THE UNITED STATES
Summary
- A Delaware C corporation remains a suitable parent for an AI startup seeking preferred-stock financing, centralized board control, employee equity, and a conventional acquisition or public-offering path. 8 Del. C. §§ 101–103, 141(a), 152–157. The corporation must qualify and register wherever its activities create state obligations.
- Directors must establish information and reporting systems for risks central to the company’s operations. Liability under Caremark requires bad faith through an utter failure to establish those systems or a conscious failure to monitor them. Stone v. Ritter, 911 A.2d 362, 370 (Del. 2006); Marchand v. Barnhill, 212 A.3d 805, 821–24 (Del. 2019).
- The corporation should acquire written assignments of founder code, inventions, datasets, domains, documentation, and trade secrets before financing. Stock, SAFEs, convertible notes, and compensatory equity require Securities Act exemptions, board authorization, accurate disclosures, and state notices. 15 U.S.C. §§ 77d(a)(2), 77q(a); 17 C.F.R. §§ 230.503, 230.506, 230.701.
- The verified federal authorities impose no generally applicable license solely for private AI development or release. The FTC Act, civil-rights statutes, sector laws, export controls, sanctions, and state laws can govern the same system. 15 U.S.C. § 45(a); Exec. Order No. 14,409, § 3(c), 91 Fed. Reg. 34,565, 34,566 (June 5, 2026).
- Public release of a covered generative-AI system can trigger training-data documentation under California Civil Code §§ 3110–3111. A provider with more than one million monthly users or visitors can face content-provenance duties under California Business and Professions Code §§ 22757–22757.6. Frontier developers must test the statutory compute threshold, while the published frontier AI framework duties apply to large frontier developers above the $500 million affiliate-revenue threshold.
- The current CCPA gross-revenue threshold is $26,625,000. The other statutory thresholds concern processing information of 100,000 consumers or households and deriving at least half of annual revenue from selling or sharing personal information. Illinois biometric processing can create direct private-action exposure. Cal. Civ. Code § 1798.140(d); 740 ILCS 14/15, 14/20.
- Texas’s AI statute has applied since January 1, 2026 and gives the attorney general exclusive enforcement authority. Colorado’s replacement automated-decision statute starts January 1, 2027 and creates no new private action. New York City presently restricts covered automated employment decision tools. Tex. Bus. & Com. Code ch. 552; Colo. S.B. 26-189, 75th Gen. Assemb., 2d Reg. Sess. (2026); N.Y.C. Admin. Code §§ 20-870–20-874.
- Copyright protects human-authored expression, while patent law requires a natural-person inventor. AI training receives no categorical fair-use answer. Ross, Bartz, and Kadrey reached different results under different records, products, acquisition methods, and market evidence. 17 U.S.C. § 107; Thaler v. Perlmutter, 130 F.4th 1039, 1046–49 (D.C. Cir. 2025), cert. denied, No. 25-449 (U.S. Mar. 2, 2026); Thaler v. Vidal, 43 F.4th 1207, 1211–13 (Fed. Cir. 2022).
- Foreign investor rights can trigger CFIUS review when the company is a TID U.S. business. Certain AI model weights fall under ECCN 4E091 and a worldwide export-license requirement. A C corporation pays a 21 percent federal rate, subject to deductions, credits, state taxes, and shareholder-level rules. 31 C.F.R. pts. 800, 850; 15 C.F.R. § 742.6(a)(13); 28 C.F.R. pt. 202; 26 U.S.C. §§ 11, 41, 83, 1202, 174, 174A.
Delaware Formation and Corporate Control
A Delaware C corporation remains the strongest entity choice on the stated venture-financing assumption. Delaware permits any person to form a corporation by filing a certificate of incorporation. 8 Del. C. §§ 101–103. The certificate should identify the registered agent, authorize adequate common and preferred shares, state the corporate purpose, and include any elected exculpation under § 102(b)(7).
The incorporator and initial board should adopt bylaws, appoint officers, approve founder stock, authorize bank accounts, and establish the stock ledger. Each stock issuance requires board authorization and legally sufficient consideration. 8 Del. C. §§ 152–157. The company should retain signed purchase agreements, capitalization records, valuation materials, and evidence of payment.
Section 141(a) places corporate management under the board. Directors owe duties of care and loyalty, while officers owe corresponding duties within their assigned functions. A certificate provision under § 102(b)(7) can limit specified monetary liability. It cannot eliminate loyalty claims, bad-faith conduct, improper personal benefits, or other statutory exclusions.
Caremark oversight liability requires bad faith. In re Caremark International Inc. Derivative Litigation, 698 A.2d 959, 970–71 (Del. Ch. 1996). Stone identifies two routes: directors may utterly fail to implement a reporting system, or they may consciously disregard their monitoring duties after establishing one. 911 A.2d at 370. A failed product decision or weak control does not satisfy that standard without the required state of mind.
Marchand applied the doctrine where compliance concerned the company’s central operational risk. 212 A.3d at 821–24. An AI board should identify which legal and technical risks are central to its business. Relevant reporting subjects can include model evaluations, cybersecurity, privacy, training-data rights, export classification, customer complaints, safety incidents, and state-law thresholds.
The reporting system should name responsible officers, reporting intervals, escalation criteria, and board committees. Minutes should record the information presented and the board’s response. These records can support fiduciary-duty defenses, financing diligence, insurance applications, and acquisition review.
Delaware requires a registered office and registered agent. 8 Del. C. §§ 131–132. A domestic corporation must file an annual report and pay franchise tax. 8 Del. C. §§ 502–503. Delinquency can affect good standing and transaction closing conditions.
Operations outside Delaware can require foreign qualification, payroll registration, workers’ compensation coverage, unemployment-insurance registration, and state tax filings. The internal-affairs doctrine generally assigns Delaware law to internal corporate questions. Employment, privacy, consumer, tax, and product claims remain governed by the laws applicable to the conduct and affected persons.
FinCEN’s final rule effective August 14, 2026 excludes domestic entities from the Corporate Transparency Act reporting-company definition. Beneficial Ownership Information Reporting Requirement Revision, 91 Fed. Reg. 52,508, 52,509, 52,523 (Aug. 14, 2026); 31 C.F.R. § 1010.380. Banks, investors, tax authorities, and state registries can still request ownership information.
A founder-funded business with limited operations may incur lower administration costs through a home-state corporation or LLC. A Delaware C corporation remains preferable when institutional investors expect preferred stock, protective provisions, option plans, and Delaware adjudication. Conversion at a later financing can require consents, tax analysis, contract assignments, and capitalization cleanup.
Founder Equity and Ownership of Technology
The corporation should obtain ownership of every asset required to train, operate, and sell the product. Founder stock purchase agreements should state the number of shares, price, vesting schedule, repurchase terms, transfer limits, and intellectual-property obligations. Board approval should precede issuance.
A founder who receives substantially nonvested stock must assess an Internal Revenue Code § 83(b) election. The election must generally be filed within 30 days after the property transfer. 26 U.S.C. § 83(b); Treas. Reg. § 1.83-2(c). Missing the deadline can cause ordinary-income recognition as the stock vests.
Code created before incorporation remains with its author until transferred. Employee work created within the scope of employment can qualify as a work made for hire under 17 U.S.C. §§ 101 and 201(b). Contractor software often falls outside the statutory commissioned-work categories. A signed present assignment under § 204(a) supplies the safer ownership record.
Patent applications require natural-person inventors and written assignments to the company. 35 U.S.C. §§ 115, 261. Assignment agreements should cover present rights, future improvements, prosecution assistance, inventor declarations, and further documents. The company should record material patent assignments with the United States Patent and Trademark Office.
California personnel require narrower employment drafting. California Business and Professions Code § 16600 generally invalidates employment noncompetes. California Labor Code § 2870 excludes qualifying inventions developed entirely on personal time without employer equipment, supplies, facilities, or trade-secret information, subject to the statutory exceptions. Sections 2871–2872 govern notice and related procedures.
Trade-secret protection requires information that derives value from secrecy and reasonable measures to preserve that secrecy. 18 U.S.C. § 1839(3). The company should restrict repository access, model-weight access, credentials, system prompts, evaluation data, and confidential customer information. Departure procedures should revoke access, recover devices, preserve logs, and obtain a written confirmation concerning retained materials.
A founder assignment cannot convey third-party rights that the founder never possessed. The company should maintain a register for datasets, model weights, software libraries, APIs, documentation, and media assets. The register should record the source, license version, acquisition date, permitted uses, attribution duties, redistribution terms, training rights, and deletion obligations.
Open-source code and model licenses require product-specific review. A hosted service can receive different treatment from distributed software. Model licenses can restrict regulated uses, military uses, model improvement, redistribution, or output exploitation. Sales materials should not describe third-party components as proprietary company assets.
Financing and Securities Compliance
Each sale of stock, a SAFE, or a convertible note requires Securities Act registration or an available exemption. Private startups commonly rely on Securities Act § 4(a)(2) and Regulation D. 15 U.S.C. § 77d(a)(2); 17 C.F.R. § 230.506.
Rule 506(b) prohibits general solicitation. It permits sales to an unlimited number of accredited investors and no more than 35 nonaccredited purchasers who satisfy the required sophistication standard. 17 C.F.R. § 230.506(b). Participation by nonaccredited purchasers triggers prescribed information duties.
Rule 506(c) permits general solicitation when every purchaser is accredited and the issuer takes reasonable verification steps. 17 C.F.R. § 230.506(c). Investor self-certification may be insufficient when the circumstances require further verification.
The company must review Rule 506(d) bad-actor disqualification. It must file Form D within 15 days after the first sale under the applicable rule. 17 C.F.R. § 230.503. States can require notice filings and fees despite federal preemption of substantive registration requirements.
Securities Act § 17(a), Exchange Act § 10(b), and Rule 10b-5 govern offering statements. 15 U.S.C. §§ 77q(a), 78j(b); 17 C.F.R. § 240.10b-5. Investor materials should distinguish historical measurements, internal targets, projections, and untested claims. Statements concerning model accuracy, customers, revenue, data rights, regulatory status, safety testing, and intellectual-property ownership require support.
A disclaimer cannot cure a material false statement or omission. The company should preserve evaluation reports, customer contracts, pipeline definitions, data licenses, and technical records supporting each material assertion. Management should update investors when an earlier statement becomes materially misleading before closing.
Rule 701 can exempt qualifying compensatory grants to employees, directors, officers, and specified natural-person consultants. 17 C.F.R. § 230.701. Aggregate sales above $10 million during a twelve-month period trigger the additional disclosure package under Rule 701(e). The board must approve grants and maintain the plan ledger.
Option exercise prices require a defensible fair-market-value process under Internal Revenue Code § 409A. The company should obtain periodic common-stock valuations and refresh them after a material financing, acquisition offer, revenue change, or other value-altering event. Incorrect pricing can impose tax and penalty consequences on the option holder.
A token or transferable digital instrument requires transaction-specific securities analysis. The inquiry examines the investment, common enterprise, expected profits, and reliance on managerial efforts under SEC v. W.J. Howey Co., 328 U.S. 293, 298–99 (1946). Product terminology cannot change the economic substance.
Foreign investors require diligence concerning nationality, upstream ownership, sanctions, requested information rights, board rights, and vetoes. CFIUS risk should be assessed before the company grants access or control rights that require investor consent to remove.
Federal AI, Consumer, and Sector Rules
The verified federal source set contains no generally applicable statute requiring a private developer to obtain a license solely because it develops or releases AI. Executive Order 14,409 expressly states that its frontier-model measures do not authorize mandatory federal licensing, preclearance, or permitting. Exec. Order No. 14,409, § 3(c), 91 Fed. Reg. 34,565, 34,566 (June 5, 2026).
Executive Order 14,365 directs the Attorney General to operate an AI Litigation Task Force and directs federal agencies to assess state AI laws. Exec. Order No. 14,365, §§ 3–7, 90 Fed. Reg. 58,499, 58,500–01 (Dec. 11, 2025). Section 9(c) disclaims an enforceable private right. The order does not itself repeal a state statute. Preemption requires a valid federal source, an actual conflict, and an available judicial or administrative path.
Section 5 of the FTC Act prohibits unfair or deceptive acts or practices in commerce. 15 U.S.C. § 45(a). Claims about accuracy, neutrality, bias, security, deletion, provenance, human review, and product fitness should match testing and operations. Material limitations should reach purchasers before they commit to the service or use it for a consequential decision.
The FTC’s July 2026 AI accuracy statement remains proposed. It creates no independent substantive duty. The Commission’s August 2026 disparate-impact policy states its present enforcement position under the FTC Act. That policy does not amend Title VII, state civil-rights laws, or other statutes enacted by Congress.
Product purpose controls sector classification. Software intended to diagnose, cure, mitigate, treat, or prevent disease can meet the device definition in 21 U.S.C. § 321(h). FDA classification, premarket review, quality requirements, evidence, labeling, and postmarket duties depend on the product and claims.
HIPAA applies when the company acts as a covered entity or business associate and handles protected health information. 42 U.S.C. § 1320d; 45 C.F.R. pts. 160, 164. A business-associate agreement cannot authorize uses that HIPAA prohibits. Deidentification, limited datasets, patient authorizations, and research pathways each have their own requirements.
A creditor or underwriting vendor must assess the Equal Credit Opportunity Act and Regulation B. 15 U.S.C. § 1691; 12 C.F.R. pt. 1002. Current § 1002.6(a) states that ECOA does not provide an effects test for determining discrimination. Intentional prohibited-basis discrimination remains unlawful. Adverse-action notices must provide specific principal reasons under § 1002.9(b)(2), and a generic reference to an internal score is insufficient.
Use of consumer-report information can trigger the Fair Credit Reporting Act. 15 U.S.C. §§ 1681a, 1681b, 1681e, 1681m. Duties can include permissible-purpose controls, certifications, accuracy procedures, user notices, file disclosures, reinvestigation support, and adverse-action notices.
The amended COPPA Rule applies to operators of child-directed online services and operators with actual knowledge that they collect personal information from children under thirteen. 15 U.S.C. §§ 6501–6506; 16 C.F.R. pt. 312. Covered operators must address notice, verifiable parental consent, parental access, retention, security, and limits on conditioning participation.
Educational records can trigger FERPA through the educational institution’s disclosure authority and vendor conditions. 20 U.S.C. § 1232g. Government procurement, defense work, banking, insurance, brokerage, and professional services can add agency rules, contract clauses, licensing requirements, record duties, and audit rights.
The company should classify each intended use before launch. The record should identify the decision, affected person, data, sector, state, customer role, level of automation, and available human review. A general-purpose model can receive different treatment when used for marketing copy, clinical recommendations, credit, or employment screening.
California AI Transparency and Frontier Models
California Civil Code §§ 3110–3111 govern training-data documentation for covered generative-AI systems and services. The statute reaches a developer that designs, codes, produces, or substantially modifies a system for public use. Training includes testing, validation, and fine-tuning.
A covered developer must post documentation by January 1, 2026 and before each later public release or substantial modification within the statute’s scope. The rule applies to systems released on or after January 1, 2022 and made publicly available to Californians, regardless of compensation.
The documentation must include a high-level dataset summary. Required subjects include dataset sources or owners, intended purpose, approximate volume, data types, intellectual-property status, purchase or licensing status, personal information, aggregate information, cleaning, collection periods, first-use dates, and synthetic-data use. Cal. Civ. Code § 3111(a).
The statute contains exceptions for systems whose sole purpose concerns specified security functions, aircraft operation, or federal national-security, military, or defense purposes. Cal. Civ. Code § 3111(b). The enacted title contains no express dedicated enforcement provision. Other statutes or contracts can still apply to a false disclosure.
A company that only calls an external model API may fall outside the developer definition for that model. Fine-tuning, material changes, or a public release under the company’s control can support a different result. The technical architecture and contractual allocation require review.
California Business and Professions Code §§ 22757–22757.6 govern a covered provider that produces a generative-AI system with more than one million monthly visitors or users and public accessibility in California. The provisions became operative January 1, 2026.
A covered provider must offer a free tool that assesses whether image, video, or audio content came from its system. The tool must support uploads, URLs, and an API. It must report detected system provenance while withholding personal provenance data. Cal. Bus. & Prof. Code § 22757.2.
The provider must offer users a manifest-disclosure option for covered content. It must place a latent disclosure in covered generated content when technically feasible and reasonable. The latent disclosure must convey specified provider, system, date, and identifier information. Cal. Bus. & Prof. Code § 22757.3.
A provider that licenses its system must contractually require preservation of the latent-disclosure capability. It must revoke the license within 96 hours after learning that a licensee removed the capability. A covered provider can face $5,000 per violation, with each day treated as a separate violation. The Attorney General, city attorneys, and qualifying county counsel may sue. Cal. Bus. & Prof. Code § 22757.4.
California Business and Professions Code §§ 22757.10–22757.16 govern frontier models. A frontier model is a foundation model trained with more than 10^26 integer or floating-point operations. The calculation includes the original run and later fine-tuning, reinforcement learning, or material modifications. Cal. Bus. & Prof. Code § 22757.11(i).
A frontier developer must publish a transparency report before or concurrently with deploying a new or substantially modified frontier model. The report must identify the developer, release date, supported languages, output modalities, intended uses, and generally applicable use restrictions. Cal. Bus. & Prof. Code § 22757.12(c)(1).
Every frontier developer must avoid materially false or misleading statements about catastrophic risk or management of that risk. Cal. Bus. & Prof. Code § 22757.12(e). A frontier developer must report a critical safety incident within 15 days after discovery. An incident posing an imminent risk of death or serious physical injury requires a report within 24 hours. Cal. Bus. & Prof. Code § 22757.13(c).
A large frontier developer is a frontier developer whose affiliates collectively earned more than $500 million in gross revenue during the preceding calendar year. Cal. Bus. & Prof. Code § 22757.11(j). It must write, implement, comply with, and publish a frontier AI framework. It must review that document at least annually and publish a material modification with its justification within 30 days. Cal. Bus. & Prof. Code § 22757.12(a)–(b).
The large-developer report must summarize catastrophic-risk assessments, results, third-party evaluator involvement, and steps taken under the frontier AI framework. The large developer must also transmit summaries concerning internal-use risk to the Office of Emergency Services under the statutory schedule.
Section 22757.15 authorizes an Attorney General action against a large frontier developer and caps the civil penalty at $1 million per violation. Separate Labor Code provisions enacted through SB 53 protect covered employees who report specified safety concerns and provide employee remedies under their terms.
An application developer using a third-party model can remain outside these frontier-model provisions. A company training its own model must calculate aggregate compute, identify affiliate revenue, preserve cloud and training records, and reassess coverage after later training work.
Privacy, Cybersecurity, and Automated Decisions
The CCPA applies to a for-profit entity that does business in California, determines processing purposes and means, and satisfies a statutory threshold. Cal. Civ. Code § 1798.140(d). The current adjusted annual gross-revenue threshold is $26,625,000.
The other thresholds concern buying, selling, sharing, or receiving for commercial purposes the personal information of 100,000 consumers or households, and deriving 50 percent or more of annual revenue from selling or sharing personal information. Affiliates can enter the definition under the statutory conditions.
A covered business must give collection notice, limit collection and retention to disclosed and compatible purposes, honor consumer rights, and execute compliant service-provider or contractor terms. Cal. Civ. Code §§ 1798.100–1798.135. Sensitive personal information receives added controls.
The private action under § 1798.150 addresses specified security breaches. Current statutory damages range from $107 to $799 per consumer per incident, or actual damages when greater. The CCPA does not create a general private action for every statutory violation.
The current regulations became effective January 1, 2026. Covered businesses must conduct risk assessments for prescribed processing beginning on that date. The first assessment attestation and summary submission is due April 1, 2028 under the current schedule.
Covered businesses using automated decisionmaking technology for significant decisions must comply with the ADMT requirements beginning January 1, 2027. Those duties include prescribed notices, access, and opt-out rights under the regulatory conditions. A company below the CCPA business thresholds can still face contract, breach-notification, biometric, sector, and FTC obligations.
Cybersecurity-audit certifications are staged for covered businesses. The current deadlines are April 1, 2028 for businesses above $100 million in revenue, April 1, 2029 for the $50 million to $100 million band, and April 1, 2030 for lower-revenue covered businesses. Revenue alone does not establish audit coverage; the regulatory processing criteria also apply.
Illinois creates a separate biometric risk. BIPA requires a public retention policy, advance written notice, disclosure of purpose and duration, and a written release before collecting or receiving covered biometric identifiers or information. 740 ILCS 14/15. It restricts sale and requires reasonable protection.
Section 20 authorizes a private action, statutory damages, attorney fees, and other relief. 740 ILCS 14/20. The 2024 amendment treats repeated collection or disclosure through the same method as one violation per person for damages purposes. The amendment does not remove the private action.
A photograph alone is excluded from the listed biometric-identifier definition. A scan of face geometry, voiceprint, retina, iris, fingerprint, or hand geometry can fall within the statute. 740 ILCS 14/10. The company should document the actual technical transformation and avoid relying on a product label.
Security planning should map prompts, outputs, training files, credentials, model weights, personal information, customer secrets, logs, and backups. Contracts should identify the parties’ data roles. Access controls, encryption, patching, vendor review, deletion, incident response, and recovery testing should match the data and representations.
Employment and Hiring Systems
An AI hiring or workforce tool remains subject to federal employment law. Title VII prohibits intentional discrimination and employment practices that create unlawful disparate impact. 42 U.S.C. § 2000e-2(a), (k). The Americans with Disabilities Act governs disability discrimination, qualification standards, medical inquiries, and reasonable accommodation. 42 U.S.C. § 12112.
The FTC’s current enforcement policy concerning disparate impact under the FTC Act does not amend Title VII. Employers and vendors should preserve job-related validation, protected-class testing, accessibility review, and accommodation procedures where federal employment law applies.
The Fair Credit Reporting Act applies when a consumer reporting agency furnishes a consumer report for employment purposes. 15 U.S.C. §§ 1681a(h), 1681b(b). The employer must provide the required disclosure and obtain authorization. Before adverse action, it must provide the report and statutory summary of rights. A final notice must satisfy § 1681m.
New York City Administrative Code §§ 20-870–20-874 restrict use of a covered automated employment decision tool for city candidates or employees. The employer or employment agency must rely on an independent bias audit completed within the preceding year and publish the required summary.
The employer must provide required notice at least ten business days before using the tool. The notice process addresses the use of the tool and the data categories involved. The local law also addresses requests concerning an alternative selection process or accommodation.
Colorado’s replacement statute begins its principal duties on January 1, 2027. Colo. S.B. 26-189, 75th Gen. Assemb., 2d Reg. Sess. (2026). It covers automated decisionmaking technology used to make, guide, or assist specified consequential decisions, including employment.
A covered developer must provide deployers with documentation concerning intended uses, training-data categories, known limitations, appropriate use, and human review. Developers must notify deployers of material updates. Developers and deployers must retain required records for at least three years.
A deployer must provide prescribed notice and post-adverse-outcome information. The enacted law addresses correction, meaningful human review, and reconsideration under its conditions. The Attorney General enforces the statute through the Colorado Consumer Protection Act.
Before January 1, 2030, the Colorado Attorney General must provide a 60-day cure opportunity when cure is possible. The statute creates no new private right of action. It addresses allocation of fault in civil actions brought under existing discrimination law.
Texas Business and Commerce Code chapter 552 has applied since January 1, 2026. The chapter reaches covered business and AI activity connected to Texas under its territorial provisions. Its discrimination section requires intent to discriminate unlawfully, and disparate impact alone is insufficient to prove that intent. Tex. Bus. & Com. Code § 552.056.
The Texas Attorney General has exclusive chapter 552 enforcement authority, subject to a limited exception stated in § 552.106. The chapter creates no private right of action. Tex. Bus. & Com. Code § 552.101.
The Attorney General must give written notice and 60 days to cure before suit. A cured party must provide supporting documentation and describe policy changes intended to prevent recurrence. Uncured violations can produce the graduated penalties in § 552.105, including daily penalties for continuing violations.
A hiring-tool contract should allocate data access, audit assistance, notice content, model-change alerts, correction support, and incident reporting. The employer retains its own statutory duties even when a vendor agrees to perform operational steps.
Intellectual Property and Training Data
United States copyright law requires human authorship. Thaler v. Perlmutter held that the Copyright Act does not permit registration of a work whose sole asserted author is an autonomous AI system. 130 F.4th 1039, 1046–49 (D.C. Cir. 2025), cert. denied, No. 25-449 (U.S. Mar. 2, 2026).
Human-authored selection, arrangement, revision, or expressive contribution can receive protection when it satisfies 17 U.S.C. § 102. Registration materials should identify the human contribution and disclaim material generated without sufficient human authorship. Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence, 88 Fed. Reg. 16,190, 16,192–94 (Mar. 16, 2023).
AI prompts alone will not always establish authorship. The result depends on the human’s control over expressive elements and the contribution embodied in the final work. Records should preserve human editing, selection, arrangement, and revision where ownership matters.
Copyright treatment of training depends on the four factors in 17 U.S.C. § 107. No statute or controlling nationwide decision creates a categorical rule that AI training is fair use. The product, source material, acquisition method, purpose, amount copied, output behavior, licensing market, and competitive effect can change the result.
Thomson Reuters Enterprise Centre GmbH v. Ross Intelligence Inc. rejected fair use on its record. 765 F. Supp. 3d 382, 397–401 (D. Del. 2025). Ross used headnote-derived material to develop a competing legal research product. The court gave substantial weight to the similar commercial purpose and potential market for AI training data. The decision concerned non-generative AI and remains district-court authority.
Bartz v. Anthropic PBC treated copies used for model training differently from copies acquired to build a permanent library. No. 3:24-cv-05417-WHA, 2025 WL 1741691 (N.D. Cal. June 23, 2025). The court treated the training use as fair on that record while reserving issues concerning unauthorized library acquisition. Its August 11, 2025 order confirmed that the piracy-related issues required a fuller record. Bartz, No. 3:24-cv-05417-WHA, Dkt. 296, at 1–4.
Kadrey v. Meta Platforms, Inc. granted Meta summary judgment on the plaintiffs’ record, including the proof concerning market harm. No. 3:23-cv-03417-VC, 2025 WL 1752484 (N.D. Cal. June 25, 2025). The decision did not announce a general exemption for model training.
These district-court decisions establish record-specific applications of § 107. Their differences require acquisition, storage, training, output, and market substitution to be assessed as distinct stages. A company should not combine those stages into one undifferentiated fair-use conclusion.
A defensible training record should preserve source URLs or delivery records, acquisition dates, license versions, opt-out signals, crawl restrictions, filtering decisions, deduplication, and deletion capability. The company should test outputs for memorization, close substitution, trademark use, publicity-rights exposure, personal data, and confidential material.
Customer terms should identify who supplies inputs, which party grants training rights, whether prompts and outputs enter future training, and which party handles infringement claims. A contractual customer warranty cannot validate the company’s independent use of material obtained elsewhere.
Patent law requires a natural-person inventor. 35 U.S.C. §§ 100(f), 115; Thaler v. Vidal, 43 F.4th 1207, 1211–13 (Fed. Cir. 2022). AI can serve as a research tool. A natural person must contribute the legally relevant conception.
Laboratory notebooks, prompts, design records, experiments, and claim-development files should identify the human contribution. The company should resolve inventorship before filing because incorrect inventorship can affect validity and ownership.
Model weights, architecture choices, evaluation datasets, system prompts, deployment methods, and unpublished research can qualify as trade secrets when the statutory elements are met. 18 U.S.C. § 1839(3). Public release, unrestricted access, publication, or inconsistent license terms can defeat secrecy.
Customer Contracts and Civil Liability
Customer contracts should match the product’s technical function and legal classification. Core terms should address permitted uses, prohibited consequential uses, inputs, outputs, training rights, confidentiality, data roles, security, retention, deletion, model changes, service levels, suspension, audit support, export restrictions, and termination.
The agreement should distinguish provider responsibilities from customer deployment duties. A vendor can supply notices, evaluation material, and audit support. Mandatory duties can remain with the customer, vendor, or each party under the governing statute.
Accuracy language requires consistency across contracts, sales decks, model cards, demonstrations, and public statements. A contract can require human review and allocate operational responsibility. It cannot waive fraud, authorize deception, or extinguish a mandatory statutory duty.
Civil liability depends on the claim and forum. Negligence can turn on duty, foreseeability, breach, causation, and damages. Professional-service rules can apply when the company supplies regulated advice. Product-liability treatment of software differs by jurisdiction and product design.
Warranty treatment can differ between licensed software, goods, and services. The company should test governing-law provisions, forum clauses, arbitration terms, damages waivers, liability caps, and limitation periods against mandatory law and customer type.
A service that hosts user content should assess 47 U.S.C. § 230. Coverage turns on the source of the challenged information and whether the claim treats the service as publisher or speaker. A provider that materially contributes to the unlawful aspect of content can face a different classification.
The TAKE IT DOWN Act governs covered nonconsensual intimate visual depictions and qualifying digital forgeries. Pub. L. No. 119-12, §§ 2–3, 139 Stat. 55, 57–61 (2025). Since May 19, 2026, a covered platform must maintain the required request process and remove validly reported content and known identical copies within 48 hours.
A generative service should identify whether users can publish, search, share, recommend, or amplify covered content. It should preserve request records, removal timestamps, hash or matching procedures, and appeal or abuse controls consistent with the statute.
Insurance should follow the identified claims. Technology errors-and-omissions coverage can address defined service failures. Cyber coverage can address specified incidents. Media or intellectual-property coverage can address defined content claims. Directors-and-officers and employment-practices policies protect different insureds.
The company should inspect exclusions for biometric data, generative AI, contractual liability, regulatory proceedings, sanctions, intellectual property, and intentional conduct. Policy language and endorsements control the available protection.
Export Controls and Cross-Border Transactions
Foreign investment can trigger CFIUS when a transaction gives a foreign person control of a United States business. 31 C.F.R. § 800.210. Certain noncontrolling investments also qualify when the target is a TID U.S. business and the investor receives specified rights.
Covered rights can include access to material nonpublic technical information, board or observer rights, nomination rights, or involvement in specified substantive decisions. 31 C.F.R. § 800.211. A TID U.S. business involves critical technology, covered investment infrastructure, or sensitive personal data under § 800.248.
An AI company is not automatically a TID U.S. business. The answer depends on its export-controlled technology, infrastructure functions, data holdings, and foreign investor rights. The company should classify those subjects before signing the investment documents.
Some covered transactions require a declaration under 31 C.F.R. § 800.401. Other transactions can support a voluntary filing. CFIUS can review an unnotified transaction, impose mitigation terms, or recommend divestment. Investor information rights and data-room access should follow the classification.
The Export Administration Regulations govern exports, reexports, in-country transfers, and releases of controlled technology. 15 C.F.R. pts. 730–774. Remote repository access, cloud access, technical support, and access by foreign personnel can create a regulated release.
Certain AI model weights or parameters fall under ECCN 4E091. Section 742.6(a)(13) requires a license for the export, reexport, or in-country transfer of an item classified under that ECCN to any destination worldwide. The classification contains technical thresholds and exclusions, including treatment of published models.
The company must classify the specific model before applying the worldwide rule. Most AI systems do not enter ECCN 4E091 merely because they use machine learning. Compute, capability, publication status, and the Commerce Control List text control the result.
OFAC sanctions require screening of investors, customers, users, counterparties, beneficial owners, and relevant locations. 31 C.F.R. ch. V. Screening should cover onboarding and later ownership or list changes. Contracts should permit information requests, suspension, blocking where required, and termination.
The outbound-investment rules in 31 C.F.R. part 850 govern specified transactions by United States persons involving covered foreign persons in countries of concern. Covered AI activity can make a transaction prohibited or notifiable, depending on intended use and computing thresholds.
Section 850.217 covers specified military, intelligence, surveillance, cybersecurity, digital-forensics, penetration-testing, robotic-control, and high-compute AI activity. A notifiable transaction generally requires a Treasury filing within 30 calendar days after completion. 31 C.F.R. §§ 850.217, 850.404.
A United States parent should screen foreign subsidiaries, joint ventures, acquisitions, greenfield investments, and fund interests before commitment. Contractual conditions should address classification, notifications, information rights, and termination when a prohibited transaction cannot close.
The Department of Justice Data Security Program regulates specified transactions that provide countries of concern or covered persons access to government-related data or bulk United States sensitive personal data. 28 C.F.R. pt. 202. Encryption or anonymization does not necessarily remove covered data from the rule.
Vendor, employment, investment, and data-broker arrangements can fall within the program’s transaction categories. A global AI company should map remote access, administrator privileges, onward transfer, beneficial ownership, and data volume before entering the arrangement.
Tax Treatment and Jurisdiction Fit
A Delaware C corporation is a separate federal taxpayer. Section 11 imposes a 21 percent federal corporate rate. 26 U.S.C. § 11(b). State income, franchise, gross-receipts, sales, use, payroll, and property taxes depend on nexus and sourcing.
Delaware franchise tax applies under state law. Incorporation in Delaware does not confine tax exposure there. Employees, property, sales, customer use, and economic-nexus provisions can create duties in other states.
Section 174A generally permits a current federal deduction for domestic research or experimental expenditures paid or incurred in tax years beginning after December 31, 2024, subject to statutory elections and transition provisions. 26 U.S.C. § 174A. Foreign research expenditures remain subject to § 174 treatment, including fifteen-year amortization under the current text.
The research credit in § 41 requires a separate calculation. Qualified research, eligible wages, supplies, and contract research must satisfy the statutory tests. A qualified small business can assess the payroll-credit election under the applicable limits.
Qualified small business stock can receive § 1202 treatment when the shareholder, issuance, asset, holding-period, and active-business requirements are satisfied. 26 U.S.C. § 1202. Public Law 119-21 amended the rules for stock acquired after July 4, 2025.
Post-enactment stock can receive a 50 percent exclusion after three years, 75 percent after four years, and 100 percent after five years. Pub. L. No. 119-21, § 70431(a), 139 Stat. 72, 240–41 (2025). The amended per-issuer dollar limit is $15 million for qualifying post-enactment stock, subject to the statutory reduction and inflation rules.
The amended qualified-small-business gross-asset threshold is $75 million for the applicable post-enactment rules. Earlier stock remains subject to the prior effective-date provisions. Redemptions, secondary sales, excluded business activities, and later asset growth can change the result.
Restricted stock requires the § 83 analysis described earlier. Options require § 409A valuation and drafting. Cross-border related-party arrangements require arm’s-length pricing under § 482.
Transfers or licenses of intellectual property to foreign related parties can invoke § 367(d), withholding provisions, and foreign tax law. The company should document intercompany services, research ownership, cost sharing, and royalties before material value accumulates.
Sales-tax treatment of software, data, and digital services varies by state. The company should classify each revenue stream and customer location. Marketplace, reseller, and enterprise arrangements can change collection duties.
Founder residence controls personal tax on compensation, stock, and exit proceeds. Employee location controls payroll duties. These facts can outweigh Delaware’s corporate-law advantages for a small project.
On the stated assumptions, a Delaware C corporation remains the preferred United States parent for an AI project expecting institutional venture financing. Launch readiness depends on the model, data, users, intended decisions, investor rights, employee locations, and cross-border access.
THE EUROPEAN UNION
Summary
- The project may proceed, but role and use-case classification must precede product commitments. The same technology can make one entity a model provider, system provider, deployer, importer, distributor, or product manufacturer. Each role carries different duties under Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744.
- The AI Act now governs most covered activity. Existing prohibitions, AI-literacy measures, general-purpose model duties, enforcement rules, and Article 50 transparency duties are current. Chapter III Sections 1 to 3 start on 2 December 2027 for Article 6(2) and Annex III systems, and on 2 August 2028 for Article 6(1) and Annex I systems. Those dates do not make all Annex I systems subject to identical duties: Article 2(2) limits Section B coverage, and Article 2(13) authorises future delegated limits for specified Section A duties. (AI Act, arts. 2(2), 2(13), 4-5, 50-56, 88-101, 113.)
- A project that develops or has a general-purpose AI model developed and places it on the Union market under its name faces current documentation, downstream-information, copyright-policy, and training-summary duties. A downstream modifier may become the provider after a fact-specific assessment; fine-tuning alone does not automatically create that role. Systemic-risk models face evaluation, risk-reduction, incident-reporting, and cybersecurity duties. A non-EU model provider usually needs an authorised representative. (AI Act, arts. 3(3), 51-55.)
- Regulation (EU) 2016/679 often controls collection, training, fine-tuning, evaluation, prompting, monitoring, and output handling. Public availability does not remove personal-data status. The project needs a purpose, an Article 6 basis, Article 9 authority where required, notices, rights handling, security, retention limits, and transfer controls. (GDPR, arts. 3, 5-6, 9, 12-22, 25, 28, 32-35, 44-49.)
- Commercial text-and-data mining can rely on Article 4 of Directive (EU) 2019/790 only where access is lawful and rights were not reserved. Dataset, database, software, trade-secret, and open-source terms still apply. The project should retain source, licence, opt-out, filtering, and deletion records.
- Consumer and platform duties depend on product design. Business-to-consumer claims, subscriptions, personal-data exchange, dark patterns, recommender systems, hosting functions, minors, and accessibility can trigger separate duties under Directives 2005/29/EC, 2011/83/EU, 2019/770, 93/13/EEC, 2019/882, and Regulation (EU) 2022/2065.
- Cybersecurity, product safety, and liability rules depend on the delivery form and sector. The Cyber Resilience Act begins vulnerability and incident reporting on 11 September 2026. Its main manufacturer duties start on 11 December 2027. The revised Product Liability Directive applies through national law to products placed on the market from 9 December 2026. (Regulation (EU) 2024/2847, art. 71; Directive (EU) 2024/2853, arts. 22-23.)
- The EU is not one incorporation, tax, employment, contract, or tort jurisdiction. A genuine Member State establishment can affect company law, tax, labour rules, courts, and the GDPR lead-authority process. A contractual choice of law cannot remove mandatory EU consumer, data, competition, product, or AI duties.
The European Union as a Market and Operating Jurisdiction
The EU is a viable market and operating base for a commercial AI project. It offers one market-access rule set in several fields, yet it does not supply one company-law or tax seat. The project should select a Member State only after it separates EU-wide duties from national duties.
EU regulations bind directly in every Member State. Directives require national implementation and can produce country differences. The AI Act, GDPR, Digital Services Act, Data Act, Cyber Resilience Act, Digital Markets Act, and Rome and Brussels regulations operate at Union level. Company formation, direct tax, employment administration, many civil claims, and procedural rules remain national. (TFEU art. 288.)
Market access can trigger EU law without an EU company. The AI Act covers third-country providers that place systems or general-purpose models in the Union. It also covers third-country providers or deployers when system output is used in the Union. The GDPR reaches non-EU processing tied to offering goods or services to people in the Union or monitoring their behaviour there. The Digital Services Act covers intermediary services with a substantial Union connection. (AI Act, art. 2; GDPR, art. 3; DSA, arts. 2-3.)
An EU establishment still has practical value. It can hold contracts, employ staff, act as importer, serve as authorised representative, and support local market access. A genuine GDPR main establishment may produce a lead supervisory authority for cross-border processing. The entity must have real decision power over that processing. A nominal office does not create the one-stop-shop result. (GDPR, arts. 4(16), 56, 60; Judgment of 15 June 2021, Facebook Ireland and Others, C-645/19, EU:C:2021:483.)
That GDPR lead-authority process does not centralise AI Act, consumer, competition, cybersecurity, product, tax, or employment enforcement. The project should budget for parallel authorities and coordinated investigations. No Member State selection creates a cross-regime one-stop shop.
The choice of Member State also sets national company, tax, employment, consumer enforcement, and civil-procedure conditions. NIS2 implementation already differs. On 8 July 2026, the Commission referred Ireland, Spain, France, and the Netherlands to the Court for incomplete transposition. The revised Product Liability Directive and Platform Work Directive have 2026 transposition deadlines. A jurisdiction decision made only by reference to one regulator can miss larger cost and liability effects.
The project should compare candidate Member States against its actual operating plan. The comparison should cover corporate form, tax, talent, employment, language, sector licensing, regulator access, court speed, evidence preservation, insolvency, and grant conditions. The EU analysis supplies the common baseline. Local counsel must complete the national comparison before incorporation or launch.
AI Act Scope and Allocation of Roles
The project should treat AI Act classification as its first legal design task. The label “AI company” does not identify the regulated actor. Each model, system, integration, and deployment needs its own role record.
The AI Act defines an AI system as a machine-based system designed to operate with varying autonomy. It may exhibit adaptiveness after deployment. It infers from input how to generate outputs that can influence physical or virtual environments. Outputs include predictions, content, recommendations, and decisions. Ordinary deterministic software may fall outside that definition. (AI Act, art. 3(1).)
A provider develops an AI system or model, has one developed, and places it on the market or puts it into service under its name. A deployer uses a system under its authority, outside personal non-professional activity. Importers and distributors have supply-chain duties. A product manufacturer can carry provider duties when it markets an AI system with its product under its own name. (AI Act, arts. 3, 16, 23-26.)
Downstream conduct can change the role. A party becomes the provider of a high-risk system when it places that system under its name, makes a substantial modification, or changes the intended purpose so the system becomes high-risk. The original provider must supply necessary information and technical access under agreed terms. Article 25 does not permit a contract to erase statutory responsibility. (AI Act, art. 25.)
The project should keep a versioned role map. It should identify the legal entity, model or system version, intended purpose, territory, customer type, distribution channel, brand, source provider, modification, and decision rights. Procurement and licence terms should state which party may alter intended purpose, safety limits, prompts, fine-tuning, retrieval sources, monitoring, and update policy.
Several exclusions may narrow the Act. The Act excludes military, defence, and national-security activity. It also excludes qualifying scientific research and pre-market research, testing, or development, subject to the statutory conditions. Personal non-professional use is outside deployer duties. Free and open-source treatment is limited and does not cover prohibited practices, covered high-risk systems, or Article 50 duties. (AI Act, art. 2.)
A project should document any exclusion before relying on it. Commercial beta use, real-world testing, customer pilots, or monetised release can leave the research exclusion. An AI system released under a free and open-source licence falls outside the Act unless it is placed on the market or put into service as high-risk, or falls under Article 5 or 50. Payment alone does not determine whether that scope exclusion applies. The factual record should support the claimed status for each release. (AI Act, art. 2(8), (12).)
Prohibited Practices, AI Literacy, and Transparency
A prohibited-use screen must precede development and sales. Eight Article 5 prohibition categories have applied since 2 February 2025. Two additional prohibitions start on 2 December 2026. A sales restriction or user term is insufficient where the project designs, markets, or supports a prohibited purpose.
Current prohibitions cover harmful manipulation or deception, harmful exploitation of vulnerabilities, specified social scoring, and individual criminal-risk prediction based solely on profiling or personality traits. They also cover untargeted facial-image scraping, most workplace or education emotion inference, biometric categorisation that infers listed protected traits, and most real-time remote biometric identification by law enforcement in public spaces. Exceptions are narrow and text-specific. (AI Act, art. 5.)
From 2 December 2026, Article 5 also covers systems that generate or manipulate non-consensual realistic intimate material or material within Directive 2011/93/EU. Placement or putting into service is prohibited when that result is intended, or is reasonably foreseeable and reproducible without adequate safeguards. Use is prohibited when the deployer uses the system for that purpose. A generative-image or editing product should implement reliable prevention, reporting, and corrective controls before that date. (AI Act, art. 5(1)(ba)-(bb), (1a)-(1b); Regulation (EU) 2026/1744.)
Article 4 now requires providers and deployers to take measures that support AI literacy for staff and other operators acting for them. Measures should reflect technical knowledge, experience, training, use setting, and affected groups. The amended text does not impose one uniform course or individual certification. A role-based programme, use restrictions, escalation rules, and completion records provide a defensible response. (AI Act, art. 4, as amended.)
Article 50 transparency duties have applied since 2 August 2026. Direct-interaction systems must tell people they are interacting with AI unless that fact is obvious to a reasonably informed user. Providers of systems that generate synthetic audio, image, video, or text must support machine-readable detection, subject to statutory limits. Deployers must disclose deepfakes and specified public-interest text. Emotion-recognition and biometric-categorisation deployments require notice. (AI Act, art. 50.)
The four-month transition is narrow. A generative system placed on the market before 2 August 2026 has until 2 December 2026 only for Article 50(2) machine-readable marking. Other Article 50 duties are current. The project should separate user disclosure, output marking, deepfake labels, editorial review, and accessibility because different actors carry those duties. (AI Act, art. 111(4).)
The Commission adopted Article 50 guidelines on 20 July 2026. It published the final transparency code on 10 June 2026. The Commission concluded on 8 July 2026 that the code adequately covers Articles 50(2), (4), and (5), and the AI Board adopted its assessment on 9 July 2026. Adherence does not conclusively prove compliance. A non-signatory remains responsible for showing compliance through its own measures. The project should record technical limits, interoperability choices, error rates, and covered output channels.
National authorities can impose severe fines. Prohibited-practice breaches can reach EUR 35 million or 7 percent of worldwide annual turnover. Other operator duties can reach EUR 15 million or 3 percent. Incorrect information can reach EUR 7.5 million or 1 percent. The AI Act applies lower maximums to undertakings that qualify for its small-business treatment. (AI Act, art. 99.)
General-Purpose AI Models
A project that develops or has a general-purpose AI model developed and places it on the Union market under its name must address current Chapter V duties. A downstream modifier may become the provider after a fact-specific assessment; modification or fine-tuning alone does not automatically create that role. Those duties applied from 2 August 2025. The model analysis is separate from the downstream system analysis. (AI Act, arts. 3(3), 51-56.)
A general-purpose AI model displays broad generality and can perform a wide range of distinct tasks. It can be integrated into many downstream systems or applications. A model used before market release only for research, development, or prototyping may fall outside the definition. A finished model offered through weights, an API, a hosted service, or another commercial channel can fall within it. (AI Act, arts. 3(63), 51-56.)
Every covered provider must maintain technical documentation and provide information to downstream system providers. The provider must adopt a policy to comply with EU copyright and related-rights law. It must publish a sufficiently detailed summary of training content using the Commission template. These duties apply regardless of the model’s business model, subject to limited open-source relief. (AI Act, art. 53.)
The free and open-source exception does not remove the copyright policy or training-summary duties. It can remove specified documentation duties where the provider releases weights, architecture information, and usage information under a qualifying free and open licence. The exception does not cover a model with systemic risk. (AI Act, art. 53(2).)
A model is presumed to present systemic risk when cumulative training compute exceeds 10^25 floating-point operations. The Commission can designate other models based on statutory capability and effect criteria. A provider may present reasoned arguments against the presumption. A provider must notify the Commission when the threshold is met or expected. (AI Act, arts. 51-52.)
Systemic-risk providers must run standardised model evaluations and adversarial testing. They must assess and reduce Union-level systemic risks. They must document serious incidents and report them to the AI Office and national authorities where required. They must maintain adequate model and infrastructure cybersecurity. The duty follows the provider, even where downstream parties control final use. (AI Act, art. 55.)
A third-country GPAI provider must usually appoint an authorised representative in the Union before placing the model there. The representative keeps documentation, cooperates with the AI Office, and may terminate the mandate if the provider breaches the Act. The representative requirement has a narrow open-source exception that does not cover systemic-risk models. (AI Act, art. 54.)
Fine-tuning does not produce one automatic legal result. The project must assess whether its modification creates a new model provider role, changes capability or risk, or amounts to downstream system development. The Commission’s 18 July 2025 GPAI guidelines provide nonbinding indicators. Contracts should allocate access to model cards, evaluation data, copyright records, incident data, and regulator communications.
The Commission, through the AI Office, enforces Chapter V. It can request documents, evaluate models, require measures, and impose fines up to 3 percent of worldwide annual turnover or EUR 15 million, whichever is higher. A provider of a model placed before 2 August 2025 has until 2 August 2027 to comply. (AI Act, arts. 88-94, 101, 111(3).)
High-Risk Systems and the Deferred Timetable
The project should classify prospective high-risk uses now, despite the deferred duties. Product design, data procurement, evidence collection, and supplier contracts can take longer than the remaining transition period.
Article 6 creates two high-risk paths. The first covers an AI system that is a safety component of a product, or is itself a product, listed in Annex I and subject to third-party conformity assessment. The second covers uses listed in Annex III. Chapter III Sections 1 to 3 start on 2 December 2027 for Article 6(2) and Annex III systems, and on 2 August 2028 for Article 6(1) and Annex I systems. Article 2(2) limits the provisions applicable to Section B Annex I systems. Article 2(13) authorises future delegated acts to limit specified duties for Article 6(1) systems where Section A product law supplies equivalent or higher protection without reducing overall protection. (AI Act, arts. 2(2), 2(13), 6, 113.)
Annex III covers specified biometric uses, critical infrastructure, education, employment, access to essential public or private services, law enforcement, migration and border control, and administration of justice or democratic processes. Creditworthiness and risk assessment for life and health insurance are listed uses. Recruitment, task allocation, performance monitoring, and termination tools are listed employment uses. (AI Act, Annex III.)
An Annex III system can avoid high-risk status when it does not pose a significant risk of harm and performs a narrow procedural, preparatory, detection, or support task. The provider must assess the statutory conditions. A system that profiles natural persons remains high-risk. The Commission had not issued final high-risk classification guidelines by 24 August 2026. Draft guidance does not control the legal result. (AI Act, art. 6(3).)
When the duties apply, a provider must operate a continuing risk-management process. It must control training, validation, and testing data. It must prepare technical documents, keep automatic logs, provide clear instructions, design human oversight, and meet accuracy, resilience, and cybersecurity requirements. It must also maintain a quality system, complete conformity assessment, register where required, place the CE mark, monitor performance, and report serious incidents. (AI Act, arts. 8-20, 43, 47-49, 72-73.)
A third-country provider of a high-risk system must appoint a Union authorised representative before making the system available. The written mandate must support document access, registration, authority cooperation, and corrective action. The provider remains liable despite the appointment. (AI Act, art. 22.)
Deployers must follow instructions, assign competent human oversight, monitor input and output, keep logs under their control, and suspend use when risk appears. Employers must inform worker representatives and affected workers before covered workplace use. Article 27 requires a fundamental-rights assessment from bodies governed by public law, private entities providing public services, and deployers of Annex III 5(b) and 5(c) systems, subject to its stated exclusions and conditions. (AI Act, arts. 26-27.)
The project should create the evidence needed for later conformity work. The file should include intended purpose, foreseeable misuse, system boundaries, model and data versions, evaluation methods, subgroup results, error tolerances, human-review design, override records, security tests, change control, complaints, and incidents. Supplier terms should preserve access to those records after termination.
Legacy treatment depends on timing and later system changes. A high-risk system placed on the market before its relevant application date may enter the Act’s duties after a significant design change. Public-authority systems have a separate 2030 deadline. Model and system version control will decide whether a release remains legacy or becomes a new regulated placement. (AI Act, art. 111.)
Personal Data, Web Collection, and Automated Decisions
The GDPR will control many AI projects before the AI Act changes the result. The project should map each processing stage and assign controller, joint-controller, or processor status for that stage. A model contract cannot decide status against the parties’ actual purposes and means.
The GDPR applies to personal data used for collection, training, fine-tuning, retrieval, testing, prompt handling, monitoring, and output delivery. Publicly accessible data remains personal data when it relates to an identified or identifiable person. A model may also contain personal data where people can be identified or information can be extracted by reasonably likely means. (GDPR, arts. 2-4; EDPB Opinion 28/2024.)
Each stage needs a specified purpose and an Article 6 basis. Consent must be freely given, specific, informed, and withdrawable. Legitimate interests require a legitimate purpose, necessity, and balancing against the person’s rights. A provider should assess development and deployment separately because the purpose, data, and affected people can differ. (GDPR, arts. 5-7, 21.)
Article 9 generally prohibits processing listed special categories unless an Article 9(2) condition applies. Article 4a of the amended AI Act supplies a narrow Union-law basis for specified bias detection and correction. One route covers providers of high-risk systems. Another covers deployers of those systems and providers or deployers of other AI systems or models. Each route requires strict necessity, specified risk conditions where applicable, and strong safeguards. (GDPR, arts. 6 and 9; AI Act, art. 4a.)
Article 4a is not a general permission to build demographic profiles. The project must show that less intrusive data, including synthetic or anonymised data, cannot perform the task effectively. It must limit reuse, apply security and privacy-preserving measures, restrict access, prevent third-party access, delete data when no longer needed, and document necessity. The project still needs an Article 6 basis and every other applicable GDPR control.
Large-scale web collection creates a high compliance burden. The provider must establish lawful access, an Article 6 basis, a collection purpose, source controls, data-minimisation filters, retention rules, and an Article 14 notice strategy. The disproportionate-effort exception is narrow and requires protective measures. Robots instructions or copyright opt-outs do not resolve privacy duties. (GDPR, arts. 5-6, 14, 21, 25, 35.)
The EDPB’s Opinion 28/2024 states that model anonymity requires a very low likelihood of identification and extraction using reasonably likely means. A statement that training data was de-identified does not settle the issue. The project should test extraction, memorisation, linkage, and model inversion. It should also retain test conditions and results.
A data protection impact assessment is required where processing is likely to create high risk for people. Novel technology, systematic evaluation, large-scale special-category data, monitoring, vulnerable groups, and decisions with serious effects are common indicators. The assessment must precede processing and remain current after material changes. Unresolved high residual risk requires prior consultation with the supervisory authority. (GDPR, arts. 35-36.)
Article 22 restricts decisions based solely on automated processing that produce legal or similarly significant effects. Contract necessity, Union or Member State law, or explicit consent can create exceptions. Safeguards include human intervention, a chance to state a view, and a right to contest. In SCHUFA, the Court treated automated scoring as covered where a recipient gave the score a determining role. (Judgment of 7 December 2023, SCHUFA Holding, C-634/21, EU:C:2023:957; GDPR, art. 22.)
Access rights can require an intelligible account of an automated result. In Dun & Bradstreet Austria, the Court required an explanation of the procedure and principles actually applied to obtain the result. A controller cannot reject the request merely by invoking trade secrets or third-party data. A court or authority can balance those interests. (Judgment of 27 February 2025, Dun & Bradstreet Austria, C-203/22, EU:C:2025:117.)
The architecture should support access, correction, erasure, restriction, objection, and provenance checks. The GDPR does not prescribe one universal model-unlearning method. The controller must adopt an effective response for the data and risk at issue. Options can include source deletion, retrieval-index deletion, suppression, output filters, fine-tuning changes, retraining, or proof that the model no longer contains personal data.
Processor contracts must identify instructions, confidentiality, security, sub-processors, assistance, deletion or return, and audit rights. Joint development can create joint control where parties jointly decide purposes or essential means. Vendor terms should cover prompts, telemetry, training use, retention, location, sub-processors, breach support, rights requests, and model changes. (GDPR, arts. 26, 28, 32-34.)
A controller or processor caught by Article 3(2) and not established in the Union must usually designate a written Article 27 representative. The representative must be in a Member State where affected people are located. The narrow occasional-processing exception rarely fits sustained consumer, profiling, or monitoring operations. The representative does not replace controller or processor liability. (GDPR, art. 27.)
Transfers outside the EEA require a Chapter V route. Adequacy applies only within its scope. Standard contractual clauses require module selection and a transfer assessment where foreign law can affect protection. Technical controls should match the assessment. The ePrivacy Directive and national cookie rules can also require consent for terminal storage or access. (GDPR, arts. 44-49; Commission Implementing Decisions (EU) 2021/914 and 2023/1795; Judgment in Schrems II, C-311/18, EU:C:2020:559; Directive 2002/58/EC, art. 5(3).)
GDPR fines can reach EUR 20 million or 4 percent of worldwide annual turnover for higher-tier breaches. Individuals can claim compensation for material or non-material damage where statutory conditions are met. A supervisory authority can order suspension, deletion, restriction, or data-flow changes. (GDPR, arts. 58, 82-83.)
Training Content, Copyright, Databases, and Confidential Information
The project needs a documented legal basis for every training and retrieval source. The AI Act does not create a general right to copy protected material. Copyright, database, software, contract, and trade-secret rules continue to apply.
Training can involve reproductions protected by Directive 2001/29/EC, software copies protected by Directive 2009/24/EC, and database extraction protected by Directive 96/9/EC. Temporary technical copies may have narrow treatment, but model development should not assume that all copies are transient. (Directive 2001/29/EC, arts. 2 and 5; Directive 2009/24/EC, arts. 4-6; Directive 96/9/EC, arts. 5 and 7.)
Article 3 of Directive (EU) 2019/790 gives qualifying research organisations and cultural-heritage institutions a text-and-data-mining exception for scientific research with lawful access. A commercial developer does not qualify merely because it conducts research. Public-private work must satisfy the applicable institutional and contractual conditions. (Directive (EU) 2019/790, art. 3.)
Article 4 supplies a broader text-and-data-mining exception for lawfully accessible works. Rights holders can reserve their rights. Online reservations must be expressed by machine-readable means. The exception does not cure unlawful access, enforceable contract limits, privacy duties, or unlawful acquisition of trade secrets. (Directive (EU) 2019/790, art. 4.)
The project should record the source URL or repository, access date, licence, paywall or authentication status, rights reservation, robots instruction, dataset terms, permitted purpose, geographic scope, and deletion request. A crawl should stop or route to review when those signals conflict. A later model audit must be able to trace a challenged source to the decision taken at collection.
Database rights can apply even where individual facts lack copyright. Extraction or reutilisation of a substantial part can infringe. Repeated and systematic extraction of insubstantial parts can also infringe when it conflicts with normal exploitation or harms the maker’s interests. Dataset licences can impose narrower limits than statutory exceptions. (Directive 96/9/EC, art. 7.)
Trade-secret protection applies to information that is secret, has commercial value because it is secret, and is subject to reasonable secrecy steps. A lawful model-training plan should exclude leaked credentials, confidential code, private repositories, restricted customer material, and data obtained through breach. Internal access controls and supplier confidentiality terms preserve the project’s own claims. (Directive (EU) 2016/943, arts. 2-4.)
Model output can infringe when it reproduces protected expression or another protected subject matter, in whole or in part, where the reproduced elements are themselves protected. The applicable exclusive right, statutory exception, and Member State remedy control the result. Filters and prompt restrictions can lower exposure, but they cannot replace source and output testing. Indemnity terms should define covered content, claim control, exclusions, and evidence duties. (Directive 2001/29/EC, art. 2; Judgment of 16 July 2009, Infopaq International, C-5/08, EU:C:2009:465, paras. 37-39.)
EU copyright requires original subject matter that reflects the author’s own intellectual creation. The Court has not issued a direct rule for copyright in purely machine-generated output. Human selection, arrangement, editing, or other creative choices may support protection for the human contribution. The project should avoid promising exclusive copyright in all outputs. (Judgments in Infopaq, C-5/08, EU:C:2009:465; Painer, C-145/10, EU:C:2011:798; Cofemel, C-683/17, EU:C:2019:721.)
Open-source and open-weight inputs require licence review. Copyleft, attribution, notice, source-availability, patent, acceptable-use, and redistribution terms can differ. The AI Act’s open-source treatment is a statutory scope rule. It does not decide whether a licence condition was satisfied or whether third-party training material was lawfully used.
Employee and contractor ownership depends partly on Member State law and contract. The project should secure assignments, moral-right consents where permitted, invention duties, confidentiality, and cooperation for registration or enforcement. The contract should identify code, weights, prompts, evaluations, synthetic data, documentation, and later improvements.
Consumer Services, Online Platforms, Minors, and Accessibility
A consumer-facing AI service carries duties beyond the AI Act. Product claims, interface design, subscription flow, output quality, personal-data exchange, and hosting functions are governed by different legal rules.
Directive 2005/29/EC prohibits unfair business-to-consumer practices. Misleading claims can concern accuracy, safety, human review, source quality, professional status, scarcity, price, endorsements, or likely results. Omitting a material limitation can also mislead. The project should keep substantiation for claims made in websites, app stores, sales scripts, demonstrations, and model cards. (Directive 2005/29/EC, arts. 5-9.)
Directive 2011/83/EU requires pre-contract information for distance contracts and digital services. Directive (EU) 2019/770 creates conformity, update, and remedy duties for digital content and services. It can apply where a consumer provides personal data instead of money, subject to statutory exclusions. Directive 93/13/EEC can invalidate unfair standard terms. (Directive 2011/83/EU, arts. 5-16; Directive (EU) 2019/770, arts. 3, 7-14; Directive 93/13/EEC, arts. 3-6.)
Consumer terms should state the service, price, renewal, output limits, minimum technical requirements, update policy, complaint route, termination rights, and refund or remedy process. They should not disclaim mandatory conformity duties or hide material restrictions. A consumer notice should separate contractual terms from consent requests and privacy notices.
The Digital Services Act applies only when the service performs a covered intermediary function. A chatbot’s own generated answer is not automatically third-party information stored at a recipient’s request. Community posts, shared agents, model marketplaces, plug-in stores, user files, or publishing functions can create hosting or online-platform duties. The project should classify each feature. (Regulation (EU) 2022/2065, arts. 3, 4-6, 14-28.)
A hosting service may need notice-and-action tools, statements of reasons, and complaint channels. An online platform may face dark-pattern, advertising, recommender, trader-traceability, and minor-protection duties. Very large platforms face systemic-risk assessment, risk-reduction, audit, and data-access duties. A non-EU provider may need an EU legal representative. (DSA, arts. 13-17, 20, 25-28, 30, 34-40.)
Article 25 bars interface design that deceives or materially impairs free and informed choice, unless the same conduct is covered by the GDPR or Directive 2005/29/EC. An AI service should test default settings, consent prompts, cancellation, model-personality cues, anthropomorphic claims, interruption prompts, paid upgrades, and retry loops. The applicable authority depends on the conduct and legal basis.
Services accessible to minors need age-sensitive risk work. DSA Article 28 requires online platforms accessible to minors to take appropriate and proportionate measures for privacy, safety, and security. The Commission’s July 2025 minor-protection guidelines are nonbinding and serve as an enforcement benchmark. Age assurance must also comply with data minimisation and proportionality. (DSA, art. 28.)
Directive (EU) 2019/882 applies through national law to covered products placed on the market after 28 June 2025 and covered services provided to consumers after that date, subject to Article 32. Covered areas include e-commerce, consumer banking, electronic communications, e-books, and specified devices. An AI interface inside a covered product or service must meet the applicable accessibility requirements. The precise duty depends on the product or service and Member State implementation.
Qualified entities can seek representative relief for listed consumer-law breaches. The AI Act amended Directive (EU) 2020/1828 to include AI Act violations within its scope. Public enforcement can therefore coincide with consumer injunctions or collective redress. The project should preserve complaint, disclosure, model-version, and remediation records. (AI Act, art. 110; Directive (EU) 2020/1828, Annex I.)
The Digital Markets Act rarely makes a startup a gatekeeper. It matters where the project depends on a designated gatekeeper for app distribution, search, advertising, operating systems, cloud access, or business-user data. Gatekeeper designation and the specific core platform service control the duties. (Regulation (EU) 2022/1925, arts. 2-3, 5-7.)
Data Access, Cloud Services, Cybersecurity, and Product Safety
The project should classify its delivery form before applying data, cybersecurity, or product rules. A hosted AI service, downloadable model, software component, connected device, and regulated product can produce different results.
The Data Act applies to connected products, related services, data holders, and data-processing services. Users can obtain and direct sharing of readily available product and related-service data. The Act distinguishes raw or pre-processed data from inferred or derived data. It also protects trade secrets and sets limits on competing connected products. (Regulation (EU) 2023/2854, arts. 3-11.)
The Data Act does not grant a general right to use third-party data for AI training. A project that receives product data must follow the permitted purpose, user instructions, confidentiality, security, and competition limits. Unilaterally imposed unfair terms on data access or use can be nonbinding. (Data Act, arts. 4-6, 13.)
A provider of cloud or other data-processing services must examine Data Act switching duties. Contracts must address switching assistance, data and digital-asset export, continuity, termination, charges, and interoperability. The project should map proprietary formats and egress dependencies before promising portability. (Data Act, arts. 23-31.)
Regulation (EU) 2018/1807 generally bars Member State localisation requirements for non-personal data, subject to public-security exceptions. Mixed datasets remain governed by the GDPR for their personal-data portion. Sector rules can impose extra location or access duties. The project should separate residency preferences from binding localisation rules. (Regulation (EU) 2018/1807, arts. 3-4.)
NIS2 applies through Member State law to medium-sized and larger entities in listed sectors, and to specified entities regardless of size or after national designation. Covered digital sectors include cloud computing, data centres, managed services, online marketplaces, online search engines, and social-network platforms. Articles 20, 21, and 23 address management accountability, cybersecurity risk measures, and significant-incident reporting. National scope and deadlines require a country check. (Directive (EU) 2022/2555, arts. 2-3, 20-23.)
DORA applies directly to listed financial entities from 17 January 2025. It addresses ICT risk, incidents, resilience testing, information sharing, and third-party contracts. An AI vendor outside direct scope can still face detailed contractual duties and oversight where it supplies a financial entity. (Regulation (EU) 2022/2554.)
The Cyber Resilience Act covers software or hardware products with digital elements made available in the Union. It also covers a manufacturer’s remote data-processing solution when the product cannot perform a function without it. A stand-alone website or unrelated cloud service usually falls outside that definition. (Regulation (EU) 2024/2847, arts. 2-3.)
CRA provisions on conformity-assessment bodies have applied since 11 June 2026. Article 14 reporting starts on 11 September 2026. Manufacturers must then report actively exploited vulnerabilities and severe security incidents under the statutory sequence. The main design, vulnerability-handling, documentation, conformity, and CE-marking duties start on 11 December 2027. (CRA, arts. 13-14, 31-32, 71; Annexes I, II, V, VII.)
A downloadable AI application, embedded model, local agent, or connected-device component can be a product with digital elements. Pure hosted access needs closer review. The project should identify the manufacturer, support period, software bill of materials, update route, vulnerability intake, disclosure policy, incident triage, and EU economic operator before the reporting date.
The General Product Safety Regulation applies from 13 December 2024 to consumer products not fully covered by more specific Union safety rules. It requires safe products, risk analysis, technical documentation, traceability, corrective action, and reporting. AI behaviour can matter where it affects product safety or foreseeable use. (Regulation (EU) 2023/988, arts. 3, 5, 9-12, 20.)
Sector product law can control the result. Medical intended purpose can trigger Regulations (EU) 2017/745 or 2017/746. Machinery, vehicles, aviation, toys, lifts, and radio equipment have separate rules. The AI Act Annex I path depends on those acts and third-party conformity requirements. Sector classification should occur before product claims or clinical, safety, or performance testing.
Liability, Contracts, Competition, and Dispute Design
The project cannot remove statutory responsibility through contract. It can allocate work, evidence, cost, indemnity, and cooperation. A contract should match the actual AI Act, GDPR, copyright, product, and cybersecurity roles.
Current liability can arise under national contract, tort, consumer, data-protection, discrimination, product-safety, and intellectual-property law. The EU did not enact the proposed AI Liability Directive. The Commission withdrew that proposal in 2025. The absence of a special directive does not reduce existing claims or public enforcement. (Commission Work Programme 2025, COM(2025) 45 final, Annex IV, item 32; Withdrawal of Commission Proposals, OJ C, 6 October 2025, CELEX 52025XC05423.)
Directive 85/374/EEC and national implementing law remain relevant for products placed on the market or put into service before 9 December 2026. Member States must apply Directive (EU) 2024/2853 through national law to products placed on the market or put into service from 9 December 2026. It expressly covers software, including AI systems, and specified related services. It also creates evidence-disclosure and proof rules. National transposition remains necessary. (Directive (EU) 2024/2853, arts. 2, 4, 9-10, 21-23, as corrected on 7 May 2026.)
The revised Product Liability Directive can place liability on a manufacturer, component manufacturer, importer, authorised representative, fulfilment provider, or platform in specified conditions. A substantial modifier can become a manufacturer. The project should preserve development, test, update, vulnerability, complaint, and incident records because missing evidence can affect presumptions.
Core supplier terms should identify the system and model versions, intended purpose, prohibited uses, performance measures, evaluation set, human-review assumptions, data sources, licences, personal-data roles, retention, security, updates, logging, audit access, incident notice, regulator support, change control, suspension, and exit assistance. A general warranty that the product “complies with EU law” does not allocate these tasks.
Article 25 of the AI Act makes information access a value-chain issue. A downstream provider can need upstream documentation, model limits, integration instructions, and test data. The contract should set delivery deadlines, confidentiality, permitted regulator disclosure, escrow or continuity measures, and post-termination access. It should also address who pays when an upstream change forces revalidation.
Competition law applies to cooperation, distribution, data, model access, compute, and pricing. Article 101 TFEU can prohibit agreements that restrict competition. Article 102 can prohibit abusive conduct by a dominant undertaking. Exclusivity, tying, discriminatory API access, most-favoured-customer terms, data pooling, and algorithmic information exchange need fact-specific review. In Eturas, knowledge of anticompetitive coordination communicated through a shared online system, coupled with failure to distance the undertaking, could support a rebuttable presumption of participation when the other elements of a concerted practice were present. (TFEU arts. 101-102; Judgment of 21 January 2016, Eturas and Others, C-74/14, EU:C:2016:42, paras. 39-49.)
An algorithm does not shield collusion or abusive conduct. A firm can be responsible where it knowingly uses a pricing or allocation tool that implements an unlawful coordination. Model providers should restrict access to competitively sensitive customer data and prevent cross-customer training that reveals prices, capacity, bids, or strategy.
Acquisitions of datasets, model providers, compute suppliers, or AI applications can trigger EU or national merger review. The EU Merger Regulation applies where turnover thresholds or referral rules are met. Transaction documents should preserve regulatory cooperation and avoid premature integration. (Council Regulation (EC) No 139/2004.)
Choice-of-law and forum clauses still matter. Rome I permits party choice for contracts, subject to mandatory consumer and employee protections. Brussels I bis sets jurisdiction and judgment-recognition rules, with special consumer and employment forums. Rome II applies to many non-contractual claims and assigns intellectual-property claims to the law of the country for which protection is sought. It excludes privacy and personality-right claims, which remain subject to national conflict rules. (Regulations (EC) No 593/2008, No 864/2007, and (EU) No 1215/2012.)
Data-protection, AI, consumer, competition, and product duties can apply regardless of the contract’s chosen law. A dispute clause should account for interim relief, regulator investigations, collective actions, evidence location, confidentiality, and multi-party claims. Arbitration can resolve some commercial disputes, but it cannot bind public authorities or remove mandatory consumer forums.
Employment, Accessibility, Sector Triggers, and Launch Conditions
Employment and sector use can change a low-risk product into a prohibited or future high-risk system. The project should control customer use through product design, sales review, terms, and monitoring.
AI used to recruit, select, allocate work, monitor performance, evaluate workers, or support termination appears in Annex III. The high-risk duties begin on 2 December 2027. Workplace emotion inference is generally prohibited now, subject to medical or safety exceptions. National labour, worker-information, consultation, and works-council rules can apply before either date. (AI Act, art. 5 and Annex III.)
Directives 2000/78/EC and 2006/54/EC prohibit specified employment discrimination. A neutral model rule can create indirect discrimination where it disadvantages a protected group and lacks objective justification. The employer remains responsible for employment decisions. The provider can face contractual, product, data, or discrimination exposure depending on national law and its conduct.
Directive (EU) 2024/2831 addresses digital labour platforms, employment status, and algorithmic management. Member States must transpose it by 2 December 2026. It includes transparency, data restrictions, human monitoring, review, and worker-representative duties. A service that organises paid work through automated monitoring or decisions needs a specific platform-work analysis.
Sector triggers require early intended-purpose control. Medical claims can create medical-device status. Credit, insurance, banking, or investment use can trigger financial rules and DORA. Education, critical infrastructure, public benefits, migration, justice, and biometric uses can enter Annex III. Public procurement can add audit, transparency, security, and data-location terms.
THE UNITED KINGDOM
Summary
- A general commercial AI project remains suitable for a conditional launch. No Act in force on 21 August 2026 creates a universal AI licence, horizontal risk classification, or single AI regulator. Existing law attaches according to conduct, data, service design, sector, and territory.
- Personal-data processing requires a purpose-specific analysis under the UK GDPR and Data Protection Act 2018. The Data (Use and Access) Act 2025 broadened the lawful bases available for significant solely automated decisions. Articles 22A to 22D retain information, representation, human-intervention, and contest rights. Data (Use and Access) Act 2025, s 80; UK GDPR, arts 22A–22D.
- Commercial model training in the United Kingdom cannot rely on the text-and-data-analysis exception in section 29A. Training copies require permission or another exception matched to the particular act. Copyright, Designs and Patents Act 1988, ss 16–18, 29A.
- Getty Images (US) Inc v Stability AI Ltd did not approve unlicensed training. Getty abandoned the United Kingdom training claim because it could not prove relevant domestic acts. The tested model weights were not infringing copies because they did not contain or store protected works. Limited trade mark claims succeeded. Getty Images (US) Inc v Stability AI Ltd [2025] EWHC 2863 (Ch) [9], [600], [758].
- Consumer-facing claims, rankings, prices, subscriptions, and agent transactions remain attributable to the trader when presented as part of its commercial practice. The Competition and Markets Authority may impose turnover-based penalties. Digital Markets, Competition and Consumers Act 2024, ss 225–230 and Part 3; Consumer Rights Act 2015, ss 34, 49, 62.
- Online Safety Act 2023 coverage turns on product architecture. User sharing, public user-created bots, multi-source search, or pornographic generation can bring a service within scope. A private one-to-one chatbot meeting Ofcom’s exclusion conditions falls outside the current service categories. Online Safety Act 2023, Parts 2, 3 and 5.
- AI-assisted employment, access, pricing, credit, or public-service decisions create equality exposure. The Equality Act 2010 applies in Great Britain. Northern Ireland applies separate equality legislation.
- A United Kingdom entity serving the European Union can also fall within Regulation (EU) 2024/1689. General application began on 2 August 2026, subject to amended transition dates. Regulation (EU) 2026/1744 moved Annex III high-risk duties to 2 December 2027 and Annex I product-system duties to 2 August 2028.
Suitability and current regulatory structure
Parliament has not enacted a horizontal AI Act or a universal approval route. The Artificial Intelligence (Regulation) Bill [HL] received only a first reading during the 2024–26 Session. It made no further progress after prorogation. Artificial Intelligence (Regulation) Bill [HL], HL Bill 76, Session 2024–26.
Several enactments contain narrower AI provisions. The Data (Use and Access) Act 2025 regulates automated decisions involving personal data. The Crime and Policing Act 2026 created a delegated power concerning illegal AI-generated content. The Product Regulation and Metrology Act 2025 permits later product regulations covering software and AI components. Those measures do not create a general AI licence.
A general chatbot, model API, productivity tool, or software service can enter the market without prior AI-specific permission. Separate permission may apply where the service performs a regulated financial activity, qualifies as a medical device, controls a safety-related product, or falls within a statutory online-service category.
Legal classification follows the project’s acts and intended purpose. Data collection invokes data law. Model training can invoke copyright and database rights. Consumer deployment invokes trading and contract law. User sharing can invoke the Online Safety Act. A physical or clinical function can invoke product or medical-device rules.
Legal systems and territorial reach
The United Kingdom contains three legal systems: England and Wales, Scotland, and Northern Ireland. Data protection and competition law generally operate across the United Kingdom. Private law, defamation, equality, product routes, court procedure, and remedies contain territorial differences.
This memorandum uses England and Wales as the business-contract and civil-liability baseline. Scotland or Northern Ireland may apply different rules where a customer, worker, harmful event, regulated product, or court claim is connected there.
A contractual English-law clause can improve predictability between businesses. It does not remove mandatory data, consumer, competition, criminal, product, or sector duties. Consumer terms also remain subject to fairness and territorial-protection rules. Consumer Rights Act 2015, ss 62, 74.
Territorial reach does not depend only on incorporation. The UK GDPR can reach a foreign controller or processor offering goods or services to people in the United Kingdom or monitoring their behaviour there. UK GDPR, art 3. The Online Safety Act can reach a foreign service with the required United Kingdom link. Online Safety Act 2023, Part 2. European Union market access is governed separately by Regulation (EU) 2024/1689, art 2.
Personal data and model development
Public availability does not remove information from the definition of personal data. Names, account handles, images, voices, device identifiers, locations, prompts, and inferred characteristics can identify a person. Scraping, collection, labelling, embedding, training, retrieval, logging, evaluation, and output generation can each constitute processing. UK GDPR, arts 4(1), 4(2), 5.
Each processing purpose needs a lawful basis under article 6. Legitimate interests may support a defined purpose after necessity and balancing work. Contract necessity is narrower than commercial convenience. Consent must be informed, specific, freely given, and withdrawable. UK GDPR, arts 6 and 7.
Special-category data requires an article 9 condition and any applicable domestic condition. Criminal-offence data invokes article 10 and the Data Protection Act 2018. Model development should not treat an unknown mixture of internet data as ordinary personal data until the business has tested that assumption. UK GDPR, arts 9 and 10; Data Protection Act 2018, Sch 1.
The controller must record sources, purposes, legal bases, retention, recipients, transfers, and data-subject rights. Indirect collection can invoke article 14. The disproportionate-effort exception in article 14(5)(b) is conditional and does not remove the duties of fairness, lawful basis, or accountability. UK GDPR, arts 12–14, 24.
Roles must be assigned across the model provider, application operator, customer, cloud host, evaluator, annotator, and support supplier. A processor that reuses customer prompts for its own training may become a controller for that purpose. Contract terminology does not determine the legal role. UK GDPR, arts 26 and 28.
A data-protection impact assessment is required where the processing is likely to create high risk. Large-scale sensitive data, vulnerable people, systematic monitoring, and significant decisions are strong triggers. Innovative technology alone does not make every project high risk. UK GDPR, art 35.
Security controls must address prompt leakage, memorisation, model extraction, retrieval permissions, tenant separation, support access, and excessive logging. The controller should test deletion propagation, access boundaries, output regurgitation, incident response, and model-version changes. UK GDPR, arts 25 and 32.
Cookies, device storage, analytics, and electronic marketing can invoke the Privacy and Electronic Communications Regulations 2003. Those rules apply independently to interface design and marketing. Privacy and Electronic Communications (EC Directive) Regulations 2003, SI 2003/2426, regs 6 and 22.
Automated decisions and profiling
The Data (Use and Access) Act 2025 replaced the former article 22 structure with articles 22A to 22D. A decision is solely automated when no person has meaningful involvement. A decision is significant when it produces a legal effect or an effect of comparable significance. Data (Use and Access) Act 2025, s 80; UK GDPR, art 22A.
A controller may use a wider range of article 6 lawful bases for a significant solely automated decision. The new recognised-legitimate-interests basis in article 6(1)(ea) cannot support such a decision. Special-category data remains subject to narrower conditions. UK GDPR, art 22B.
The controller must provide information about the decision. It must permit representations, human intervention, and a contest. UK GDPR, art 22C. A nominal reviewer does not provide meaningful human involvement. The reviewer needs authority, relevant information, competence, and time to change the result.
Recruitment, credit, insurance, benefits, education, fraud, account suspension, and access decisions deserve early classification. Each decision record should identify the input, consequence, lawful basis, reviewer, challenge route, and final action.
The Data Protection Act 2018 now requires a data-protection complaint process. The controller must facilitate complaints, acknowledge them within 30 days, investigate, keep the complainant informed, and respond without undue delay. Data Protection Act 2018, s 164A.
International data transfers
Overseas hosting, support, telemetry, moderation, backup, or subprocessor access can constitute a restricted transfer. The project must map remote access as well as server location.
Available routes include adequacy regulations, the International Data Transfer Agreement, the United Kingdom Addendum to European Union standard clauses, binding corporate rules, and the limited article 49 derogations. Appropriate safeguards also require the statutory data-protection test. UK GDPR, arts 44–49.
Commission Implementing Decision (EU) 2025/2574 renewed European Union adequacy for the United Kingdom through 27 December 2031. The decision supports covered transfers from the European Economic Area to the United Kingdom. It does not authorise every onward transfer from the United Kingdom.
Copyright and model training
Model development can create copies during collection, storage, cleaning, tokenisation, caching, batching, training, fine-tuning, and retrieval. Each restricted act occurring in the United Kingdom requires permission unless an exception applies. Copyright, Designs and Patents Act 1988, ss 16–18.
Section 29A permits computational analysis where the researcher has lawful access and acts for non-commercial research. A commercial training programme cannot use that exception. Copyright, Designs and Patents Act 1988, s 29A. Other exceptions require an act-specific analysis.
The dataset record should identify each source, right holder, licence, access term, permitted purpose, territory, model-training clause, sublicensing right, attribution duty, deletion duty, and termination consequence. Public web access does not itself grant a training licence.
Database right can protect investment in obtaining, verifying, or presenting database contents. Extraction or reutilisation of a substantial part can infringe. Repeated extraction of insubstantial parts can also engage the right. Copyright and Rights in Databases Regulations 1997, SI 1997/3032.
Website terms, API conditions, access controls, confidentiality, and trade secrets create separate exposure. A copyright defence does not decide a contract or confidence claim. Trade Secrets (Enforcement, etc.) Regulations 2018, SI 2018/597.
Getty Images and imported models
Getty Images (US) Inc v Stability AI Ltd gives narrow guidance. Getty abandoned its training claim because it could not establish that relevant training or development acts occurred in the United Kingdom. The court did not decide that unlicensed training was lawful. Getty Images (US) Inc v Stability AI Ltd [2025] EWHC 2863 (Ch) [9].
The secondary-infringement claim failed on the tested evidence. The model weights did not contain or store reproductions of the works. They were therefore not infringing copies under the statutory definition. Getty [600].
Limited trade mark claims succeeded where specified outputs reproduced Getty or iStock watermarks in circumstances satisfying the statutory test. The remaining secondary copyright claim failed. Getty [758].
The March 2026 government copyright report recorded an appeal. No appellate judgment had been issued by 21 August 2026. Getty should not be treated as settled approval for datasets, training locations, imported models, or output conduct.
Outputs and ownership
An output can infringe when it reproduces all or a substantial part of a protected work. Liability depends on the act performed, the responsible person, knowledge requirements, and available defences. Copyright, Designs and Patents Act 1988, ss 16–21, 23.
The project should test prompts likely to produce protected characters, logos, watermarks, code, or memorised passages. Notice handling should preserve the challenged output, prompt path, model version, retrieval source, and response action.
Trade mark liability can arise where a protected sign is used in the course of trade and the statutory conditions are met. Trade Marks Act 1994, s 10. The Getty judgment confirms that generated watermarks can satisfy those conditions on particular facts.
Section 9(3) identifies the author of a computer-generated literary, dramatic, musical, or artistic work as the person making the necessary arrangements. Copyright, Designs and Patents Act 1988, ss 9(3), 178. That provision does not establish copyright subsistence for every output or identify the relevant person across every supply chain.
Customer terms should avoid an unconditional promise of exclusive ownership. The provider first needs to confirm copyright subsistence, human contribution, necessary arrangements, upstream terms, and retained third-party rights.
Patent protection remains available for qualifying technical inventions. A natural person must be named as inventor. Ownership of an AI system does not create inventorship or title by itself. Thaler v Comptroller-General of Patents, Designs and Trade Marks [2023] UKSC 49 [56]–[63], [73].
Emotional Perception AI Ltd v Comptroller-General of Patents, Designs and Trade Marks rejected the former Aerotel approach. An artificial neural network is a program for a computer. A claim involving computer hardware has technical character and is not excluded as a computer program “as such.” Novelty, inventive step, and the remaining requirements still require examination. Emotional Perception AI Ltd v Comptroller-General of Patents, Designs and Trade Marks [2026] UKSC 3 [59]–[67], [87]–[98], [112]–[118].
Consumer services and agent transactions
An AI-generated statement presented by a trader can form part of the trader’s commercial practice. Claims concerning accuracy, bias, professional equivalence, source provenance, security, savings, or predicted outcomes need evidence matching the representation.
The Digital Markets, Competition and Consumers Act 2024 prohibits unfair commercial practices, misleading actions, misleading omissions, and aggressive practices. Digital Markets, Competition and Consumers Act 2024, ss 225–230. A general warning about model error will not cure a specific misleading claim.
The Competition and Markets Authority can use direct enforcement powers. A fixed monetary penalty can reach £300,000 or 10 per cent of global turnover, whichever is higher. Digital Markets, Competition and Consumers Act 2024, Part 3.
Digital content must meet the statutory quality standard. Services must be performed with reasonable care and skill. Consumer terms and notices must be fair. Consumer Rights Act 2015, ss 34, 49, 62.
Terms allowing broad prompt reuse, unilateral model changes, indefinite suspension, or complete exclusion of remedies require a fairness review. Statutory consumer rights cannot be removed through a disclaimer.
An AI agent authorised to buy, book, or contract should use defined spending limits, confirmation events, counterparty identification, revocation, error handling, and evidence of user authority. The provider’s design and representations remain relevant to liability.
Online services and generated content
Online Safety Act coverage turns on service functions. A user-to-user service allows users to encounter content generated, uploaded, or shared by other users. A search service lets a user search more than one website or database. Part 5 applies to services publishing or displaying pornographic content. Online Safety Act 2023, Parts 2, 3 and 5.
A private chatbot falls outside those categories when users interact only with the chatbot, it does not search multiple websites or databases, and it cannot generate pornography. Adding group chat, public output sharing, public user-created bots, or live multi-source search can change that result.
AI-generated material shared through an in-scope user-to-user service is user-generated content. The provider must complete the applicable illegal-content assessment, maintain records, operate reporting routes, and apply the relevant safety duties. Child-accessible services require the statutory child-access and child-risk work.
A service that publishes or displays pornographic material must use highly effective age assurance. Online Safety Act 2023, Part 5.
Ofcom can impose a penalty of £18 million or 10 per cent of qualifying worldwide revenue, whichever is greater. Online Safety Act 2023, Sch 13.
Section 248 of the Crime and Policing Act 2026 inserted section 216A into the Online Safety Act. The new section permits later regulations concerning illegal AI-generated content and AI services used for priority offences. The power does not place every standalone AI service within scope by itself. No implementing instrument was in force as of 21 August 2026.
Equality, employment, and access decisions
The Equality Act 2010 applies in Great Britain to employment, services, education, public functions, and other defined fields. Direct discrimination, indirect discrimination, disability discrimination, harassment, victimisation, and reasonable-adjustment duties can attach to AI-assisted conduct. Equality Act 2010, ss 13, 19, 20, 29, 39.
A neutral criterion can create indirect discrimination where it disadvantages a protected group. The organisation must prove the applicable justification. A vendor’s assurance or aggregate accuracy score does not decide that issue.
Recruitment, promotion, scheduling, performance, access, pricing, and fraud tools should be tested against the population and purpose claimed. The record should cover false positives, false negatives, proxy variables, accessibility, missing data, and model drift.
The employer or service provider remains responsible for its own decision. Human review needs authority to examine relevant evidence and reverse the machine result. A reviewer who routinely accepts the score provides little protection.
Northern Ireland does not use the Equality Act 2010 as its general equality statute. Separate instruments govern religion or belief, political opinion, race, sex, disability, sexual orientation, and age. Material instruments include the Fair Employment and Treatment (Northern Ireland) Order 1998, Race Relations (Northern Ireland) Order 1997, Sex Discrimination (Northern Ireland) Order 1976, Disability Discrimination Act 1995, and Employment Equality (Age) Regulations (Northern Ireland) 2006.
Public authorities must also consider the Human Rights Act 1998. Authorities in Great Britain must comply with the public-sector equality duty. Human Rights Act 1998, s 6; Equality Act 2010, s 149.
Children and biometric data
A service likely to be accessed by children requires child-specific data design. The controller must account for children’s higher protection needs under the amended article 25. UK GDPR, art 25. The Information Commissioner’s Age Appropriate Design Code remains the main statutory operational code.
The project should set child-appropriate defaults for profiling, geolocation, data sharing, retention, recommender functions, and parental controls. A general adult privacy notice does not address those design questions.
Biometric data is special-category data when processed to identify a person uniquely. Facial templates, voiceprints, gait, and comparable identifiers require an article 9 condition. UK GDPR, arts 4(14), 9.
The project should define enrolment, matching thresholds, liveness checks, template security, retention, deletion, demographic performance, and contest routes. Employment surveillance and public-space identification must satisfy their own necessity and proportionality tests.
Cybersecurity and operational resilience
Article 32 requires security appropriate to the risk where personal data is processed. The assessment should cover model endpoints, retrieval stores, plugins, agent permissions, secrets, dependencies, training access, and support accounts. UK GDPR, art 32.
Testing should address prompt injection, data exfiltration, poisoning, model extraction, unsafe tool use, compromised updates, and tenant crossover. The project should connect security tests to incident decisions and release authority.
The Network and Information Systems Regulations 2018 can apply to operators of essential services and defined relevant digital service providers. Defined services include cloud computing, online search engines, and online marketplaces. Covered providers must take appropriate and proportionate security measures and report qualifying incidents. Network and Information Systems Regulations 2018, SI 2018/506, regs 10–12.
Consumer connectable products can invoke the Product Security and Telecommunications Infrastructure Act 2022 and the 2023 security regulations. Covered manufacturers, importers, and distributors face requirements concerning default passwords, vulnerability reporting, and the stated minimum security-update period. Product Security and Telecommunications Infrastructure Act 2022; Product Security and Telecommunications Infrastructure (Security Requirements for Relevant Connectable Products) Regulations 2023, SI 2023/1007.
The government’s AI Cyber Security Code of Practice remains voluntary. Contract terms or a regulator’s statutory test can still make its measures relevant evidence. The Cyber Security and Resilience Bill had not become law by 21 August 2026.
Products and physical safety
AI embedded in a physical product must satisfy the laws applying to that product and its supply chain. Duties can include conformity assessment, technical records, marking, instructions, corrective action, and market surveillance.
The Product Regulation and Metrology Act 2025 supplies regulation-making powers. It does not itself create a complete safety code for standalone AI. The government’s March 2026 product proposals remained consultations as of 21 August 2026.
The Consumer Protection Act 1987 can impose strict liability for damage caused by a defective product in Great Britain. Northern Ireland has a separate product-liability order. Whether every form of standalone software falls within existing product liability remains unsettled. Consumer Protection Act 1987, Part I; Consumer Protection (Northern Ireland) Order 1987.
A safety-related deployment should define intended purpose, expected use, foreseeable misuse, performance limits, human authority, safe failure, update controls, rollback, incident escalation, and post-release monitoring. Product claims can affect the safety expected by users.
Medical and financial functions
Software can qualify as a medical device according to intended purpose and function. Medical Devices Regulations 2002, SI 2002/618, reg 2. Clinical claims, diagnosis, treatment, monitoring, prediction, and patient-specific recommendations require an early classification decision.
Great Britain requires the applicable conformity route and MHRA registration before market placement. Northern Ireland follows the relevant European Union medical-device rules. Since 28 May 2026, most non-custom devices for Northern Ireland require EUDAMED registration. Great Britain manufacturers serving Northern Ireland also need an authorised representative established in the European Union or Northern Ireland.
A financial function requires a perimeter review under the Financial Services and Markets Act 2000 and Regulated Activities Order 2001. Advice, arranging, dealing, credit, insurance, and payment functions may require authorisation. Financial Services and Markets Act 2000; Financial Services and Markets Act 2000 (Regulated Activities) Order 2001, SI 2001/544.
The Financial Conduct Authority applies existing authorisation, systems, conduct, consumer, and accountability rules to AI use. It has not adopted a separate rulebook that replaces those duties.
Competition and commercial coordination
Competition Act 1998 section 2 prohibits anticompetitive agreements and concerted practices. Section 18 prohibits abuse of a dominant position. AI-mediated conduct remains attributable under the ordinary statutory tests.
Shared pricing systems, competitor-data feeds, common optimisation providers, or agents reacting to rivals can create coordination risk. The business should restrict competitively sensitive inputs and retain records of pricing objectives, constraints, and intervention.
Special conduct requirements under the Digital Markets, Competition and Consumers Act 2024 apply only after strategic-market-status designation. Ordinary competition and consumer rules apply without designation.
Civil liability and contracts
The United Kingdom has no single rule assigning every AI loss to the model developer. Liability follows the cause of action, defendant’s role, contractual promise, duty, causation, defences, and loss.
Contract liability can arise from a description, warranty, service level, data-use promise, security obligation, or statutory standard. Negligence remains fact-sensitive. Reliance, proximity, assumption of responsibility, warnings, professional use, and user conduct can affect the result. Hedley Byrne & Co Ltd v Heller & Partners Ltd [1964] AC 465; Caparo Industries plc v Dickman [1990] 2 AC 605.
Generated factual allegations can create defamation exposure. England and Wales apply the Defamation Act 2013. Scotland and Northern Ireland have separate defamation statutes. Publication, adoption, notice, correction, and republication can affect liability.
Prompts or outputs can disclose private or confidential information. Misuse of private information, breach of confidence, data protection, harassment, and intellectual-property claims may arise. Campbell v MGN Ltd [2004] 2 AC 457.
Business contracts should allocate model access, data roles, training reuse, security, subprocessing, transfers, service changes, evaluation rights, incident notice, intellectual-property claims, audit access, suspension, exit, and evidence retention. Indemnities need defined triggers, conduct control, exclusions, limits, and survival terms.
Investment, exports, and sanctions
The National Security and Investment Act 2021 can require pre-completion notification for a qualifying acquisition involving activities defined within the artificial-intelligence sector. National Security and Investment Act 2021; National Security and Investment Act 2021 (Notifiable Acquisition) (Specification of Qualifying Entities) Regulations 2021, SI 2021/1264.
The government announced an intended narrowing for off-the-shelf AI in March 2026. The operative 2021 regulations remained in force on 21 August 2026. A transaction should use the enacted definition until amending regulations take effect.
Export controls can apply to controlled hardware, software, technology, cryptography, technical assistance, end uses, destinations, and counterparties. AI software is not controlled merely because it uses AI. Export Control Order 2008, SI 2008/3231.
Sanctions screening should cover customers, beneficial owners, payment routes, support access, and technology transfers. Sanctions and Anti-Money Laundering Act 2018 and the applicable country or thematic regulations control that analysis.
European Union access and Northern Ireland
A United Kingdom establishment does not prevent Regulation (EU) 2024/1689 from applying. Article 2 can reach providers placing systems or general-purpose models on the European Union market. It can also reach certain providers or deployers where output is used in the European Union.
Prohibited-practice and AI-literacy provisions applied from 2 February 2025. General-purpose model obligations and institutional provisions applied from 2 August 2025. Most remaining provisions, including article 50 transparency duties, applied from 2 August 2026. Regulation (EU) 2024/1689, arts 5, 50, 53–55, 113.
Regulation (EU) 2026/1744 moved the main Annex III high-risk application date to 2 December 2027. It moved the principal Annex I product-integrated high-risk date to 2 August 2028. Role-specific transition provisions still require system-level review.
A United Kingdom provider serving European Union users should identify its role, prohibited-practice exposure, high-risk classification, transparency duties, technical documentation, copyright policy, representative obligations, and conformity route.
The Windsor Framework does not apply the whole European Union AI Act in Northern Ireland through the replacement-law mechanism. The United Kingdom notification identified articles 103 to 107 and 109. Independent article 2 territorial reach can still apply where a Northern Ireland business places a system on the European Union market or its output is used there.
European Union adequacy for United Kingdom data protection does not satisfy the European Union AI Act. The two instruments regulate separate matters.
IRELAND
Summary
- Ireland is a suitable EU base when the company places real management, product control, records, and skilled staff there. A nominal office will not establish Irish regulatory leadership.
- The EU AI Act applies directly. Prohibited practices, AI literacy, general-purpose-model duties, and Article 50 transparency duties are already applicable under the Act’s staged dates. Annex III high-risk duties start on 2 December 2027. Article 6(1) systems governed by Annex I Section A product legislation enter the high-risk regime on 2 August 2028; Article 2(2) limits the AI Act provisions that apply to Annex I Section B products. (Regulation (EU) 2024/1689, arts. 2(2), 4, 6, 50, 113, Annexes I and III, as amended by Regulation (EU) 2026/1744.)
- The Regulation of Artificial Intelligence Act 2026 created the AI Office of Ireland. Ireland uses fifteen sector authorities, so one project may face several regulators. (Regulation of Artificial Intelligence Act 2026; S.I. No. 366/2025; S.I. No. 405/2026.)
- GDPR compliance will control most training, personalization, monitoring, and automated-decision designs. Publicly accessible data remains personal data when it identifies people. Article 4a of the AI Act creates only a narrow, safeguarded route for special-category data used strictly for bias detection and correction; it does not authorize ordinary model training or personalization. (Regulation (EU) 2016/679, arts. 5, 6, 9, 13-15, 22, 25, 32-35; Regulation (EU) 2024/1689, art. 4a.)
- Ireland offers useful copyright rules for computer-generated works. Those rules do not remove training-data, database, license, or EU originality risks. (Copyright and Related Rights Act 2000, ss. 21, 23; S.I. No. 567/2021.)
- Cyber, cloud, platform, and product duties depend on delivery architecture. NIS2 transposition remains incomplete, while the Data Act already applies and Cyber Resilience Act reporting starts on 11 September 2026.
- The standard trading corporation tax rate remains 12.5 percent. Current tax reliefs can assist research and qualifying IP income, but eligibility depends on substance, transfer pricing, and the applicable tax rules.
Suitability of Ireland as the operating jurisdiction
Ireland can support an EU-facing AI business, but the legal advantage depends on substance. The Irish company should control product design, data purposes, model release, customer terms, risk acceptance, and incident response. Those decisions should appear in Irish board records, delegated authorities, employment roles, and technical change records. A company that merely invoices from Ireland gains little regulatory certainty.
EU law supplies most operative rules. Ireland adds company law, enforcement procedure, tax, civil liability, employment law, and regulator allocation. The result is an English-speaking common-law forum inside the EU legal order. It is not a separate route around EU digital law.
The principal benefit is institutional access. Ireland has one statutory AI coordinator, an established Data Protection Commission, a specialist Commercial Court list, and sector regulators familiar with cross-border businesses. The principal cost is regulatory density. A single product can attract the AI Office, the Data Protection Commission, the Competition and Consumer Protection Commission, Coimisiún na Meán, and a sector authority.
EU AI Act role allocation and territorial reach
The first legal task is to classify each company role. The AI Act separates providers, deployers, importers, distributors, product manufacturers, and providers of general-purpose AI models. A company can hold several roles for one service. Developing or materially fine-tuning a general-purpose AI model can make the company a model provider. For high-risk systems, rebranding, substantial modification, or a changed intended purpose can transfer provider duties under Article 25 when the relevant high-risk provisions apply. (Regulation (EU) 2024/1689, arts. 2, 3, 25, 53.)
The Act reaches providers that place AI systems or models on the EU market. It also reaches certain third-country providers and deployers when the system output is used in the Union. An Irish entity cannot allocate all duties to a foreign affiliate if the Irish company markets, modifies, or controls the EU service. (Regulation (EU) 2024/1689, art. 2.)
The project should maintain a role memorandum for every model and product version. That record should identify the base-model supplier, fine-tuning party, system provider, customer deployer, importer, distributor, and product manufacturer. Customer contracts should match that classification. A contract label cannot defeat the functions performed in fact.
Open-source release does not create a general exemption. The Act contains limited treatment for certain free and open-source components. General-purpose models with systemic risk and prohibited practices remain subject to the relevant duties. The project should review the exact license, release method, downstream controls, and monetization model before relying on an exclusion. (Regulation (EU) 2024/1689, arts. 2, 53-55.)
General-purpose AI models
A company that develops or materially fine-tunes a general-purpose AI model faces duties beyond ordinary system deployment. Providers must keep technical documentation, give downstream information, maintain a Union copyright-compliance policy, and publish a sufficiently detailed training-content summary. (Regulation (EU) 2024/1689, art. 53.)
Providers of models with systemic risk face model evaluations, adversarial testing, systemic-risk assessment, incident reporting, and cybersecurity duties. The European AI Office supervises those rules. The voluntary General-Purpose AI Code of Practice can support proof, but the Regulation remains controlling. (Regulation (EU) 2024/1689, arts. 51, 55, 88-93, 101.)
The GPAI rules started on 2 August 2025. Providers of models placed on the market before that date generally receive a transition until 2 August 2027. A model family may contain versions with different placement dates, so version history matters. (Regulation (EU) 2024/1689, arts. 111 and 113.)
A project that only calls a third-party model still needs supplier diligence. The Irish company should obtain model documentation, permitted-use terms, training and output restrictions, safety information, incident cooperation, and change notice. It should test whether its fine-tuning makes it a general-purpose-model provider and whether its integration or modification will create high-risk provider duties under Article 25.
High-risk systems and delayed application dates
High-risk status depends on intended purpose and product integration. Annex III covers specified uses in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice, and democratic processes. Article 6 also covers safety components of listed regulated products. (Regulation (EU) 2024/1689, art. 6, Annexes I and III.)
Regulation (EU) 2026/1744 moved Annex III application to 2 December 2027. The Article 6(1) regime for systems governed by Annex I Section A product legislation starts on 2 August 2028. Annex I Section B products remain primarily governed by their sector legislation because Article 2(2) limits the AI Act provisions that apply to them. The delayed dates do not suspend GDPR, equality, consumer, product-safety, or sector duties, and they do not excuse prohibited practices or current transparency duties. (Regulation (EU) 2024/1689, arts. 2(2), 6 and 113.)
A high-risk provider must build risk management, data controls, technical documentation, records, human oversight, accuracy, resilience, cybersecurity, quality management, registration, conformity assessment, post-market monitoring, and incident reporting. Deployers face instructions, monitoring, logs, oversight, and affected-person duties. Once the relevant high-risk rules apply, bodies governed by public law, private entities providing public services, and deployers of the Annex III creditworthiness or life-and-health-insurance systems identified in Article 27 must conduct a fundamental-rights impact assessment before first use. (Regulation (EU) 2024/1689, arts. 8-27, 43, 49, 72-73.)
The project should not use the delayed date as the engineering start date. Data provenance, logging, human oversight, and supplier evidence often require architectural changes. A system intended for recruitment, credit access, medical products, or public services should use the final duty set during development.
Irish supervision, enforcement, and remedies
The Regulation of Artificial Intelligence Act 2026 created Oifig IS na hÉireann, the AI Office of Ireland. The Office is an independent statutory body and Ireland's central coordinator. It acts as the national single point of contact and supports cooperation among sector authorities. (Regulation of Artificial Intelligence Act 2026.)
Ireland uses a distributed model with fifteen designated competent authorities. The list includes the Data Protection Commission, Competition and Consumer Protection Commission, Coimisiún na Meán, and Central Bank of Ireland. It also includes the Workplace Relations Commission, health regulators, and transport or utility regulators. (S.I. No. 366/2025; S.I. No. 405/2026.)
The AI Office does not replace each sector regulator. The relevant authority depends on the system, market, and affected right. A recruitment tool may attract the Workplace Relations Commission and Data Protection Commission. A consumer chatbot may attract the Competition and Consumer Protection Commission and the Data Protection Commission.
The 2026 Act gives market-surveillance authorities investigation, notice, restriction, seizure, sanction, complaint, and court-backed powers. EU penalty ceilings include up to EUR 35 million or seven percent of worldwide annual turnover for specified breaches. Other major breaches carry lower ceilings. (Regulation (EU) 2024/1689, arts. 99-101; Regulation of Artificial Intelligence Act 2026.)
Ireland’s statutory regulatory-sandbox programme can support supervised testing when a cohort is available. The AI Act requires Ireland to have at least one national sandbox operational by 2 August 2027. Participation does not remove civil liability, GDPR duties, intellectual-property restrictions, or sector licences. (Regulation (EU) 2024/1689, arts. 57-59 and 113; Regulation of Artificial Intelligence Act 2026.)
Personal data, web collection, and model training
GDPR will control most personal-data uses in an AI project. Except for the narrow bias-detection route in Article 4a, the AI Act does not create a legal basis for collection, training, fine-tuning, retrieval, evaluation, monitoring, or personalization. Each processing purpose needs an Article 6 basis. Special-category data require Article 9 conditions, subject to Article 4a where its strict terms are met; criminal-offence data remain subject to Article 10. (Regulation (EU) 2016/679, arts. 5, 6, 9, 10; Regulation (EU) 2024/1689, art. 4a.)
Article 4a permits providers and deployers to process special-category data only to the extent strictly necessary to detect and correct bias and only under the safeguards stated in that Article. The company still needs an Article 6 basis and must comply with purpose limitation, minimisation, security, access restriction, recordkeeping, and deletion duties. Article 4a does not authorize ordinary model training, personalization, or unrelated analytics. (Regulation (EU) 2024/1689, art. 4a; Regulation (EU) 2016/679, arts. 5, 6, 25 and 32.)
Public accessibility does not remove personal-data status. A web page, social post, public register, or image can still identify a person. The company must define purpose, necessity, retention, source limits, fairness, accuracy, transparency, and objection handling. Collection at scale raises a strong case for a data protection impact assessment. (Regulation (EU) 2016/679, arts. 5, 12-14, 21, 25, 35.)
Legitimate interests can support some development uses, but it requires a documented purpose, necessity test, and balancing test. The company should examine source expectations, sensitivity, scale, model memorisation, downstream effects, and opt-out feasibility. Consent will often fail at scale, while contract necessity rarely covers general model training.
Article 14 transparency remains the starting rule when data comes from third parties. The disproportionate-effort exception is narrow and requires protective measures, including public information. A generic privacy notice cannot cure an incompatible purpose or excessive collection. (Regulation (EU) 2016/679, art. 14(5)(b).)
EDPB Opinion 28/2024 is nonbinding, but national authorities will likely use its reasoning. It treats model anonymity as a case-specific technical and legal question. It also requires legitimate-interest analysis for model development and deployment. The project should test extraction, memorisation, singling out, and linkability before calling a model anonymous.
EDPB Guidelines 03/2026 address web scraping for generative AI. They remained in public consultation as of 24 August 2026, so they are not binding. Their controls still identify likely supervisory questions about collection limits, robots signals, access restrictions, special-category data, security, and individual rights.
Automated decisions, explanations, and children
Article 22 restricts solely automated decisions that produce legal or comparably serious effects. A score can qualify when it determines the result in practice. (Regulation (EU) 2016/679, art. 22; Case C-634/21, SCHUFA Holding (Scoring), ECLI:EU:C:2023:957.)
A claimed human review must be real. The reviewer needs authority, competence, relevant inputs, and time to depart from the model. The company should record overrides, escalation routes, reasons, and outcomes. A nominal approval click does not remove Article 22 risk.
Data subjects can seek meaningful information about the logic and consequences of relevant automated processing. The Court of Justice requires a concise and intelligible explanation of the procedure and principles applied to the person's result. Source code is not the default answer. (Case C-203/22, Dun & Bradstreet Austria, ECLI:EU:C:2025:117.)
Ireland sets sixteen as the digital-consent age for information-society services offered directly to children. Child-facing products still need fairness, age-appropriate language, minimisation, safety controls, and a lawful basis. (Data Protection Act 2018, s. 31; Regulation (EU) 2016/679, arts. 8, 12, 25.)
The company should create a decision inventory before launch. It should identify each output that ranks, excludes, prices, recommends, allocates, or escalates a person. Legal review should then test Article 22, AI Act classification, equality risk, explanation duties, and appeal routes.
International transfers and Irish lead-supervisor status
Use of non-EEA model vendors, cloud providers, support teams, or data stores can trigger GDPR Chapter V. The company needs an adequacy decision, standard clauses, binding corporate rules, or another lawful mechanism. It must assess foreign-law access and adopt supplementary measures where required. (Regulation (EU) 2016/679, arts. 44-49; Case C-311/18, Data Protection Commissioner v Facebook Ireland and Schrems, ECLI:EU:C:2020:559.)
An Irish establishment does not automatically make the Data Protection Commission the lead authority. The Irish entity must take decisions on purposes and means, and it must have power to implement those decisions. Board minutes, executive roles, system controls, and operational staff should support that position.
The one-stop-shop also has limits. Local authorities can act under GDPR procedures in defined cases. The lead authority must cooperate with concerned authorities. (Regulation (EU) 2016/679, arts. 56 and 60; Case C-645/19, Facebook Ireland, ECLI:EU:C:2021:483.)
The project should map every controller, joint controller, processor, recipient, and transfer. Contracts must match actual conduct. A central Irish privacy team without decision power will not create a defensible main establishment.
Copyright, database rights, and training material
Ireland does not give AI developers a general right to ingest protected material. Copyright, the sui generis database right, contract terms, technological controls, and personal-data law can apply to the same source. Lawful access for one purpose does not always authorize model training. (Copyright and Related Rights Act 2000, Parts II and VI.)
Ireland implemented the EU text-and-data-mining rules through S.I. No. 567/2021. Research bodies receive a scientific-research exception. Other users may mine lawfully accessible works when no appropriate rights reservation exists. Online reservations can be machine-readable. (Directive (EU) 2019/790, arts. 3-4; S.I. No. 567/2021.)
The general exception is not a complete commercial training licence. It does not remove the separate database right under Part VI of the Copyright and Related Rights Act 2000, access conditions, confidentiality, personal-data duties, or rights in later distribution. A machine-readable reservation can defeat reliance on the general exception for an online work. (Copyright and Related Rights Act 2000, ss. 320-334; S.I. No. 567/2021.)
The company should keep source-level evidence. That file should record origin, acquisition date, access basis, license, rights reservation, robots signals, database terms, personal-data class, permitted uses, retention, and deletion capability. It should also record exclusions and later rights-holder notices.
Output filters and memorisation tests reduce infringement risk but do not cure unlawful acquisition. Contracts with dataset vendors should include provenance warranties, audit rights, notice duties, deletion support, and tailored indemnities. Liability caps should reflect the vendor's access to source evidence.
AI outputs, patents, trade secrets, and personnel IP
Irish copyright law contains a specific rule for computer-generated works. The author is the person who undertook the arrangements necessary for creation. (Copyright and Related Rights Act 2000, s. 21(f).) That rule can support ownership. EU originality law still controls whether the expression receives protection.
The statutory rule does not identify the arranger in every multi-party service. The model provider, system integrator, customer, prompt author, and editor may each claim a role. Customer terms should allocate output rights, permitted use, infringement risk, confidentiality, and responsibility for human review.
An employer is generally first owner of copyright created by an employee in the course of employment, subject to contract. Contractors require express assignments when ownership matters. The company should also address moral rights, inventions, datasets, prompts, evaluation suites, and post-employment confidentiality. (Copyright and Related Rights Act 2000, s. 23.)
Irish patent law excludes mathematical methods and computer programs as such. An AI invention can still qualify when the claimed subject matter supplies a patentable technical contribution. Filing strategy should precede public disclosure. (Patents Act 1992, s. 9; European Patent Convention, art. 52.)
Model weights, training recipes, evaluation data, prompts, and deployment methods can qualify as trade secrets. They must remain secret, hold commercial value, and receive reasonable protective steps. Access controls, segmented repositories, logging, confidentiality terms, and exit procedures provide evidence. (S.I. No. 188/2018.)
Open-source models and datasets require license-by-license review. The project should check attribution, notice, copyleft, acceptable-use terms, field restrictions, model-output clauses, and data-source conditions before distribution.
Cybersecurity, cloud services, connected products, and platforms
Security duties arise before NIS2 transposition. GDPR Article 32 requires measures proportionate to risk. The AI Act adds security duties for high-risk systems and systemic-risk general-purpose models. Contracts should allocate vulnerability handling, access controls, logs, recovery, testing, and incident evidence. (Regulation (EU) 2016/679, art. 32; Regulation (EU) 2024/1689, arts. 15 and 55.)
Ireland had not enacted national NIS2 transposition by 24 August 2026; the National Cyber Security Bill remained pending. Irish implementing duties were therefore not yet in force for private entities. Cloud, managed-service, digital, health, energy, transport, and infrastructure projects should still design to Directive (EU) 2022/2555 because the implementing statute can impose short compliance and registration periods.
The Cyber Resilience Act applies to products with digital elements, including relevant software. Its vulnerability-reporting duties start on 11 September 2026, while the main product duties start on 11 December 2027. Pure hosted services require a scope review, especially when remote processing is integral to a product. (Regulation (EU) 2024/2847, art. 71.)
The Data Act has applied since 12 September 2025, subject to its transition rules. It can affect connected products, related services, contractual data access, unfair business terms, and cloud-switching obligations. Ireland’s national Data Bill remained pending as of 24 August 2026, so the directly applicable EU duties operate before the final allocation of all Irish enforcement functions. (Regulation (EU) 2023/2854.)
The Digital Services Act applies only when the service performs an intermediary function. Hosting user content, operating an online platform, or providing an online search function can trigger it. A standalone AI tool is not automatically an intermediary. (Regulation (EU) 2022/2065; Digital Services Act 2024.)
Cookies, software identifiers, and electronic direct marketing also require review. Irish ePrivacy rules require consent for non-essential terminal access and regulate unsolicited electronic communications. (S.I. No. 336/2011.)
Consumer duties, product liability, and civil claims
Consumer-facing AI services must meet the Consumer Rights Act 2022. Digital content and digital services require conformity, updates, remedies, and fair terms. Capability limits, model changes, service dependencies, and material restrictions should appear before purchase. (Consumer Rights Act 2022.)
The Consumer Protection Act 2007 prohibits misleading acts, misleading omissions, and aggressive practices. Claims about accuracy, safety, autonomy, bias, legal validity, or professional substitution need evidence. Disclaimers placed after a strong marketing claim may not correct the initial impression. (Consumer Protection Act 2007.)
The Equal Status Acts prohibit direct and indirect discrimination in the disposal of goods and provision of services. AI rules for eligibility, pricing, ranking, identity verification, or service access can breach those Acts when protected grounds or proxy variables change treatment without a lawful justification. The provider should test outcomes across protected groups and preserve the reasons for material decision rules. (Equal Status Act 2000, ss. 3 and 5, as amended.)
The European Union (Accessibility Requirements of Products and Services) Regulations 2023 apply from 28 June 2025 to covered products and services, including e-commerce services. A consumer AI service supplied online to conclude a consumer contract may fall within that category. Service-providing microenterprises are exempt, but other providers should document accessibility, any applicable exemption, and any disproportionate-burden assessment. (S.I. No. 636/2023.)
The Liability for Defective Products Act 1991 remained the Irish strict-liability statute as of 24 August 2026. Directive (EU) 2024/2853 expressly covers software and treats AI system providers as manufacturers. Ireland must transpose it by 9 December 2026, but had not enacted the required transposition as of 24 August 2026.
The new Directive will apply to products placed on the market or put into service after its application date. It expands software treatment and evidence rules. A late-2026 launch should preserve development records, safety cases, version histories, incident data, warnings, and corrections. (Directive (EU) 2024/2853.)
The General Product Safety Regulation can apply when AI forms part of a consumer product or its safety function. Sector product law can also control medical devices, machinery, toys, vehicles, or radio equipment. (Regulation (EU) 2023/988.)
Contract and negligence claims remain available where their elements are met. Consumer terms cannot remove mandatory rights. The Representative Actions Act 2023 also permits qualified entities to seek collective consumer relief. Insurance should address technology errors, cyber events, IP claims, product exposure, and regulatory investigations.
Employment, equality, and worker monitoring
AI used for recruitment, work allocation, promotion, performance, discipline, or termination can fall within Annex III. Those high-risk duties start on 2 December 2027. GDPR and Irish equality law apply now. (Regulation (EU) 2024/1689, Annex III; Employment Equality Act 1998.)
The Employment Equality Act 1998 prohibits discrimination across protected grounds. A neutral model can create indirect discrimination through proxy variables, training imbalance, labels, or deployment thresholds. The employer should test group outcomes, investigate disparities, and record job-related reasons for each decision rule.
Workplace emotion recognition is prohibited, subject to narrow medical or safety exceptions. General productivity or conduct monitoring will not fit those exceptions. (Regulation (EU) 2024/1689, art. 5.)
Employee notices should explain monitoring, data sources, decision use, retention, recipients, and challenge routes. Worker consultation or representation duties may also arise from the employment setting. A reviewer must have power to change the result.
A labour platform may also fall under Directive (EU) 2024/2831 on platform work and algorithmic management. The transposition deadline is 2 December 2026. A platform launch should check Irish implementing measures again at closing.
Corporate form, tax, investment screening, and export controls
An Irish private company limited by shares is the usual operating vehicle. It can have one director, but a sole director cannot also serve as company secretary. The company normally needs an EEA-resident director or the statutory bond or real-link route. (Companies Act 2014, ss. 128, 129, 137, 140.)
Directors owe statutory duties to the company. AI risk acceptance, data acquisition, major model releases, insurance, and regulatory incidents should enter board reporting when material. (Companies Act 2014, s. 228.) Irish substance should match the claimed location of management and intellectual-property activity.
Ireland taxes trading income at 12.5 percent and other income at 25 percent. Pillar Two can impose a fifteen-percent minimum rate on in-scope groups. The consolidated-revenue threshold is EUR 750 million. Transfer pricing and permanent-establishment rules can change the result. (Taxes Consolidation Act 1997, s. 21 and Part 4A.)
Finance Act 2025 raised the research and development corporation tax credit to thirty-five percent. The Knowledge Development Box can produce a ten-percent effective rate on qualifying profits, but the present extension covers accounting periods commencing before 1 January 2027. Eligibility depends on qualifying work, records, nexus, ownership, and the operative rules for the accounting period. (Taxes Consolidation Act 1997, ss. 766C-766D and 769G-769R; Finance Act 2025.)
The Screening of Third Country Transactions Act 2023 can require pre-closing notification. The test covers prescribed control or voting thresholds, a transaction value of at least EUR 2 million, and an Irish target active in a sensitive field. Artificial intelligence is a listed critical technology under Regulation (EU) 2019/452. (Screening of Third Country Transactions Act 2023, s. 9.)
The transaction should be screened before a non-EU financing, acquisition, or strategic investment. Standstill duties and review timelines can affect closing. The analysis must cover direct and indirect investors, control rights, asset location, sensitive activity, and internal restructurings.
Most general AI software is not a controlled dual-use item. Advanced computing, encryption, cyber-surveillance, military functions, listed technology, destination sanctions, and end use can change that result. The company should classify exports and technical assistance under Regulation (EU) 2021/821 and the Control of Exports Act 2023.
Contracts, governing law, and dispute resolution
Customer and supplier contracts should implement the regulatory allocation. They should identify each AI Act role, controller or processor status, training rights, model rights, output use, human oversight, security duties, incident notices, audit evidence, and change control. Service descriptions should state material limits and dependencies.
Supplier terms should address model withdrawal, version replacement, safety restrictions, price changes, location changes, subprocessors, training on customer data, and regulator cooperation. A customer should receive enough evidence to meet its own deployer duties. A supplier should control uses that would create prohibited or high-risk exposure.
Indemnities and liability caps should follow control of the risk. Training-data provenance, confidentiality, personal-data breaches, product injury, and prohibited-use claims may need separate caps or exclusions. Mandatory consumer and product rights cannot be contracted away.
Irish governing law is generally available for business contracts under Rome I. Mandatory consumer, employment, data, competition, product, and public-law rules can still apply. Jurisdiction clauses operate subject to Brussels I Recast protections. (Regulation (EC) 593/2008; Regulation (EU) 1215/2012.)
The Arbitration Act 2010 supports commercial arbitration through the UNCITRAL Model Law. The 2026 amendment concerns defined intra-EU investment awards. It does not displace ordinary commercial arbitration. Court relief, evidence needs, confidentiality, cost, and enforceability should determine the clause. (Arbitration Act 2010; Arbitration (Amendment) Act 2026.)
Qualifying technology disputes can enter the Irish Commercial Court list, subject to judicial control and procedural requirements. The company should preserve model versions, prompts, logs, evaluations, notices, approvals, and source records. Those materials will often decide causation and reasonableness.
Sector-specific gates
Creditworthiness, insurance risk, fraud, and customer treatment can trigger Annex III, GDPR Article 22, consumer rules, and sector duties. DORA has applied since 17 January 2025 to covered financial entities and ICT arrangements. (Regulation (EU) 2022/2554.)
Health products need medical-device classification before marketing. Software that serves a medical purpose can fall under the Medical Devices Regulation or In Vitro Diagnostic Medical Devices Regulation. The Health Products Regulatory Authority then joins the AI and privacy analysis. (Regulation (EU) 2017/745; Regulation (EU) 2017/746.)
Public bodies and private entities providing public services can face procurement, transparency, fundamental-rights, records, accessibility, and sector duties. Article 27 also covers deployers of specified creditworthiness and life-and-health-insurance systems. The fundamental-rights impact assessment duty applies when the corresponding high-risk provisions take effect. (Regulation (EU) 2024/1689, art. 27.)
Biometric, child-facing, education, migration, law-enforcement, and justice uses can be prohibited or classified as high-risk. Lawful bases and necessity tests are narrow.
Media, hosting, marketplace, and search functions need Digital Services Act and online-safety analysis. Connected hardware needs product-safety, Cyber Resilience Act, recall, and conformity work. No single Irish jurisdiction opinion can resolve those sector gates without the product facts.
A project that intends to build or directly operate large computing infrastructure must also address Irish planning, grid-connection, energy, and environmental requirements. This memorandum does not cover an Irish data centre or guaranteed power capacity.
SWITZERLAND
Summary
- No general Swiss AI statute is in force. The Federal Act on Data Protection, contract law, employment law, intellectual-property statutes, competition law, product rules, and sector legislation apply according to the system’s function. The Confederation expects to open consultation on legislation implementing the Council of Europe Framework Convention on Artificial Intelligence by the end of 2026.
- The Federal Act on Data Protection applies directly to AI processing. A launch may require data inventories, notices, processor terms, transfer safeguards, security controls, processing records, an impact assessment, breach procedures, and human review of automated individual decisions. Federal Act on Data Protection, SR 235.1, arts. 3, 6 to 9, 12, 16 to 25.
- An Aktiengesellschaft requires CHF 100,000 share capital, with at least 20 per cent and CHF 50,000 paid in. A Gesellschaft mit beschränkter Haftung requires CHF 20,000 fully paid. Each form needs Swiss-resident representation. A new federal beneficial-owner register takes effect on 1 October 2026.
- Swiss copyright protects human intellectual creation. A routine autonomous output may have no copyright owner, while training and output generation can still infringe copyrights, contractual restrictions, trade secrets, marks, or personality rights. Federal Act on Copyright and Related Rights, SR 231.1, arts. 2, 6, 10, 17 and 24d.
- AI does not displace contract, tort, unfair-competition, personality, product-safety, or competition liability. Contract terms may allocate operational risk, but Article 100 of the Code of Obligations invalidates advance exclusions for unlawful intent or gross negligence.
- Hiring tools, workforce scoring, and employee monitoring require close review. Code of Obligations art. 328b limits employee-data processing, and Article 26 of Ordinance 3 to the Employment Act prohibits systems intended to monitor employee behaviour.
- A Swiss entity does not avoid EU law. The EU AI Act can apply when a Swiss provider places a system or general-purpose AI model on the EU market, or when output from a Swiss system is used in the EU. The GDPR may apply through its establishment, offering, or monitoring tests.
- The project should not proceed where it depends on unlicensed mass ingestion, autonomous employment or credit decisions, biometric identification or categorisation, medical claims, regulated financial activity, physical safety control, or critical-infrastructure deployment. Those uses must satisfy the applicable requirements before launch or operational commitment.
Present AI law and legislative direction
Switzerland had no general AI statute in force on 24 August 2026. Existing federal and cantonal rules govern the activity performed by the AI system. The operative law may concern personal data, employment, medical devices, financial services, products, competition, communications, public procurement, or criminal conduct. Incorporating an AI company does not create a separate regulatory category or exemption.
Switzerland signed the Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law on 27 March 2025. The Confederation is preparing legislation for consultation by the end of 2026. That work may add duties concerning transparency, discrimination, human rights, and supervision. It does not yet constitute an enforceable private-company AI code.
Product function determines the present burden. A bounded software tool that assists trained business users presents a lower Swiss legal risk than a system that ranks people, determines access to work or services, monitors conduct, diagnoses disease, prices financial products, or controls machinery. The project should fix the intended purpose, prohibited uses, affected persons, material failure modes, and human authority before choosing data or models.
Entity, ownership, tax, immigration, and disputes
An Aktiengesellschaft, or AG, normally fits an externally financed technology venture. Its minimum share capital is CHF 100,000. At least 20 per cent of each share must be paid, subject to an aggregate minimum of CHF 50,000. One shareholder may form the company. At least one person domiciled in Switzerland must hold authority to represent it. Code of Obligations, SR 220, arts. 621, 625, 632 and 718(4).
A Gesellschaft mit beschränkter Haftung, or GmbH, requires CHF 20,000 fully paid capital. Its members appear in the commercial register, and transfers of membership interests carry more formality than ordinary transfers of AG shares. A Swiss-domiciled manager or director must hold representation authority. Code of Obligations arts. 773, 775, 777c, 785 and 814(3). An AG usually accommodates institutional equity, employee participation, and later share transfers more readily, although financing documents remain transaction-specific.
The Federal Act on the Transparency of Legal Persons and the Identification of Beneficial Owners enters into force on 1 October 2026. It creates a central federal register and imposes beneficial-owner identification and updating duties on covered legal entities. A company incorporated before or after that date should maintain verified ownership records, investor notices, change-reporting procedures, and responsibility for register filings. Transitional periods begin on the commencement date.
Federal direct tax on corporate net profit is 8.5 per cent. Cantonal and communal profit taxes produce the larger location difference, and cantons impose capital tax under their own rules. A canton decision should use expected payroll, taxable profit, capital, office substance, intellectual-property ownership, and founder residence. Direct Federal Tax Act, SR 642.11, art. 68.
Swiss VAT registration generally becomes mandatory when qualifying worldwide turnover reaches CHF 100,000, subject to the statutory exclusions and place-of-supply rules. The standard VAT rate is 8.1 per cent. Dividends generally attract 35 per cent Swiss withholding tax, with refund or treaty relief available when the applicable conditions are met. Customer location, service classification, investor domicile, and beneficial ownership therefore affect the tax structure.
Ownership of a Swiss company does not itself grant a right to work or reside in Switzerland. EU and EFTA nationals operate under the applicable free-movement rules. Third-country founders and employees face quotas, qualification requirements, labour-market tests, and cantonal approval unless a separate entitlement applies. The project should settle founder and key-hire permits before fixing the operating canton.
Swiss law and forum clauses are generally available for commercial contracts, subject to mandatory rules and applicable treaties. The Federal Act on Private International Law governs choice of law and Swiss-seated international arbitration. The Lugano Convention may control jurisdiction and judgment enforcement between Switzerland and covered European states. Consumer, employment, competition, product, and data rules can restrict party choice.
Personal data, model inputs, and automated decisions
The Federal Act on Data Protection protects natural persons whose personal data are processed. It applies to circumstances producing effects in Switzerland, even when the conduct begins abroad. Federal Act on Data Protection arts. 2, 3 and 5. A Swiss AI company may act as controller for account data, telemetry, model improvement, security, support, or analytics. It may act as processor when it handles customer data solely on documented customer instructions.
Swiss private-sector data law does not reproduce the GDPR requirement to select an Article 6 lawful basis for every processing operation. The controller must comply with the processing principles in Article 6 and avoid unlawful personality infringements under Article 30. Consent, an overriding private or public interest, or a statutory basis may justify an infringement under Article 31. Sensitive data, high-risk profiling, vulnerable persons, secrecy duties, and unequal bargaining power restrict the available justification.
The company should document each purpose, data category, source, affected group, recipient, retention period, country transfer, and model use. Article 7 requires data protection by design and by default. Article 8 requires security proportionate to the risk. Article 9 governs processor appointments. Article 12 requires records of processing activities, subject to the statutory and ordinance-level exemptions. Article 19 generally requires a collection notice identifying the controller, purposes, recipients, and foreign disclosures.
Using customer prompts, uploaded files, or support material for model improvement should be treated as a separate purpose. The contract and privacy notice should state whether that use occurs, which data enter training or evaluation, how long they remain, and how a customer can prevent reuse where the service offers that option. Segregation between tenants, access restrictions, deletion controls, and subprocessor disclosure should match the documented use.
Articles 16 and 17 govern foreign disclosures. Transfers to a state without recognised adequacy generally need an approved safeguard, binding corporate rules, another statutory guarantee, or a narrow exception. The exporter must assess whether the recipient can comply with the safeguard and may need encryption, access restrictions, or split processing. The FADP does not impose a blanket private-sector localisation rule. Sector secrecy and regulated-customer duties may still restrict hosting locations.
Article 21 applies when a controller makes a decision based solely on automated processing that has legal consequences for the individual or significantly affects that person. The controller must notify the individual, who may generally request human review and state a position. Article 25 supports access to available information concerning the logic behind an automated individual decision. A reviewer must have competence, access to the relevant record, and authority to change the outcome.
Article 22 requires a data protection impact assessment when planned processing is likely to create a high risk to personality or fundamental rights. Large-scale sensitive-data processing and high-risk profiling are statutory indicators. Novel technology, surveillance, vulnerable groups, and consequential decisions can reinforce the risk assessment. Article 23 requires consultation with the Federal Data Protection and Information Commissioner when planned measures leave a high residual risk, subject to the statutory adviser route.
Article 24 requires the controller to notify the Commissioner as soon as possible when a data-security breach is likely to create a high risk. Processor agreements should require immediate escalation and cooperation. The incident plan should cover prompt leakage, model extraction, credential compromise, training-data exposure, corrupted outputs, unauthorised tool use, and cross-tenant disclosure.
Intentional offences under the FADP primarily expose responsible individuals to criminal fines of up to CHF 250,000. The Commissioner may investigate and order processing changes, suspension, deletion, or other corrective action. Data subjects may also pursue private-law remedies. Named responsibility, written approvals, staff training, and retained decision records reduce the risk of personal exposure.
The European Commission recognises Switzerland as providing adequate protection for transfers under the GDPR. EU personal data may therefore move to Switzerland without a separate Chapter V transfer instrument solely because of the Swiss destination. Adequacy does not remove the GDPR duties of an EU-facing controller or processor, and it does not cover onward transfers from Switzerland to a non-adequate destination.
Training data, intellectual property, and generated output
Swiss copyright protects literary and artistic intellectual creations with individual character. The author is the natural person who created the work. Federal Act on Copyright and Related Rights arts. 2 and 6. A routine autonomous output may therefore lack Swiss copyright protection. Human selection, revision, arrangement, or direction may attract protection where the resulting expression contains the individual character of the human contribution.
Training can involve reproductions reserved to the copyright owner under Article 10. Article 24d permits technically necessary reproductions for scientific research when its conditions are met. Its text does not create a general commercial AI-training exemption. A commercial training programme should obtain a source-specific assessment before relying on Article 24d, particularly where the venture collects expressive works at scale or retains reusable copies.
The project should separate public-domain material, licensed material, customer data, open-source code, synthetic data, personal data, and material obtained under access terms. Each source record should identify acquisition date, licence, permitted purposes, territorial limits, attribution duties, opt-outs, retention, transformations, and deletion routes. Website accessibility alone does not establish permission to reproduce or use content for commercial training.
An output can infringe copyright even when the output itself lacks protection. It can also infringe a trade mark, reveal confidential information, violate a person’s image or voice rights, or breach a model provider’s licence. Release review should test memorisation, substantial similarity, attribution, confidential content, living-person references, branded material, and open-source obligations.
Article 17 grants an employer exclusive rights to use a computer program created by an employee within the employee’s duties. It does not establish the same automatic allocation for every other copyright work. Employment and contractor agreements should assign economic rights in documentation, data sets, evaluations, prompts, interfaces, model modifications, and other project material. Contractor assignments require particular care.
Employee inventions are governed by Article 332 of the Code of Obligations. Patent applications must identify the human inventor. Contribution records should separate human conception from machine assistance and preserve dated evidence. Confidentiality clauses, access controls, repository restrictions, and exit procedures should protect non-public model weights, evaluations, methods, customer data, and commercial know-how.
Contracts, claims, competition, and product responsibility
A Swiss AI company remains responsible for contractual non-performance under Article 97 of the Code of Obligations. Article 101 addresses responsibility for auxiliaries, including subcontractors used to perform obligations. Article 41 governs unlawful damage caused to another person. A supplier agreement may allocate loss between contracting parties, but it does not bind an injured third party.
Article 100 invalidates an advance exclusion of liability for unlawful intent or gross negligence. Mandatory product, consumer, employment, personality, and competition rules may also override contract language. A disclaimer cannot cure a false performance statement, an undisclosed safety limit, or a service marketed for a purpose that the company has not tested.
The Federal Act against Unfair Competition prohibits deceptive commercial conduct and misleading statements about a business, product, price, or performance. Accuracy claims, benchmark claims, demonstrations, customer testimonials, and statements about human review should match retained evidence. Civil Code arts. 28 and 28a protect personality interests, including identity, image, voice, honour, and private life. Synthetic media may create exposure without copying a protected work.
The Cartel Act applies to algorithmic pricing and coordination. An AI system cannot lawfully implement an agreement among competitors, transmit protected pricing intentions, or facilitate prohibited market coordination. A dominant undertaking must avoid abusive conduct under Article 7. Marketplace and recommendation products should document data separation, pricing inputs, access conditions, and any communications among competing users.
The Product Liability Act imposes producer liability when a defective product causes death, personal injury, or qualifying property damage. Its statutory definition of a product centres on movable property and electricity. The application of the current Act to standalone software remains legally uncertain. Exposure is stronger when AI forms part of machinery, a medical device, a vehicle, a consumer product, or another physical item.
The Product Safety Act and sector legislation may impose design, instruction, conformity, monitoring, recall, and reporting duties on AI-enabled products. Intended purpose, integration, foreseeable misuse, update control, user competence, and safety functions determine the result. Describing a system as software does not remove product duties where the system controls a covered product.
Customer terms should define the service, intended users, permitted inputs, prohibited uses, model-improvement rights, output treatment, human review, security responsibilities, incidents, service changes, audit rights, suspension, termination, and data return. Warranties should track documented testing. Liability caps should reflect the product’s actual loss profile. Insurance review should cover technology errors, cyber events, privacy claims, media liability, intellectual-property defence, bodily injury, and regulated services.
Employment, hiring, and workplace AI
An employer may process employee data only when the data concern suitability for employment or are necessary for performance of the employment contract. Code of Obligations art. 328b. Broad productivity scoring, sentiment analysis, inferred health status, or reuse of internal communications requires a documented necessity and proportionality assessment.
Article 26 of Ordinance 3 to the Employment Act prohibits monitoring and control systems intended to monitor employee behaviour at work. A system used for another legitimate purpose must protect employee health and freedom of movement. Security logging, fraud detection, or quality controls therefore need a stated operational purpose, limited configuration, notice, restricted access, and proportionate retention. A covert behavioural-scoring feature presents a high legal risk regardless of its product label.
Hiring, promotion, discipline, scheduling, and termination systems can trigger Article 21 of the FADP when they make solely automated individual decisions. A nominal human step does not provide effective review when the reviewer lacks time, evidence, competence, or authority to depart from the output. The company should preserve the input data, output, reasons available, reviewer decision, correction route, and final result.
The Gender Equality Act prohibits sex discrimination in employment. Data-protection principles and personality rights also restrict discriminatory or irrelevant processing. Before deployment, the employer should test job relevance, error rates, subgroup effects, accessibility, data quality, and reviewer consistency. Candidate and employee notices should identify the data sources, purposes, recipients, retention period, and decision role.
Regulated products and services
A sector licence depends on the activity performed, not the company’s description of itself as a software supplier. Finance, insurance, medicine, transport, telecommunications, public administration, and critical infrastructure each require separate qualification. A customer’s licence does not automatically cover the technology provider.
Financial products may engage the Banking Act, Financial Institutions Act, Financial Services Act, Collective Investment Schemes Act, Anti-Money Laundering Act, or Insurance Supervision Act. A pure software supplier may avoid direct licensing when it does not perform the regulated service. Outsourcing, secrecy, operational-risk, audit, continuity, and supervisory-access duties may still pass through the customer contract.
FINMA Guidance 08/2024 identifies model correctness, explainability, bias, data quality, cyber risk, third-party dependency, and legal risk as supervisory concerns. FINMA states that its guidance is not itself a supervisory instrument and has no independent legal effect. Regulated customers will still expect model inventories, validation evidence, access controls, incident reporting, subcontractor disclosure, continuity plans, and exit support.
Software with an intended medical purpose may qualify as a medical device. The manufacturer’s stated intended purpose controls the initial classification. Medical software can require conformity assessment, technical documentation, clinical evidence, quality controls, registration, vigilance, and post-market surveillance. Swissmedic supervises the market; medical devices do not pass through a medicinal-product-style pre-market authorisation.
Registration of devices, systems, and procedure packs in swissdamed became mandatory on 1 July 2026, with a transition period through 31 December 2026. An AI product intended for diagnosis, prevention, monitoring, prediction, prognosis, or treatment should not launch under a general software opinion.
AI used in medicinal-product development must support complete, traceable, scientifically current documentation. Swissmedic identifies data quality, model transparency, quality control, and bias as review concerns. A research designation does not remove clinical-trial, medicinal-product, data, or ethics requirements when the activity falls within those statutes.
Public-sector sales may engage procurement law, public-law data duties, accessibility, records management, constitutional protections, and security requirements. Transport or physical-control systems may engage technical product and safety rules. Each deployment should receive a sector screen before customer trials or binding commitments.
Cybersecurity, export controls, sanctions, and investment review
Article 8 of the FADP requires risk-proportionate security. The security design should address privileged access, model and data extraction, prompt injection, data poisoning, dependency integrity, secrets, tenant isolation, tool permissions, update signing, logging, recovery, and incident evidence. Contractual or sector duties may require more than the FADP baseline.
Covered operators of critical infrastructure must report qualifying cyberattacks to the National Cyber Security Centre within 24 hours of discovery. They have 14 days to complete an initially incomplete report. The duty took effect on 1 April 2025, and the fine provisions took effect on 1 October 2025. The duty applies to defined operators, not every AI company.
Swiss export controls can cover goods, technology, and software listed under the Goods Control Ordinance. Catch-all controls can also require a licence. Ordinary AI software is not controlled solely because it uses AI. Advanced cryptography, intrusion functions, surveillance capabilities, military applications, source-code transfers, technical assistance, and specified end uses require classification before export or remote access.
Sanctions screening should address the contracting party, beneficial owners, control, destination, end user, payment route, and intended use. SECO’s search tool displays directly listed persons and entities but does not determine ownership or control relationships. A name-only screen is therefore insufficient.
Parliament adopted the Investment Screening Act on 19 December 2025. It is expected to enter into force in 2027. The Act targets certain acquisitions of Swiss companies in especially sensitive sectors by foreign state-controlled investors. A company serving security-sensitive infrastructure should review the regime before accepting a qualifying investor or negotiating an exit.
EU reach from a Swiss base
Switzerland is outside the EU and EEA. A Swiss incorporation does not create general access to the EU internal market or displace EU rules. The Switzerland-EU mutual-recognition agreement assists only the covered product sectors and conformity procedures. It is not a general passport for AI software.
Article 2 of Regulation (EU) 2024/1689 reaches providers that place AI systems or general-purpose AI models on the EU market. It also reaches third-country providers and deployers when the output produced by the AI system is used in the EU. Server location, Swiss governing law, and a Swiss contracting entity do not defeat that territorial rule.
The AI Act became broadly applicable on 2 August 2026. Prohibited-practice and AI-literacy duties applied from 2 February 2025. General-purpose AI obligations applied from 2 August 2025. Regulation (EU) 2026/1744 moved Annex III high-risk duties to 2 December 2027 and Annex I product-system duties to 2 August 2028. The transparency duties for covered interactive and synthetic-content systems apply from 2 August 2026, subject to the specific statutory conditions.
EU analysis must identify the provider, deployer, importer, distributor, product manufacturer, authorised representative, and general-purpose model provider. A company may acquire provider duties if it places its name on a system, changes the intended purpose, or makes a substantial modification. Contract labels do not override the operational facts.
A Swiss company should screen every EU-facing use against Article 5 prohibitions, Article 50 transparency duties, general-purpose AI obligations, and the future high-risk classifications. Employment, education, access to essential services, biometrics, migration, and certain critical-infrastructure uses can enter Annex III. Product-integrated systems may enter Annex I.
The GDPR applies to a Swiss controller or processor when Article 3 is satisfied. The main third-country triggers are an EU establishment, offering goods or services to people in the EU, or monitoring their behaviour there. The GDPR can require a lawful basis, special-category conditions, notices, data-subject rights, processor terms, security, impact assessments, breach reporting, and an EU representative.
Swiss adequacy simplifies EU-to-Switzerland transfers. It does not exempt a Swiss company from the GDPR where Article 3 applies. It also does not validate an onward transfer to a non-adequate model provider, cloud region, or support location.
EU Member States must transpose Directive (EU) 2024/2853 by 9 December 2026. The Directive treats software as a product and addresses AI-related product defects. It applies to products placed on the market or put into service from 9 December 2026. A Swiss supplier entering EU product markets should prepare for that liability regime even where the current Swiss Product Liability Act remains uncertain for standalone software.
THE UNITED ARAB EMIRATES
Summary
- There is no generally applicable federal statute dedicated to private-sector AI. The project instead falls under company, licensing, data-protection, cybercrime, digital-trade, consumer, intellectual-property, civil-liability, competition, tax, and sector laws. The UAE Charter for the Development and Use of Artificial Intelligence and the National Cyber Security Policy for Artificial Intelligence state national expectations, but neither instrument supplies a general private enforcement code. (UAE Charter for the Development and Use of Artificial Intelligence, issued 10 June 2024; National Cyber Security Policy for Artificial Intelligence, updated 2 July 2026.)
- ADGM is the strongest default candidate for an internationally funded B2B AI company under the stated assumptions. It applies English common law directly, offers English-language courts, and has no separate autonomous-systems certification regime comparable to DIFC Regulation 10. That recommendation remains conditional on activity pre-clearance, office and substance requirements, customer location, tax treatment, and the absence of regulated financial activity. DIFC is preferable when Dubai financial institutions are central to the business. A mainland company is preferable when UAE consumer sales, government work, or locally regulated services are material. (Federal Law No. 8 of 2004 on Financial Free Zones; ADGM Application of English Law Regulations 2015.)
- Federal Decree-Law No. 45 of 2021 governs most mainland private-sector personal-data processing and specified offshore processing involving people in the UAE. It requires a lawful basis, security, processor control, breach procedures, data-subject rights, impact assessment for high-risk processing, and lawful international transfers. Article 18 grants a right to object to certain decisions produced by automated processing. The project should not treat customer instructions as authority for its separate analytics or model-improvement purposes. (Federal Decree-Law No. 45 of 2021, arts. 2, 4, 9-10, 18, 21-23.)
- Regulation 10 of the DIFC Data Protection Regulations creates detailed binding AI duties. It allocates duties among Providers, Deployers, and Operators of autonomous or semi-autonomous systems that process personal data. Commercial high-risk processing requires the applicable audit and certification route, human-defined or human-approved purposes, and an Autonomous Systems Officer. The DIFC Commissioner has published an Accreditation and Certification Framework, so a high-risk project must confirm the current certification path before deployment. (DIFC Data Protection Law No. 5 of 2020, arts. 22 and 38; DIFC Data Protection Regulations, regs. 10.1-10.3.)
- ADGM Data Protection Regulations 2021, as amended, impose lawful-processing, transparency, security, impact-assessment, transfer, breach, and automated-decision duties. Section 31 contains a narrow retention rule for data already used to lawfully train or refine an AI system. It does not authorize collection or training. There is no separate ADGM instrument equivalent to DIFC Regulation 10. (ADGM Data Protection Regulations 2021, ss. 20, 31-35 and Part V.)
- Federal cybercrime law can attach criminal exposure to unauthorized system access, privacy invasion, impersonation, deceptive online advertising, and specified unlawful content. A covered social-media platform must comply with the Child Digital Safety Law and Cabinet Resolution No. 106 of 2026. Children under 15 may not create or use a personal account on a covered platform. Age-assurance, child-risk, design, advertising, and reporting duties also apply. An enterprise AI service without social profiles or interaction features may fall outside that resolution, but the general child-safety, data, content, and consumer laws still apply. (Federal Decree-Law No. 34 of 2021; Federal Decree-Law No. 26 of 2025; Cabinet Resolution No. 106 of 2026.)
- UAE copyright law protects software, applications, and databases, but it does not designate an AI system as an author. There is no express general text-and-data-mining exception. The company therefore needs documented rights for training sources, employee and contractor assignments, open-source and model-licence controls, and trade-secret protection for weights and methods. Customer terms must allocate input rights, output rights, model-improvement uses, security, human review, regulated-use limits, and liability. (Federal Decree-Law No. 38 of 2021, arts. 1-2 and 22; Federal Law No. 11 of 2021.)
- The standard corporate tax rate is 9 percent above the statutory taxable-income threshold. A free-zone 0 percent rate applies only to a Qualifying Free Zone Person and its Qualifying Income. The R&D tax credit may support genuine UAE research expenditure, subject to its statutory conditions. Incorporation should follow completion of an activity matrix, use-case register, data map, training-data ledger, security plan, tax model, and contract suite. (Federal Decree-Law No. 47 of 2022; Cabinet Resolution No. 215 of 2025.)
Applicable law and regulatory perimeter
Private AI activity in the UAE is governed through several laws rather than one general AI code. There is no federal statute regulating every private AI provider or deployer as of 24 August 2026. The UAE Charter for the Development and Use of Artificial Intelligence states principles on safety, fairness, privacy, transparency, human control, and accountability. Minimum security expectations for AI adoption appear in the National Cyber Security Policy for Artificial Intelligence. Each is an official policy instrument. Neither replaces a statute, sector licence, or binding data rule. (UAE Charter for the Development and Use of Artificial Intelligence, issued 10 June 2024; National Cyber Security Policy for Artificial Intelligence, updated 2 July 2026.)
On 14 June 2026, the Cabinet approved the establishment of the Artificial Intelligence and Data Authority. The official announcement assigns it national functions concerning AI, data, and digital government and states that functions of the UAE Data Office will transfer to it. The establishing instrument and final transition provisions had not been issued as of 24 August 2026. A company should therefore confirm the competent authority and filing channel before submitting a notification, complaint response, or approval request. (UAE Cabinet, "Mohammed bin Rashid approves establishing Artificial Intelligence and Data Authority," 14 June 2026.)
Legal classification turns on the actual function, not the marketing label. A model may simultaneously perform commercial activity, personal-data processing, content generation, advertising, automated decision-making, or a regulated sector function. Each production use case should identify the user, affected person, decision, data, autonomy level, sector, legal consequence, and human review. That record determines which licence and legal duties apply.
Cabinet Resolution No. 14 of 2019 permits temporary licences for qualifying innovative future projects. The competent authority controls the approved activity, period, conditions, and test limits. A temporary licence does not disapply federal criminal law, data law, intellectual-property rights, or sector rules outside the approved terms. A pilot should proceed only after written confirmation of the authority, scope, data use, customer group, and exit obligations. (Cabinet Resolution No. 14 of 2019 Organizing the Issuance of Temporary Licenses for Innovative Future Projects.)
Entity and licence selection
A UAE entity must hold a licence that matches the activities it conducts. Software development, IT consultancy, data analytics, cloud services, platform operation, electronic commerce, and regulated advice may sit under different activity descriptions. External approval may apply even when the registrar accepts the company activity. The incorporation file should contain a written activity matrix covering development, hosting, licensing, support, data processing, platform functions, payments, advertising, and each sector use.
A mainland limited liability company is generally available with full foreign ownership. Activities designated as having strategic impact remain subject to separate ownership or approval rules. Cabinet Resolution No. 55 of 2021 identifies strategic activities that include security and defence, banking, exchange, finance, insurance, telecommunications, and other listed fields. A general software company may fall outside that list, while a product designed for one of those fields can require sector approval. (Federal Decree-Law No. 32 of 2021 on Commercial Companies, as amended; Cabinet Resolution No. 55 of 2021.)
Federal Decree-Law No. 20 of 2025 expanded routes for free-zone and financial-free-zone companies to establish branches or representative offices in the UAE. The amendment does not make a free-zone licence valid throughout the mainland. The branch or office still needs the licence, premises, registrations, and sector approvals required by the competent emirate or federal authority. A representative office also cannot be used to conduct revenue activity beyond its approved purpose. (Federal Decree-Law No. 20 of 2025 amending Federal Decree-Law No. 32 of 2021.)
DIFC and ADGM are financial free zones with separate civil and commercial laws, registrars, data-protection authorities, and courts. Federal criminal law continues to apply. Federal tax, sanctions, immigration, and applicable sector rules also remain relevant. ADGM directly applies English common law and equity, subject to ADGM enactments. DIFC applies its own statutes and common-law court system. Incorporation in either centre does not authorize regulated financial services unless the relevant financial regulator grants permission. (Federal Law No. 8 of 2004 on Financial Free Zones; ADGM Application of English Law Regulations 2015.)
Under the stated assumptions, ADGM is the strongest starting candidate for the international B2B company. Its direct application of English common law supports familiar investment and commercial documentation. Its data law controls automated decisions and AI training datasets without a separate provider-deployer-operator certification regime. The recommendation depends on the Registration Authority approving the activity and on the project accepting ADGM office, substance, employment, and cost requirements.
DIFC becomes the stronger choice when the core customer base consists of Dubai banks, insurers, asset managers, or professional-services firms. Its commercial setting can outweigh the additional duties under Data Protection Regulation 10. A company that develops or deploys high-risk autonomous processing in DIFC must budget for certification, an Autonomous Systems Officer, system records, human controls, and regulator engagement before launch.
A mainland company is usually the better initial vehicle when the business expects substantial direct consumer revenue, government contracts, regulated local services, or a broad UAE operating footprint. A standard commercial free zone may offer lower establishment costs. Mainland market access, customer contracting, permanent establishment, tax qualification, and data location must still be addressed. No free-zone label answers those questions by itself.
A group can later use a financial-free-zone parent with a mainland branch or subsidiary. That structure should follow actual customer, hiring, licensing, and funding needs. Early separation creates transfer-pricing, management, payroll, data-sharing, audit, and substance work. The project should add the second entity when the commercial benefit exceeds those costs.
Federal personal data law
Federal Decree-Law No. 45 of 2021 is the principal cross-sector personal-data law for mainland private-sector processing. Article 2 reaches controllers and processors in the UAE and specified processing outside the UAE involving data subjects in the UAE. It excludes government data and entities, personal or household processing, certain security and judicial data, health data and banking or credit data governed by special legislation, and entities in free zones with their own personal-data laws. A group can therefore operate under different data laws through different entities. (Federal Decree-Law No. 45 of 2021, art. 2.)
Personal-data training, fine-tuning, retrieval, monitoring, and inference each require a lawful basis and a defined purpose. Consent is central to the federal law. Article 4 lists the cases in which processing may proceed without consent. The statute does not state a free-standing general legitimate-interests ground comparable to DIFC and ADGM law. Each processing purpose should be tied to consent or a specific Article 4 case. The company should preserve evidence of consent and offer an effective withdrawal method when consent controls the activity. (Federal Decree-Law No. 45 of 2021, arts. 4-6.)
The company must classify its role for every processing operation. It may act as a processor for customer-directed prompts and outputs, while acting as controller for billing, fraud detection, security logs, abuse monitoring, or separate product analytics. Contract wording does not override the actual allocation of purpose and essential means. A customer instruction also does not authorize the vendor's separate benchmarking, training, or product-development purpose.
The controller must provide required information, use appropriate security, control processors, respect retention limits, and support data-subject rights. AI records should cover prompts, outputs, model versions, vector stores, logs, evaluations, moderation data, support tickets, and improvement datasets. The company should link each category to a purpose, lawful basis, retention period, access group, hosting location, and deletion method.
Article 10 requires a Data Protection Officer in specified high-risk circumstances. The statutory triggers include high risk arising from new technologies or data volume, systematic and comprehensive assessment involving profiling or automated processing, and large-volume sensitive-data processing. Article 21 requires a data protection impact assessment before processing that is likely to create high risk. A project should complete an assessment before biometric analysis, sensitive-data use, large-scale monitoring, or automated decisions affecting access to work, credit, insurance, health, education, housing, or essential services. (Federal Decree-Law No. 45 of 2021, arts. 10 and 21.)
Article 18 gives a data subject the right to object to decisions resulting from automated processing, including profiling, when the decision has legal consequences or seriously affects the person. A covered service should provide a real challenge process. The reviewer needs authority to change the outcome and access to the inputs, model version, applicable rules, output, and supporting records. The reviewer should exercise independent judgment rather than routinely adopt the model result. (Federal Decree-Law No. 45 of 2021, art. 18.)
Article 9 governs personal-data breach notification. Articles 22 and 23 govern international transfers. The company should map every cloud region, backup, support location, vector database, observability service, moderation vendor, and subprocessor. Each transfer needs a statutory route. Customer contracts should control location changes and subprocessor additions and should allocate assistance with breaches, rights requests, and regulator inquiries. (Federal Decree-Law No. 45 of 2021, arts. 9 and 22-23.)
The law leaves important procedures to its Executive Regulation. Article 28 directs the Cabinet to issue that regulation. No generally applicable Executive Regulation or federal administrative-penalty schedule was in force as of 24 August 2026. Substantive duties remain operative. Before a live filing, the project should obtain current regulator confirmation on forms, timing, adequacy decisions, transfer applications, and penalty procedure.
The federal law contains no special permission to train AI on personal data. A training dataset must satisfy the same collection, notice, lawful-basis, purpose, security, retention, rights, and transfer rules as other processing. De-identification should be tested against re-identification risk and retained linkage. A label stating that data is anonymous does not determine the statutory position when the company can re-identify a person or reasonably combine the data with other records.
DIFC data law and autonomous systems
DIFC Data Protection Law No. 5 of 2020, as amended, applies its own lawful-processing, notice, accountability, security, impact-assessment, breach, transfer, and rights rules within its territorial scope. It permits legitimate-interests processing where the controller completes the required balancing and protects the data subject. A DIFC company should document that test rather than copy a generic assertion into its privacy notice. (DIFC Data Protection Law No. 5 of 2020, arts. 9-21.)
Article 22(4)(c) contains a narrow rule for continued retention when personal data forms part of a dataset used to lawfully train or refine an AI system and the use presents no risk to data-subject rights. Article 22(5) requires a data protection impact assessment before reliance on that rule. The provision addresses retention after lawful use. It does not legalize the original collection, create a new lawful basis, excuse notice, or authorize an incompatible training purpose. (DIFC Data Protection Law No. 5 of 2020, arts. 22(4)(c) and 22(5).)
Article 38 governs specified decisions based solely on automated processing that produce legal or comparably serious effects. The controller must identify whether the decision falls within an exception and provide the required safeguards. An effective human review path should exist before the company markets a service for credit, insurance, employment, health, or access decisions. (DIFC Data Protection Law No. 5 of 2020, art. 38.)
Regulation 10 applies when an autonomous or semi-autonomous system processes personal data. It defines the Provider that develops or commissions the system, the Deployer that directs or benefits from its use, and the Operator that operates it. One company may hold more than one role. Regulation 10.3.4 generally treats the Deployer as controller and the Operator as processor for the regulated processing. Contracts should allocate notices, instructions, testing, security, intervention, records, incident response, and complaint handling by reference to those roles. (DIFC Data Protection Regulations, regs. 10.1 and 10.3.4.)
Regulation 10 requires human-defined or human-approved purposes and limits for commercial processing. It also requires design and operation consistent with the stated principles, evidence concerning system decisions, intervention rights, risk and impact assessment, and a register of regulated systems. A release record should identify the purpose, model, data, tests, limitations, human controls, incidents, and material changes. (DIFC Data Protection Regulations, regs. 10.2 and 10.3.1-10.3.2.)
Regulation 10.3.3 places additional conditions on commercial High Risk Processing Activities. The system must comply with applicable audit and certification requirements established or recognized by the Commissioner. Its purposes must remain human-defined or human-approved. The Deployer or Operator must appoint a qualified Autonomous Systems Officer with status and functions comparable to those specified for a Data Protection Officer. The DIFC Commissioner has published a Regulation 10 Accreditation and Certification Framework. A project should confirm the current accredited route, scope, evidence standard, and renewal terms before it commits to a high-risk launch. (DIFC Data Protection Regulations, reg. 10.3.3; Regulation 10 Accreditation and Certification Framework.)
DIFC opened Consultation Paper No. 3 of 2026 on 18 June 2026. The consultation addressed amendments to Regulation 10 and closed on 18 July 2026. No final enactment had been issued as of 24 August 2026. The enacted 2023 Regulation 10 therefore controls unless and until an amendment takes effect.
DIFC is legally workable for AI, but Regulation 10 changes cost and timing. A low-risk enterprise assistant can remain manageable with role allocation, notices, testing, records, and human controls. A high-risk product needs the certification and officer workstream at the design stage. Choosing DIFC after the model is complete may require expensive rework.
ADGM data law
ADGM Data Protection Regulations 2021, as amended, apply lawful-processing, notice, security, processor, recordkeeping, rights, impact-assessment, breach, and transfer duties within their scope. The Office of Data Protection also administers registration and enforcement. A company must use the ADGM forms and current fee rules that apply to its activities.
Section 20 gives a person the right not to be subject to specified decisions based solely on automated processing, including profiling, when the decision produces legal or comparably serious effects. The section contains exceptions and safeguards. A covered decision should have effective human review and records showing the input data, purpose, model version, output, and final action. (ADGM Data Protection Regulations 2021, s. 20.)
Section 31(4)(c) permits continued retention when personal data forms part of a dataset used to lawfully train or refine an AI system and the use presents no risk to the individual's rights. Section 31(5) requires a data protection impact assessment before the company relies on that provision. The rule does not authorize collection or training. The company still needs a lawful basis, notice, purpose control, security, rights handling, and a lawful transfer route. (ADGM Data Protection Regulations 2021, ss. 31(4)(c) and 31(5).)
Section 32 requires notice of a qualifying personal-data breach to the Commissioner without undue delay and, where feasible, within 72 hours after awareness. Section 34 requires an impact assessment before processing likely to create high risk. Section 35 requires a Data Protection Officer for specified public-authority, monitoring, and large-scale special-category processing. Part V requires an adequacy decision, approved safeguards, or a valid derogation for transfers outside ADGM. (ADGM Data Protection Regulations 2021, ss. 32-35 and 40-44.)
ADGM has no separate autonomous-systems instrument equivalent to DIFC Regulation 10 as of 24 August 2026. ADGM therefore does not impose the DIFC role taxonomy, Autonomous Systems Officer, or AI certification gate. Ordinary data law still requires lawful training data, fair processing, security, processor control, human review where section 20 applies, and documented assessments.
This difference supports ADGM as the default financial-free-zone candidate for the assumed B2B company. The result changes if the activity licence is unavailable, Dubai customers require a DIFC presence, regulated finance becomes part of the product, or substantial mainland operations make a free-zone structure inefficient.
Cybersecurity, online conduct, and child access
Federal Decree-Law No. 34 of 2021 applies throughout the UAE, including the financial free zones through the federal reservation for criminal law. It criminalizes specified unauthorized access to systems and data. It also addresses false accounts, impersonation, privacy invasion, deceptive online advertising, and specified unlawful information. Product design, employee conduct, customer instructions, and knowing assistance can each create exposure under the statutory elements. (Federal Decree-Law No. 34 of 2021 on Countering Rumors and Cybercrimes.)
Public visibility does not establish permission to collect or reuse data. A crawler should not bypass authentication, technical access controls, private areas, or express restrictions. Dataset intake should record the source, access method, site terms, copyright position, personal-data basis, confidentiality status, and deletion rule. Scraping a public page may still involve copyright, database rights, privacy, contract, or cybercrime risk.
The National Cyber Security Policy for Artificial Intelligence states minimum security expectations for AI adoption in the UAE. A private company should use it as an internal baseline when it is relevant to the product or customer. The security program should assign named responsibility and cover model and data classification, secure development, supply-chain review, adversarial testing, prompt injection, model extraction, data leakage, poisoning, privileged tools, incident response, and decommissioning. The policy does not replace a binding sector standard or customer control.
Agentic systems require stricter authority controls. The product should use least privilege, environment separation, transaction limits, identity checks, tamper-resistant logs, and prior human approval for irreversible or legally serious acts. Payments, account closure, legal notices, data disclosure, hiring, credit, medical, and safety actions should not occur on inferred authority alone.
Federal Decree-Law No. 26 of 2025 on Child Digital Safety and Cabinet Resolution No. 106 of 2026 regulate child access and safety on covered digital services. The Cabinet Resolution applies specifically to covered social-media platforms. Children under 15 may not create, use, or operate a personal account on such a platform. Children aged 15 but under 16 receive the special access protections stated in the Resolution. Covered platforms also face age-assurance, child-risk, design, advertising, monitoring, reporting, and awareness duties. The Resolution grants a 12-month transition period from its entry into force. (Federal Decree-Law No. 26 of 2025; Cabinet Resolution No. 106 of 2026.)
An enterprise API or assistant without profiles, user interaction, publishing, or algorithmic social-content features may fall outside the social-media Resolution. That assessment depends on the actual service design. The broader Child Digital Safety Law, personal-data law, consumer law, and content offences can still apply. Product classification should identify every account, sharing, messaging, recommendation, and content-ranking feature before launch.
Training data, software, model assets, and outputs
Federal Decree-Law No. 38 of 2021 protects software, software applications, and databases. It defines an author by reference to the person who creates the work. The statute does not designate an AI system as an author or create a special ownership rule for machine-generated output. Output with sufficient human creative contribution may qualify under ordinary rules. The law supplies no clear basis for copyright in output generated without sufficient human authorship. Contract terms can allocate rights between the parties, but they cannot create statutory copyright when the legal conditions are absent. (Federal Decree-Law No. 38 of 2021, arts. 1-2.)
Training and fine-tuning can involve reproduction, storage, adaptation, extraction, or use of protected works and databases. There is no express general text-and-data-mining exception. A company should rely on ownership, an express machine-learning licence, public-domain status, or a verified statutory exception. Website access, copyright permission, privacy law, confidentiality, and cyber authorization are distinct requirements. (Federal Decree-Law No. 38 of 2021, art. 22.)
The company should maintain a dataset ledger. Each entry should identify the source, acquisition date, access method, licence, territory, permitted purpose, attribution duty, retention rule, personal-data status, sensitive-data status, opt-out process, deletion process, and model lineage. Purchased and customer-supplied datasets should carry evidence and warranties matched to their risk. A general supplier statement that it owns all rights is weak support for a high-risk corpus.
Federal Law No. 11 of 2021 excludes schemes, rules, computer programs, and business methods as such from patent protection. A software-implemented technical invention may still qualify when it satisfies novelty, inventive step, industrial application, and the remaining statutory requirements. Patent drafting should focus on the technical system or effect rather than an algorithm or business rule in the abstract. (Federal Law No. 11 of 2021 on the Regulation and Protection of Industrial Property Rights.)
Trade-secret protection may be more useful for model weights, prompts, evaluation sets, inference methods, orchestration logic, fine-tuning methods, and security controls. Protection of undisclosed information depends on secrecy, commercial value, and reasonable protective measures. The company should segment access, encrypt sensitive assets, control repositories, monitor extraction, use confidentiality terms, and apply exit procedures. (Federal Law No. 11 of 2021.)
Employment and contractor documents should assign code, models, datasets, documentation, inventions, prompts, evaluations, and improvements to the company. They should address moral rights to the extent permitted and should match the applicable employment regime. Mainland, DIFC, ADGM, and foreign contractors do not share one employment law.
Open-source software and open-weight models need a bill of materials. The review should cover copyright licences, notices, attribution, source-disclosure duties, patent terms, acceptable-use restrictions, model licences, security history, and upstream changes. An "open" label does not establish unrestricted commercial use.
Digital contracting, consumer protection, and liability
Federal Decree-Law No. 46 of 2021 recognizes electronic documents, signatures, and contracts formed through automated electronic systems, subject to its conditions and exclusions. An API or online workflow can therefore form a contract. The company should preserve evidence of identity, authority, terms displayed, version, acceptance method, date, and automated steps. (Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services; Cabinet Resolution No. 28 of 2023.)
Federal Decree-Law No. 14 of 2023 governs trade through modern technological means within its territorial scope. It imposes licensing, disclosure, transaction, security, data-protection, and consumer duties on covered digital traders. Cabinet Resolution No. 200 of 2025 supplies the current administrative-penalty schedule. A digital contract worth less than AED 50,000 may not contain an arbitration clause. The company should identify whether each consumer or digital sale falls within that restriction before using a standard arbitration term. (Federal Decree-Law No. 14 of 2023 Concerning the Modern Technology-Based Trade; Cabinet Resolution No. 200 of 2025.)
Federal Law No. 15 of 2020 prohibits false or misleading descriptions and advertising and grants mandatory consumer rights under the statute and its Executive Regulation. Claims about accuracy, bias, security, legal compliance, professional equivalence, or regulator approval need evidence tied to a model version, test population, metric, and date. An AI disclosure does not cure fraud, privacy invasion, defamation, unlawful advertising, or unsafe performance. (Federal Law No. 15 of 2020 on Consumer Protection; Cabinet Resolution No. 66 of 2023.)
ADGM Consumer Protection Regulations 2025 apply within their stated scope. A consumer-facing ADGM company should test both the ADGM rules and any applicable federal rules for the transaction. DIFC and sector regulators can also impose conduct duties where their laws apply.
Federal Decree-Law No. 25 of 2025 has governed federal civil obligations since 1 June 2026. Its rules on contract, good faith, harmful acts, causation, and compensation interact with commercial, consumer, and digital-trade law. A liability cap cannot displace criminal law, public order, mandatory consumer rights, or a sector duty. Its effect on other claims depends on the obligation, fault, drafting, and governing law. (Federal Decree-Law No. 25 of 2025 Promulgating the Civil Transactions Law.)
A B2B AI agreement should define permitted use, prohibited use, input rights, output allocation, privacy roles, model-improvement rights, hosting locations, subprocessors, security controls, incident duties, performance tests, human review, regulated-use exclusions, change procedure, suspension, audit evidence, indemnities, liability allocation, insurance, termination, deletion, governing law, and forum. The allocation should match the technical design and actual party roles.
Agentic functions require a separate authority clause. The contract and interface should distinguish a recommendation from an authorized act. Transaction limits, confirmation steps, revocation, identity checks, and logs should match the seriousness of the action. Validation of automated contracting does not excuse an unauthorized or unlawful act.
Sector-specific restrictions
Health AI is subject to specific data, professional, product, and emirate requirements before pilot or sale. Federal Law No. 2 of 2019 restricts specified offshore handling of health data, including storage and processing, subject to authorized cases. Ministerial Resolution No. 51 of 2021 states cases and conditions for offshore storage or transfer. Diagnostic, triage, treatment, clinical-documentation, insurance, and patient-data functions may also require professional, facility, product, or emirate approval. A general cloud architecture should not be offered to a health customer before the data-location and authorization position is confirmed. (Federal Law No. 2 of 2019, art. 13; Ministerial Resolution No. 51 of 2021.)
Financial AI can trigger authorization from the Central Bank, Securities and Commodities Authority, DFSA, FSRA, VARA, or another competent regulator. Credit, underwriting, insurance, investment advice, portfolio management, payments, lending, exchange, and virtual-asset functions require activity-by-activity review. A software vendor can also inherit contractual and audit duties from a regulated customer's outsourcing, operational-resilience, conduct, and model-risk rules.
Telecommunications, digital identity, trust services, cybersecurity services, defence, dual-use technology, autonomous transport, education, public procurement, government data, biometric identification, and employment decisions must each be classified under the applicable regime. The product terms should prohibit an unapproved regulated use. A customer warranty does not cure a vendor licensing breach when the vendor itself performs or markets the regulated activity.
Mainland employment generally falls under federal labour law. DIFC and ADGM maintain separate employment laws. Hiring plans should address the applicable contract, visa and office conditions, confidentiality, intellectual-property assignment, post-termination restrictions, and employee monitoring. An AI hiring or workforce-scoring product must comply with data, automated-decision, and discrimination rules.
Federal competition law reaches conduct that affects UAE markets, including qualifying conduct outside the UAE. Cabinet Resolution No. 3 of 2025 sets notification thresholds for economic concentrations based on annual UAE relevant-market sales above AED 300 million or a combined market share above 40 percent. Cabinet Resolution No. 59 of 2026 supplies current executive procedures. Acquisitions, exclusivity, tying, restricted data access, model distribution, and interoperability terms require competition review when the thresholds or market-power issues become plausible. (Federal Decree-Law No. 36 of 2023; Cabinet Resolutions Nos. 3 of 2025 and 59 of 2026.)
Tax and incentives
Federal corporate tax applies to mainland and free-zone entities. The standard rate is 0 percent on taxable income up to AED 375,000 and 9 percent above that amount, subject to the Corporate Tax Law. Registration, filing, records, and transfer-pricing duties can apply even when no tax is payable. (Federal Decree-Law No. 47 of 2022 on the Taxation of Corporations and Businesses.)
A Qualifying Free Zone Person receives a 0 percent rate only on Qualifying Income. It must satisfy the statutory conditions, including adequate substance, qualifying-income rules, transfer pricing, audited financial statements where required, and the de minimis test. Non-qualifying income and profits attributable to a mainland or foreign permanent establishment can bear the 9 percent rate. Software licensing, services to mainland customers, intellectual-property income, headquarters functions, and individual customers require classification under the current decisions. A free-zone commercial licence does not establish tax qualification.
Cabinet Resolution No. 215 of 2025 established the R&D Tax Credit for tax periods or fiscal years beginning on or after 1 January 2026. Phase 1 permits a non-refundable credit of up to 50 percent on qualifying expenditure up to AED 5 million. A model-research program should document the technical uncertainty, hypotheses, qualified personnel, UAE activities, ownership, time, and cost. Ordinary implementation and customer customization should be separated from qualifying research. (Cabinet Resolution No. 215 of 2025; Ministry of Finance Phase 1 announcement, 18 March 2026.)
VAT is generally charged at 5 percent. A UAE-resident business must register when taxable supplies and imports exceed AED 375,000, subject to the statutory rules. Place of supply, export treatment, reverse charge, marketplaces, and electronic services depend on the customer and delivery facts. (Federal Decree-Law No. 8 of 2017 on Value Added Tax, as amended.)
The UAE Domestic Minimum Top-up Tax applies to UAE constituent entities in multinational groups that meet the EUR 750 million revenue test stated in the rules. It applies for financial years starting on or after 1 January 2025. A group-level review should precede reliance on a free-zone rate when the project belongs to a large multinational group.
The entity decision should follow a tax model using expected customer type, revenue location, IP ownership, mainland activity, staff, permanent establishments, related-party charges, and exit structure. A simple comparison of licence fees will not show the real tax result.
Disputes and governing law
Mainland UAE contracts operate within a civil-law system. Court proceedings are principally conducted in Arabic. Mandatory federal or emirate law can apply despite a foreign governing-law clause, especially for licensing, consumers, employment, property, insolvency, criminal law, and public order. Federal Decree-Law No. 25 of 2025 should be used for obligations within its temporal scope.
DIFC and ADGM offer English-language commercial courts. Subject to its enactments, ADGM applies English common law directly; DIFC applies its own laws and precedent. Incorporation in either centre does not give its courts jurisdiction over every dispute. The contract should state governing law and forum separately and should satisfy the chosen court's jurisdiction or opt-in rules.
Federal Law No. 6 of 2018 supports arbitration for arbitrable disputes, as amended in 2023. A clause should identify the seat, institution or rules, number of arbitrators, language, governing law, interim-relief route, confidentiality terms, and service method. The AED 50,000 restriction in the Modern Technology-Based Trade Law must be checked for covered digital contracts. (Federal Law No. 6 of 2018 on Arbitration, as amended by Federal Decree-Law No. 15 of 2023.)
A B2B international contract can use ADGM or DIFC law and courts, or a suitable arbitration clause, when the jurisdictional requirements are met. Consumer and small digital transactions need separate terms. Employment, privacy, IP ownership, and regulated services may also require mandatory local provisions.
SINGAPORE
Summary
- Singapore applies existing statutes according to the product’s function, data, affected persons, and sector. MDDI has retained the option of targeted legislation where existing measures prove inadequate.
- A Singapore private company limited by shares remains the preferred operating vehicle on the assumed facts. It requires at least one ordinarily resident director, a locally resident natural-person secretary appointed within six months, and a registered office. A foreign founder normally uses a registered corporate service provider for incorporation.
- The Personal Data Protection Act 2012 is the principal binding statute for account data, prompts, uploaded files, retrieval stores, model-development records, outputs, logs, and inferred profiles. The company needs a data protection officer, documented purposes, consent or a statutory exception, suitable notice, accuracy controls, security, retention limits, overseas-transfer protection, and breach procedures.
- The PDPC’s July 2026 generative-AI guidelines and IMDA’s May 2026 Model AI Governance Framework for Agentic AI are current official guidance. They do not create a licence, statutory safe harbour, or universal human-review duty. They identify regulator expectations for responsibility allocation, testing, transparency, permission limits, monitoring, and incident handling.
- Copyright Act 2021, sections 243 and 244, may permit computational data analysis using lawfully accessed material. The exception does not cure unlawful access, personal-data misuse, breach of confidence, or a use outside its statutory conditions. Singapore appellate authority requires human authorship, but no appellate judgment addresses copyright in modern generative-AI output.
- Electronic Transactions Act 2010, section 15, recognises contracts formed through automated message systems. Quoine Pte Ltd v B2C2 Ltd [2020] SGCA(I) 2 concerns deterministic software and does not settle every question raised by adaptive agents. The operator should define authority, confirmation points, monetary limits, records, suspension, and reversal rights.
- Consumer, competition, cybercrime, online-harm, financial-services, medical-device, employment, and export-control laws can apply without an AI-specific offence. The Digital Infrastructure Bill remained a consultation draft; MAS’s AI Risk Management Guidelines remained proposed; and the Workplace Fairness Act and Health Information Act 2026 were not in force as of 24 August 2026.
General AI regulation
The applicable duties follow the product’s conduct. Personal-data processing engages the Personal Data Protection Act 2012. Diagnostic software may enter the medical-device regime. Advice, payments, trading, or insurance functions may require financial-services authorisation. Public-content services can enter online-safety or IMDA regimes. Systems supporting essential services may face duties under the Cybersecurity Act 2018.
PDPC and IMDA have issued current official AI materials. The PDPC published its Advisory Guidelines on Use of Personal Data in Generative AI on 20 July 2026. IMDA updated the Model AI Governance Framework for Agentic AI on 21 May 2026 and issued voluntary chatbot-transparency guidance in July 2026. Their advisory status must remain distinct from statutory duties.
No Singapore judgment assigns those 2026 documents a defined evidentiary role in negligence or contract litigation. A regulator, customer, or litigant may refer to them when examining expected practice, but no reported judicial holding gives them that role. The company should record any material departure and the reasons supporting it.
Corporate form and tax
A Singapore private company limited by shares provides a separate operating entity and a conventional contracting vehicle. ACRA requires at least one director ordinarily resident in Singapore. The company must appoint a locally resident natural-person secretary within six months. The sole director cannot also act as secretary. A foreign founder normally engages a registered corporate service provider for the incorporation filing.
The constitutional documents and internal delegations should cover software development, model services, data processing, licensing, research, regional sales, and external agent activity. Employment and contractor agreements should assign code, documentation, evaluation sets, inventions, training material created for the company, and other project rights. Intercompany agreements should match the functions that personnel and systems perform.
Singapore’s headline corporate income tax rate is 17 percent. GST is 9 percent, and domestic registration generally becomes compulsory when taxable turnover exceeds S$1 million under the applicable retrospective or prospective test. The actual tax result depends on control and management, source, transfer pricing, intellectual-property ownership, staff location, permanent establishments, and available reliefs.
Singapore incorporation does not confine exposure to Singapore law. Foreign privacy, consumer, employment, tax, sanctions, and sector rules may apply because users, data subjects, personnel, infrastructure, or regulated activity are located abroad. A market-by-market review remains necessary.
Personal data
The Personal Data Protection Act 2012 applies when the Singapore organisation collects, uses, or discloses personal data. Relevant records can include user accounts, prompts, uploads, retrieved documents, support tickets, model evaluations, output logs, embeddings, inferred attributes, and agent-action histories. Pseudonymisation does not remove the Act when the organisation can reasonably reidentify an individual.
Sections 11 and 12 require accountability measures, including appointment of a data protection officer and suitable policies. Sections 13, 18, and 20 govern consent, appropriate purposes, and notice, subject to statutory exceptions. Section 23 governs accuracy where the data is likely to affect an individual or be disclosed. Sections 24, 25, and 26 address protection, retention, and overseas transfers. Sections 21 and 22 address access and correction, subject to their statutory conditions and exceptions.
The company must identify the purpose and legal basis for each material use. Consent to create an account does not automatically authorise general model training, advertising profiles, human review, or disclosure to another model provider. The business-improvement, legitimate-interests, research, and publicly available data exceptions have separate conditions. None supplies unrestricted authority for secondary model development.
Public accessibility does not settle lawful collection. Access restrictions, account controls, contractual terms, technical barriers, confidentiality, copyright, and foreign law can independently restrict collection. The data register should record each source, access method, date, licence, personal-data basis, permitted purpose, retention period, and downstream restriction.
The final July 2026 GenAI guidance distinguishes Model Providers, System Providers, and System Deployers according to their activities. A company can occupy more than one role. A supplier that selects its own training or reuse purposes may have organisational responsibility for that processing, even when a contract describes it as a processor.
There is no general statutory right to human review or a complete explanation of model logic under the PDPA or current general AI rules. MDDI’s July 2026 response tied oversight measures to the risk and deployment rather than announcing a universal rule. Sector statutes, contractual promises, accuracy duties, access rights, or fairness requirements may produce a different result for a specific use.
Section 26 permits overseas transfers where the organisation provides protection comparable to the PDPA. Supplier review should address processing instructions, reuse for training, subprocessors, locations, remote support, security, audit evidence, incident notice, deletion, return, and onward transfer. A contractual warranty without operational verification is insufficient for prudent launch control.
A breach becomes notifiable when it is likely to cause significant harm or is of significant scale. The regulations treat 500 or more affected individuals as significant scale. Once the organisation determines that notification is required, it must notify the PDPC as soon as practicable and no later than three calendar days. Section 48J permits a penalty of up to 10 percent of annual turnover in Singapore for an organisation above the statutory turnover threshold, or S$1 million in other cases.
AI testing and human control
IMDA’s agentic-AI material recommends named responsibility, risk limits tied to autonomy, technical controls, operational monitoring, and user accountability. These are official recommendations rather than universal statutory elements. A binding duty can arise from the PDPA, a sector statute, a customer contract, a licence, or ordinary civil law.
Each production system should have a versioned record covering its intended use, prohibited uses, model and supplier, training or fine-tuning sources, evaluation population, known failure modes, security tests, external tools, approval decision, incidents, and material changes. The record should distinguish mandatory controls from voluntary practices and contractual commitments.
An agent that sends messages, spends money, changes records, submits forms, publishes content, or controls another system needs a written authority boundary. The boundary should specify permitted tools, recipients, credentials, monetary limits, confirmation steps, expiry, suspension, and reversal. High-consequence actions should require separate approval unless a narrow automated action has been authorised and tested.
Human review has limited value when the reviewer lacks information, time, authority, or a practical ability to reject the output. Review procedures should identify the evidence to inspect, known error classes, escalation conditions, and required records. These controls support the company’s legal position but do not create a statutory safe harbour.
Cybersecurity and digital infrastructure
The Personal Data Protection Act’s protection obligation and the Computer Misuse Act 1993 apply to ordinary AI services. Unauthorised access, interception, use, or modification can arise through scraping, credential sharing, model extraction, automated browsing, security testing, or an agent acting beyond permission. Customer instructions should define access rights, and technical permissions should enforce those limits.
The 31 October 2025 Cybersecurity Act commencement notice specifically addressed provisions concerning provider-owned or virtual critical information infrastructure, expanded CII reporting, and Systems of Temporary Cybersecurity Concern. CSA’s current July 2026 overview separately confirms that the Act now contains powers concerning entities of special cybersecurity interest and foundational digital infrastructure. The commencement notice should not serve as the sole authority for every expanded regulatory class.
Only penetration testing and managed security operations-centre monitoring were listed as licensable cybersecurity services on CSA’s current page. A general AI vendor does not require that licence unless its service falls within a licensed category. Designation or customer-specific duties may still apply where the product supports essential services or regulated infrastructure.
MDDI issued the Digital Infrastructure Bill for consultation on 1 July 2026. The consultation described a draft rather than enacted law and proposed licensing for major cloud and data-centre services under stated thresholds. Ordinary software-as-a-service was outside the proposed major-cloud definition in that consultation text. The company should monitor later bills and commencement instruments without treating the draft as current law.
Training rights, outputs, patents, and confidence
Copyright Act 2021, sections 243 and 244, creates an exception for specified acts undertaken for computational data analysis. The user must have lawful access and meet the statutory conditions. The exception may support commercial model development, but it does not authorise access obtained through circumvention, stolen credentials, breach of confidence, or conduct prohibited by another statute.
The company should maintain source-level records for every training and evaluation collection. The record should identify ownership, licence, access basis, jurisdiction, personal-data content, permitted acts, retention term, redistribution limits, and downstream obligations. Customer data should remain outside shared training unless the contract and applicable data law permit that use.
In Asia Pacific Publishing Pte Ltd v Pioneers & Leaders (Publishers) Pte Ltd [2011] SGCA 37, the Court of Appeal connected copyright authorship to a natural person. No Singapore appellate judgment decides copyright in a modern generative-AI output. A conclusion that a wholly machine-generated item lacks copyright is therefore an inference from the human-author rule. Protection for mixed human-machine work depends on the person’s original contribution to the resulting expression.
The absence of copyright does not make an output legally unrestricted. It can reproduce protected expression, reveal confidential information, misuse a trade mark, defame a person, or breach a contract. Customer terms should avoid an unqualified promise that every output is exclusive, copyright-protected, or non-infringing.
No Singapore case recognises an AI system as a patent inventor. IPOS maintains supplemental examination guidance for AI-related patent applications, while existing law continues to require identification of the relevant human deviser. The company should record human technical contributions and assess patent filing before public disclosure.
Automated contracts and civil liability
Electronic Transactions Act 2010, section 15, prevents denial of a contract’s validity solely because automated message systems formed it without contemporaneous human review. Section 16 provides a limited route concerning input errors where the system did not offer a correction opportunity and the statutory conditions are met.
Quoine concerned deterministic trading programs. The Court of Appeal examined the relevant programmers’ knowledge when the software was written. Later official judicial commentary recognises that adaptive agents present questions that Quoine did not finally decide. The project should not treat Quoine as a complete attribution rule for autonomous systems.
Contracts should identify who authorises an agent, the actions that bind the account, confirmation requirements, spending and tool limits, error reporting, suspension, reversal, data disclosure, and record retention. Supplier contracts should allocate failures caused by the model, hosting service, plug-in, retrieval source, or external tool.
Ordinary negligence principles remain relevant. Spandeck Engineering (S) Pte Ltd v Defence Science & Technology Agency [2007] SGCA 37 supplies Singapore’s general duty-of-care analysis. Foreseeability, proximity, policy, breach, causation, and loss depend on the deployment and relationship. The Unfair Contract Terms Act 1977 prohibits exclusion of negligence liability for death or personal injury and subjects specified other exclusions to reasonableness.
Consumer transactions and marketing
Section 4 of the Consumer Protection (Fair Trading) Act 2003 addresses conduct that may deceive or mislead, false claims, and listed unfair practices. AI-generated statements remain the trader’s representations when the trader uses them in the consumer transaction. Disclaimers cannot reliably cure a specific sales claim that lacks evidence.
CCCS’s 2025 Agoda action addressed remuneration-influenced ranking, badges, countdown timers, discount claims, and other interface features. The action confirms that automated ranking and interface design can fall within ordinary consumer enforcement. A recommendation system should disclose material commercial influence and avoid fabricated endorsements or urgency claims.
Unsolicited commercial electronic messages remain subject to the Spam Control Act 2007. The current Act contains requirements concerning sender information and unsubscribe facilities for covered messages. Marketing systems must also comply with telecommunications and direct-marketing rules before launch.
Online harms and public content
The Online Safety (Relief and Accountability) Act 2025 began partial operation on 29 June 2026 together with the Online Safety Commission. The first operational phase covers intimate-image abuse, image-based child abuse, doxxing, online harassment, and online stalking. Duties and remedies depend on the actor, service, communication, and harm defined by the Act.
The Online Criminal Harms Act 2023 and the Protection from Online Falsehoods and Manipulation Act 2019 provide separate direction powers for defined conduct. A private chatbot does not become a regulated public platform solely because it generates text. Hosting, public posting, user-to-user communication, ranking, monetisation, or large-scale dissemination requires classification under the applicable service category.
A service with public-content features should maintain reporting, preservation, review, restriction, appeal, and emergency escalation procedures. The product should keep sufficient provenance and account records to investigate impersonation, fraud, child abuse material, harassment, manipulated media, and other covered conduct.
Competition
Competition Act 2004, section 34, prohibits agreements that prevent, restrict, or distort competition in Singapore. Section 47 prohibits abuse of a dominant position, and section 54 governs mergers that substantially lessen competition. Automated pricing, bidding, ranking, or allocation remains attributable to the undertaking operating or adopting the system.
A supplier serving competing customers should segregate sensitive information and prevent a shared model from disclosing future prices, capacity, customer allocation, bid strategy, or other competitively sensitive data. A common pricing recommendation does not automatically prove an infringement, but the company should review any feature that can coordinate market conduct.
Employment
The Workplace Fairness Act had been enacted but was not in force as of 24 August 2026. MOM continued to target implementation for the end of 2027. Current fair-employment measures, including the Fair Consideration Framework and Tripartite Guidelines on Fair Employment Practices, remain relevant before commencement.
An AI system used for recruitment, promotion, scheduling, discipline, or dismissal must comply with employment, data-protection, and fairness rules. The employer remains responsible for the decision and the personal data used. Testing should address proxy discrimination, unequal error rates, accessibility, data quality, and the reviewer’s ability to correct the result.
Financial services
A product that provides financial advice, payment services, securities dealing, insurance functions, credit, or discretionary transactions requires activity-specific analysis under the applicable Singapore financial statutes. Describing the product as an assistant or information tool does not control its legal classification.
MAS consulted on proposed Guidelines on Artificial Intelligence Risk Management in November 2025. MAS still described those guidelines as proposed in its August 2026 material. Existing licensing, technology-risk, outsourcing, fair-dealing, and institution-specific duties continue to apply independently. A financial function should remain disabled until the company and any licensed customer confirm the legal route.
Healthcare
Software intended to diagnose, monitor, treat, prevent, or manage a medical condition can qualify as a medical device under the Health Products Act 2007 and the Health Products (Medical Devices) Regulations 2010. Classification follows intended purpose and claims rather than the product’s marketing label. Registration, dealer licensing, quality, labelling, and post-market duties may apply.
MOH and HSA’s AIHGle 2.0 provides current guidance for developers, deployers, and healthcare users. It complements the binding medical-device rules. The Health Information Act 2026 was not in force as of 19 August 2026 and should not be treated as current binding law.
Strategic goods and technology transfers
The Strategic Goods (Control) Act 2002 and Strategic Goods (Control) Order 2025 regulate listed goods, software, technology, brokering, and intangible transfers. Making controlled technology stored on a Singapore server accessible from another country can require a permit. Ordinary commercial AI software is not controlled merely because it uses AI; classification, destination, end user, and end use determine the result.
Projects involving advanced computing hardware, cryptography, defence functions, surveillance, weapons-related research, or controlled technical data should obtain a classification before export or remote access. The record should identify origin, destination, end user, end use, classification, and permit.
Dispute resolution and launch decision
Singapore offers ordinary court proceedings, the Singapore International Commercial Court for qualifying international commercial disputes, and international arbitration under the International Arbitration Act 1994. The Supreme Court includes the Court of Appeal and the High Court, with the Appellate Division, General Division, and SICC. The forum clause should reflect counterparties, confidentiality, urgent remedies, appeal rights, and enforcement locations.
Singapore remains a legally workable jurisdiction for the assumed project. Launch should wait until the company has completed its entity and tax structure, data inventory, source-rights review, supplier agreements, privacy notices, transfer assessment, security testing, agent-authority controls, consumer claims review, incident procedures, and sector classification.
The launch decision changes if the product gives regulated advice, processes payments, diagnoses or treats disease, makes consequential employment decisions, operates public-content functions at regulated scale, supports designated infrastructure, or transfers controlled technology. Each activated function must satisfy its applicable legal and regulatory requirements before launch.
HONG KONG
Summary
- Hong Kong is a workable jurisdiction for the assumed AI project, subject to project-specific launch conditions. Existing statutes regulate the project through its data, copying, contracts, users, content, security, and sector. There is no general horizontal AI statute or bill establishing one as of 24 August 2026. Government and regulator AI instruments remain non-statutory guidance.
- The Personal Data (Privacy) Ordinance governs personal data under the company’s control. It requires fair and necessary collection, purpose limits, accuracy, retention limits, security, openness, and access and correction procedures.
- Section 33 of the Personal Data (Privacy) Ordinance remains uncommenced. Cross-border transfers still require compliance with the operative data protection principles, processor controls, contracts, and applicable foreign or sector law.
- Training, fine-tuning, retrieval, and output generation can engage restricted copying. The current Copyright Ordinance contains no specific enacted text-and-data-mining exception, while the Government’s proposed exception remains pending.
- Data Protection Principle 4 applies to personal-data security. Cap. 653 duties and incident clocks apply only after statutory designation and only to designated critical computer systems.
- Consumer claims require substantiation. Automated employment or service decisions remain subject to Hong Kong’s discrimination statutes, although those statutes do not impose a universal bias-testing or human-review process.
Present AI position
Hong Kong remains a viable base for the assumed project. The Basic Law preserves Hong Kong’s common law and judicial system (Basic Law, arts. 8, 19, 82 and 84). Commercial parties may select Hong Kong law and use Hong Kong courts or arbitration, subject to mandatory law and arbitrability.
The Government stated in June 2026 that no specific legislation governed embodied intelligence. It also confirmed that existing technology-neutral laws continue to apply. An inter-departmental working group is reviewing whether bespoke legislation or administrative measures are needed (Innovation, Technology and Industry Bureau, LCQ4: Development of Embodied Intelligence Technologies, 3 June 2026).
The Digital Policy Office publishes the Ethical Artificial Intelligence Framework and the Hong Kong Generative Artificial Intelligence Technical and Application Guideline. The Privacy Commissioner publishes Artificial Intelligence: Model Personal Data Protection Framework. These materials provide recommendations and best practices. They do not create offences, civil causes of action, or licensing duties unless an operative statute or contract supplies that effect (Digital Policy Office, Ethical Artificial Intelligence Framework, rev. December 2025; Hong Kong Generative Artificial Intelligence Technical and Application Guideline, rev. December 2025; PCPD, Artificial Intelligence: Model Personal Data Protection Framework, 11 June 2024).
The Privacy Commissioner’s model document identifies four recommended areas: Establish AI Strategy and Governance; Conduct Risk Assessment and Human Oversight; Customisation of AI Models and Implementation and Management of AI Systems; and Communication and Engagement with Stakeholders. Adoption can support compliance evidence. A company must still identify the statutory duty that each control addresses (PCPD, Artificial Intelligence: Model Personal Data Protection Framework, 11 June 2024).
Personal data and transfers
The Personal Data (Privacy) Ordinance applies where the company controls the collection, holding, processing, or use of personal data. Personal data concerns an identifiable living individual and must exist in a practicable form. Prompts, uploads, support records, telemetry, embeddings, logs, and inferred profiles can qualify when they meet that definition (Cap. 486, s. 2).
Data Protection Principle 1 requires a lawful purpose connected with the data user’s function or activity. Collection must be necessary, adequate, and not excessive. Direct collection generally requires notice of the purpose, recipient classes, supply consequences, and access and correction rights (Cap. 486, Sch. 1, DPP1).
Data Protection Principle 2 addresses accuracy and retention. Section 26 separately requires practicable erasure when data is no longer required, subject to statutory exceptions. The project should assign retention periods to prompts, account records, safety logs, model feedback, retrieval stores, and backups (Cap. 486, s. 26; Sch. 1, DPP2).
Data Protection Principle 3 restricts a new use that falls outside the original purpose or a directly related purpose. Prescribed consent can authorise the new use. Reusing customer files or prompts to improve a shared model must be supported by an appropriate purpose and consent design (Cap. 486, Sch. 1, DPP3).
Data Protection Principle 4 requires all practicable steps against unauthorised or accidental access, processing, erasure, loss, or use. Data processors are not directly regulated as data users merely because they process data for another person. The data user must use contractual or other means to address processor retention and security (Cap. 486, Sch. 1, DPP2(3) and DPP4(2)).
Data Protection Principles 5 and 6 require openness and support access and correction rights. The Ordinance does not create a general private-sector right to an explanation or human reconsideration for every automated decision. Access and correction rights still apply to qualifying personal data (Cap. 486, Sch. 1, DPP5 and DPP6).
Part 6A regulates direct marketing. The company must distinguish service communications from marketing and obtain the consent required by sections 35C to 35H. Silence does not satisfy the statutory consent standard for those provisions.
A breach of a data protection principle does not make every contravention a criminal offence. The Privacy Commissioner may investigate and issue an enforcement notice. Failure to comply with that notice is an offence under section 50A. Section 66 permits compensation where its requirements are met. Section 64 separately addresses specified doxxing conduct.
Hong Kong has no general statutory duty requiring every data user to report every personal-data breach. The Privacy Commissioner recommends notification. Contracts and sector rules may impose separate deadlines (PCPD, Data Breach Notification).
Section 33, which would regulate specified transfers outside Hong Kong, remains uncommenced. Its status does not disapply Data Protection Principles 2, 3, and 4. The Privacy Commissioner’s recommended model clauses provide a contractual template for transfers to data users or processors abroad. Foreign law may impose additional transfer conditions (PCPD, Guidance on Recommended Model Contractual Clauses for Cross-border Transfer of Personal Data, 12 May 2022).
Training data and generated output
Copyright creates a material development risk. Copyright owners control restricted acts, including copying, in relation to a protected work or a substantial part (Copyright Ordinance, Cap. 528, ss. 22 and 23). Dataset ingestion, preprocessing, caching, fine-tuning, and retrieval can involve copies. Liability still depends on subsistence, ownership, authorisation, substantiality, and any applicable exception.
The current Copyright Ordinance contains no specific enacted text-and-data-mining exception (Copyright Ordinance, Cap. 528). The Government announced a proposed exception, but it had not been enacted as of 24 August 2026 (IPD, Public Consultation on Copyright and Artificial Intelligence). Training sources should rest on licences, owned material, public-domain material, or an existing exception that covers the exact act.
A training-data register is a prudent control rather than a statutory formality. It should record source, licence, permitted purpose, territory, term, attribution, rights reservations, deletion duties, and downstream restrictions. Public web access alone does not establish permission to copy for model development.
Third-party model contracts should allocate input use, output rights, training use, retention, sub-processors, security, infringement support, suspension, and exit rights. Open model releases may contain separate terms for code, weights, datasets, and acceptable use. Each applicable instrument requires review.
Under section 11(3), the person who undertakes the necessary arrangements is the author of a computer-generated literary, dramatic, musical, or artistic work. Section 198 defines a computer-generated work by the absence of a human author. Copyright in that work receives the special fifty-year term in section 17(6). Those provisions do not settle every modern generative-AI ownership dispute without facts about the system and human contribution.
Customer terms should allocate contractual rights without promising that every output attracts copyright. They should preserve third-party rights and address prompts, customer data, fine-tuned components, feedback, similar outputs, and retrieval stores. Output screening and complaint procedures can reduce infringement exposure, but they do not supply a statutory defence.
Cybersecurity and critical infrastructure
Data Protection Principle 4 supplies the general statutory personal-data security duty. The required measures depend on the data, foreseeable harm, access arrangements, and available protections. The project should use access controls, encryption, secrets management, logging, testing, backup protection, and supplier restrictions that match its risk.
AI-specific testing is a prudent means of meeting security and product duties. Relevant tests may cover prompt injection, data exfiltration, retrieval poisoning, unsafe tool calls, model extraction, and tenant isolation. Hong Kong law does not prescribe one universal technical checklist for every private AI service.
The Protection of Critical Infrastructures (Computer Systems) Ordinance commenced on 1 January 2026 (Cap. 653; L.N. 144 of 2025). The Commissioner may designate critical-infrastructure operators under section 12 and critical computer systems under section 13. Direct statutory duties arise through those designations (Cap. 653, ss. 12 and 13).
Section 28 and Schedule 6 require a designated operator to report specified incidents involving a designated critical computer system. The applicable deadline is twelve hours for the listed serious incidents and forty-eight hours for other specified incidents, measured after awareness. An ordinary AI supplier does not acquire those duties merely by serving a covered sector.
Consumer terms and marketing
Section 17 of the Electronic Transactions Ordinance supports formation and validity of electronic contracts, subject to statutory conditions and Schedule 1 exclusions (Cap. 553, s. 17 and Sch. 1). The service should preserve assent, the accepted terms, authority, version history, price, renewal terms, and cancellation records.
The Trade Descriptions Ordinance prohibits specified unfair trade practices by traders against consumers. Sections 7A and 13E address false trade descriptions of services and misleading omissions. Claims about accuracy, privacy, security, human review, ownership, price, availability, or cancellation need evidence (Cap. 362, ss. 7A and 13E).
Those consumer provisions do not govern every business-to-business representation. Enterprise claims can still create contractual, misrepresentation, confidentiality, or negligence exposure. Product wording should match tested performance and the supplier’s actual data practices.
Section 5 of the Supply of Services (Implied Terms) Ordinance implies reasonable care and skill where it applies. The Control of Exemption Clauses Ordinance regulates covered exclusions, including negligence terms. The Unconscionable Contracts Ordinance permits relief for covered consumer contracts (Cap. 457, s. 5; Cap. 71, s. 7; Cap. 458, ss. 5 and 6).
A disclaimer can describe limits and allocate verification duties. It cannot cure a false headline claim or exclude liability that statute preserves. Consumer terms should state prices, renewal, cancellation, refunds, data uses, acceptable use, suspension, output limits, and complaint channels.
Automated decisions and discrimination
Hong Kong has no single statute governing every automated decision. Existing discrimination statutes apply when a company uses AI in employment or service provision. Relevant provisions include the Sex Discrimination Ordinance, sections 11 and 28; Disability Discrimination Ordinance, sections 11 and 26; Race Discrimination Ordinance, sections 10 and 27; and Family Status Discrimination Ordinance, sections 8 and 19.
The employer or service provider remains responsible for its decision process. Use of an external model does not transfer statutory responsibility. Selection criteria, data fields, thresholds, accommodations, and reviewer authority require legal assessment.
The discrimination statutes do not prescribe a universal bias test or human-review mechanism. Group testing, validation, documented overrides, accessible channels, and review by an authorised decision-maker are prudent controls for serious decisions. They can identify unlawful criteria or effects before deployment.
Employee monitoring also engages the Personal Data (Privacy) Ordinance where it uses personal data. The employer should define the collection purpose, necessity, access, retention, and notice. Employment policies should identify approved tools, confidential information rules, verification duties, and incident reporting.
Content and misuse
Generated content can engage laws that apply regardless of the production method. The Control of Obscene and Indecent Articles Ordinance regulates specified publication and display. Cap. 579 criminalises specified child-pornography conduct. Fraud and blackmail fall within the Theft Ordinance. Section 64 of the Personal Data (Privacy) Ordinance addresses specified doxxing acts (Cap. 390; Cap. 579, s. 3; Theft Ordinance, Cap. 210, ss. 16A and 23; Cap. 486, s. 64).
A public service should match controls to its capabilities and audience. Account restrictions, input controls, output controls, reporting, evidence preservation, and specialist escalation may be necessary for serious abuse. The legal duty depends on the project’s role, knowledge, conduct, and the applicable offence or civil claim.
Government guidance recommends labels, watermarks, metadata, or digital signatures for relevant synthetic content (Innovation, Technology and Industry Bureau, LCQ11: Regulating Use of AI-generated Synthetic Content, 15 July 2026). The product should disclose generation where users could reasonably mistake synthetic media for an authentic record.
Products involving national-security, political, public-order, or state-related material are governed by the applicable offences and the specific facts. The Hong Kong National Security Law and the Safeguarding National Security Ordinance may become relevant (Instrument A302; Instrument A305).
Corporate, tax, and dispute structure
A Hong Kong private company must have at least one director, including at least one natural-person director, and one company secretary. A sole director cannot act as company secretary. The company must maintain a registered office in Hong Kong (Companies Ordinance, Cap. 622, ss. 454, 457, 474, 475 and 658).
A non-Hong Kong company must register within one month after establishing a place of business in Hong Kong (Cap. 622, s. 776). Business registration is a separate requirement (Business Registration Ordinance, Cap. 310). The project’s ownership, staffing, funding, and operating model will determine the preferred structure.
Hong Kong profits tax applies under the territorial source rules in section 14 of the Inland Revenue Ordinance (Cap. 112, s. 14). Corporations generally pay 16.5 percent. The two-tier regime applies 8.25 percent to the first HK$2 million of assessable profits and 16.5 percent above that threshold, subject to connected-entity and statutory limitations (IRD, Profits Tax and Two-tiered Profits Tax Rates Regime).
Eligible intellectual-property income may attract a 5 percent rate on the concessionary portion of assessable profits. Eligibility depends on the statutory nexus calculation and other conditions. Copyright subsisting in software can qualify, but ownership alone does not establish the concession (IRD, Tax Concessions for Intellectual Property Income).
Qualifying Type B research and development expenditure may receive a 300 percent deduction for the first HK$2 million and 200 percent for the remainder. The expenditure, activity, taxpayer, and recordkeeping must meet the statutory conditions. Product development does not qualify automatically (IRD, Deduction for Research and Development Expenditure).
Commercial contracts may select Hong Kong law and Hong Kong-seated arbitration. The Arbitration Ordinance supports confidentiality, stays in favour of arbitration agreements, and limited statutory grounds for setting aside an award (Cap. 609, ss. 18, 20 and 81). Consumer, employment, privacy, regulatory, and criminal matters may fall outside an enterprise arbitration clause.
Territorial and sector limits
Hong Kong incorporation does not confine the project’s obligations to Hong Kong. Foreign mandatory privacy, consumer, AI, content, sanctions, and sector laws may apply where the service targets users or conducts operations abroad. A governing-law clause cannot displace those rules.
Mainland China remains a separate jurisdiction for personal information, data security, cybersecurity, algorithms, and generative AI. The Greater Bay Area standard contract is a facilitation measure for qualifying transfers between Hong Kong and the nine specified Mainland GBA cities. It does not replace the laws of either jurisdiction (PCPD, Mainland’s Personal Information Protection Law, section V).
Financial services, insurance, healthcare, telecommunications, broadcasting, education, transport, public procurement, and critical infrastructure are regulated sectors. A product used in those activities may trigger licensing, professional, conduct, records, outsourcing, or incident duties.
Advanced chips, encryption products, robotics, sensors, or controlled software may fall within strategic-commodity controls. Classification depends on technical specifications under Cap. 60 and Cap. 60G. The Trade and Industry Department’s pre-classification service can address uncertain products, but its advice does not replace a required licence (Trade and Industry Department, Pre-classification Services on Strategic Commodities).
Launch decision
Hong Kong is suitable for the assumed project after a documented product review. The release file should identify functions, users, deployment countries, data categories, training sources, vendors, integrations, and decision effects.
The company should confirm rights for material training sources and customer data. It should adopt privacy notices, processor terms, retention rules, security tests, content controls, marketing evidence, and incident procedures that match the product.
Release should stop where material training rights remain unresolved, sensitive data enters uncontrolled models, or a serious automated decision lacks lawful criteria and effective review. Regulated activity should remain blocked until the licence and regulator position are confirmed.
Subject to those conditions, Hong Kong provides a workable legal base for the assumed service. A legal update is required before launch and after any material change in data use, model capability, target market, or regulated function.
JAPAN
Summary
- The assumed service may enter the market without an AI-specific license, registration, conformity assessment, or statutory high-risk designation. Product features can activate separate licensing and supervision.
- Act No. 53 of 2025 applies to developers, providers, and business users through a broad policy statute. Article 7 requires business users to cooperate with national and local measures. Articles 13 and 16 support official guidance, incident analysis, advice, and information measures. The Act states no administrative fine or private damages claim.
- Current APPI duties attach to identifiable prompts, logs, profiles, support records, and training material. Purpose limitation, notice, security, vendor supervision, breach response, data-subject rights, transfer records, and foreign-recipient controls must be designed before collection.
- Act No. 56 of 2026 was promulgated on 17 July 2026. Its AI-relevant statistical-use routes and most substantive changes await commencement by Cabinet Order. The project cannot rely on those routes at launch unless commencement occurs and their conditions are met.
- Copyright Act Article 30-4 may cover machine learning that lacks an enjoyment purpose and does not unreasonably prejudice copyright owners. It provides no general license for retrieval output, memorization, or infringing output. Human creative contribution governs authorship. Current patent law requires a natural-person inventor.
- Contracts can allocate data rights, model use, service levels, security, indemnities, and liability between parties. Civil Code claims, consumer-law limits, third-party tort claims, and physical-product liability remain outside many contractual caps.
- Communications intermediation, public user posts, hiring decisions, regulated advice, medical functions, critical-infrastructure use, or controlled technology can trigger extra duties. Classification requires the final architecture, feature set, customer sectors, and corporate structure.
Launch posture under the AI Act
Japan's AI Act permits the assumed launch without an authorization procedure for an ordinary commercial AI service. The statute defines AI-related technology broadly and applies policy duties across research, development, provision, and business use. The assumed developer or provider is an AI business user because it will develop or provide a service using AI-related technology. (Act on Promotion of Research and Development and Utilization of Artificial Intelligence-Related Technology, Act No. 53 of 2025 (AI Act), arts. 2 and 7.)
Article 3(4) identifies crime, personal-data leakage, copyright infringement, and harm to rights as risks from improper AI development or use. Article 7 requires AI business users to pursue active use and cooperate with measures adopted by national or local authorities. Article 13 directs the State to prepare guidance that reflects international norms. Article 16 directs the State to collect information, analyze rights-infringement incidents, consider responses, and provide guidance or advice. The AI Strategy Headquarters may request cooperation from persons outside government when specially needed. (AI Act, arts. 3(4), 7, 13, 16, and 25.)
The operative text contains no commercial license, registration, conformity assessment, enumerated prohibited-practices list, administrative fine, or private damages claim. Article 7's cooperation duty still has legal effect. A ministry can use Article 16 work to issue guidance, public information, or advice after harmful incidents. The project should retain records that explain model purpose, data sources, testing, user controls, and incident decisions. Those records also support compliance with statutes that carry direct remedies.
The Cabinet Office states that the Act was promulgated and partly commenced on 4 June 2025, then fully commenced on 1 September 2025. The project should treat the Act as current law. The Cabinet approved the second AI Basic Plan under Article 18 on 14 July 2026; the plan sets government policy and does not create an independent product-authorization regime. Future statutes or orders can add product-specific duties because the Act requires periodic review of its operation. (AI Act, art. 18 and Supplementary Provisions arts. 1 and 2; Cabinet Decision, 14 July 2026.)
Operational controls under official AI guidance
The Cabinet Office guideline adopted on 19 December 2025 supplies the main official control baseline under AI Act Article 13. It creates no sanction independent of applicable law. Its proportional approach asks each developer, provider, or user to select controls by role, scale, purpose, affected persons, and risk. The AI Guidelines for Business version 1.2 add lifecycle practices for developers, providers, and users. (Cabinet Office, Guideline for Ensuring the Appropriateness of Research & Development and Utilization of Artificial Intelligence-Related Technology, AI Strategy Headquarters Decision, 19 December 2025; MIC and METI, AI Guidelines for Business, ver. 1.2, 31 March 2026.)
The assumed operator should assign a named executive owner and an operational owner. The control record should identify intended uses, excluded uses, foreseeable misuse, affected groups, model limits, training-data policy, evaluation results, monitoring thresholds, incident escalation, and change approval. Product materials should state material limitations, prohibited uses, the role of human review, and the conditions under which the provider retains prompts. Each major release should receive documented safety, security, privacy, copyright, and reliability testing.
The MIC's Guidelines on Technical Measures for Ensuring AI Security, published on 27 March 2026, support controls for prompt injection, data poisoning, model extraction, malicious output, unauthorized access, service interruption, and supply-chain weakness. METI's AI Use and Development Contract Checklist and its 9 April 2026 civil-liability guide support allocation of data rights, development duties, monitoring, and responsibility between provider and customer. These documents do not bind a court as statutes. A court could consider them when assessing reasonable care under Civil Code Article 709. No reported Japanese judgment treats compliance as a safe harbor.
A proportionate control record has greater evidentiary value than a generic policy statement. It permits the operator to show which risk was assessed, who approved the response, what test was run, and what residual limit was disclosed. A customer-facing claim that the service complies with government guidance should identify the exact document, version, scope, and exceptions.
On 18 August 2026, the government's AI-Era Intellectual Property Rights Study Group considered a revised draft Principle Code on intellectual-property protection and transparency for generative AI. The material remained a draft as of 24 August 2026 and creates no independent statutory sanction. A Japan-facing developer or provider should retain records that support proportionate disclosure about training sources and model practices, and prepare processes for rights-holder and user inquiries. (AI-Era Intellectual Property Rights Study Group, 13th Meeting, 18 August 2026, Material 1.)
Personal data, prompts, model improvement, and cross-border cloud
The Act on the Protection of Personal Information applies to identifiable prompt text, account records, logs, support tickets, profiles, and training material handled by a personal information handling business operator. A foreign operator can fall within the Act when it handles personal information acquired in connection with supplying goods or services to persons in Japan. The assumed service should therefore design for the APPI even if the contracting entity and servers are abroad. (Act on the Protection of Personal Information, Act No. 57 of 2003 (APPI), arts. 16 and 171.)
The operator must specify use purposes as precisely as reasonably possible, use personal information within those purposes, avoid improper use, acquire information properly, and notify or publish the purposes. Prior consent is generally required to acquire special-care-required personal information unless a statutory exception applies. Prompt processing for a requested answer, fraud control, service analytics, product improvement, model training, and targeted marketing are distinct operations. A single phrase stating that data may improve services can be too indefinite for a sensitive or unexpected training use. (APPI, arts. 17 through 21.)
Personal data requires security controls, employee supervision, and supervision of entrusted vendors. The contract and control record should cover access restrictions, encryption, retention, deletion, subcontractors, model-training use, incident notice, audit evidence, and return or destruction. A leakage event within the reportable categories requires a report to the Personal Information Protection Commission and notice to affected persons, subject to the statutory alternative measures where individual notice is difficult. The incident plan should preserve the facts needed for the initial and final reports. (APPI, arts. 23 through 26 and Enforcement Rules.)
Third-party disclosure normally requires prior consent and transfer records. An entrustment that stays within the disclosed purpose can fall outside the third-party rule, yet Article 25 vendor supervision still applies. A recipient outside Japan engages Article 28 unless the recipient is in a recognized jurisdiction or maintains an equivalent control system. Consent-based foreign transfer requires prescribed information about the foreign system and recipient controls. The operator must also provide information and take measures for continued implementation where Article 28 requires them. (APPI, arts. 27 through 30.)
The APPI imposes no general domestic-storage rule. Foreign hosting remains subject to security measures, foreign-transfer analysis, and disclosure of the external environment. The data map should identify each recipient, hosting country, support location, subprocesser, transfer basis, retention period, and training use. Unknown future subprocessers should not receive unrestricted approval in the customer terms.
The PPC's 2 June 2023 generative-AI notice addresses the central prompt risk. A business user that enters personal data must confirm that the input is needed within the stated use purpose. When the user's consent does not cover a provider's further use, the business user should verify that the provider will not use the input for model training or another purpose beyond producing the response. The assumed operator should offer contract and technical settings that disable training on customer content when required. (PPC, Notice on Use of Generative AI Services, 2 June 2023.)
Data-subject rights can reach retained personal data used in account, profile, moderation, or support systems. The operator should maintain an intake route for disclosure, correction, deletion, and use-stoppage requests. Model weights may not permit direct extraction of an individual's record, yet source records and surrounding datasets can remain subject to the Act. Pseudonymized or anonymized information can support some analytics when the statutory creation and use conditions are met. (APPI, arts. 32 through 46.)
Act No. 56 of 2026 will change the legal position once its relevant provisions commence. It was promulgated on 17 July 2026 and, except for specified provisions, will commence on a date set by Cabinet Order within two years. The enacted amendments create consent-free routes for third-party provision of personal data and acquisition of publicly available special-care-required personal information when the data is used only to create statistical information, including qualifying AI development, subject to disclosure, written-agreement, purpose-limitation, and onward-transfer conditions. Those AI-relevant routes were not in force as of 24 August 2026. The project cannot use them as a present basis for third-party provision or acquisition of training data. They may be relied on only after commencement and subject to the final implementation rules and PPC guidance. (Act Partially Amending the APPI and Related Acts, Act No. 56 of 2026, new arts. 30-2 and 31-3 and Supplementary Provisions; PPC promulgation materials, 17 July 2026.)
Copyright in training, retrieval, and outputs
Japan permits some machine-learning uses of protected works under Copyright Act Article 30-4. The provision applies when a work is exploited without the purpose of personally or publicly enjoying the thoughts or sentiments expressed in it. The use must stay within the extent considered necessary and must not unreasonably prejudice the copyright owner's interests in light of the work's nature, purpose, and manner of exploitation. (Copyright Act, Act No. 48 of 1970, art. 30-4.)
A training pipeline aimed at extracting statistical patterns can fall within Article 30-4 when it lacks an enjoyment purpose. A pipeline intentionally designed to output all or part of the creative expression in particular works can have a concurrent enjoyment purpose; the same can apply to deliberately limited creator-specific training intended to generate common protected expression. Similarity of style alone is not enough. The prejudice proviso can also defeat the exception where, for example, a rights holder offers a licensed database or API for information analysis and unlicensed use would unreasonably prejudice that market. The operator should record the source, acquisition method, purpose, rights status, exclusion requests, and duplicate or memorization controls for each corpus. (Agency for Cultural Affairs, General Understanding on AI and Copyright in Japan, 15 March 2024, pp. 19-22.)
Retrieval-augmented generation raises additional copyright issues. Article 30-4 can cover collection and indexing that serve non-enjoyment analysis. It does not authorize expressive output to users merely because an index was lawfully built. Article 47-5 permits limited incidental exploitation for specified computerized processing and result provision, while the use must remain minor. A product that returns substantial protected text, images, code, or music should obtain permission or redesign the output. (Copyright Act, art. 47-5; General Understanding, pp. 21-22.)
Ordinary output liability turns on the exclusive right at issue, protectable similarity, and reliance on the earlier work. The Supreme Court has treated reliance and protectable expressive similarity as distinct parts of infringement analysis. An output that shares only an idea, style, method, or unprotected element does not infringe on that basis alone. Memorized or near-verbatim passages, protected character expression, code, images, or adapted text create a different record. (Sup. Ct., 7 September 1978, Minshu Vol. 32, No. 6, p. 1145; Sup. Ct., 28 June 2001, Minshu Vol. 55, No. 4, p. 837.)
The user may be the direct actor when the user requests and publishes infringing output. Provider exposure depends on design, control, knowledge, contribution, and response under ordinary infringement and tort principles. The Agency for Cultural Affairs materials discuss possible provider responsibility, while Japan has little accumulated generative-AI case law. No current Supreme Court holding resolves provider liability for a general-purpose model. The operator should use similarity testing, protected-content filters where justified, complaint intake, evidence preservation, and repeat-abuse controls. (General Understanding, pp. 31-33.)
Training access can support an inference of reliance when an output resembles a training work, though it does not establish infringement without protected similarity. The operator should keep provenance records and test known memorization risks. A complaint process should distinguish source removal, output suppression, user conduct, and preservation of evidence. Terms should prohibit rights-infringing prompts and publication while preserving the operator's right to investigate and restrict misuse.
A website's access terms, technical restrictions, copyright in databases, confidentiality, and the Unfair Competition Prevention Act can apply even when Article 30-4 addresses copyright. The source review should therefore cover more than copyright status. Scraping that bypasses access controls or acquires secret data can create separate liability.
Ownership of AI-assisted output and patentable inventions
Japanese copyright protects a work that creatively expresses human thoughts or sentiments. An autonomous machine output lacks a human author. A person can obtain copyright in an AI-assisted result when the person's creative intent and contribution shape the protected expression through prompt design, selection, iteration, arrangement, or editing. Routine instructions and acceptance of an output may be insufficient. (Copyright Act, arts. 2(1)(i), 15, and 17; Agency for Cultural Affairs, General Understanding, pp. 33-36.)
The operator should avoid promising that every output is owned by the customer as copyright. The contract can assign any provider-held rights, grant broad use rights, and allocate claims between the parties. It cannot create copyright where the statute recognizes no human authorship. Enterprise customers should retain records of human choices and revisions for valuable works. Employment and contractor agreements should address authorship, assignment, moral-right handling, confidential material, and prompt records.
Current patent law requires a natural-person inventor. On 30 January 2025, the Intellectual Property High Court upheld dismissal of an application that named DABUS as the autonomous inventor. The court held that the existing Patent Act assumes inventions made by natural persons and left AI-only inventions to legislative policy. A false human designation would create inventorship and entitlement risk. (IP High Ct., 30 January 2025, 2024 (Gyo-Ko) 10006; Patent Act, Act No. 121 of 1959, arts. 2, 29, and 184-5.)
AI-assisted inventions can remain patentable when one or more natural persons made the inventive technical contribution. The project should record the problem definition, technical choices, experiments, rejected paths, model role, and each person's contribution. Employee-invention rules and internal remuneration arrangements should cover AI-assisted work. The operator should not list a manager, prompt writer, or model owner as an inventor without the required contribution. (Patent Act, art. 35.)
Protecting datasets, prompts, weights, and confidential inputs
Trade-secret protection depends on statutory conditions rather than the asset's commercial value alone. Information must be useful technical or business information, managed as secret, and not publicly known. Model weights, source code, system prompts, evaluation sets, customer inputs, red-team findings, data-cleaning methods, and deployment records can qualify when those conditions are proved. (Unfair Competition Prevention Act, Act No. 47 of 1993 (UCPA), art. 2(6).)
Secret management requires conduct that communicates and maintains restricted status. The operator should classify assets, limit access by role, mark confidential records, log exports, restrict local copies, review departing personnel, and bind vendors by use and security terms. A cloud transfer does not by itself destroy secrecy when the provider preserves restricted access. Public disclosure, broad internal sharing, or uncontrolled model training can defeat the claim.
The UCPA also protects certain shared data with limited access, subject to its separate elements and exclusions. That route can matter for valuable datasets shared under controlled commercial terms even when secrecy is not maintained. The project should identify whether each dataset will remain secret, be shared under limited access, be licensed broadly, or be published. Mixing those categories weakens enforcement. (UCPA, art. 2(7).)
Customer confidential information should not enter provider training by default when the service is sold as a confidential business tool. The enterprise contract should state permitted processing, retention, human review, subprocessers, training use, derived data, and deletion. Technical tenant separation, no-training settings, output access controls, and support-access approval should match those promises.
Contract, tort, and product liability
Contract liability will govern many disputes between the operator and its customer. Civil Code Articles 415 and 416 permit damages for nonperformance within the statutory scope. Standard terms require proper incorporation, and unilateral amendments must satisfy Civil Code rules for standard-form contracts. The service contract should define the service, model version, acceptable use, customer data rights, output status, security duties, availability, change process, suspension rights, and remedies. (Civil Code, Act No. 89 of 1896, arts. 415, 416, and 548-2 through 548-4.)
A limitation clause can allocate commercial risk in a business contract. It does not bind an injured third party and may fail under mandatory law, public policy, or the Consumer Contract Act. The clause should separate direct damages, data-loss remedies, confidentiality breaches, intellectual-property claims, personal-data incidents, willful conduct, and gross negligence. Indemnities should address control of defense, settlement consent, notice, loss-reduction steps, and cooperation.
Civil Code Article 709 supports tort liability when intentional or negligent conduct unlawfully harms another. Article 715 can impose employer liability for employee conduct. Foreseeability, duty, breach, causation, damage, warnings, human review, and product control will shape an AI claim. METI's April 2026 civil-liability guide distinguishes systems that support a human decision from systems that substitute for one. Greater provider or user reliance can increase the need for validation, monitoring, and intervention. (Civil Code, arts. 709, 715, and 722; METI, Guide on Interpretation and Application of Civil Liability in AI Use, ver. 1.0, 9 April 2026.)
The operator should avoid promises of factual accuracy or suitability beyond tested conditions. High-consequence uses need calibrated warnings, source display where available, reliable uncertainty information, human review, and a route to stop automated action. Logs should capture model version, material settings, retrieved sources, safety interventions, and user action when proportionate. These records can address causation and allocation after an incident.
The Product Liability Act applies to a defective manufactured or processed movable. Standalone cloud software ordinarily falls outside that statutory definition. A software-related defect in a robot, vehicle component, medical device, appliance, or other movable can support a product claim. A physical deployment must therefore address safety, warnings, integration, and recall. (Product Liability Act, Act No. 85 of 1994, arts. 2 and 3.)
The project should maintain a claim-response protocol. It should preserve the relevant model and configuration, secure logs, suspend a dangerous feature where justified, assess regulator notice, coordinate with customers, and document remedial action. A blanket disclaimer that outputs are informational will not cure negligent design or a misleading sales claim.
Consumer terms, advertising, and online sales
A consumer-facing service must satisfy the Consumer Contract Act. A consumer may rescind for specified misrepresentations or improper solicitation. Clauses that wholly exclude the operator's damages liability for nonperformance or related tort are void, and clauses that partially exclude liability for intentional or grossly negligent conduct are also void. Article 8-2 invalidates clauses that force consumers to waive cancellation rights arising from the operator's default or give the operator authority to determine whether those rights exist. Article 10 can invalidate other one-sided terms that depart from default law against the consumer's interests. The operator should use readable Japanese terms and a direct purchase flow when targeting consumers in Japan. (Consumer Contract Act, Act No. 61 of 2000, arts. 4, 8, 8-2, and 10.)
Advertising claims about accuracy, safety, privacy, human review, training use, benchmark results, output ownership, or professional suitability require current substantiation. Article 5 of the Act against Unjustifiable Premiums and Misleading Representations prohibits misleading representations about quality, content, price, and transaction terms. A claim that prompts are not used for training must match every model, vendor, support channel, and default setting. (Act against Unjustifiable Premiums and Misleading Representations, Act No. 134 of 1962, art. 5.)
Online subscriptions can engage the Act on Specified Commercial Transactions. Required seller, price, payment, renewal, cancellation, and final-confirmation information should appear before the order is placed. Trial conversion, annual plans, cancellation friction, and automatic renewal must satisfy the applicable consumer rules. The operator should preserve the version shown to each purchaser. (Act on Specified Commercial Transactions, Act No. 57 of 1976.)
There is no horizontal statute requiring every ordinary generative-AI output to carry an AI label as of 24 August 2026. A missing label can still make a statement misleading when users are likely to believe a human reviewed or created the content. Sector rules, election rules, impersonation claims, and platform policies can produce a different result. Product design should disclose machine generation where identity, provenance, reliance, or safety makes the fact material.
Telecommunications and public-content platform classification
The Telecommunications Business Act can apply when the operator provides telecommunications services to meet another person's demand. Registration or notification depends on the service and facilities. A one-to-one AI assistant that receives a user's content and returns the provider's own response may fall within the Article 164(1)(iii) exemption from most of the Act if it installs no telecommunications line facilities and does not intermediate communications between other persons. User-to-user communications, agent or external-service relays, or other features that transmit another person's communication can change that result. The final architecture requires classification under Articles 2, 9, 16, and 164. (Telecommunications Business Act, Act No. 86 of 1984.)
Article 4 protects the secrecy of communications handled by a telecommunications carrier and, through Article 164(3), communications handled by businesses within the listed exemptions. The duty can reach content and associated facts. Prompt inspection, model improvement, advertising, safety review, and disclosure to vendors must be tested against consent and statutory necessity. Article 27-12's external-transmission rules can also apply to covered telecommunications carriers and Article 164(1)(iii) businesses. Cookie, SDK, analytics, advertising, and model-observability flows must also comply with the external-transmission rules. (Telecommunications Business Act, arts. 4, 27-12, and 164, and applicable MIC rules.)
A public sharing, community, feed, marketplace, or user-publication feature can engage the Act on Measures Against Rights Infringement Arising from Distribution of Information by Specified Telecommunications, known as the Information Distribution Platform Act. The Act limits provider liability in defined conditions and supports sender-information disclosure. Amendments effective 1 April 2025 impose complaint, investigation, notice, published-standard, staffing, and transparency duties on providers designated by MIC for large public services. (Act No. 137 of 2001, as amended by Act No. 25 of 2024.)
A private assistant with no user-to-public dissemination can fall outside the public-content provisions. A sharing link, public gallery, agent marketplace, or community prompt library can create covered information distribution. The operator should classify each feature before release, establish a rights complaint route, retain sender records lawfully, and prepare deletion procedures that respect user notice and evidence preservation. The enhanced large-platform duties apply only after the statutory criteria and designation are met.
Competition and data contracting
The Antimonopoly Act applies to AI markets without a separate AI exemption. Agreements or conduct that unreasonably restrain trade, constitute private monopolization, or fall within unfair trade practices can draw JFTC action. The analysis can reach model access, compute supply, cloud credits, data, distribution, plugins, app stores, and partnerships. (Act on Prohibition of Private Monopolization and Maintenance of Fair Trade, Act No. 54 of 1947, arts. 2, 3, and 19.)
The JFTC's Generative AI Market Survey Report version 2.0, published on 16 April 2026, identifies competition issues across infrastructure, models, applications, data, and related transactions. Product tying, discriminatory access, self-preference, exclusionary exclusivity, coordinated pricing, and control of scarce inputs require review when the operator holds market power or deals with a stronger platform. The report is an official market study rather than a finding that the assumed project violates the Act.
Data and model contracts can also create abuse-of-superior-bargaining-position concerns. A stronger party should not extract customer data, intellectual property, evaluation results, or unilateral risk without fair disclosure and commercial justification. The Guidelines Concerning Abuse of Superior Bargaining Position, etc. for Appropriate Transactions Involving Intellectual Property Rights, Know-how and Data, issued on 24 June 2026 by the JFTC, the Small and Medium Enterprise Agency, and the JPO, provide current agency views. Contract changes, API deprecation, output restrictions, and data reuse should follow disclosed procedures.
The assumed entrant has no stated market power. Baseline controls should still bar employee discussion of competitor prices, output restrictions aimed at coordinated conduct, and exchange of competitively sensitive customer information. Partnerships with a cloud, model, device, or distribution provider require competition review when they contain exclusivity, parity, tying, preferential access, or restrictions on rival models.
Cybersecurity and incident response
The APPI creates direct security and breach duties for personal data. The Unauthorized Computer Access Act, UCPA, contracts, sector rules, and general tort law add consequences for intrusion, theft, disclosure, or deficient controls. The Basic Act on Cybersecurity mainly organizes national policy, while it also informs official critical-infrastructure work. (APPI, arts. 23 through 26; Act on Prohibition of Unauthorized Computer Access, Act No. 128 of 1999; Basic Act on Cybersecurity, Act No. 104 of 2014.)
The AI threat model should cover prompt injection, retrieval poisoning, malicious files, tool misuse, model extraction, membership inference, data exfiltration, unsafe code, privileged-agent action, supply-chain compromise, and service interruption. Controls should include access separation, secret handling, input and output checks, sandboxing, tool permissions, rate limits, anomaly detection, backup, rollback, and vendor assessment. Testing should match the model's actual tools and data access.
Incident rules should name the decision-maker, escalation path, evidence owner, customer notice owner, PPC assessment owner, and service-suspension authority. The team should preserve prompts, outputs, retrieved sources, account events, model version, configuration, safety-system results, and vendor notices. Retention should remain proportionate and consistent with disclosed purposes. A response playbook should distinguish personal-data leakage, security intrusion, harmful output, copyright complaint, model defect, and public misinformation.
A customer can rely on security claims in sales materials, data-processing terms, or audit reports. The operator should state the tested scope and date instead of promising absolute security. Material changes to hosting, base model, subprocessers, logging, or agent permissions should pass change control before deployment.
Employment and high-consequence decision support
Japan has no general ban on AI-assisted recruitment. The employer remains responsible for the selection process. MHLW guidance states that each selection method, including AI, must preserve open access and use criteria based on the applicant's ability and aptitude for the job. Sex discrimination in recruitment is prohibited, and job-seeker information must be handled within employment-law and APPI limits. (Employment Security Act, Act No. 141 of 1947; Act on Equal Opportunity and Treatment between Men and Women in Employment, Act No. 113 of 1972, art. 5; MHLW Fair Recruitment and Selection materials.)
An employer or vendor should avoid features that infer family origin, beliefs, medical history, social status, or another sensitive trait unrelated to the role. Training data and validation sets should be checked for proxy discrimination and historic bias. The system should produce evidence that a reviewer can assess rather than a score with no traceable basis. A human reviewer should have authority to change the result and should receive training on the model's limits.
Applicant notices should identify the decision purpose, main data categories, source, retention, external vendors, and contact route. A vendor contract should allocate APPI duties, security, audit evidence, model changes, bias testing, incident notice, deletion, and support for complaints. Automated monitoring of employees can also engage privacy, labor consultation, work rules, and proportionality concerns.
The assumed general-purpose service should prohibit customers from using an unvalidated configuration as the sole basis for employment, credit, housing, education, medical, or comparable high-consequence decisions. A sector module can be released only after its legal basis, validation protocol, human-review design, and complaint route are documented.
Sector licensing, foreign investment, and export controls
The baseline result changes when the AI performs a regulated function. Software intended for diagnosis, treatment, or another medical purpose can qualify as a medical device under the Pharmaceuticals and Medical Devices Act. PMDA classification, quality, clinical evidence, approval or certification, post-market duties, and advertising rules can apply before sale. A wellness label will not control if the intended purpose and functions are medical. (Act on Securing Quality, Efficacy and Safety of Products Including Pharmaceuticals and Medical Devices, Act No. 145 of 1960; PMDA Software as a Medical Device materials.)
Financial institutions and regulated intermediaries remain subject to the Banking Act, Financial Instruments and Exchange Act, Insurance Business Act, Payment Services Act, supervisory guidelines, outsourcing controls, and customer-protection duties. The FSA's AI Discussion Paper version 1.1, published on 3 March 2026, does not displace those statutes. A general model that gives regulated advice, makes underwriting decisions, executes trades, or supports anti-money-laundering controls needs a product-specific review.
Autonomous vehicles, aviation, drones, industrial safety, education, government procurement, defense, and critical-infrastructure deployments carry separate approval, safety, record, and procurement duties. The Economic Security Promotion Act can affect specified critical infrastructure and supply chains. The operator should use a release gate that blocks these sectors until the relevant authority, intended use, responsible operator, and assurance evidence are identified.
Foreign Exchange and Foreign Trade Act controls can affect exports of listed technology, encryption, advanced computing items, technical assistance, and transactions involving sanctioned destinations or end uses. Inward-investment screening can attach to investment in designated sectors. An ordinary cloud AI service is not automatically controlled. The project must classify the technology, destination, end user, end use, corporate activity, and investment structure before relying on that baseline. (Foreign Exchange and Foreign Trade Act, Act No. 228 of 1949.)
Governing law, forum, and enforcement
A Japanese-law clause is generally permitted, and parties can choose another law for a contract. The Act on General Rules for Application of Laws preserves mandatory consumer protections in specified cases and applies separate rules to tort and product liability. A foreign-law clause therefore does not remove APPI, competition, telecommunications, product, sector, or other public-law duties that apply in Japan. (Act on General Rules for Application of Laws, Act No. 78 of 2006, arts. 7, 8, 11, 17, 18, and 20.)
Japanese courts can exercise international jurisdiction under the Code of Civil Procedure when statutory connecting factors are met. Consumer and employment disputes receive special protection, and exclusive foreign-court clauses face limits. A B2B forum clause should identify the court and scope. Consumer terms should not assume that an overseas forum will bar proceedings in Japan. (Code of Civil Procedure, Act No. 109 of 1996, arts. 3-2 through 3-10.)
Arbitration can suit negotiated B2B contracts, subject to validity, scope, interim relief, and enforcement planning. Under Supplementary Provisions Article 3 of the Arbitration Act, a consumer may cancel a pre-dispute consumer arbitration agreement unless the consumer has initiated the arbitration. Japanese court proceedings use Japanese, so evidence, notices, logs, and contracts can require certified or reliable translation. The operator should preserve Japanese-facing terms and the exact version accepted by each user. (Arbitration Act, Act No. 138 of 2003, art. 13 and Supplementary Provisions art. 3; Court Act, Act No. 59 of 1947, art. 74.)
Regulatory enforcement depends on the statute. The PPC can investigate and issue recommendations or orders under the APPI, with criminal or administrative consequences for specified violations. The JFTC can investigate and impose statutory remedies under competition law. Consumer, telecommunications, platform, sector, civil, and criminal authorities retain their own powers. The AI Act does not consolidate those routes into one regulator.
THE BRITISH VIRGIN ISLANDS
Summary
- There is no horizontal BVI statute regulating artificial intelligence as a technology as of 24 August 2026. Sector rules, future enactments, common-law duties, and foreign laws may still apply.
- The Data Protection Act, 2021 is the principal BVI privacy statute. It can apply to a BVI-established controller and, subject to its territorial rules, to a non-BVI controller using equipment in the Territory. AI design must therefore map controller/processor roles, lawful processing, sensitive data, security, retention, data-subject rights, automated decisions and transfers (Data Protection Act, 2021).
- Electronic records, signatures and contracts receive statutory recognition, but the Electronic Transactions Act, 2021 contains exclusions. Wills/testamentary instruments, certain real-property, trust, power-of-attorney and other formal instruments cannot safely be treated as ordinary e-signature transactions without checking the statutory schedule (Electronic Transactions Act, 2021).
- An AI service giving personalized investment recommendations may constitute investment advice under SIBA. The electronic-publication/information exclusion and the separate incidental professional or non-investment-business advice exclusion have different conditions and must not be merged (Securities and Investment Business Act, 2010, as amended).
- A project performing exchange, transfer, custody, administration or specified financial services involving virtual assets in or from within the BVI may require VASP registration. Token terminology is not determinative; the asset and actual service must be classified (Virtual Assets Service Providers Act, 2022, as amended; Anti-Money Laundering Regulations, 2008; Anti-Money Laundering and Terrorist Financing Code of Practice, as amended).
- A BVI entity that owns or licenses model, software, patent, brand or other IP can enter the economic-substance regime if it conducts “intellectual property business.” Classification turns on the statutory activity and income, not the asset label alone. High-risk IP carries a particularly demanding presumption (Economic Substance (Companies and Limited Partnerships) Act, 2018, as amended; Rules on Economic Substance in the Virgin Islands; current BVI International Tax Authority guidance).
- Current corporate-transparency compliance uses a 10% beneficial-ownership threshold for the filing definition. The separate 25% figure associated with a narrower inspection/access mechanism is not the filing threshold (BVI Business Companies and Limited Partnerships (Beneficial Ownership) Regulations, 2024; BVI Financial Services Commission 2025-2026 corporate and beneficial-ownership circulars, FAQs and filing notices).
- New and continuing companies must comply with current filing timelines for registers of members and directors; changes also have short filing windows. Any acquired or legacy company should be checked through its registered agent before use (BVI Business Companies Act, Revised Edition 2020, as subsequently amended; BVI Business Companies (Amendment) Act, 2024 and related 2024 amendments and regulations; BVI Financial Services Commission 2025-2026 corporate and beneficial-ownership circulars, FAQs and filing notices).
- The Virgin Islands remained under FATF increased monitoring on 19 June 2026. FATF does not call for automatic enhanced due diligence solely because of increased-monitoring status, but banks, investors and counterparties may apply their own risk policies (Financial Action Task Force, Jurisdictions under Increased Monitoring, 19 June 2026).
- At the 17 February 2026 EU update, the BVI was not in Annex I of the EU tax list and remained in Annex II. This status is dynamic and should be refreshed at signing and closing (Council of the European Union, EU list of non-cooperative jurisdictions for tax purposes, 17 February 2026).
Suitability by proposed role
Generally suitable for a conventional BVI parent or financing vehicle; conditionally suitable for an IP-owning/licensing entity; ordinarily unsuitable as the only operating entity where the substantive people, data, customers or regulated functions are elsewhere. A financial-AI, payment, custody, exchange, or token project must be classified under the FSC regime before launch.
- Group parent / equity holding company: Generally suitable. Maintain corporate filings, beneficial-ownership data, governance, accounting records and foreign tax analysis. Confirm any economic-substance classification.
- Financing or treasury vehicle: Conditional. Financing-and-leasing economic substance, transfer pricing, sanctions, lender requirements and any regulated financing activity must be analyzed.
- IP owner / model licensor: Higher-risk conditional use. Establish chain of title; classify IP business; evaluate high-risk IP rules, substance, transfer pricing and where development/control actually occur.
- AI SaaS operating company: Possible but fact-sensitive. Data protection, consumer, contracting, cyber, employment and foreign-market laws follow the operations and users; the place of incorporation does not control their application.
- Robo-adviser / financial-AI provider: Licensing screen required. Test SIBA investment-business categories and each excluded activity separately. Do not rely on an “information” label or automated delivery alone.
- Token, exchange, custody or payment platform: High regulatory sensitivity. Test VASP, SIBA, money-services, AML/CFT, sanctions and foreign securities/payment laws before launch.
The analysis distinguishes entity law from operating law. BVI incorporation establishes the company, governance and BVI regulatory nexus; it does not disapply the mandatory law of a country where personnel, management, users, data subjects, servers, sales or regulated effects are located.
Typical vehicle and formation
A company limited by shares under the BVI Business Companies Act is the conventional vehicle. It requires a BVI registered office and licensed registered agent. The constitutional documents, shareholder arrangements and reserved-matter matrix should allocate authority over model releases, safety controls, IP licensing, data use, material outsourcing, financing, token issuance and regulated activities (BVI Business Companies Act, Revised Edition 2020, as subsequently amended).
BVI law offers substantial constitutional flexibility, but directors remain responsible for exercising their powers for proper purposes, complying with the Act and the company’s memorandum and articles, managing conflicts, and applying the statutory solvency test to distributions. A founder-controlled board should still document material decisions and related-party arrangements.
Registers and filing deadlines
The current regime requires filing of the register of members with the Registrar within 30 days after incorporation or continuation and filing changes within 30 days. The register of directors must be filed on the shorter statutory timeline, generally 15 days after the relevant appointment or change, and the first director is to be appointed within the current statutory period. Operational responsibility normally sits with the registered agent, but the company must supply accurate information promptly (BVI Business Companies Act, Revised Edition 2020, as subsequently amended; BVI Business Companies (Amendment) Act, 2024 and related 2024 amendments and regulations; BVI Financial Services Commission 2025-2026 corporate and beneficial-ownership circulars, FAQs and filing notices).
Because transition periods for pre-existing entities had expired by 24 August 2026, an acquired shelf, dormant or legacy company should not be assumed compliant. Obtain a registered-agent certificate or filing extract confirming: current members; current directors; beneficial owners; registered office and agent; annual fees; annual financial returns; and any penalties or restrictions.
The register-of-members and register-of-directors filings are distinct from internal governance records. The project should maintain executed subscription documents, share certificates where used, board and shareholder resolutions, option or incentive records, director consents, conflict disclosures and evidence supporting each filing.
Accounting records and annual financial return
A BVI company must keep records sufficient to explain its transactions and enable its financial position to be determined with reasonable accuracy. The records may be maintained outside the BVI if the prescribed information and access are supplied to the registered agent. Record-retention and location decisions should also account for tax, audit, sanctions and litigation holds (BVI Business Companies Act, Revised Edition 2020, as subsequently amended).
Subject to statutory exemptions, a company must file an annual financial return with its registered agent within the prescribed period, ordinarily nine months after the end of the relevant financial year. The return is not a substitute for any group audit, tax filing, economic-substance report, regulatory return or management accounts (BVI Business Companies annual financial return legislation and BVI Financial Services Commission guidance).
Beneficial ownership and corporate transparency
For beneficial-ownership filing, the relevant ownership threshold is 10%, together with control-based limbs. A 25% threshold must not be substituted. The 25% figure belongs to a narrower access/inspection context and does not redefine who must be identified and filed (BVI Business Companies and Limited Partnerships (Beneficial Ownership) Regulations, 2024; BVI Financial Services Commission 2025-2026 corporate and beneficial-ownership circulars, FAQs and filing notices).
The company, its registered agent and the Registrar-facing filing process must identify the natural person or persons who ultimately own or control the entity under the current statutory test. The analysis cannot stop at the immediate shareholder. It must trace through holding companies, nominees, trusts, partnerships, voting arrangements, veto rights and other control mechanisms (BVI Business Companies and Limited Partnerships (Beneficial Ownership) Regulations, 2024).
New entities and changes are subject to short filing periods, commonly 30 days under the beneficial-ownership regulations. Contractual covenants should therefore require founders, investors and upstream entities to provide complete information and notify changes well before the statutory deadline.
Beneficial-ownership information is not equivalent to an unrestricted public shareholder register. Access is governed by the statutory and regulatory regime. Confidentiality should never be presented as anonymity, and onboarding banks, regulators, service providers and competent authorities will require full information.
AI-specific regulation and product governance
There is no horizontal BVI AI act, general-purpose-model regime, or BVI equivalent of the EU AI Act as of 24 August 2026. The product is instead governed through existing corporate, data-protection, consumer, cybercrime, contract, IP, financial-services, AML, sanctions, employment and common-law rules.
The absence of a horizontal AI statute does not reduce the need for governance. A BVI board approving a high-impact or externally deployed model should receive documented information on intended use, known limitations, evaluation results, data provenance, security, human escalation, incident response, vendor dependencies, regulatory classification and insurance. These controls help evidence reasonable governance and support compliance in the operating markets.
Where the system is marketed into the EU, UK, United States or another regulated market, local AI, product, discrimination, consumer, professional-services, privacy and sector laws can apply irrespective of BVI incorporation. The project should maintain a market-entry register rather than treating “offshore” incorporation as a conflicts-of-law answer.
Data protection, training data and automated decisions
The Data Protection Act, 2021 is the principal BVI privacy statute. Its application should be tested for a BVI-established controller and for any non-BVI controller using equipment in the Territory, subject to the statutory territorial formulation and transit limitation. The project should identify each controller, joint controller and processor rather than placing all group entities under a generic “platform” label (Data Protection Act, 2021).
For each processing activity, record the purpose, categories of data and data subjects, source, recipient, retention period, security measures, transfer path and applicable processing condition. Sensitive personal data requires the more specific statutory treatment. Consent should not be used mechanically where it is not informed, specific, freely given or operationally revocable.
The BVI Act should not be described as an EU-style adequacy regime. A transfer outside the BVI must be tested against the Act’s comparable-protection rule and the available statutory exceptions. Consent is not a universal substitute for safeguards. Vendor contracts should address purpose limitation, confidentiality, security, onward transfers, deletion, audit support and incident cooperation (Data Protection Act, 2021).
Because most AI infrastructure and model providers are outside the BVI, transfer mapping is a core design task. The BVI analysis should be coordinated with GDPR, UK GDPR, state privacy, localization and sector rules wherever those regimes apply. The strictest applicable contract and engineering control may be preferable to fragmented country configurations.
The project should confirm the current Information Commissioner process, complaint route and enforcement practice immediately before launch. It should not infer non-enforcement from the maturity or resourcing of the supervisory regime.
Electronic contracts, signatures and evidence
The Electronic Transactions Act, 2021 generally supports legal recognition of electronic information, formation by electronic means, electronic signatures and retention of electronic records. The Act supports online terms, enterprise agreements, consents, API orders, board processes and many financing documents where the statutory reliability and availability requirements are met (Electronic Transactions Act, 2021).
The Act is not universal. Its exclusions include wills and testamentary instruments, together with specified formal transactions involving real property, trusts, powers of attorney and other listed instruments. The statutory exclusion schedule must be checked for each document type. A contract process should also verify witnessing, notarization, apostille, filing, registry and governing-law requirements outside the Act.
For enforceability and evidence, preserve the version presented, assent mechanism, timestamp, account identity, authentication data, IP/device logs where proportionate, amendment history and a durable copy available to the user. Terms should not claim that an AI system has authority to bind a customer unless agency and authentication have been expressly established.
Intellectual property, model assets and data rights
BVI copyright and trade-mark legislation provides the local rules for software, documentation, content and branding, but an AI project’s commercially relevant rights are multinational. Ownership and infringement will often be assessed where development, copying, training, deployment or market use occurs (Copyright Act, 2020; Trade Marks Act, 2013).
The BVI company should receive executed assignments from founders, employees and contractors covering source code, model architecture, weights to the extent transferable, datasets, evaluation suites, prompts, documentation, inventions, domain names and business identifiers. The agreement should address background IP, moral-rights consents where legally effective, further-assurance obligations and the governing law of the assignment.
Training-data rights require a separate ledger. A right to access data is not necessarily a right to reproduce it for training, generate embeddings, create derivative datasets, commercialize model outputs, or retain data after termination. Privacy permission is also distinct from copyright, database, confidentiality and contract permission.
Open-source and open-weight components should be inventoried with exact versions, licences and dependency paths. Copyleft, attribution, field-of-use, model-output and responsible-AI licence terms require legal review. Production releases should be blocked where provenance or licence obligations are unresolved.
Generated-output terms should allocate use rights without promising exclusive copyright in material that may be unprotectable or third-party-derived. The project should state material limitations, provide a notice-and-takedown channel, and reserve rights to investigate abusive or infringing use.
Financial-services perimeter
SIBA’s exclusion for qualifying information supplied through electronic or media channels and its separate exclusion for advice incidental to a profession or business that is not otherwise investment business and is not separately remunerated are distinct. Their conditions cannot be combined into a single generic “automated information” exemption (Securities and Investment Business Act, 2010, as amended).
An AI tool can cross into investment advice where it gives a person recommendations or opinions about acquiring, disposing of, holding or exercising rights in investments. Personalization, portfolio optimization, suitability scoring, trading signals, model portfolios, paid alerts and integration with execution increase regulatory risk. Calling the output “education,” “research” or “information” is not determinative.
The electronic-information exclusion must be tested against its own statutory conditions, including the nature and principal purpose of the publication or service. The incidental professional/non-investment-business advice exclusion has different requirements, including the context of the other business and remuneration. A project should obtain a written perimeter memorandum before offering recommendations from or through a BVI entity.
Where the project deals, arranges, manages, safeguards assets, operates a market or performs another SIBA activity, the analysis extends beyond investment advice. Foreign licensing may also apply where customers or market effects are located (Securities and Investment Business Act, 2010, as amended; Regulatory Code, 2009, as amended; applicable BVI Financial Services Commission licensing materials).
Virtual assets, payments and money services
The VASP Act requires registration for specified virtual-asset services carried on in or from within the BVI. Relevant functions include exchange, transfer, custody or administration and specified financial services connected with virtual-asset issuance or sale. Classification turns on the token or asset and actual function, not labels including “utility,” “credit,” “point” or “AI token.” (Virtual Assets Service Providers Act, 2022, as amended)
A token can also be an investment under SIBA, and a service can fall within both VASP and investment-business regimes. Fiat payment processing, money transmission, stored value, lending or treasury services may engage the Financing and Money Services Act or other financial-services legislation (Securities and Investment Business Act, 2010, as amended; Virtual Assets Service Providers Act, 2022, as amended; Financing and Money Services Act, 2009, as amended).
A regulatory sandbox can provide a supervised testing route where accepted, but it should not be presented as an automatic licence waiver. The project must confirm admission conditions, permitted activity, customer limits, disclosures and exit requirements (Financial Services (Regulatory Sandbox) Regulations, 2020; BVI Financial Services Commission innovation materials).
AML/CFT and financial crime
A regulated financial or virtual-asset business will require governance, customer due diligence, beneficial-owner identification, risk assessment, transaction monitoring, suspicious-activity escalation, recordkeeping, sanctions screening, staff training, independent testing and travel-rule controls where applicable (Anti-Money Laundering Regulations, 2008; Anti-Money Laundering and Terrorist Financing Code of Practice, as amended).
Even an unregulated AI SaaS company should implement proportionate counterparty and payment screening where it serves high-risk markets, sells dual-use capability, accepts unusual payment methods or permits enterprise automation. Contractual restrictions without technical and operational enforcement are insufficient.
Economic substance and tax architecture
The Economic Substance Act applies to legal entities carrying on one or more defined relevant activities, subject to the statutory tax-residence and other rules. Relevant activities include financing and leasing, headquarters, holding business, intellectual property business, distribution and service centre business, and regulated sectors (Economic Substance (Companies and Limited Partnerships) Act, 2018, as amended).
An AI company is not automatically engaged in “intellectual property business” merely because software or a model is valuable. The statutory test focuses on holding an intellectual-property asset from which separately identifiable income accrues. Licensing income, royalties and group arrangements are important indicators. An entity may also fall into another relevant activity depending on what it does (Economic Substance (Companies and Limited Partnerships) Act, 2018, as amended; Rules on Economic Substance in the Virgin Islands; current BVI International Tax Authority guidance).
For a relevant activity, assess direction and management in the BVI, core income-generating activity, adequate expenditure, premises and qualified personnel, and permitted outsourcing in the BVI with appropriate supervision. Documentary substance should follow actual decision-making, not meeting minutes created after the event.
High-risk IP
A BVI entity that acquired IP from a connected person, funded development outside the BVI, and earns income from licensing or selling that IP to connected persons can enter the high-risk IP rules. The presumption of non-compliance is difficult to rebut. Do not transfer model IP to a BVI entity merely to book royalties without a defensible people, control, value-creation and tax structure (Economic Substance (Companies and Limited Partnerships) Act, 2018, as amended; Rules on Economic Substance in the Virgin Islands; current BVI International Tax Authority guidance).
Tax
The conventional BVI company is commonly used in a tax-neutral domestic environment, but “BVI tax neutral” is not equivalent to “the project is tax free.” Confirm the current BVI fiscal treatment for the company and period, including any payroll tax, property or land-related duty, licence fees and sector charges (BVI income-tax, payroll-tax and related fiscal legislation and official guidance).
The principal tax exposures frequently arise elsewhere: corporate residence based on central management and control; permanent establishments; controlled-foreign-company rules; transfer pricing; withholding taxes; VAT/GST/sales tax; digital-services rules; employee equity taxation; and the OECD global minimum-tax rules for in-scope groups. The IP and financing structure should be designed with counsel in every material jurisdiction, not reverse-engineered after launch.
Sanctions, export controls and restricted uses
The BVI implements applicable UK sanctions measures extended to the Territory through the relevant legal instruments. A BVI company must not deal with frozen funds or economic resources, make funds or economic resources available where prohibited, or participate in circumvention. Current BVI reporting and licensing channels should be confirmed for the applicable regime (applicable UK sanctions regulations and Overseas Territories Orders; current BVI implementation guidance).
AI capability can create additional export-control and end-use risk under the laws of the countries from which models, chips, code, cloud access, technical assistance or personnel are supplied. BVI incorporation does not neutralize those controls. The project should classify high-performance compute, model weights, cybersecurity functionality and end users before export or access.
Implement customer and beneficial-owner screening, geographic controls, restricted-use terms, access revocation, payment screening, escalation and records. Enhanced review is warranted for military, intelligence, surveillance, cyber exploitation, biometric identification, weapons, sanctions-evasion or high-risk government use.
Consumer protection, marketing and product claims
BVI consumer law can apply to relevant BVI-facing conduct, while the consumer and unfair-practices laws of customer markets may apply extraterritorially or as mandatory law. Product claims should be evidence-based, appropriately qualified and consistent across website, sales material, demonstrations, model cards and contracts (Consumer Protection Act, 2020).
Do not market a system as accurate, unbiased, secure, compliant, autonomous, confidential or suitable for a regulated purpose unless the claim is supported in the stated context. Material limitations, human-review requirements, data-use practices, subscription renewal, usage charges and refund rules should be prominent rather than hidden in generic terms.
Terms should allocate risk but should not attempt to exclude non-excludable duties, misrepresentation, fraud, deliberate misconduct or mandatory consumer rights. Enterprise contracts should define service levels, data ownership, security, audit cooperation, acceptable use, suspension, output risk, IP claims, indemnities, liability caps, regulatory change and termination assistance.
Cybersecurity and operational resilience
The Data Protection Act’s security obligations, the Computer Misuse and Cybercrime Act, sector rules, contracts and foreign cyber laws collectively create the baseline (Data Protection Act, 2021; Computer Misuse and Cybercrime Act, 2014). An AI security program should address conventional cloud and application threats together with model-specific threats: prompt injection, data poisoning, model extraction, adversarial inputs, unsafe tool use, supply-chain compromise and leakage through outputs.
Board-approved controls should include asset inventory, least privilege, strong authentication, secrets management, encryption, logging, secure development, dependency scanning, red teaming, vendor review, model and dataset access controls, recovery testing, incident response and post-incident remediation. Enterprise customers commonly require evidence through audits, certifications or contractual questionnaires even where BVI law does not prescribe a named standard.
Employment, immigration and management location
Employees physically working in the BVI engage the Labour Code, work-permit and immigration requirements, payroll taxes, social-security and local employment practices (BVI income-tax, payroll-tax and related fiscal legislation and official guidance; Labour Code, 2010; current immigration and work-permit legislation). Contractors should not be treated as independent merely by label where the factual relationship is employment.
Employees and directors working elsewhere can create payroll, employment, permanent-establishment and corporate-residence risk in those locations. The group should identify where strategic management, product control, model release approval, IP development and customer contracting actually occur. Board meetings held in the BVI are not by themselves a complete substance or tax-residence solution.
Disputes, arbitration and insolvency
The BVI has a specialist Commercial Division within the Eastern Caribbean Supreme Court structure and a modern Arbitration Act, 2013. The New York Convention extends to the Territory, supporting recognition and enforcement of qualifying arbitral awards (Arbitration Act, 2013; Convention on the Recognition and Enforcement of Foreign Arbitral Awards, territorial status).
For shareholder, financing and IP disputes, the choice between BVI court jurisdiction and arbitration should reflect the remedy needed, confidentiality, interim relief, location of assets and counterparties, joinder, appeal rights and enforcement. Consumer and employment disputes may be subject to mandatory fora.
The Insolvency Act, 2003 governs liquidation and related creditor remedies. Directors should obtain advice where cash flow, solvency, asset transfers, related-party payments or financing covenants become stressed. Model and data licences should address insolvency, escrow or continuity where dependency on the BVI company is material (Insolvency Act, 2003, as amended).
External status and transaction friction
The Virgin Islands remained on the FATF list of jurisdictions under increased monitoring in the statement dated 19 June 2026. FATF’s own statement does not call for automatic enhanced due diligence solely on that basis. Banks, payment providers, investors and counterparties may impose additional information, approvals or risk pricing (Financial Action Task Force, Jurisdictions under Increased Monitoring, 19 June 2026).
At the Council update of 17 February 2026, the BVI was absent from Annex I and remained in Annex II. Annex II is a cooperative-state-of-play list, not Annex I, but institutional policies may still treat it as a diligence factor. Refresh this status at every material financing, acquisition and banking event (Council of the European Union, EU list of non-cooperative jurisdictions for tax purposes, 17 February 2026).
THE CAYMAN ISLANDS
Summary
- Overall assessment. Cayman is a credible but conditional jurisdiction for an internationally oriented AI project. It is strongest as a holding, financing, IP-owning or export-facing platform with real governance and carefully delimited activities. It is not a substitute for product-market regulation in customer jurisdictions, and it is not a safe harbour for financial, virtual-asset, telecommunications, consumer or high-impact automated-decision functions.
- International holding / financing vehicle. Generally suitable. Flexible company law, established professional-services ecosystem and tax-neutral platform; beneficial ownership and governance remain mandatory. Confirm group tax, financing, substance and investor requirements (Companies Act (2026 Revision), s. 174; Beneficial Ownership Transparency Act (2026 Revision)).
- IP-owning/licensing company. Suitable only with design controls. Can hold and license IP, but IP income can create economic-substance obligations and fact-sensitive high-risk-IP treatment. Document development history, CIGA, people, premises, decision-making and connected-person flows (International Tax Co-operation (Economic Substance) Act (2026 Revision)).
- Enterprise AI SaaS sold outside Cayman. Potentially suitable. Exempted-company model can align with external business; DPA, contract, sanctions and foreign customer-country law still apply. Avoid unlicensed local trade and map all data flows/subprocessors (Companies Act (2026 Revision), s. 174; Data Protection Act (2021 Revision)).
- CEC/SEZ operating company. Potentially suitable. Can support approved technology activities and local staffing; eligibility and licensing are activity-specific. Obtain SEZA/CEC confirmation; do not treat “AI” as automatic qualification (Special Economic Zones Act (2023 Revision); Special Economic Zones (Cayman Enterprise City) Order, 2024).
- Consumer AI directed at Cayman residents. Higher friction. Local trade, consumer, privacy, marketing and potentially ICT rules become more prominent. Use a domestic-market licensing and consumer-compliance workstream (Contracts Act, Sale of Goods Act, Trade and Business Licensing Act, Data Protection Act (2021 Revision), and applicable sector legislation).
- AI investment, trading or advice product. Regulatory gating issue. SIBA turns on functions, not software labels. Obtain CIMA perimeter analysis before marketing or onboarding (Securities Investment Business Act (2020 Revision)).
- Tokenised / exchange / custody product. Regulatory gating issue. VASP and AML regimes may apply; implementation status must be checked at launch. Obtain CIMA classification and complete licensing/registration path before operations (Virtual Asset (Service Providers) Act (2022 Revision); Anti-Money Laundering Regulations (2025 Revision)).
- Telecommunications/network service. Regulatory gating issue. Offering an ICT service/network in Cayman may require OfReg approval. Seek OfReg classification; ordinary SaaS facts must be distinguished from regulated communications services (Information and Communications Technology Act).
Exempted company
An exempted company is ordinarily the starting point for an internationally oriented Cayman business. The material restriction is not a prohibition on having Cayman governance, directors, contracts, banking, premises or service providers. It is the statutory restriction on trading in the Islands except within the permitted external-business framework. The operating model and customer-facing activity must be designed around the exact statutory language (Companies Act (2026 Revision), s. 174).
- Appropriate uses. Group holding, investment issuance, external customer contracting, IP ownership/licensing, treasury and international business administration, subject to the entity’s objects and all sector rules.
- Local-market caution. Selling to Cayman residents, operating a local marketplace, maintaining public-facing premises or supplying locally regulated services can require a domestic operating and licensing analysis.
- Governance. Keep board minutes, conflict procedures, delegated-authority matrices, records and registered-office compliance aligned with where key decisions are actually made.
Cayman Enterprise City and the Special Economic Zone route
CEC can be relevant where the proposed activity fits an approved zone business, commonly technology development, software or related digital activity, and SEZA accepts and licenses the activity. Neither “AI company” nor “software company” is a statutory passport. The application should describe actual functions, customer flow, hosting, development, IP ownership, regulated features and any Cayman-facing activity (Special Economic Zones Act (2023 Revision), ss. 16–18; Special Economic Zones Regulations (2018 Revision), as amended; Special Economic Zones (Cayman Enterprise City) Order, 2024; Special Economic Zone Authority licensing materials).
- Obtain written confirmation of the specific approved activity and the legal entity that will carry it on.
- Keep activities within the licensed zone scope; establish a change-control process for new products or revenue lines.
- Separately analyse CIMA, OfReg, AML, consumer, immigration, health-insurance, pension and data-protection obligations.
- Treat zone employment/immigration processing as an operational benefit, not an exemption from employment standards or employer duties.
Data protection and AI governance
The DPA analysis begins with factual control over purposes and means. A Cayman AI vendor may be a processor for customer prompts and datasets, a controller for account, telemetry, security, fraud and product-improvement data, and in some circumstances a joint controller. Contract labels do not override actual control (Data Protection Act (2021 Revision); Office of the Ombudsman data-protection guidance).
Build a processing register that distinguishes: customer content; prompts and outputs; model-training and fine-tuning data; evaluation data; human-review data; account and billing data; employee/applicant data; security logs; cookies/analytics; and support communications. Record purpose, legal basis, source, recipients, retention, transfer route, sensitivity, automated-decision use and deletion method.
The DPA contains rights in relation to decisions based solely on automated processing that significantly affect an individual, with statutory exceptions and safeguards. Not every model-assisted recommendation meets that test. Conversely, inserting nominal human review does not solve the issue if the reviewer cannot meaningfully understand, challenge or change the output (Data Protection Act (2021 Revision), s. 12; Office of the Ombudsman data-protection guidance).
- Classify use cases by impact: content assistance, ranking, fraud, credit, insurance, employment, education, health, identity, pricing and access to essential services.
- For high-impact use, document logic at an appropriate level, data categories, expected consequences, validation, bias/error testing, human escalation and appeal/correction procedures.
- Contractually prohibit customers from deploying a general-purpose product for undisclosed high-impact decisions without the required configuration and assessment.
Remote access, cloud hosting, support, telemetry and model APIs can all be transfers. A Cayman controller must identify the destination and use an available adequacy, statutory exception or safeguard route. The analysis is separate from GDPR/UK GDPR transfer rules that may also apply (Data Protection Act (2021 Revision), Sch. 1, eighth principle, and Sch. 4; Office of the Ombudsman data-protection guidance).
The DPA’s personal-data-breach notification regime uses a short Cayman-specific statutory clock. The incident plan should therefore trigger immediate legal triage and preserve when the controller “should have been aware,” rather than importing a 72-hour assumption from another regime (Data Protection Act (2021 Revision), s. 16; Office of the Ombudsman data-protection guidance).
Intellectual property, training data and model outputs
Software source code and qualifying original materials can be protected through the Cayman copyright framework. Protection does not remove the need for a clean chain of title. Founder, employee, contractor, university and vendor contributions should be traced and assigned where necessary, with moral-rights, confidentiality and further-assurance language tailored to the governing law (Copyright (Cayman Islands) Order 2015 and the extended Copyright, Designs and Patents Act 1988).
- Maintain a bill of materials for code, model weights, datasets, prompts, evaluation suites, documentation, pre-trained components and open-source dependencies.
- Separate ownership of base models, fine-tunes, adapters, embeddings, customer data and outputs in contracts and technical access controls.
- Review copyleft, source-available, responsible-AI and model licences for field-of-use, hosting, attribution, redistribution, training and output restrictions.
There is no broad Cayman commercial AI-training exception that substitutes for rights clearance. Depending on the material and use, copyright, database, contract, confidentiality, privacy, trade-mark, passing-off and foreign law may apply. Public accessibility is not permission (Data Protection Act (2021 Revision); Copyright (Cayman Islands) Order 2015; Trade Marks Act).
- Create dataset cards recording source, collector, date, licence/permission, territorial scope, personal-data status, exclusions, provenance and deletion/opt-out process.
- Use a pre-ingestion legal gate for scraped data, customer data, confidential repositories, biometric data, children’s data and regulated records.
- Preserve evidence supporting licence scope and the version of terms in force at acquisition.
Terms can allocate as between vendor and customer whatever rights each party has, but should not warrant that every output is protectable or non-infringing. Address customer inputs, output use, similarity risk, prohibited prompts, human review, attribution, takedown, model improvement, feedback and defence/cooperation procedures. Avoid a blanket vendor ownership clause that conflicts with the commercial model or customer confidentiality expectations.
Patent strategy should be pursued in grant jurisdictions and coordinated with Cayman registration/extension mechanisms where available; Cayman incorporation does not itself create a patent position. Brand protection should use Cayman trade-mark registration where the mark is used or exposed in Cayman. Confidential model, dataset and process information should be protected through access controls, contracting and operational secrecy (Patents Act; Trade Marks Act).
Economic substance, tax and transparency
A Cayman entity must be classified annually under the economic-substance regime. If it is a relevant entity carrying on a relevant activity, including IP business where applicable, it must satisfy the corresponding test and reporting requirements. Classification follows actual income-producing activity, not the words in the objects clause or website (International Tax Co-operation (Economic Substance) Act (2026 Revision); Department for International Tax Cooperation, Economic Substance Guidance).
- Ordinary IP business. Map ownership, development, enhancement, maintenance, protection and exploitation functions; identify personnel, expenditure, premises and decision-making in Cayman.
- High-risk IP. Apply the statutory definition cumulatively. The category turns on specified acquisition/development facts and connected-person/group exploitation conditions. It is not triggered merely because the IP was developed outside Cayman or acquired from an unrelated third party.
- Evidence. Keep R&D agreements, assignment history, board materials, development records, employee/contractor functions, budgets, time records, licence flows and transfer-pricing support.
The high-risk IP category and its rebuttal/evidentiary consequences must be analysed under the exact statutory test. Externally developed IP does not automatically fall into that category (International Tax Co-operation (Economic Substance) Act (2026 Revision), definition of “high risk intellectual property business” and associated intellectual-property provisions; Department for International Tax Cooperation, Economic Substance Guidance).
Failure consequences escalate. Initial and subsequent economic-substance failures carry separate statutory penalties under the current provisions (International Tax Co-operation (Economic Substance) Act (2026 Revision), provisions imposing the initial and subsequent economic-substance penalties).
Cayman’s tax-neutral platform is commercially relevant, but the decision should not be described as “tax free” without qualification. Government fees, duties and sector charges can apply. More importantly, parent and customer jurisdictions may impose CFC, transfer-pricing, withholding, permanent-establishment, source, anti-hybrid or global minimum-tax consequences. A Cayman structure should be selected only after a group-wide tax model and substance plan.
The current beneficial-ownership framework requires an entity-by-entity scope and filing analysis. Legacy assumptions about exemptions or access should not be carried forward. The company should identify registrable beneficial owners or relevant legal entities, maintain supporting evidence, monitor changes and coordinate filings with its corporate service provider (Beneficial Ownership Transparency Act (2026 Revision); Beneficial Ownership Transparency Regulations (2026 Revision); General Registry beneficial-ownership materials).
Securities investment business
An AI product can enter SIBA if the Cayman entity carries on a regulated securities investment activity, for example, fact-dependent dealing, arranging, managing or advising. Pure general information or enterprise software may fall outside, but the conclusion must be based on user flow, contractual responsibility, compensation, personalisation, discretion and transaction integration (Securities Investment Business Act (2020 Revision), licensing and registration provisions and Schedule definitions; Cayman Islands Monetary Authority securities investment business materials).
Virtual assets
Token issuance, exchange, transfer, custody, trading-platform or financial-service functions relating to virtual-asset issuance can engage the VASP regime. The current CIMA implementation status and the precise service model must be confirmed before launch; “non-custodial” and decentralised labels require technical verification (Virtual Asset (Service Providers) Act (2022 Revision), registration and licensing provisions; Cayman Islands Monetary Authority virtual-asset materials).
AML and sanctions
A pure software vendor is not automatically an AML-regulated business. Where the entity conducts relevant financial business or an activity brought within an AML perimeter, it must implement risk assessment, CDD, beneficial-owner verification, monitoring, sanctions screening, recordkeeping, internal reporting and suspicious-activity escalation appropriate to the regime (Anti-Money Laundering Regulations (2025 Revision), risk-based systems, customer due diligence and monitoring provisions; Proceeds of Crime Act).
Cayman sanctions rules and reporting duties apply independently of AML status. Foreign export-control and sanctions regimes can also constrain advanced chips, model weights, technical assistance, cloud access, counterparties and destinations. Implement customer, user, payment and destination screening proportionate to exposure (applicable Cayman sanctions orders and Cayman Islands Government sanctions materials).
OfReg perimeter
An AI application is not necessarily an ICT service, but offering regulated communications, network, transmission, numbering or infrastructure functions in Cayman can require OfReg classification or licensing. The product architecture, not the “cloud software” label, should be provided to OfReg where the boundary is uncertain (Information and Communications Technology Act, licensing provisions; OfReg ICT licensing materials).
Cybersecurity and authorised testing
The Computer Misuse Act creates criminal exposure for unauthorised access and related conduct. Penetration testing, red teaming, model extraction testing and agent/tool security testing should have written authority, scope, target identifiers, timing, data handling, escalation and safe-harbour terms (Computer Misuse Act (2015 Revision), unauthorised-access provisions).
Consumer, marketing and product claims
Where the product is offered to consumers in Cayman, marketing claims, subscriptions, pricing, renewals, complaints, refunds and representations about accuracy, safety or human equivalence require consumer-law review. “For information only” language will not cure a product whose design or marketing creates a different reasonable expectation (Contracts Act, Sale of Goods Act, Trade and Business Licensing Act, and applicable sector legislation).
- Substantiate accuracy, benchmark, bias, security, privacy and “human-level” claims before publication.
- Disclose material limitations and the role of automation at the point of decision, not only in long-form terms.
- Create a complaint, correction, takedown and escalation channel suitable for the product’s risk.
Employment, immigration and workplace AI
Local staff bring Cayman labour, work-authorisation, pension and health-insurance obligations into the operating model. CEC/SEZ processes can facilitate staffing but should not be treated as displacing minimum employment standards or immigration requirements (Labour Act (2021 Revision); Immigration (Transition) Act and official work-authorisation materials).
Dispute resolution and enforcement
Cayman is an established common-law forum and supports arbitration under the Arbitration Act. For cross-border AI contracts, select governing law, court or arbitral seat, rules, tribunal number, language, confidentiality, interim relief, service, evidence preservation and enforcement strategy deliberately. A Cayman entity may still face mandatory claims in the customer or data-subject forum (Arbitration Act, 2012, confidentiality provisions).
