminating in the preparation of a reasoned opinion in writing or its oral presentation in the transcript. In civil and commercial proceedings, expert opinions in this field are most often used in cases involving the verification of digital evidence provided by the parties – its authenticity and the content thereof.</p>



<p id="ember3496">Screenshots are defined as a specific recording of the current image displayed on a computer monitor, tablet, smartphone, or other device equipped with a display. In essence, they constitute a type of digital &#8220;photograph&#8221; or &#8220;still&#8221; that permanently captures and depicts the content currently being generated on the screen. Under Polish civil procedure and the case law of common courts and the Supreme Court, printouts and files containing screenshots have the status of evidence in the case. In court practice, a screenshot is most often classified as private document evidence (constituting an information carrier enabling review of its content and confirming the submitter&#8217;s assertion of specific circumstances) or as other evidence within the meaning of Article 309 of the Code of Civil Procedure. Screenshots are widely used, among others, in family matters (documenting parents&#8217; conversations), consumer matters (shop offers, prohibited clauses in regulations), copyright infringements (use of a protected photo) or disputes over the infringement of reputation and personal rights on social networking sites, forums and blogs.</p>



<p id="ember3497">The main limitation of this evidence is that it is subject to the principle of limited confidence due to its susceptibility to simple and arbitrary interference. Parties to the proceedings frequently challenge the authenticity of screenshots, alleging that they can be easily modified, are incomplete, taken out of context, or have partially removed content. The mere submission of a single screenshot does not determine the veracity of the facts, and this evidence only demonstrates that a computer recording of specific content existed at the time the recording or printout was made. The Court of Appeal in Warsaw (ref. no. I ACa 2111/15) explicitly stated that the potential ease of modification does not deprive a screenshot of its evidentiary value; however, it requires the court to conduct a thorough analysis. The Court of Appeal in Kraków adopted a similar approach in judgment I ACa 315/16. An additional limitation is the legality of the source of their acquisition, as malicious actions or hacking into the application in order to perform a dump may result in criminal liability for violating the secrecy of correspondence and result in the rejection of evidence by the court.</p>



<p id="ember3498">To increase the credibility of screenshots and protect against allegations of manipulation, additional archiving or procedural measures are necessary. The evidentiary value of a screenshot can be enhanced by securing the page in digital form (saving it on a hard drive or in the cloud) or by preparing a proper protocol by a notary, who will personally confirm the credibility and existence of the content. Furthermore, it is crucial that the screenshot is accompanied by other electronic documents and objective verification data. From a procedural perspective, the evidentiary value of screenshots varies progressively depending on their degree of IT integration, with the screenshot itself, devoid of additional elements, having the lowest probative value. In such cases, it merely constitutes a private document demonstrating that a computer recording of specific content existed at a given moment. However, due to the widespread and easy possibility of graphic modification, it is most susceptible to challenge by the opposing party. A screenshot presented with an analytical report has slightly higher and more objective value. It constitutes enhanced evidence, in which the raw image is supplemented with external system data, allowing for a precise demonstration in court of the scale, dynamics, and situational context of the digital tort being analyzed. The probative value of the screenshot with metadata option is low to medium, as submitting the original, source image file only allows for the identification of the device and recording time. The raw metadata of the image file only documents the moment the image itself was created. The highest probative value, fully accepted and sanctioned by, among others, the case law of the Court of Justice of the European Union, is characterized by a screenshot combined with a parallel website archive. Combining screenshots with information from independent internet archives, which store copies of the historical code of websites and record any changes made to it, undoubtedly confirms that specific content, statements or graphic materials were actually published on a specific date, while the potential technical possibility of subsequent modification of the website by its author does not invalidate the probative value of such a package, as external data from digital archives effectively verifies and confirms the full authenticity of the submitted screenshot.</p>



<h2 class="wp-block-heading" id="ember3499">Documenting the course of events on the internet – a timeline as reconstructive evidence</h2>



<p id="ember3500">Digital events that are procedurally significant, such as the publication of a defamatory post, the launch of an advertising campaign that violates personal rights or the principles of fair competition, are rarely one-off and momentary phenomena. In fact, they constitute processes spread over time, composed of successive stages, each of which leaves a separate, identifiable digital trace. A complete reconstruction of these stages in the form of a chronological timeline evidence) performs a function similar to that of a protocol recording the course of events in real time, the integration of which requires specialist knowledge and methodology.</p>



<h2 class="wp-block-heading" id="ember3501">Time reconstruction model</h2>



<h3 class="wp-block-heading" id="ember3502">1. Content publishing – moment zero</h3>



<p id="ember3503">This is the starting point of the entire timeline. Reconstructing moment zero requires determining the exact date and time of the first publication, with at least minute accuracy (via a timestamp in the platform&#8217;s metadata, HTTP headers of the server response, or the WARC archive from the first dump); the URL at which the content was available, including the permalink or canonical URL, which identifies the content regardless of subsequent address changes; the identity of the author or account from which the publication was made (e.g., through the user ID in the page&#8217;s source code, domain WHOIS data, email headers notifying about a new entry); and the original content in its entirety, before any subsequent edits (the source could be the first WARC or MHTML archive, a copy from the Google Cache, or a record in the Wayback Machine).</p>



<p id="ember3504">The start of an advertising campaign – equivalent to the moment the content is published. It has particular evidentiary significance in cases involving acts of unfair competition. The reconstruction of this layer is based, among other things, on data from the Meta Ad Library.</p>



<h3 class="wp-block-heading" id="ember3505">2. First shares and initial reach</h3>



<p id="ember3506">This layer reconstructs the mechanism by which content first spread beyond the original publication. This is key evidence for demonstrating that the violation has spread beyond the author&#8217;s immediate followers and has become public. Data for this layer&#8217;s reconstruction comes from publicly available sharing data (e.g., retweets on X) or through media monitoring tools. The reconstruction report should present this layer as a map of the initial distribution nodes, using a graph or table indicating which platforms and when the content reached within the first 24-48 hours of publication.</p>



<h3 class="wp-block-heading" id="ember3507">3. Increase in the number of interactions</h3>



<p id="ember3508">This layer documents the acceleration of the phenomenon, meaning the moment the content ceased to be a niche post and began to generate significant user engagement. Its reconstruction is crucial for demonstrating that the violation was not a marginal event. Data needed to establish this includes a daily or hourly chart of the increase in the number of likes, comments, shares, and views obtained by exporting data from the platform&#8217;s dashboard or analytical tools; identification of the moment the content exceeded virality thresholds ; and data on the engagement of high-reach accounts that shared the content, which provides evidence that the plaintiff&#8217;s damaged reputation reached influential circles.</p>



<h3 class="wp-block-heading" id="ember3509">4. Increased geographic and demographic reach</h3>



<p id="ember3510">This layer documents the territorial and demographic extension of the publication&#8217;s impact, which may be important both for assessing the scale of damage and for establishing jurisdiction in cross-border cases, e.g., <strong>by determining the place where the damage was caused under the Brussels Ia Regulation</strong>. This data is obtained from geolocation reports of some platforms, showing the countries and regions from which users came, as well as the demographic data of the recipients (gender and age indicated when creating an account).</p>



<h3 class="wp-block-heading" id="ember3511">5. User reactions and sentiment</h3>



<p id="ember3512">This layer documents the qualitative dimension of the publication, i.e., how recipients reacted to the published content, which can, for example, be the basis for demonstrating that the infringement actually harmed the plaintiff&#8217;s reputation and did not go unnoticed. Reconstruction of this layer includes, among other things, a sentiment analysis of comments and mentions from social media monitoring tools, indicating the percentage distribution of positive, neutral, and negative reactions towards the plaintiff or company during the period under review; and the provision of representative quotes from the comments, e.g., in the form of screenshots. In the reconstruction report, this layer should be presented with methodological caution, as sentiment analysis generated automatically by monitoring tools is not always fully reliable and should be verified by an expert or accompanied by information about the algorithm&#8217;s margin of error.</p>



<h3 class="wp-block-heading" id="ember3513">6. Business implications</h3>



<p id="ember3514">This is the final layer of the timeline and is the most important for demonstrating pecuniary or non-pecuniary damage within the meaning of Article 361 of the Civil Code. It documents the measurable consequences of the infringement on the plaintiff&#8217;s business. Evidence in this layer may include data showing a decline in organic traffic on the plaintiff&#8217;s website in correlation with the escalation of the infringement (daily session chart, bounce rate, average session time before and after the infringement); data from the plaintiff&#8217;s CRM or ERP system documenting a decline in the number of quotations; data from e-commerce platforms, e.g., Allegro, Amazon, showing changes in sales volume or the number of views of the plaintiff&#8217;s offers; documentation of costs incurred in managing the reputational crisis, e.g., invoices from PR agencies, costs of remedial advertising campaigns, legal costs in the pre-litigation phase; and reports from industry media or specialized market monitoring services that noted the infringement and its effects.</p>



<h2 class="wp-block-heading" id="ember3515">Reconstruction report form</h2>



<p id="ember3516">The reconstruction report should be a PDF document with a qualified electronic signature and a certified time stamp. Its structure should include a title page with the file reference number, date of preparation, and author information; a chronological timeline in graphical form with key points for each layer; an event and evidence correlation table linking each event on the timeline to the source file reference number in the digital evidence folder; and a narrative description of each layer with references to specific file reference numbers and folder page numbers.</p>



<p id="ember3517">Such a report, incorporated into a digital file, becomes a key orientation document for the court and allows for understanding the entire evidence without having to independently review hundreds of source files, constituting the procedural equivalent of the dispute plan used in English and American proceedings.</p>



<h2 class="wp-block-heading" id="ember3518">Description of evidence</h2>



<p id="ember3519">The description of digital evidence in a lawsuit or a procedural document containing an evidentiary motion serves a much broader purpose than traditional evidence labeling. Digital evidence, when included in a multi-gigabyte digital evidence file, requires a description that allows the court to understand its technical nature, origin, method of acquisition, and relationship to the evidentiary thesis. This description therefore fulfills four distinct procedural functions. The first is the identification function, as it precisely identifies the evidence with a signature, file name, and location within the file, making it uniquely identifiable at every stage of the proceedings, during the hearing, and in the transcript. The second is the verification function, fulfilled by providing the SHA-256 checksum and the date of acquisition, allowing the opposing party and the court to verify whether the submitted file is identical to the one that formed the basis of the claims in the lawsuit. The third is the contextualizing function, a substantive description and an indication of the connection with the factual situation allows the court to understand, already at the stage of reading the claim, what specific fact a given file is used to prove.</p>



<p id="ember3520">The digital evidence description template should be used consistently for each item in the digital evidence index. Below is an example of a professional description template for a text document.</p>



<h2 class="wp-block-heading" id="ember3521">Pattern &#8211; Text Document</h2>



<p id="ember3522">The evidence ID is TD-1/TXT/0001. The file name in the folder is distribution_agreement_2026-01-16.pdf, and the original source file name is Sales Agreement No. 12/2026.pdf. The date the evidence was obtained is June 16, 2026, which is the date the file was included in the digital evidence folder and the checksum was calculated. The source of the evidence is the plaintiff&#8217;s electronic mailbox: a file attached to an email dated January 16, 2026, sent by the defendant from j.kowalski@pozwani.p. The file&#8217;s SHA-256 checksum is a3f1d8&#8230;9b2c (the full string in file TD-1/MET/0001 of the digital folder).</p>



<p id="ember3523">The technical description indicates that the evidence is an 842 KB PDF/A-1b file with a searchable text layer. The file does not contain active scripting or embedded multimedia. The document&#8217;s metadata identifies the author as Jan Kowalski, the creation date as January 14, 2026, 10:47:22 UTC, and the file was generated using Microsoft Word 2019. The metadata was extracted using exiftool version 12.60 and archived in file TD-1/MET/0001.</p>



<p id="ember3524">The substantive description indicates that the file contains an agreement signed by both parties for the exclusive distribution of the plaintiff&#8217;s products in the Masovian Voivodeship, concluded for a period of three years from March 15, 2022. Paragraph 7 of the agreement prohibits the defendant from conducting parallel distribution of products competing with the plaintiff&#8217;s product range. Paragraph 12 specifies contractual penalties for violating this prohibition at PLN 50,000 for each identified violation.</p>



<p id="ember3525">The evidentiary thesis for this evidence is: the fact that the parties concluded distribution agreement No. 12/2026 on 16 January 2026, the content of the defendant’s obligation to provide exclusive distribution and prohibit the distribution of competitive products, the amount of the stipulated contractual penalties, as well as the fact that the defendant submitted a declaration of intent with the content corresponding to paragraph 7 of this agreement, which demonstrates his full awareness of the limitations imposed on him.</p>



<p id="ember3526">The connection with the factual circumstances lies in the fact that this evidence constitutes the primary source of the legal relationship between the parties. A finding of violation of the prohibition by the defendant, documented by further evidence from section TD-2 of the file, is possible only by reference to the content of the contractual obligation arising from this document.</p>



<figure class="wp-block-image"><img decoding="async" src="https://media.licdn.com/dms/image/v2/D4D12AQGe014loHWlLg/article-inline_image-shrink_1500_2232/B4DZ8ibmXzK8AU-/0/1782989088478?e=1784764800&amp;v=beta&amp;t=CSsXExMl-dgbgKxqP7ZECjbwVGI7kWVhMEpTtrJGnMY" alt="Article content"/><figcaption class="wp-element-caption">summary table</figcaption></figure>



<p id="ember3528">A sample summary table for cases involving multiple files, which replaces the separate listing of each piece of evidence in the procedural document. A separate table should be created for the most important pieces of evidence.</p>



<h2 class="wp-block-heading" id="ember3529">Final conclusions</h2>



<p id="ember3530">Contemporary commercial disputes unfold in two parallel realities. The first is the traditional, paper-based reality, well-known to civil litigation theory and practice, which is gradually losing its significance. The second is the digital, networked reality, generating billions of electronic traces daily and becoming the dominant environment in which contracts are concluded, negotiations are conducted, marketing campaigns are launched, infringements are committed, and damages are inflicted. The paradox is that procedural law, which is formally prepared for this change, for example, thanks to an open catalog of evidence and the technologically neutral definition of a document in Article 77³ of the Civil Code. However, in court practice, it is still often applied through the prism of categories developed for the paper-based reality. The main thesis of this article is simple and yet practically significant: evidence in 21st-century commercial cases cannot be limited solely to traditional paper documents, because the facts crucial to resolving a dispute increasingly do not exist in paper form at all. A contract concluded through an exchange of messages on corporate messaging, a violation of a non-compete clause documented in system logs – none of these events leave a paper trail. They exist solely as digital data, and their occurrence, content, and effects must be proven using appropriate methods and tools.</p>



<p id="ember3531">The online activity of businesses, as well as their contractors, competitors, and customers, leaves a vast amount of digital traces that are susceptible to analysis. As demonstrated in the individual chapters of this article, these traces include not only obvious electronic documents such as text files and emails, but also metadata and analytical data from social media platforms. The key to the effectiveness of this evidence, however, is its proper preparation, security, and presentation. A raw screenshot devoid of metadata and an online archive has minimal evidentiary value and is easily challenged. The same screenshot, provided with a qualified timestamp, supported by a parallel archive, supplemented by an analytical report documenting reach and sentiment, and integrated with a timeline reconstructing the course of events, becomes highly persuasive evidence, difficult to refute even with an active defense by the opposing party.</p>



<h2 class="wp-block-heading" id="ember3532">Digital evidence folder as a system tool</h2>



<p id="ember3533">The concept of a digital evidence folder, proposed in this article as an adaptation of the Anglo-Saxon electronic institution trial Bundle, a Polish civil procedure tool, addresses a fundamental procedural challenge: how to present tens or hundreds of gigabytes of electronic data to the court in a way that is understandable, verifiable, and procedurally efficient. A bundle is not a new piece of evidence, but an organizational tool that organizes existing evidence according to the logic of evidentiary thesis, assigns each file a unique reference number, links evidence to facts, ensures the integrity of the file, and enables immediate retrieval of each piece of evidence during the hearing via an interactive table of contents with hyperlinks. A properly prepared digital evidence bundle is one of the most effective tools for presenting evidence in court. First, it forces the attorney to select and prioritize the material before filing a procedural document, eliminating chaotic and overwhelming collections of unselected files. Secondly, it makes the evidence transparent for the opposing party and the court, because each piece of evidence is described, classified and linked to a specific thesis, which eliminates the objection of ambiguity and facilitates an effective defense or procedural attack.</p>



<h2 class="wp-block-heading" id="ember3534">Postulates de lege ferenda</h2>



<p id="ember3535">The analysis conducted in this article reveals significant regulatory gaps, the filling of which would significantly improve the effectiveness of evidence in cases involving digital materials. These proposals are both legislative and quasi-legislative in nature, involving standardization through case law and court rules.</p>



<p id="ember3536">The first and most important proposal is to introduce a legal definition of digital evidence into the Code of Civil Procedure. While the lack of such a definition does not prevent the taking of electronic evidence, it generates terminological uncertainty in case law and doctrine, leading to inconsistent assessment of the evidentiary value of the same categories of materials by different adjudicating panels. The definition should encompass all information recorded in the form of digital data, of value to ongoing proceedings, stored, downloaded, or transmitted via an electronic device.</p>



<p id="ember3537">The second postulate is the introduction of the English Practice Rules into the court regulations. The e- bundle guidelines should standardize the presentation of electronic evidence in cases where it exceeds a certain volume or number of files. Such regulations should mandatorily require: a uniform file identification system, a table of contents in PDF format with hyperlinks, and the provision of identical copies of the medium to the court and the opposing party no later than a specified number of days before the hearing. This solution, implemented without amending the law through orders of court presidents or guidelines from the Minister of Justice, would immediately improve the evidentiary culture in proceedings involving mass digital evidence.</p>



<h2 class="wp-block-heading" id="ember3538">Sources:</h2>



<p id="ember3539">Tacij Przemysław, Digital content and uncertified copies as evidence in civil proceedings</p>



<p id="ember3540">Lewulis Piotr, Social Media as a Source of Evidence in Civil Cases: Results of a Preliminary Survey Among Attorneys and Legal Counselors</p>



<p id="ember3541">Rafał Prabucki, Metadata related to a document and evidentiary proceedings in a civil trial</p>



<p id="ember3542">Wręczycka Katarzyna, Electronic evidence in civil proceedings</p>



<p id="ember3543">Nowak Mariusz, Types of electronic evidence in civil proceedings</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-evidence-bundle-as-a-modern-means-of-organizing-evidence/">Digital evidence bundle as a modern means of organizing evidence</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/digital-evidence-bundle-as-a-modern-means-of-organizing-evidence/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 17:54:28 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[3D Scanning]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI in Defence]]></category>
		<category><![CDATA[Armed Forces]]></category>
		<category><![CDATA[Arms Trade]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[ASAP]]></category>
		<category><![CDATA[B2B]]></category>
		<category><![CDATA[B2G]]></category>
		<category><![CDATA[Civil Defence]]></category>
		<category><![CDATA[Classified Information]]></category>
		<category><![CDATA[Crisis Preparedness]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Defence Conference]]></category>
		<category><![CDATA[Defence Expo]]></category>
		<category><![CDATA[Defence Industry]]></category>
		<category><![CDATA[Defence IP]]></category>
		<category><![CDATA[Defence Procurement]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Defense Expo]]></category>
		<category><![CDATA[Defense Industry]]></category>
		<category><![CDATA[Defense Tech]]></category>
		<category><![CDATA[Drones]]></category>
		<category><![CDATA[Dual Use Technology]]></category>
		<category><![CDATA[EDF]]></category>
		<category><![CDATA[Emergency Preparedness]]></category>
		<category><![CDATA[European Defence Fund]]></category>
		<category><![CDATA[EXPO XXI]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[Firearms Law]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[Infrastructure Protection]]></category>
		<category><![CDATA[Intellectual Property]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[Law Firm]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[Military Innovation]]></category>
		<category><![CDATA[Military Modernization]]></category>
		<category><![CDATA[Military Technology]]></category>
		<category><![CDATA[Mini MSPO]]></category>
		<category><![CDATA[MON RP]]></category>
		<category><![CDATA[MSWiA]]></category>
		<category><![CDATA[National Security]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[Personal Protective Equipment]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[Polish Armed Forces]]></category>
		<category><![CDATA[Polish Defence Industry]]></category>
		<category><![CDATA[Public Procurement]]></category>
		<category><![CDATA[Range Safety]]></category>
		<category><![CDATA[Resilience]]></category>
		<category><![CDATA[Security Conference]]></category>
		<category><![CDATA[Shooting Sports]]></category>
		<category><![CDATA[Sport Shooting]]></category>
		<category><![CDATA[State Resilience]]></category>
		<category><![CDATA[Tactical Communications]]></category>
		<category><![CDATA[Territorial Defence]]></category>
		<category><![CDATA[UAV]]></category>
		<category><![CDATA[Unmanned Systems]]></category>
		<category><![CDATA[WARSAW]]></category>
		<category><![CDATA[Warsaw Defence Expo]]></category>
		<category><![CDATA[Warszawa]]></category>
		<category><![CDATA[Warszawskie Targi Obronne]]></category>
		<category><![CDATA[Weapons Permits]]></category>
		<category><![CDATA[WOT]]></category>
		<category><![CDATA[WTO2026]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8803</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 – the first edition of a new nationwide event dedicated to the defence, security and resilience of the state On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-group is-nowrap is-layout-flex wp-container-core-group-is-layout-1 wp-block-group-is-layout-flex">
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>


</div>



<h3 class="wp-block-heading">– the first edition of a new nationwide event dedicated to the defence, security and resilience of the state</h3>



<p id="ember53">On June 19-20, 2026, representatives of our law firm will participate in the Warsaw Defense Trade Fair (WTO 2026), which will be held at the EXPO XXI Exhibition Center in Warsaw. This is the first edition of a completely new trade fair and conference event, created in response to the growing importance of the defense sector, national security, and technologies supporting Poland&#8217;s institutional, economic, and social resilience. The fair is held under the honorary patronage of the Ministry of Interior and Administration and the Minister of National Defense. The event is informally referred to as a &#8220;mini-MSPO in Warsaw&#8221; – a capital city-based, intimate alternative to the September International Defense Industry Fair in Kielce, open not only to professionals but also – on the second day – to the general public.</p>



<span id="more-8803"></span>



<p id="ember54">The goal of the Warsaw Defense Fair is to integrate key groups responsible for national security and to create a space for dialogue, collaboration, and exchange of experiences between public administration, the military, uniformed services, the defense industry, the technology sector, the investor community, and military universities. The event combines exhibition, conference, and networking elements , creating a platform for showcasing modern technologies, exchanging expert knowledge, and building business relationships in one of the fastest-growing sectors of the Polish economy.</p>



<p id="ember55">The trade fair program is divided into two complementary days, representing one of the most distinctive solutions adopted by the organizers. Friday, June 19, 2026, will be an industry day (B2B/B2G), intended exclusively for companies, institutions, and business partners. Industry registration is required. This day will be a platform for meetings and discussions between individuals and entities interested in establishing cooperation in the defense and security sector, including representatives of public administration and local governments, soldiers and uniformed services, representatives of companies in the defense and technology sectors, investors, industry advisors, and representatives of military universities. The program focuses on key challenges facing the defense and national security sectors, including conferences, panel discussions, and business and institutional meetings concerning the development of the Polish defense industry, modernization of the Armed Forces, public procurement in the defense sector, and cross-sectoral cooperation.</p>



<p id="ember56">Saturday, June 20, 2026, will be an open day (B2B/B2G/B2C), also open to the public interested in security, defense, and shooting. The second day significantly complements the industry portion and expands the event to include the general public, as well as educational and outreach communities. It will feature demonstrations of equipment and technologies in near-operational settings, demonstration zones by exhibitors and manufacturers, presentations of solutions in cybersecurity, drones, communications, and critical infrastructure protection, as well as numerous lectures for enthusiasts. Topics covered include firearms licenses – myths and legal realities, training and shooting sports, hearing and eye protection, safety and ergonomics at the shooting range, and civic preparedness for crisis situations.</p>



<h2 class="wp-block-heading" id="ember57">Exhibitors and thematic scope</h2>



<p id="ember58">Over 100 exhibitors will be present at the fair, representing a full cross-section of entities active in the Polish defense and security sector. Exhibitors include military units such as the 1st Warsaw Armored Brigade and the 18th Capital Territorial Defense Brigade, international technology companies, including 3M Poland, which presents personal protection solutions for the defense sector, and Artec 3D with 3D scanners used in military applications. The shooting and equipment segment will be strongly represented, with companies such as House of Guns , Hubertus Pro Hunting , Kaliber, 4HUNTING, Kolba, 4SHOOTER, Son of Gun , Jammas , and Wolfer. Group and Works11. The event is also partnered by the Legia Warsaw Central Military Sports Club – Shooting Section.</p>



<p id="ember59">The exhibition covers cutting-edge weapons, equipment, facilities and technologies used in the defense and security sector: unmanned systems and drones, cybersecurity solutions, tactical communications and communication technologies, critical infrastructure protection, personal protective equipment, 3D scanning and simulation technologies, individual soldier equipment, as well as solutions in the area of civil defense and population protection.</p>



<h2 class="wp-block-heading" id="ember60">Three conference stages and a substantive agenda</h2>



<p id="ember61">The WTO 2026 program will unfold simultaneously across three conference stages. The industry day will be dedicated to the most important strategic challenges facing the defense sector – the technical modernization of the Polish Armed Forces, the development of the domestic arms industry, cooperation with foreign partners, public procurement in the defense sector, new dual-use technologies , and the role of the private sector in building national resilience. The second day, open to the public, will feature lectures and discussions covering a much broader range of topics – from legal issues concerning access to weapons and individual security, through shooting sports and defense training, to preparing society for crisis situations and disseminating knowledge about modern defense technologies.</p>



<p id="ember62">The significance of the event from a legal perspective</p>



<p id="ember63">The establishment of the Warsaw Defense Fair is part of the broader context of the dynamic development of the Polish defense sector, which in recent years has become one of the most important areas of public and private investment, generating significant demand for legal services. From the firm&#8217;s perspective, issues related to public procurement in the defense sector, regulations regarding trade in arms and dual-use technologies, export controls, protection of classified information, cybersecurity in the context of the NIS2 directive, intellectual property rights in defense technology projects, and financing of projects from European funds (including the European Defense Fund and ASAP), as well as the development of regulations regarding artificial intelligence in military applications in light of the European AI Act . The participation of representatives of the KG LEGAL KIEŁTYKA GŁADKOWSKI law firm in this event is a natural element of tracking the development of one of the fastest-growing sectors of the Polish economy and building competences in the area of law related to new defense technologies.</p>



<p id="ember64">The Warsaw Defense Fair 2026 demonstrates that security and defense are no longer the exclusive domain of the military and state administration. They have become an area of broad cross-sectoral cooperation, with technology companies, investors, academia, non-governmental organizations, and informed citizens playing key roles. The development of this sector today requires not only advanced technological competencies but also an appropriate legal, regulatory, and institutional environment.</p>



<p id="ember65">Link to the event: <a href="https://wto26.exposupport.pl/program">https://wto26.exposupport.pl/program</a></p>



<p id="ember66">#WarsawDefenceExpo #WTO2026 #WarszawskieTargiObronne #DefenceIndustry #DefenseIndustry #DefenceExpo #DefenseExpo #PolishDefenceIndustry #PolishArmedForces #NationalSecurity #StateResilience #CivilDefence #HomelandSecurity #DefenceTechnology #DefenseTech #MilitaryTechnology #MilitaryInnovation #DualUseTechnology #DefenceProcurement #PublicProcurement #ArmsTrade #ExportControl #ClassifiedInformation #CyberSecurity #NIS2 #CriticalInfrastructure #InfrastructureProtection #UnmannedSystems #Drones #UAV #TacticalCommunications #PersonalProtectiveEquipment #3DScanning #AIinDefence #AIAct #ArtificialIntelligence #EuropeanDefenceFund #EDF #ASAP #IntellectualProperty #DefenceIP #TerritorialDefence #WOT #ArmedForces #MilitaryModernization #SportShooting #FirearmsLaw #WeaponsPermits #ShootingSports #RangeSafety #CrisisPreparedness #EmergencyPreparedness #Resilience #B2B #B2G #EXPOXXI #Warsaw #Warszawa #Poland #MONRP #MSWiA #MiniMSPO #DefenceConference #SecurityConference #LegalTech #LawFirm #KGLegal #KieltykaGladkowski</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/">Representatives of our law firm KG LEGAL KIEŁTYKA GŁADKOWSKI will take part in the Warsaw Defence Fair 2026</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/representatives-of-our-law-firm-kg-legal-kieltyka-gladkowski-will-take-part-in-the-warsaw-defence-fair-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CHIPS AND DIGITALIZATION</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/chips-and-digitalization/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/chips-and-digitalization/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 16 Feb 2026 19:17:58 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CHIPS AND DIGITALIZATION]]></category>
		<category><![CDATA[Digital Europe]]></category>
		<category><![CDATA[Large-scale calculations]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8635</guid>

					<description><![CDATA[<p>Publication date: February 12, 2026 The EU Chips Act is a major European legislative package launched to boost the EU&#8217;s semiconductor industry, aiming to double its global market share to 20% by 2030, enhance supply chain resilience, and reduce reliance on external chipmakers. The EU Chips Act 2.0 is a proposed follow-up to the 2023 [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/chips-and-digitalization/">CHIPS AND DIGITALIZATION</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: February 12, 2026</mark></strong></p>



<p>The EU Chips Act is a major European legislative package launched to boost the EU&#8217;s semiconductor industry, aiming to double its global market share to 20% by 2030, enhance supply chain resilience, and reduce reliance on external chipmakers. The EU Chips Act 2.0 is a proposed follow-up to the 2023 Chips Act, driven by a coalition of EU member states (including Germany, France, Netherlands) in late 2025 to shift from crisis management to long-term industrial strategy. It aims to secure supply chains, boost competitiveness, and accelerate investment by simplifying regulations and targeting R&amp;D.</p>



<span id="more-8635"></span>



<h2 class="wp-block-heading">Digital Europe</h2>



<p><strong>Program Digital Europe</strong> is an integral part of the Multiannual Financial Framework 2021-2027, representing the European Commission&#8217;s response to the challenges of the digital transformation in the EU. It is a key financial instrument for building digital policy capacity, as recommended by the European Council. The programme builds on and complements existing investment initiatives. The Programme&#8217;s main objective is to support the digital transformation of the European economy and society and ensure that it benefits EU citizens and businesses, to support and accelerate the digital transformation of the European economy, industry and society, to deliver benefits to citizens, public administrations, and businesses across Europe, and to contribute to a competitive Europe within Europe. The general objective is further specified in five specific objectives in Regulation (EU) 2021/694 of the European Parliament and of the Council:</p>



<h2 class="wp-block-heading">Large-scale calculations:</h2>



<p>&#8211; Implementation, coordination, and operation at EU level of an integrated, demand-driven, high-performance computing and data infrastructure aligned with global standards. This infrastructure will be easily accessible to both public and private users, with a particular focus on small and medium-sized enterprises (SMEs), regardless of the Member State in which users are located. It will also be available for scientific research purposes, in accordance with Regulation (EU) 2018/1488.</p>



<p>&#8211; Deployment of operational technology emerging from research and innovation, to create an integrated EU high-performance computing (HPC) ecosystem. This ecosystem will encompass various aspects of the scientific and industrial value chain, including hardware, software, applications, services, interactions, and digital skills, while ensuring a high level of security and data protection.</p>



<p>&#8211; Implementation and operation of a computing infrastructure that will exceed exascale capabilities, including integration with quantum computing technologies and research infrastructures, supporting the development of the necessary hardware and software at EU level.</p>



<p>These activities will be implemented mainly through the European High Performance Computing Joint Undertaking, established under Council Regulation (EU) 2018/1488.</p>



<h2 class="wp-block-heading">Artificial Intelligence:</h2>



<p>&#8211; Strengthening key AI capabilities and knowledge in the EU, including the development of high-quality data resources, exchange mechanisms, and algorithm libraries. All this should be implemented with a human-centric and inclusive approach, consistent with the Union&#8217;s values.</p>



<p>&#8211; These capabilities must be accessible to companies, especially small and medium-sized enterprises (SMEs), start-ups, civil society organizations, research institutions and universities, and public administrations. The goal is to maximize their benefits for European society and the economy.</p>



<p>&#8211; Strengthening and integrating AI testing and experimentation networks across Member States.</p>



<p>&#8211; Developing and promoting commercial applications and production systems that facilitate the integration of technologies across value chains, fostering innovative business models and shortening the time needed to transition from innovation to commercial use. It is also important to promote AI-based solutions in areas crucial to society.</p>



<p>&#8211; Data based on AI must respect privacy and security principles from the design stage and fully comply with applicable data protection law.</p>



<h2 class="wp-block-heading">Cybersecurity and Trust:</h2>



<p>&#8211; Supporting the development and procurement of advanced cybersecurity equipment, tools and data infrastructure, in cooperation with Member States, to achieve a high level of cybersecurity at European level, in compliance with data protection rules and fundamental rights, and ensuring the strategic autonomy of the Union.</p>



<p>&#8211; Supporting the accumulation and optimal use of knowledge, capabilities and skills in the field of cybersecurity in Europe, as well as sharing and popularising best practices.</p>



<p>&#8211; Ensuring the widespread implementation of modern, effective cybersecurity solutions in the European economy, paying particular attention to public institutions and small and medium-sized enterprises (SMEs).</p>



<p>&#8211; Increasing the capacity of Member States and the private sector to help them comply with Directive (EU) 2016/1148 of the European Parliament and of the Council, including by supporting the uptake of best practices in cybersecurity.</p>



<p>&#8211; Improving resilience to cyberattacks and increasing risk awareness and knowledge of cybersecurity processes, as well as supporting public and private organizations in achieving basic levels of cybersecurity, for example by introducing full encryption of data transmission and regular software updates.</p>
<p>&#8211; Intensifying cooperation between the civilian and defense sectors on dual-use cybersecurity projects, services, competencies, and applications, in line with the Regulation establishing the European Cybersecurity Industrial, Technology, and Research Competence Centre and the National Coordination Network.</p>



<h2 class="wp-block-heading">Advanced digital skills:</h2>



<p>&#8211; Supporting the creation and implementation of high-quality long-term training and courses, including residential education, aimed at both students and the professionally active population,</p>



<p>&#8211; Supporting the creation and implementation of high-quality short-term training and courses for people working, especially in small and medium-sized enterprises and the public sector.</p>



<p>&#8211; Supporting high-quality on-the-job training and internship programs for students, including internships, and for the working population, particularly in SMEs and the public sector.</p>



<p>These activities are implemented primarily through direct management.</p>



<h2 class="wp-block-heading">Implementation and optimal use of digital capabilities and interoperability:</h2>



<p>&#8211; Support for the public sector and areas of public interest, such as healthcare, education, justice, customs, transport, mobility, energy, environment, and culture and creative industries. This support involves the effective implementation of modern digital technologies, such as high-performance computing (HPC), artificial intelligence (AI), and cybersecurity, as well as facilitating access to these technologies.</p>



<p>&#8211; Implementation, operation and maintenance of a modern trans-European interoperable digital service infrastructure throughout the Union, with an emphasis on complementarity with national and regional actions.</p>



<p>&#8211; Supporting the integration and use of trans-European digital service infrastructures and agreed European digital standards in the public sector and public interest areas, with the aim to facilitate cost-effective implementation and interoperability.</p>



<p>&#8211; Facilitating the development and modernisation of solutions and structures by public administrations, businesses and citizens, including open source and the reuse of interoperable solutions.</p>



<p>&#8211; Ensuring the public sector and EU industry, in particular small and medium-sized enterprises (SMEs), easy access to testing and piloting digital technologies and increasing their use, including across borders.</p>



<p>&#8211; Supporting the public sector and EU industry, in particular SMEs and start-ups, in adopting modern digital technologies such as HPC, AI, cybersecurity, and innovative technologies such as distributed ledger technologies (e.g., blockchain).</p>



<p>&#8211; Supporting the design, testing, implementation, and maintenance of interoperable digital solutions, including digital government, for public services at EU level. These services will be delivered through reusable, data-driven platforms to foster innovation and create a common framework that unleashes the full potential of public government services for citizens and businesses.</p>



<p>&#8211; Ensuring the EU&#8217;s continued capacity to lead digital developments, monitoring and analysing rapidly evolving digital trends, and promoting the exchange and dissemination of best practices.</p>



<p>&#8211; Fostering cooperation to create a European ecosystem of trusted infrastructure for data exchange and digital services and applications based on distributed ledger technologies (such as blockchain). Promoting interoperability and standardisation, as well as implementing cross-border solutions within the EU, is key, in line with the principle of security and privacy by design and in compliance with consumer and data protection regulations.<br><br>&#8211; Development and strengthening of European digital innovation hubs and their networks.</p>



<h2 class="wp-block-heading">European Digital Innovation Hubs</h2>



<p>Digital innovation centers are essential for the implementation of the program and their tasks include:</p>



<p>&#8211; Building awareness and providing or ensuring access to expertise, know-how and services in the field of digital transformation, providing testing and experimental facilities.</p>



<h2 class="wp-block-heading">Virtual Chip Design Platform</h2>



<p>In the context of the intended creation of a so-called virtual chip design platform, this regulation provides for measures to develop the European semiconductor ecosystem, which was further strengthened by Regulation (EU) 2023/1781 of 13 September 2023, which amends Regulation 2021/694 and establishes a framework for measures to strengthen the European semiconductor ecosystem, including initiatives related to chip design and manufacturing.</p>



<p>The virtual design platform, supported by the Chips for Europe Initiative, aims to enable the development of large-scale innovative design capabilities for integrated semiconductor technologies available across the European Union. The platform will stimulate broad collaboration between user communities and design companies, start-ups, SMEs, intellectual property and tool providers, designers, and research and technology organizations. It will integrate existing and new design databases with extended EDA libraries and tools. It will promote flexible access models to design tools, especially for prototyping, and common interface standards.</p>



<p>The virtual design platform will be continuously developed and enriched with new technologies and designs, including low-power processors (e.g., based on the RISC-V architecture) and FPGA-based programmable logic devices. Services will be offered in the cloud, increasing the platform&#8217;s accessibility and openness by integrating existing and new design centers across EU Member States. The pilot lines will be equipped with specialized design infrastructure, including models simulating the manufacturing process using tools used for circuit and system design. A user-friendly virtualization of these lines will be created, enabling direct access across Europe via the aforementioned design platform.</p>



<p>These pilot lines will accelerate the development of European intellectual property and skills related to innovation in semiconductor manufacturing technology. These will strengthen Europe&#8217;s position in the context of new devices and materials for the production of advanced semiconductor technology modules, such as lithography and semiconductor wafer technologies. Building a network of competence centers across the EU will provide expertise for small and medium-sized enterprises and start-ups, enabling them to develop skills and access design infrastructure and pilot lines, thus attracting innovation and talent.</p>



<p>To support the Initiative&#8217;s activities, a new legal instrument is needed: the European Chip Infrastructure Consortium (ECIC). This instrument should have legal personality. This means that the ECIC, rather than individual organizations, can apply for funding for the Initiative&#8217;s activities. All applications to the program will be open to various forms of collaboration. The ECIC&#8217;s primary goal is to foster collaboration between research organizations, industry, and Member States.</p>



<p>To achieve the overall goal and address the challenges in the semiconductor market, the initiative should consist of five key elements:</p>



<p>&#8211; A virtual platform accessible throughout the EU should be created to connect design companies with small and medium-sized enterprises, startups, and technology and tool suppliers. The platform should support the development of virtual prototyping technologies.</p>



<p>&#8211; To improve security of supply and reduce dependence on production in third countries, pilot lines should be developed to test and validate semiconductor technologies. Pilot lines should operate at higher technology readiness levels, with minimal environmental impact. EU investment in these lines is essential to reduce existing gaps in innovation and competitiveness.</p>



<p>&#8211; The initiative should support the development of alternative technologies, such as quantum technologies, by investing in quantum chip design libraries and testing centers.</p>



<p>&#8211; To support access to semiconductor technologies and address the skills shortage, competence centers should be established in each Member State. Access to pilot lines and other resources must be open and fair.</p>



<h2 class="wp-block-heading">Grants</h2>



<p>Grants under the Digital Europe Programme can cover up to 100% of eligible costs. They are awarded and managed according to specific specifications that address different objectives.</p>



<p>Award criteria are defined in work programmes and calls for proposals. They take into account the following aspects:</p>



<p>&#8211; the level of maturity of a specific action in the project development phase;</p>



<p>&#8211; the feasibility of the implementation plan;</p>



<p>&#8211; financial barriers, such as a shortage of market financing;</p>



<p>&#8211; the leverage effect of EU support on public and private investment;</p>



<p>&#8211; the expected economic, social, climate, and environmental impact;</p>



<p>&#8211; the availability of appropriate services;</p>



<p>&#8211; a trans-European dimension;</p>



<p>&#8211; a balanced geographical distribution across the Union, including actions to reduce the digital divide between the outermost regions;</p>



<p>&#8211; a long-term plan to ensure the sustainability of operations;</p>



<p>&#8211; the possibility of reusing and adapting project results;</p>



<p>&#8211; compatibility with other EU programmes.</p>



<p>The EU Emissions Trading System (EU ETS) is a mechanism that addresses carbon dioxide emissions from energy-intensive industries and the energy sector. Based on established emission caps and trading, this system is a key tool for the EU in reducing emissions.</p>



<p>The new regulations include:</p>



<p>&#8211; including maritime transport in the emissions trading system; &#8211; accelerating the reduction of available emission allowances and phasing out free allowances in selected sectors; &#8211; introducing a CO₂ offsetting and reduction mechanism for international aviation within the EU ETS; &#8211; increasing funding for the modernization and innovation fund; &#8211; modifying the market stability reserve.</p>



<h2 class="wp-block-heading">REPowerEU plan</h2>



<p>In 2022, the European Commission presented the REPowerEU plan, which lays the foundation for implementing the legislative proposals contained in the Ready for 55 package . The plan aims to reduce the European Union&#8217;s greenhouse gas emissions by at least 55% by 2030, in line with the European Green Deal, to achieve climate neutrality by 2050. The main source of financing for the plan is the Recovery and Resilience Facility , which was established in response to the crisis caused by the COVID-19 pandemic, aiming to temporarily mitigate the socio-economic impact of the situation.</p>



<p>Since the adoption of Regulation (EU) 2021/241 of the European Parliament and of the Council of 12 February 2021, which established the Recovery and Resilience Facility, the geopolitical situation has changed significantly. In response to the difficulties in the global energy market caused by Russia&#8217;s aggression against Ukraine, the European Commission announced the REPowerEU plan in 2022, aimed at rapidly reducing Europe&#8217;s dependence on Russian fossil fuels by 2030 and accelerating the EU&#8217;s energy transition.</p>



<p>Reforms under REPowerEU aim to: &#8211; Facilitate the development of renewable energy sources (RES).</p>



<p>&#8211; Eliminate barriers to the development of RES.</p>



<p>&#8211; Support local energy communities.</p>



<p>&#8211; Accelerate the integration of renewable energy sources into distribution networks.</p>



<p>&#8211; Develop sustainable transport.</p>



<p>&#8211; Develop green skills.</p>



<p>&#8211; Increase energy efficiency.</p>



<h2 class="wp-block-heading">European Chip Act.</h2>



<p>The European Chip Act aims to increase Europe&#8217;s competitiveness and resilience in semiconductor technology. This act will give Europeans the opportunity to strengthen their technological leadership and achieve their digital and ecological transformation goals. Furthermore, the development of the semiconductor industry could create new jobs in regions that were not previously considered technology hubs. The document aims not only to strengthen the semiconductor ecosystem in the European Union but also to ensure the stability of supply chains, reduce external dependencies, and enable a faster response to changing market needs. This is a key step towards the EU&#8217;s technological sovereignty and towards achieving the goal of doubling the global semiconductor market share to 20% by 2030.</p>



<p>The European Semiconductor Council will act as a facilitator in mapping and monitoring the EU semiconductor value chain and preventing crises in this area through appropriate emergency measures.</p>



<p>The European Chips Act focuses on five strategic objectives.</p>



<p>These are:</p>



<p>&#8211; strengthening our leadership in research and technology,</p>



<p>&#8211; developing and strengthening Europe&#8217;s capacity to innovate in the design, production and packaging of advanced chips,</p>



<p>&#8211; establishing the right framework to increase production by 2030,</p>



<p>&#8211; addressing the skills shortage and attracting new talent,</p>



<p>&#8211; increasing knowledge of global semiconductor supply chains.</p>



<h2 class="wp-block-heading">The three pillars of the act.</h2>



<p>To achieve these goals, three key actions are planned:</p>



<p>&#8211; the Chips for Europe initiative, which aims to support technological capacity building and large-scale innovation,</p>



<p>&#8211; the development of a security framework that will support investments in production facilities, ensuring security of supply and the resilience of the EU semiconductor sector,</p>



<p>&#8211; The creation of tools and methods for predicting semiconductor shortages and related crises, as well as the ability to respond to them, aims to ensure supply continuity. Several key elements can be identified in this context:</p>



<p>&#8211; Supply Chain Alerts (SCAN);</p>



<p>&#8211; Crisis Phase and a set of tools that can be used in the event of an emergency.</p>



<p>The European Semiconductor Board (ESB) plays an important role, providing the Commission with advice, support, and recommendations in three key areas: &#8211; Monitoring the situation and responding to crises;</p>



<p>&#8211; Advising on the initiative for the Public Authorities Board of the Chips Joint Undertaking;</p>



<p>&#8211; Consulting the Commission on decisions regarding the granting of IPF and OEF status.</p>



<p>Article 5 of the Act describes in detail the tasks to be implemented.</p>



<p>Operational objective 1 includes: &#8211; creating and managing a virtual design platform, accessible throughout the Union, that would integrate existing and new design functions with extensive libraries and tools for automated electronic design (EDA); &#8211; strengthening design capabilities by supporting innovative solutions such as open processor architectures, chiplets, programmable chips, and modern types of memories and processors – manufactured in accordance with safety-by-design principles; &#8211; expanding the semiconductor ecosystem by integrating vertical market sectors, including health, mobility, energy, telecommunications, security, defense, and space, which will contribute to the implementation of the Union&#8217;s green, digital, and innovation programs.</p>



<p>Under Operational Objective 2: &#8211; strengthening production capacities for next-generation chips and equipment by integrating research and innovation activities and preparing the development of future generations of technologies, including the latest generations of technologies, FD-SOI (fully depleted silicon on an insulator), new semiconductor materials and heterogeneous systems integration; &#8211; supporting large-scale innovation by providing access to new or existing pilot lines, enabling experimentation, testing, process control and validation of new design concepts combining key functions; &#8211; providing support to integrated production facilities and open EU factories by granting preferential access to new pilot lines, as well as fair access to these lines for a wide range of users of the EU semiconductor ecosystem.</p>



<p>Under Operational Objective 3: &#8211; developing innovative design libraries dedicated to quantum chips; &#8211; supporting the development of new and existing pilot lines, clean rooms, and factories for prototyping and manufacturing quantum chips aimed at integrating quantum circuits and control electronics; &#8211; expanding facilities for testing and validating advanced quantum chips to be manufactured in pilot lines to bridge the feedback gap between designers, manufacturers, and users of quantum components.</p>



<p>Under Operational Objective 4: &#8211; strengthening capabilities and making a wide range of expertise available to stakeholders, including startups and small and medium-sized enterprises (SMEs), which are end-users. Facilitating access to these capabilities and facilities and supporting their effective use. Addressing knowledge and skills shortages, as well as skills mismatches, requires strategies to attract, mobilize, and retain new talent in research, design, and production. Supporting the development of appropriately qualified personnel in STEM (science, technology, engineering, and mathematics) fields at postdoctoral level is crucial. These actions aim to strengthen the semiconductor ecosystem by offering students appropriate training opportunities, such as dual-degree programs and introductory programs for students. It is also worthwhile to focus on upskilling existing workers.</p>



<p>Under Operational Objective 5, these actions include: &#8211; increasing the efficiency of EU budget spending to leverage private sector financing;</p>



<p>&#8211; providing support to companies facing difficulties in accessing financing and addressing the need to strengthen economic resilience across the Union and Member States;</p>



<p>&#8211; accelerating and improving the availability of investments in chip design, manufacturing technologies, and semiconductor integration. Furthermore, attracting financing from both the public and private sectors will be crucial, contributing to the security of supply and resilience of the semiconductor ecosystem across the entire value chain.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/chips-and-digitalization/">CHIPS AND DIGITALIZATION</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/chips-and-digitalization/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
