Sekėjai

Ieškoti šiame dienoraštyje

2026 m. liepos 23 d., ketvirtadienis

Laboratories for Progress: The AI ​​Act is set to be amended to ease the burden on the economy. However, if companies and research institutions are deprived of the opportunity to develop AI in compliance with the law within AI regulatory sandboxes, the EU will be making a fatal mistake.


“The EU AI Act is set to be amended before it comes into full effect. It speaks well of the legislature to rectify imbalances in a law before it causes harm. If the regulations of the so-called "AI Omnibus" secure a majority, the amending act will yield positive results. For instance, the burdensome obligations intended for high-risk AI systems will not apply starting in August 2026, but rather from the end of 2027.

 

This gives businesses breathing room to adapt to the rules governing the development and operation of this technology—which is desirable and sometimes vital, yet also dangerous and highly complex. The legal obligation for operators to possess AI competence is being clarified and underscored. This is crucial, as the liability consequences of using a dangerous tool incompetently can lead to financial ruin. A sound solution is also envisaged regarding the data protection authorization for training AI models—an approach foreshadowed by the Higher Regional Court of Cologne in a 2025 ruling on the matter.

 

However, another planned change is highly controversial. The aim is to avoid duplicative regulation. To this end, a number of product sectors—including medical devices—are to be excluded from the scope of the AI ​​Act. These AI products would then only need to meet the requirements of their specific product legislation.

 

The argument in favor is that products in which AI performs control functions are already so strictly regulated that the AI ​​Act’s additional obligations constitute a burden without added value. This is already the case for cars and aircraft under the current version of the AI ​​Act. Other products, however, must comply with AI-specific regulations under the AI ​​Act in addition to the applicable product legislation. This applies, for example, to children's toys—such as teddy bears with voice bots—that can influence children, as well as to products manufactured and operated for medical diagnostics that are trained using sensitive health data. This is set to change. In the future, the AI ​​Act is largely no longer intended to apply to the specific product groups listed within it—including medical devices.

 

However, the planned new regulation creates a problem that must be resolved if the development of AI products in the EU is not to suffer severe setbacks. The catch can be illustrated by the development of AI for medical diagnostics. An international consortium, led by the Department of Neuropathology at Heidelberg University Hospital, is conducting the "EUcanAI" project. Funded by the EU’s Horizon research program, the project aims to improve care for brain tumor patients through data processing.

 

Specifically, the goal is to develop powerful yet specialized—and therefore controllable—AI models to support the entire course of treatment. Designed for a "high-risk" yet medically vital and legally supported purpose, this modular AI system is intended—subject to patient consent—to listen in on doctor-patient consultations. It will be capable of asking guiding questions, evaluating MRI scans and tissue samples, and even identifying additional treatment options during surgery.

 

The project requires the analysis of vast amounts of highly sensitive data. To ensure that such data can be lawfully processed for research purposes—specifically for developing an AI model—the research must take place within AI regulatory sandboxes. However, the AI ​​Act only provides for these protected environments if the Act’s scope of application is triggered. The AI ​​Act wisely envisions these sandboxes as spaces where health data can be processed under state supervision, balancing data protection with innovation.

 

A critical issue must now be navigated during the revision of the AI ​​Act. If medical devices are excluded from the scope of the AI ​​Act, they also lose the protection afforded by the legislation. The Cologne Research Center for Media Law at TH Köln is providing support for this funded AI development project aimed at fighting cancer and from a data protection law perspective.

 

If medical research loses the protection afforded by the "regulatory sandbox" (real-world laboratory), the legal scope for saving lives through data processing becomes extremely precarious. Existing legal mechanisms—including the right to use health data and conduct research outside of AI regulatory sandboxes—likely cannot provide adequate support, as they do not specifically account for the unique characteristics of AI training.

 

The AI ​​Act’s legislator could resolve this issue by stipulating within the Act’s scope of application that certain provisions of the AI ​​Act—despite the far-reaching existing sectoral exemptions—such as those for cars and aircraft—continue to apply. If medical devices were also to be excluded from the scope of the law in the future, the legislation could specify that the AI ​​Act’s chapter on innovation-promoting measures—which contains the rules regarding regulatory sandboxes—remains applicable to these products. Consequently, providers of the products in question—specifically medical devices—would have the option to develop their products within AI regulatory sandboxes in a manner that ensures legal certainty and compliance, while simultaneously upholding data protection requirements.

 

Baden-Württemberg recognized the potential of regulatory sandboxes at an early stage. Since 2015, more than 40 such sandboxes have received funding from various government departments in the state. From a data protection perspective, the supervisory authority was able to support these projects through advisory services. A demand for such concepts has also emerged in other regions; in North Rhine-Westphalia, regulatory sandboxes are now distributed across the entire state. However, prior to the AI ​​Act, there were no mechanisms allowing for specific data processing activities to go beyond standard data protection regulations—under controlled conditions and in close coordination between project management and the supervisory authority—within the framework of "genuine" AI regulatory sandboxes.

 

It is highly regrettable that the establishment of AI regulatory sandboxes as a measure to foster innovation is set to be scaled back in specific sectors before the initiative has even gained momentum. This squanders the potential to embed a high degree of legal certainty right from the project design phase. Indeed, the Bundesrat recently recommended the exact opposite in its proposed amendments to the "Digital Omnibus" legislation: a much broader integration of AI regulatory sandboxes—extending beyond the AI ​​Act to include provisions within the GDPR framework.

 

Innovation happens locally—at public-sector research institutions or at business hubs at the state level. These could take the form of existing regional digital hubs. Another crucial factor will be determining who decides on access and based on what criteria. The European Commission’s general guidelines still require further elaboration in this regard.

 

In any case, the federal states have now thrown their hat in the ring; a recent Bundesrat resolution called upon the federal government to amend the draft legislation implementing the AI ​​Act to ensure that states have the option to establish their own AI labs. There are valid doubts as to whether this is possible under current law. The consequences—extending well beyond the states themselves—would be significant: regional areas of specialization would become virtually impossible; close links between the regional economy, academia, labs, and authorities would be severed; the kind of stimulating competition that drives innovation among labs could not emerge; and a new dependency on the federal government would be created.

 

In pursuing their own innovation initiatives, the states can also point to the AI ​​Act, which explicitly permits AI labs at the regional or even local level. If the federal government accommodates this request and the states actually and swiftly exercise these options, it could provide a major boost to German AI development—which faces fierce international competition—while maintaining reliability and high quality standards, thereby driving significant progress.

 

It is in the interest of both the federal government and the states to find a sound solution that establishes Germany—domestically, within Europe, and globally—as a location offering a reliable and secure framework for innovation. A single federal AI regulatory sandbox will not suffice to provide companies and research institutions with the scope needed to propel Germany forward. Yet, there are currently voices arguing that a single AI regulatory sandbox established under the AI ​​Act—hosted by the Federal Network Agency (the future market surveillance authority)—would be enough.

 

Such a view is open to doubt; once the engine of AI development in this country truly starts running, a single authority in Bonn with a broad mandate would be hopelessly overwhelmed by the task of supporting AI development across research institutions and companies nationwide. The matter at hand is too important to be allowed to fail due to bureaucratic overload or turf wars over regulatory oversight regarding AI regulatory sandboxes. From a constitutional perspective—characterized in the federal system by a division of labor and cooperation between the federal government and the states—the establishment of AI regulatory sandboxes at both federal and state levels is highly welcome.

 

Negotiations between the EU Commission, the European Parliament, and the Council of the EU Member States are scheduled to conclude on April 28, 2026. The outcome will reveal whether the EU will provide a stable legal framework for progress in AI regulatory sandboxes in the future. We have outlined solutions and hope that lawmakers do not squander this important milestone. In Germany, the Federal Government and the Bundesrat are fundamentally in agreement. The government supports the establishment of AI regulatory sandboxes in the federal states. However, this position must also be unequivocally articulated in the national AI legislation currently being enacted. A mere reference to state-level AI authorities in specific sectors is insufficient. What is required is an unambiguous allocation of competence to the states, granting them the freedom to establish AI regulatory sandboxes in areas of their choosing. This approach fosters competition and creates room for maneuver. If European and national laws mesh effectively and the legal framework for AI regulatory sandboxes is established at both federal and state levels, the business and scientific communities can bring it to life. The federal government cannot achieve this alone.

 

Prof. Dr. Bernd Grzeszick teaches at Heidelberg University and serves as a judge at the Constitutional Court of North Rhine-Westphalia.

 

Andreas Jaspers is a lawyer and a member of the Society for Data Protection and Data Security (GDD e.V.).

 

Prof. Dr. Tobias Keber is the State Commissioner for Data Protection and Freedom of Information in Baden-Württemberg.

 

Prof. Dr. Günter Krings (CDU) is a Member of the German Bundestag.

 

Dr. Dominik Roderburg is a judge at the Higher Regional Court of Cologne and Head of the State Modernization Unit at the State Chancellery of North Rhine-Westphalia.

 

Prof. Dr. Dr. Felix Sahm is Medical Director of Neuropathology at Heidelberg University Hospital.

 

Prof. Dr. Rolf Schwartmann heads the Cologne Research Center for Media Law at the TH Köln (University of Applied Sciences).

 

Axel Voss (CDU) is a Member of the European Parliament.

 

Kai Zenner is the Head of Office for Axel Voss.” [1]

 

1. Labore für den Fortschritt: Die KI-Verordnung soll geändert werden, um die Wirtschaft zu entlasten. Nimmt man Unternehmen und Forschungseinrichtungen aber die Möglichkeit, in KI-Reallaboren KI rechtskonform zu entwickeln, macht die EU einen fatalen Fehler. Frankfurter Allgemeine Zeitung; Frankfurt. 27 Apr 2026: 19. Von Bernd Grzeszick, Andreas Jaspers, Tobias Keber, Günter Krings, Dominik Roderburg, Felix Sahm, Rolf Schwartmann, Axel Voss und Kai Zenner

Komentarų nėra: