Data Protection & AI

When the model sings: Copyright limits of AI training after the Suno ruling

Where AI & Copyright Hit a Sour Note

Six songs were enough. „Atemlos“, „Rasputin“, „Daddy Cool“, „Big in Japan“, „Forever Young“, and the chorus of „Mambo No. 5" – that was all the collection society GEMA – the German sister of AKM – needed to show before the Munich I Regional Court that the Suno AI music generator contains not only learned patterns, but the works themselves. You enter the lyrics, the style, and the title, and nothing else, and out comes something that is deceptively similar to the original. On July 31, 2026, the court ruled: This is a copy.

The verdict (42 O 763/25) is not yet legally binding. A closer look is still worthwhile now, because for the first time a court in the EU has ruled on compositions in the output of an AI model, taken apart the mechanics of this model, and evaluated each step individually under copyright law. The central question of whether the model memorizes or generalizes cannot be answered any differently in Vienna than it is in Munich.

Table of Contents

The decision

The core of the judgment is a factual finding, not a legal one: the six works are contained in model versions v3.5 and v4 in a reproducible manner. Following computer science, the chamber calls this Memorization: The model not only extracts information about patterns from the training data, but also incorporates the content into its parameters. This was proven by comparing the training data with the output; given the length and complexity of the pieces, the court ruled out the possibility of coincidence. Suno’s objection—that the weights merely represented „statistically learned patterns“ and that the storage space was „mathematically insufficient to store 1 % of the training data“—was therefore not accepted. Suno is now expressly prohibited from reproducing the work „by storing it in the form of parameters or other data structures in such an AI model.“.

From this finding, the rest follows almost inevitably.

  • First: The reproducible storage in the model alone constitutes a copyright-relevant reproduction (§ 16 German Copyright Act (UrhG), corresponding to § 15 Austrian Copyright Act (UrhG)) – specifically on the German servers where the models were hosted.
  • Second, the text and data mining (TDM) exception (§ 44b German Copyright Act, corresponding to § 42h Austrian Copyright Act) does not justify this. It permits analysis, not the permanent storage of the works in the model.
  • Third: If the generator produces outputs in response to simple prompts in which the original elements are recognizable, this constitutes a further reproduction and a public communication.

However, the most important sentence for practice concerns the imputation. Suno had argued that users were responsible for the output—after all, they entered the prompt. The court saw it differently: because the prompts were simple and open-ended—just lyrics and style, with no specifications for melody, harmony, or arrangement—the model determines the content of the output, not the user. Responsibility remains with the provider. And simply offering a model built in this way constitutes an infringement of the unnamed right of public performance (§ 15 para. 2 German Copyright Act, dUrhG), according to the chamber. Such a catch-all provision does not exist in Austrian law; there, one would have to argue via a directive-compliant interpretation of §§ 18, 18a Austrian Copyright Act (öUrhG) in light of Article 3 of the InfoSoc Directive. It is also noteworthy where GEMA’s argument did not succeed: the chamber rejected the right of making available to the public (§ 19a dUrhG)—unlike in the OpenAI proceedings—and only awarded the claim brought in the alternative („unnamed rights“).

The international part goes the furthest. Relying on § 131 VGG (Collective Management of Copyright and Related Rights Act), the court also assumed jurisdiction over the training conducted in the USA. Paragraph 1 of this provision establishes exclusive jurisdiction at the place of the infringement, and paragraph 2 allows a collecting society to bundle all claims against the same infringer before any one of the competent courts—originally intended for the „promoter moving from place to place.“ The chamber applied this concentration rule in a „dual-functional“ manner to international jurisdiction as well, defending it against objections under public international law. It then examined the foreign training—following the *lex loci protectionis* principle—under US law. Result: no fair use. This is precisely where it becomes interesting for classification purposes, because that same fair-use doctrine had protected the AI providers in two other US proceedings. More on that in a moment.

Another factor carries significant weight. Suno had pulled the tracks from YouTube via stream-ripping, thereby circumventing a technical protection measure. This is not purely an AI problem, but a straightforward breach of protection measures—and it makes the case a terribly poor test balloon for the AI industry.

Consistent line of the Munich Regional Court I

The Suno ruling does not stand alone. The Munich Regional Court had already ruled in November 2025 in the proceedings between GEMA and OpenAI (42 O 14139/24). At that time, the case concerned lyrics that ChatGPT outputted almost verbatim in response to simple prompts. Even back then, the reasoning was that memorization in the model constitutes reproduction—in that case additionally combined with a violation of the right of making available to the public—that the TDM exception (§ 44b German Copyright Act corresponds to § 42h Austrian Copyright Act) does not cover this, and that the reproduction in the output constitutes a separate copyright infringement. The current Suno ruling extends this line of reasoning from language to music.

Two decisions by the same chamber in less than a year, both against US AI providers, both in favor of GEMA. What is remarkable is the practical consequence that was recognized early on: If every memorization is a reproduction and memorized works cannot be reliably removed from a trained model (unlearning does not yet exist; cf. Chess, the extraction of websites for AI training purposes as copyright infringement de lege lata et ferenda (NJW 2024, 113 [114] with further references), then a provider is often left with no choice but to obtain a license, or withdraw the affected version of the model from the market. This scenario contains the true explosive potential of the jurisprudence.

That's far from clear

The Munich Regional Court has answered a question that legal scholars have been debating for years—albeit only for a specific set of facts. The dispute itself remains.

One side argues in the same way the court ruled. A model from which a work can be retrieved again with the right prompt must contain this work in some form. The result cannot be explained otherwise. A model is a data structure consisting exclusively of what it was taught. The copyright definition of reproduction is intentionally broad. The term does not require the copy to be directly perceptible. According to this interpretation, the fact that the storage is distributed across billions of weights and no one can specifically read it out changes nothing. Depending on the model and training conditions, according to the studies this position is based on, between 0.1 and 10 percent of the training data can be reproduced identically (in-depth Dornis, Generative AI, copyright-related reproduction and making available to the public – Part 1: The Inside of the Model, CR 2024, 765 [768]). Suno countered that the storage space of the parameters is mathematically insufficient even for one percent of the training corpus.

The opposing view, which is prominently represented in Austria, starts precisely there. Neural networks do not store data, but probabilities. Out of a hundred trillion data points, a few billion weights are created in the end—a drastic reduction that ultimately leaves no fixation that could make a work even indirectly perceptible. If a model does reproduce a training work, that is an exception, usually the result of overfitting: an error, not the normal state, and an error that modern training methods are specifically trying to avoid. To assume copyright infringement without any permanent fixation would mean overextending protection and intolerably constricting the AI market (as Dürager/Heinzl, Artificial Intelligence and Machine Learning, ÖBl 2025/2, 3 [13]).

Between the two camps lies a mediating view that is meanwhile gaining ground: whether there are reproductions in the fully trained model depends on „whether the AI model is capable in the specific individual case of making the work perceptible to human senses in some way, directly or indirectly“ (BGH 23.02.2017, I ZR 92/16; cf. Schwartmann / Köhler, Reproductions of copyrighted works in the context of developing generative AI models, NJW 2026, 711 [712]).

Determining who is right is initially not a legal question, but a technical one. And that is precisely what makes the matter inconvenient in practice. Whether a model memorizes is decided by the individual model—its size, the composition of its training data, and how often a work appears in it. The Munich court did not have to resolve this abstractly; six songs that could be reproduced were enough for it. An Austrian court would face the same evidentiary issue.

Moreover, the denial of reproduction within the model itself does not mean that copyright law is thereby off the table. Collection comes before training. At the latest during web scraping and the creation of the training corpus, a reproduction occurs that seriously nobody disputes—in the working memory, but in any case in the permanently stored data collection. The question is then no longer whether an act of exploitation exists, but only whether an exception covers it. Thus, the entire weight shifts to Section 42h of the Copyright Act (UrhG).

This question will not be decided in Munich in the end, nor in Vienna. The first preliminary ruling procedure concerning AI and copyright has been pending before the CJEU since April 2025 (C-250/25, Like CompanyAt its core, that is precisely about whether the training process of a language model constitutes reproduction and whether the TDM exception applies. Until that answer is available, all national rulings are interim stages (cf. regarding the referral procedure Product, Copyright on the siding – Handling protected works in AI training, ailex 2025/11 [Pt C.3.]).

Translation to Austria: a different paragraph, the same logic

Caution is advised regarding the understandable reflex to apply the Munich ruling one-to-one to Austria.

The relevant standard in Austria is § 42h UrhG. Just like § 44b dUrhG, it implements a European directive (Article 4 DSM Directive). In terms of content, the Austrian TDM exception is worded somewhat more generously than in Germany: since January 1, 2022, § 42h para. 6 UrhG has allowed everyone—including companies, also for commercial purposes—to make copies for automated analysis, provided there is lawful access and no machine-readable reservation of use opposes it.

That sounds like a blank check for training. But it isn't, for three reasons that would each apply in the Suno case:

  • Storage periodSection 42h of the German Copyright Act (UrhG) only permits the retention of the reproduction for as long as it is necessary for the purposes of data analysis. A work that is permanently and reproducibly embedded in the model is no longer covered by this – precisely the point where the Munich Regional Court also draws the line for the German exception. Memorization oversteps the exception in both cases.
  • Lawful access. The privilege only applies to lawfully accessible works. Anyone who circumvents a technical protection measure—such as Suno with stream ripping—does not have lawful access. For this reason alone, Section 42h of the Copyright Act (UrhG) would be off the table in a parallel Austrian case.
  • Rights holders can prohibit training through a machine-readable reservation (§ 42h para. 6 UrhG). In practice, this means: the reservation must be stored in a machine-readable format – in robots.txt, in metadata –, not as a sentence in the terms and conditions. Conversely, anyone who trains should document that no such reservation existed.

The output side, in turn, does not even require any special legal doctrine in Austria. A piece of music that recognizably adopts the original features of a protected work is a reproduction or dependent adaptation—the assessment under Section 5(2) and Sections 14 et seq. of the Austrian Copyright Act leads to the same result as in Munich. With regard to transferring those results to the Austrian legal situation, it can be concisely stated: Different section, same logic. An Austrian court would, with high probability, arrive at the same result in this factual scenario.

Two arguments that go further

In the Munich judgment, the TDM exception already fails due to the duration of storage. This is the most direct way to deny the application of the exception. In the literature, there are additionally two arguments that go significantly further—and which also affect a model that demonstrably does not memorize anything.

First: the purpose of the TDM exception

According to the wording of the law, text and data mining aims at extracting information about patterns, trends, and correlations. Therefore, it is about what is contained in the data, not about the intellectual content of the works themselves. Strictly speaking, true TDM therefore does not even touch upon copyright law. The situation is different with generative training: There, the focus is precisely on the expression, because the goal is to produce content that is identical or similar in nature.

Anyone who takes this distinction seriously arrives at a teleological reduction – the limitation was created in 2019 when the European legislature simply did not have generative AI in mind. The fact that a right to read does not entail a right to mine is more than just a play on words (regarding the state of the debate Schwartmann / Köhler, NJW 2026, 711 [714]). Historically, the exemption for mere enjoyment of a work is based on the fact that remuneration cannot be enforced against private end users – not on a lofty principle that could be applied to industrial scraping.

In addition, the legal restriction is a poor technical fit. It only permits data retention as long as it is necessary for evaluation. A continuously learning model does not know this point in time. Furthermore, the obligation to delete conflicts with the documentation requirements of the AI Act—and deletion in the sense of retroactive „unlearning“ is still not technically available today.

Second: the three-step test as an international reservation

Free uses of works are subject to reservation in both European and international copyright law. They may only concern certain special cases, must not conflict with the normal exploitation of the work, and must not unreasonably prejudice the legitimate interests of the rights holders. All three conditions must be met cumulatively. The test binds not only the legislature during implementation, but is also a standard of interpretation for the courts – a limitation on the limitation (in detail Behm/Mitterauer, „Move fast and break things“ – but not at the expense of creators, MR 2025 H 1 Supplement, 6 [11]).

At the second level, an argument begins whose premise is simple: A market for training data has long existed. Large publishers and media companies are licensing their archives to AI providers, the demand for high-quality data is growing—Suno itself concluded a licensing agreement with Warner Music at the end of 2025, after Warner had previously taken legal action against the company. A remuneration-free exception strips this market of the very thing that sustains it—whoever is allowed to scrape for free does not buy. Added to this is the substitution effect on the output side. The output enters into direct competition with the works used for training, most clearly in the case of simple texts, illustrations, and applied graphics.

The obvious objection is that training and use must be kept separate. The exception only concerns the preceding process, while the output is a different matter. The opposing side considers this to be an artificial splitting of a unitary process—after all, training is conducted precisely so that the output is generated. According to the case law of the CJEU, a substitution effect does not have to arise directly from the act of use itself in order to count at the second stage (Behm/Mitterauer, MR 2025 H 1 Supplement, 6 [13]; dissenting opinion Schwartmann / Köhler, NJW 2026, 711 [717]).

This is relevant for practice because this argument works independently of the memorization question. Even a model that is proven to only generalize would have to be measured against it. Anyone who relies on the assumption that their own architecture stores nothing has not yet refuted all objections.

The reservation of use and its design flaws

The TDM exception stands and falls with the reservation of use. It is intended to return control to the rights holders: Anyone who does not want their works to be trained on declares this in a machine-readable format, and the privilege no longer applies. Elegant in theory. In practice, the construct has at least three vulnerabilities.

First, it demands action from those who wish to protect their work. Copyright arises without formality; the reservation effectively reverses this principle because only those who take technical action retain protection. For a publishing house with an IT department, this is feasible; for a freelance photographer or composer, it is hardly so. What „machine-readable“ precisely requires is, moreover, still disputed to this day.

Second, the reservation does not apply where the works are actually located. Under the European understanding, access to content freely available on the net is already considered lawful access. However, very few creators operate the sites where their works are located—platforms, agencies, media companies, and sometimes the very same corporations that are training models themselves do this. Whether a reservation is set there is completely beyond the creator's control.

Third, enforcement is weak. An ignored reservation costs nothing initially, and scraping can be shifted to another jurisdiction. The AI Act addresses this: providers of general-purpose AI models must maintain a copyright compliance strategy, including the identification of stated reservations, pursuant to Article 53(1)(c) of the AI Act, and publish a „sufficiently detailed summary“ of the training content pursuant to letter d. The regulation does not specify what this strategy must look like—and unlike the summary, it does not have to be published at all. The AI Office template, in turn, does not require the listing of individual works, but only information on the most important datasets and domains (on this Product, ailex 2025/11 [Pkt B.1]). As a general rule, it will not be possible to provide proof for individual works in this way. Whether subjective claims by the rights holders can be derived from this is an open question; in the case of damages, causality and the amount of damage would stand in the way. For the rights holders, this leaves what the literature calls the „opacity risk“ (Schwartmann / Köhler, NJW 2026, 711 [716]): It is impossible to tell from the outside whether a model was trained on one's own works at all. After all, the provider's inability to prove compliance with its reservation strategy is likely to serve as an indicator against it.

Anyone wishing to protect their own content should establish a machine-readable rights reservation sooner rather than later, because retrospective declarations do not apply retroactively to training that has already taken place. Anyone hosting third-party works on their own pages should clarify contractually who sets the reservation (if desired). Anyone who sets a reservation should know and factor in that the same signals that block training crawlers can also block search engines.

That this construction is not sustainable has been recognized at the European level: in early 2026, the Legal Affairs Committee of the European Parliament adopted an own-initiative report on copyright and generative AI that addresses precisely these two vulnerabilities—the legal uncertainty regarding the scope of the TDM exception and the practical ineffectiveness of the opt-out. The report does not contain binding regulations. However, it is a signal of the direction a reform could take (cf. Schwartmann / Köhler, NJW 2026, 711 [718]).

The other half of the problem: Who owns the output?

So far, it has been about the input. In everyday corporate life, the flip side is more common—and her answer surprises most.

Initially, the assessment is largely undisputed. Purely AI-generated content is not protected by copyright. Protection requires an intellectual creation of a personal nature, meaning a human act of creation. The developer of the model is ruled out as the author because the specific content is something distinct from the system. The user is generally also ruled out because a prompt dictates the idea rather than the execution—and ideas are not protected. Therefore, even a particularly sophisticated prompt fundamentally does not change this classification (cf. on the nuanced debate, for example Raue, Creativity in the age of its technical reproducibility: Generative AI as the gravedigger of copyright? ZUM 2024, 157 [160]; Crown, Copyright protection of ChatGPT texts? RDi 2023, 117 [122]; Dürager/Heinzl, ÖBl 2025/2, 3 [6]).

The practical consequence should not be underestimated. Anything that is not protected may be adopted by anyone. Anyone who commissions an agency with an advertising concept and receives a largely AI-generated result is not granted any rights of use. After all, what should a grant of rights encompass if one has not acquired any oneself? A competitor may replicate the motif, and no one can prohibit them from doing so.

The way out of this gap lies in the human contribution. If AI is used merely as a tool in an otherwise human creative process, or if a generated draft is edited in such a way that human achievement remains in the foreground, a work is created once again. There are no fixed criteria for this; as a rule of thumb, the formative creative decisions must lie with the human (Siems/Wiborg, Copyright protection for AI-generated work products – Contractual structuring options for clients, RDi 2025, 136 [138 f]; for software code Kerch, From Prompt to Code: Copyright Risks, Open-Source Pitfalls, and Transactional Relevance, ailex 2026/10 [Item A.1]).

In addition, a new problem has emerged that has only become visible in recent years. Previously, the status of a work of authorship was a legal question that the court assessed based on objective criteria. Since AI outputs can no longer be reliably distinguished from human ones, this is now accompanied by a question of fact: Was a human involved at all? If the opposing party contests the quality of the work with substantiated arguments, the plaintiff must fundamentally outline the creation process and, if necessary, prove it. This is difficult in purely digital workflows. The presumption of authorship does not help because it presupposes a work, and that is precisely what is in dispute. Anyone who creates work creatively thus has a new and unexpected reason to document their creation process (on this Kögel, Copyright implications of using creative and generative artificial intelligence, InTeR 2023, 179 [183 f]).

What companies can do now

The legal situation is uncertain, but the decisions are not. Three roles must be distinguished – and in each of them, there is room for maneuver.

Anyone who trains models or purchases them should first document their origin. Lawful access is a statutory prerequisite under Section 42h of the German Copyright Act (UrhG). Anyone invoking the exception must prove its prerequisites. Therefore, what must be recorded are the source, the time, and the access path – and above all, that no technical protection measure was circumvented. This point is not an AI-specific issue. Also to be logged is the review for reservation of use, specifically in relation to the time of scraping. Anyone who „purchases“ a model should obtain origin guarantees, an indemnity, and the training data summary pursuant to the AI Act, rather than taking them for granted.

Furthermore, the model should be tested for memorization before entering the market: extraction attempts using simple, open-ended prompts on known works, similarity matching of outputs, and documented output filters. The reason for this is uncomfortably simple. There is no such thing as „unlearning.“ Whoever has a memorized work in the model has it permanently—and then faces the choice between licensing or withdrawing the affected version from the market. Diligence before training is therefore incomparably more valuable than any repair afterwards.

A special case deserves particular attention here: software code. For a specific programming problem, there are far fewer sensible formulations than for a sentence in natural language. Accordingly, the probability is high that an assistant will reproduce open-source code almost word for word. The actual risk lies less in copyright infringement than in license violation: copyleft licenses can force the distribution of derivative works under the same terms, and anyone who does not know the origin of a fragment cannot include the license notice. To make matters worse, a reliable retrospective audit is hardly possible because the reference works—proprietary code—are not accessible at all. Therefore, only preventative measures are effective: model selection, open-source review, documented release processes. In M&A transactions, this has meanwhile become a separate inspection item in IP due diligence, which is reflected in indemnifications and closing conditions (cf. Kerch, ailex 2026/10 [Pkt B.]).

Purchasers of creative services have the greatest degree of creative freedom and should make use of it. For example, it could make sense to require the contractor to use AI exclusively as a subordinate tool and to edit generated content in such a way that human effort remains central. In the case of complete works such as a brochure or a campaign, it can additionally be stipulated that AI may only be used for subordinate parts, while the drafting, selection, and compilation must be done by humans. This should be flanked by a documentation obligation in the contract. It should record which tools were used to what extent and which editing steps were performed on the generated material, including confirmation by the contractor. This is not bureaucracy for its own sake, but rather the basis of evidence for disputes in which the quality of the work is contested.

In the event of a breach of these obligations, a subsequent performance obligation is hardly practical: If the result is good, no one wants to rework it cosmetically, and whether that still establishes copyright is doubtful. More effective are a contractual penalty that requires no proof of damage and above all acts as a deterrent, an indemnification provision for sublicensing to third parties, and a right of termination (with clause suggestions). Siems/Wiborg, RDi 2025, 136 [139 f]). Internally, the same goal cannot be achieved contractually, but only through clear guidelines – hardly any company will ban generative AI for its employees, but every company can regulate how it is used and documented.

Conclusion

The Suno ruling from Munich does not decide any of the major open questions of AI training—it decides a specific, poorly chosen case. However, it is likely to be a reliable compass for the direction European courts are heading: generalizing is one thing, memorizing another. As long as a model only learns patterns and outputs nothing recognizable, it has strong arguments. As soon as protected works can be reproduced through simple prompts, the assessment flips—specifically via Section 44b of the German Copyright Act (dUrhG) in Germany, and via Section 42h of the Austrian Copyright Act (öUrhG) in Austria.

Companies in Austria should keep an eye on this development—specifically in four roles:

  • Who AI trained, requires lawfully acquired data, must respect third-party usage reservations, and should document origin and access – the TDM exception covers training, not the permanent storage of the works.
  • Who AI tools begins, is liable for infringing outputs even if the provider built the model; a sharp eye on AI results is a must, not a luxury.
  • Who creative services additional purchase, should bring the question of AI use into the contract instead of leaving it to chance – the protection of the result is decided by the creation process, not by its quality.
  • And those who own works protect Will, make sure the reservation of use is machine-readable before the next model is trained.

The courts have begun to shed light on copyright grey areas of the AI revolution. It is becoming clear that companies would be well advised to monitor developments and take appropriate measures.

Frequently Asked Questions (FAQs)

Is training an AI on third-party works permitted in Austria?

In principle, yes. Since January 1, 2022, Section 42h (6) of the Copyright Act (UrhG) has also allowed companies and commercial purposes to make reproductions for automated analysis. However, the exception has three fracture points: lawful access, storage duration, and reservation of use. Anyone who circumvents a technical protection measure or retains works permanently and reproducibly in the model can no longer rely on it. Whether the TDM exception even applies to generative training will (hopefully) be clarified by the ECJ in case C-250/25.

 

What does „memorization“ mean – and why is so much riding on it?

Memorization occurs when a model retains training content in its parameters in such a way that it can reproduce it in whole or in part in its output. It is precisely on this basis that the Regional Court of Munich I bases its ruling. If a model only generalizes patterns, its provider has strong arguments; if a protected work can be retrieved with simple prompts, the assessment changes. Whether a model memorizes is first and foremost a technical question – and it must be answered individually for each model.

 

Is a notice in the terms and conditions sufficient as a reservation of use?

For works accessible online, the law requires a machine-readable format. The secure route is via robots.txt and metadata, not a sentence in the terms of use. Whether a statement in natural language is sufficient is disputed; for Austria, there is no case law whatsoever on this. Above all, timing is crucial: the reservation does not apply retroactively to training that has already taken place.

 

Is our company covered by the NISG 2026?

Sector and size are decisive. Covered are entities from 18 sectors that generally have at least 50 employees or more than 10 million euros in annual turnover or balance sheet total; a few activities are covered regardless of company size. The classification must be carried out independently; there is no official notification. Even those not directly covered should check whether NIS-2-obligated customers pass on the requirements via supply chain clauses.

 

Who owns the results generated by an AI?

Initially, to no one. Purely AI-generated content is not protected by copyright due to a lack of human creation; accordingly, no rights of use can be granted for it. Protection only arises when the defining creative decisions lie with a human—because the AI was merely a tool or because the result was substantially post-processed. Anyone wishing to rely on this should document the creation process.

 

What should companies regulate when purchasing creative services?

Three points go the furthest: the obligation to use AI solely as a subordinate tool and substantially revise results; a documentation requirement regarding the tools used and processing steps; and legal consequences that actually take effect—contractual penalties, indemnification, and the right to termination. Percentages regarding the „human share“ should be avoided because creative contributions cannot be quantified. Within a company, a clear guideline replaces the contract.

Are you using AI in your company or developing your own models – and want to know where you stand legally regarding copyright?

The IP and IT legal experts at ATB.LAW support companies at the intersection of copyright law and artificial intelligence. We review your training and deployment processes, design licensing and usage concepts, and set up reservations of rights cleanly from both a technical and legal perspective. Contact Stefan Knotzer and Roman Taudes at any time under office@atb.law or by phone at 01 39 12345 for a non-binding initial consultation.

More articles

EU Commission CRA Guidelines

Cyber Resilience Act: EU Commission guidelines published

Get companies out of standby mode and into the fast lane for the CRA.
Picture of Stefan Knotzer
Stefan Knotzer
Laptop is losing data

Data Breach: The Devil Never Sleeps

What Austrian companies can learn from the incident at a major US law firm
Picture of Stefan Knotzer
Stefan Knotzer
AI Act Transparency Guidelines

AI Transparency under the AI Act

What companies need to know about the new EU guidelines
Picture of Stefan Knotzer
Stefan Knotzer