<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gdpr - KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</title>
	<atom:link href="https://www.kg-legal.eu/info/tag/gdpr/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kg-legal.eu/info/tag/gdpr/</link>
	<description>KIELTYKA GLADKOWSKI LEGAL &#124; CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</description>
	<lastBuildDate>Mon, 07 Sep 2026 20:31:08 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Mon, 07 Sep 2026 20:30:11 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[Act on Patients Rights]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI cybersecurity]]></category>
		<category><![CDATA[AI in healthcare]]></category>
		<category><![CDATA[AI-enabled attacks]]></category>
		<category><![CDATA[anomaly detection]]></category>
		<category><![CDATA[anonymisation]]></category>
		<category><![CDATA[anonymization]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[breach notification]]></category>
		<category><![CDATA[cloud healthcare]]></category>
		<category><![CDATA[controller liability]]></category>
		<category><![CDATA[Cyber Five]]></category>
		<category><![CDATA[cyber insurance]]></category>
		<category><![CDATA[Cyber Resilience]]></category>
		<category><![CDATA[cyber resilience healthcare]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[cybersecurity certification]]></category>
		<category><![CDATA[cybersecurity insurance]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[data breach response]]></category>
		<category><![CDATA[data controller]]></category>
		<category><![CDATA[data minimisation]]></category>
		<category><![CDATA[data minimization]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data processing agreement]]></category>
		<category><![CDATA[data processor]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data protection impact assessment]]></category>
		<category><![CDATA[deepfake]]></category>
		<category><![CDATA[digital health]]></category>
		<category><![CDATA[digital healthcare]]></category>
		<category><![CDATA[DPA]]></category>
		<category><![CDATA[DPIA]]></category>
		<category><![CDATA[e-health]]></category>
		<category><![CDATA[eHealth platforms]]></category>
		<category><![CDATA[electronic medical records]]></category>
		<category><![CDATA[EMR security]]></category>
		<category><![CDATA[EU AI Act]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Article 28]]></category>
		<category><![CDATA[GDPR Article 32]]></category>
		<category><![CDATA[GDPR Article 33]]></category>
		<category><![CDATA[GDPR Article 34]]></category>
		<category><![CDATA[GDPR Article 35]]></category>
		<category><![CDATA[GDPR Article 82]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR compliance healthcare]]></category>
		<category><![CDATA[health data]]></category>
		<category><![CDATA[health tech]]></category>
		<category><![CDATA[Healthcare AI]]></category>
		<category><![CDATA[healthcare compliance]]></category>
		<category><![CDATA[healthcare contracts]]></category>
		<category><![CDATA[healthcare cybersecurity]]></category>
		<category><![CDATA[healthcare data breach]]></category>
		<category><![CDATA[healthcare data security]]></category>
		<category><![CDATA[healthcare IT]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[healthcare software]]></category>
		<category><![CDATA[healthcare technology]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[information security management]]></category>
		<category><![CDATA[ISO 27001]]></category>
		<category><![CDATA[IT supplier contracts]]></category>
		<category><![CDATA[joint and several liability]]></category>
		<category><![CDATA[liability insurance]]></category>
		<category><![CDATA[medical data protection]]></category>
		<category><![CDATA[medical records]]></category>
		<category><![CDATA[medical technology]]></category>
		<category><![CDATA[MedTech]]></category>
		<category><![CDATA[MFA]]></category>
		<category><![CDATA[multi-factor authentication]]></category>
		<category><![CDATA[MyDr data breach]]></category>
		<category><![CDATA[National Cybersecurity System]]></category>
		<category><![CDATA[network segmentation]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[patient data]]></category>
		<category><![CDATA[patient privacy]]></category>
		<category><![CDATA[patients rights]]></category>
		<category><![CDATA[Personal data breach]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[phishing attacks]]></category>
		<category><![CDATA[Poland cybersecurity]]></category>
		<category><![CDATA[Polish GDPR]]></category>
		<category><![CDATA[Polish healthcare law]]></category>
		<category><![CDATA[privacy by design]]></category>
		<category><![CDATA[processor liability]]></category>
		<category><![CDATA[pseudonymisation]]></category>
		<category><![CDATA[pseudonymization]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[risk assessment]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[sensitive personal data]]></category>
		<category><![CDATA[special category data]]></category>
		<category><![CDATA[sub-processors]]></category>
		<category><![CDATA[subprocessor management]]></category>
		<category><![CDATA[supplier risk management]]></category>
		<category><![CDATA[technology contracts]]></category>
		<category><![CDATA[telemedicine]]></category>
		<category><![CDATA[third-party liability]]></category>
		<category><![CDATA[UODO]]></category>
		<category><![CDATA[vendor risk]]></category>
		<category><![CDATA[voice deepfake]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8909</guid>

					<description><![CDATA[<p>Publication date: September 07, 2026 What happened On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: September 07, 2026</mark></strong></p>



<h2 class="wp-block-heading"><strong>What happened</strong></h2>



<div class="wp-block-media-text is-stacked-on-mobile" style="grid-template-columns:42% auto"><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4"></video></figure><div class="wp-block-media-text__content">
<p>On 10 August 2026, MyDr, one of Poland&#8217;s largest providers of electronic medical records software, confirmed that it had been the target of a deliberate criminal attack on its systems. Two days later, the Ministry of Digital Affairs announced that the incident may affect close to 19 million individuals and more than 12,000 healthcare facilities, and that the exfiltrated database exceeds 2 terabytes.</p>
</div></div>



<p>The attackers supplied the security portal Zaufana Trzecia Strona with a data sample suggesting that they hold PESEL numbers (Polish national identification numbers) and at least fragments of prescription information.</p>



<span id="more-8909"></span>



<p>To date, the company has not publicly confirmed the full scope and nature of the compromised data, referring instead to a pending forensic analysis. The investigation is being conducted by the Central Bureau for Combating Cybercrime under the supervision of the Warsaw Regional Prosecutor&#8217;s Office, and the President of the Personal Data Protection Office (UODO) has opened an inspection covering the technical and organisational measures applied and the underlying risk analysis. Since 29 August, the dataset from the incident has been available on the government portal bezpiecznedane.gov.pl, where anyone can check whether their data was affected.</p>



<p>The scale of the incident prompted the Ministry of Digital Affairs to announce, within three weeks, a legislative package branded the &#8220;Cyber Five&#8221;. Its key elements include certification of entities processing medical data within the existing national cybersecurity certification framework; a mandatory risk assessment before processing begins and at least every two years thereafter; new obligations for entities serving more than 100 controllers or processing data of more than 100,000 individuals (including rapid transfer of affected persons&#8217; data to CSIRT NASK and a duty to inform client facilities about the level of their own security); and notifications of medical events via the mObywatel and mojeIKP applications. The amendments are to cover the Act on Patients&#8217; Rights and the legislation governing the National Cybersecurity System.</p>



<h2 class="wp-block-heading"><strong>Why roles in the processing chain decide everything</strong></h2>



<p>From a legal standpoint, the critical point is that, in relation to medical records, MyDr acts as a processor, while each facility – from a large clinic network to a single-doctor practice – remains the controller. The consequences of this structure became fully apparent after the incident:</p>



<ul class="wp-block-list">
<li><strong>The obligation to notify UODO (Article 33 GDPR) and to communicate the breach to patients (Article 34 GDPR)</strong> rests with the controller, i.e. the facility. The processor is merely required to inform the controller &#8220;without undue delay&#8221; (Article 33(2) GDPR). In practice, thousands of healthcare providers had to assess risk and communicate with patients on the basis of fragmentary information from the supplier.</li>



<li><strong>Liability for damages (Article 82 GDPR)</strong> is joint and several: a patient may sue the facility, the supplier, or both. The processor is liable where it has failed to comply with obligations specifically imposed on processors by the GDPR or acted contrary to the controller&#8217;s instructions – but the facility is liable for having entrusted data to an entity that did not provide sufficient guarantees (Article 28(1) GDPR).</li>



<li><strong>Sector-specific requirements under the Act on Patients&#8217; Rights</strong> (Article 24(4)) impose on any entity entrusted with the processing of medical records a duty of confidentiality and data security – this is precisely the provision now slated for extension to include certification and minimum technological standards.</li>
</ul>



<p>Deputy Minister of Digital Affairs Dariusz Standerski stated openly that in this case, liability under the contract remained entirely with the controllers, i.e. small medical practices. This is the most important lesson of the incident: a data processing agreement is not a formality but the document that, on the day of a breach, determines who pays.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How a healthcare service provider can protect itself</strong></h2>



<p><strong>1. The data processing agreement and the main contract as risk-allocation tools.</strong> Standard DPA templates offered by software vendors focus on satisfying the minimum requirements of Article 28(3) GDPR. A healthcare provider should negotiate further: a precise deadline and format for incident notification (e.g. 24 hours, with a defined scope of information enabling a risk assessment); audit and penetration-testing rights; an obligation to maintain specified certifications (ISO 27001 and, in future, certification under the National Cybersecurity System Act); a duty to cooperate in communications with patients and the supervisory authority; liability and recourse clauses not capped at the annual fee; and a requirement that the vendor hold cyber insurance with a defined sum insured, with the facility named as a co-insured or beneficiary.</p>



<p><strong>2. Cyber and liability insurance.</strong> Standard professional liability policies for healthcare providers typically do not cover the cost of notifying patients, crisis management, administrative fines or claims arising from data breaches. A dedicated cyber policy covers these elements, but its exclusions must be read carefully: insurers increasingly condition cover on the implementation of MFA, system patching and backups, and an incident at an external supplier (a so-called <em>third-party breach</em>) is often covered only under an express extension. It is also worth verifying whether the software vendor&#8217;s own policy actually exists and what its limit is – given the number of facilities relying on a single system, such amounts may prove illusory.</p>



<p><strong>3. A map of relationships between entities.</strong> In a real-world e-health ecosystem, patient data flows between the facility, the EMR vendor, the hosting or cloud provider, the e-prescription and e-referral operator, laboratories, IT subcontractors and billing companies. Each link is a distinct legal relationship: processing on behalf of the controller, sub-processing (Article 28(2) and (4) GDPR) or joint controllership (Article 26 GDPR). A facility should maintain an up-to-date register of these entities, know where the data is physically located and control the chain of sub-processors – a &#8220;general&#8221; consent to sub-processors without a list and without a right to object is, in practice, an abdication of control.</p>



<p><strong>4. Anonymisation, pseudonymisation and data minimisation.</strong> Data that is not in the system cannot leak. Healthcare providers and vendors should separate identifiers (PESEL numbers, contact details) from clinical data, apply pseudonymisation (Article 4(5) and Article 32(1)(a) GDPR) in test, analytical and research environments, and store statistical data exclusively in anonymised form. It should be remembered that anonymisation is an irreversible process and only such a process removes data from the scope of the GDPR; pseudonymisation remains processing of personal data, but it significantly limits the consequences of a breach and is a valuable argument both in proceedings before UODO and in litigation over damages.</p>



<p><strong>5. Internal obligations and incident readiness.</strong> A breach response procedure should be tested, not merely written down: who decides on notifying UODO within 72 hours, who communicates with patients, who with the media, who secures the evidence. Regular risk analysis and a data protection impact assessment (DPIA) for EMR systems – which, given their scale and the categories of data involved, almost always meet the criteria of Article 35 GDPR – is an obligation already today, and once the &#8220;Cyber Five&#8221; enters into force it will additionally become a sector-specific requirement with a prescribed frequency.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>AI-enabled attacks</strong></h2>



<p>The healthcare sector is particularly exposed to a new generation of AI-supported attacks. Large language models enable the mass generation of credible phishing messages in flawless Polish, personalised on the basis of data from previous breaches – a PESEL number, a surname and information about a prescription are enough to construct a convincing message &#8220;from your clinic&#8221; or &#8220;from the National Health Fund&#8221;. AI tools also automate the discovery of vulnerabilities in systems and the generation of malicious code, shortening the window between disclosure of a vulnerability and its exploitation. There is a growing number of cases involving voice deepfakes used to impersonate medical staff or IT administrators in order to obtain access credentials.</p>



<p>For vendors and facilities, this means that traditional &#8220;don&#8217;t click suspicious links&#8221; training is no longer sufficient. Technical mechanisms are required (phishing-resistant MFA, network segmentation, AI-assisted anomaly monitoring on the defensive side), together with identity verification procedures for every request for data access or a change of permissions. Regulatory risk should also be kept in mind: AI systems deployed in healthcare facilities – including tools supporting diagnostics or triage – fall under the AI Act, and their integration with EMR systems constitutes yet another link in the processing chain that must be reflected in contracts and in the risk analysis.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>How we support institutional clients</strong></h2>



<p>KG Legal advises healthcare providers, medical networks, telemedicine platform and e-health software vendors, and investors in this sector on managing liability for data. Our support includes auditing existing data processing agreements and IT supplier contracts for risk allocation; negotiating liability, recourse and insurance clauses; mapping the chain of processors and vetting subcontractors; preparing and testing breach response procedures; handling notifications to UODO and communications with patients; and representation in inspection proceedings and in damages litigation. For medical technology vendors, we prepare documentation and contract templates meeting the requirements of the GDPR, the Act on Patients&#8217; Rights, NIS2 and – once enacted – the &#8220;Cyber Five&#8221; provisions, and we assess the compliance of AI-based solutions with the AI Act and the MDR. Our aim is that, on the day an incident occurs, the client knows exactly who is responsible for what and has evidence of having exercised due diligence.</p>



<p><em>Facts as at 2 September 2026, based on statements by MyDr, the Ministry of Digital Affairs and UODO, and press reports. This article is for information purposes only and does not constitute legal advice.</em></p>
<p>#MyDr #DataBreach #HealthcareCybersecurity #HealthcareData #DataProtection #GDPR #Cybersecurity #HealthTech #eHealth #DigitalHealth #MedicalRecords #EMR #PatientData #PatientPrivacy #UODO #Poland #CyberRisk #CyberInsurance #IncidentResponse #DataPrivacy #NIS2 #CyberFive #ISO27001 #AIAct #AIinHealthcare #AICybersecurity #MedTech #Telemedicine #CyberResilience #DataSecurity</p>
<p> </p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/">The MyDr Data Breach – Lessons for Healthcare Service Providers and e-Health Platforms</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/mydr-data-breach-lessons-for-healthcare-providers-kglegal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/09/generated-video-1-1.mp4" length="492961" type="video/mp4" />

			</item>
		<item>
		<title>Drone Warfare</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 13:55:20 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[Anti-Drone Technology]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[Autonomous Weapon Systems]]></category>
		<category><![CDATA[Aviation Law]]></category>
		<category><![CDATA[BVLOS]]></category>
		<category><![CDATA[Counter-Drone Systems]]></category>
		<category><![CDATA[Critical Infrastructure]]></category>
		<category><![CDATA[Defence Tech]]></category>
		<category><![CDATA[Defence Technology]]></category>
		<category><![CDATA[Drone Compliance]]></category>
		<category><![CDATA[Drone Law]]></category>
		<category><![CDATA[Drone Regulation]]></category>
		<category><![CDATA[Drone Warfare]]></category>
		<category><![CDATA[Dual-Use Export Controls]]></category>
		<category><![CDATA[Dual-Use Regulation]]></category>
		<category><![CDATA[Dual-Use Technology]]></category>
		<category><![CDATA[EU Drone Regulation]]></category>
		<category><![CDATA[Export Control]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[High-Risk AI Systems]]></category>
		<category><![CDATA[Military AI]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[personal data protection]]></category>
		<category><![CDATA[Polish Drone Law]]></category>
		<category><![CDATA[U-space]]></category>
		<category><![CDATA[UAV Law]]></category>
		<category><![CDATA[Unmanned Aircraft]]></category>
		<category><![CDATA[Unmanned Aircraft Systems]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8874</guid>

					<description><![CDATA[<p>Publication date: August 26, 2026 The Legal Environment and Practical Aspects of Dual-Use Technology – the Ukrainian Conflict as a Lens on the Development of EU Regulation and the Polish Jurisdiction &#8211; Expanded Edition &#8211; Legal status as at 25 August 2026 Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: August 26, 2026</strong></mark></p>



<h3 class="wp-block-heading">The Legal Environment and Practical Aspects of Dual-Use Technology – the Ukrainian Conflict as a Lens on the Development of EU Regulation and the Polish Jurisdiction &#8211; Expanded Edition &#8211; Legal status as at 25 August 2026</h3>



<p><em>Authors: attorney-at-law (radca prawny) K. Jakub Gładkowski (corporate practice, court and regulatory representation), attorney-at-law (radca prawny) Małgorzata Kiełtyka (M&amp;A, high-technology and highly regulated sectors) – KG Legal Kiełtyka Gładkowski Spółka Partnerska Kancelaria Radców Prawnych; iSTART1 programme.</em></p>



<p><em>This material is of a popular-science and informational nature. It does not constitute legal advice or a binding opinion. Before citing any specific provision, the current consolidated version in EUR-Lex and the current entry in the Polish Journal of Laws (Dziennik Ustaw) should be verified in each case.</em></p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png" target="_blank" rel=" noreferrer noopener"><img fetchpriority="high" decoding="async" width="980" height="551" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png" alt="" class="wp-image-8875" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image.png 980w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-300x169.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-768x432.png 768w" sizes="(max-width: 980px) 100vw, 980px" /></a></figure>



<span id="more-8874"></span>



<h4 class="wp-block-heading"><em>Abstract</em></h4>



<p class="has-luminous-vivid-amber-background-color has-background">The Russo-Ukrainian conflict has become a lens in which the future of dual-use unmanned technology is brought into focus – and, at the same time, a barometer of the direction its regulation will take. Within two to three years, technological progress has occurred which, in peacetime conditions, would have taken decades. This article combines two perspectives: a technological taxonomy of drone warfare and a map of the legal environment of the European Union and Poland, encompassing nine mutually interpenetrating regulatory pillars – from product certification and airspace management, through artificial intelligence, export control, defence financing, satellite communications, cybersecurity and personal data protection, to international law and the national regime.</p>



<p class="has-white-color has-vivid-red-background-color has-text-color has-background has-link-color wp-elements-6caed12e936c828f3ed6d240556392b7"><strong>The thesis to be verified is that the legal regime of the UAV sector is structurally dual-track: on the civil track, law operates as a consequence of need and as a risk-dampening factor, whereas on the defence track it operates as a driver of development. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive instruments, while the line of dispute is the increasingly blurred dual-use boundary. We analyse seven concrete points of friction between the tracks and formulate a practical qualification map and a 2026–2028 compliance calendar for manufacturers, operators and investors in this sector.</strong></p>



<p><em><strong>Keywords:</strong> unmanned aircraft, dual use, Artificial Intelligence Act, high-risk systems, autonomous weapon systems, export control, U-space, NIS2, CER, personal data protection, European Drone Defence Initiative.</em></p>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile is-vertically-aligned-center has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-74fa267e46e25de8e613770e79a485db"><div class="wp-block-media-text__content">
<h3 class="wp-block-heading">Part I: the Legal Environment and Practical Aspects of Dual-Use Technology</h3>
</div><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/output.mp4"></video></figure></div>



<h2 class="wp-block-heading">1 Introduction</h2>



<h3 class="wp-block-heading">1.1 Nineteen objects over Poland – the moment when law caught up with reality</h3>



<p>The impulse to look at the drone problem not merely as a tactical phenomenon but as a growing strategic threat to Europe comes from reports circulating in the analytical and milblogger space – based on statements of Ukrainian military intelligence (HUR) – that Russia is already producing more jet-powered variants of the Geran-4 and Geran-5 than piston-engined Geran-2s, with figures in the order of approximately 3,000 jet platforms per month against approximately 2,800 piston variants. Assessments of this kind, even if they call for source-related caution, are of significant analytical importance: they show that the scale of Russian production of unmanned means of aerial attack may exceed the framework of a war of attrition against Ukraine and may be perceived as a capability able to support a broader campaign of pressure or threat directed at European states. In this sense, the drone problem is no longer an exclusively military issue, but also a stimulus for a fresh reading of the legal environment of unmanned technologies in Europe – from aviation law, through export control and AI, to cybersecurity, the protection of critical infrastructure and state security.<a href="#_ftn1" id="_ftnref1">[1]</a></p>



<p>On the night of 9/10 September 2025, a dozen or so unmanned aircraft flew into Polish airspace; some of them were shot down by NATO aircraft. This was not an isolated incident – the Romanian government had reported violations as early as January 2025, and in August of the same year a Russian Geran-2-type platform came down near Osiny in eastern Poland. The September event, however, carried a different weight: it triggered consultations under Article 4 of the Washington Treaty, led to the launch of NATO’s operation _Eastern Sentry_, and, in the EU dimension, to the announcement of a “drone wall”, subsequently transformed into the <strong>European Drone Defence Initiative (EDDI)</strong> and <strong>Eastern Flank Watch</strong>.</p>



<p>The current phase of the Russo-Ukrainian conflict makes it plain that both sides are developing unmanned technologies according to different operational logics and economics of use. The Russian side has to a greater extent expanded the segment of drones performing a function complementary to classic means of aerial attack: decoys, platforms imitating the actual strike assets, and cheap carriers used to saturate air defence and force the expenditure of effectors on the Ukrainian side. The Ukrainian side, conversely, is developing more broadly the segment of long-range drones with a real strike function, whose principal purpose is to strike rear-area infrastructure, including refineries, logistics and other objects of high operational value. This difference matters not only militarily but also in legal-regulatory terms, because it translates into different risk profiles as regards the qualification of dual-use technology, liability for the use of means of aerial attack, the protection of critical infrastructure, and the economics of air defence. In practice, the Russian model relies to a considerable degree on forcing a costly defensive reaction on the adversary’s side, whereas the Ukrainian model aims at the asymmetric striking of rear-area targets using relatively cheap platforms, which further deepens the problem of cost disproportionality between a cheap drone and an expensive defensive effector, such as the missiles of the S-300, S-400, Tor or Pantsir systems. In this sense, the conflict is a lens not only of the development of technology, but also of the transformation of the regulatory logic itself: law must now contend not with a single device, but with entire models of the operational use of unmanned technologies.<a href="#_ftn2" id="_ftnref2">[2]</a></p>



<p>For the lawyer, however, something else is most important. The facts give rise to questions about an asymmetry which is the crux of the entire regulatory problem: against platforms with a unit cost counted in thousands of dollars, systems were used whose single effector should cost hundreds of thousands. This cost asymmetry is not merely a budgetary problem. It forces the burden of defence to be shifted onto solutions that are cheap, mass-produced and increasingly autonomous – and therefore precisely onto that class of technology which European Union law regulates most cautiously on the civil side and almost not at all on the military side.</p>



<p><strong>The new regulatory architecture of drone security: from EU strategy to the obligations of critical infrastructure operators and AI systems</strong></p>



<p>Over the following months, the legislative tempo concerning unmanned systems accelerated in a manner unprecedented for this sector. The existing drone regulations had concentrated primarily on aviation safety, the rules for conducting operations, and technical requirements for operators and manufacturers. In 2026, however, a significant shift of regulatory emphasis took place: the drone began to be treated not only as an aviation device, but also as a potential tool of threat to critical infrastructure and as a system that may be subject to the requirements of artificial intelligence regulation.</p>



<p>The first element of this new architecture was the <strong>Action Plan on Drone and Counter Drone Security</strong> (COM(2026) 81 final) presented by the European Commission on 11 February 2026.<a href="#_ftn3" id="_ftnref3">[3]</a> This document does not constitute a legally binding act within the meaning of Article 288 of the Treaty on the Functioning of the European Union,<a href="#_ftn4" id="_ftnref4">[4]</a> but has the character of a European Commission communication – a political and programmatic instrument belonging to the category of so-called soft law. It does not establish direct obligations for Member States, undertakings or critical infrastructure operators, but it sets the direction of the European Union’s future legislative and organisational actions.</p>



<p>The significance of this document lies above all in a change in the way threats connected with unmanned aircraft are perceived. The Commission indicated that the rapid development of drone technologies, their commercial availability and the possibility of their use by entities conducting hostile activities make it necessary to build a European security system encompassing both protection against unauthorised drone operations (counter-drone) and the strengthening of the resilience of Member States’ infrastructure.</p>



<p>The Action Plan provides for the development of Member States’ capabilities in detecting, identifying and neutralising threats caused by drones, better information exchange between security authorities, and the development of counter-drone technologies. Particular importance was attached to the protection of critical infrastructure, military facilities, the external borders of the European Union, and places particularly exposed to the unlawful use of drones.</p>



<p>The European Commission’s Action Plan should accordingly be treated as the first level of the new regulation – the strategic level. It does not yet impose specific legal obligations, but it creates the political justification for subsequent legislative changes at national and EU level.</p>



<p>The second level was the intervention of the Polish legislator. The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts introduced solutions enabling the use of jamming devices in the protection of critical infrastructure.<a href="#_ftn5" id="_ftnref5">[5]</a></p>



<p>This amendment<a href="#_ftn6" id="_ftnref6">[6]</a> is of particular importance because, for the first time in the Polish legal system, an express basis was created for the application of measures interfering with the communications or control of unmanned aircraft by entities connected with the protection of critical infrastructure. It must, however, be precisely noted that the legislator did not grant critical infrastructure operators an independent right to use jamming devices.<a href="#_ftn7" id="_ftnref7">[7]</a> The legal construction was shaped at two levels.</p>



<p>First, <strong>Article 16c</strong>,<a href="#_ftn8" id="_ftnref8">[8]</a> added to the Act on Crisis Management, grants the critical infrastructure operator the competence to take a decision on the admissibility of the use of specified devices.</p>



<p>That provision reads:</p>



<p>“<em>In order to ensure the protection of critical infrastructure, the critical infrastructure operator (…) may take a decision on the admissibility of the use of the devices referred to in paragraph 1, for the time necessary for the performance of activities by security staff of specialist armed security formations (…)</em>”.</p>



<p>Second, the technical scope of those measures follows from the provisions of the <strong>Aviation Law</strong>, in particular Article 156ze(1), which sets out the possibility of using devices serving to counter unmanned aircraft.</p>



<p>Under that provision, such devices may be used for the purpose of:</p>



<p>“<em>interfering with or taking over control of an unmanned aircraft, interfering with the flight control signal or the navigation signal enabling the flight of that aircraft</em>”.<a id="_ftnref9" href="#_ftn9">[9]</a></p>



<p>In practice, this means that the critical infrastructure operator has obtained a new power of a decision-making character, whereas the physical use of the devices remains tied to the activities of the staff of specialist armed security formations (SUFO). This solution is a compromise between the need for effective protection of strategic facilities and the necessity of limiting the risk of uncontrolled use of devices capable of interfering with communications or navigation systems.</p>



<p>The explanatory memorandum to the bill<a href="#_ftn10" id="_ftnref10">[10]</a> stated that the purpose of the regulation is to increase the resilience of critical infrastructure and to provide operators with tools corresponding to contemporary threats, in particular threats making use of unmanned systems.</p>



<p>The third level of regulation was the modification of the timetable for the application of the provisions of the EU Artificial Intelligence Act.</p>



<p>On 29 June 2026, the Council of the European Union approved an amendment to Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (the AI Act).<a href="#_ftn11" id="_ftnref11">[11]</a> This amendment did not change the AI Act’s basic risk-based regulatory model, but postponed the dates on which part of the obligations concerning high-risk systems begin to apply.</p>



<p>The most significant change was the extension of the preparatory period for providers of high-risk AI systems. The regulation was intended to enable undertakings, supervisory authorities and standardisation institutions to prepare the appropriate technical and organisational mechanisms, including conformity standards, risk assessment procedures and quality management systems.</p>



<p>This change is also relevant for the drone sector. Contemporary unmanned systems increasingly use artificial intelligence algorithms for autonomous navigation, object identification, image analysis or operational decision-making. In consequence, particular applications of drones may simultaneously be subject to aviation law regulations, provisions concerning the security of critical infrastructure, and the requirements of the AI Act.</p>



<p>By way of example, Article 113 of Regulation (EU) 2024/1689, which sets out the timetable for the application of the AI Act’s provisions, was amended as regards the dates of applicability of the rules concerning high-risk systems, postponing the full application of part of the obligations to later dates.<a href="#_ftn12" id="_ftnref12">[12]</a></p>



<p>As a result, in 2026 a multi-level regulatory architecture concerning a single device came into being. At European Union level, the European Commission set the strategic direction of the development of drone security policy through the non-binding Action Plan. At national level, Poland created a mechanism for the protection of critical infrastructure enabling the use of counter-drone measures. At the technological level, the AI Act laid down the principles of the responsible use of artificial intelligence systems employed in autonomous devices.</p>



<p><strong>Three different regimes. Three different regulatory logics. And all of them concern the same device.</strong></p>



<h2 class="wp-block-heading">1.2 The paradox of acceleration</h2>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="980" height="551" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png" alt="" class="wp-image-8877" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1.png 980w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1-300x169.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-1-768x432.png 768w" sizes="(max-width: 980px) 100vw, 980px" /></a></figure>



<p>The history of military technology knows few moments in which the development curve breaks as abruptly as in Ukraine after 2022. Commentators<a href="#_ftn13" id="_ftnref13">[13]</a> estimate that the technological leap<a href="#_ftn14" id="_ftnref14">[14]</a> in the field of unmanned aircraft accomplished during two to three years of war would, in the absence of an arms race, have taken 20–30 years.<a href="#_ftn15" id="_ftnref15">[15]</a> As to the period, it must be assessed that the thesis itself is <strong>fundamentally true</strong>, but the formulation “20–30 years” is not a scientific claim easily attributable to a single source. It is rather a <strong>metaphor used by military analysts, representatives of the defence industry and commentators</strong>, who describe a <strong>step-change acceleration of the innovation cycle</strong> under the influence of the war. In the space of only two to three years, drones travelled the road from specialised reconnaissance tools to mass-deployed combat systems, encompassing cheap single-use platforms, unmanned swarms, systems resistant to electronic jamming, and solutions using artificial intelligence. In the view of many military analysts, this conflict has shortened the development cycles of unmanned technologies in a way that, in peacetime conditions, would correspond to a multi-year or even multi-decade process of evolution.<a href="#_ftn16" id="_ftnref16">[16]</a></p>



<p>This paradox of acceleration has its source not in success but in failure.<a href="#_ftn17" id="_ftnref17">[17]</a> The original plan of a lightning resolution – seizing the capital within a week and taking control of the south of the country – collapsed already in the cyber phase, when the operation intended to paralyse the digital administration, banking and state budget did not translate into the country’s military collapse. The result was a positional stalemate in the east – trench warfare reminiscent of the fronts of a hundred years ago.</p>



<p>And it was precisely this stalemate, not manoeuvre, that became the incubator of innovation. Tactical pressure in an environment in which neither side can gain a conventional advantage forced a cascade of technological solutions: from commercial observation drones, through mass-scale FPV drones, to satellite-controlled long-range platforms with elements of autonomy.</p>



<p>It is worth emphasising that this mechanism was to a considerable extent <strong>civilian in its genesis</strong>. The drone revolution did not come out of the laboratories of the great arms concerns, but out of the model-making market, out of commercial consumer electronics and out of open-source software. A manufacturer which in 2021 was selling a platform for power-line inspection was in 2023 delivering the same design with a different payload configuration. The law, which for two decades had been building separate regimes for civil aviation and for armaments, found itself confronted with a product that crosses that boundary without any design modification.</p>



<h2 class="wp-block-heading">1.3 Thesis, research question and structure of the argument</h2>



<p>For a lawyer serving entities in the high-technology sector, the paradox of acceleration has a practical dimension. It gives rise to the question that is the axis of this text: <strong>does law in this area merely react to a technology which the conflict has outpaced, or has it itself become an instrument of acceleration – and perhaps, in some segments, an instrument of its extinguishment.</strong></p>



<p>The answer, which we substantiate in the remainder of this text, is: law performs <strong>three different roles simultaneously</strong> in this sector, and which of them is activated is decided not by the technology but by the qualification of the purpose of use. And that qualification is, in the case of dual-use products, inherently unstable.</p>



<p>The structure of the argument is as follows. Part 2 presents the technological taxonomy of drone warfare – without it, legal analysis operates in a vacuum, because each of the regulatory regimes attaches legal consequences to specific technical features (mass, range, presence of sensors, degree of autonomy, type of link). Part 3 maps the legal environment of the European Union and Poland, divided into nine pillars.</p>



<figure class="wp-block-image size-full"><a href="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png" target="_blank" rel=" noreferrer noopener"><img decoding="async" width="627" height="353" src="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png" alt="" class="wp-image-8879" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2.png 627w, https://www.kg-legal.eu/wp-content/uploads/2026/08/image-2-300x169.png 300w" sizes="(max-width: 627px) 100vw, 627px" /></a></figure>



<p>Part 4 analyses seven points of friction at which these pillars collide with one another – it is there that the undertaking’s real legal risk is concentrated. Part 5 formulates the thesis of the dual-track nature of the regime. Part 6 translates the analysis into transactional and compliance practice, together with a compliance calendar up to 2028.</p>



<h2 class="wp-block-heading">2 · The Anatomy of Drone Warfare – a Technological Taxonomy</h2>



<p>The point of departure for any legal analysis must be the differentiation of categories. It is a fundamental error – also in the regulatory debate – to treat the “drone” as a single class of devices. A more apt analogy here is to optics and photography: there is no single universal lens for every photograph, because each type of shot – macro, portrait, telephoto, wide-angle landscape – requires a different optical construction, a different focal length and a different compromise between reach and field of view. It is exactly the same with drones and counter-drone systems: there is no single “anti-drone system”; there are systems countering specific categories of platforms, matched to their signature, range and mode of communication. This differentiation is not merely descriptive but legal in character – it determines product qualification, the export regime and the scope of compliance obligations.</p>



<p>This differentiation has directly normative consequences. At the level of product qualification, the mass, construction and intended purpose of the platform determine its place in the EU UAV regime, in particular in Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, which treat product classes and the “open”, “specific” and “certified” categories of operations differently; in practice this means that the same aircraft may, as a product, remain in lawful civil circulation while at the same time, with a different mode of use or retrofitting, pass into the area of heightened regulatory risk. At the level of the export regime, the identical differentiation decides whether a component, software, sensor, communications module or navigation system falls within the scope of Regulation (EU) 2021/821 as a dual-use product, which may trigger an authorisation requirement, an end-user assessment and a proliferation risk analysis. At the level of compliance obligations, in turn, what matters are not only the physical features of the drone but also its data and autonomy functions: the presence of cameras, sensors or AI modules may in parallel trigger the requirements of the GDPR, cybersecurity, information security and – outside the scope of the military exclusion – the obligations arising from the AI Act. As a result, in the UAV sector it is not enough to ask “what is the product”; the key question becomes in what chain of use, circulation and liability the product operates.</p>



<p>The importance of this differentiation lies in the fact that, in the UAV sector, technical categories translate into different normative consequences in several overlapping legal regimes at once. First, at the level of product and operational qualification, features such as take-off mass, communications architecture, scope of autonomy or type of payload affect the classification of the platform in the light of Delegated Regulation (EU) 2019/945 and Implementing Regulation (EU) 2019/947, and thus the admissibility of its placing on the market and the mode of its lawful operation. Second, at the level of export control, the same features may determine whether specific components, sensors, navigation modules, software or technical documentation are covered by the regime of Regulation (EU) 2021/821, which triggers licensing obligations, end-user assessment and proliferation risk assessment. Third, at the level of functional compliance, what matters is no longer only the material features of the platform itself, but also its data-processing, observation and decision-support functions: the use of optical sensors, thermal-imaging sensors, remote identification systems or image-analysis algorithms may in parallel trigger requirements arising from the GDPR, cybersecurity regulation and – outside the scope of the military exclusion – the obligations laid down in the AI Act. In this sense, the legal qualification of a drone is not a one-off act but a multi-layered process, dependent on construction, function, context of use and the architecture of circulation.<a href="#_ftn18" id="_ftnref18">[18]</a></p>



<p>A separate phenomenon, irreducible to any of the above categories, is the drone swarm. Whereas the existing taxonomy ordered drones according to the features of a single platform – mass, range, mode of communication, degree of autonomy – the swarm is an emergent phenomenon at the level of many platforms operating as one system. Three elements are key here: iteration and coordination between units (drones exchange data on position, target and status in real time, often via a mesh network, with no single point of failure), distributed processing of sensor data (imagery and telemetry from many platforms are aggregated and classified jointly, which increases target-detection effectiveness beyond the sum of individual sensors), and collective control by a single operator or a supervisory algorithm which allocates tasks among the units of the swarm. Ukrainian deployments of this technology – including autonomous swarming systems used since 2025 for mine-laying and target engagement, and large-scale operations combining several dozen to several hundred platforms in a single strike – show that the swarm is no longer an experiment but an operational reality. This has serious legal consequences which remain unresolved to date: whether the swarm should be qualified as a single system subject to a single conformity assessment or as a collection of separate products; who bears responsibility for a decision taken at swarm level when no single platform takes it independently; and how the data protection and radio spectrum management regime is to treat a network whose nodes come into being and disappear in flight.<a href="#_ftn19" id="_ftnref19">[19]</a></p>



<p>This differentiation is not merely terminological or descriptive in character, but produces direct legal effects. The individual technical properties of an unmanned aircraft constitute the triggering conditions for different regulatory regimes of European Union law and national law. In practice, this means that a change in one technical parameter of a drone may lead to a fundamentally different legal qualification of the same device.</p>



<p>The first such parameter is the <strong>Maximum Take-Off Mass (MTOM)</strong>. Commission Delegated Regulation (EU) 2019/945 establishes classes of unmanned aircraft systems (C0–C6), whose assignment takes place, among other things, with regard to technical parameters, in particular mass, speed and system equipment. This classification is not purely technical in character – it determines the possibility of conducting operations in the appropriate subcategories of the “open” category provided for in Commission Implementing Regulation (EU) 2019/947 and affects the manufacturer’s obligations connected with conformity assessment and product class marking.<a href="#_ftn20" id="_ftnref20">[20]</a></p>



<p>The significance of mass is also revealed at the level of the operator’s obligations. Under Article 14 of Implementing Regulation (EU) 2019/947, the operator of an unmanned aircraft system is subject to a registration obligation, inter alia, where it operates an aircraft with a maximum take-off mass of at least <strong>250 g</strong> or – regardless of mass – an aircraft equipped with a sensor capable of capturing personal data, unless the device meets the conditions provided for toys within the meaning of Directive 2009/48/EC. The 250 g mass thus constitutes one of the fundamental legal thresholds in the European drone regulatory system.<a href="#_ftn21" id="_ftnref21">[21]</a></p>



<p>The second parameter of fundamental importance is the <strong>drone’s equipment with sensors enabling the capture of personal data</strong>, above all optical cameras, thermal-imaging cameras, LiDAR scanners or other devices allowing the identification of natural persons. In such a case, the General Data Protection Regulation (GDPR) applies. Data recorded by a drone may constitute personal data within the meaning of Article 4(1) GDPR, which entails the necessity of ensuring a legal basis for processing in accordance with Article 6 GDPR, complying with the principles set out in Article 5 GDPR and – in the case of operations creating a high risk to the rights and freedoms of natural persons – carrying out a data protection impact assessment in accordance with Article 35 GDPR. These obligations arise regardless of the mass of the aircraft, and therefore also in relation to the smallest drones weighing under 250 g, if they are equipped with devices enabling the capture of personal data.<a href="#_ftn22" id="_ftnref22">[22]</a></p>



<p>This approach is confirmed in the case law of the Court of Justice of the European Union. In its judgment of 11 December 2014 in Case <strong>C-212/13, Ryneš</strong>, the Court held that the recording of images enabling the identification of natural persons constitutes the processing of personal data, even if it takes place with the use of devices monitoring the surroundings of private property. Although the case concerned video surveillance, the conclusions flowing from that judgment apply mutatis mutandis also to unmanned systems equipped with cameras or other observation sensors.<a href="#_ftn23" id="_ftnref23">[23]</a></p>



<p>A further feature determining the legal regime is the <strong>character of the equipment and payload</strong>. Regulation (EU) 2021/821 of the European Parliament and of the Council establishes the Union’s system for the control of exports of dual-use items. The qualification of a drone or its components for the list of dual-use items is decided not only by flight parameters but also by the technical capabilities of the device, such as range, autonomy, navigation systems, observation equipment, high-resolution cameras, data transmission systems or specialised sensors. In consequence, two seemingly similar drones may be subject to entirely different export obligations solely on account of differences in their equipment or technical capabilities.<a href="#_ftn24" id="_ftnref24">[24]</a></p>



<p>Even more complex is the legal qualification of systems using <strong>artificial intelligence</strong>. The degree of flight autonomy alone does not automatically determine the applicability of the AI Act. It must first be established whether the given solution constitutes an “AI system” within the meaning of Article 3 of Regulation (EU) 2024/1689. Only at the next stage is it necessary to assess whether the system belongs to the high-risk category in accordance with Article 6 of that regulation and Annexes I and III. This means that two drones with identical flight parameters may be subject to different regulatory obligations solely on account of differences in the software responsible for autonomous navigation, object identification, image analysis or operational decision-making.<a href="#_ftn25" id="_ftnref25">[25]</a></p>



<p>In consequence, the legal qualification of an unmanned aircraft does not follow from a single technical feature, but from the configuration of its constructional, functional and operational properties. The same drone may simultaneously be subject to aviation law regulations, personal data protection provisions, the dual-use item control regime, provisions concerning the protection of critical infrastructure and – in specific cases – Regulation (EU) 2024/1689 (the AI Act). This signifies a transition from the classic model of sectoral regulation to a model of functional regulation, in which different branches of law simultaneously apply to the same device, protecting different legal goods: aviation safety, privacy, state security, control of trade in technologies and the safety of artificial intelligence systems.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.1 · Observation drones – the foundation of situational awareness</strong></h3>



<p>The lowest tier consists of commercial multirotor drones (the Chinese DJI Mavic,<a href="#_ftn26" id="_ftnref26">[26]</a> Ukrainian equivalents of the Zoom class). Their role is to provide <strong>situational awareness</strong> – the category that decides the success of every assault and every defence. A contemporary soldier with an overhead picture operates in an entirely different reality from one who scans the field with his eyes.</p>



<p>In the Ukrainian trade and military-technology discourse,<a href="#_ftn27" id="_ftnref27">[27]</a> the designation ZOOM refers to a specific reconnaissance platform developed by the Ukrainian company Frontline / Frontline Robotics, presented as an alternative to the Chinese DJI Mavic drones. It is a light multirotor observation drone intended for reconnaissance tasks, fire correction and building situational awareness at the tactical level, and therefore for the same operational niche which for a long time was dominantly occupied at the front by Mavic platforms. In this sense, the “Ukrainian equivalent of the Mavic of the ZOOM class” should be understood not as a formal technical category but as the proper name of a domestic platform positioned in the segment of light reconnaissance drones with a substitutive function vis-à-vis DJI. The available sources<a href="#_ftn28" id="_ftnref28">[28]</a> also indicate that ZOOM forms part of a broader Ukrainian trend of building domestic Mavic analogues in order to reduce dependence on foreign civilian commercial systems.</p>



<p>Importantly, despite rapid development these platforms have not disappeared – on both sides of the front, civilian Mavics are still used, whose sole task is to “hang in the air and watch”. This is an observation of primary legal importance: <strong>the most numerous category of platforms used in the conflict consists of mass-produced consumer products, placed on the market under the civil regime, with CE marking, in classes C0–C2.</strong> The same unit which yesterday was subject to Implementing Regulation (EU) 2019/947 as an operation in the open category is today carrying out a reconnaissance task outside any EU regime.</p>



<p>The DJI Mavic constitutes a model example of the detachment of the product from the purpose of use. As a commercial product, it was designed and placed on the market for the needs of the civil market: photography, inspection, surveying, recreation and light professional applications. In that order, its legal status is determined by the classic instruments of EU aviation law and product law – in particular the requirements of CE marking, the product classes under Delegated Regulation (EU) 2019/945, the operating rules under Implementing Regulation (EU) 2019/947, the operator’s obligations, remote identification, geographical zones, registration and – depending on the sensor configuration – data protection requirements. However, the moment that same unit is used on contested territory to build situational awareness, correct fire or conduct military reconnaissance, the logic for which the EU civil aviation regime was built ceases to operate. The product itself as a thing does not change, but its operational function changes, and with it the normative order changes: from the area of product safety and lawful civil operation we pass into the area of military operations, military logistics, the law of armed conflict, export control and state security. It is precisely for this reason that, in the UAV sector, the legal nature of a platform is increasingly determined not by its construction but by the chain of use into which it is incorporated.</p>



<p>A good counterpoint to this transformation is the example of the Ukrainian Mavic equivalents, such as the ZOOM developed by the above-mentioned Frontline Robotics. Where the manufacturer communicates<a href="#_ftn29" id="_ftnref29">[29]</a> that a given complex has been entered in the NATO Codification System (NCS) and has received a NATO Stock Number (NSN), this means not so much the obtaining of civil certification as the product’s entry into the common language of NATO defence logistics: the item is unambiguously identified, classified and prepared to function within the system of supply, storage and military interoperability. The NSN is therefore a catalogue-logistics designation, not a mark of quality or an authorisation for marketing in the sense of consumer law or civil aviation law. The juxtaposition of the Mavic with a platform codified in the NATO system well illustrates the institutional shift: the first product begins its life in the regime of civil commercialisation, while the second is from the outset positioned as an element of the defence architecture and the military supply chain. This difference does not consist solely in technology, but in normative embedding – that is, in whether the product is designed for the civil market or for the order of military logistics and allied interoperability.<a href="#_ftn30" id="_ftnref30">[30]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.2 · FPV drones – a squad weapon and the cost revolution</h3>



<p>The current combat standard in the front-line zone is the FPV (first person view) drone – single-use platforms controlled from a first-person perspective through goggles. This is not, however, a weapon of the individual soldier: the operation of a single drone requires a team of 3–4 persons (pilot, relay operator, sapper, frequently a navigator). The FPV is a squad weapon, like a mortar or a heavy machine gun. One team is able to carry out 25–30 sorties a day, consuming a corresponding number of single-use platforms.<a href="#_ftn31" id="_ftnref31">[31]</a></p>



<p>The scale of this revolution has above all an economic and institutional dimension. It is no accident that industry analyses describe FPV as the “$1,000 revolution”: the essence of the breakthrough lies not solely in the platform itself, but in the relationship between the low unit cost of the means of attack and the high cost of countering it, as well as in the possibility of rapidly scaling production on the basis of a dispersed component market, a simple assembly architecture and short iteration cycles. In this sense, FPV is not merely a new category of drone but a new model of the economics of war – a model in which a relatively cheap, partly standardised and rapidly modifiable platform can generate tactical and operational effects disproportionate to its price. That is precisely why the weight of the analysis shifts from the question of the individual product to the question of the production ecosystem, the capacity for its continuous reproduction, and the institutional conditions that enable the transition from field improvisation to mass production.<a href="#_ftn32" id="_ftnref32">[32]</a></p>



<p>In the case of Ukraine, this capacity is no longer solely the effect of spontaneous industrial mobilisation, but results from the construction of an organised, state-supported defence tech ecosystem, centred on the Brave1 platform.<a href="#_ftn33" id="_ftnref33">[33]</a> Brave1 was launched on 26 April 2023 as a governmental defence tech cluster, co-created by the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries,<a href="#_ftn34" id="_ftnref34">[34]</a> with the implementation layer carried out by the Innovation Development Fund. From a legal perspective, this is not a classic commercial-law company nor a single procurement procedure, but rather a public coordination platform combining grant, testing, matchmaking and acceleration functions. Officially, Brave1 describes its role as supporting the development of defence technologies through organisational, informational and financial support for projects, and the platform’s successive initiatives – including grant programmes, a defence innovation marketplace and projects carried out with international partners – show that it operates as an intermediate layer between the technological idea, the prototype, military testing, IP protection and further implementation into procurement or operational use. It is therefore an institutional mechanism for mobilising defence innovation, not a separate, homogeneous statutory regime.</p>



<p>The significance of Brave1 for the FPV market lies in the fact that this platform aggregates dispersed manufacturers and lowers the threshold of entry into the defence sector, shortening the road from design to implementation. Analytical sources indicate that around 1,500 defence tech companies and start-ups are gathered around Brave1, with some more recent analyses speaking of an even greater number of entities functioning within this ecosystem.<a href="#_ftn35" id="_ftnref35">[35]</a> From the point of view of this report, however, more important than the number itself is that Brave1 produces an architecture of scale: new entities can enter the sector via a grant, testing, validation, contact with the military user, intellectual property protection and entry into the procurement circuit, without having to pass immediately through the classic, heavy model of the armaments industry. It is precisely this institutional model that explains why Ukraine was able to move from the early phase of improvisation and purchases from the commercial market to a phase in which drone production began to be treated as a mass state capability.<a href="#_ftn36" id="_ftnref36">[36]</a></p>



<p>The volumes of this production are unprecedented. Industry analyses and statements by representatives of the Ukrainian authorities cite figures of the order of about 800 thousand drones in 2023, about 2 million in 2024, production capacities reaching 4 million annually, and subsequently procurement plans covering about 4.5 million FPV drones in 2025. In parallel, declared targets for 2026 have also appeared in public circulation, according to which Ukraine would aim for a level of 7 million drones annually, presented as a volume many times exceeding American production. Even if the individual figures must be treated with caution and a distinction must be drawn between actual production, production capacity, procurement plan and political-industrial target, the direction itself is unambiguous: Ukraine has transformed drones – especially FPV – from an auxiliary technology into an industrial strategic resource, whose development depends no longer solely on the technical capability of an individual manufacturer, but on state-supported organisational, grant, testing and procurement infrastructure. In this sense, Brave1 operates as a multiplier of production sovereignty: it not only supports a specific project, but builds the conditions in which the entire sector can reproduce itself, scale and become independent of imports of ready-made platforms.<a href="#_ftn37" id="_ftnref37">[37]</a></p>



<p>In the legal and economic layer, it is particularly significant that Brave1 is not limited to the distribution of public funds from the Ukrainian budget. Over time, this platform has also been opened to international grants, partnerships with Western states and institutions, and channels of cooperation with the NATO procurement and interoperability environment. This means that the Ukrainian FPV market is today developing at the intersection of national law, mechanisms of public support for innovation, defence cooperation with foreign partners, and the wartime logic of rapid testing and deployment. From this perspective, the success of Ukrainian unmanned production should not be described solely as an industrial success, but also as a success in the design of institutional instruments which have made it possible to combine thousands of smaller entities into one functional ecosystem capable of delivering effects at the scale of millions of units annually.</p>



<p>The mass character of FPV production and the dispersal of suppliers in Ukraine are not solely a spontaneous effect of wartime mobilisation, but the result of the institutional ordering of the defence tech ecosystem. The importance of Brave1 lies precisely in the fact that this platform does not replace the individual manufacturer or the classic armaments industry, but creates an organisational framework within which hundreds – and, according to the available sources, around one and a half thousand – entities can function as elements of a single innovation-production system. From a legal and economic perspective, Brave1 is therefore not merely a sectoral cluster, but an instrument of the state ordering of defence innovation: it shortens the road from idea to test, from test to grant, from grant to implementation, and in the longer perspective – to an order or operational use. This architecture can be described most cleanly at three levels: institutional, project and operational.</p>



<p class="has-pale-pink-background-color has-background"><strong>1. The institutional level</strong></p>



<p>At the institutional level, Brave1 functions as a governmental initiative / defence tech cluster of Ukraine, launched on 26 April 2023 and co-created by the key state organs responsible for security, defence and technology policy, in particular the Ministry of Digital Transformation of Ukraine, the Ministry of Defence, the General Staff of the Armed Forces of Ukraine, the National Security and Defence Council and the Ministry of Strategic Industries. The official description further indicates that the initiative is implemented by the Innovation Development Fund, which allows Brave1 to be treated as an instrument embedded at the interface of public administration, the security sector and state innovation policy. It does not follow from the publicly available materials that Brave1 is a self-standing entity established by a single separate statute or a single specific normative act; it is more accurate to conceive of it as a state coordination platform whose status results from the combination of the competences of public institutions and the implementation mechanisms of the innovation development fund. It is precisely this institutional embedding that explains why Brave1 was able to become a focal point for a broad ecosystem of drone manufacturers, including FPV platforms, instead of remaining merely a grant programme or a sectoral initiative of limited reach.</p>



<p class="has-pale-pink-background-color has-background"><strong>2. The project level</strong></p>



<p>At the project level, the Brave1 cluster has been linked with the European Union-financed undertaking EU4UA Defence Tech, functioning publicly under the title “Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base”. It follows from the available sources that this is not a self-standing act of secondary Union law of the kind of a regulation or directive, but an implementation and grant project, officially announced by the Delegation of the European Union to Ukraine within the EEAS structure, financed by the European Union and implemented by BRDO in cooperation with Brave1. In this architecture, Brave1 plays the role of the Ukrainian cluster and access point to the defence tech ecosystem, while the project layer gives this ecosystem an additional dimension of internationalisation, grant support and linkage with the policy of strengthening the Ukrainian defence technological and industrial base. The formal specification of this layer does not, however, take place through a single “founding act” of statutory or Union rank, but through a set of project and operational documents: the EEAS institutional communication, the BRDO project description and the regulations of the grant programme.</p>



<p>Particularly significant from the point of view of a legal report is that the project layer finds its concrete expression in the draft grant agreement concluded between the Innovation Development Fund and the beneficiary being the developer of a specific technology.<a href="#_ftn38" id="_ftnref38">[38]</a> This means that entry into the Brave1 / EU4UA Defence Tech system does not lead directly to a relationship with a Union institution in the typical model of a European Commission grant, but to a contractual relationship governed by Ukrainian law with a public entity on the Ukrainian side. From this perspective, the project level of Brave1 should be understood as a space in which the dispersed sector of manufacturers – including creators of FPV technology – is drawn into a structured model of public support, but at the price of entering a specific contractual regime. Of particular importance here are the clauses concerning ownership and intellectual property rights: the draft grant agreement provides that ownership rights and rights to IP created with the use of grant funds as a rule remain with the developer, which at first sight may suggest a model friendly to commercialisation and to the retention of private control over the result of the project. At the same time, however, the same draft agreement grants the fund a broad, free-of-charge entitlement to use – at its own discretion – all documents and information obtained in the course of the granting of the grant, insofar as such use remains consistent with existing IP rights. This construction therefore does not lead to a simple takeover of IP by the state, but creates a hybrid model of control in which formal ownership remains with the developer, while the fund secures for itself a strong position of access and use in relation to the documentation and information connected with the project. In legal practice, this means that the key question is no longer only who owns the result, but also how broadly the scope of “documents and information” will be interpreted, what technical material is transferred to the fund, and where the boundary runs between the authorised use of documentation and indirect interference with the developer’s economic exclusivity (in accordance with Article 5(1) and (2) of the grant form: “<em>Ownership rights and property rights to intellectual property created as a result of the use of Grant funds belong to the Developer, unless otherwise specified by the Developer.”; ”The Developer grants the Fund the right to use, free of charge and at its own discretion, all documents and information obtained in the process of providing the Grant, if such use complies with existing intellectual property rights</em>”) (see footnote 38).</p>



<p>This tension is further reinforced by the clause on governing law and disputes, according to which the agreement is to be interpreted under the law of Ukraine, and any disputes are to be resolved first by way of negotiations and then in accordance with the procedure provided for by Ukrainian law and/or before a court. In the functional sense, Brave1 / EU4UA Defence Tech therefore remains an undertaking co-financed and politically legitimised by the European Union, but its contractual core – at least at the level of the relationship with the developer – has a clearly Ukrainian jurisdictional embedding. It is precisely this element that should close the analysis of the project level: Brave1 is not solely a mechanism for stimulating innovation, but also a system in which the Ukrainian state, through the innovation development fund and the contractual template, shapes the rules of access to technology, documentation and the results of R&amp;D work. Thanks to this, the cluster can perform the function of a multiplier of mass and scale of production, but it does so in a formula which combines the retention of private intellectual property with a public safeguarding of informational and operational access. It is precisely this combination – and not the mere number of manufacturers – that explains why the dispersed market of FPV suppliers can be integrated into a single functional ecosystem of state-supported defence capability.<a href="#_ftn39" id="_ftnref39">[39]</a></p>



<p class="has-pale-pink-background-color has-background"><strong>3. The operational level</strong></p>



<p>At the operational level, the basic source document is not a general political communication but the regulations of the grant programme, i.e.&nbsp;the Regulations for the Brave1 EU4UA Defence Tech Grant Program, made available in the Legal Terms section of the programme. It is precisely this document that constitutes the most useful source for practical analysis: it determines the framework of participation, the conditions of application, the function of grant support and the operational rules of the call within the initiative linked with EU4UA Defence Tech. In combination with the EEAS communication and the BRDO project description, this document creates the actual operational basis of the programme: the institutional communication legitimises the project and its financing by the EU, the project description indicates its purpose and place in the architecture of cooperation, while the grant regulations order the manner in which undertakings and technology teams can enter the support system. From the perspective of a legal report, it is precisely this operational layer that is key to understanding how dispersed manufacturers of FPV and other defence technologies have been gathered around a single cluster: not through an abstract political declaration, but through a set of specific procedures, grants, tests, validations and pathways to implementation. As a result, Brave1 operates as an institutional multiplier of production capability – it not only finances innovation but organises its transition into a mass state capability.<a href="#_ftn40" id="_ftnref40">[40]</a></p>



<p>The regulatory consequence of this scale is under-appreciated. Product certification regimes – both aviation and armaments – were built around the assumption of small-series production of goods with a long life cycle and high unit value. A model in which a platform comes into being within a week, is consumed within hours and undergoes continuous design modification in reaction to the adversary’s countermeasures is structurally incompatible with that assumption. No European conformity regime was designed for a product whose iteration cycle is shorter than the conformity assessment cycle.</p>



<p>That is precisely why the Ukrainian mass production of FPV should not be described solely as the result of wartime improvisation or of the cost advantage of a cheap platform over an expensive defensive effector, but also as the result of a consciously built institutional architecture in which Brave1 performs the function of a common node for the state, the military, grant-givers and the dispersed defence tech industry.<a href="#_ftn41" id="_ftnref41">[41]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.3 · Communications, the radio horizon and relays</strong></h3>



<p>The effectiveness of FPV depends on communications to a degree perhaps greater than on the quality of the platform itself, and the absolutely fundamental category here is the <strong>radio horizon</strong>. The radio horizon is not a separate normative concept of EU law or of Polish aviation law, but a technical-operational category describing the limit of effective propagation of a radio signal in communications requiring a line of sight between transmitter and receiver. In practice, this means that the range of control and data transmission depends not only on the power of the devices, but also on antenna height, terrain obstacles, built-up areas, forestation and the shape of the terrain. The legal significance of this category is therefore indirect in character: the concept itself is not regulated as a statutory definition, but the phenomena it describes enter legal analysis through the regime of radio equipment, spectrum management, electronic communications, and the safety and reliability requirements for unmanned operations, especially BVLOS and within U-space.<a href="#_ftn42" id="_ftnref42">[42]</a></p>



<ul class="wp-block-list">
<li><strong>BVLOS – flight beyond visual line of sight, i.e. beyond the operator’s visual range.</strong><br><strong>In practice, it is precisely this category of operations that most needs stable, trusted and legally permissible relay infrastructure.</strong></li>



<li><strong>U-space – simplifying, this is the digital drone traffic management environment, created so that a larger number of drones can fly safely, predictably and in an automated manner, especially in more difficult operations and denser airspace.</strong></li>
</ul>



<p>The control signal and image transmission in classic FPV systems require as clean a line of sight as possible, which is why their propagation is attenuated not only by buildings, forest walls or dense development, but also by the relief of the terrain itself: depressions, escarpments, embankments, forested ridges, rural development and all obstacles that “break” the connection between the operator and the platform. In the realities of the Russo-Ukrainian war, this means that the advantage does not follow solely from the flight parameters of the drone, but from the ability to raise the communications point above terrain obstacles and to maintain a stable transmission channel despite jamming, masking and target movement. Hence the great importance acquired by relays – signal repeaters mounted on masts, on ground vehicles, and most often on separate drones hovering higher than the combat platform. In the simplest variant, such a relay is a separate item of equipment, a kind of “communications superstructure” added to the system; in more advanced solutions, the relay function becomes part of a larger architecture, in which one drone carries the payload, a second observes, a third provides retransmission, and further nodes take over part of the traffic in a network model. This means that the relay need not be understood solely as a single device purchased separately – increasingly it is a separate technological layer, which may take the form of a radio module, an additional aerial platform, a ground set, or a node in a mesh network. It is precisely here that one of the most interesting trends appears: the transition from a single repeater to a layered architecture, and then to dynamic mesh networks, in which every modem or selected platforms can simultaneously transmit and repeat the signal, creating a self-repairing chain of communications. In such an arrangement, the radio horizon problem is no longer solved by a single device, but by a system of systems, functionally approaching a swarm with a division of roles. This in turn means that <strong>the most valuable IP in this segment may not reside in the airframe at all, but in the signal-routing algorithms</strong>, <strong>node switching, jamming resistance, bandwidth management and the integration of the relay function with the combat or reconnaissance role</strong>. Competitive advantage may here be protected as a patent, software, a trade secret or systemic know-how; in practice, value increasingly shifts from “the drone itself” to the communications and control architecture which allows the platform to operate effectively outside the classic line of sight. In this sense, the fight for advantage in the air simultaneously becomes a fight over who will build a higher-elevated, more resilient and more intelligently managed transmission network than the adversary.</p>



<p>This architecture has legal significance extending beyond the battlefield. <strong>Retransmission</strong> is in essence the construction of an <strong>ad hoc, mobile radio communications network</strong> – and thus an activity which, in the civil regime, is subject to electronic communications law, spectrum management and the requirements of Directive 2014/53/EU on radio equipment. The civil equivalent of this architecture – relay networks for BVLOS operations – is one of the fundamental implementation challenges of the U-space framework.</p>



<p><strong>RED 2014/53/EU – this is the radio equipment regime, i.e.&nbsp;not only “does the drone work”, but whether its communications modules:</strong></p>



<ul class="wp-block-list">
<li><strong>lawfully use the spectrum,</strong></li>



<li><strong>do not interfere with other systems,</strong></li>



<li><strong>are safe and electromagnetically compatible.</strong></li>
</ul>



<p>The retransmission architecture has legal significance extending far beyond the battlefield, because from the civil perspective it in essence means the construction of an <strong>ad hoc, mobile electronic communications network for unmanned operations</strong>. What in wartime conditions takes the form of an improvised or semi-improvised radio bridge between operator and drone becomes, in the civil environment, a multi-layered issue: <strong>it concerns not only the aircraft itself, but also radio equipment, frequencies, electromagnetic compatibility, data integrity, network resilience and liability for the continuity of the communications service</strong>. For this reason, at least three legal orders enter here in parallel.<a href="#_ftn43" id="_ftnref43">[43]</a> First, the law of electronic communications and spectrum management, because the relay is no longer merely “part of the drone”, but an element of transmission infrastructure affecting the <strong>radio spectrum and requiring conformity with the rules on the use of bands</strong>. Second, Directive 2014/53/EU (RED), i.e.&nbsp;the radio equipment regime, whose essence is to ensure that equipment uses the spectrum efficiently, does not interfere with the operation of other systems and satisfies safety and compatibility requirements. Third, the U-space framework, which is not “a single drone system” but a regulatory model of highly digitalised and partly automated management of a large number of unmanned operations, in particular also BVLOS (beyond visual line of sight) flights. Relay networks for BVLOS operations therefore in practice mean a model in which the continuity of the flight does not depend on a simple, linear operator-drone connection, but on an entire chain of communications services, identification, data transmission and coordination with the digital airspace. That is precisely why one of the main implementation challenges of U-space is not the mere fact that the drone flies beyond visual range, but who is responsible, and on what terms, for the communications layer sustaining such a flight: for the reliability of the channel, the interoperability of the equipment, information security, jamming resistance, cybersecurity and the technical conformity of the entire transmission chain. In civil conditions, the problem which at the front is solved by an improvised relay or a mesh network therefore becomes a regulatory problem of the highest rank: the question is no longer only whether the drone may fly, but whether there exists a lawful and secure communications infrastructure allowing it to fly outside the simple logic of direct contact.<a href="#_ftn44" id="_ftnref44">[44]</a></p>



<p>If, however, the relay and the mesh network<a href="#_ftn45" id="_ftnref45">[45]</a> are an attempt to solve the radio horizon problem within the logic of radio emission, then fibre-optic drones represent an attempt to step outside that logic altogether. Whereas the relay architecture endeavours to elevate, stabilise and disperse the signal, the optical fibre eliminates the need for its emission in radio space, and thereby undermines a considerable part of the existing assumptions of both counter-drone technologies and regulation based on the detectability and jammability of the signal.</p>



<p><strong>Mesh network, Shahed/Geran and the shift from loitering munition to a networked strike system</strong></p>



<p>One of the most interesting and at the same time most disturbing phenomena of the current phase of the drone war is the transition from a simple point-to-point control model to a mesh network architecture, that is a lattice or grid network. Unlike the classic arrangement in which the operator communicates directly with a single platform or via a single relay, the mesh network consists of many nodes capable of simultaneously receiving, forwarding and amplifying the signal. Each such node can be part of a larger transmission system: a ground modem, an intermediate station, an observation platform or the drone itself. In practice, this means that communications do not depend on one channel and one transmission route, but can be dynamically reconfigured depending on which elements of the network remain active, where the platforms are located and what the jamming environment looks like. That is precisely why the mesh network is an architecture more resilient, flexible and difficult to disable than a classic linear connection. It is no longer a “link to the drone”, but a dispersed operational network.</p>



<p>In relation to heavy platforms of the Shahed/Geran type, such an architecture has breakthrough significance, because it blurs the boundary between a loitering munition and a network-controlled or network-supervised drone. Traditionally, loitering munitions are perceived as an essentially single-use means flying along a route programmed in advance or corrected to a limited extent. Meanwhile, equipping heavy drones with mesh modems, retransmission nodes and external relay points means that the system ceases to be merely a “blind carrier” executing a sequence of commands recorded once. It enters a more flexible model: it can maintain communications deeper over the adversary’s territory, benefit from mutual signal amplification, and in some configurations also from more up-to-date mission supervision. It is precisely for this reason that analysts speak of the blurring of the boundary between the classic loitering munition and the one-way attack UAV with elements of networked command. In other words: if the “Shahed” begins to function as part of a communications system, it ceases to be solely a single-use kinetic effect and begins to resemble a networked means of aerial attack, whose effectiveness depends not only on the airframe and warhead, but on the data transmission architecture.</p>



<p>This is very well illustrated by the Belarusian case from the beginning of 2026, when reports appeared in the analytical space of Russia’s use of relay stations and other network nodes supporting the flights of Shaheds operating from that direction, and subsequently of their elimination by the Ukrainian side.<a href="#_ftn46" id="_ftnref46">[46]</a> Even if part of the details of those events remains based on front-line, technical and media sources rather than on full, open official material, the operational sense of such a solution is itself logical and coherent: if the platform is to fly deep, maintain communications and benefit from the effect of mutual retransmission, then the network cannot end at the drone itself. It must have external nodes sustaining the communications architecture, whether in the form of border stations, relay towers, ground amplification points or other supporting elements. The destruction of such nodes does not mean the destruction of a single drone, but a strike at the network layer which makes the entire system more dangerous. In this sense, Ukraine is not merely destroying the carrier of a warhead, but degrading the communications infrastructure of the attack.</p>



<p>Technologically, the most dangerous aspect is that the mesh network changes the logic of defence. In the classic model, it was enough to cut the connection, destroy the platform or jam a single channel. In the grid model, the adversary can attempt to:</p>



<ul class="wp-block-list">
<li><strong>redirect traffic along another route,</strong></li>



<li><strong>use other drones as relays,</strong></li>



<li><strong>dynamically change the structure of communications,</strong></li>



<li><strong>combine strike, reconnaissance and retransmission platforms into a single arrangement.</strong></li>
</ul>



<p><strong>This in turn naturally brings such a system closer to a swarm with a division of roles</strong>. Not all platforms have to attack. Some may perform the role of:</p>



<ul class="wp-block-list">
<li>communications nodes,</li>



<li>observers,</li>



<li>decoys,</li>



<li>retransmission carriers,</li>



<li>elements building the resilience of the network.</li>
</ul>



<p>This means that advantage increasingly depends not on a “better drone” but on a better systemic architecture. It is precisely here that IP of the highest value is born: not in the airframe itself, but in the modems, transmission protocols, routing algorithms, jamming resistance, throughput management, node authorisation and the integration of the relay role with the combat role. Solutions of this kind may be protected as a patent, software, a trade secret or systemic know-how. In practice, market and military value therefore shifts from the individual product to the network architecture, which may be more difficult to copy than the drone itself.</p>



<p>This shift also has very significant legal consequences. First, the mesh network is not directly a legal category of aviation law or EU drone law; it is above all a technical concept. However, its legal significance is indirectly enormous, because it describes the structure of communications on which the operation of unmanned platforms depends. The moment such a network is analysed outside the theatre of hostilities, we immediately enter the area of electronic communications law, spectrum management and the radio equipment regime. For if the effectiveness of the drone depends on a dispersed arrangement of transmitters, modems and relay nodes, then we are no longer dealing solely with an aircraft, but with regulated communications infrastructure. Here, Directive 2014/53/EU (RED) gains significance, because all radio transmission modules – especially when they form a system of mutual relays – must be analysed from the perspective of the efficient use of the spectrum, electromagnetic compatibility and equipment safety. In such a framing, the mesh network is not only a technical feature but a question of whether the radio network being built conforms to the rules on the use of bands and does not generate new risks for other communications systems.</p>



<p>Second, the mesh network has a cybersecurity and information security dimension. Every additional node means not only greater flexibility of the communications architecture, but also a greater attack surface: more points vulnerable to takeover, impersonation of an authorised element of the system, spoofing, jamming or the injection of false data. The injection of false data should here be understood as the introduction into the network of signals, messages or parameters which appear authentic but are intended to mislead the other nodes, cause an erroneous reconfiguration of connections, direct the platforms along another route or distort the picture of the operational situation. The more the system passes from a simple point-to-point connection to a dispersed lattice network, the more crucial becomes not the mere transmission of the signal, but trust in its source, integrity and authenticity. That is precisely why mesh technology shifts the analysis from the level of simple drone control towards the issues of node authorisation, data integrity and the resilience of the communications architecture to manipulation.</p>



<p>The legal dimension of this phenomenon is multi-layered. First, the more the effectiveness of the system depends on a multi-node transmission architecture, the less sufficient it is to treat it solely as an aircraft, and the more necessary it becomes to conceive of it as an element of regulated radiocommunications infrastructure – and thus also through the prism of the radio equipment regime, spectrum use and electromagnetic compatibility, with which the significance of Directive 2014/53/EU (RED) is indirectly connected. Second, the strategic value of the system shifts from the airframe itself to the modems, antennas, amplifiers, jamming-resistance systems and routing software, which reinforces their significance as dual-use components. Third, the mesh architecture creates the conditions for dispersed functional autonomy: it enables the redirection of the flight during the mission, the use of other platforms as relays, the dynamic alteration of the communications structure and the combination of strike, reconnaissance and retransmission platforms into a single arrangement. In the case of heavy Shahed/Geran drones, this leads to the blurring of the boundary between the classic loitering munition and a network-supported means of aerial attack. The reports of the use of external relay stations on the Belarusian direction and of their elimination by the Ukrainian side show well that the object of the fight is now not only the drone itself, but also the communications layer which sustains its operation. In this sense, the drone war simultaneously becomes a war for control over dispersed data transmission infrastructure.</p>



<p>In a dispersed communications system, security no longer depends on a single link, but on the integrity of the entire arrangement of mutual trust between nodes. This makes the legal analysis of such systems naturally shift also towards questions of:</p>



<ul class="wp-block-list">
<li>signal integrity,</li>



<li>device authorisation,</li>



<li>resistance to manipulation,</li>



<li>the security of data transmitted between nodes,</li>



<li>and, in the civil equivalent, also towards regimes functionally approximating the requirements imposed on high-risk digital infrastructure.</li>
</ul>



<p>Third, mesh technology has an obvious significance for dual-use export control. While the airframe itself may be relatively simple, the true value and strategic sensitivity is concentrated in the communications components: modems, amplifiers, antennas, jamming-resistance systems, routing and network management software. It is precisely these elements that most easily move from the civil market to the military one and vice versa. In consequence, the components building mesh networks may be analysed not only as part of the end product, but as self-standing dual-use components, whose export, technical transfer and integration may be subject to a separate licensing and security assessment.</p>



<p>Fourth, the mesh network leads us to the boundary of the issues of AI and functional autonomy. The lattice network itself is not yet artificial intelligence, but when it begins to support:</p>



<ul class="wp-block-list">
<li>automatic selection of the signal route,</li>



<li>adaptive node switching,</li>



<li>coordination of multiple platforms,</li>



<li>sharing of observations and targeting data,</li>



<li>maintenance of the mission despite the loss of part of the system’s elements,</li>
</ul>



<p>then in practice we approach an architecture in which operational decisions no longer flow solely from a direct human command, but from the dispersed operation of the system. This gives rise to the classic questions of responsibility, predictability and the qualification of such a network as an element of a more autonomous means of warfare. In the European context, this tension is particularly interesting, because civil applications of AI and communications are subject to ever greater regulation, while military applications of networked autonomy remain to a large extent outside the scope of the classic civil conformity regimes.</p>



<p>Finally, from the perspective of the law of armed conflict, the mesh network changes the very object of what is regarded as a significant component of combat capability. If the effectiveness of the system depends on a dispersed layer of relays, modems and relay stations, then the target of military significance becomes not only the drone itself, but also the communications infrastructure sustaining its operation. This shifts the analysis from the level of the individual effector to the level of the entire network architecture. One might say that, in such a model, the drone war is becoming to an ever greater degree a war for control over the aerial and border-zone tactical internet.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>2.4 · Fibre-optic drones – the end of the jamming era</strong></h3>



<p>The breakthrough proved to be drones controlled by <strong>optical fibre</strong> – a spool of thin glass fibre unwound in flight. The solution has its costs (the mass of the fibre limits range, payload and manoeuvrability), but it eliminates two problems at once: the radio horizon ceases to matter, and the drone cannot be jammed, because it emits no radio signal. It is an electronically “mute” platform – practically undetectable by RF detectors and resistant to electronic warfare.</p>



<p>Fibre-optic drones appeared en masse in August 2024 in the Kursk area,<a href="#_ftn47" id="_ftnref47">[47]</a> where Russian platforms of this type – with a range of over 30 km and a “crystal-clear” image – paralysed Ukrainian logistics along the sole supply route. As one Ukrainian medic put it, logistics simply collapsed, because fibre-optic drones were monitoring all the routes. By January 2026, fibre-optic variants accounted in some sectors for 30–50% of Russian FPV operations and around 15% of Ukrainian ones. In 2025, countering fibre-optic drones became the central theme of the NATO Innovation Challenge.<a href="#_ftn48" id="_ftnref48">[48]</a></p>



<p>The regulatory significance of this category is difficult to overestimate and remains unnoticed in the public debate. <strong>The entire European acquis on countering unauthorised unmanned operations – both technical and normative – rests on the assumption that the drone emits a radio signal</strong>.<a href="#_ftn49" id="_ftnref49">[49]</a> On this assumption were built the remote identification requirement, RF detection systems, the jamming powers granted to the services and, from June 2026, to critical infrastructure operators. The fibre-optic platform invalidates each of those mechanisms simultaneously. Regulation aimed at a specific relay technology ages faster than the legislative process in which it comes into being.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.5 · Electronic warfare and spoofing</h3>



<p>Classic <strong>jamming</strong> consists in generating noise on radio frequencies so that the drone cannot distinguish the operator’s signal from the interference and loses control. For platforms flying to preset coordinates (deep strike), <strong>spoofing</strong> is used instead – the substitution of the satellite navigation signal, as a result of which the drone “thinks” it is somewhere else and corrects its flight in the wrong direction.</p>



<p>This distinction translates directly into the choice of defensive means – but also into legal qualification. <strong>Jamming is an interference with the radio spectrum</strong>, and thus with a good administered by the state and protected by electronic communications provisions; <strong>spoofing is an interference with the integrity of the signal of a satellite navigation system</strong>,<a href="#_ftn50" id="_ftnref50">[50]</a> and thus with infrastructure of a global character, the disruption of which has effects far beyond the target. The side effects of both measures – loss of the GNSS signal by civil aviation, maritime transport, power grids synchronised by satellite time – are a classic example of damage in which establishing the causal link and the responsible entity is exceptionally difficult. We return to this issue in section 4.3.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">2.6 · Heavy platforms – bombers, wings, loitering munitions</h3>



<ul class="wp-block-list">
<li><strong>Heavy bombers</strong> (Ukr. Vampire,<a id="_ftnref51" href="#_ftn51">[51]</a> colloquially “Baba Yaga”<a id="_ftnref52" href="#_ftn52">[52]</a>) – multirotors carrying anti-tank mines and performing logistics tasks (transport of ammunition, water, medicines). They require heavier means of engagement – 12.7/14.5 mm machine guns with thermal imaging.</li>



<li><strong>Light wings</strong> (Rus. Molniya<a id="_ftnref53" href="#_ftn53">[53]</a>) – cheap long-range airframes, of low precision but mass-produced; they are sometimes armed with incendiary charges.</li>



<li><strong>Loitering munitions</strong> (Rus. Lancet,<a id="_ftnref54" href="#_ftn54">[54]</a> Ukr. Bulava,<a id="_ftnref55" href="#_ftn55">[55]</a> Pol. Warmate<a id="_ftnref56" href="#_ftn56">[56]</a>) – advanced platforms for the elimination of artillery and anti-aircraft systems; difficult to shoot down owing to low-detectability materials and their flight profile.</li>
</ul>



<p>The category of loitering munitions deserves separate legal attention. It is a construction at the boundary between an unmanned aircraft and a missile: a platform which remains in the task area for an extended time, searching for a target, and then carries out the strike. The blurring of the boundary between “aircraft” and “munition” has consequences in each of the regimes analysed – from classification on the control list of dual-use items, through the intra-EU transfer regime, to the question of the character of human control over the use of force.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-b829efbeca099a974d06d935cfe43b95">2.7 · Deep strike and autonomy – Fire Point as a case study</h3>



<p>The highest tier consists of heavy long-range platforms. The model example is the Ukrainian <strong>FP-1.</strong> The Ukrainian FP-1,<a href="#_ftn57" id="_ftnref57">[57]</a> developed by Fire Point, is a one-way strike drone of light construction,<a href="#_ftn58" id="_ftnref58">[58]</a> including fuselage elements made of plywood, powered by a two-cylinder engine; industry and media sources estimate its unit cost at approximately USD 55,000–58,000, i.e.&nbsp;significantly below the level of comparable systems. In mid-2025, a rapid increase in the scale of production was reported, already counted in hundreds of units weekly and over 100 units daily, and in July 2026 drones attributed to the FP-1 family were linked to the strike on the refinery in Omsk, one of the deepest Ukrainian long-range attacks.<a href="#_ftn59" id="_ftnref59">[59]</a></p>



<p>This case study is instructive for three reasons. First, it shows the <strong>inversion of the classic cost curve</strong> of the defence industry: a construction made of commercially available materials achieves an operational effect comparable to systems of many times higher cost. Second, it demonstrates the <strong>scalability of production outside the traditional armaments chain</strong> – growth from 30 to over 100 units daily within a few months is difficult under the regime of classic military certification. Third, this problem illustrates that range is not solely a technical parameter, but also a regulatory category. This follows from the logic of the Missile Technology Control Regime (MTCR), which – although it is not a classic international agreement in treaty form, but an informal export control regime based on common guidelines and a control annex – has long covered not only classic missiles but also unmanned aerial systems capable of carrying a payload over considerable distances. The most restrictive layer, i.e.&nbsp;Category I, encompasses complete rocket systems and unmanned aerial systems capable of delivering a payload of at least 500 kg to a range of at least 300 km, together with specified subsystems and technologies. This means that a platform with a range exceeding 2,500 km – even if it does not always satisfy every historical parameter of a classic missile system – enters the same type of strategic regulatory sensitivity which for decades has triggered the sharpest logic of proliferation control. In European practice, this logic was subsequently absorbed into the dual-use regime, in which references to the MTCR remain an element of the system of control of exports of technology and means of delivery (in EU law, the logic of the Missile Technology Control Regime (MTCR) was taken over into the system of control of exports of dual-use items primarily by Regulation (EU) 2021/821, which in recital 3 refers to the multilateral export control regimes, including expressly the MTCR, and then develops this logic operationally in Annex I, containing the EU dual-use control list). In this sense, great range is not merely an engineering feature, but a legally relevant feature, because from a specified threshold it triggers a normative order closer to proliferation control, export control and strategic security than to the ordinary regulation of a civil UAV.<a href="#_ftn60" id="_ftnref60">[60]</a></p>



<p>The boundary between control and autonomy is blurring. Placing a satellite communications terminal on a drone allows it to be controlled from enormous distances; the use of machine vision algorithms enables autonomous terminal guidance onto the target after loss of communications.<a href="#_ftn61" id="_ftnref61">[61]</a> It is precisely this last feature – <strong>terminal autonomy, i.e.&nbsp;the capability to complete the task without a human in the decision loop</strong> – that is the heart of the legal problem to which we now turn.</p>



<p>Conceptual precision, usually lacking in the public debate, is worth preserving here. Autonomy is not a binary feature but a spectrum encompassing at least: (i) flight stabilisation and route keeping, (ii) navigation without a satellite signal using terrain image correlation, (iii) automatic detection and classification of objects, (iv) automatic tracking of a target designated by the operator in the terminal phase, (v) independent selection of a target within a designated area. Legal regimes – both the EU Artificial Intelligence Act and the discussion of autonomous weapon systems within the framework of the CCW Convention – react differently to each of these levels, and the distinction between (iv) and (v) is in practice the most difficult to prove in evidentiary proceedings and at the same time the most legally momentous.<a href="#_ftn62" id="_ftnref62">[62]</a></p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-c24f92bca5ae43f507f4405514293ee8">2.8 · The countermeasure layer – a C-UAS taxonomy</h3>



<p>Symmetrically to the strike layer, the countermeasure layer (_counter-UAS_, C-UAS) has developed, which for the European civil market today has greater economic significance than the strike layer itself. Its taxonomy comprises two segments.</p>



<p><strong>Detection and identification:</strong> radio sensors (monitoring of control and image-transmission bands), low-power radars, acoustic sensors, optoelectronic systems with a thermal channel, and – increasingly – fusion of data from multiple sensors with machine-learning-based classification. It is precisely in this segment that artificial intelligence performs a critical role, and it is precisely this segment that is fully civil, and therefore covered by the EU regime without exclusions.</p>



<p><strong>Neutralisation:</strong> jamming of the control link and image transmission, spoofing of satellite navigation, taking over control of the platform, mechanical means (nets, including those launched from interceptor platforms), kinetic means (from smoothbore weapons to artillery systems with programmable ammunition), directed energy (lasers, high-power pulse) and interceptor drones.</p>



<p>This distinction is legally significant, because <strong>each of the effectors is subject to a different regime</strong>: jamming and spoofing fall under electronic communications law and spectrum management; kinetic means fall under the law on weapons and ammunition and liability for damage caused by falling debris; taking over control is an interference with an ICT system, and thus potentially an act criminalised under criminal law if it does not have an express statutory basis. A separate problem is that effective detection requires data processing – on which see section 3.7.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-fc4ca7a709b60c51cc6529ffa9fbd3e2">2.9 The kill chain and the place of the human in the loop</h3>



<p>For the legal analysis of autonomy, it is indispensable to break the process down into links. Adopting a simplified model of the kill chain: <strong>a)</strong> <strong>detection b) identification and classification c) prioritisation d) engagement decision e) terminal guidance f) effects assessment</strong>. The debate on “meaningful human control” in essence concerns the question in which of these links the human takes the constitutive decision and whether at that moment he has information and time sufficient for that decision to be real rather than formal in character.</p>



<p>In the practice of contemporary drone operations: the first and second links are increasingly automated (image classifiers), the fourth link remains on the human side, and the fifth link is sometimes autonomous out of technical necessity – after loss of the link. Legally, this means that <strong>the “human in the loop” construction rests on a link of which the adversary consistently tries to deprive it</strong>. The argument that loss of communications is a technical circumstance and not a design decision loses its force at the moment when the manufacturer designs the platform on the assumption of operation in a heavily jammed environment.</p>



<p>An analogous structure – with different consequences – occurs on the civil side. Article 14 of the Artificial Intelligence Act requires that a high-risk system be designed so that natural persons can effectively oversee it, including understanding its limitations, correctly interpreting its output and deciding not to use it or to interrupt its operation. This requirement is technically identical to the postulate of meaningful human control – with the difference that on the civil track it is a legal norm backed by a sanction, while on the military track it remains the subject of unfinished international negotiations.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-2017345879af2cf699291d5c1d972a9a">2.10 · The data layer – the drone as a sensory platform</h3>



<p>The last layer, systematically omitted in technical analyses, is the data layer. Each of the platforms described is above all a <strong>sensor generating a stream of data</strong>: visual and thermal imagery, telemetry, position, radio spectrum parameters. The operational value of an unmanned system today lies to a lesser degree in the platform and to a greater degree in the chain of processing of those data – from transmission, through storage and annotation, to use in training image-recognition models.</p>



<p>From this arises a chain which crosses the civil-military boundary in both directions. Collections of recordings from combat operations constitute training material of a value impossible to obtain in laboratory conditions – and they are used to perfect classifiers, which subsequently find their way into civil systems (infrastructure monitoring, border protection, crisis management). In the other direction: models trained on civil collections of aerial imagery constitute the base for target-recognition systems.</p>



<p>This bidirectional flow is – as we demonstrate in section 4.5 – the area in which the EU data protection and artificial intelligence regimes come into contact with the defence exclusions in the manner that is legally most unclear and practically most momentous.</p>



<h3 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-b40798181a77e5f0106eeefd5df8d31e">2.11 · The innovation spiral as a law of development</h3>



<p>Drone warfare is a spiral process: each innovation provokes a countermeasure, and that forces the next innovation: the observation Mavic; drops; FPV; jamming; the relay; the optical fibre; satellite communications; satellite jamming; AI autonomy; interceptor drones.</p>



<p>For the regulator, this means that <strong>every norm aimed at a specific technology ages at the pace of that spiral</strong>. This is an argument in favour of regulation based on effects and on the level of risk, rather than on a catalogue of technical solutions – and at the same time an explanation of why acts based on risk classification (the Artificial Intelligence Act) have a greater chance of remaining current than acts based on product catalogues (dual-use control lists, classes C0–C6).</p>



<h2 class="wp-block-heading has-vivid-cyan-blue-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-1035e1196f56a434e54324ff2724ae0c"></h2>



<div class="wp-block-media-text has-media-on-the-right is-stacked-on-mobile"><div class="wp-block-media-text__content">
<h3 class="wp-block-heading has-vivid-red-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color wp-elements-3a45f71ad483e1cd03cf6eadb1a92188">3 · The Legal Environment – Nine Pillars</h3>
</div><figure class="wp-block-media-text__media"><video controls src="https://www.kg-legal.eu/wp-content/uploads/2026/08/output-1-1.mp4"></video></figure></div>



<p>The legal environment of the UAV sector is not one act or one branch. It is a lattice of regimes, which it is worth ordering into nine pillars. Below, we furnish each of them both with its legal basis and with a practical “flavour” relevant to the servicing of entities in the sector.</p>



<p>The original version of this taxonomy comprised seven pillars. The extension by two further ones – personal data protection and data governance, and public international law – is not a tidying-up exercise. It follows from the observation made in section 2.10: since the value of the unmanned system has shifted from the platform to the data, the data regime has ceased to be a side issue and has become one of the two or three pillars determining the business model. International law, in turn, is the only regime which covers the space left by the defence exclusions of EU law – and therefore precisely the space in which the revolution described above is playing out.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>3.1 · Pillar I – UAV categories and airspace</strong></h3>



<p>The core of the civil regime is formed by three related acts founded on the basic Regulation (EU) 2018/1139 (EASA): <strong>Delegated Regulation (EU) 2019/945</strong> (product requirements, classes C0–C6, CE marking) and <strong>Implementing Regulation (EU) 2019/947</strong> (operations in the open, specific and certified categories). The spatial layer is completed by the U-space package: <strong>Implementing Regulation (EU) 2021/664</strong> together with 2021/665 and 2021/666.</p>



<p>The architecture of this pillar rests on two independent axes of qualification, the confusion of which is the most frequent error in the practice of the industry. The first axis – the <strong>product axis</strong> – concerns what the device is: classes C0–C6 lay down construction requirements, including the obligation to be equipped with a remote identification system and a geo-awareness function for the higher classes. The second axis – the <strong>operational axis</strong> – concerns what is done with it: the open category covers low-risk operations within visual range, the specific category requires an authorisation based on a risk assessment (the SORA methodology) or a declaration of conformity with a standard scenario, and the certified category brings the regime close to classic manned aviation.</p>



<p>The U-space layer, in turn, introduces mandatory services in designated airspaces: network identification, geo-awareness, traffic information and flight authorisation, provided by certified service providers.</p>



<p><strong>The practical dimension is therefore that</strong> the regime is not static. Regulation 2019/947 has applied in its consolidated version since 1 May 2025, and the U-space framework was reinforced by <strong>Regulation (EU) 2023/203</strong>, which added information security requirements – risk assessment, management and incident response. Of key interpretative importance is therefore the revision of the Easy Access Rules for UAS of June 2026, consolidating the AMC/GM to Regulation 2019/947 (ED Decision 2025/018/R). From 1 January 2026, flights in standard scenarios require platforms holding a class C5 or C6 certificate. In a broader perspective, this confirms that in the UAV sector law does not end with the text of the regulation itself, but also functions in the executive, interpretative and operational layer. It is precisely at this level – through the AMC, GM and their consolidation in the Easy Access Rules – that general norms are translated into compliance practice, risk assessment, operational documentation and the everyday application of the law by operators, manufacturers, advisers and supervisory authorities. As a result, an analysis of the legal environment of drones requires account to be taken not only of the formally binding provisions, but also of how they are operationalised in executive and interpretative materials, because it is only there that the real regulatory weight of the sector is revealed. <strong>AMC (Acceptable Means of Compliance) and GM (Guidance Material)</strong> do not have the character of independently binding provisions of the rank of a regulation, but they perform a fundamental interpretative and practical function: they show how entities can demonstrate conformity with the requirements arising from Regulation (EU) 2019/947 and how authorities and operators should understand the individual obligations in operational practice. That is precisely why the Easy Access Rules for Unmanned Aircraft Systems are of such great importance for the UAV sector – they do not create new law, but order, consolidate and operationalise the normative material and its interpretation, becoming in practice the basic working tool for operators, manufacturers, advisers and supervisory authorities.<a href="#_ftn63" id="_ftnref63">[63]</a></p>



<p><strong>A systemic remark</strong>: this entire pillar concerns civil aviation exclusively. Article 2(3)(a) of Regulation 2018/1139 excludes from its scope of application aircraft carrying out military, customs, police, search and rescue, firefighting, border control and coastguard operations. The first and most far-reaching defence exclusion therefore appears already at the level of the foundation, and not only in the Artificial Intelligence Act. This means that the boundary between the civil and the defence order is drawn already in the EASA basic regulation itself: it is that regulation which determines that the development, certification and operation of military unmanned systems are not subject to the EU regime of common civil aviation rules, but remain within the domain of the competence of the Member States, their defence policies and the relevant national security regimes. From the perspective of an analysis of the UAV sector, this is of fundamental importance, because it shows that the dual-track nature of the regime does not begin at the stage of AI, autonomy or export control, but already at the level of the most basic question of whether a given aircraft is subject to common European aviation law at all. In practice, this means that identical or nearly identical technology may be covered by the full civil conformity regime if it functions on the commercial market, while at the same time remaining outside that regime if it is incorporated into a military operation or one directly connected with it.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.2 · Pillar II – Artificial intelligence and decision-making autonomy</h3>



<p><strong>Regulation (EU) 2024/1689</strong> (the Artificial Intelligence Act, “AI Act”) introduces a risk-based classification: prohibited practices (Article 5), high-risk systems (Article 6 in conjunction with Annexes I and III), systems subject to transparency obligations (Article 50), general-purpose models (Articles 51–55) and the remainder, not covered by substantive obligations.</p>



<p>For the UAV sector, however, what is decisive is not what the act regulates, but <strong>what it does not regulate</strong>. Article 2(3) provides:</p>



<p>“<em>This Regulation does not apply to AI systems where and in so far they are placed on the market, put into service, or used with or without modification <strong><u>exclusively</u></strong> for military, defence or national security purposes</em>.” – Article 2(3) of Regulation (EU) 2024/1689.</p>



<p>The consequence is paradoxical: <strong>a civil drone with AI is subject to the full high-risk regime, while a technologically identical platform used “exclusively” for military purposes remains outside the scope.</strong> The criterion is not the technology, but the purpose of use. Lethal autonomous weapon systems (LAWS) therefore remain outside the EU regime; the matter is the subject of international law and NATO doctrines, and the European Parliament has repeatedly warned against the Union’s regulatory backwardness in this area. The European Parliament was one of the earliest institutional actors to take up the subject of autonomous weapon systems and military AI, adopting already in 2018 a resolution on LAWS, and then in 2021 a resolution relating to artificial intelligence in the military and civil context.<a href="#_ftn64" id="_ftnref64">[64]</a></p>



<p>Key, however, is the word <strong>“exclusively”</strong>. Recital 24 of the preamble specifies that if the system is also used for purposes other than military, defence or national security – even temporarily and even by another entity – the exclusion does not apply to that extent. For a dual-use manufacturer, this means that <strong>the exclusion is not a feature of the product, but a feature of the specific placing on the market or putting into service</strong>. The same product series sold simultaneously to a military purchaser and to a critical infrastructure operator is, in the second case, subject to the full regime – and the manufacturer must be able to document this duality, separate the product lines and demonstrate it in the event of an inspection.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">Qualification of a drone system as a high-risk system</h3>



<p>In practice, the classification proceeds along two independent tracks:</p>



<ul class="wp-block-list">
<li><strong>Article 6(1) (Annex I)</strong> – an AI system is high-risk if it constitutes a safety component of a product covered by the Union harmonisation legislation listed in Annex I, and that product is subject to third-party conformity assessment. Section B of Annex I expressly lists Regulation (EU) 2018/1139. <strong>This means that control software performing a safety function in a certified unmanned system may be a high-risk system on precisely this basis</strong> – a circumstance still under-appreciated in market practice, because the discussion concentrates almost exclusively on Annex III.</li>



<li><strong>Article 6(2) (Annex III)</strong> – covers, inter alia, the management of critical infrastructure, law enforcement, and migration management and border control. Drone systems used by border services or critical infrastructure operators fall here directly.</li>
</ul>



<p>The consequence of qualification is the set of obligations under Articles 8–15: a risk management system, data and data quality governance (Article 10), technical documentation (Article 11), automatic recording of events (Article 12), transparency and information for the user (Article 13), human oversight (Article 14) and accuracy, robustness and cybersecurity (Article 15) – and, on the procedural side: conformity assessment, the EU declaration, CE marking and registration in the EU database.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">The calendar – amended in June 2026</h3>



<p>Market practice planned compliance for over a year around the date of 2 August 2026. That date has changed. On 19 November 2025, the Commission presented a simplification package (the Digital Omnibus), whose part concerning artificial intelligence – after the unsuccessful trilogue of 28 April 2026 and the political agreement of 6–7 May 2026 – was finally approved by the Council on <strong>29 June 2026</strong> (Parliament: 16 June 2026). The result is a postponement:</p>



<ul class="wp-block-list">
<li>obligations for standalone high-risk systems under Annex III – <strong>2 December 2027</strong>;</li>



<li>obligations for AI embedded in regulated products under Annex I (and thus, inter alia, unmanned systems) – <strong>2 August 2028</strong>;</li>



<li>transparency obligations under Article 50 – <strong>unchanged, 2 August 2026</strong>;</li>



<li>Article 50(2) (marking of generated content) in relation to systems already present on the market, and the new prohibitions – <strong>2 December 2026</strong>.</li>
</ul>



<p>The postponement is conditional in character and is linked to a readiness mechanism: the registration of systems in the EU database and the availability of harmonised standards. The following, by contrast, apply unchanged: the prohibitions under Article 5 (from 2 February 2025), the AI literacy obligation under Article 4 (from 2 February 2025) and the general-purpose model regime (from 2 August 2025).<a href="#_ftn65" id="_ftnref65">[65]</a></p>



<p><strong>In practice,</strong> the postponement is not a relief but a shift. The task which cannot be omitted or accelerated is the inventory of AI systems in the organisation and the assignment of each of them to the appropriate category – work independent of the state of the harmonised standards. In addition, the grandfathering principle applies: systems placed on the market before the date of application are not subject to the obligations until they are substantially modified – which, in a sector with an iteration cycle counted in weeks, is a guarantee of limited value.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><a>3.3 · Pillar III – Dual-use products and export control</a></h3>



<p><strong>Regulation (EU) 2021/821</strong> establishes the Union’s system for the control of exports of dual-use items; it entered into force on 9 September 2021, replacing Regulation (EC) No 428/2009, and has applied in its consolidated version since 15 November 2025. On 8 September 2025,<a href="#_ftn66" id="_ftnref66">[66]</a> the Commission updated Annex I (the control list), covering emerging technologies – which directly affects drone components, electronics and AI software.</p>



<p>Four mechanisms of this regime are significant for the unmanned sector:</p>



<p>1. <strong>The control list (Annex I)</strong> – drone components are dispersed across several categories: electronics (cat. 3), sensors and lasers (cat. 6), navigation and avionics (cat. 7) and aerospace and propulsion (cat. 9). Qualification rarely concerns the platform as a whole – most often a single subassembly is decisive.</p>



<p>2. <strong>Catch-all clauses (Article 4)</strong> – the obligation to obtain an authorisation arises also for items not included in the list, if the exporter has been informed or is aware of an intended use connected with weapons of mass destruction, military purposes in a state subject to an embargo, or parts for armaments exported without authorisation. This is the instrument which in practice covers the largest number of drone transactions, because it operates independently of the list.</p>



<p>3. <strong>Control of intangible technology transfer (ITT)</strong> – the regime covers not only things, but also software and technology, including making them available by electronic means. In practice, this means that granting remote access to a code repository, transferring model weights<a href="#_ftn67" id="_ftnref67">[67]</a> or placing technical documentation in a cloud outside the customs territory of the Union may constitute an export requiring an authorisation.</p>



<p>4. <strong>Cyber-surveillance items (Article 5)</strong> – a control mechanism covering items not included in the list, intended for surveillance, where there is a risk of use for human rights violations; it applies directly to advanced observation systems and image analytics.</p>



<p>The complementary layer is formed by: <strong>Directive 2009/43/EC</strong> on intra-EU transfers of defence-related products (simplified within the framework of the Defence Readiness Omnibus), the international regimes (the Wassenaar Arrangement, the MTCR – whose Category I traditionally covers unmanned systems with specified range and payload parameters) and, at national level, the <strong>Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance</strong>.</p>



<p><strong>IMPORTANT for M&amp;A practice:</strong> in the due diligence of an entity in the drone sector, the qualification of components as dual use determines the export authorisation regime, the end-user and re-export prohibition clauses and – in real terms – the feasibility of the cross-border transaction. The disappearance of the commercial/combat boundary (a mass-produced observation drone converted into a combat platform without design changes) makes this qualification ever broader, and the regulatory risk ever more difficult to price. Particular attention is required in the situation where the purchaser is an entity from outside the Union: the mere transfer of technical documentation in the company examination process may require an authorisation before the agreement is even concluded.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.4 Pillar IV – Defence financing and procurement (the driver)</h3>



<p>This is the pillar in which law performs the function of a <strong>driver</strong>. The EU instruments do not react to technology – they create demand, direct the stream of public funds and establish the framework for joint production and procurement:</p>



<p>•&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <strong>The European Defence Fund (EDF)</strong><a href="#_ftn68" id="_ftnref68">[68]</a> – co-financing of joint defence research and development projects, lowering the industry’s investment risk.</p>



<ul class="wp-block-list">
<li><strong>EDIRPA</strong> (Regulation (EU) 2023/2418) – support for common defence procurement.<a id="_ftnref69" href="#_ftn69">[69]</a></li>



<li><strong>ASAP</strong><a id="_ftnref70" href="#_ftn70">[70]</a> – the regulation on supporting ammunition production: increasing the production capacities of industry; a logic fully transferable to the mass production of loitering munitions and drones.</li>



<li><strong>SAFE</strong> (Security Action for Europe, 2025)<a id="_ftnref71" href="#_ftn71">[71]</a> – a loan instrument with procurement to be carried out by the end of 2030.</li>



<li><strong>EDIP</strong> – the European Defence Industry Programme, together with the construction of <strong>SEAP</strong> (Structure for European Armament Programme) as a voluntary legal framework for the long-term cooperation of Member States across the entire life cycle of a defence product.<a id="_ftnref72" href="#_ftn72">[72]</a></li>
</ul>



<p>The superstructure of these instruments is the <strong>Defence Readiness Omnibus</strong><a href="#_ftn73" id="_ftnref73">[73]</a> of 17 June 2025 – a legislative and non-legislative package intended to remove administrative barriers to defence investment estimated at EUR 800 billion over a four-year perspective. It includes, inter alia, accelerated authorisation procedures for defence projects with a single point of contact, extension of the maximum duration of framework agreements to ten years, simplification of intra-EU transfers of defence products (where delays reached a year), clarification of the defence exclusions in chemicals legislation (REACH, CLP, biocidal products) and – which is particularly significant for financing – a communication clarifying the application of the sustainable finance framework to the defence sector. In June 2026, the co-legislators reached a preliminary agreement on the procurement part of the package, extending the increased EDF financing to actions carried out within the framework of SEAP and permitting the eligibility of the costs of tests conducted in Ukraine.</p>



<p>A separate, younger layer is formed by the <strong>four flagship projects</strong><a href="#_ftn74" id="_ftnref74">[74]</a> of the Readiness Roadmap 2030: the European Drone Defence Initiative, Eastern Flank Watch, the European Air Shield and the European Space Shield. EDDI – originally communicated as the “drone wall” – is to create a multi-layered network capable of detecting, tracking and neutralising hostile platforms, while preserving a dual-use dimension allowing civil applications (border protection, disaster response). The assumed timetable: launch in Q1 2026, initial capability by the end of 2026, full functionality by the end of 2027 (Eastern Flank Watch – by the end of 2028). They are complemented by the <strong>Action Plan on drone and counter-drone security</strong> of 11 February 2026 and the <strong>Drone Alliance with Ukraine</strong>, together with the announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets to support Ukrainian drone production.</p>



<p>The market confirms the direction: over a twelve-month horizon, autonomous drones attracted around USD 6.2 billion in 169 transactions, driving a 139-per-cent increase in defence robotics financing. Analysts at the same time point to the gap between the “battle-tested” Ukrainian ecosystem and the capital actually flowing in – a field in which legal advice and transaction structuring become critical.</p>



<p><strong>The practical dimension:</strong> participation in the driver instruments has a legal price which must be factored in at the stage of structuring the consortium. The EDF and EDIP regimes contain extensive provisions on rights to the results of the project, access to existing knowledge (background) and generated knowledge (foreground), export restrictions on results and requirements of control over the entity (registered office in the Union, absence of third-country control or effective mechanisms for its limitation). For a company with capital from outside the Union, eligibility can be illusory if the ownership structure is not appropriately arranged in advance.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.5 · Pillar V – Satellite communications (IRIS²)</h3>



<p><strong>Regulation (EU) 2023/588</strong> establishes the Union’s secure connectivity programme for 2023–2027 and the <strong>IRIS²</strong> constellation (Infrastructure for Resilience, Interconnectivity and Security by Satellite). It is the sovereign European answer to dependence on commercial satellite systems, whose role in the control of long-range drones was revealed by the conflict.<a href="#_ftn75" id="_ftnref75">[75]</a></p>



<p>Law here builds the physical layer on which the future generation of satellite-controlled platforms will rest – a classic infrastructural driver. The significance of this pillar is, however, deeper than technical: the experience of recent years has shown that <strong>a private satellite operator’s decision on coverage or on refusal to provide the service in a given area may have operational effects comparable to a decision of a state</strong>. The construction of a public capability is the answer to a problem which should be called the privatisation of communications sovereignty.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.6 · Pillar VI – Critical infrastructure, cybersecurity and product resilience</h3>



<p>Since the first phase of the conflict was cyber warfare, the pillar of digital and physical resilience has systemic significance. It is formed by three acts of differing logic:</p>



<ul class="wp-block-list">
<li><strong>Directive (EU) 2022/2555 (NIS2)</strong><a id="_ftnref76" href="#_ftn76">[76]</a> – raises the common level of cybersecurity, extending the circle of essential and important entities and the obligations of risk management, incident reporting and the responsibility of management bodies. It covers, inter alia, air transport, energy, digital infrastructure and – which is significant for the sector under discussion – the manufacture of products, including electronic devices. NIS2 shifts the weight from “IT security” itself to risk management at the level of the entire organisation, including the responsibility of management, incident reporting obligations and the requirement of operational resilience for entities operating in critical and technologically sensitive sectors.</li>



<li><strong>Directive (EU) 2022/2557 (CER)</strong><a id="_ftnref77" href="#_ftn77">[77]</a> – regulates the resilience of critical entities in the physical and organisational dimension: the identification of critical entities, risk assessment, resilience plans, personnel security vetting. The key significance of CER lies in the fact that it concentrates not on cyberspace, but on the physical and organisational resilience of critical entities, and thus on the capability to maintain continuity of operation despite an attack, sabotage, disruption or infrastructural crisis.</li>



<li><strong>Regulation (EU) 2024/2847 (Cyber Resilience Act, CRA)</strong><a id="_ftnref78" href="#_ftn78">[78]</a> – the youngest act and, in practice, the most burdensome for manufacturers. It establishes horizontal cybersecurity requirements for <strong>products with digital elements</strong>, and thus for drones, ground controllers, detection systems and software. It imposes obligations of secure design, vulnerability management throughout the support period, provision of a software bill of materials (SBOM) and reporting of actively exploited vulnerabilities and serious incidents. The reporting obligations apply from September 2026, and the entirety – from December 2027. The most momentous element of the CRA is that, for the first time, it imposes on manufacturers of products with digital elements a continuous cybersecurity obligation throughout the product’s entire life cycle, encompassing secure design, vulnerability management and response obligations also after the product’s placing on the market.</li>
</ul>



<p>Both directive-form acts (NIS2, CER) require national transposition – which shifts the weight to the Polish level, discussed in Pillar IX.</p>



<p><strong>The practical dimension:</strong> the convergence of the three regimes means that a manufacturer of a drone system for a critical infrastructure operator may simultaneously: (i) be subject to the CRA as a manufacturer of a product with digital elements, (ii) be an important entity within the meaning of NIS2 by virtue of its own manufacturing activity, and (iii) be covered by requirements arising from the obligations of its client under CER and NIS2, passed down contractually within the framework of supply chain risk management. Three regimes, three separate calendars, three separate sets of reporting obligations – while the event that triggers them is one.</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.7 · Pillar VII – Personal data and data governance</h3>



<p>This is a pillar systematically omitted in analyses of the defence sector, and at the same time the one which in practice most often blocks civil deployments. This follows from the observation made in section 2.10: the drone is above all a sensor, and a sensor turned towards the surface of the earth in an urbanised environment almost always records personal data.</p>



<p><strong>Regulation (EU) 2016/679 (GDPR)</strong> applies to the processing of imagery from an unmanned platform on general principles, whereby in practice four issues are decisive:</p>



<ul class="wp-block-list">
<li><strong>Scope of application.</strong> Article 2(2)(a) and (b) excludes processing in the course of an activity which falls outside the scope of Union law and within the framework of the common foreign and security policy. National security remains the competence of the Member States (Article 4(2) TEU). There thus arises – symmetrically to Article 2(3) of the Artificial Intelligence Act – a second defence exclusion, with differently drawn boundaries.</li>



<li><strong>Legal basis and transparency.</strong> The information obligation under Articles 13–14 is difficult to perform in a real manner in aerial operations; practice relies on area-based information, signage and the publication of flight plans, which the European Data Protection Board analysed in Guidelines 3/2019 on the processing of personal data through video devices.</li>



<li><strong>Data protection impact assessment (Article 35).</strong> Systematic monitoring of public space on a large scale with the use of new technologies falls within the typical criteria of a mandatory impact assessment; in Polish practice, the list of operations requiring a DPIA maintained by the supervisory authority includes monitoring with the use of drones.</li>



<li><strong>Special categories (Article 9).</strong> The processing of facial imagery for the purpose of the unique identification of a natural person constitutes the processing of biometric data; in combination with Article 5 of the Artificial Intelligence Act (the prohibition of real-time remote biometric identification in public space for law enforcement purposes, subject to exceptions), this creates a double barrier for observation systems with facial recognition.</li>
</ul>



<p>For operations conducted by the services, the appropriate regime is <strong>Directive (EU) 2016/680</strong> (the so-called Police Directive), transposed in Poland by the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.</p>



<p>A separate, younger layer is constituted by the <strong>governance of non-personal data</strong>. <strong>Regulation (EU) 2023/2854 (the Data Act)</strong>, applicable from 12 September 2025, covers “connected products” – that is, devices generating data on their use and environment, to which unmanned systems belong directly. It imposes obligations to make data available to the user and to third parties designated by the user, and limits the freedom to shape contracts in this respect. <strong>Regulation (EU) 2022/868 (the Data Governance Act)</strong>, in turn, creates the framework for the re-use of public sector data and data intermediation.</p>



<p>Finally, <strong>Article 10 of the Artificial Intelligence Act</strong> introduces quality requirements for the training, validation and testing data sets of high-risk systems – representativeness, relevance, examination for systematic errors. These requirements overlap with the GDPR regime in a manner which is sometimes a source of practical contradictions: the obligation to examine bias sometimes requires the processing of special-category data, the processing of which the GDPR as a rule prohibits. This issue is the subject of work on the data part of the Digital Omnibus.</p>



<p><strong>Legislative status:</strong> in contrast to the part concerning artificial intelligence, <strong>the part of the simplification package covering the GDPR, the ePrivacy Directive, NIS2, the Data Act and DORA remains at the negotiation stage.</strong> At the end of June 2026, the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority; the file was taken over by the Irish Presidency. The European Data Protection Board and the European Data Protection Supervisor expressed, in Joint Opinion 2/2026 of 11 February 2026, decided opposition to the proposed narrowing of the definition of personal data. <strong>Until formal adoption, the existing state of the law applies</strong> – the contrary assumption is at this moment the most frequent error in compliance planning (The legislative status remains unclosed: in contrast to the part of the simplification package concerning artificial intelligence, the component covering the GDPR, privacy and electronic communications, NIS2, the Data Act and DORA still remains at the negotiation stage. It is officially known that the EDPB and the EDPS, in Joint Opinion 2/2026 of 11 February 2026, expressed substantial reservations about the proposed changes, including the narrowing of the definition of personal data. Expert sources further indicate that at the end of June 2026 the Cypriot Presidency withdrew the compromise text from the approval procedure in COREPER II in the absence of a qualified majority, which means that until formal adoption the existing state of the law continues to apply.<a href="#_ftn79" id="_ftnref79">[79]</a>).</p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.8 · Pillar VIII – Public international law and autonomous weapon systems</h3>



<p>The space left by the defence exclusions of EU law is not a lawless space. It is filled – with varying effectiveness – by three regimes of international law.</p>



<p><strong>International aviation law.</strong> The Chicago Convention of 1944 excludes state aircraft from its scope (Article 3), requires special authorisation for flights of pilotless aircraft over the territory of another state (Article 8) and – in Article 3 bis, added in 1984 – confirms the obligation to refrain from resorting to the use of weapons against civil aircraft in flight. This construction arose in a world in which the distinction “civil/state aircraft” was possible visually and procedurally. Applying it to an object with a wingspan of two metres, without markings, crossing the border unannounced, is a task for which the treaty was not designed.</p>



<p><strong>International humanitarian law.</strong> The principles of distinction, proportionality and precautions in attack apply regardless of whether the decision on the use of force is taken by a human or assisted by an algorithm. Article 36 of Additional Protocol I of 1977 imposes on the parties the obligation to review new weapons, means and methods of warfare for their compatibility with international law – this provision is today the only universally binding instrument that covers autonomy in armaments, although it does so indirectly.<a href="#_ftn80" id="_ftnref80">[80]</a></p>



<p><strong>The CCW process and the UN forum.</strong> The Group of Governmental Experts on lethal autonomous weapon systems (GGE on LAWS), operating since 2016 within the framework of the Convention on Prohibitions or Restrictions on the Use of Certain Conventional Weapons, has been working since 2024 on the so-called rolling text, encompassing elements of a potential instrument based on a two-tier approach of prohibitions and regulation. At the September 2025 session, a group of 42 states – one third of the parties to the Convention – declared readiness to move to negotiations on the basis of that text. On 6 November 2025, the UN General Assembly adopted, for the third time in succession, a resolution on autonomous weapon systems, supported by 156 states. The UN Secretary-General and the President of the International Committee of the Red Cross jointly called for the conclusion of negotiations on a legally binding instrument <strong>by the end of 2026</strong>. The Seventh CCW Review Conference, planned for November 2026, is the moment at which it will be decided whether a negotiating mandate will come into being – whereby the consensus rule applicable in that forum makes this outcome uncertain.<a href="#_ftn81" id="_ftnref81">[81]</a></p>



<p><strong>The NATO layer</strong> comprises the principles of the responsible use of artificial intelligence in defence adopted in 2021 (lawfulness, accountability, explainability and traceability, reliability, governability, bias mitigation) and the revised AI strategy. These are not legally binding norms, but they constitute a point of reference for contractual requirements in allied procurement – and in this sense they affect industry more strongly than many a legal act.<a href="#_ftn82" id="_ftnref82">[82]</a></p>



<h3 class="wp-block-heading has-luminous-vivid-amber-background-color has-background">3.9 · Pillar IX – The Polish level</h3>



<p>The Polish regime combines directly applicable EU regulations with national statutes and operational provisions. The Regulations (2019/945, 2019/947, 2021/664, 2021/821, 2023/588, 2024/1689, 2024/2847) apply directly; the directives (NIS2, CER) require transposition.</p>



<p><strong>The aviation layer.</strong> The national basis is formed by the <strong>Act of 3 July 2002 – Aviation Law</strong>, substantially amended by the Act of 24 January 2025, which entered into force on 27 February 2025. The amendment adapted national law to the EU regime and introduced, inter alia: a register of operators of unmanned systems (a registration obligation for platforms of at least 250 g <strong>and – regardless of mass – those equipped with sensors capable of collecting personal data</strong>), the statutory empowerment of the Polish Air Navigation Services Agency to designate geographical zones, the extension of the catalogue of services entitled to check pilots, the lowering of the minimum age of a pilot in the open category from 16 to 14 under supervision, and a chapter devoted to the prevention of the unlawful performance of operations with the use of unmanned systems. Notification of the intention to perform an operation takes place through the <strong>DroneTower</strong> application, integrated with the PANSA UTM system and the National Drone Information System (KSID). The legal basis for the neutralisation of a platform remains <strong>Article 156ze of the Aviation Law</strong> (destruction, immobilisation or taking over control of the flight), supplemented by the provisions of the chapter on the prevention of unlawful operations.</p>



<p>Institutionally, this layer is completed by the <strong>Act of 8 December 2006 on the Polish Air Navigation Services Agency</strong> (Journal of Laws of 2025, item 1267), extended by the Agency’s competences in the area of unmanned systems, including the possibility of providing services to operators, supporting the testing of new solutions and creating special-purpose companies. Supervision is exercised by the President of the Civil Aviation Authority.</p>



<p><strong>The resilience and countermeasure layer.</strong> The breakthrough is the <strong>Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815)</strong>, implementing the CER Directive. Its significance for the sector under discussion extends far beyond its declared purpose:</p>



<ul class="wp-block-list">
<li><strong>Critical infrastructure operators have obtained the right to apply countermeasures against unmanned platforms, including jamming devices.</strong> Until now, a private entity managing a strategic facility could only await the intervention of the services; it can now itself interrupt communications with the intruder. The power entered into force on 26 June 2026.</li>



<li>The catalogue of authorised formations (the Police, the Border Guard, the State Protection Service, the Military Gendarmerie) obtained competences to destroy, immobilise or take over control of <strong>unmanned surface/floating objects and robots and autonomous vehicles moving on land</strong>, where they create a threat to critical infrastructure. The new Chapter 6a of the Act, modelled constructionally on the provisions of the Aviation Law concerning aircraft, extends the counter-drone regime to the maritime and land domains.</li>



<li>The Act further introduces an obligation of security audits, mechanisms for the protection of supply chains, and establishes the Maritime Security Centre.</li>
</ul>



<p><strong>The defence layer.</strong> It is formed by the <strong>Act of 11 March 2022 on the Defence of the Homeland</strong> – the national framework for the acquisition and operation of unmanned and counter-drone systems, together with the procurement regime in the fields of defence and security.</p>



<p><strong>The direction of change.</strong> This area is evolving intensively in the years 2024–2026 and requires ongoing verification of the entries in the Journal of Laws and of legislative drafts. After a period of tightening of administrative sanctions, assessed by the operator community as disproportionate, the Civil Aviation Authority transmitted to the Ministry of Infrastructure on 5 May 2026 a draft amendment of a deregulatory and ordering character, covering the system of penalties, insurance, mandatory notifications, the securing of critical infrastructure and counter-drone systems. Entry into force is announced for the turn of 2026 and 2027. In parallel, work is under way on the full transposition of NIS2 within the framework of the amendment of the Act on the National Cybersecurity System.<a href="#_ftn83" id="_ftnref83">[83]</a></p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><a>4 · Seven Points of Friction</a></h2>



<p>The pillars described in Part 3 do not form a coherent system. They come into contact with one another at points where their assumptions are mutually contradictory, and the resolution of the collision does not follow from any of them. It is precisely at these points that the undertaking’s real legal risk is concentrated – and it is they, not the content of the individual acts, that should set the agenda of legal advice.</p>



<h3 class="wp-block-heading">4.1 · The “exclusivity” test – the military exclusion in relation to a dual-use product</h3>



<p>The exclusion in Article 2(3) of the Artificial Intelligence Act operates on the condition of the <strong>exclusivity</strong> of the military, defence or national security purpose. This construction assumes that the purpose can be unambiguously assigned to the placing on the market or the putting into service. In the dual-use sector, this assumption is empirically false: the same machine vision module may be sold to the manufacturer of a power plant perimeter protection system and at the same time integrated into a military platform.</p>



<p>The practical consequences are three. First, <strong>the burden of demonstrating exclusivity rests on the entity that invokes it</strong> – and demonstrating a negative fact (the absence of civil application) requires documented control of the distribution channel and end-user clauses. Second, the exclusion relates to the system, not to the undertaking: a company may simultaneously be a provider of a high-risk system and a provider of an excluded system. Third, <strong>modification of the intended purpose after placing on the market changes the regime</strong> – and in a sector in which the end user routinely modifies the platform, this is a real risk, not a hypothetical one.</p>



<p>The practical recommendation is unambiguous: the separation of product lines at the documentary, contractual and – as far as possible – technical level, before the first mixed contract comes into being. Untangling this situation later is costly, and in the course of a company examination it is sometimes impracticable.</p>



<h3 class="wp-block-heading">4.2 · Human oversight: two regimes, one technical requirement</h3>



<p>Article 14 of the Artificial Intelligence Act and the postulate of meaningful human control in humanitarian law<a href="#_ftn84" id="_ftnref84">[84]</a> describe the same property of a system – the human’s capability to understand, verify and interrupt the operation of the automaton – but have an entirely different normative status. On the civil side, it is a legal obligation with an administrative sanction and a documentation requirement. On the military side – the subject of unfinished negotiations.</p>



<p>From this arises an asymmetry with industrial effects: <strong>a manufacturer that builds one technical platform for both tracks must design to the stricter requirement</strong>, because it cannot foresee in advance in which track a given unit will end up. Consequently, the civil requirement becomes the de facto design standard also for excluded applications – a mechanism worth calling the standard-transfer effect. This is one of the few situations in which the defence exclusion operates to the benefit, rather than to the detriment, of the coherence of the system.</p>



<p>The converse mechanism is, however, equally real: operational pressure to shorten the decision chain in a heavily jammed environment leads to constructions in which human oversight is formally preserved but in fact illusory – the operator approves a decision which he had neither the time nor the data to assess. Demonstrating such a situation in evidentiary proceedings requires access to event logs, which Article 12 of the Artificial Intelligence Act requires only on the civil side.</p>



<h3 class="wp-block-heading">4.3 · Jamming as a legally regulated activity</h3>



<p>The jamming power, granted in Poland to critical infrastructure operators from June 2026, is an example of a norm which solves one problem and opens three further ones.<a href="#_ftn85" id="_ftnref85">[85]</a></p>



<p>Jamming devices are, as a rule, inadmissible for marketing and use: they do not satisfy the essential requirements of Directive 2014/53/EU on radio equipment (harmful interference), and their use violates the spectrum management regime. The grant of a statutory power removes the unlawfulness of the act itself, but <strong>does not settle liability for side effects</strong>. Interference in the bands used by satellite navigation systems affects civil aviation, transport, telecommunications networks and – which is sometimes overlooked – energy infrastructure synchronised by satellite time. Questions therefore arise as to: (i) the compensation liability regime of the facility operator towards third parties, (ii) the delimitation of liability between the operator and the manufacturer of the device, (iii) the documentation obligations allowing the course of the event to be reconstructed.</p>



<p>To this is added a third problem, described in section 2.4: <strong>the legal measure was granted at the moment when the technology against which it is effective is in retreat.</strong> The fibre-optic platform is resistant to jamming by definition. The norm responds to the state of the art of two years ago.</p>



<h3 class="wp-block-heading">4.4 · Kinetic neutralisation and liability for damage</h3>



<p>Shooting down or immobilising a platform does not end the event – it begins the fall of a mass with kinetic energy over terrain which is usually precisely what was to be protected. Polish law provides a basis for neutralisation (Article 156ze of the Aviation Law, the provisions of the chapter on the prevention of unlawful operations, the new powers under the Act of 29 May 2026), but <strong>the regime of liability for damage caused as a result of lawful neutralisation remains dispersed</strong> between the liability of the State Treasury for acts of public authority, the general rules of tortious liability and the special provisions on damage caused by the movement of aircraft.</p>



<p>A separate issue is the qualification of independent neutralisation by an unauthorised entity. The shooting down of a drone by the owner of the property over which it is flying is not the exercise of the right of ownership – it is the destruction of another’s thing and, depending on the circumstances, the creation of a danger. Judicial practice in this area is already taking shape.</p>



<h3 class="wp-block-heading">4.5 · Battlefield data as training material</h3>



<p>This is the most under-defined point of the entire map. Collections of recordings from combat operations – visual and thermal imagery from thousands of sorties – have a training value unattainable in laboratory conditions. They flow, formally and informally, in both directions across the civil-military boundary.</p>



<p>The legal issues arrange themselves in three layers. <strong>Data protection:</strong> material of this kind contains the images of natural persons; processing in the course of hostilities falls within the exclusion of Article 2(2) GDPR, but the use of the same collection by a commercial entity to train a model intended for the civil market no longer does – and determining the moment at which the data “enter” the scope of application of the regulation has no unambiguous normative answer. <strong>Data quality:</strong> Article 10 of the Artificial Intelligence Act requires that the training data sets of high-risk systems be representative and free of systematic errors; a collection originating from one theatre of operations, one season of the year and one type of terrain does not satisfy that requirement, which has a direct bearing on the reliability of classifiers in civil applications. <strong>Export control:</strong> the weights of a model trained on such a collection may constitute controlled technology, and making them available outside the customs territory of the Union – an export requiring authorisation (cf.&nbsp;section 3.3, point 3).</p>



<p>The practical recommendation: in every transaction concerning an entity possessing vision models, the provenance of the training data sets must be established and documented in a manner allowing the lawfulness of the chain to be demonstrated. This is today one of the most frequently omitted – and most difficult to repair after the fact – elements of a company examination.</p>



<h3 class="wp-block-heading">4.6 Intangible technology transfer and the dispersed working model</h3>



<p>The export control regime is not limited to the physical movement of goods across the border. Within the meaning of Regulation (EU) 2021/821, “export” also includes the transmission of software or technology by electronic means – inter alia electronic mail, telephone or other electronic means – to a destination outside the customs territory of the Union. Making such software or technology available in electronic form to natural or legal persons located outside the customs territory of the Union is also deemed to be an export. In consequence, granting a foreign engineer, consultant or potential investor the ability to download controlled files from a repository may constitute an export, even if the data at all times remain saved on the same server and the access was remote and short-lived.<a href="#_ftn86" id="_ftnref86">[86]</a></p>



<p>This does not, however, mean that every making available of source code outside the Union automatically requires an authorisation. It must first be established whether the software or technical information in question has been included in the list of dual-use items in Annex I to Regulation 2021/821, or whether the conditions for the control of unlisted items are met on account of their intended end use or end user. In the unmanned aircraft sector, this assessment may concern both the design of the drone itself, its subassemblies and equipment, and the dedicated software and the technology necessary for their development, production or use. Potentially significant will be, inter alia, design documentation, aerodynamic models and simulations, control system diagrams, autopilot code, solutions concerning autonomous navigation, sensor integration, encrypted communications or jamming resistance. The classification should, however, refer to the parameters and criteria of the specific control entry, and not solely to the fact that the given technology is connected with drones.</p>



<p>The risk of intangible technology transfer arises above all in three configurations: (i) in a geographically dispersed development team including persons working from third countries; (ii) in the due diligence process, if the advisers or technical experts of a potential purchaser from outside the Union receive access to the repository, the design documentation or the test environment; and (iii) in the use of cloud infrastructure, if the data are transmitted to servers located outside the Union or can be accessed from there. The mere decentralisation of infrastructure, the use of blockchain technology or the storage of data in the cloud do not yet determine the occurrence of a controlled export. What matters above all is the content of the data, their export classification, the location of the recipient and whether the entity from outside the Union has obtained a real possibility of acquainting itself with the controlled technology. In the case of dispersed data storage, an additional problem may be the impossibility of reliably establishing in which states the individual nodes or copies of the data are located.</p>



<p>For this reason, control of access to repositories containing drone technologies should be an element of the internal export compliance programme, and not solely a cybersecurity procedure. Such a system should encompass the classification of repositories and documentation, the establishment of the state from which the user actually obtains access, the verification of end users and of the purpose of use of the technology, the segmentation of projects, the principle of least privilege, restrictions on the downloading and copying of files, and the keeping of access logs. For the protection of data against unauthorised access does not itself replace the answer to a separate regulatory question: whether the access of a person who is authorised, but located outside the Union, constitutes an export requiring an authorisation.</p>



<h3 class="wp-block-heading">4.7 Supply chain, components and investment control</h3>



<p>The last point of friction is the tension between strategic autonomy and the structure of the component market. The ecosystem which made possible the cost revolution described in section 2.2 rests to a considerable extent on components of geographically concentrated origin – from cells and motors to integrated circuits and cameras. The policy of reducing dependence collides with the fact that alternative European chains do not exist at a scale corresponding to demand.</p>



<p>Legally, this tension materialises in three instruments: the eligibility mechanisms in the financing programmes (the requirement of component origin and of control over the contractor), <strong>Regulation (EU) 2019/452 on the screening of foreign direct investments</strong> together with the national Act of 24 July 2015 on the control of certain investments,<a href="#_ftn87" id="_ftnref87">[87]</a> and the sanctions regime. For an investor, this means that a transaction in this sector requires a parallel analysis of three consent paths: merger control, investment control and – where the object comprises listed assets – export consents. The transaction timetable must take this into account from day one; the attempt to catch up on these consents after the signing of the preliminary agreement is a typical cause of the failure of the process.</p>



<h2 class="wp-block-heading has-luminous-vivid-amber-background-color has-background"><strong>5 · The Dual-Track Nature of the Regime – an Answer to the Practical Question in the Legal Environment</strong></h2>



<p>The juxtaposition of the nine pillars leads to the conclusion that law simultaneously performs <strong>three different roles</strong> – depending on the track in which we find ourselves – and leaves one area uncovered.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><td><strong>Role of law</strong></td><td><strong>Pillars</strong></td><td><strong>Mechanism</strong></td></tr></thead><tbody><tr><td>Consequence of need</td><td>UAV/EASA, U-space level (civil track)</td><td>National law chases technology outpaced by the conflict; it regulates ex post what has already come into being</td></tr><tr><td>Driver</td><td>EDF, EDIRPA, ASAP, SAFE EDIP/SEAP, Defence Readiness Omnibus, IRIS², EDDI</td><td>Law creates demand, finances development, builds infrastructure and removes administrative barriers</td></tr><tr><td>Dampener</td><td>AI Act (civil track), dual use 2021/821, NIS2/CER/CRA, GDPR and the Data Act</td><td>Law limits the risk of mass dissemination, conditioning access to the market</td></tr><tr><td>Regulatory gap</td><td>LAWS / military AI, Art. 2(3) AI Act, art. 2 (2) GDPR, art. 2(3) (a) Reg. 2018/1139)</td><td>The defence exclusions leave development without a brake; international law fills this space only partially</td></tr></tbody></table></figure>



<p><strong>Law is neither exclusively a consequence nor exclusively a driver – it is dual-track.</strong> On the civil track it operates as a consequence of need and as a dampener; on the defence track as a driver. The mechanism separating the two tracks is the military exclusion in Article 2(3) of the Artificial Intelligence Act and the analogous defence exclusions in successive acts – whereby, as we demonstrated in section 3.1, the first of them appears already in the EASA basic regulation, and thus at the level of the foundation of the entire regime, not as a special exception.</p>



<p>The paradox lies in the fact that <strong>the same technology is simultaneously being accelerated on the defence side and dampened on the civil side</strong> – and the dual-use boundary along which this division runs is increasingly indistinct. What is more, in the years 2025–2026 we observe an additional phenomenon, which is worth noting as a fourth mechanism: <strong>simplification as a tool of industrial policy</strong>. Both the Defence Readiness Omnibus and the Digital Omnibus aim to lower regulatory burdens – the first on the defence track, the second on the civil one. The direction is convergent, the justifications different: in the first case defence readiness, in the second competitiveness. The effect is a convergence of the two tracks on the procedural side, while their substantive separateness is preserved.</p>



<h2 class="wp-block-heading">6 · Practical Implications for Entities in the Sector</h2>



<h3 class="wp-block-heading">6.1 · The qualification map – questions which must be answered in this order</h3>



<p>For a client from the UAV sector, one question is key: <strong>on which side of the boundary – dual use, military/civil – is its product or project located.</strong> This qualification determines the entire legal regime that covers it. In practice, it is worth conducting it sequentially:</p>



<p>1. <strong>Is the product intended exclusively for military, defence or national security purposes?</strong> If so – the basis of that assertion and the mechanisms of control over the distribution channel must be documented. If not, or not fully – the civil regime applies in its entirety.</p>



<p>2. <strong>Does the Artificial Intelligence Act apply, and if so, on which basis?</strong> Annex I (a safety component of a certified product) or Annex III (critical infrastructure, law enforcement, borders)? On this depends not only the scope of the obligations, but also the date of their application (2 December 2027 or 2 August 2028).</p>



<p>3. <strong>Which product class and operational category does the platform concern</strong> under the 2019/945 and 2019/947 regime – and do the operations require an authorisation in the specific category?</p>



<p>4. <strong>Is the product or any of its components subject to export control</strong> on the basis of Regulation (EU) 2021/821 and the current control list, including under the regime of the catch-all clauses and intangible technology transfer?</p>



<p>5. <strong>Does the device process personal data</strong> – and if so, has an impact assessment been carried out and is the legal basis of the processing documented? Is the platform a “connected product” within the meaning of the Data Act?</p>



<p>6. <strong>What cybersecurity obligations</strong> (the CRA as manufacturer, NIS2 by virtue of its own activity, CER indirectly through the client) cover the manufacturer and the operator?</p>



<p>7. <strong>Does the project qualify for driver financing</strong> (EDF, EDIRPA, ASAP, SAFE, EDIP/SEAP) – and does the ownership and consortium structure satisfy the eligibility and control requirements?</p>



<h3 class="wp-block-heading"><a>6.2 Due diligence of a drone entity</a></h3>



<p>In M&amp;A practice, this means that the examination of the company must cover not only the classic areas (legal title to intellectual property, contracts, obligations), but also <strong>regulatory positioning</strong>. The checklist covers at least:</p>



<ul class="wp-block-list">
<li>the dual-use classification of every component and product, together with the substantiating documentation and the history of authorisations issued;</li>



<li>the status vis-à-vis the Artificial Intelligence Act: an inventory of systems, assignment to categories, assessment of the existence and effectiveness of the exclusion under Article 2(3);</li>



<li>the provenance of the training data sets and the rights to use them – including the chain of title to data originating from third parties or from real operations;</li>



<li>the history of security incidents and compliance with the reporting regimes;</li>



<li>operator registration, operational authorisations, the history of proceedings before the aviation supervisory authority and of administrative sanctions;</li>



<li>exposure to investment control (Regulation 2019/452, the Act of 24 July 2015) and the eligibility requirements in the financing programmes of which the company is a beneficiary;</li>



<li>compliance with the intangible technology transfer regime in the dispersed working model, including a list of the jurisdictions from which access to the repositories was granted;</li>



<li>rights to the results of projects financed from public funds, including export restrictions and access rights allocated to Member States.</li>
</ul>



<p><strong>A procedural remark of significant practical importance:</strong> the mere conduct of the company examination may trigger export obligations if access to the technical documentation is obtained by advisers from third countries. The sequence of steps in the transaction process is therefore not a matter of convenience – it is an element of compliance.</p>



<h3 class="wp-block-heading"><a>6.3 · Compliance calendar 2026–2028</a></h3>



<figure class="wp-block-table"><table class="has-luminous-vivid-orange-background-color has-background has-fixed-layout"><thead><tr><td><strong>Date</strong></td><td><strong>Event</strong></td></tr></thead><tbody><tr><td>2 August 2026</td><td>Transparency obligations under Article 50 of the Artificial Intelligence Act (unchanged despite the simplification package)</td></tr><tr><td>September 2026</td><td>Manufacturers’ reporting obligations under the Cyber Resilience Act</td></tr><tr><td>November 2026</td><td>The Seventh CCW Review Conference – decision on the negotiating mandate concerning autonomous weapon systems</td></tr><tr><td>2 December 2026</td><td>Article 50(2) of the AI Act in relation to systems already present on the market; the new prohibitions under Article 5</td></tr><tr><td>end of 2026</td><td>Initial capability of the European Drone Defence Initiative and Eastern Flank Watch</td></tr><tr><td>turn of 2026/2027</td><td>Announced entry into force of the Polish deregulatory amendment of the Aviation Law</td></tr><tr><td>&nbsp; end of 2027</td><td>&nbsp; Full functionality of EDDI</td></tr><tr><td>2 December 2027</td><td>Obligations for standalone high-risk systems (Annex III of the AI Act)</td></tr><tr><td>December 2027</td><td>Full application of the Cyber Resilience Act</td></tr><tr><td>2 August 2028</td><td>Obligations for AI embedded in regulated products (Annex I – including unmanned systems)</td></tr><tr><td>end of 2028</td><td>Full functionality of Eastern Flank Watch</td></tr></tbody></table></figure>



<p>The dates concerning the part of the simplification package relating to the GDPR, privacy in electronic communications, NIS2 and the Data Act remain unsettled – the file is in negotiations in the Council, and adoption before the end of 2026 is uncertain.</p>



<h3 class="wp-block-heading">6.4 What cannot be postponed</h3>



<p>The postponement of the obligations for high-risk systems is sometimes read as consent to suspend work. This is an error with a measurable cost. Three tasks have no temporal alternative:</p>



<ul class="wp-block-list">
<li><strong>Inventory and classification.</strong> The most difficult element of compliance with the Artificial Intelligence Act is not the completion of documentation, but the identification of all systems in the organisation and the maintenance of that register as successive versions of the product are introduced. This work does not depend on the state of the harmonised standards.</li>



<li><strong>AI literacy (Article 4).</strong> The obligation to ensure an appropriate level of knowledge of the personnel operating AI systems has applied since 2 February 2025 and has not been postponed.</li>



<li><strong>Data architecture and event logs.</strong> The requirements of Articles 10 and 12 are of a design character – satisfying them after the completion of construction work is many times more costly than taking them into account from the outset.</li>
</ul>



<p>It is precisely here – at the interface of technology and the ever-denser lattice of regimes – that the added value of legal advice specialised in highly regulated sectors lies.</p>



<h2 class="wp-block-heading">7 Conclusion – the Conflict as Lens and Barometer</h2>



<p>The Ukrainian conflict is a lens in which the future of dual-use technology can be seen, and a barometer of the direction of its regulation. It refutes the popular thesis that law by its nature restrains technological development: on the defence track, the legal layer of public financing has proved to be a vector of abrupt acceleration – and the instruments adopted in the years 2025–2026, from the Defence Readiness Omnibus to the flagship projects of the Readiness Roadmap 2030, are proof of this on a scale hitherto unknown in Europe. At the same time, it shows that as drones become widespread, civil law assumes a dampening function – controlling export, autonomy, data processing and access to airspace.</p>



<p>Three observations seem most significant for the further discussion.</p>



<p><strong>First</strong>, the defence exclusions are not an exception to the rule, but a systemic construction repeated at every level of regulation – from the EASA basic regulation, through the GDPR, to the Artificial Intelligence Act. Each time, however, they have differently drawn boundaries, which means that the same platform may simultaneously be excluded from one regime and covered by another. The ordering of those boundaries is a task which the EU legislator has not yet undertaken.</p>



<p><strong>Second</strong>, with the shift of value from the platform to the data and models, the regulatory weight is shifting from aviation law towards data and artificial intelligence law. A manufacturer that in 2019 needed mainly a certificate needs, in 2026, a documented chain of provenance of the training data sets, a vulnerability management system and jurisdiction-based access control.</p>



<p><strong>Third</strong>, the innovation spiral will not slow down – and with it, the pace of the layering of the law will not slow down either. A norm responding to the state of the art of two years ago, adopted in reaction to an incident of a year ago, entering into force in a year’s time, will at the moment of its application relate to a world that no longer exists. This is an argument not against regulation, but for regulation based on effects and on the level of risk, resistant to a change of technical solution.</p>



<p>For lawyers serving this sector, the conclusion is one: <strong>an effective legal strategy begins with the conscious positioning of the product on the right side of each of the boundaries of the regime</strong> – and there are today nine of those boundaries, not one. The ability to move simultaneously in the technological and regulatory layer ceases to be an advantage and becomes a condition of presence on this market.</p>



<h2 class="wp-block-heading">Annex A: Glossary of Technical Terms</h2>



<figure class="wp-block-table"><table class="has-vivid-red-color has-luminous-vivid-amber-background-color has-text-color has-background has-link-color has-fixed-layout"><thead><tr><td><strong>Term</strong></td><td><strong>Meaning</strong></td></tr></thead><tbody><tr><td>BSP / UAS / UAV</td><td>Unmanned aircraft; an unmanned aircraft system also includes the control station and the link</td></tr><tr><td>FPV (first person view)</td><td>Control from a first-person perspective, through goggles receiving the image from the on-board camera</td></tr><tr><td>BVLOS</td><td>An operation beyond the operator’s visual line of sight</td></tr><tr><td>ISR</td><td>Intelligence, surveillance and reconnaissance</td></tr><tr><td>Relay</td><td>A repeater of the control signal and imagery, allowing terrain obstacles to be bypassed</td></tr><tr><td>Radio horizon</td><td>The maximum range of signal propagation limited by terrain relief and obstacles</td></tr><tr><td>Jamming</td><td>Emission of noise on the control frequencies with the aim of severing the link</td></tr><tr><td>Spoofing</td><td>Substitution of the satellite navigation signal, causing an erroneous determination of position</td></tr><tr><td>WRE / EW</td><td>Electronic warfare</td></tr><tr><td>Loitering munition</td><td>A platform remaining in the task area and carrying out a strike after detecting a target</td></tr><tr><td>Deep strike</td><td>A strike on targets located deep in the adversary’s territory</td></tr><tr><td>Terminal autonomy</td><td>The platform’s capability to complete the task without communications with the operator</td></tr><tr><td>C-UAS</td><td>Counter-unmanned aircraft systems</td></tr><tr><td>SBOM</td><td>A software bill of materials, required by the Cyber Resilience Act</td></tr><tr><td>U-space</td><td>A set of digital services enabling safe UAV operations in designated airspace</td></tr><tr><td>SORA</td><td>The risk assessment methodology for operations in the specific category</td></tr></tbody></table></figure>



<h2 class="wp-block-heading">About the Authors and the Firm</h2>



<p><strong>KG Legal Kiełtyka Gładkowski. Partnership – Attorneys law firm </strong>advises entities from the high-technology sectors and highly regulated industries.</p>



<p><strong>Attorney-at-law (radca prawny) Kazimierz Jakub Gładkowski</strong> specialises in corporate matters.</p>



<p><strong>Attorney-at-law (radca prawny) Małgorzata Kiełtyka</strong>, entitled to appear before all courts, specialises in M&amp;A transactions for entities from the high-technology and highly regulated sectors.</p>



<p><em>This article is of an informational and popular-science nature; it does not constitute legal advice. In individual matters, we recommend contacting the firm.</em></p>



<p><strong>Additional Footnotes and Sources</strong></p>



<p><strong>1.</strong> Violations of Polish airspace on 9/10 September 2025 and earlier incidents (Romania – January 2025; Osiny – August 2025); launch of NATO’s operation Eastern Sentry; compare: T. Withington, “Europe’s Drone Wall – Ready, EDDI, Go!”, <em>European Security &amp; Defence</em>, 13 March 2026, pp.&nbsp;38–41; <a href="https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/">https://euro-sd.com/2026/03/articles/exclusive/49854/europes-drone-wall-ready-eddi-go/</a></p>



<p><strong>2.</strong> Expert estimate concerning the pace of development of unmanned technologies in wartime conditions; cf.&nbsp;the analysis systematising drone warfare technology – M. Strzyżewski, “Anti-drone defense &#8211; shotguns, nets, EW, interceptor drones”, Marcin Strzyżewski YouTube channel, 2026 (video material).</p>



<p><strong>3.</strong> The analogy and taxonomy of drone categories and the role of situational awareness; the persistence of commercial observation platforms on the battlefield after: M. Strzyżewski, op. cit.</p>



<p><strong>4.</strong> “FPV Drone Warfare: The $1,000 Revolution Reshaping Modern Combat”, drone-warfare.com, 2026. <a href="https://drone-warfare.com/research/fpv-drone-warfare">https://drone-warfare.com/research/fpv-drone-warfare</a></p>



<p><strong>5.</strong> V. Sutea, “Fiber-optic drones have emerged as critical kit for both Russia and Ukraine”, Atlantic Council – UkraineAlert, 24 February 2026 (the appearance of fibre-optic drones in August 2024 in the Kursk area; range of over 30 km, no susceptibility to jamming); <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/?utm_source=chatgpt.com">https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine</a></p>



<p><strong>6.</strong> NATO Allied Command Transformation, Innovation Challenge devoted to countering fibre-optic drones, 2025 – cf.&nbsp;Atlantic Council, op. cit.</p>



<p><strong>7.</strong> “Fire Point FP-1”, Wikipedia (as at 21 July 2026); cf.&nbsp;“FP-1 vs Shahed: Ukraine Ramps Up Production…”, United24 Media, 20 August 2025 (unit cost approx. USD 55 thousand; plywood fuselage, two-cylinder engine).</p>



<p><strong>8.</strong> “Russian largest oil refinery hit for first time by Ukrainian drones”, Politico Europe, 6 July 2026; cf.&nbsp;Tom’s Hardware, 17 July 2026 (strike on the Omsk refinery after a flight of over 2,500 km). <a href="https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery">https://www.tomshardware.com/tech-industry/drones/ukraines-55000-plywood-drone-flew-2500-km-and-shut-down-russias-largest-oil-refinery</a></p>



<p><strong>9.</strong> Regulation (EU) 2018/1139 (EASA), including Article 2(3)(a) (exclusion of military, customs, police and related operations); Delegated Regulation (EU) 2019/945; Implementing Regulation (EU) 2019/947 (open / specific / certified categories). Source: EUR-Lex.</p>



<p><strong>10.</strong> Implementing Regulation (EU) 2021/664 (the U-space framework) together with 2021/665 and 2021/666. Source: EUR-Lex; EASA.</p>



<p><strong>11.</strong> Regulation (EU) 2023/203 (information security requirements in U-space); the consolidated version of 2019/947 applicable from 1 May 2025. Source: EUR-Lex; SKYbrary.</p>



<p><strong>12.</strong> EASA, Easy Access Rules for Unmanned Aircraft Systems – revision of June 2026 (consolidation of the AMC/GM to 2019/947, ED Decision 2025/018/R).</p>



<p><strong>13.</strong> Regulation (EU) 2024/1689 (the Artificial Intelligence Act), Article 2(3) and recital 24; Articles 4, 5, 6, 8–15, 50, 51–55; Annexes I and III. Source: EUR-Lex; artificialintelligenceact.eu (Article 2: Scope).</p>



<p><strong>14.</strong> European Parliament, EPRS, “Defence and artificial intelligence”, 2025 (LAWS outside the scope of the AI Act by virtue of Article 2(3); calls for international regulation).</p>



<p><strong>15.</strong> Digital Omnibus on AI: Commission proposal of 19 November 2025; unsuccessful trilogue of 28 April 2026; preliminary political agreement of 6–7 May 2026; confirmation by Member State representatives on 13 May 2026; approval by the Parliament on 16 June 2026 and by the Council on 29 June 2026. New dates: 2 December 2027 (Annex III), 2 August 2028 (Annex I), 2 December 2026 (Article 50(2) in relation to existing systems and the new prohibitions). Cf. analyses: Gibson Dunn, May 2026; Travers Smith, May 2026.</p>



<p><strong>16.</strong> Regulation (EU) 2021/821 (dual-use export control); entry into force on 9 September 2021; consolidated version from 15 November 2025; Article 4 (catch-all clauses), Article 5 (cyber-surveillance items), the intangible technology transfer regime. Source: EUR-Lex.</p>



<p><strong>17.</strong> European Commission, update of Annex I to Regulation (EU) 2021/821 of 8 September 2025 (emerging technologies). Cf. Akin, “EU Updates Dual-Use Export Control List”, 16 September 2025.</p>



<p><strong>18.</strong> Directive 2009/43/EC on intra-EU transfers of defence-related products; the Act of 29 November 2000 on foreign trade in goods, technologies and services of strategic importance.</p>



<p><strong>19.</strong> Regulation (EU) 2023/2418 (EDIRPA – common defence procurement). Source: EUR-Lex; European Commission (DG DEFIS).</p>



<p><strong>20.</strong> The SAFE instrument (Security Action for Europe), 2025; procurement to be carried out by the end of 2030. Cf. European Parliament, EPRS, “EU joint defence procurement”, 2026.</p>



<p><strong>21.</strong> Defence Readiness Omnibus, European Commission, 17 June 2025 (accelerated authorisations, framework agreements up to 10 years, simplification of intra-EU transfers, exclusions in REACH/CLP, communication on sustainable finance); preliminary agreement of the co-legislators on the procurement part, June 2026. Source: European Commission (DG DEFIS); Staff Working Document to the proposal of 17 June 2025.</p>



<p><strong>22.</strong> Readiness Roadmap 2030 and the four flagship projects: European Drone Defence Initiative, Eastern Flank Watch, European Air Shield, European Space Shield; timetable: launch Q1 2026, initial capability end of 2026, full functionality of EDDI end of 2027, Eastern Flank Watch end of 2028. Source: European Commission (DG DEFIS); European Parliament, EPRS, “Eastern Flank Watch and European Drone Wall”, October 2025.</p>



<p><strong>23.</strong> European Commission, Action Plan on drone and counter-drone security, 11 February 2026 (IP/26/364); Drone Alliance with Ukraine; announcement of the allocation of EUR 6 billion from the interest on immobilised Russian assets.</p>



<p><strong>24.</strong> “Drone deals fueled VC’s 139% surge into defense robotics”, PitchBook, 19 March 2026 (approx. USD 6.2 billion in 169 transactions; a 139% increase).</p>



<p><strong>25.</strong> “Ukraine 2025 defence tech investment topped $57.2M, but the ‘funded market’ is $6.8B, says PitchBook”, Resilience Media, 9 July 2026.</p>



<p><strong>26.</strong> Regulation (EU) 2023/588 (the secure connectivity programme 2023–2027; the IRIS constellation). Source: EUR-Lex; European Commission (DG DEFIS).</p>



<p><strong>27.</strong> Directive (EU) 2022/2555 (NIS2), repealing Directive 2016/1148. Source: EUR-Lex; European Commission (DG CNECT).</p>



<p><strong>28.</strong> Directive (EU) 2022/2557 (CER – resilience of critical entities). Source: EUR-Lex.</p>



<p><strong>29.</strong> Regulation (EU) 2024/2847 (the Cyber Resilience Act) – reporting obligations from September 2026, full application from December 2027. Source: EUR-Lex.</p>



<p><strong>30.</strong> Regulation (EU) 2016/679 (GDPR), Article 2(2)(a) and (b), Articles 5, 6, 9, 13–14, 35; Article 4(2) TEU. European Data Protection Board, Guidelines 3/2019 on the processing of personal data through video devices. Directive (EU) 2016/680 and the Act of 14 December 2018 on the protection of personal data processed in connection with the prevention and combating of crime.</p>



<p><strong>31.</strong> Regulation (EU) 2023/2854 (the Data Act), applicable from 12 September 2025; Regulation (EU) 2022/868 (the Data Governance Act).</p>



<p><strong>32.</strong> The Digital Omnibus – the data part (GDPR, privacy in electronic communications, NIS2, the Data Act, DORA): negotiating status as at July 2026; withdrawal of the Cypriot Presidency’s compromise text from the COREPER II procedure at the end of June 2026. EDPB and EDPS, Joint Opinion 2/2026 of 11 February 2026 (opposition to the narrowing of the definition of personal data); Joint Opinion 1/2026 of 20 January 2026 on the amendments to the Artificial Intelligence Act.</p>



<p><strong>33.</strong> The Convention on International Civil Aviation (Chicago, 1944), Articles 3, 3 bis and 8; Additional Protocol I to the Geneva Conventions (1977), Article 36.</p>



<p><strong>34.</strong> The Group of Governmental Experts on LAWS within the framework of the CCW Convention: rolling text since 2024; joint statement of 42 states, September 2025; resolution of the First Committee of the UN General Assembly of 6 November 2025 (156 states); joint call of the UN Secretary-General and the President of the ICRC for the conclusion of negotiations by the end of 2026; Seventh CCW Review Conference – November 2026. Source: UNODA; Lieber Institute West Point, May 2026.</p>



<p><strong>35.</strong> NATO, principles of the responsible use of artificial intelligence in defence (2021) and the revised AI strategy.</p>



<p><strong>36.</strong> The Act of 8 December 2006 on the Polish Air Navigation Services Agency (Journal of Laws of 2025, item 1267), including the Agency’s extended competences in the area of unmanned systems.</p>



<p><strong>37.</strong> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts (Journal of Laws of 2026, item 815) – implementation of the CER Directive; the powers of critical infrastructure operators to use jamming devices (from 26 June 2026); the new Chapter 6a concerning unmanned floating objects; the extension of the powers of the Police, the Border Guard, the State Protection Service and the Military Gendarmerie; security audits; the Maritime Security Centre.</p>



<p><strong>38.</strong> The Act of 11 March 2022 on the Defence of the Homeland.</p>



<p><strong>39.</strong> The draft deregulatory amendment of the Aviation Law, transmitted by the Civil Aviation Authority to the Ministry of Infrastructure on 5 May 2026 (the system of penalties, insurance, notifications, protection of critical infrastructure, counter-drone systems) (at present no publication of the source text – see the footnotes referring to press information sources).</p>



<p><strong>40.</strong> Directive 2014/53/EU on radio equipment (essential requirements, harmful interference).</p>



<p><strong>41.</strong> Regulation (EU) 2019/452 establishing a framework for the screening of foreign direct investments; the Act of 24 July 2015 on the control of certain investments.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p><a href="#_ftnref1" id="_ftn1">[1]</a> <a href="https://www.youtube.com/watch?v=GCOeO35PQh8">https://www.youtube.com/watch?v=GCOeO35PQh8</a> Cf. the analytical material of a Polish commentator on the war and new technologies, based on accounts attributed to Ukrainian military intelligence (HUR), where it was indicated that Russia is producing “more Shaheds of the Geran 4 and 5 model, i.e.&nbsp;the jet variants, than Geran 2 drones, i.e.&nbsp;the piston ones – 3,000 jet-powered per month and 2,800 piston-powered.”</p>



<p><a href="#_ftnref2" id="_ftn2">[2]</a> Paweł Jeżowski, Rosja 2026: Koniec snu Putina o Imperium [Russia 2026: The End of Putin’s Dream of Empire] – Paweł Jeżowski <a href="https://www.youtube.com/watch?v=JSA9sh44Qj4&amp;t=27s">https://www.youtube.com/watch?v=JSA9sh44Qj4&amp;t=27s</a></p>



<p><a href="#_ftnref3" id="_ftn3">[3]</a> European Commission, <em>Communication from the Commission to the European Parliament and the Council – Action Plan on Drone and Counter Drone Security</em>, COM(2026) 81 final, 11 February 2026.</p>



<p><a href="#_ftnref4" id="_ftn4">[4]</a> Treaty on the Functioning of the European Union, Article 288 – the legal character of regulations, directives and other instruments of EU law.</p>



<p><a href="#_ftnref5" id="_ftn5">[5]</a> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815.</p>



<p><a href="#_ftnref6" id="_ftn6">[6]</a> The governmental bill amending the Act on Crisis Management and certain other acts, Sejm print no. 2355, the explanatory memorandum to the bill.</p>



<p><a href="#_ftnref7" id="_ftn7">[7]</a> The Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, <strong>Journal of Laws of 2026, item 815</strong>, introducing, inter alia, Article 16c into the Act of 26 April 2007 on Crisis Management. Text of the act: <a href="https://eli.gov.pl/eli/DU/2026/815/ogl/pol?utm_source=chatgpt.com">https://eli.gov.pl/eli/DU/2026/815/ogl/pol</a></p>



<p><a href="#_ftnref8" id="_ftn8">[8]</a> The Act of 26 April 2007 on Crisis Management, Article 16c, added by the Act of 29 May 2026.</p>



<p><a href="#_ftnref9" id="_ftn9">[9]</a> The Act of 3 July 2002 – Aviation Law, Article 156ze(1).</p>



<p><a href="#_ftnref10" id="_ftn10">[10]</a> The governmental bill amending the Act on Crisis Management and certain other acts, <strong>Sejm print no. 2355</strong>, together with the explanatory memorandum, Sejm of the Republic of Poland, 10th term: <a href="https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355"><u>https://www.sejm.gov.pl/Sejm10.nsf/druk.xsp?nr=2355</u></a></p>



<p><a href="#_ftnref11" id="_ftn11">[11]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), Article 6 and Article 113.</p>



<p><a href="#_ftnref12" id="_ftn12">[12]</a> The regulation amending Regulation (EU) 2024/1689 as regards the dates of application of the obligations concerning high-risk AI systems.</p>



<p><a href="#_ftnref13" id="_ftn13">[13]</a> <strong>Council on Foreign Relations (CFR)</strong> The CFR indicates that the war in Ukraine has led to a hitherto unseen pace of innovation in unmanned systems: “the Russia-Ukraine war is driving innovations in autonomous warfare not seen on other battlefields.” Kristen Thompson, <em>How the Drone War in Ukraine Is Transforming Conflict</em>, Council on Foreign Relations, 16 January 2024.</p>



<p><a href="#_ftnref14" id="_ftn14">[14]</a> The <strong>Carnegie Endowment for International Peace</strong> describes the conflict as a “living laboratory” for new doctrines of warfare: “both sides are now engaged in a sustained effort to gain advantage through rapid innovation and adaptation, introducing new types of unmanned systems, countermeasures, and operating methods at unprecedented speed.” Andriy Zagorodnyuk, <em>The New Revolution in Military Affairs</em>, Carnegie Endowment for International Peace, 2026.</p>



<p><a href="#_ftnref15" id="_ftn15">[15]</a> <strong>CSIS – Center for Strategic and International Studies</strong> The CSIS report describes how, after the start of the full-scale invasion, Ukraine created within about three years an entirely new defence technology ecosystem based on drones, shortening development cycles from multi-year military programmes to months. Kateryna Bondar, <em>Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine</em>, Center for Strategic and International Studies (CSIS), 18 July 2025.</p>



<p><a href="#_ftnref16" id="_ftn16">[16]</a> K. Bondar, <em>Unleashing U.S. Military Drone Dominance: What the United States Can Learn from Ukraine</em>, Center for Strategic and International Studies (CSIS), 2025. The author indicates that the war in Ukraine has radically shortened the cycles of development and deployment of drone technologies: solutions whose development in classic military programmes took many years are now designed, tested and deployed in periods counted in months. Link: <a href="https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine">https://www.csis.org/analysis/unleashing-us-military-drone-dominance-what-united-states-can-learn-ukraine</a> , Michael Kofman, Rob Lee, <em>Not Built for Purpose: The Russian Military’s Ill-Fated Force Design</em>, Center for a New American Security / Carnegie Endowment for International Peace, an analysis of the technological adaptation of both sides of the conflict and the role of the rapid iteration of unmanned systems.</p>



<p>Link: <a href="https://carnegieendowment.org">https://carnegieendowment.org</a> International Institute for Strategic Studies (IISS), <em>The Military Balance 2025</em>, chapters on the Russo-Ukrainian war and the development of unmanned systems. The IISS indicates that the conflict in Ukraine has led to the mass use of drones as a basic element of combat operations and has accelerated the development of technologies for countering unmanned systems. Link: <a href="https://www.iiss.org/publications/the-military-balance/">https://www.iiss.org/publications/the-military-balance/</a></p>



<p>Samuel Bendett, <em>Russia’s War in Ukraine: The Role of Unmanned Systems and the Future of Warfare</em>, Center for Naval Analyses (CNA). Bendett’s analyses frequently indicate that the war in Ukraine has become a “laboratory” for the rapid evolution of unmanned systems, in which the innovation cycle has been shortened from years to months.</p>



<p>Link: <a href="https://www.cna.org/">https://www.cna.org/</a></p>



<p><a href="#_ftnref17" id="_ftn17">[17]</a> <a href="https://www.youtube.com/watch?v=vI1W4bYCuNA&amp;t=181s">https://www.youtube.com/watch?v=vI1W4bYCuNA&amp;t=181s</a>; thus General Skrzypczak in the press service: “<em>the 7th day of the offensive operation conducted by the Russians is ending. The Russians have not achieved their main objectives, the objectives of the operation, that is they have not captured and have not managed to carry out the encirclement of Kyiv and have not come out on the Mykolaiv axis towards Odesa in order to encircle it jointly with a naval landing. On the auxiliary axes they achieved limited success; they approached Kharkiv and Mariupol; they took Zaporizhzhia. The problem is that the Russians have lost their momentum; the offensive has been halted essentially along the entire front line; the Russians are preparing, trying to bring up reserves, to reconstitute the forces that are prepared, in order to prepare them for combat, but at this moment they do not have such capabilities.</em>”</p>



<p><a href="#_ftnref18" id="_ftn18">[18]</a> In practice, it is precisely at this point that the real value of legal advice for companies from the UAV and dual-use sector begins. For the same product may simultaneously be subject to the rules of aviation law, export law, data protection, cybersecurity, AI compliance and contractual restrictions connected with its further use by the client or integrator. Effective advice therefore does not consist in the analysis of a single provision in isolation from the rest, but in building a coherent risk map: from the classification of the product and the market entry model, through the assessment of compliance obligations and export restrictions, to the structure of contracts, responsibility for implementation and the security of project financing. In the drone sector, the advantage today is gained not only by those who develop better technology, but also by those who are able to order its legal and transactional status earlier in many jurisdictions simultaneously.</p>



<p><a href="#_ftnref19" id="_ftn19">[19]</a> Lieber Institute at West Point, <em>Whose Decision Was It? Drone Swarms and the Accountability Gap in Ukraine</em>, 25 July 2026.</p>



<p><a href="#_ftnref20" id="_ftn20">[20]</a> Commission Delegated Regulation (EU) 2019/945 of 12 March 2019 on unmanned aircraft systems and on third-country operators of unmanned aircraft systems, OJ EU L 152 of 11.06.2019, p.&nbsp;1.</p>



<p><a href="#_ftnref21" id="_ftn21">[21]</a> Commission Implementing Regulation (EU) 2019/947 of 24 May 2019 on the rules and procedures for the operation of unmanned aircraft, in particular Article 14 (the operator registration obligation). The character of the operator registration obligation, including for drones equipped with sensors capable of capturing personal data, is also explained by EASA.</p>



<p><a href="#_ftnref22" id="_ftn22">[22]</a> Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), in particular Article 4(1), Article 5, Article 6 and Article 35.</p>



<p><a href="#_ftnref23" id="_ftn23">[23]</a> Judgment of the Court of Justice of 11 December 2014, <strong>František Ryneš v Úřad pro ochranu osobních údajů</strong>, C-212/13, EU:C:2014:2428.</p>



<p><a href="#_ftnref24" id="_ftn24">[24]</a> Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items.</p>



<p><a href="#_ftnref25" id="_ftn25">[25]</a> Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), in particular Article 3, Article 6 and Annexes I and III.</p>



<p><a href="#_ftnref26" id="_ftn26">[26]</a> DJI (full name: SZ DJI Technology Co., Ltd., also referred to as Shenzhen DJI Sciences and Technologies Ltd.) is a private technology company with its registered office in Shenzhen in the People’s Republic of China, founded in 2006 by Frank Wang. The company specialises in the production of commercial and professional unmanned systems, image stabilisers, cameras, aerial imaging devices and solutions for consumer, industrial and agricultural applications. Its most recognisable product lines include, inter alia, Mavic, Mini, Air, Avata, Matrice, Agras and the Osmo line of handheld devices. In the trade literature and media coverage, DJI is commonly described as the largest manufacturer of consumer drones in the world, whereby, owing to the private character of the company, data on its precise revenues and sales volumes are not fully public; publicly available sources point, however, to the global scale of its activity, employment counted in the thousands, and a dominant position in the segment of civil camera drones; <a href="https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/">https://www.reuters.com/article/technology/game-of-drones-chinese-giant-dji-hit-by-us-tensions-staff-defections-idUSKBN2AZ0PV/</a></p>



<p><a href="#_ftnref27" id="_ftn27">[27]</a> <a href="https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic">https://odessa-journal.com/the-ukrainian-company-has-unveiled-the-zoom-drone-as-an-alternative-to-the-chinese-dji-mavic</a></p>



<p><a href="#_ftnref28" id="_ftn28">[28]</a> <a href="https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/">https://rubryka.com/ru/2024/10/21/ukrayinska-kompaniya-rozrobyla-dron-rozvidnyk-zoom-u-nishi-dji-mavic/</a></p>



<p><a href="#_ftnref29" id="_ftn29">[29]</a> <a href="https://www.frontline-robotics.tech/en#product">https://www.frontline-robotics.tech/en#product</a></p>



<p><a href="#_ftnref30" id="_ftn30">[30]</a> The NATO Codification System (NCS) does not derive from a single statute or regulation, but from NATO’s allied standardisation-logistics system, managed by Allied Committee 135 (AC/135). The basic system document is ACodP-1 (NATO Manual on Codification / AC/135 Codification Manual), which sets out the principles, responsibilities and procedures of codification. The system further rests on a series of NATO standardisation agreements (STANAG), in particular STANAG 3150, STANAG 3151, STANAG 4199 and STANAG 4438.</p>



<p><a href="https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO">https://www.dla.mil/Working-With-DLA/Federal-and-International-Cataloging/NATO</a></p>



<p><a href="#_ftnref31" id="_ftn31">[31]</a> <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/">https://www.atlanticcouncil.org/blogs/ukrainealert/fpv-drones-in-ukraine-are-changing-modern-warfare/</a></p>



<p><a href="#_ftnref32" id="_ftn32">[32]</a> <a href="https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/">https://vgi.com.ua/en/the-race-for-drone-independence-ukraines-fpv-component-ecosystem/</a></p>



<p><a href="#_ftnref33" id="_ftn33">[33]</a> <a href="https://brave1.gov.ua/en">https://brave1.gov.ua/en</a></p>



<p><a href="#_ftnref34" id="_ftn34">[34]</a> <a href="https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii">https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii</a></p>



<p><a href="https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems">https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems</a></p>



<p><a href="#_ftnref35" id="_ftn35">[35]</a> <a href="https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/">https://www.aspistrategist.org.au/the-underexploited-potential-of-ukrainian-defence-tech/</a></p>



<p><a href="#_ftnref36" id="_ftn36">[36]</a> <a href="https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy">https://digitalstate.gov.ua/news/tech/brave1-market-ukrayina-zapuskaye-marketpleys-viyskovykh-innovatsiy</a></p>



<p><a href="#_ftnref37" id="_ftn37">[37]</a> <a href="https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation">https://www.nationaldefensemagazine.org/articles/2025/5/28/as-russia-ukraine-war-continues-so-does-drone-innovation</a></p>



<p><a href="https://www.reuters.com/business/aerospace-defense/ukraine-sharply-raise-purchases-home-produced-fpv-drones-2025-2025-03-10">https://www.reuters.com/business/aerospace-defense/ukraine-sharply-raise-purchases-home-produced-fpv-drones-2025-2025-03-10</a></p>



<p><a href="https://www.reuters.com/world/europe/ukraine-ramps-up-arms-production-can-produce-4-million-drones-year-zelenskiy-2024-10-02">https://www.reuters.com/world/europe/ukraine-ramps-up-arms-production-can-produce-4-million-drones-year-zelenskiy-2024-10-02</a></p>



<p><a href="https://euromaidanpress.com/2026/01/26/ukraine-aims-to-build-7-million-drones-in-2026-70-times-more-than-the-us">https://euromaidanpress.com/2026/01/26/ukraine-aims-to-build-7-million-drones-in-2026-70-times-more-than-the-us</a></p>



<p><a href="#_ftnref38" id="_ftn38">[38]</a> <a href="https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c">https://cms.egrants.com.ua/assets/4621da83-b816-4967-8328-b9223a6c0d1c</a></p>



<p><a href="#_ftnref39" id="_ftn39">[39]</a> <a href="https://usf.com.ua/en/about-usf">https://usf.com.ua/en/about-usf</a></p>



<p><a href="#_ftnref40" id="_ftn40">[40]</a> <a href="https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en">https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en</a></p>



<p><a href="#_ftnref41" id="_ftn41">[41]</a> See Cabinet of Ministers of Ukraine, <em>Ukraine launches BRAVE1 defence tech cluster to stimulate development of military innovations and defence technologies</em>; cf.&nbsp;also Brave1, <em>About Brave1</em>, where it is indicated that Brave1 is a governmental initiative directed at the development of defence technologies, implemented by the Innovation Development Fund and initiated by the competent state organs and the components of Ukraine’s security and defence sector.</p>



<p><a href="https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii">https://www.kmu.gov.ua/en/news/v-ukraini-zapustyly-defense-tech-cluster-brave1-iakyi-stymuliuvatyme-rozvytok-viiskovykh-innovatsii-ta-oboronnykh-tekhnolohii</a></p>



<p>See EEAS / Delegation of the European Union to Ukraine, <em>EU4UA Defence Tech: EU and Ukraine launch new EUR 3.3 million BRAVE1 grant programme</em>, indicating that the project is financed by the European Union and implemented by BRDO in cooperation with Brave1; cf.&nbsp;also BRDO, <em>Strengthening the Innovation Capacities of the Ukrainian Defence Technological Industrial Base</em>, where the title of the implementation project linked with the EU4UA Defence Tech initiative was disclosed.</p>



<p><a href="https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en">https://www.eeas.europa.eu/delegations/ukraine/eu4ua-defence-tech-eu-and-ukraine-launch-new-%E2%82%AC33-million-brave1-grant-programme_en</a></p>



<p>See Regulations for the Brave1 EU4UA Defence Tech Grant Program, available in the Legal Terms section of the programme <em>Grant for the development of components for unmanned systems</em> on the eGrants platform; cf.&nbsp;also the Digital State communication, indicating that EU4UA Defence Tech is financed by the European Union and implemented by BRDO in cooperation with Brave1.</p>



<p><a href="https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems">https://egrants.com.ua/en/programs/grant-for-the-development-of-components-for-unmanned-systems</a></p>



<p><a href="#_ftnref42" id="_ftn42">[42]</a> The concept of the radio horizon should be treated as a technical, not a normative, term. It does not function as a legal definition in the EASA regime, in U-space or in the classic acts of electronic communications law. Its legal significance is, however, obvious, because it describes a material limitation of communications on which the possibility of conducting unmanned operations beyond the direct line of sight depends, and thus it indirectly affects the assessment of the conformity of radio equipment, the safety of operations, the design of BVLOS architecture and liability for the continuity and reliability of transmission.</p>



<p><a href="#_ftnref43" id="_ftn43">[43]</a> <a href="https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0">https://interoperable-europe.ec.europa.eu/collection/rolling-plan-ict-standardisation/u-space-0</a></p>



<p><a href="#_ftnref44" id="_ftn44">[44]</a> <a href="https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/">https://militaeraktuell.at/en/ukraine-opens-next-round-in-drone-frequency-war/</a>;</p>



<p><a href="#_ftnref45" id="_ftn45">[45]</a> <strong>Mesh modems turn Shaheds into FPV drones: how enemy technology works:</strong></p>



<p><a href="https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495">https://dev.ua/en/news/mesh-modemy-u-shakhedakh-peretvoriuiut-ikh-na-fpv-drony-1762344495</a></p>



<p><a href="#_ftnref46" id="_ftn46">[46]</a> <a href="https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/">https://dronexl.co/2026/02/28/ukraine-shahed-drone-relay-stations-belarus/</a></p>



<p><a href="#_ftnref47" id="_ftn47">[47]</a> <a href="https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/">https://www.atlanticcouncil.org/blogs/ukrainealert/fiber-optics-drones-have-emerged-as-critical-kit-for-both-russia-and-ukraine/</a>, <a href="https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/">https://www.washingtonpost.com/world/2025/05/23/ukraine-russia-drones-fiberoptic-jamming/</a></p>



<p><a href="#_ftnref48" id="_ftn48">[48]</a> <a href="https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/">https://www.act.nato.int/article/innovation-challenge-fibre-optic-drones/</a></p>



<p><a href="#_ftnref49" id="_ftn49">[49]</a> European Commission, Joint Research Centre, <em>C-UAS detection, tracking and identification technology</em>.</p>



<p><a href="https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf">https://publications.jrc.ec.europa.eu/repository/bitstream/JRC140692/JRC140692_01.pdf</a></p>



<p>Alex Braszko, Center for Army Lessons Learned, August 12, 2025; Fiber Optic Drones: Posing a Significant C-UAS Challenge &#8211; <a href="https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge">https://www.army.mil/article/287737/fiber_optic_drones_posing_a_significant_c_uas_challenge</a></p>



<p><a href="#_ftnref50" id="_ftn50">[50]</a> <a href="https://csrc.nist.gov/glossary/term/spoofing">https://csrc.nist.gov/glossary/term/spoofing</a>, <a href="https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf">https://www.faa.gov/about/office_org/headquarters_offices/avs/offices/afx/afs/afs400/afs410/GNSS/GPS_GNSS_Interference_Resource_Guide.pdf</a></p>



<p><a href="#_ftnref51" id="_ftn51">[51]</a> <a href="https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying">https://www.armyrecognition.com/archives/archives-defense-exhibitions/2026-archives-news-defense-exhibitions/bedex-2026/ukraine-to-export-combat-proven-vampire-heavy-drone-for-night-strikes-and-mine-laying</a></p>



<p><a href="#_ftnref52" id="_ftn52">[52]</a> <a href="https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371">https://united24media.com/latest-news/russia-forms-units-of-agricultural-drones-to-mirror-ukrainian-tactics-7371</a></p>



<p><a href="#_ftnref53" id="_ftn53">[53]</a> <a href="https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/">https://www.pravda.com.ua/eng/articles/2026/01/15/8016293/</a> ; <a href="https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647">https://united24media.com/defense-tech/a-russian-drone-that-takes-off-every-minute-along-ukraines-front-how-do-you-stop-molniya-19647</a></p>



<p><a href="#_ftnref54" id="_ftn54">[54]</a> <a href="https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md">https://github.com/cognis-digital/awesome-drone-warfare-osint/blob/main/docs/drones/lancet.md</a></p>



<p><a href="#_ftnref55" id="_ftn55">[55]</a> <a href="https://defence-blog.com/ukraine-fields-new-recon-strike-drone/">https://defence-blog.com/ukraine-fields-new-recon-strike-drone/</a></p>



<p><a href="#_ftnref56" id="_ftn56">[56]</a> <a href="https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/">https://www.wbgroup.pl/en/produkt/warmate-loitering-munnitions/</a>, <a href="https://en.wikipedia.org/wiki/WB_Electronics_Warmate">https://en.wikipedia.org/wiki/WB_Electronics_Warmate</a></p>



<p><a href="#_ftnref57" id="_ftn57">[57]</a> <a href="https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html">https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html</a>;</p>



<p><a href="#_ftnref58" id="_ftn58">[58]</a> <a href="https://bavovna.ai/uav/fp-1/">https://bavovna.ai/uav/fp-1/</a>;</p>



<p><a href="#_ftnref59" id="_ftn59">[59]</a> See NV, How Ukraine-made FP-1 drone reshapes long-range strikes; Militarnyi, Ukrainian Fire Point Establishes In-House Production of Engines for Long-Range Drones; Reuters, Ukrainian drones hit Russia’s largest refinery, in one of deepest strikes yet; cf.&nbsp;also UNN and RBC-Ukraine in relation to the attack on Omsk and the scale of FP-1 production <a href="https://english.nv.ua/nation/ukraine-fields-the-low-cost-fp-1-long-range-drone-nv-discloses-the-uav-specs-50559428.html"><u>NV</u></a> <a href="https://militarnyi.com/en/news/ukrainian-fire-point-establishes-in-house-production-of-engines-for-long-range-drones"><u>Militarnyi</u></a> <a href="https://www.reuters.com/business/energy/ukrainian-drones-hit-russias-largest-refinery-one-deepest-strikes-yet-2026-07-06/"><u>Reuters</u></a> <a href="https://unn.ua/en/amp/siberia-is-also-within-reach-of-ukrainian-precision-president-on-the-fp-1-drone-strike-on-the-omsk-refinery"><u>UNN</u></a> <a href="https://newsukraine.rbc.ua/news/ukraine-s-fp-1-drones-fly-3-400-km-to-strike-1783345876.html"><u>RBC-Ukraine</u></a>.</p>



<p><a href="#_ftnref60" id="_ftn60">[60]</a> See the MTCR Guidelines, the official MTCR website, indicating the division of the control annex into Category I and Category II; cf.&nbsp;also U.S. Department of State, <em>Missile Technology Control Regime (MTCR) Frequently Asked Questions</em>, where it is indicated that Category I covers complete rocket systems and unmanned aerial vehicle systems capable of delivering a payload of at least 500 kg to a range of at least 300 km; as regards the absorption of this logic into EU law, see Regulation (EU) 2021/821 setting up a Union regime for the control of exports of dual-use items. <a href="https://www.mtcr.info/en/mtcr-guidelines"><u>MTCR</u></a> <a href="https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions"><u>U.S. Department of State</u></a> <a href="https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:L:2021:338:FULL&amp;from=EN"><u>EUR-Lex</u></a>; <a href="https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions">https://www.state.gov/bureau-of-international-security-and-nonproliferation/releases/2025/01/missile-technology-control-regime-mtcr-frequently-asked-questions</a></p>



<p><a href="#_ftnref61" id="_ftn61">[61]</a> On the significance of long-range communications for modern drone operations, see Atlantic Council, <em>The coming compute war in Ukraine</em>; on terminal guidance / machine vision enabling autonomous terminal-phase homing, see Modern War Institute, <em>Battlefield Drones and the Accelerating Autonomous Arms Race in Ukraine</em> and Defense Express, <em>How Ukrainian FPV Drones With Automated Terminal Guidance Work</em>; <a href="https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/">https://mwi.westpoint.edu/battlefield-drones-and-the-accelerating-autonomous-arms-race-in-ukraine/</a></p>



<p><a href="#_ftnref62" id="_ftn62">[62]</a> See Article 2(3) and recital 24 of Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the AI Act), which exclude from the regulation’s scope AI systems used exclusively for military, defence or national security purposes; cf.&nbsp;also the discussions on autonomous weapon systems (LAWS) conducted within the framework of the Convention on Certain Conventional Weapons (CCW), in particular the work of the Group of Governmental Experts on Lethal Autonomous Weapons Systems (GGE on LAWS).</p>



<p><a href="#_ftnref63" id="_ftn63">[63]</a> See EASA, <em>Easy Access Rules for Unmanned Aircraft Systems</em>, revision from June 2026, indicating that this revision incorporates the AMC and GM to Regulation (EU) 2019/947 stemming from ED Decision 2025/018/R; cf.&nbsp;also the online version of the publication of 30 June 2026. <a href="https://www.easa.europa.eu/en/document-library/easy-access-rules/easy-access-rules-unmanned-aircraft-systems">EASA</a> <a href="https://www.easa.europa.eu/en/document-library/easy-access-rules/online-publications/easy-access-rules-unmanned-aircraft-systems">EASA online publication</a>.</p>



<p><a href="#_ftnref64" id="_ftn64">[64]</a> See European Parliamentary Research Service, <em>Defence and artificial intelligence</em> (2025), indicating that the European Parliament adopted two main resolutions concerning LAWS and military AI – in 2018 and 2021; cf.&nbsp;also EEAS, <em>Autonomous weapons must remain under human control, Mogherini says at European Parliament</em>. <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2025/769580/EPRS_BRI(2025)769580_EN.pdf"><u>EPRS PDF</u></a> <a href="https://www.eeas.europa.eu/eeas/autonomous-weapons-must-remain-under-human-control-mogherini-says-european-parliament_en"><u>EEAS</u></a></p>



<p><a href="#_ftnref65" id="_ftn65">[65]</a> See European Parliament Legislative Train, <em>Digital Omnibus on AI</em>, indicating that the proposal formed part of the package published on 19 November 2025; cf.&nbsp;also EPRS, <em>Digital Omnibus on AI</em>, where it is indicated that the co-legislators reached agreement in the trilogue on 7 May 2026, and the Parliament approved it on 16 June 2026; on the final adoption by the Council, see Consilium, <em>Artificial Intelligence: Council gives final green light to simplify and streamline rules</em>, 29 June 2026; the final act: Regulation (EU) 2026/1744. <a href="https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai">Legislative Train</a> <a href="https://www.europarl.europa.eu/RegData/etudes/BRIE/2026/782651/EPRS_BRI%282026%29782651_EN.pdf">EPRS PDF</a> <a href="https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules">Consilium</a> <a href="https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng">EUR-Lex</a>;</p>



<p><a href="#_ftnref66" id="_ftn66">[66]</a> Regulation (EU) 2021/821 entered into force on 9 September 2021 as the new basic act of the Union’s system for the control of exports of dual-use items, replacing the earlier Regulation (EC) No 428/2009. The reference to 15 November 2025 does not mean that the act “ends” in 2025, but that from that day the cited consolidated version applies, taking account of the amendments to the text so far. The date of 8 September 2025, in turn, refers to one of the updates of the control lists / annexes. In August 2026, the regulation still remains an act in force.</p>



<p><a href="#_ftnref67" id="_ftn67">[67]</a> The transfer of model weights means the transfer of the trained parameters of the AI model themselves – that is, the numbers which the model “carries within itself” after training and on the basis of which it operates.</p>



<p><a href="#_ftnref68" id="_ftn68">[68]</a> See Regulation (EU) 2021/697 of the European Parliament and of the Council of 29 April 2021 establishing the European Defence Fund; cf.&nbsp;also the European Defence Fund (2021–2027) on EUR-Lex and the European Commission’s official website concerning the EDF. <a href="http://eur-lex.europa.eu/eli/reg/2021/697/oj/eng">EUR-Lex</a> <a href="https://eur-lex.europa.eu/EN/legal-content/summary/european-defence-fund-2021-2027.html">EUR-Lex summary</a> <a href="https://commission.europa.eu/funding-and-tenders/find-funding/eu-funding-programmes/european-defence-fund_en">European Commission</a>;</p>



<p><a href="#_ftnref69" id="_ftn69">[69]</a> See Regulation (EU) 2023/2418 of the European Parliament and of the Council of 18 October 2023 establishing an instrument for the reinforcement of the European defence industry through common procurement (EDIRPA); cf.&nbsp;also the EUR-Lex summary and the European Commission’s official website concerning EDIRPA. <a href="https://eur-lex.europa.eu/eli/reg/2023/2418/oj/eng">EUR-Lex</a> <a href="https://eur-lex.europa.eu/EN/legal-content/summary/strengthening-the-european-defence-industry-through-common-procurement.html">EUR-Lex summary</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/edirpa_en">European Commission</a>;</p>



<p><a href="#_ftnref70" id="_ftn70">[70]</a> ASAP was established by Regulation (EU) 2023/1525 of the European Parliament and of the Council of 20 July 2023 as an instrument supporting the increase of the production capacities of European industry in the field of ammunition and missiles; the logic of this act – consisting in the public strengthening of the production capabilities of the defence industry – is functionally transferable also to the mass production of loitering munitions and drones. <a href="https://eur-lex.europa.eu/eli/reg/2023/1525/oj/eng">EUR-Lex</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/asap_en">European Commission</a>;</p>



<p><a href="#_ftnref71" id="_ftn71">[71]</a> SAFE (Security Action for Europe) was established by Council Regulation (EU) 2025/1106 of 27 May 2025 as a new instrument strengthening European defence capabilities and the defence industry through financial mechanisms and the support of coordinated actions of the Member States; it remains a current element of the EU defence architecture also in 2026. <a href="https://eur-lex.europa.eu/eli/reg/2025/1106/oj/eng">EUR-Lex</a> <a href="https://www.consilium.europa.eu/en/press/press-releases/2025/05/27/safe-council-adopts-new-financial-instrument-to-boost-eu-defence-capabilities/">Consilium</a>;</p>



<p><a href="#_ftnref72" id="_ftn72">[72]</a> See Regulation (EU) 2025/2643 of the European Parliament and of the Council of 16 December 2025 establishing the European Defence Industry Programme (EDIP); cf.&nbsp;also the European Commission’s official website concerning EDIP. <a href="https://eur-lex.europa.eu/eli/reg/2025/2643/oj/eng">EUR-Lex</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/edip-forging-europes-defence_en">European Commission</a>;</p>



<p><a href="#_ftnref73" id="_ftn73">[73]</a> This is a broader European Commission package, adopted on 17 June 2025, intended to create a “defence-readiness mindset” and to simplify the regulatory environment for defence investment. The Commission itself describes it as a comprehensive package and a simplification proposal, and the Parliament in the Legislative Train speaks outright of a Communication on the Defence Readiness Omnibus. It is therefore not simply “the same as EDIP”, but rather a deregulatory-simplification package and the political-legislative environment for faster action by the defence sector. <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/defence-readiness-omnibus_en">European Commission</a> <a href="https://www.europarl.europa.eu/legislative-train/theme-a-new-era-for-european-defence-and-security/file-defence-omnibus">Legislative Train</a></p>



<p><a href="#_ftnref74" id="_ftn74">[74]</a> See European Commission, <em>Readiness Roadmap 2030</em> and <em>White Paper for European Defence &#8211; Readiness 2030</em>, indicating the four flagship projects: Eastern Flank Watch, the European Drone Defence Initiative, the European Air Shield and the European Space Shield. <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/readiness-roadmap-2030_en">European Commission</a> <a href="https://defence-industry-space.ec.europa.eu/eu-defence-industry/white-paper-european-defence-readiness-2030_en">White Paper</a>.</p>



<p><a href="#_ftnref75" id="_ftn75">[75]</a> Regulation (EU) 2023/588 of the European Parliament and of the Council of 15 March 2023 establishing the Union Secure Connectivity Programme for the period 2023–2027. <a href="https://eur-lex.europa.eu/eli/reg/2023/588/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref76" id="_ftn76">[76]</a> Directive (EU) 2022/2555 (NIS2) of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union. <a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref77" id="_ftn77">[77]</a> Directive (EU) 2022/2557 (CER) of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities. <a href="https://eur-lex.europa.eu/eli/dir/2022/2557/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref78" id="_ftn78">[78]</a> Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA) of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity requirements for products with digital elements. <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng">eur-lex.europa.eu</a>.</p>



<p><a href="#_ftnref79" id="_ftn79">[79]</a> See EDPB/EDPS Joint Opinion 2/2026 of 11 February 2026 on the Digital Omnibus and the EDPB communication of the same day; as to the further negotiating stage and the withdrawal of the text from COREPER II at the end of June 2026, cf.&nbsp;the expert source: Privacy Next, Digital Omnibus Negotiations (GDPR) &#8211; July 2026 Update. <a href="https://www.edpb.europa.eu/news/digital-omnibus-edpb-and-edps-support-simplification-and-competitiveness-while-raising-key_en">EDPB</a> <a href="https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-22026-on-the-proposal-for-a-regulation-as_en">Joint Opinion 2/2026</a> <a href="https://www.privacynext.eu/resources/digital-omnibus-negotiations-gdpr-july-2026-update/">Privacy Next</a>.</p>



<p><a href="#_ftnref80" id="_ftn80">[80]</a> See Article 36 of Additional Protocol I of 1977 to the Geneva Conventions; cf.&nbsp;also ICRC, <em>A Guide to the Legal Review of New Weapons, Means and Methods of Warfare</em>. <a href="https://ihl-databases.icrc.org/en/ihl-treaties/api-1977/article-36">ICRC art. 36</a> <a href="https://www.icrc.org/en/publication/0902-guide-legal-review-new-weapons-means-and-methods-warfare-measures-implement-article">ICRC Guide</a>.</p>



<p><a href="#_ftnref81" id="_ftn81">[81]</a> See CCW/MSP/2023/7, para. 20, in which the mandate of the Group of Governmental Experts (GGE) on emerging technologies in the area of lethal autonomous weapons systems (LAWS) was defined as the further consideration and formulation, “by consensus”, of a set of elements of an instrument, without prejudging its character; see also CCW/GGE.1/2026/WP.2, paras. 3–5, 76–78. The Seventh CCW Review Conference has been scheduled for 16–20 November 2026 in Geneva (CCW/MSP/2025/8, para. 19(g); see also UN Secretary-General, Letter convening the Seventh Review Conference of the CCW, April 2026).</p>



<p><a href="#_ftnref82" id="_ftn82">[82]</a> NATO, <em>Summary of the NATO Artificial Intelligence Strategy</em>, 22 October 2021, paras. 7–10, in particular para. 9, containing the six Principles of Responsible Use for AI in Defence: Lawfulness, Responsibility and Accountability, Explainability and Traceability, Reliability, Governability and Bias Mitigation; NATO, <em>Summary of NATO’s revised Artificial Intelligence (AI) strategy</em>, 10 July 2024, paras. 2, 5-10. The revised strategy of 2024 confirms the applicability of the six principles of the responsible use of AI and provides for their further operationalisation, inter alia through standards, assessment and testing procedures (TEV&amp;V) and certification mechanisms.</p>



<p><a href="#_ftnref83" id="_ftn83">[83]</a> <a href="https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r">https://www.swiatdronow.pl/podsumowanie-posiedzenia-podkomisji-stalej-do-spraw-lotnictwa-cywilnego-10-06-2026-r</a>; Record of the proceedings of the Standing Subcommittee on Civil Aviation (no. 10) of 10 June 2026, Sejm of the Republic of Poland, in particular the statement of the Director of the Unmanned Aircraft Department of the Civil Aviation Authority, Paweł Szymański, who indicated that the draft amendment concerning unmanned aircraft systems prepared by the Civil Aviation Authority was transmitted to the Ministry of Infrastructure on 5 May 2026, constituting a response to the postulates of civil society and the problems revealed in the practice of applying the new provisions; the draft was described as being of a deregulatory, clarifying and ordering character, covering, inter alia, a change of the regulations concerning mandatory third-party liability insurance and sanctions. <a href="https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&amp;documentId=2AEF7DEF0751F54BC1258E22003E5D23&amp;utm">https://www.sejm.gov.pl/sejm10.nsf/biuletyn.xsp?SessionID=55B1AE69A4EDC2996BDD70EE751F3A4A86C14EE1&amp;documentId=2AEF7DEF0751F54BC1258E22003E5D23&amp;utm</a></p>



<p><a href="#_ftnref84" id="_ftn84">[84]</a> The postulate of meaningful human control does not currently constitute a separate, binding norm of international law. It is a concept developed within the framework of the negotiations concerning autonomous weapon systems, whose purpose is to ensure that the human retains real control over the application of force. Its legal justification is connected above all with the obligation to comply with the existing norms of international humanitarian law, in particular the principles of distinction, proportionality and the taking of precautionary measures, and the obligation to review new means and methods of warfare on the basis of Article 36 of Additional Protocol I.</p>



<p><a href="#_ftnref85" id="_ftn85">[85]</a> Article 6zj(1)–(4) of the Act of 26 April 2007 on Crisis Management, in the wording given by the Act of 29 May 2026 amending the Act on Crisis Management and certain other acts, Journal of Laws of 2026, item 815, in conjunction with Article 156ze(1) of the Act of 3 July 2002 – Aviation Law, consolidated text: Journal of Laws of 2025, item 1431, as amended.</p>



<p><a href="#_ftnref86" id="_ftn86">[86]</a> Article 2(2)(d) and Article 2(3) of Regulation (EU) 2021/821 of the European Parliament and of the Council of 20 May 2021 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, in the current consolidated text; see also Commission Recommendation (EU) 2021/1700 of 15 September 2021 on internal compliance programmes for controls of research involving dual-use items: <a href="https://eur-lex.europa.eu/eli/reg/2021/821/2025-11-15/eng?utm_source=chatgpt.com">Regulation 2021/821</a> and Recommendation 2021/1700.</p>



<p><a id="_ftn87" href="#_ftnref87">[87]</a> The Act of 24 July 2015 on the control of certain investments (consolidated text: Journal of Laws of 2026, item 47, as amended).</p>
<p> </p>






<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/">Drone Warfare</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/drone-warfare/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/output.mp4" length="1532791" type="video/mp4" />
<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/08/output-1-1.mp4" length="1247152" type="video/mp4" />

			</item>
		<item>
		<title>A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Fri, 24 Jul 2026 18:04:36 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[Advertising Law]]></category>
		<category><![CDATA[artificial intelligence law]]></category>
		<category><![CDATA[CONSUMER PROTECTION]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Digital Markets]]></category>
		<category><![CDATA[Digital Markets Act]]></category>
		<category><![CDATA[Digital Services Act]]></category>
		<category><![CDATA[DMA]]></category>
		<category><![CDATA[DSA]]></category>
		<category><![CDATA[e-commerce law]]></category>
		<category><![CDATA[eu regulation]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[influencer marketing]]></category>
		<category><![CDATA[KG Legal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[new technologies]]></category>
		<category><![CDATA[Platform Regulation]]></category>
		<category><![CDATA[Poland business law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[social commerce]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[TikTok Shop]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8857</guid>

					<description><![CDATA[<p>Publication date: July 24, 2026 You see a video, a product catches your eye, and an &#8220;add to cart&#8221; button is already blinking in the corner of the screen. A few seconds later the order is placed, paid for, and on its way — all without leaving the app. That&#8217;s how TikTok Shop works: a [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/">A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 24, 2026</mark></strong></p>



<figure class="wp-block-video"><video autoplay controls loop src="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-2.mp4"></video></figure>



<p>You see a video, a product catches your eye, and an &#8220;add to cart&#8221; button is already blinking in the corner of the screen. A few seconds later the order is placed, paid for, and on its way — all without leaving the app. That&#8217;s how TikTok Shop works: a <em>closed-loop</em> model in which the path from watching a piece of content to completing a purchase has been cut to the bare minimum. That very immediacy is its greatest strength and, at the same time, the source of its most serious concerns.</p>



<span id="more-8857"></span>



<p id="ember53">A platform that in 2017 drew around 72 million monthly users now attracts more than 1.5 billion — and between 11 and 15 million in Poland alone. TikTok has stopped being merely a place for entertainment and has turned into a powerful advertising and sales engine, combining influencer marketing, algorithmic personalization, and the emotional purchasing impulse. For businesses, it is a new and remarkably effective retail space. For consumers, it is an environment in which it grows ever harder to tell an authentic recommendation from an ad, or a fleeting enthusiasm from a considered decision.</p>



<p id="ember54">That is precisely why TikTok Shop has landed at the center of lawmakers&#8217; attention. While its model is not unlawful, the platform&#8217;s operation intersects with an entire web of regulation: from consumer law and the ban on &#8220;dark patterns,&#8221; through the EU&#8217;s DSA and DMA, data protection and safeguards for minors, all the way to advertising, media, and electronic communications law. This article shows where the convenience of one-tap shopping ends and the protection of the buyer&#8217;s free will begins.</p>



<h2 class="wp-block-heading" id="ember55">What makes the TikTok Shop platform innovative?</h2>



<p id="ember56">Today, an effective marketing strategy is becoming an increasingly important priority for sellers. In Poland, monopolies in sales are relatively rare. Many competing companies operate in most industries. When purchasing products, consumers must choose from hundreds, or even thousands, of options offered by different brands. The scale of this phenomenon is evidenced by the fact that in the fourth quarter of 2025, over 2.9 million active businesses operated in Poland alone, the largest group of which were those associated with the retail sector. Meanwhile, buyers generally do not want to spend much time thoroughly analyzing goods available on the market. They are often guided by the opinions of other users, brand recognition, or media coverage. Therefore, in an information society based on the dynamic development of social media, tailoring advertising to current consumer needs and behaviors becomes crucial for running a business. Authentic and credible recommendations from trusted creators are becoming more important, and for many buyers, they are more persuasive than formulaic television commercials.</p>



<p id="ember57">Considering the above arguments, many companies are making changes to their advertising strategies, for example, opting for influencer marketing. Online creators typically publish aesthetically and thematically consistent content that captures the interest of users with similar preferences and tastes. A business partnering with an influencer who shares similar values gains the opportunity to reach a large group of potential consumers, made up of the influencer&#8217;s followers. TikTok has become the dominant platform enabling the implementation of the marketing model described above. In 2017, the application had approximately 72 million monthly active users, and according to data from 2026, this number has increased to approximately 1.54 billion. In Europe alone, TikTok has already reached over 200 million users, and in Poland, the number ranged from 11 to 15 million. The average time spent on the platform is 70 minutes per day, which translates to approximately 35 hours per month. These statistics also indicate the continued growth of TikTok&#8217;s popularity, confirming the future of using social media for advertising and promotional purposes.</p>



<p id="ember58">The development of influencer marketing significantly changed existing marketing practices, and its increasing prevalence led to the transformation of the TikTok app from a social media platform into an advertising system. The effective and profitable collaboration between media and advertising prompted the platform to take the next step in its development, combining these two sectors. Users were offered the opportunity to completely simplify the purchasing process. Previously, consumers only saw product advertisements, which attracted their attention and prompted them to search for sales offers. However, this pattern left them time to consider whether a purchase was truly necessary or necessary. It was also likely that, despite their interest in the product, they would eventually forget about the advertised product, and therefore their desire to purchase it.</p>



<p id="ember59">The solution to the marketing strategy described above turned out to be a new feature presented by TikTok: TikTok Shop. The innovative nature of this tool is based on a closed-loop model, meaning the purchasing process takes place within a single app. Users first encounter content promoting a specific item. They then have the option to immediately purchase it by adding the advertised item to their shopping cart in the bottom corner of the app. TikTok acts as an intermediary for payment, shipping, and the entire order process. In this way, the app has evolved not only into a profitable advertising system but also an online store, becoming a marketplace platform that mediates payment, logistics, and order fulfillment.</p>



<h2 class="wp-block-heading" id="ember60">The origins of TikTok Shop</h2>



<p id="ember61">Initially, the online shopping phenomenon developed through e-commerce. Its popularity contributed to the diversification of online sales into several business models: B2C, B2B, and C2C. The former involves a relationship between a business and an individual customer (examples include online stores such as Zalando, Zara, and IKEA). B2B refers to transactions between businesses, while C2C refers to sales between individuals, such as on platforms like Vinted, OLX, and Allegro.</p>



<p id="ember62">These e-commerce models typically control the sales process independently. Their profits largely come from consumers who shop by searching for specific products they need. Entrepreneurs compete with each other through marketing activities aimed at convincing consumers of the quality of their products and building brand recognition.</p>



<p id="ember63">In the next stage, the development of social media, and consequently influencer marketing, contributed to the emergence of a completely new type of buyer, one driven by impulse. Online creators present a specific lifestyle on their profiles in a significantly idealized form, which attracts the attention of their followers and becomes a role model. The desire to emulate the creator they follow can manifest itself both in their behavior and in the possessions they possess. The influencer thus becomes a person who inspires and encourages the purchase of a given product. Even if, from a rational perspective, the buyer doesn&#8217;t need the product, they often decide to purchase it under the influence of influencer marketing.</p>



<p id="ember64">Additionally, a new branch of e-commerce has emerged, known as discovery commerce . This model relies on the discovery and purchase of new items while actively browsing social media. Highly advanced algorithms select content for users that aligns with their tastes or interests, in order to evoke certain emotions that then transform into a strong purchasing impulse. Social media platforms, recognizing this profitable sector, have contributed to the development of social commerce, including TikTok Shop. This solution capitalizes on users&#8217; fleeting enthusiasm and allows them to complete their order without leaving the app. The entire process, from advertising content to payment and shipping, is handled by TikTok, which can limit the time available for rational purchase consideration.</p>



<h2 class="wp-block-heading" id="ember65">What exactly does the purchasing process look like on TikTok Shop?</h2>



<p id="ember66">TikTok Shop is not a separate app, but a new feature added to the TikTok platform. There&#8217;s no need to create a new account or install a new app. This solution provides access to a wide group of potential consumers, as every existing TikTok user over the age of 18 can familiarize themselves with the new feature. This solution gives businesses multiple ways to reach consumers. The platform offers a separate tab, &#8220;Shop,&#8221; where users can search for specific products using filters and categories, or browse recommended items based on their activity on the platform.</p>



<p id="ember67">Products offered by sellers using the TikTok Shop service can also be viewed on the &#8220;For You Page&#8221; tab. This is the subpage most frequently visited by users. This option is especially useful when a company decides to use influencer marketing. A creator posts a video promoting a selected product, and buyers are immediately presented with a purchase button at the bottom of the page. Consumers can also directly access the profiles of brands and creators to find the products they offer or promote.</p>



<p id="ember68">The latest feature, TikTok Live, is gaining popularity. Before the live stream begins, the seller or influencer adds products available in the TikTok Shop. During the live stream, the host can showcase products, communicate with users, and answer their questions via chat. This can increase the credibility of the product and the seller, as well as encourage consumers to make a purchase, which they can do without interrupting the stream.</p>



<p id="ember69">The very process of posting ads on TikTok Shop helps build consumer trust. Becoming a seller requires thorough verification, which the TikTok platform conducts to protect users from unreliable and fictitious businesses.</p>



<p id="ember70">The first step to becoming a seller is to log in to your TikTok Seller Center account using your email address, phone number, or existing TikTok account. You&#8217;ll also need to fill out an application form with information that proves your seller credentials, such as your company name, address, and contact information.</p>



<p id="ember71">After successful verification, the seller completes their store profile, adding a description, name, logo, seller details, addresses, customer service information, and tax information. It&#8217;s also necessary to configure payment and delivery methods, including the shipping address, available delivery methods, order processing time, and return policy. Connecting the store dashboard to a regular TikTok account is also crucial. This allows for tagging offered products in live videos, etc. The seller then has the option to publish their product, including the title, description, price, available models, and inventory. The platform also allows businesses to add listings by importing a product catalog from another sales platform.</p>



<p id="ember72">After a consumer makes a purchase, the seller receives a sale notification in the TikTok Seller Center. The seller is then responsible for packaging and shipping the item to the user, which can be done manually or using external order processing systems.</p>



<h2 class="wp-block-heading" id="ember73">Distance selling and consumer rights</h2>



<p id="ember74">The TikTok Shop platform offers the option of concluding a sale via a distance contract. This does not require the parties to be physically present at the same time, but rather requires at least one means of distance communication (Act of 30 May 2014 on consumer rights, Article 2). Therefore, when making a purchase through the TikTok Shop, consumer rights are governed by national and European Union law.</p>



<p id="ember75">In Poland, the primary legal act regulating these activities is the Act of May 30, 2014, on Consumer Rights. Article 12 requires businesses to clearly inform consumers in distance contracts, including the method and deadline for contract execution, the total price including taxes, the right to withdraw from the contract, the complaint procedure, and the seller&#8217;s identifying information. The TikTok Shop platform is therefore obligated to provide the required information to the user before finalizing the order via the app. An important regulation is also included in Article 17 of the aforementioned Act and concerns the requirement to design the interface in a way that confirms the consumer&#8217;s awareness of the obligation to pay. In the case of platforms that allow order completion via a &#8220;button,&#8221; it must be clearly marked, e.g., &#8220;I buy with an obligation to pay&#8221; or &#8220;I buy and pay.&#8221; Otherwise, the contract is not concluded. The requirements described above are referred to as &#8221; button &#8221; solution &#8221; and are intended to protect consumers from accidentally concluding paid contracts. Alternative obligations also arise from the Directive of the European Parliament and of the Council of 25 October 2011 on consumer rights.</p>



<p id="ember76">The Consumer Rights Act also implements the EU Commodity Directive (2019/771), introducing uniform standards for the conformity of goods with the contract. A trader is liable for any lack of conformity of goods with the contract upon delivery and for two years from the date the discrepancy is discovered. The Act also governs basic consumer claims in the event of non-conformity, including repair or replacement of the goods, and if this is not possible, a price reduction or withdrawal from the contract.</p>



<p id="ember77">Given that the sales strategy on the TikTok Shop platform relies on recommendation algorithms and influencer marketing, the Omnibus Directive (EU) 2019/2161 of November 27, 2019, plays a significant role in consumer empowerment. Its regulations introduce the obligation to provide information about the lowest price, disclose whether reviews were published by verified consumers, and indicate whether the seller is a business or an individual. The Omnibus Directive therefore increases consumer awareness and allows consumers to make more rational and manipulation-free purchasing decisions.</p>



<h2 class="wp-block-heading" id="ember78">Digital Services Act Regulation</h2>



<p id="ember79">Due to their global nature, online platforms reach hundreds of millions of users. Content published through them can reach a very wide audience, thus influencing social, political, and economic relations. Massive social networking sites, therefore, go beyond simply providing entertainment or communication services and digital space, and are beginning to shape the reality around us.</p>



<p id="ember80">The strong influence of individual platforms on current international relations has initiated more stringent oversight, including through the provisions of Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on the single market for digital services and amending Directive 2000/31/EC (Digital Services Act &#8211; DSA). Based on this regulation, TikTok was recognized by the European Commission as a Very Large Online Platform (VLOP). This status is granted to portals with monthly active users exceeding 10% of the EU population. TikTok exceeded the threshold and was classified as a VLOP in 2023.</p>



<p id="ember81">Platforms deemed globally influential are not solely responsible for removing illegal content. They are also required to counteract the negative consequences that may arise from their operation. Among the most important responsibilities of very large online platforms (VLOPs) is the identification and assessment of systemic risks and the potential implementation of proportionate mitigation measures. Impacts on fundamental rights, democratic processes, the protection of minors, public safety, and the dissemination of illegal content are particularly scrutinized. Once a specific risk is identified, measures are planned to counteract its escalation, such as modifying the user interface or changing certain advertising practices. In emergency situations, the European Commission has the authority to require VLOP providers to assess the platform&#8217;s impact on the development of the crisis, implement specific mitigation measures, and submit periodic reports on the effectiveness of these actions. Very large online platforms are also required to undergo an annual independent audit of compliance with the Digital Services Act (DSA) and regularly publish comprehensive reports on their activities. The aim of this action is to ensure transparency of the platform&#8217;s operation towards users and supervisory authorities.</p>



<p id="ember82">The DSA also regulates advertising by introducing the requirement to maintain a public ad repository. This repository should include, among other things, the ad&#8217;s content, advertiser, funding entity, broadcast time, and the number of recipients. This solution is intended to ensure transparency in advertising messages and enable social and scientific analysis of platforms&#8217; promotional activities. Restrictions have also been imposed on recommendation systems. This means that VLOPs are required to provide users with at least one way to display content that is not based on profiling, meaning it does not use user activity history or data. To monitor platforms&#8217; compliance with the EU regulation, it is also possible to impose a requirement to share data on, for example, the performance of recommendation algorithms with the European Commission, national digital service coordinators, or verified researchers.</p>



<p id="ember83">TikTok, however, is not subject only to the obligations of very large online platforms. It is subject to all regulations provided for in the Digital Services Act. According to Article 26, each advertisement must be clearly identified as promotional material and indicate the advertiser, the funding entity, and the mechanism by which it was tailored to the user. This restriction is particularly useful for the TikTok Shop platform, where sponsored content is commonly created in the manner of regular content published by creators. Limiting the phenomenon of so-called hidden advertising through the provisions described above aims to increase user awareness.</p>



<p id="ember84">One of the DSA&#8217;s key goals is also the protection of minors. When designing their services, platforms are required to consider a high level of protection for minors and their privacy. It is prohibited to display advertisements based on the profiling of minors when the platform has knowledge of the user&#8217;s minor status. The goal is to limit the use of children&#8217;s data for marketing purposes and reduce the risk of addictive use of the app.</p>



<p id="ember85">The European Commission has also become concerned about potential negative consumer behavior resulting from the increasing transformation of large social media platforms into e-commerce portals. Complex profiling algorithms, influencer marketing, and instant purchases can encourage users to make impulsive decisions or even become dependent on purchasing processes. Articles 25 and 27 of the Consumer Protection Act (DSA) mitigate this risk. Designing web interfaces that manipulate or complicate consumer decision-making &#8211; so-called dark patterns &#8211; is prohibited. Examples of unacceptable solutions include hiding options that are less favorable to the business, making it difficult to unsubscribe from services, or designing buttons that encourage a specific choice. Users should also be fully aware of how the recommendation system works; therefore, platforms are required to clearly present its main parameters and the possibility of changing the content suggestion method.</p>



<h2 class="wp-block-heading" id="ember86">Tamper protection and dark patterns</h2>



<p id="ember87">A key premise of the TikTok Shop platform is the immediacy of purchases. While this solution is very beneficial for businesses and, typically, consumers, it can lead to abuse. Sales without leaving the app, a simplified order completion process, and algorithmic personalization of recommended products seem to provide greater convenience when shopping online. However, some activities can be classified as &#8221; dark patterns&#8221;, manipulations used to mislead users and influence their decisions. Because the practices described above can lead to impulsive behavior and distort consumer will, they may be treated as unfair market practices and subject to criminal penalties.</p>



<p id="ember88">The Act of 23 August 2007 on Counteracting Unfair Market Practices defines an unfair market practice as a sale that is contrary to good practice and significantly distorts or may distort the market behavior of the average consumer before, during or after the conclusion of a product agreement , in particular a misleading market practice and an aggressive market practice (Act of 23 August 2007 on Counteracting Unfair Market Practices, Article 4). The main grounds for considering a market practice misleading include the dissemination of false information or truthful information in a potentially misleading manner. Such misleading information typically concerns the existence of a product, its type or availability, price, the method of price calculation, or the existence of a special price advantage.</p>



<p id="ember89">To encourage immediate purchases, sellers pressure buyers with messages suggesting limited availability or a limited-time promotion for a specific product. Examples of such messages include phrases like &#8220;100 people are viewing the product,&#8221; &#8220;offer ends in 2 hours,&#8221; or &#8220;only 4 items left.&#8221; This practice is not illegal and is one of the most common marketing mechanisms. Problems arise when the website or portal is programmed to continually extend promotions, the offer doesn&#8217;t actually expire after the specified date, or the counter restarts upon page refresh.</p>



<p id="ember90">Misleading practices, such as suggesting the limited nature of a permanently available offer, and aggressive practices, such as exerting time pressure, may result in legal consequences. In addition to the aforementioned Act of 23 August 2007 on Combating Unfair Commercial Practices, this issue is also regulated by Directive 2005/29/EC concerning unfair business-to-consumer commercial practices in the internal market. This directive distinguishes between misleading commercial practices and aggressive commercial practices. Together, they constitute unfair commercial practices, which include, in particular, actions that are contrary to the requirements of professional diligence and that significantly distort or are likely to significantly distort the economic behavior of the average consumer who reaches or is targeted by the practice, or the average member of a group of consumers if the commercial practice is targeted at a specific group of consumers (Directive 2005/29/EC of the European Parliament and of the Council of 11 May 2005 concerning unfair business-to-consumer commercial practices in the internal market and amending Council Directive 84/450/EEC, Directives 97/7/EC, 98/27/EC and 2002/65/EC of the European Parliament and of the Council and Regulation (EC) No 2006/2004 of the European Parliament and of the Council (&#8220;Unfair Commercial Practices Directive&#8221;), Chapter 2, Article 5, paragraph 2).</p>



<p id="ember91">Directive (EU) 2019/2161 of the European Parliament and of the Council of 27 November 2019 (Omnibus Directive) is also intended to combat various manifestations of the &#8220;dark patterns&#8221; phenomenon. It requires sellers to disclose the lowest price for a product within the last 30 days. This is intended to prevent the practice of artificially inflating prices and then announcing sales. The practice of fake reviews has also been curbed by introducing an obligation to disclose whether and how reviews posted on sales websites are verified. The Omnibus Directive also introduced the requirement to indicate on marketplace platforms whether the seller is a private individual or a professional entrepreneur, so that consumers are aware of who they are buying from.</p>



<p id="ember92">The European Union has also introduced restrictions related to the design of digital services, contained in Regulation 2022/2065 on the Digital Single Market (DSA). As a result, online platform providers cannot design, organize, or operate their online interfaces in a way that misleads, manipulates, or otherwise interferes with or limits the ability of service users to make free and informed decisions. The regulation therefore directly addresses the fight against &#8220;dark patterns,&#8221; i.e., website design practices that deliberately use deceptive techniques, such as pre-selected consents or difficult unsubscribes.</p>



<p id="ember93">The President of the Office of Competition and Consumer Protection (UOKiK) has broad authority to protect consumers from the unfair commercial practices mentioned above. Under the Act of 16 February 2007 on Competition and Consumer Protection, one of his powers is to protect the collective interests of consumers, including through provisions counteracting unfair market practices. If necessary, the UOKiK President may initiate proceedings against a business, ordering it to cease the unfair practice, or requiring the seller to remedy the effects of the violation. Should a business fail to comply with the guidelines, he may impose a fine of up to 10% of the business&#8217;s turnover in the previous year.</p>



<p id="ember94">The number of legal acts, including EU documents, regulating unfair commercial practices reflects the considerable interest in this issue among both legislators and consumer protection authorities. TikTok Shop, as a social commerce model, is not illegal. It utilizes mechanisms combining influencer marketing, personalization, and emotional impact on the recipient, but the design of the user interface is crucial for this platform. The popularity of mass sales portals has contributed to the increasing use of &#8220;dark patterns&#8221; by businesses over the past few years. For this reason, the European Union and the Office of Competition and Consumer Protection (UOKiK) are increasingly rigorously monitoring sales tactics and issuing new legal acts to protect consumers and their free will when making purchases.</p>



<h2 class="wp-block-heading" id="ember95">Influencer Marketing and Advertising Law</h2>



<p id="ember96">The effectiveness of influencer marketing stems from combining advertising with the ability to make an immediate purchase. Affiliate links, product tags, or direct purchase buttons, such as those on the TikTok Shop platform, are displayed beneath posts, videos, or other promotional materials. This purchasing model has proven effective by significantly simplifying the ordering process, thus reducing the time consumers spend considering the rationale behind the transaction.</p>



<p id="ember97">The popularity of the marketing strategy described above stems from its perception by users, who perceive it as authentic and credible. Influencers present promoted products in a natural way, integrating them into their daily routine. However, if the material does not solely reflect the creator&#8217;s personal opinion but is created after receiving a benefit in return, it is considered commercial communication. This means it is subject to legal regulations on advertising and consumer protection. In Poland, influencers should clearly label advertising content in accordance with the Recommendations of the President of the Office of Competition and Consumer Protection. These regulations are intended to prevent misleading users.</p>



<p id="ember98">Only content regarding a product that the influencer purchased independently and for which they did not receive remuneration or other benefits can be marked as a private opinion. Such material contains genuine feelings and opinions and therefore does not constitute advertising under the law and is not subject to advertising law. This is the most credible and reliable form of review for potential consumers, as it was created by a person not under any obligation to the manufacturer.</p>



<p id="ember99">A manufacturer may enter into an agreement with an influencer to promote a product in exchange for a free product, financial benefit, or other form of remuneration. This creates legally regulated advertising. It may take the form of a post, report, or live broadcast in which the creator demonstrates how they use the product and its positive properties. Due to the natural presentation of the product as an everyday element, the recipient may have difficulty distinguishing a genuine recommendation from commercial content. The Act of August 23, 2007, on Counteracting Unfair Market Practices, classifies the act of concealing a promotional message as a misleading omission. Failure to clearly indicate the commercial nature of the material may hinder consumers&#8217; proper assessment of the message and directly influence their purchasing decisions.</p>



<p id="ember100">Another common advertising strategy is to feature a product integrated into published content without directly promoting it, for example, by placing it in the background of the material. This phenomenon is called product placement. Activities covered by advertising and consumer protection law also include, among others, affiliate and partner links, ambassador programs, and partner competitions. In Poland, these practices must contain clear, understandable to the average recipient, and visible advertising labels from the very beginning, such as &#8220;advertisement,&#8221; &#8220;paid collaboration,&#8221; or &#8220;sponsored content.&#8221; The Office of Competition and Consumer Protection (UOKiK) also recommends the use of two-level labeling, meaning that, in addition to the information contained in the content, the platform&#8217;s functionality must also be used to announce the paid collaboration. Detailed guidelines can be found in the Recommendations of the President of the UOKiK regarding the labeling of advertising content by influencers. Material is considered advertising content not only when the influencer receives monetary compensation in exchange for its creation. The same obligation applies when promoting your own business, receiving a free product or service, or obtaining a sales commission via an affiliate link or discount code (Recommendations of the President of the Office of Competition and Consumer Protection regarding the marking of advertising content by influencers).</p>



<p id="ember101">In the event of non-compliance with the Recommendations of the President of the Office of Competition and Consumer Protection regarding the labeling of advertising content by influencers, pursuant to the Act of 16 February 2007 on Competition and Consumer Protection, the Office of Competition and Consumer Protection (UOKiK) conducts proceedings against entrepreneurs using practices that violate the collective interests of consumers. Actions may be taken against advertisers, influencers, and marketing agencies. Therefore, responsibility for incorrect labeling of advertising content rests not only with the creator publishing the material but also with all entities participating in organizing the promotional campaign. One of the sanctions that the President of the UOKiK has the right to impose is a financial penalty. Incorrectly labeled promotional material can also be considered surreptitious advertising. Due to the dynamic development of influencer marketing, the proper creation of marketing content is currently widely subject to UOKiK scrutiny. Therefore, it is worth clearly and understandably labeling sponsored publications, among other things, to avoid significant financial penalties.</p>



<h2 class="wp-block-heading" id="ember102">Personal data protection</h2>



<p id="ember103">TikTok Shop, as a hybrid social network and e-commerce platform, processes a significant amount of data related to both user activity and purchasing processes. The app&#8217;s operation is based on audience profiling and matching the most relevant content. Therefore, the platform&#8217;s operations are subject to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR).</p>



<p id="ember104">In addition to user data such as name, surname, contact details, shipping addresses, and payment information, media platforms also collect information that allows for behavioral analysis. Time spent browsing specific products, interactions with ads, and the history of items added to carts or wish lists allow the TikTok Shop platform to create a personalized recommendation system based on past activity. This phenomenon creates so-called behavioral advertising, a marketing strategy based on user profiling using advanced algorithms to predict future purchasing decisions. The concept of profiling refers to the automated processing of personal data, particularly for the purpose of predicting a user&#8217;s economic situation, personal preferences, interests, health, and location.</p>



<p id="ember105">According to the GDPR, profiling is permissible, but it also comes with a number of obligations. Platforms are obligated to transparently inform users about, among other things, the purposes of profiling, the legal basis for data processing, the consequences of the actions taken, and their rights, including the right to object to profiling. Data of minors is particularly protected. Due to the growing popularity of the TikTok app among young users, it was necessary to subject it to special regulations in this regard. In the area of information society services, the processing of data of children over 16 years of age is lawful. An exception is made for situations in which a person with parental authority or guardianship provides prior consent. However, EU member states may introduce a lower age limit in their laws, but it must be at least 13 years old, as is the case in Poland, for example. To ensure that platforms enforce their obligations related to the protection of minors, they should use appropriate age verification mechanisms. In practice, however, this solution requires further improvement due to the common practice of users providing false data during registration.</p>



<p id="ember106">The President of the Office of Competition and Consumer Protection (UOKiK) plays a crucial role in protecting users, especially the collective interests of consumers. He is authorized to take action against entrepreneurs who engage in unfair market practices, design manipulative interfaces, and so on. Personal data protection, however, falls primarily within the remit of the Office for Personal Data Protection (UODO), which oversees compliance with the GDPR and the secure processing of information by companies and institutions. Due to its global influence, TikTok has attracted increasing attention from EU authorities in recent years and is becoming the subject of more frequent inspections. Due to the platform&#8217;s European headquarters being located in Ireland, the relevant supervisory authority is the Irish Data Protection Commission (DPC). For example, in 2025, this institution imposed a fine of €530 million on ByteDance, the app&#8217;s owner. The fine was imposed on the transfer of user data from the European Economic Area to China in violation of the GDPR and the failure to demonstrate data protection at the level guaranteed in the EU.</p>



<p id="ember107">The GDPR is supplemented by Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), which regulates, in addition to the processing of personal data, the confidentiality of electronic communications, also known as ePrivacy. Due to the scope of its regulations, the provisions of this directive have particular relevance to the TikTok Shop application. The platform uses numerous tracking technologies, such as cookies and mobile device advertising identifiers, to monitor user activity. Information may be stored on a user&#8217;s device or accessed only after obtaining prior consent. Exceptions are made only for technologies strictly necessary to provide the service requested by the user, such as remembering a shopping cart. An additional ePrivacy regulation was also envisaged, the purpose of which was to replace the current directive and harmonize the personal data protection rules applicable in all EU Member States. The changes were to include, among other things, simplifying the rules regarding cookies. However, the project encountered legislative difficulties and was not adopted by decision of the European Commission.</p>



<h2 class="wp-block-heading" id="ember108">Abuse of Market Power and the Digital Markets Plan</h2>



<p id="ember109">The dynamic expansion of the largest digital platforms&#8217; influence has led to the need to adapt competition law to the new situation, particularly in the digital market. To this end, the European Union adopted Regulation (EU) 2022/1925 of the European Parliament and of the Council of 14 September 2022 on contestable and fair markets in the digital sector and amending Directives (EU) 2019/1937 and (EU) 2020/1828 (Digital Markets Act – DMA). The Act introduces the concept of a gatekeeper. This term refers to an entrepreneur with an influential position in the internal market, through which business users reach end users. A gatekeeper provides a core platform service and maintains an established market position.</p>



<p id="ember110">The dominant position of a gatekeeper is also associated with a number of obligations. Among other things, the practice of self-preferencing, which involves favoring one&#8217;s own products or services over the offers of other businesses using the platform, is prohibited. In the case of TikTok Shop, this could involve using recommendation algorithms to increase the visibility of products promoted by individual sellers, without applying objective and fair advertising criteria. This type of favoritism and limiting the reach of individual entities could lead to a distortion of fair competition between businesses using TikTok Shop for sales purposes.</p>



<p id="ember111">By decision of the European Commission, BytaDance Ltd. was granted gatekeeper status solely for the operation of the TikTok application as a social media platform. The DMA regulations governing the gatekeeper position do not apply directly to TikTok Shop, but they may impact the rules for recommending products and using entrepreneurs&#8217; data.</p>



<h2 class="wp-block-heading" id="ember112">Media law and audiovisual regulations</h2>



<p id="ember113">Audiovisual materials are the primary tool for promoting and selling products on the TikTok Shop marketplace. Therefore, the app&#8217;s operations are also subject to scrutiny for compliance with media law and regulations governing audiovisual media services. The dominant role in this regard is played by Directive 2010/13/U of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation, or administrative action in Member States concerning the provision of audiovisual media services (Audiovisual Media Services Directive – AVMSD) and the Broadcasting Act of 29 December 1992, which implements it into Polish law. As a result of the amendment to the Act of 11 August 2021, the regulations have been extended to video-sharing platforms, including the TikTok app.</p>



<p id="ember114">Video-sharing platforms are primarily obligated to implement appropriate measures to protect minors from harmful content that could negatively impact their moral, mental, or physical development. These provisions have been implemented into Polish law through Article 47e of the Broadcasting Act, which mandates, among other things, the marking of potentially inappropriate content with special graphics for young viewers. These regulations are particularly important for the TikTok Shop platform due to the constantly growing number of underage users. Posting content that spreads hatred and discrimination is also prohibited.</p>



<p id="ember115">TikTok Shop, a hybrid social media platform and e-commerce platform, is often used to publish so-called audiovisual commercial communications—images used to directly or indirectly promote goods, services, or individuals (Directive 2010/13/U of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services, Article 1). Article 9 of the AVMSD requires member states to ensure that such communications are easily recognizable, thus prohibiting hidden audiovisual commercial communications. The use of subliminal techniques or the inclusion of discriminatory content would also be illegal. The National Broadcasting Council (KRRiT) is responsible for ensuring compliance with audiovisual law. Its remit includes, among other things, overseeing the activities of video-sharing platform providers.</p>



<p id="ember116">The sales method used by TikTok Shop may seem analogous to teleshopping, offerings directly to consumers to deliver goods or services in exchange for payment. This modern form of interactive audiovisual commerce (live shopping) bears numerous similarities to traditional teleshopping. The mechanisms of both aforementioned sales methods involve presenting the product, its specific features, available options, and generally encouraging the recipient to purchase. However, teleshopping is targeted at a general, anonymous audience who may only be interested in the recommended product. Meanwhile, TikTok Shop relies on advanced algorithms that target promotional content to users who, based on their previous activity, have shown interest in similar content.</p>



<h2 class="wp-block-heading" id="ember117">Platform liability under e-commerce regulations</h2>



<p id="ember118">The original act regulating the legal liability of online platforms in the European Union was Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (Directive on electronic commerce). Its foundation was the so-called safe harbor principle, i.e., the principle of limited liability of online intermediaries. According to this principle, hosting service providers and online platforms were not liable for content or goods published by users, provided they had no actual knowledge of the illegal nature of the content or goods or services or, upon obtaining such knowledge, promptly removed any infringements. Furthermore, the directive did not impose a general obligation on platforms to monitor content published by users.</p>



<p id="ember119">However, the ongoing development of digital platforms has made it necessary to amend the current liability model. Regulation (EU) 2022/2065 – Digital Services Act (DSA) – came into effect on February 17, 2024. This regulation does not eliminate the principle of limited liability but significantly expands monitoring obligations, especially for very large online platforms (VLOPs). One of the key obligations introduced under the new regulations is the Know Your Business Customer (KYBC) principle. This regulation aims to increase the safety of consumers shopping online by limiting sales conducted by dishonest or anonymous traders. Before enabling sales through its platform, an online platform must collect and verify basic data identifying the seller. The required information includes, among others, the trader&#8217;s name, registered office address, contact details, registration number in the relevant register of traders, and the trader&#8217;s payment account details. In the event of refusal to provide the specified data or providing it falsely, the platform should prevent the trader from conducting sales until the situation is resolved.</p>



<p id="ember120">A problematic issue related to the TikTok Shop app is defining the platform&#8217;s responsibility for transactions conducted by sellers using it. Although TikTok Shop formally acts as an online intermediary, it can be argued that its operating mechanism goes beyond passive hosting. A recommendation system using algorithms, promoting offers, and providing marketing and analytical tools to sellers are the mechanisms TikTok Shop uses to shape consumer behavior and purchasing decisions. The platform&#8217;s influence on the visibility of offers and the order fulfillment process may support assigning it broader responsibilities in overseeing the online sales process.</p>



<h2 class="wp-block-heading" id="ember121">Regulations on electronic communications, including the European Electronic Communications Code and the Polish Electronic Communications Law</h2>



<p id="ember122">The TikTok Shop platform does not constitute an electronic communications service under European Union law, but its operations provide for various forms of electronic communication. TikTok Shop&#8217;s use of push notifications, in-app messages, and marketing communications requires the platform to comply with regulations governing electronic marketing and the protection of user privacy in electronic communications. The primary legal acts regulating these aspects are Directive (EU) 2018/1972 of the European Parliament and of the Council of 11 December 2018 establishing the European Electronic Communications Code (EECC) and the Act of 12 July 2024 – Electronic Communications Law.</p>



<p id="ember123">The primary function of TikTok Shop is to enable entities to sell goods through the social media platform. Article 2 of the European Electronic Communications Code defines an electronic communications service as the transmission of signal transmissions or the provision of interpersonal communications services. The mere ability to exchange messages between users or with sellers does not automatically qualify the TikTok Shop platform as a provider of electronic communications services, as this is not its core competency and does not constitute its core business. However, because electronic communications are primarily used for marketing purposes, it is obligated to comply with regulations governing direct marketing and the protection of user privacy.</p>



<p id="ember124">Push notifications, messages sent directly to users&#8217; mobile devices, are an increasingly popular marketing solution. TikTok Shop uses them to provide information about order status, discounts, time-limited campaigns, or the launch of live shopping. Transactional notifications regarding order fulfillment, shipping, or payment status are typically part of the contract and do not require marketing consent. However, notifications encouraging potential consumers to make a purchase are classified as direct marketing and, in accordance with electronic communications law, require prior user consent.</p>



<p id="ember125">The practice of using automated calling systems and electronic means of communication for advertising purposes without the user&#8217;s prior consent is also prohibited. Users should be clearly informed about the purpose of receiving marketing communications, the data controller, and the possibility of withdrawing consent, which should not result in any negative consequences. With respect to the TikTok Shop platform, the above position means that it is unlawful to send promotional content to users solely based on the fact that they have an account on the app.</p>



<p id="ember126">TikTok Shop is the clearest example of how thin the line between entertainment, advertising, and commerce has become &#8211; a one-tap purchase woven into a stream of content is now as effortless as liking a video. Yet that convenience comes at a price: the <em>closed-loop</em> model and algorithmic personalization shrink the time left for rational reflection, while responsibility for protecting the consumer shifts increasingly away from the buyer and onto the platform and the legislator. EU and national regulations &#8211; from consumer law, through the DSA and DMA, data protection and safeguards for minors, all the way to media and electronic communications law &#8211; form a web meant to counterbalance the platform&#8217;s power and restore the buyer&#8217;s awareness of their own choices. TikTok Shop thus remains a dual phenomenon: on one hand a groundbreaking innovation in digital commerce, on the other a test of whether the law can keep pace with a technology that sells faster than we can think.</p>
<p>&nbsp;</p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/">A Store in Your Pocket, the Law in the Background: TikTok Shop Under the Regulators&#8217; Lens</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/a-store-in-your-pocket-the-law-in-the-background-tiktok-shop-under-the-regulators-lens/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://www.kg-legal.eu/wp-content/uploads/2026/07/generated-video-2.mp4" length="2083444" type="video/mp4" />

			</item>
		<item>
		<title>A Major Milestone for KG Legal&#8217;s Data, AI &#038; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</title>
		<link>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/</link>
					<comments>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Tue, 07 Jul 2026 19:32:01 +0000</pubDate>
				<category><![CDATA[KG LEGAL NEWS]]></category>
		<category><![CDATA[AI Act]]></category>
		<category><![CDATA[AI Compliance]]></category>
		<category><![CDATA[AI Regulation]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[CEE]]></category>
		<category><![CDATA[Corporate Counsel]]></category>
		<category><![CDATA[Cross Border Business]]></category>
		<category><![CDATA[Cross Border Legal Services]]></category>
		<category><![CDATA[Cyber Compliance]]></category>
		<category><![CDATA[Cyber Law]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[DataGuidance]]></category>
		<category><![CDATA[Digital Compliance]]></category>
		<category><![CDATA[Digital Economy]]></category>
		<category><![CDATA[Digital Law]]></category>
		<category><![CDATA[Doing business in Poland]]></category>
		<category><![CDATA[Emerging Technologies]]></category>
		<category><![CDATA[EU Law]]></category>
		<category><![CDATA[European Law]]></category>
		<category><![CDATA[Foreign Investors]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[GDPR Compliance]]></category>
		<category><![CDATA[GDPR Poland]]></category>
		<category><![CDATA[General Counsel]]></category>
		<category><![CDATA[Global Law]]></category>
		<category><![CDATA[Healthcare Law]]></category>
		<category><![CDATA[Healthcare Regulation]]></category>
		<category><![CDATA[In House Counsel]]></category>
		<category><![CDATA[International Law Firm]]></category>
		<category><![CDATA[International Legal Services]]></category>
		<category><![CDATA[Invest in Poland]]></category>
		<category><![CDATA[kglegal]]></category>
		<category><![CDATA[kiełtyka gładkowski]]></category>
		<category><![CDATA[Law Firm Poland]]></category>
		<category><![CDATA[Legal Innovation]]></category>
		<category><![CDATA[Legal Tech]]></category>
		<category><![CDATA[Legal Thought Leadership]]></category>
		<category><![CDATA[Life Sciences Law]]></category>
		<category><![CDATA[NIS2]]></category>
		<category><![CDATA[OneTrust]]></category>
		<category><![CDATA[Pharmaceutical Law]]></category>
		<category><![CDATA[Poland Law]]></category>
		<category><![CDATA[Polish law]]></category>
		<category><![CDATA[Polish Law Firm]]></category>
		<category><![CDATA[Privacy Law]]></category>
		<category><![CDATA[Regulatory Compliance]]></category>
		<category><![CDATA[Technology Law]]></category>
		<category><![CDATA[Technology Transactions]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8822</guid>

					<description><![CDATA[<p>Publication date: July 07, 2026 We are delighted to share an important milestone in the continued development of KG Legal&#8217;s Data, AI &#38; Cybersecurity Desk. It has been a great honour to serve as the exclusive expert contributors for Poland to the OneTrust DataGuidance Privacy Overview – Poland, one of the world&#8217;s leading professional legal [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: July 07, 2026</mark></strong></p>



<p>We are delighted to share an important milestone in the continued development of <strong>KG Legal&#8217;s Data, AI &amp; Cybersecurity Desk</strong>.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="1000" height="1000" src="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png" alt="" class="wp-image-8823" srcset="https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge.png 1000w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-300x300.png 300w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-150x150.png 150w, https://www.kg-legal.eu/wp-content/uploads/2026/07/DataGuidance-Contributor-Badge-768x768.png 768w" sizes="auto, (max-width: 1000px) 100vw, 1000px" /></figure>



<p>It has been a great honour to serve as the <strong>exclusive expert contributors for Poland</strong> to the <strong>OneTrust DataGuidance Privacy Overview – Poland</strong>, one of the world&#8217;s leading professional legal compliance resources relied upon by in-house counsel, privacy professionals, compliance officers, multinational organisations and technology companies operating across multiple jurisdictions.</p>



<span id="more-8822"></span>



<p>Preparing this contribution was a long-term project that required several months of intensive legal analysis, research and editorial work. Our objective was not simply to describe the application of the GDPR in Poland. Instead, we sought to create a practical and comprehensive guide reflecting the significant transformation of the Polish regulatory landscape that has taken place in recent years as a result of new European legislation and its implementation into Polish law.</p>



<p>The publication therefore extends far beyond a traditional overview of Polish data protection law. It examines the interaction between privacy, digital regulation, cybersecurity and artificial intelligence, providing readers with practical guidance on the most important legal developments affecting organisations operating in Poland.</p>



<p>Our contribution discusses, among other things:</p>



<ul class="wp-block-list">
<li>the practical application of the GDPR within the Polish legal system;</li>



<li>the powers and regulatory practice of the Polish supervisory authority for personal data protection;</li>



<li>employee monitoring and workplace privacy;</li>



<li>cookies, consent mechanisms and online tracking technologies;</li>



<li>electronic communications and direct marketing requirements;</li>



<li>international data transfers;</li>



<li>personal data breaches and notification obligations;</li>



<li>practical compliance with Polish privacy legislation;</li>



<li>cybersecurity-related regulatory developments;</li>



<li>the growing interaction between data protection and artificial intelligence governance.</li>
</ul>



<p>A particularly important aspect of this work was addressing the rapidly evolving legislative environment. During the last few years, Poland has experienced substantial regulatory changes resulting from the implementation of numerous European legal instruments and the entry into force of directly applicable EU regulations that significantly affect organisations processing personal data.</p>



<p>Accordingly, the publication takes into account the practical implications of the evolving European digital regulatory framework, including the interaction between the GDPR and newer legal instruments governing digital services, artificial intelligence, cybersecurity and data governance. The analysis also reflects the impact of the AI regulatory framework, developments concerning data governance and electronic communications, as well as the increasingly interconnected compliance obligations facing businesses operating in today&#8217;s digital economy.</p>



<p>Rather than presenting legislation in isolation, the publication adopts a practical, compliance-oriented perspective. It combines:</p>



<ul class="wp-block-list">
<li>the GDPR and Polish implementing legislation;</li>



<li>guidance issued by the European Data Protection Board (EDPB);</li>



<li>the jurisprudence of the Court of Justice of the European Union;</li>



<li>decisions and regulatory guidance published by the Polish Personal Data Protection Office (UODO);</li>



<li>recent Polish legislative developments and market practice.</li>
</ul>



<p>Our ambition was to create a resource that would assist both international and domestic organisations in navigating one of the fastest-changing areas of European regulation, where privacy law increasingly intersects with cybersecurity, AI governance, digital platforms, online communications and emerging technologies.</p>



<p>The contribution was prepared by <strong>Małgorzata Kiełtyka</strong> and <strong>Jakub Gładkowski</strong>, whose combined experience covers complex cross-border advisory work in data protection, artificial intelligence, life sciences, healthcare, technology law, cybersecurity, intellectual property and regulatory compliance.</p>



<p><a href="https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski" target="_blank" rel="noreferrer noopener">https://www.dataguidance.com/experts-directory/Jakub_G%C5%82adkowski</a></p>



<p><a href="https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka">https://www.dataguidance.com/experts-directory/Malgorzata_Kieltyka</a></p>



<p>For many years, Małgorzata Kiełtyka has advised international companies on GDPR compliance, healthcare regulation, AI governance, technology transactions and cross-border regulatory matters. Her practice combines strategic legal advice with practical implementation of compliance frameworks for multinational businesses operating in highly regulated sectors.</p>



<p>Jakub Gładkowski focuses on data protection, digital regulation, cybersecurity, intellectual property, IT law and emerging technologies. His practice includes advising innovative businesses on regulatory compliance, digital transformation projects and the implementation of European technology legislation affecting both public and private sector organisations.</p>



<p>Being entrusted with preparing Poland&#8217;s national contribution to OneTrust DataGuidance represents an important recognition of our team&#8217;s expertise and international standing. We are particularly proud that this publication reflects not only our experience in privacy law, but also our broader interdisciplinary approach, integrating data protection with AI regulation, cybersecurity, digital compliance and technology law.</p>



<p>We sincerely thank the editorial team at <strong>OneTrust DataGuidance</strong> for their confidence in our expertise and for the opportunity to contribute to a publication that supports legal and compliance professionals around the world.</p>



<p>For KG Legal, this publication marks another significant milestone in the continued growth of our <strong>Data, AI &amp; Cybersecurity Desk</strong> and reinforces our commitment to delivering practical, business-oriented legal advice at the intersection of privacy, technology and innovation.</p>
<p> </p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/">A Major Milestone for KG Legal&#8217;s Data, AI &amp; Cybersecurity Practice: Exclusive Poland Contribution to OneTrust DataGuidance</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/kg-legal-news/a-major-milestone-for-kg-legals-data-ai-cybersecurity-practice-exclusive-poland-contribution-to-onetrust-dataguidance/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</title>
		<link>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/</link>
					<comments>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 13 May 2026 10:56:58 +0000</pubDate>
				<category><![CDATA[IT, NEW TECHNOLOGIES, MEDIA AND COMMUNICATION TECHNOLOGY LAW]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DataAct]]></category>
		<category><![CDATA[DataGovernance]]></category>
		<category><![CDATA[DataPrivacy]]></category>
		<category><![CDATA[EUDataAct]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[LegalTech]]></category>
		<category><![CDATA[RegTech]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8769</guid>

					<description><![CDATA[<p>Publication date: May 13, 2026 The entry into application of the EU Data Act on 12 September 2025 marks one of the most significant developments in European data regulation since the adoption of the General Data Protection Regulation (GDPR). While the GDPR established a comprehensive framework for the protection of personal data, the Data Act [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/">Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color"><strong>Publication date: May 13, 2026</strong></mark></p>



<p>The entry into application of the EU Data Act on 12 September 2025 marks one of the most significant developments in European data regulation since the adoption of the General Data Protection Regulation (GDPR). While the GDPR established a comprehensive framework for the protection of personal data, the Data Act introduces a new legal regime designed to improve access to and use of data generated by connected products and related digital services.</p>



<span id="more-8769"></span>



<p>For businesses operating in the European Union, the key challenge is not understanding each regulation in isolation, but determining how they interact in practice. Many organizations already have mature GDPR compliance frameworks, but the Data Act creates additional obligations that require them to share data with users and third parties. Where those datasets contain personal data, compliance with the Data Act must be reconciled with the GDPR.</p>



<p>This article explains the relationship between the Data Act and the GDPR in practical terms. It highlights the main legal issues and outlines the steps businesses should take to prepare.</p>



<p><strong>What Is the Data Act?</strong></p>



<p>The Data Act, Regulation (EU) 2023/2854, is part of the European Union&#8217;s broader strategy to build a single market for data. Its purpose is to ensure that users of connected products and related services can access the data they generate and, in certain circumstances, require that such data be shared with third parties.</p>



<p>The regulation is intended to rebalance the relationship between manufacturers, service providers and users. In many industries, companies that design connected products control large volumes of data generated through use of those products. The Data Act seeks to ensure that users are able to benefit from this data rather than being locked into a single ecosystem.</p>



<p>The regulation applies to both personal and non-personal data, which is one of the key differences from the GDPR.</p>



<p>Examples of products and services covered by the Data Act include smart watches, connected vehicles, industrial machinery, medical devices, smart home appliances, agricultural equipment and software applications that process the data generated by such products.</p>



<p><strong>What Is the GDPR?</strong></p>



<p>The GDPR governs the processing of personal data relating to identified or identifiable natural persons. Its objective is to protect privacy and ensure that personal data is processed lawfully, fairly and transparently.</p>



<p>The GDPR applies whenever data relates to an individual and a controller or processor carries out an operation such as collecting, storing, sharing or analyzing that data.</p>



<p>Unlike the Data Act, the GDPR does not grant a broad right of access to all data generated by products. It focuses solely on personal data and establishes rights such as access, rectification, erasure and portability.</p>



<p><strong>The Relationship Between the Data Act and the GDPR</strong></p>



<p>The Data Act expressly states that it is without prejudice to EU and national laws on personal data protection, privacy and confidentiality of communications. In practical terms, this means that the Data Act does not override the GDPR. If a company is required to provide data under the Data Act and the dataset contains personal data, the GDPR continues to apply in full.</p>



<p>This principle has several important consequences.</p>



<p>First, the Data Act does not create a new legal basis for processing personal data. A company cannot rely on the Data Act alone to justify collecting, disclosing or otherwise processing personal data.</p>



<p>Second, organizations must continue to comply with all GDPR principles, including purpose limitation, data minimization, storage limitation and security.</p>



<p>Third, where there is a conflict between the two regulations, the GDPR prevails in relation to personal data.</p>



<p><strong>Why This Matters in Practice</strong></p>



<p>Most data generated by connected products is not purely personal or purely non-personal. Instead, businesses often deal with mixed datasets.</p>



<p>A connected vehicle, for example, may generate information on speed, fuel consumption, component performance, geolocation and driver behavior. Some of this information clearly relates to an identifiable person and therefore qualifies as personal data. Other elements may be technical or operational in nature.</p>



<p>Where personal and non-personal data are inextricably linked, organizations should assume that the GDPR applies to the dataset as a whole unless the data can be effectively separated.</p>



<p>This means that compliance with the Data Act often requires a GDPR analysis before any disclosure can take place.</p>



<p><strong>Practical Example: Smart Watch Data</strong></p>



<p>A consumer uses a smart watch that collects heart rate, sleep patterns, exercise metrics and location information. The consumer wishes to transfer the data to a third-party health application.</p>



<p>Under the Data Act, the user may request access to the data generated by the device and ask the manufacturer to transmit the data to another provider.</p>



<p>Because the dataset contains information relating to an identifiable person, the GDPR applies.</p>



<p>In this scenario, the manufacturer must verify that the request is valid, ensure the transmission is secure and process the data in accordance with the GDPR. The Data Act creates the obligation to provide the data, but the GDPR determines how the transfer must be carried out.</p>



<p><strong>Practical Example: Industrial Equipment</strong></p>



<p>A manufacturing company leases connected machinery that generates data concerning temperature, output, wear and maintenance cycles. The company wants to share this data with an independent maintenance provider.</p>



<p>The Data Act allows the user to request access to the data and to require the data holder to share it with a third party.</p>



<p>If the dataset contains no personal data, the GDPR may not apply.</p>



<p>However, if the data includes operator IDs or logs that can identify employees, GDPR considerations arise. The data holder must assess whether a lawful basis exists for sharing those elements.</p>



<p><strong>Key Roles Under the Data Act and the GDPR</strong></p>



<p>The terminology used by the two regulations differs, but the concepts often overlap. Under the Data Act, the principal roles are the data holder, the user and the data recipient. Under the GDPR, the key roles are the controller and processor. In practice, a data holder will often act as a controller because it determines the purposes and means of processing personal data. A business user receiving data may also become a controller if it decides how the data will be used.</p>



<p>This distinction is important because the recipient of data under the Data Act may inherit independent GDPR obligations.</p>



<p><strong>Data Portability: How the Data Act Expands Existing Rights</strong></p>



<p>The GDPR grants individuals a right to data portability, but this right is limited to personal data provided by the data subject and processed on the basis of consent or contract. The Data Act significantly broadens this concept.</p>



<p>It applies to data generated through the use of connected products and related services, regardless of whether the data is personal or non-personal.</p>



<p>For businesses, this means that existing GDPR portability procedures will usually not be sufficient. Organizations may need entirely new technical and contractual frameworks to handle Data Act requests.</p>



<p><strong>Trade Secrets and Confidential Information</strong></p>



<p>One of the most common concerns raised by businesses is the protection of proprietary information. The Data Act recognizes that data may contain trade secrets and allows data holders to implement safeguards such as confidentiality agreements, access controls and contractual restrictions. However, trade secret protection is not an automatic ground for refusing access. A refusal is permitted only in exceptional circumstances where disclosure would likely cause serious economic harm and where protective measures are insufficient.</p>



<p>In practice, businesses should assume that most requests will need to be fulfilled, subject to appropriate safeguards.</p>



<p><strong>Smart Contracts</strong></p>



<p>The Data Act introduces specific requirements for smart contracts used to automate data sharing.</p>



<p>Where businesses use blockchain-based or automated systems to execute data-sharing arrangements, those systems must meet standards relating to security, integrity and the ability to terminate or interrupt execution where necessary. Although this aspect of the regulation may not affect all organizations, it is highly relevant to businesses deploying decentralized or automated contractual technologies.</p>



<p><strong>Cloud Switching and Digital Assets</strong></p>



<p>The Data Act also addresses switching between providers of data processing services, including cloud providers. Customers must be able to move digital assets such as applications, configuration files, metadata and access credentials to another provider more easily. Organizations that offer cloud or platform services should review their contractual and technical arrangements to ensure that customers can migrate without undue barriers.</p>



<p><strong>Legal Basis for Processing Personal Data</strong></p>



<p>A recurring misconception is that the Data Act itself authorizes disclosure of personal data. This is incorrect. Whenever personal data is involved, a valid legal basis under the GDPR remains necessary. The applicable legal basis will depend on the circumstances. In some cases, processing may be necessary for the performance of a contract. In others, consent or legitimate interests may be relevant. Where the user requesting the data is a business rather than the individual to whom the data relates, the requesting party may need to demonstrate that it has an independent lawful basis for processing the personal data.</p>



<p><strong>What Businesses Should Do</strong></p>



<p>Organizations should begin by identifying whether they fall within the scope of the Data Act. Businesses that manufacture connected products, provide related services, control access to product-generated data or offer cloud services are the most likely to be affected. The next step is to map the data generated by products and services. This exercise should identify what data is collected, whether it includes personal data, who controls it and with whom it may be shared.</p>



<p>Once the data landscape is understood, businesses should review the legal bases for processing any personal data contained in those datasets.</p>



<p>Policies and procedures should then be updated to address Data Act requests. Existing GDPR processes will rarely be sufficient because they are designed primarily for requests from individuals, not business-to-business data sharing.</p>



<p>Contracts with customers, partners and recipients should be revised to address data use restrictions, confidentiality obligations, trade secret protections and security measures.</p>



<p>Technical teams should ensure that systems can provide data in accessible formats, authenticate requesters, record disclosures and protect sensitive information.</p>



<p>Finally, legal, compliance, IT and customer support teams should be trained so that they understand how to manage requests consistently.</p>



<p><strong>Common Pitfalls</strong></p>



<p>Businesses preparing for the Data Act frequently make several mistakes. The first is assuming that the Data Act overrides the GDPR. In reality, the GDPR remains fully applicable whenever personal data is involved. The second is underestimating the complexity of mixed datasets. The third is relying too heavily on trade secret arguments to resist disclosure. The fourth is failing to update contracts and operational procedures.</p>



<p>The fifth is treating compliance as a purely legal issue rather than a multidisciplinary project involving legal, IT, security and commercial teams.</p>



<p><strong>Enforcement and Business Risk</strong></p>



<p>Failure to comply with the Data Act may result in regulatory investigations, disputes with customers and partners, and reputational damage. Where personal data is mishandled, GDPR enforcement risks also arise, including potentially significant administrative fines. For this reason, businesses should approach the Data Act as a strategic compliance project rather than a narrow contractual exercise.</p>



<p><strong>Conclusion</strong></p>



<p>The Data Act and the GDPR are complementary regulations that pursue different objectives. The GDPR protects individuals and their personal data. The Data Act promotes broader access to data generated by connected products and services. When those datasets contain personal data, organizations must apply both regimes simultaneously. The Data Act creates the obligation to make data available, while the GDPR determines the conditions under which personal data may be processed and shared.</p>



<p>Businesses that rely on connected products, IoT ecosystems, industrial data or cloud services should begin preparing well in advance.</p>



<p>Organizations that invest now in data mapping, contractual updates, technical controls and internal governance will be best positioned to comply with the new rules and to leverage data as a strategic asset.</p>



<p><strong>Client Alert</strong></p>



<p><strong>EU Data Act Applies from 12 September 2025: Is Your Business Ready?</strong></p>



<p>The EU Data Act introduces a new framework governing access to data generated by connected products and related services. It applies from 12 September 2025 and will affect manufacturers, software providers, cloud providers and businesses that rely on connected technologies.</p>



<p>The regulation grants users the right to access data generated by products they use and to request that such data be shared with third parties.</p>



<p>Where the data includes personal data, the GDPR remains fully applicable.</p>



<p>For many organizations, the Data Act will require updates to contracts, technical systems and operational procedures.</p>



<p>Businesses should begin by identifying whether they control product-generated data, determining whether datasets include personal data, and assessing whether existing systems can support secure and compliant data sharing.</p>



<p>Organizations should also review trade secret protections and update agreements with customers and business partners.</p>



<p>Companies that prepare early will be better positioned to meet legal obligations and capitalize on new opportunities arising from increased data portability.</p>



<p><strong>Data Act Implementation Checklist</strong></p>



<p>An effective implementation project should begin with a governance assessment to determine which internal teams will be responsible for legal analysis, technical implementation and operational oversight.</p>



<p>The organization should then conduct a comprehensive data mapping exercise covering all connected products, related services and cloud environments. This exercise should distinguish between personal data, non-personal data and mixed datasets.</p>



<p>A legal review should be undertaken to confirm the GDPR legal bases for processing personal data and to identify any restrictions arising from confidentiality obligations or trade secret protections.</p>



<p>Customer terms, data-sharing agreements, cloud contracts and internal policies should be revised to reflect Data Act requirements.</p>



<p>Technical teams should ensure that systems are capable of exporting data in usable formats, authenticating requesters, logging disclosures and protecting confidential information.</p>



<p>Operational procedures should be established for receiving, reviewing and responding to requests.</p>



<p>Training should be delivered to legal, compliance, IT, security and customer-facing teams.</p>
<p> </p>



<p><strong>The EU Data Act Meets the GDPR: What Businesses Need to Know</strong></p>



<p>With the EU Data Act becoming applicable from <strong>12 September 2025</strong>, we’re entering a new era of data regulation in Europe — one that doesn’t replace the GDPR, but fundamentally reshapes how it operates in practice.</p>



<p>For many organizations, the challenge is no longer <em>GDPR vs. Data Act</em>, but how both frameworks work together when data is shared, accessed, and reused.</p>



<p>The key reality?<br>Most data generated by connected products is <strong>mixed — personal and non-personal at the same time</strong>. And that changes everything.</p>



<h3 class="wp-block-heading">Key takeaway:</h3>



<p>The Data Act creates obligations to <strong>share data</strong>, but the GDPR still governs <strong>how personal data can be processed and transferred</strong>. The Data Act never overrides GDPR requirements.</p>



<h3 class="wp-block-heading">What this means in practice:</h3>



<ul class="wp-block-list">
<li>No new legal basis for processing personal data under the Data Act</li>



<li>GDPR principles (minimization, purpose limitation, security) still fully apply</li>



<li>Trade secrets don’t automatically block access requests</li>



<li>Data portability rights are significantly expanded beyond GDPR scope</li>



<li>Cloud and IoT ecosystems will need major technical and contractual updates</li>
</ul>



<h3 class="wp-block-heading">The real challenge for businesses</h3>



<p>Compliance is no longer just legal — it’s operational and technical.</p>



<p>Organizations will need to:<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Map all product-generated data<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Identify where personal data is involved<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Update contracts and data-sharing frameworks<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Build secure, auditable data access systems<br><img src="https://s.w.org/images/core/emoji/15.0.3/72x72/2714.png" alt="✔" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Align legal, IT, and compliance teams</p>



<h3 class="wp-block-heading">Bottom line:</h3>



<p>The Data Act doesn’t replace the GDPR — it adds a new layer of complexity on top of it. Companies that prepare early will not only reduce compliance risk but also gain a competitive advantage in the emerging EU data economy.</p>
<p> </p>


<p>Artykuł <a href="https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/">Interplay Between the Data Act and the GDPR: A Practical Guide for Businesses</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/it-new-technologies-media-and-communication-technology-law/interplay-between-the-data-act-and-the-gdpr-a-practical-guide-for-businesses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>National Healthcare and the processing of personal data by means of AI</title>
		<link>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/</link>
					<comments>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/#respond</comments>
		
		<dc:creator><![CDATA[jakub]]></dc:creator>
		<pubDate>Wed, 12 Nov 2025 10:22:53 +0000</pubDate>
				<category><![CDATA[PHARMACEUTICAL, HEALTHCARE & LIFE SCIENCES LAW]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Artificial intelligence]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[National Health Fund]]></category>
		<category><![CDATA[National Healthcare]]></category>
		<category><![CDATA[nfz]]></category>
		<category><![CDATA[personal data]]></category>
		<category><![CDATA[Poland]]></category>
		<category><![CDATA[processing of personal data]]></category>
		<guid isPermaLink="false">https://www.kg-legal.eu/?p=8478</guid>

					<description><![CDATA[<p>Publication date: November 12, 2025 Artificial intelligence (AI) is currently finding widespread use in healthcare. A prime example is the Polish National Health Fund (NFZ) initiative, which utilizes AI to analyze patient data stored in the Fund&#8217;s databases. This data is then analyzed with the support of machine learning tools to make strategic decisions regarding [&#8230;]</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/">National Healthcare and the processing of personal data by means of AI</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Publication date: November 12, 2025</mark></strong></p>



<p>Artificial intelligence (AI) is currently finding widespread use in healthcare. A prime example is the Polish National Health Fund (NFZ) initiative, which utilizes AI to analyze patient data stored in the Fund&#8217;s databases. This data is then analyzed with the support of machine learning tools to make strategic decisions regarding the health of Poles. This approach will certainly simplify the work of doctors by searching for and analyzing the desired information, undoubtedly reducing their workload. However, such a solution may raise several issues and legal requirements related to regulations regarding the protection and processing of personal data.</p>



<span id="more-8478"></span>



<h2 class="wp-block-heading"><strong>What is personal data?</strong></h2>



<p>The most common definition of personal data is contained in the EU Regulation 2016/679 (GDPR), according to which personal data is any information about an identified or identifiable natural person. This includes direct identification (e.g., name and surname) or certain factors allowing indirect identification (e.g., job description or nationality). This concept is expanded by the Polish Act on the Protection of Personal Data Processed in Connection with the Prevention and Combating of Crime of December 14, 2018, by applying it directly to health. Health data here means personal data relating to the physical or mental health of an individual, including data on the use of healthcare services that reveal information about their health.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Patients&#8217; rights</strong></p>



<p>A number of patient rights are listed in the EU Regulation 2025/327 (Regulation on the European Health Data Space). The fundamental right is the right of individuals to access their electronically collected data (especially &#8220;priority data,&#8221; e.g., electronic prescriptions or imaging test results), which should be granted immediately after data is registered in the system. Individuals can also add their own information to their data already visible in the system and correct it. Furthermore, patients can grant access or request the transfer of their data to another provider. Access to healthcare professionals can also be restricted (however, in such cases, the patient should also be informed of the potential impact of such action on the quality of care provided). In this case, institutions collecting patient data should be aware of these rights, because if they are not respected, the patient could file a complaint (provided, however, that the rights or interests of the individual are adversely affected) and demand appropriate compensation.</p>



<p>The EU GDPR also provides similar rights, which additionally provides for one crucial privilege: the right to object. According to this regulation, an individual may object at any time to the processing of their data, including in connection with the performance of healthcare tasks, for reasons relating to their particular situation. In such a case, the data may no longer be processed unless the controller demonstrates compelling and legitimate grounds for further processing. Under the regulation, a patient could also request the deletion of their personal data if, for example, they are no longer necessary for the purpose for which they were collected or if they were processed unlawfully. Furthermore, the regulation also provides for the possibility of imposing an administrative fine of up to €20 million for a controller&#8217;s violation of guaranteed rights. Furthermore, Article 79 of the GDPR grants the right to an effective judicial remedy if the individual (patient) believes that the processing of their personal data violated the law.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Obligations of entities storing and processing data</strong></p>



<p>Pursuant to Article 24 of the GDPR, the data controller is obligated to implement appropriate technical and organizational measures to ensure data processing is carried out in compliance with legal provisions and the rights and freedoms of others. The controller must also review and update these measures as necessary. In the case of <strong><u>AI-based patient data processing</u></strong>, the obligation specified in this article to design the measures described above is also crucial, ensuring that only information necessary to protect the patient&#8217;s life and health is processed by default. In the event of a personal data breach, the controller should (within 72 hours of becoming aware of the breach) notify the relevant supervisory authority of the personal data breach. However, the controller is not obligated to do so if the likelihood of a breach affecting the rights and freedoms of natural persons is low. If the risk of a breach is high, the controller should also notify the affected individual. Furthermore, before processing begins, even using new technologies (including AI), if it may result in a high future risk to the rights and freedoms of natural persons, it will be necessary to assess the impact of the planned processing on personal data protection. If such an assessment indeed reveals a high risk, and if the controller fails to implement any measures to mitigate it, the controller must contact the relevant supervisory authority (in Poland, the President of the Personal Data Protection Office [President of the UODO]), which then provides the controller with a written recommendation and may also temporarily restrict or prohibit processing or issue a warning to the controller. General obligations, according to which personal data must be processed lawfully and fairly, in a transparent manner, and limited to what is necessary for the purposes for which they are processed, are also important.</p>



<p>In this situation, Regulation 2024/1689 (&#8220;AI Act&#8221;) also provides an interesting requirement. According to Article 4 thereof, healthcare entities using AI systems to make strategic decisions about patients are responsible for maintaining an appropriate level of AI competence among their staff, taking into account the purpose of using the system and the persons for whom the systems are to be used.</p>



<p class="has-luminous-vivid-amber-background-color has-background has-medium-font-size"><strong>Requirements for the AI systems themselves</strong></p>



<p>The basic requirements that AI systems used for data processing would have to meet are set out in the aforementioned AI Act. This document explicitly classifies AI systems as &#8220;high-risk systems&#8221;, and therefore, the requirements set out in the act apply to them. Primarily, this requires maintaining appropriate documentation for the system: technical documentation regarding the quality management system (including data acquisition, collection, analysis, and labeling) and an EU declaration of conformity confirming the system&#8217;s compliance with the requirements set out in the regulation. Furthermore, this documentation should be kept at the disposal of the competent national authorities for 10 years after the system&#8217;s commissioning. Such systems should also meet transparency requirements, meaning they should be designed to facilitate proper use and interpretation of their actions (they should also have clear operating instructions). They must also have an appropriate oversight system that allows for human oversight of the AI if necessary, especially if its operation were to get out of control and harm others. Finally, AI systems are also subject to certain formal requirements, such as undergoing a pre-market conformity assessment and registering in a dedicated EU database for high-risk AI systems. It is also important to remember that high-risk AI systems are subject to general CE marking regulations. Once placed on the market, suppliers are required to establish a post-market monitoring system for AI systems to ensure their legal compliance.</p>



<p><strong><u>The issue of non-personal data</u></strong></p>



<p>It is also worth raising the issue of non-personal data, for example, in the context of a situation where a hospital, in order to decide on the appropriate medication for a patient, requests information about certain medications from a pharmacy. A public sector body may request such information only to the extent that the lack of this data would prevent it from performing its public interest tasks or when the body has no other available means of obtaining such data. A request for this purpose should be submitted (specifying, in particular, the purpose for which the information is requested). However, the data subject who received it may refuse to provide it if they have no control over the requested information or if a similar request for the same purpose has already been submitted by another public sector body. Once the requested information is in the possession of the requester, they must not use it in a manner inconsistent with the purpose for which the data was provided. They must ensure measures to protect its confidentiality or integrity, and they must delete the data as soon as it is no longer needed for the specified purpose. They are also prohibited from using the information obtained to improve a competitive product or from disclosing any information in this regard to third parties. It is also important to bear in mind the right of a public sector body to share the data received with individuals or organisations for the purposes of scientific research or analyses consistent with the purpose for which the data was requested, or with national statistical offices (e.g. the Central Statistical Office). It is important here that these organisations do not have a commercial nature or are not related to entities that do.</p>



<p><strong><u>The status in Poland</u></strong></p>



<p>As mentioned above, Poland has established a special supervisory authority for personal data protection, the President of the Personal Data Protection Office (UODO), acting with the assistance of the Office for Personal Data Protection. Among other things, this authority is responsible for consultations on data processing that poses a significant risk of violating the rights of others. It also conducts proceedings in cases of violations of personal data protection regulations and establishes a plan for monitoring compliance with these regulations.</p>



<p>It is also worth remembering the regulations of the Polish Act on Patients&#8217; Rights and the Patient Ombudsman. It stipulates that patients have the right to access medical records concerning their health and the services provided to them. The entity storing this documentation is obligated to disclose the data contained therein only to the patient themselves or an authorized person (or, for example, to a university or research institute for scientific purposes, but without any data allowing for the identification of the individual). Furthermore, the entity providing services is obligated to retain medical records only for a specified period (generally 20 years), after which they should be destroyed in a way that prevents the identification of the patient to whom they pertained. The Act on the Healthcare Information System also limits access to these records to medical professionals and physicians.</p>



<p>Also important are the provisions of the Act on the computerization of the activities of entities carrying out public activities, under which an entity maintaining a public register (i.e. any type of records used to carry out public tasks based on the relevant provisions) should provide another public entity with access to the data in its possession to the extent necessary to carry out public tasks.</p>



<p>It is also important to remember the Polish Code of Medical Ethics, which, in Article 14, requires physicians to inform patients about the benefits and risks associated with proposed diagnostic procedures and, where appropriate, about the possibility of using other methods. Furthermore, according to Article 12, the use of AI in treatment may only occur after the following conditions are met: informing the patient that artificial intelligence will be used in the diagnosis or therapeutic process; obtaining the patient&#8217;s informed consent to the use of artificial intelligence in the diagnostic or therapeutic process; and using AI algorithms that are approved for medical use and have the appropriate certifications. However, the final decision always rests with the physician.</p>



<p>A government draft legislation is currently being prepared, which will be designed to adapt the national legal system to the requirements imposed by the AI Act. The government&#8217;s proposals primarily envisage the establishment of the Artificial Intelligence Development and Security Commission, which will oversee the AI market within the scope specified in Article 2 of Regulation 2024/1689. The second main body will be the President of the Personal Data Protection Office (UODO) that will oversee high-risk AI systems, including those related to healthcare.</p>



<p><strong><u>Summary</u></strong></p>



<p>Processing personal data for healthcare purposes, additionally supported by artificial intelligence, is undoubtedly a convenient and practical solution, but it is associated with a number of legal obligations intended to ensure the security of the data used (e.g., using the acquired data only for a strictly defined purpose), the security of patients themselves (e.g., the obligation to inform the patient of the intention to use artificial intelligence in the treatment process), or simply related to formalities (e.g., the requirement to register the artificial intelligence system in an EU database). Currently, EU regulations are much more detailed in this matter.</p>
<p>Artykuł <a href="https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/">National Healthcare and the processing of personal data by means of AI</a> pochodzi z serwisu <a href="https://www.kg-legal.eu">KIELTYKA GLADKOWSKI LEGAL | CROSS BORDER POLISH LAW FIRM RANKED IN THE LEGAL 500 EMEA SINCE 2019</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kg-legal.eu/info/pharmaceutical-healthcare-life-sciences-law/national-healthcare-and-the-processing-of-personal-data-by-means-of-ai/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
