How Europe builds AI liability (Part I.): The three regimes, and what they mean for a US company entering the EU market
(This piece appears in two parts. Part II follows this blog shortly.)
No dedicated European AI liability statute
US companies would typically expect either a single European AI liability statute or, as it is in American tort law, a body of court-made rules accumulating case by case. Neither exists in European law. Europe has no dedicated AI liability instrument, and it is not in the works at this time. The European Commission, the European Union’s executive, abandoned the proposed AI Liability Directive in 2025 (announced in the Commission Work Programme 2025, COM(2025) 45 of 11 February 2025; formal withdrawal notice at OJ C/2025/5423, 6 October 2025), citing no foreseeable agreement among the EU political institutions.
EU AI litigation exposure arises under three regimes (and none of them is aimed at the frontier model developers that most current discussions are about):
- national copyright law,
- Article 22 of the GDPR (the EU’s generally applicable data protection regulation, which also reaches companies outside the Union that serve or monitor people in it), and
- for most products placed on the market after 9 December 2026, the revised EU product liability rules.
European courts work from general instruments. National copyright law and Article 22 of the GDPR have applied to AI all along; no new rule was needed for them to cover AI. Since late 2023, European courts have been settling, decision by decision, what AI looks like under rules written for other things:
- the Court of Justice of the European Union (CJEU) in SCHUFA, C-634/21 and in Dun & Bradstreet Austria, C-203/22 on automated decision-making;
- the Amsterdam Court of Appeal, which in April 2023 decided a group of cases against Uber and Ola on algorithmic management, holding that automated deactivation and fraud scoring decisions engaged Article 22 and that drivers were entitled to meaningful information about the logic involved (ECLI:NL:GHAMS:2023:793, 796 and 804); and
- the Munich I Regional Court on copyright, in the GEMA rulings set out in the copyright section below.
- In Lindenapotheke (C-21/23, Grand Chamber, 4 October 2024), the CJEU held that the GDPR does not preclude national laws that let a competitor sue over a rival’s GDPR breach as an unfair commercial practice. Where national law provides for it, as German law does, the competitor can sue over an entering company’s data practices.
Whether that route exists depends on the EU Member State entered (which is an aspect of the choice of entry market, discussed below).
Then the third regime was added in 2024 through the amended EU Product Liability Directive (Directive (EU) 2024/2853) that added strict product liability (liability without proof of fault). Until its adoption, whether standalone software and AI systems counted as a ‘product’ at all under European product liability law was genuinely contested. The new (amended) Directive settled this issue by expressly including in its scope software, among them AI systems, digital manufacturing files and digital services essential to a product’s functioning, as ‘products’.
The amended Product Liability Directive is an update to a general, technology neutral instrument, but it is the first EU liability instrument of its kind that says AI in its text. The EU Member States must transpose the Directive into national law by 9 December 2026, and the resulting national rules apply to products placed on the EU market or put into service after that date.
So, what will bind US companies entering the EU market after December 9, 2026 is not the EU Directive itself, but the EU Member States’ national statutes implementing it. The Directive is a maximum harmonization instrument (Article 3): Member States may not diverge from it unless it says they may. Differences therefore will be in procedure and detail, such as disclosure practice and on how national courts handle platforms and fulfilment providers.
One divergence is expressly permitted. Under Article 18 (1) a Member State may maintain existing measures holding operators liable even where the development risk defense would otherwise apply, and any Member State doing so must notify the European Commission by 9 December 2026. On that date there will be a published list of which markets have switched the defense off, which is a concrete, checkable input for a company choosing where to enter. The list is not a closed set, as under Article 18(2) to (5) a Member State may also introduce a new derogation later, limited to specific categories of product and justified by public interest, by notifying the Commission and holding the measure in abeyance for six months while the Commission may issue a non-binding opinion.
Also, the EU Member States are not all transposing at the same pace. In a late transposing Member State, the first years of the new regime are less predictable for companies (and no softer on them): courts there will read the existing national law in line with the Directive as far as possible, so old statute cases can be pulled toward new regime outcomes even before the implementing law exists.
The choice of entry market (forum) has more than business consequences: the first EU domestic market a company enters determines which national statute applies, and also how predictable the rules will be in the early years of the new product liability regime in that Member State (the period between 9 December 2026 and the point when the country has enacted its implementing statute and its courts have begun applying it in a settled way).
The dedicated EU instrument exists: it is the EU AI Act (Regulation (EU) 2024/1689)), and it governs AI conduct and market access (how AI can be built and placed on the market). It does not govern AI liability, nor does it create a right to sue for damages (private claim). The EU AI Act does give affected people two procedural rights: anyone can complain to a national market surveillance authority (Article 85), and a person affected by certain high-risk systems can demand an explanation of a decision concerning them (Article 86). But neither is a damages claim. The European liability doctrine also does not develop the way American tort law does (through private suits accumulating into a rule).
When looking for answers, we will find them in: national copyright law, as harmonized by the EU Copyright Directive; Article 22 of the GDPR; and (from 9 December 2026) the revised EU product liability regime.
None of these reads as AI law on its face: two never mention AI at all, and the third, the one naming AI systems in its text, only starts applying after 9 December 2026.
About European civil liability exposure in general
All three regimes in this post are civil liability (private claims for remedies between parties before civil courts). More precisely, they are non-contractual civil liability.
a word here on contractual liability. It needs no adaptation for AI, because parties write their own rules and they can address AI risk the moment they know AI risk exists. A software vendor and its customer already allocate AI risk through warranties, indemnities, limitation clauses and SLAs, and contract law then enforces their written agreement. The legal system faces no AI-specific gap there.
For non-contractual civil liability, on the other hand, AI adaptation is needed, because the rules the European legislator crafted were written for human conduct and physical products. The withdrawn AI Liability Directive proposal aimed at fixing that gap, and the new EU Product Liability Directive ((EU) 2024/2853) will partly fill it.
Non-contractual civil liability means the claims of people who never signed anything with the vendor. Such as the pedestrian hit by an autonomous vehicle, the job applicant who was scored by software the prospective employer licensed, the songwriter whose lyrics are memorized in a model’s parameters (weights) or the patient injured by clinical software the hospital bought. None of them chose the vendor, paid the price that reflected the AI risk, or accepted a limitation clause capping vendor liability. Their claims arise from the law itself, which means they cannot be excluded by contract. A vendor indemnity moves money inside the supply chain, and does not help against the claimant, who sues whoever the law points at. Most US companies deploying rather than building AI believe their exposure is handled because the master agreement has an indemnity (“our vendor contract covers this”). While the indemnity has value and operates after liability is established (reallocating cost between the company and its vendor, a reallocation that the Directive itself supports through the right of recourse between operators in Article 14), it does not stop the claimant choosing the defendant.
Who gets sued when you have no EU entity (Article 8)?
A US manufacturer with no EU establishment does not escape the regime; someone in the EU supply chain (the next company in the chain) answers alongside it. The manufacturer is liable, and for software the manufacturer is the developer. Where the manufacturer is established outside the Union, the EU importer and the authorized representative are liable as well, and where neither exists, the fulfilment service provider. Where none of those can be identified, liability can reach distributors and online marketplaces that fail (per Article 8(3), within one month of the injured person’s request) to name an upstream operator. The same liability also applies to anyone who substantially modifies a product outside the manufacturer’s control, expressly including through software updates. These operators are liable jointly and severally (Article 12(1)): the claimant can sue one or all, and collect in full from any of them. A company that merely deploys someone else’s AI system internally (such as a company screening applicants to its own openings with a licensed tool, a bank running a vendor’s fraud scoring on its own accounts, a hospital using a purchased clinical decision support in treating its patients, or a firm deploying an off the shelf customer service chatbot, unmodified and under the vendor’s brand) is usually not an Article 8 operator for that system (deployer is the EU AI Act’s word for user; the Product Liability Directive does not use it). Its exposure to the affected individuals arises instead under the other regimes: Article 22 and Article 82 of the GDPR, and national non-contractual liability rules (tort). However, a deployer that integrates the system into its own product, rebrands it, or (as explained above) substantially modifies it is treated as a manufacturer and joins the joint and several pool.
The Directive also closes off the basic software defense. An operator normally escapes liability by proving the defect did not exist when the product was placed on the market (Article 11(1)(c)). Article 11(2) removes that route where the defectiveness is due to a related service, to software (including updates or upgrades), to the absence of security updates to maintain safety, or to a substantial modification, in each case within the manufacturer’s control. For a SaaS or a connected device company the classic “it was fine when it shipped” argument no longer works, and failing to patch a known vulnerability becomes a product liability exposure as a standalone matter.
Where does the EU AI Act fit in this picture?
Its enforcement is administrative: market surveillance authorities, corrective orders and fines payable to the state, with no compensation flowing to anyone harmed (it creates no private claim for damages). And, as the Munich rulings (see the copyright section below) show, complying with the EU AI Act is no defense. Administrative enforcement and civil liability are two different systems and they operate in parallel. The same conduct can trigger both: a GDPR violation can produce a supervisory fine and a civil damages claim at the same time.
The EU AI Act also does not require an establishment: under Article 2 it applies to providers and deployers placing AI systems on the EU market or putting them into service there, and to providers placing general-purpose AI models on the market, irrespective of where they are established. A US company with no EU entity of its own, running AI-generated campaigns aimed at European audiences, or a chatbot made available to EU customers, is therefore in the scope of the EU AI Act. For high-risk systems and general-purpose AI models the obligation to appoint an EU-established authorized representative applies under Article 22 and Article 54 of the EU AI Act respectively.
What will 9 December 2026 add to this?
That date is the deadline under Article 22(1) of the new Product Liability Directive (Directive (EU) 2024/2853) for the Member States to enact the national laws implementing the Directive. The new regime applies to products, expressly including software and AI systems, placed on the market or put into service after that date (Article 2). From then on, what the EU AI Act requires for market access starts impacting civil liability outcomes: its requirements set the standard a court applies in product liability claims and the compliance documentation prepared to satisfy those requirements will be evidence. A provider of a high-risk system must prepare a record wider than the technical documentation (file) alone, including the risk management records, data governance choices, testing results, automatically generated logs and instructions for use. And an Article 9 disclosure order is not limited to the technical documentation: logs that contradict a seemingly compliant file can become the claimant’s strongest evidence against a company (being the most damaging document a judge reads).
There is also a provision in the Product Liability Directive most directly written for AI: under Article 10 (4), where (despite disclosure under Article 9, and taking account of all relevant circumstances) a claimant faces excessive difficulties in proving defectiveness or causation, in particular because of technical or scientific complexity, and shows only that the product was likely defective or likely caused the damage, the court must presume the point. Recital 48 names machine learning as an example of such complexity, adding that the claimant need not explain the AI system’s inner workings.
The disclosure and presumption rules above apply to any software product, whatever its classification under the EU AI Act. But they operate most powerfully where the EU AI Act obliges a provider to prepare documentation because every record created to demonstrate compliance becomes disclosable evidence in product liability proceedings.
Those documentation obligations apply to the systems the EU AI Act classifies as high-risk: for example HR and recruitment screening, credit scoring, life and health insurance pricing and risk assessment, and educational assessment under Annex III. And clinical decision support and medical device software under Annex I, which are high-risk not because of what the AI system decides, but because the AI system is built into a product that already needs EU safety approval, such as medical devices, machinery and vehicles.
Most companies entering the EU market will not be high-risk providers under the EU AI Act and for them no high-risk compliance documentation is required by law at all (other documentation can be mandatory: GDPR records of processing and data protection impact assessments or DPIAs, sectoral rules such as in finance or health, and the EU AI Act’s Article 50 transparency duties). A brand using generative tools for campaign assets, e-commerce fraud scoring and dynamic pricing, a connected consumer device with AI features, content generation tools, customer service agents are mostly not high-risk, or are borderline. Deployers must comply with fewer obligations: fundamental rights impact assessments or FRIAs for certain deployers (Article 27), human oversight arrangements, log retention, and in parallel the GDPR’s DPIA where Article 35 requires one.
For the majority of companies outside the scope of Annex III (listed high-risk use cases) and Annex I (products under EU safety law), the EU AI Act does not contribute much to the safety standard a court will apply. Civil liability never depended on the EU AI Act classification. The new Product Liability Directive applies to any software product that causes harm, and an Article 9 disclosure order reaches “relevant evidence in the defendant’s control”, whatever the risk category. The claimant’s ability to sue and the court’s ability to demand company documents are the same for a minimal risk chatbot and for an Annex III high-risk screening tool.
The difference is that companies outside the high-risk category are not told what their documentation must contain. These businesses will be judged on whatever documentation they may have (design notes, test results, incident tickets, marketing copy), assembled into the claim by the claimant’s lawyer, who chooses what to request under Article 9 and how to present what is received. Defectiveness is then assessed by reference to, among other circumstances, relevant product safety requirements – including the General Product Safety Regulation and sectoral safety law -, reasonably foreseeable use and misuse, and in particular the company’s own presentation of the product (its instructions, labelling and marketing claims, which set the safety expectation the product must meet).
The useful question is not which risk category a company falls under but what the company’s records would look like to a judge.
The compliance documentation does not go dormant once EU market access is granted. When a product liability claim arrives years later, a court measures defectiveness against the safety requirements the file was written to satisfy. The court can order the compliance file disclosed under Article 9 of the new Product Liability Directive (which lets a claimant who presents facts and evidence sufficient to support the plausibility of a damages claim obtain a court order for disclosure of relevant evidence in the defendant’s control, limited to what is necessary and proportionate). The court presumes defectiveness (subject to rebuttal, Article 10) if technical documentation is not produced (refused, or produced in an incomplete or obstructive manner), and also where the product fails mandatory safety requirements intended to protect against the risk of damage that occurred (Article 10).
Worth noting that compliance work is usually regarded as a mere form-filling exercise to get access to EU markets. But it is much more under this mechanism. Everything written down in the technical documentation is a potential piece of evidence, which is why the quality of the file is not a regulatory formality. The documentation is the company’s future defense, written years in advance and without litigation in mind, and it will matter whether that was done well.
The product liability regime applies to products placed on the market after 9 December 2026. The high-risk requirements and the compliance obligations bind Annex III providers only from 2 December 2027, and Annex I products from 2 August 2028, under Regulation (EU) 2026/1744. What the deferral did not move binds most companies already: the Article 50 transparency and AI content labelling duties apply from 2 August 2026 (with a transitional period to 2 December 2026 for systems already on the EU market); the Article 4 AI literacy duty applies; the general purpose AI (GPAI) obligations have applied since August 2025; and the Article 5 prohibitions (subliminal or manipulative techniques; exploitation of vulnerabilities; social scoring; predictive policing; untargeted scraping of facial images from the internet or CCTV footage to build or expand facial recognition databases; emotion recognition in the workplace and in education (with medical and safety exceptions); biometric categorization; and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow, judicially authorized exceptions) have been in force since February 2025. Plus two additional prohibitions added by the Digital Omnibus on AI (Regulation (EU) 2026/1744), that is the amending regulation to the EU AI Act): so-called nudifier applications and AI systems used for generating non-consensual intimate imagery or child sexual abuse material are prohibited in the European Union from 2 December 2026.
An example from the list above. A company making a customer-facing chatbot available to EU users owes the Article 50(1) duty of the EU AI Act, to design the AI system so that its human users know that they are interacting with AI (unless that is obvious to a reasonably well-informed person). This duty is with the provider and the company deploying the chatbot obtains the warranty from its provider. If the chatbot is the deployer’s product, then the deployer qualifies as the provider and the system design transparency obligation applies to it.
As far as high-risk AI systems are concerned, in the interim period (between 9 December 2026 and 2 December 2027), a court assessing the defectiveness of a product placed on the EU market measures the product against general European product safety law, because the EU AI Act’s specific requirements are not yet mandatory. (For embedded systems, the interim interval extends from 9 December 2026 to 2 August 2028).
Comparing US and EU civil liability systems
European civil liability lacks the features that make US litigation exposure challenging to anticipate. In Europe:
- Under Article 6(1) of the new EU Product Liability Directive ((EU) 2024/2853), the categories of recoverable damage are enumerated (death or personal injury, including medically recognized damage to psychological health, damage to property not used exclusively for professional purposes, and destruction or corruption of data not used for professional purposes). Article 6(2) adds that non-material losses flowing from those harms are compensable to the extent national law provides. Recoverable damages are limited to natural persons (a company cannot sue for its own losses under the regime, which leaves business-to-business disputes to contract and to national non-contractual liability rules (tort). For those who can, the recoverable amount is unlimited (Article 15 forbids capping or excluding this liability vis-à-vis the injured person, by contract or by national law). The exclusions matter as much as the inclusions: the Directive does not cover damage to the defective product itself, and pure economic loss, privacy infringements and discrimination do not by themselves trigger liability under it (Recital 24). A discriminatory screening AI tool is a GDPR and national law matter rather than a product liability one.
- There is no US style discovery: disclosure under Article 9 of the new Product Liability Directive is ordered by the court, limited to what is necessary and proportionate, and is available to defendants as well.
- There are no juries and no punitive damages. Also, no punitive multipliers. Compensation is capped at the harm actually proved. So no jury can turn a 2 million euro injury into a 200 million euro verdict. The worst case scenario cannot exceed the actual damage, which makes the exposure estimable in advance. In other words, if we just take State Farm v Campbell, 538 U.S. 408 (2003) (a case where the same proved harm supported 1 million dollars in compensatory damages for emotional distress, but then an additional 145 million dollars in punitive damages; the US Supreme Court held the 145 to 1 ratio unconstitutional and remanded, and the Utah Supreme Court set the figure at roughly 9 million on remand), that multiple fold swing on identical facts illustrates the pricing problem Europe does not have. Or, if we want a product liability example of the same phenomenon: just take BMW v Gore, 517 U.S. 559 (1996). There, 4,000 dollars were awarded in compensatory damages for a repainted car, followed by 4 million dollars in punitive damages from the jury, halved to 2 million by the Alabama Supreme Court before the US Supreme Court held even that grossly excessive and remanded.
- Collective redress exists in Europe, but it works only through vetted (qualified) entities under the Representative Actions Directive (EU) 2020/1828, and not through opt out class actions. Qualified entities are increasingly active and several Member States permit third party litigation funding, so European collective claims are an established feature of the European litigation. What Europe lacks is the silent, automatic aggregation of an opt out class.
In practice, EU AI liability is narrower and more predictable than the litigation exposure most US companies already carry domestically.
In addition to the above (fewer categories of recoverable damage, fewer claimants, no punitive multiplier), the European exposure is differently constructed, has a start date (9 December 2026), and most of it is managed by decisions taken before a company enters the EU market.
Much of the outcome of a future European claim is set before the product is on the EU market, instead of during litigation. The pre-market entry documentation determines more of the outcome in Europe than in the US, because what moves US outcomes after a case is filed is simply not there in Europe. In the US, discovery is itself a weapon, because its cost and sheer volume push parties to settle independent of the merits; the jury enters as an unpredictable fact finder; punitive damages mean the same liability finding can produce wildly different amounts (see State Farm example above); and the class action mechanism can turn a defendant’s exposure from minimal to existential (through aggregation).
Who bears strict liability in the EU is decided by how a company sets up its market entry because the choices determine the liability chain: manufacturer, importer, authorized representative, fulfilment service provider, and where none of those can be identified, distributors and marketplaces. And what the defectiveness standard will be is decided by the technical documentation (file) and the company’s own instructions and marketing claims. Whether a company comes out of an Article 9 disclosure order intact is decided by whether the compliance documentation exists and stands up to a court’s scrutiny. Whether an Article 22 (automated decision making) problem exists is decided by whether the human review step is genuine. Whether a rightsholder’s cease and desist letter must be taken seriously is decided by training data provenance and the vendor indemnity. In US litigation the decisive events happen after filing, in discovery and before a jury.
In the European model most of what a court will see already exists when the product is placed on the EU market, which is the first making available of the product in the EU. However, there is a longer tail of exposure.
- The ten year expiry period under Article 17 – corresponding to a statute of repose in US terms – starts running from this point: after the product is placed on the market or put into service, or substantially modified. The injured person’s rights under the regime are extinguished at the end of the period, unless the person initiated proceedings before then.
- This expiry period is extended to twenty-five years for personal injuries that produce no symptoms within the ten years.
- However, there is also a separate three year limitation period (Article 16) that starts running from the injured person’s actual or constructive knowledge of the damage, the defect and the identity of the liable operator. This period does not run from the sale. Therefore, for example, a prospective employee can file a claim seven or eight years later, after learning that s/he had been given the score by the software. This may be a longer window of exposure than US practice would suggest (a state statute of repose cutting off all claims about ten to twelve years after the sale of the product).
As a general rule of the new Product Liability Directive, products placed on the EU market before 9 December 2026 stay under the old EU regime (this is the so called grandfathering rule) designed for physical goods and leaving the status of standalone software unsettled.
- The grandfathering rule gives companies already on the market time and companies entering a date to work towards. The transition rule deserves attention, though, because it is narrower than it looks: a substantial modification after 9 December 2026 (including significant software update) will count as a new placing on the market and the product will fall under the new regime from that point.
- The exception matters to anyone shipping software updates, which is everyone. A SaaS company shipping updates continuously can lose the benefit of the old rules the first time an update changes what the product does or how safely it works.
- Substantial modification is defined (Article 4(18)) by a two prong test: the change must alter the product’s original performance, purpose or type in a way not foreseen in the manufacturer’s initial risk assessment, and must change the nature of a hazard, create a new one, or increase the level of risk. Both prongs are required, which is why routine patching should rarely meet them, and courts have not yet applied the threshold. Recital 40 names the continuous learning of an AI system expressly. A substantial modification does not only move the product into the new product liability regime, but it also starts a new ten year expiry period (Article 17).
Which companies does European AI liability reach?
US businesses looking to EU markets must be aware of EU AI liability exposures along the three regimes outlined above. Those businesses need not be a GPAI provider to have European AI litigation posture. Nor is EU litigation posture particular only to AI companies.
Any business shipping software into Europe is within the Directive’s reach, with or without a trained (learned) component, and so are the related digital services necessary to a product’s function. Two exclusions are worth naming. The Directive does not cover information as such, including content of digital files and mere source code (recital 13). And free and open source software developed or supplied outside a commercial activity is excluded (Article 2(2)); the exclusion protects the upstream open source developer, not the company that commercializes the result. If a company integrates free software into a product which it places on the market, it is liable as the manufacturer (recital 15).
The EU AI Act’s obligations are an add-on through which the compliance documentation, as described above, becomes the evidence when a claim is filed. Beyond the Annex III categories named earlier (recruitment screening, credit scoring, insurance pricing, educational assessment, clinical decision support), the affected products include: industrial control and robotics, connected consumer hardware with AI features, fraud detection, logistics and routing, content generation tools and customer-service agents that take actions on a consumer’s behalf.
Before placing a product on the EU market
If a US company is planning EU entry in 2027, it is taking the decisions now that will determine its European liability years later. It decides which entity imports, who signs as authorized representative, what its technical documentation includes, whether there is meaningful human review.
Instead of asking whether the company is in Annex III, the more useful information is what the company’s existing written records would look like to a judge in Hamburg or Milan a few years from now.
Answered before EU market entry, these are decisions. Answered after a claim is filed, they are findings.
Holon Law Partners works with US clients to secure the best strategic answers, both from the business and legal point of view.
Copyright: the regime where case law already exists
European courts have already ruled here, against the providers. The Munich I Regional Court held in GEMA v OpenAI (November 2025, concerning song lyrics) and GEMA v Suno (31 July 2026, concerning six musical compositions) that works memorized in an AI model are copyright reproductions, and that training offshore did not put the conduct beyond the reach of copyright enforcement in a European court. The EU AI Act did not affect the outcome in either ruling: European market access rules and European liability rules are separate systems, and compliance with one is no defense under the other.
In Suno, a US company was held liable in a German court, under US law, for conduct that happened entirely in the United States. The German court took jurisdiction over the US training under a venue rule available to collecting societies (section 131 of the German Collecting Societies Act that gives collecting societies an expanded venue to reach relevant infringements abroad), while the German “acts” of exploitation (memorization by the model on German servers, reproduction, communication to the public) were directed at the German market.
For now, everything remains under challenge: GEMA v OpenAI is on appeal before the Oberlandesgericht München (Munich Higher Regional Court), and the Suno judgment is first instance (not final), with an appeal open to the same court.
The Court of Justice of the European Union in Luxembourg will pronounce for the first time on how copyright applies to generative AI in Like Company v Google (C-250/25), a case referred by a Hungarian court and heard by the Grand Chamber (a signal the Court considers the questions fundamental). The Advocate General’s much anticipated opinion is expected on 3 September 2026. (Part two of this post will analyze the copyright case law closely.)
On 9 September 2026, Holon Law Partners will take up the AG opinion and the wider AI litigation landscape at the firm’s Budapest AI Breakfast, which is organized alongside the prestigious regional AI SUMMIT 2026 BUDAPEST happening on 7-8 September 2026.
In Budapest, Holon Law Partners will bring together leading AI practitioners – including compliance leads -, policy makers, regulators and researchers discussing the stakes and anticipating the changes AI is bringing.
