YOUR
Search

    07.10.2026

    AI regulation in China, the EU and Germany: New Chinese Legal Opinions on AI-related Disputes and Their Alignment with European Law


    On 7 September 2026, the Supreme People’s Court of China (“SPC”) officially released and implemented the “Opinions of the Supreme People’s Court on the Trial of Cases Involving Artificial Intelligence Disputes” (hereinafter referred to as the “Opinions”). 

    The Opinions, which contain 24 provisions, constitute the SPC’s first comprehensive set of legal guidelines specifically addressing civil and related disputes arising from the development and use of artificial intelligence (“AI”).

    In this article, we provide an overview of the Opinions – and of the extent to which they are consistent with, or deviate from, EU law and German law.

    Principles of Attribution for AI Tort Liability

    For China, the Opinions clarify the principles of attribution for AI-related tort liability, stipulating that where the existing legislation does not expressly provide for strict or presumed liability, AI-related tort liability is to be determined on the basis of fault as set forth in the PRC Civil Code. 

    This approach is significant for AI developers and service providers. It indicates that China does not introduce a strict liability regime, and the mere occurrence of damage caused by an AI system does not automatically give rise to liability. Rather, liability depends on the specific circumstances of the case and the respective ability of the parties to prevent or control the risk in question. The courts shall consider, among other factors, the specific application scenario, the degree of autonomy and transparency of the AI system, the potential risks and their scope, the preventive measures taken by the parties involved, and the user’s ability to foresee and control potential damage.

    In Europe, the question of tort liability is generally governed by the national laws of the EU Member States. However, the revised EU Product Liability Directive also seeks to establish no-fault liability (strict liability) for defective software and AI systems. It must be transposed into national law by the EU Member States by 9 December 2026.

    The Directive only applies to certain types of compensable damage, namely death or personal injury, now also including damage to mental health, damage to property, and the destruction or corruption of data not used for professional purposes. Under this provision, pure economic loss and professionally used data are not considered independent categories of recoverable damage. Claimants also benefit from targeted access to evidence and from rebuttable presumptions regarding defects and causation, particularly where technical or scientific complexity would otherwise make it unduly difficult to prove these matters. The manufacturer is generally the party primarily liable. A person who substantially modifies a product beyond the manufacturer's control and then places it on the market or puts it into service may be treated as the manufacturer in relation to that modification. The mere use or internal configuration of an AI agent is not automatically sufficient.

    Under German law, general tort liability remains fault-based. As in China, liability depends on the specific circumstances and the respective ability of the parties to prevent or control the risk in question. 

    In accordance with the EU Product Liability Directive, Germany is currently preparing the implementation of the revised product liability rules, which will lead to a strict liability regime for certain types of harm caused by AI.

    Tort Liability in Different Application Scenarios

    For China, the Opinions set out in detail how the tortious liability is determined and allocated in various scenarios in which AI is used to infringe personality rights (including the right to privacy), personal data rights and interests, and consumer rights and interests. Again, we compare how China, the EU and Germany deal with these scenarios.

    Personality Rights: The Opinions explicitly state that generating a virtual digital image or a synthesised voice without the individual’s consent or using such material to engage in improper conduct or spread false information that damages a person’s reputation in society, constitutes an infringement.

    The Opinions further address so-called “doxxing” and “human flesh searches” carried out using AI. The use of AI to track and analyse public information for the purpose of obtaining or disclosing private information, or of infringing a person‘s privacy - as well as the unauthorised filming, peeping, or eavesdropping in private spaces and during private activities - is legally considered an infringement of the right to privacy.

    At EU level, the GDPR protects individuals where the creation or use of synthetic content involves the processing of personal data. In addition, the EU AI Act requires providers to enable the detection of synthetically generated or manipulated content and requires deployers to disclose certain deepfakes. These transparency obligations do not, however, determine whether the creation or use of the content is lawful. As EU Regulations, the GDPR and the AI Act are directly applicable in the EU Member States.

    German law further protects an individual's name, image, voice, reputation, privacy and other personality interests under both constitutional and civil law. Depending on the circumstances, affected individuals may seek the removal of content, an injunction and, where the relevant requirements are met, compensation for damages.

    Personal Information and Interests: The Opinions restrict the use of publicly available personal data for training AI models, clarifying that processing within reasonable limits - and where the individual has not objected - does not generally constitute an infringement. However, if such processing has a significant impact on the rights and interests of a data subject, consent must be obtained in accordance with the statutory provisions.

    This provision provides AI developers with a degree of legal certainty while also making it clear that “publicly available” does not mean “freely usable for any purpose”.

    From a German and EU perspective (GDPR), the fact that personal information is publicly available does not imply that it may be freely used for AI training – this results in more stringent restrictions on the use personal data for AI training than in China, according to the Opinions. Any processing must have a valid legal basis and comply with the fundamental principles of purpose limitation, data minimisation and transparency. More stringent requirements apply to sensitive personal data. Nevertheless, the Regional Court of Cologne ruled that Meta has implemented sufficient safeguards when using data available on Facebook to train its AI. 

    Consumer Rights and Interests: The Opinions strictly regulate the practice of “Big Data Differential Pricing” using algorithms, explicitly classifying the imposition of unreasonable differential treatment for the same product based on information such as consumer preferences and payment capacity as a legal infringement for which liability must be assumed. Furthermore, where the use of AI to imitate celebrities for product promotion constitutes fraud, courts will, in accordance with the law, uphold consumers’ claims for punitive damages. 

    Under EU law and German law, personalised pricing is not prohibited as such – so the regimes are less strict than in China. Consumers, however, must be informed if a price has been personalised through automated decision-making. The practice may be unlawful where it violates the GDPR, for instance in the absence of a legal basis, insufficient transparency, or unjustified automated decision-making. Personalised pricing may also be considered an unfair commercial practice, for instance if it is misleading. Naturally, it must not be discriminatory. 

    Civil Liability for Specific AI Entities

    In addition, the Opinions clarify the tort liability of providers of generative AI services, AI product liability, and liability for damages in traffic accidents involving autonomous vehicles and vehicles equipped with driver-assistance features.

    Determination of Tort Liability for Providers of Generative AI: The Opinions specify that providers of generative AI services are subject to China’s statutory “notice-and-take-down” mechanism. Where AI-generated content infringes rights, or if users maliciously induce the generation of infringing content and the service provider fails to promptly take necessary measures - such as ceasing generation or issuing blocking instructions - upon receiving a valid notice containing the identity of the infringer and preliminary evidence, the service provider shall be liable for the resulting damages in accordance with the law.

    The Opinions therefore prioritise the different roles and control mechanisms of developers, service providers, and end users, thus refraining from imposing absolute liability on AI providers indiscriminately.

    From a German and EU perspective, although online intermediary services may benefit from conditional exemptions of liability under the Digital Services Act, they must put mechanisms in place for notifying and addressing illegal content. 

    Through the Digital Services Act, EU law establishes the framework for the exemption from liability of intermediary service providers and the limitations on such exemption; however, the national courts of the EU Member States must decide whether there is an infringement (unless escalated to EU courts). Whether these provisions apply to a provider of generative AI depends on the service's actual function and degree of control; such a provider is not automatically treated in the same way as a conventional hosting service.

    Case-law in this respect is still far from settled. Generally, German courts have recently tended to hold AI service providers liable for AI-generated content as can be seen in cases against OpenAI, Suno, and Google.

    Product Liability for AI Products: The Opinions makes it clear that AI products embodied in physical objects are subject to the relevant product liability regulations. Manufacturers and sellers are liable for damage caused by product defects. The assessment requires a comprehensive weighing up of factors such as autonomous learning capabilities, software updates, user control mechanisms and compliance with standards, with a particular focus on whether the inherent limitations and foreseeable risks have been truthfully disclosed and clearly warned against.

    In the EU, the recently revised product liability regime – which we have already mentioned above - expressly covers software, including AI systems, and retains strict liability for defective products. The new rules apply to products placed on the market or put into service after 9 December 2026, following national implementation. 

    Liability for Autonomous and Driving-Assisted Vehicles: Liability for accidents involving smart vehicles is governed by the PRC Civil Code and the PRC Road Traffic Safety Law. Manufacturers or sellers are held liable for damage caused by a vehicle defect, while both parties share liability if a vehicle defect and the driver's negligence jointly cause the accident; furthermore, false advertising regarding automation levels or performance is strictly penalised. People's courts have the authority to require data controllers - such as vehicle manufacturers, sellers, or operators - to provide authentic and complete records or data on autonomous or driver-assistance events to ascertain the cause of an accident.

    At the German level, accidents involving automated or driving-assisted vehicles can give rise to several parallel lines of liability. The vehicle owner may be liable irrespective of fault, the driver may be liable for negligent conduct, and the manufacturer may face product-liability claims if a defect contributed to the accident. Product liability is a strict liability regime and does not require fault. 

    Misleading advertising falls under unfair competition law rules. In Germany, there are some notable court rulings on Tesla's advertising of its "autopilot" system, as well as the autopilot's "phantom braking". 

    AI and Intellectual Property

    The Opinions set forth five rules for resolving legal disputes in the field of intellectual property relating to AI, covering copyright, open-source software, patents, technology contracts and data:

    Copyright Infringements caused by AI-generated Content: The People’s courts are instructed to consider factors such as the type of AI service, industry, sources of training data, the degree of participation by the parties involved, necessary measures taken, and profitability to determine the liability of developers, providers, and users, and will support the prosecution of unfair competition practices - such as counterfeiting and false advertising - committed through the use of AI.

    Heavily influenced by EU Directives, German copyright law distinguishes between copies made during model training and potentially infringing outputs. AI training may be permitted as text and data mining for lawfully accessible material, but rights holders may reserve their rights. More extensive exemptions apply to qualifying scientific research. Under the EU AI Act providers of general-purpose AI models must also submit a copyright-compliance policy and publish a sufficiently detailed summary of the content used for training. Please see above for related case law.

    Results generated solely by AI do not generally enjoy copyright protection, unless they sufficiently reflect creative human decisions; by contrast, results that reproduce protected works may constitute an infringement under general copyright provisions.

    Liability for AI Open-source Software: The People’s courts are instructed to consider factors such as open-source licence agreements, the specific content of rights restrictions, measures taken to comply with security regulations, and the extent of information disclosure - to grant appropriate exemptions to open-source software developers and providers. Developers and providers of free open-source software who have clearly disclosed relevant risks may be exempted from liability for third-party infringements, provided they themselves are not at fault.

    From a German and EU perspective, open-source status does not establish a general exemption under copyright law, contract law, cybersecurity or tort liability. The assessment depends first on the applicable licence and on the conduct and role of the relevant actor. The EU AI framework contains specific exemptions for certain freely and openly licensed components and models, but these are limited. Under the revised product-liability regime, free and open-source software developed or supplied outside a commercial activity is generally exempt; however, commercial integration or substantial modification may lead to a different result. A similar logic applies under the Cyber Resilience Act, which will apply from 11 December 2027 to virtually all hardware and software placed on the Union market, including components. Open-source status grants no general privilege and only free and open-source software not supplied as part of a commercial activity will fall outside the scope of the Act.

    AI-related Inventions: The Opinions confirm that AI-related inventions that comply with the laws of nature and solve technical problems are patentable. Only natural persons who make creative contributions to the substantive features of such inventions shall be recognised as inventors. AI systems per se cannot be named as inventors. The patent specification must disclose the invention in sufficient detail to enable a person skilled in the art to carry out the invention.

    At European level, the use of AI does not prevent patent protection. The invention must meet the standard patentability requirements, and only a natural person may be named as inventor.

    German patent law follows the same approach. A natural person must be named as inventor, even if an AI system has played a substantial role in identifying the claimed technical solution. According to the German Federal Court of Justice, the human contribution must have had a legally relevant influence on the process leading to the invention, but need not, in itself, constitute an independent inventive contribution. The use of AI does not have to be disclosed merely because AI was used as a tool, unless information about the AI system is necessary for a person skilled in the art to carry out the claimed invention.

    AI Technology Contract Performance: To determine liability for breaches of contract in technology development, transfer and licensing disputes, People’s courts are obliged to adhere strictly to the contractual provisions, while balancing the unique characteristics of AI technology R&D against the developer’s compliance with the duty of reasonable diligence.

    EU law does not provide a general framework for AI contracts. However, it regulates specific aspects, including responsibilities along the AI value chain, data access, unfair data-related contract terms and switching between cloud services under the EU Data Act. These mandatory provisions may limit the contractual allocation of responsibilities.

    Under German law, contracts can allocate risks in the areas of development, service provision, data, intellectual property, security and change-management in considerable detail. This freedom is not unlimited: standard terms remain subject to fairness controls, liability cannot always be excluded, and mandatory regulatory duties cannot be transferred by agreement. Given the probabilistic nature of AI performance, contracts should define acceptance criteria, benchmarks, permissible data uses, update obligations, audit rights, incident handling and the consequences of model drift or regulatory change.

    Use and Security of AI Data: The Opinions protect the rights of AI developers to data obtained through legitimate channels. Depending on the nature of the data, protection is provided under either the PRC Copyright Law or the PRC Anti-Unfair Competition Law. Furthermore, legal liability will be strictly enforced against those who use technical means to engage in monopolistic practices, abuse a dominant market position, or jeopardize the operational security of AI systems.

    EU law does not establish a general ownership right over data. Instead, it regulates certain aspects, including access to data generated by connected products, the processing of personal data, the protection of databases and trade secrets, and cybersecurity. In particular, the Data Act grants users certain rights to access to and disclosure of data generated by connected products, subject to safeguards for personal data, trade secrets, and system security.

    German law also does not recognise such rights. Rights to control or use data may instead arise from contracts, data protection law, copyright law and database protection, or trade secret law. Effective protection of trade secrets generally requires the holder to implement appropriate confidentiality measures.

    Four Core Rules for AI-related Evidence and Litigation

    To accurately ascertain the facts of a case, People's courts may exercise procedural control, order evidence preservation, apply adverse inferences against parties who refuse to submit evidence, and draw upon the support of professionals such as expert witnesses and technical investigators.

    Parties submitting AI-generated pleadings, case law research, or other documents generated by AI must verify their accuracy and disclose the use of AI assistance to the court. They remain responsible for the authenticity and accuracy of the submitted documents.

    Criminal charges will be brought for offences such as the use of AI to commit fraud, invasion of privacy, and the illegal acquisition of data, as well as acts in which driving-assistance monitoring systems are hacked or circumvented without authorisation, resulting in traffic accidents.

    In the EU, procedural law is regulated by the Member States rather than at EU level. German civil procedure law currently does not provide for a general obligation to disclose every use of generative AI in court filings. Lawyers and parties nevertheless remain fully responsible for the accuracy of their statements and citations and must continue to protect confidential and attorney-client privileged information. Electronic material is assessed in accordance with standard procedural rules. In product-liability cases, the revised EU Product Liability Directive will facilitate targeted access to relevant evidence and introduce rebuttable presumptions.

    Conclusion

    China and the EU face common challenges in addressing AI-related risks. Their approaches converge to a certain extent, but understanding the differences is key. The EU AI Act may be the most prominent piece of legislation in the EU which is relevant for AI, but it is far from being the only one. Rather, the EU has a mosaic of laws relevant for AI – some at EU level and others at Member State level. Understanding how these interact is key.

    Susanne Rademacher
    Dr. Jenna Wang-Metzner
    Kelly Tang
    Dr. Andreas Lober
    Fabian Eckstein
    Daniel Trunk, LL.M.

    China's Decree No. 841: When Border Control Becomes a Technology Enforcement Tool
    Introduction On 22 July 2026, China's State Council published the Provisions on…
    Read more
    Red Lines for AI in China: New SPC Judicial Opinions on AI-related Disputes
    On 7 September 2026, the Supreme People’s Court of China (“SPC”) officially…
    Read more
    ADVANT Beiten and ADVANT Nctm advise JLL Partners on the acquisition of Life Couriers
    Berlin/Milan, August 19, 2026 – The international law firm ADVANT, with teams…
    Read more
    ADVANT Beiten Advises Banyan Software on the Acquisition of tec4U-Solutions GmbH
    Berlin/Freiburg, 1 July 2026 - The international law firm ADVANT Beiten has…
    Read more
    ADVANT Advises Pidigi S.p.A. on the Acquisition of Key Assets of Sympatex Technologies GmbH from Insolvency Proceedings
    Munich, 5 May 2026 – ADVANT Beiten has assisted the Italian firm Pidigi S.p.A.…
    Read more
    New Chinese Outbound Investment Regulations: Opportunities Through Compliance for Chinese Investors in Germany
    On June 1, 2026, Chinese Premier Li Qiang signed the State Council Order…
    Read more
    The EU's Foreign Subsidies Regulation and the Chinese "Blocking" Response: Navigating the Escalating Tensions Between Brussels and Beijing
    Introduction: A New Era of Legal Confrontation in EU-China Trade Relations The…
    Read more
    Covert Advertising Is the Devil – or: What Meryl Streep Has to Do with Media Law
    Fashionistas are speculating whether “The Devil Wears Prada 2” can help…
    Read more
    Arbitration Awards vs. Court Judgments – China vs. Germany
    China has been Germany's most important trading partner for many years. As…
    Read more