Skip to content
Flag_of_Germany

Germany

Tools Tools
AIRA | AKIRA | AKLS | ALeKS | Beck-Noxtua | Codefy/ASTRA | Fake-Shop-Detektor | FRIDA | hessenDATA | INDATA (SMART) | JAIF | Jailbox | JANO | Lexis AI Workspace | Mobile Network Analyser | Palantir Gotham | PolizeiCloud Hessen | PreCobs | Project PerIS | Relativity aIR | SKALA | Specialised systems | StruKi | VeRA | Videmo 360
Tasks Tasks
Case management | Charging support | Data review and analysis | Decision-making support | Evidence review and analysis | Legal research, analysis and drafting support | Operational support | Predictive analytics
User Users
Law enforcement | Prosecutors | Courts | Defence
Scope Scope
Nationwide
Training Training
Yes, but not systematic or mandatory
Regulation Regulation
Use of AI in law enforcement and the judicial branch in Germany is mainly governed by the EU AI Act and the rules under the German Code of Criminal Procedure
Cases Cases
The German Constitutional Court has already ruled on law enforcement and intelligence surveillance powers encompassing AI and thereby set out strict requirements in particular to justify interference with the fundamental right to informational self-determination
Insight Insights
AI-enabled tools are being tested in German law enforcement and in some cases already in use. In law enforcement, several German states are using versions of Palantir Gotham which is subject to criticism and being challenged on constitutional grounds
Information uploaded as at June 2026

AT A GLANCE

Germany is increasingly integrating AI across law enforcement, prosecution, and the courts, within its federal system and under strong constitutional oversight. Police in several states use AI-powered data integration platforms such as Palantir Gotham (e.g. hessenDATA in Hesse and VeRA in Bavaria), predictive policing tools (e.g. SKALA), automated licence plate recognition, facial recognition systems, and AI-based child abuse material detection, though some deployments—particularly in Hesse—have been narrowed following a 2023 Constitutional Court ruling requiring stricter safeguards. Prosecutors use AI for detecting online fraud, analysing financial crime and mobile data, reviewing large volumes of digital evidence, and identifying child exploitation material. Courts focus on administrative and supportive applications, including anonymisation of judgments, document structuring and summarisation, transcription, and limited drafting assistance, while rejecting automated judicial decision-making; a 2025 national AI strategy for the judiciary emphasises a human-centred, “ethics by design” approach. Defence lawyers have access to AI-powered research and evidence-review tools, though overall uptake is unclear. There is no mandatory nationwide AI training yet, but ad hoc judicial and police training is available, and coordinated competency development is planned from 2026 onward. 

As at June 2026, there is no statutory regime specifically governing the use of AI in criminal proceedings; the primary binding framework is the EU AI Act. Various professional and institutional bodies have issued guidance for practitioners, including the Federal and State Ministers of Justice' Joint Declaration on AI in the Justice System, the German Federal Bar's guidance on AI use, and a paper on AI and algorithmic systems prepared for the Presidents of the Higher Regional Courts and the Federal Court of Justice, alongside guidelines for public administration and law enforcement at federal and state level. In addition, existing general laws — including the German Constitution, the Code of Criminal Procedure, the Federal Data Protection Act, the Law Enforcement Directive and GDPR as implemented in German law, and the Criminal Code — may limit the use of AI and AI-generated material in criminal proceedings. German courts have also, in recent cases, examined the constitutionality of automated data analysis and surveillance measures, including Federal Constitutional Court decisions on the HessenDATA system and surveillance powers under the Hessian Protection of the Constitution Act.

Use

As at June 2026, AI is gradually finding its way into German law enforcement, the judiciary, and legal practice. Across sectors, AI tools are being tested and, in some cases, are already being implemented.

Law enforcement

As Germany is a federal state, the federal government takes responsibility for deploying and implementing AI software in law enforcement. For example, the Federal Ministry of the Interior (Bundesministerium des Innern) has established an AI campus ‘KI-campus’, to coordinate the transfer of knowledge in the field of AI technologies used for police work. The Federal Criminal Police office has also established a central coordination office for AI to coordinate the needs and requirements of police forces with regard to AI.

Operational support

Police in Hessen use AI applications on PolizeiCloud Hessen, a safe cloud environment operated by the Hessian centre for data processing (Hessische Zentrale für Datenverarbeitung) and the Hessian police, to reduce data inputs. While the Hessian police previously used decentralized systems requiring seized evidence, particularly image and video material, to be sent from one agency to another, such evidence can now be accessed centrally by multiple users via a forensic desktop. Further, among other systems, this application is used in child pornography cases to classify the material automatically. This has reduced data filtering by officers and, as such, reduced their emotional distress. The platform is logged, and only certain police officers are able to use it.

Predictive analytics

Bavarian State Police and Baden-Württemberg were the early pioneers of a data analysis tool called PreCobs, first deployed in 2014. This tool analysed historical burglary data to determine whether and where a second break-in was likely to occur within a short window of time. Police officers would then increase patrols in the identified hotspots. The tool was later dropped in major cities as the algorithm lacked enough data points to remain statistically reliable.

SKALA was a tool piloted in 2015 by the State Police of North Rhine-Westphalia. The tool forecasted residential burglaries and commercial theft by weighing hundreds of environmental factors, from proximity to highway exits to the socioeconomic layout of a neighbourhood. As at June 2026, SKALA is currently full-scale operated. It has expanded from its initial six pilot cities to cover almost the entire state of North Rhine-Westphalia and is currently being integrated into the State’s broader ‘Police 2040’ digitisation strategy.

Data review and analysis

The Federal Criminal Police Office operates the Federal Facial Recognition System, which has been available since 2008. This tool serves as Germany’s central retrospective biometric search engine. The system is used by investigators to identify known suspects by uploading images and comparing them against their database, which as at June 2026 holds over 7 million images of previously processed individuals. Following a major AI-driven upgrade in late 2024, the system has significantly improved its accuracy in ‘non-cooperative’ scenarios, such as those with poor lighting or difficult angles. The statutory legal basis for the use of this system is unclear.

Several law enforcement agencies in Germany have also deployed other facial recognition and surveillance systems:

Berlin

Between 2017 and 2018, the Berlin police force piloted facial recognition tools in train stations. The police force reported positive results, but the pilot never developed into a full-scale programme, and civil society organisations suggested that the technology had a tendency to produce false positives.

Görlitz

Görlitz Police, in collaboration with tech firm OptoPrecision, operates Project PerIS (Saxony). This tool has been monitoring the German-Polish border since 2019 to combat cross-border property crime and human trafficking. It uses high-resolution infrared cameras mounted on stationary columns and mobile vans to capture both vehicle license plates and the faces of drivers and passengers through windshields, even at night. While it recently faced a constitutional hurdle in late 2023 regarding its specific legal basis for automated 'live' matching, the Saxony Interior Ministry has continued its operation by pivoting the system's legal justification toward general crime prevention and retrospective investigation. The system was expanded to the city of Zittau in 2024.

Hamburg

After the 2017 G20 Summit, Hamburg Police used an automated facial recognition system called Videmo 360 to analyse large volumes of images and videos for criminal investigations, creating biometric 'face IDS' for faces appearing in the material and enabling searches for both unknown individuals and known suspects. In August 2018, the Hamburg Data Protection Authority said that this kind of biometric mass processing and storage lacked a sufficiently specific legal basis, and that the biometric data should be deleted. The police force stopped using the system in 2020.

Hesse

The police in Frankfurt am Main (the largest city in Hesse) have been implementing an AI surveillance video system since 10 July 2025 in a crime hot-spot of the city, located around the train station. By using it, the police aim to locate missing persons to protect them from the risks of drug addiction and prostitution, and to find terrorism suspects. Two years prior, in 2023, the public prosecutor’s office of Giessen, Hesse working together with local police used AI in connection with the Eritrea-Festival to analyse police video footage and was thus able to identify up to 650 suspects that attacked police officers and committed other crimes. The legal basis for this specific use of AI remains unclear.

In 2018, Mannheim piloted a project entitled Intelligent Video Surveillance’, which evolved into a long-term, semi-permanent operation. This tool uses AI to detect certain behaviour in public places, such as running, hitting, or falling, but without carrying out facial recognition. As at June 2026, the project is still in operation.

In 2019, the Ministry of Justice of North Rhine-Westphalia initiated a research project on the development and use of an AI tool to prevent suicide in correctional facilities. 'Event based' video surveillance was intended to detect critical situations in detention rooms at an early stage. The Ministry of Justice of Lower Saxony has run a similar project. To establish a legal framework for future deployment of such automated surveillance systems, an amendment to Section 81a of the Lower Saxony Prison Act was passed in July 2022, restricting deployment to averting a danger to the life of a prisoner.

AKLS is an automated license plate recognition software used by the Bavarian and Brandenburg State Police since 2006. It uses cameras mounted on bridges or patrol cars to instantly scan passing license plates and compare them against search lists for stolen cars or vehicles linked to violent offenders. It is currently in full scale operation.

Finally, as at June 2026, at least three federal states use versions of Palantir Gotham for AI-enabled data integration and analysis. Palanatir Gotham was initially created for the US Central Intelligence Agency. It allows police and public prosecutors to create a profile on every person it deems interesting for law enforcement purposes. This profile includes criminal records, bank accounts, registered cell phones, addresses and names. Additionally, it can give an assessment of which persons are likely to commit crimes or to become victims of a crime.

Several law enforcement agencies have also deployed other AI tools:

Hesse

HessenDATA was deployed by Hessen State Police in 2017 to help combat terrorism and organised crime. Built on Palantir’s Gotham platform, the system pulls data from a number of separate police databases to find hidden links between people, vehicles, and locations that a human analyst might not notice. As at June 2026, the system is in full-scale operation in Hesse, though it underwent a major legal backlash in 2023. Following a landmark ruling by the German Federal Constitutional Court (ruling 1 BvR 1547/19 and 1 BvR 2634/20, see more below in 'Cases'), the state had to strictly rewrite the laws governing it to ensure the software isn't used against innocent citizens.


The deployment of Palantir in Hesse has been scrutinised by a parliamentary investigative committee regarding procurement and data protection concerns.

Bavaria

Bavaria uses VeRA, a version of Palantir Gotham, which acts as a cross-procedural research and analysis platform.


VeRa has been used in Bavaria since September 2024 and uses data not only from police databases, but also from other databases of the Federal Motor Transport Authority, as well as the central alien registry.


In most cases, VerA is used in low-risk cases such as crimes against property, rather than cases involving threats to life, bodily integrity, and freedom of individuals.

North Rhine-Westphalia

North Rhine-Westphalia uses Palantir Gotham (or a version thereof) for data analysis, but with opposition from the Minister of Interior, who announced that in the future, he would only offer short-term contracts with Palantir.

Lower Saxony

Though data analysis tools are not in use in Lower Saxony at as June 2026, the state parliament began debating amendments to the state policing law in November of 2025. With these amendments, the state would be allowed to biometrically compare images from the internet for law enforcement purposes and to prevent terrorist attacks. However, as the proposed legislation touches on European law, federal laws, and the case law of the Federal Constitutional Court in several respects, it is unclear how long the legal review will take. According to media reports, the law may be passed in 2026 or 2027.

Baden-Wuettemburg

As at June 2026, the state of Baden-Wuettemberg plans to roll out similar software at the end of 2026, according to media reports. The Federal Government is also assessing and debating a roll out of the software on a federal level.

According to statements from the Ministry of Interior of the State Baden-Wuerttemberg and the Chief Digital Officer of the Hessian Police, to date, there appears to be no German or European competitors of the software.

Prosecutors

In June 2025, the Ministers of Justice of the 16 federal states in Germany and the Federal Minister of Justice declared in a joint statement that they intend to broaden the use of AI in the judiciary. With reference to the EU AI Act (see below), the statement emphasised the significance of a human-centred approach requiring that decision-making must remain human-centred.

Charging support

In 2023, the Attorney General’s Office in Bamberg, the Bavarian State Ministry of Justice and the Austrian Institute of Technology in Vienna began a cooperation on a project entitled Fake-Shop-Detektor. This tool uses AI to examine unknown online shops in real-time for more than 21,000 characteristics and issues a warning if a shop appears suspicious. The aim is for the tool to identify fake shops and underlying structures at an early stage to investigate criminal activities in the e-commerce sector more efficiently.

As part of a research project conducted by Microsoft Germany and the Central Cybercrime Contact Point, a hybrid cloud solution for automated detection and categorisation of child and youth pornography called AIRA ('AI-enabled rapid assessment') was developed. In the test phase, the tool was able to correctly categorise images into criminal depictions versus permitted content in 92 percent of all cases. Due to its open architecture, the cloud-based solution could also be used by other national or international authorities in the future. As at June 2026, the practical application based on this research is currently being further developed in collaboration with the State Criminal Police Office of North Rhine-Westphalia as part of the JAIF ('Joint AI Force') project (see also below) and is already ready for practical use in its initial phases.

Since September 2022 and until September 2025, the Attorney General’s Offices (Generalstaatsanwaltschaften) of Frankfurt am Main, Celle and Stuttgart have been engaging with other stakeholders, such as Leipzig University, on a research project called MaLeFiz. The project’s aim is to investigate how AI might more efficiently identify suspicious financial transactions that might be linked to money laundering and terrorist support.

Legal research, analysis and drafting support

Prosecutors may benefit from legal research AI solutions developed by providers of legal databases such as the Lexis AI Workspace and Beck-Noxtua, which is already being used by major law firms in Germany.

Evidence review and analysis

JAIF, developed by the state of North Rhine-Westphalia, is a high-performance AI framework used to pre-assess vast quantities of electronic evidence, specifically photo and video material, for child sexual abuse content. Among others, JAIF pursues the practical application of the research results gained through AIRA. This has allowed prosecutors to determine the ‘incriminating status’ of evidence instantly, shielding investigators from traumatising imagery and accelerating decisions on whether to seize or return devices.

Another tool developed by the state of North Rhine-Westphalia is Jailbox, to support the legally required monitoring of prisoners’ correspondence. The tool scans handwritten or foreign-language mail, converting it into machine-readable text and providing immediate translations.

The State of Saxony has launched the Mobile Network Analyser (MoNA), a specialised platform for the forensic analysis of mobile communications. MoNA enables prosecutors to analyse chat histories across multiple devices simultaneously, automatically transcribing voice messages and translating foreign-language texts.

There is no general statutory provision permitting the use of AI-based facial recognition in prosecutorial investigations in Germany as at June 2026. While facial recognition technology has been used by multiple law enforcement agencies, as noted above, these instances have primarily been based on specific security laws (such as Section 14 of the Hessian Police Law (Hessisches Sicherheits- und Ordnungsgesetz)). In other instances, the legal basis for such usage has been unclear and in some cases, the use has been terminated. In general, AI based data processing is considered a significant interference with the fundamental right to informational self-determination pursuant to Article 2 (1) in conjunction with Article 1 (1) of the German Constitution (Federal Constitutional Court, judgment of 16 February 16 2023, 1 BvR 1547/19, 1 BvR 2634/20, NJW 2023, 1196, 1199, para. 50). Pursuant to Article 20 (3) of the German Constitution, such interference requires a legal basis that specifies the purpose for which the data will be used in a precise and sector-specific manner (Federal Constitutional Court, order of 4 April 2006, 1 BvR 518/02, NJW 2006, 1939, 1947, para. 150). Such interferences can therefore not be justified by the general clauses set out in Sections 161, 163 and 98c of the German Code of Criminal Procedure (Strafprozessordnung – StPO). As at June 2026, the Federal Ministry of Justice has proposed a new section 98d StPO, which is under legislative consideration and would allow prosecutorial agencies, under certain circumstances, to investigate the facts of the case, to establish the identity of, or to determine the whereabouts of the accused or a witness by comparing biometric data from criminal proceedings with biometric data publicly available on the internet using an automated data-processing application.

Courts

In April 2025, the German E-Justice Council (E-Justice-Rat) issued a strategy paper to coordinate nationwide adoption of trustworthy AI in the judicial sector. In view of potential risks especially related to generative AI systems, the strategy is built on the premise of an ‘ethic by design approach’, to ensure protection of the rights of all actors and affected parties in judicial proceedings. At the same time, the paper points out the potential increase of efficiency of judicial processes, including through the organisation of legal documents and data, transcription, data-driven proposals to support decision-making, and anonymisation of sensitive information.

Case management

A variety of case management systems are currently either in development or deployed in a number of locations in Germany:

Baden-Wuertemberg

StruKi (Structuring with AI or Strukturierung mit KI) is currently being developed under the coordination of the Ministry of Justice and Migration of the State Baden-Wuertemberg. The tool uses AI to process applications for financial support for legal costs (Prozesskostenhilfe) in court proceedings, the preparation of cost decisions in mass proceedings, the anonymisation of documents, and summarisation of electronic case files. StruKI was initially planned to be made available to all courts and prosecutor’s offices in Germany from 2023-2024 and is currently being developed by the state of Baden-Wuerttemberg for all states in Germany. Following a strategic decision in 2024, the findings of Codefy/ASTRA (see below) are integrated into StruKI.


Baden-Wuertemberg has also contributed to the development of the JANO tool, discussed below.


The Ministry of Justice and Migration of Baden-Wuerttemberg is currently pursuing the project AKIRA to support the summarisation and pre-structuring of court files. The goal is to enable judges to review files more quickly, accurately, and comprehensively, and allow them to focus more of their time on case management and legal assessment. The project is intended to initially be used in Social Courts (Sozialgerichtsbarkeit).


The Regional Court of Hechingen has piloted Codefy/ASTRA, discussed below.

Bavaria and Rhineland-Palatine

Lower Saxony, Bavaria and Rhineland-Palatine have been cooperating since 2025 on the project INDATA (formerly known as SMART), which aims to develop an AI-powered tool for streamlining data input processing in courts and prosecutors’ offices. The application will, for example, automatically name incoming documents and extract information to be recorded, such as data concerning the parties.


Bavarian courts also use ALeKS (see below).

Hesse

The application JANO has been developed to support the anonymisation of judgments in 2025, as required under German law for data protection. The tool automatically identifies personal data and suggests them for anonymisation, though the suggestions still need to be reviewed and approved by court clerks. As at June 2026, the tool is deployed at the Regional Court of Darmstadt.


Codefy/ASTRA is an AI tool that functions as a ‘digital clerk’, capable of reading thousands of pages of court files, categorising documents, hyperlinking evidence, and visualising relationships between different actors in a case. As at June 2026, the tool has been officially piloted at the Regional Court of Frankfurt.

Lowe Saxony

The tool ALeKS, developed and deployed in Lower Saxony and Bavaria, performs anonymisation of decisions and replaces personal data with synonyms, with a reported 97% accuracy. The tool automatically generates legal summaries for quicker review. As at June 2026, state-wide implementation is being prepared.

In 2023, the German Federal Ministry of Justice and Consumer Protection introduced a legislative initiative to allow AI-supported recording and transcription of main hearings in criminal proceedings. The draft bill passed the German Federal Parliament (Bundestag) but was referred to the Mediation Committee (Vermittlungsausschuss) at the request of the Federal Council (Bundesrat) and ultimately terminated by expiry of the electoral term in 2024. The envisaged technology was a LLM tool that could translate speech from several speakers, even with strong accents, and without errors. As at June 2026, it is unclear whether this initiative will be taken up again by the current government.

Legal research, analysis and drafting support

The StruKI tool used for case management in Baden-Wuertemberg (discussed above) can also be used for drafting support.

Decision-making support

FRIDA is an in-house development by the Frankfurt District Court, aiming to support judges in traffic administrative offence proceedings by assisting in the drafting of written court documents from text modules and automatically extracting procedural details from relevant electronic files, using fixed search criteria. As at June 2026, the Ministry of Justice of Hess reports positive operational experience among judges.

The University of Cologne and the Fraunhofer Institute for Intelligent Analysis and Information Systems are collaborating on a research project to develop an AI application to support criminal judges with sentencing. The aim is to develop an algorithmic analysis tool for criminal judgments, which will categorise judicial considerations and reasons for sentencing to identify and process existing differences in judicial sentencing practices. The tool will allow judges to ascertain how other courts in comparable situations have assessed penalties, to compare with their own findings. As at June 2026, this system has not yet been tested in practice.

Defence

Though reports of AI adoption by German defence counsel remains limited, AI tools developed for general legal practice are increasingly available and address challenges that regularly arise in criminal proceedings.

Legal research, analysis and drafting support

Beck-Noxtua is a legal AI workspace that combines legal content with an AI system trained specifically for legal applications. This enables a secure and effective handling of legal research, document analysis, and drafting of legal texts.

Evidence review and analysis

Relativity aIR, a widely available AI review tool, supports tasks such as document review, privilege review, and case strategy. The tool provides AI-assisted fact extraction, generation of chronologies, and the classification of factual elements to support the development of a case strategy. The tool uses generative AI to help legal teams identify relevant documents and conduct a multi-step reasoning as to why certain documents matter, according to defined review criteria.

Futuristic Data Display

Victims

Under German criminal procedural rules, victims of criminal offences are (under certain circumstances) entitled to actively participate in criminal proceedings in various ways (Sections 373b to 406l of the German Code of Criminal Procedure). These include private prosecution ('Privatklage') (Sections 374 to 394 of the German Code of Criminal Procedure), accessory prosecution ('Nebenklage') (Sections 395 to 402 of the German Code of Criminal Procedure), adhesion proceedings ('Adhäsionsverfahren'), in which civil claims may be pursued within the criminal proceedings (Sections 403 to 406c of the German Code of Criminal Procedure), as well as various other victims’ rights, including rights to information, access to files, and legal assistance (Sections 406d to 406l of the German Code of Criminal Procedure).

As at June 2026, there are no reported cases of victims using AI in criminal proceedings in Germany.

TRAINING

As at June 2026, there are no uniform or mandatory training programmes for law enforcement, judges, or legal professionals participating in criminal proceedings on the responsible use of AI.

In April 2025, the German E-Justice Council (the forum of the heads of the justice ministries of the federal government and states) adopted a nationwide AI Strategy for the judiciary, aiming to coordinate the development and use of AI systems across the justice system. This strategy explicitly recognises the need for skills and competence development regarding AI, and the design of training concepts to build AI competencies among judicial actors. The implementation of these measures, including the development and rollout of corresponding training concepts, is envisaged for 2026.

In the context of police education and training, the Conference of Police Colleges and Departments emphasised that AI will become an increasingly relevant component of police work, and has called for the inclusion of AI competencies in technical, legal, and ethical respects, with the aim of enabling future police officers to critically assess AI systems, understand their limitations, and use them responsibly.

Ad hoc training is offered by established legal training institutions in Germany. The German Judicial Academy, for example, has offered a three-day conference for judges and prosecutors focused on AI. According to the academy’s description, the course covered how different AI models function and how they can be used in the judicial system, with particular attention to the detection of AI-generated content, such as texts, images, and videos.

REGULATION

The EU AI Act is at the heart of AI regulation in Germany. As an EU regulation, it is applicable without an implementing act within all 27 EU member states. The AI Act mirrors and specifies constitutional principles both under European and German law. Further rules and guidelines in particular at the European level supplement the AI Act, albeit its provisions and their future interpretation by the CJEU are ultimately binding. Besides the AI Act, data protection and cybersecurity regulations are of particular relevance with regard to AI in Germany and its use in the area of criminal justice.

AI Regulations

EU AI Act (Regulation (EU) 2024/1689)

The EU AI Act is a key part of the legal framework regulating the use of AI across the EU. It entered into force on 1 August 2024, and sets out a comprehensive legal framework aiming to ‘guarantee safety, fundamental rights and human-centric AI’. The EU AI Act is being phased between 2025 and 2030. Germany is obliged to implement and comply with the provisions of the Act, which set out a harmonised legal framework for ‘the development, the placing on the market, the putting into service, and the use’ of AI systems across the EU.

The EU AI Act introduces a risk-based approach, categorising AI systems into four levels of risk, banning ‘unacceptable-risk’ systems, and imposing strict obligations on high-risk systems. The rules on prohibited uses have applied since 2 February 2025, the rules on general-purpose AI models and the designation of competent national authorities have applied since 2 August 2025 while obligations related to the use of high-risk AI systems, are being introduced later.

The EU AI Act includes explicit references to AI systems related to the administration of justice, and to criminal proceedings. These are mainly classified as high-risk given ‘their potentially significant impact on . . . the rule of law, individual freedoms . . . the right to an effective remedy and to a fair trial’ as well as the right to defence and the presumption of innocence, particularly if ‘such AI systems are not sufficiently transparent, explainable [or] documented’. The Act highlights the potential ‘difficulty in obtaining meaningful information on the functioning of those systems and the resulting difficulty in challenging their results in court, in particular by natural persons under investigation’.

EU AI Act’s risk-based approach

Unacceptable risk (prohibited)

AI systems posing ‘a clear threat to safety, livelihood and rights of people’ are prohibited. This includes uses in law enforcement and criminal justice such as (1) assessing or predicting an individual’s criminal offence risk ‘based solely on the profiling of a natural person or on assessing their personality traits and characteristics’; (2) undertaking ‘untargeted scraping of the internet or CCTV footage’ to build or expand facial recognition databases; and (3) deploying ‘real-time remote biometric identification systems in public spaces or biometric categorisation to infer race, religion or other protected characteristics’ although narrow exceptions exist.

High-risk (subject to strict obligations)

AI systems that ‘can pose serious risks to health, safety or fundamental rights’ are deemed ‘high-risk’ under article 6. This includes the use of AI (1) to assess the risks of persons ‘becoming the victim of criminal offences’, (2) to assess the risk of persons ‘offending or re-offending’ in certain circumstances and to profile persons during investigations or prosecutions, (3) to evaluate the reliability of evidence ‘in the course of investigations or prosecution of criminal offences’, (4) for remote biometric identification, biometric categorisation in certain circumstances, and emotion recognition, and (5) ‘to assist judicial authorities in researching and interpreting facts and law’ and ‘applying the law to the facts’ (emphasis added). AI systems used for purely ancillary administrative activities that do not affect the actual administration of justice in individual cases are not considered high-risk.


High-risk AI systems are subject to strict obligations for developers, providers and users, including risk assessment; human oversight, the use of high-quality training data and ensuring explainability, accuracy, robustness and cybersecurity. When AI systems assist judicial decision-making, the persons concerned must be informed about the use of AI systems, and be provided with explanations about the role of AI in the decision-making process.

Limited risk (subject to transparency obligations)

This category refers to the risk associated with a need for transparency around the use of AI such as chatbots. Specific disclosure obligations apply for this category.

Minimal risk (no requirements)

Minimal risk or no risk AI systems are not subjected to any requirements.

Articles 51-56 of the EU AI Act establish a specific regime for ‘general-purpose AI models’, defined in article 3(63) as models trained on large datasets capable of performing a wide range of tasks. They typically include large language models (LLMs) that can be integrated into legal research platforms, drafting tools or judicial support systems. Providers of such models must:

  • maintain technical documentation;
  • provide information to downstream integrators;
  • comply with EU copyright law; and
  • publish a summary of training data.

Under articles 55-56, additional obligations apply to general-purpose AI models presenting systemic risk, including risk assessment, mitigation measures and incident reporting. The framework is particularly relevant to the judicial sector given that courts and prosecutors may rely on external LLM-based tools rather than developing their own systems.

In terms of governance and enforcement of the EU AI Act, the Act adopts a two-pronged approach. At the EU-level, according to Articles 64-69 of the AI Act, the AI Office of the European Commission and an AI Board (Article 65) are the main actors. The AI Office enjoys enforcement powers with respect to obligations of general-purpose AI models (Article 88 et seqq.). The AI Board assists the European Commission and the member States in facilitating coherent applications of the AI Act, and therefore contributes to the coordination among national authorities (Article 66(a)).

With respect to domestic enforcement, in Germany a current draft law to supplement the EU AI Act designates the Federal Network Agency (Bundesnetzagentur – BNetzA) as the market surveillance and notifying authority. The Federal Network Agency is already the competent authority under the Digital Services Act (Regulation (EU) 2022/2065) and the supporting German Digital Services Act (Digitale-Dienste-Gesetz – DDG).

Several non-binding guidelines have already been published by the European Commission to provide further directions when implementing the AI Act:

  • Guidelines on prohibited artificial intelligence (AI) practices (published on 04 February 2025) provide legal explanations and practical examples of AI practices that are deemed unacceptable and hence prohibited by Article 5 of the AI Act, due to their potential risks to European values and fundamental rights. The guidelines specifically address practices such as harmful manipulation, social scoring, and real-time remote biometric identification, among others.
  • Guidelines on AI system definition (published on 06 February 2025) explain the practical application of the legal concept of AI to assist providers and other relevant persons in determining whether a software system constitutes an AI system. The guidelines elaborate on each of the seven elements of the definition of an AI system provided by Article 3(1) AI Act : (1) machine-based system, (2) autonomy, (3) adaptiveness, (4) AI system objectives, (5) inferencing how to generate outputs using AI techniques, (6) outputs that can influence physical or virtual environments, (7) interaction with the environment.
  • Other guidelines are currently being developed by the European Commission. For instance, the Commission has issued Draft guidelines on the classification of high-risk AI systems, setting out the Commission’s interpretation of certain concepts that are relevant for classification purposes, and contain practical examples of AI systems that should or should not be classified as high-risk. High-risk uses of AI systems may include, for example, tools for the assessment of an individual’s risk of offending or reoffending, generating risk scores, profiling identified persons, or otherwise supporting operational law-enforcement decision-making. The Guidelines emphasise that classification depends on the system’s intended purpose and practical use, rather than solely on how it is labelled by the provider.

Other European Regulations and Guidelines

At the European level, the AI Act coexists with additional regulations and guidelines:

Ethics Guidelines for Trustworthy Artificial Intelligence (2019)

Prior to the adoption of the AI Act, the High-Level Expert Group on AI set up by the European Commission presented the non-binding Ethics Guidelines for Trustworthy Artificial Intelligence on 8 April 2019. These guidelines provide a framework to achieve trustworthy AI based on fundamental rights as enshrined in the Charter of Fundamental Rights of the European Union (EU Charter).

The Guidelines put forward a set of seven key requirements that AI systems should meet in order to be deemed trustworthy:

  1. Human agency and oversight
  2. Technical robustness and safety
  3. Privacy and data governance
  4. Transparency
  5. Diversity, non-discrimination and fairness
  6. Societal and environmental well-being
  7. Accountability

European Declaration on Digital Rights and Principles for the Digital Decade

The European Commission adopted on 26 January 2022 the European Declaration on Digital Rights and Principles for the Digital Decade. This Declaration is non-binding, but affirms the commitment of European institutions to ‘ensuring transparency’ in AI, guaranteeing the quality of data, preventing these tools from being used to predetermine individuals' choices, and providing safeguards to protect individuals' fundamental rights. Chapter III specifically declares that everyone shall be able to make ‘free and informed choices in the digital environment, while being protected from risks and harm to their health, safety, and fundamental rights’.

Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law

The Council of Europe adopted in May 2024 the Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, which is the ‘first-ever international legally binding treaty’ regulating AI. The Convention establishes rules relating to respect for fundamental rights at all stages of the AI systems lifecycle, which must be transposed into the domestic law of the signatory states.

The Convention establishes seven fundamental principles for AI systems development: human dignity and individual autonomy (art. 7), transparency and oversight (art. 8), accountability and responsibility (art. 9), equality and non-discrimination (art. 10), privacy and personal data protection (art. 11), reliability (art. 12) and safe innovation (art. 13).

The Convention applies across all public and private uses of AI where human rights may be affected, including within law enforcement, prosecution and judicial activities. It mandates risk and impact assessments to mitigate potential harms and provides safeguards such as the right to challenge AI-driven decisions.

As at June 2026, Germany has not yet ratified the Convention and the Convention is not yet binding on Germany.

European Ethical Charter on the use of AI in the judicial systems and their environment

Similarly, the European Ethical Charter on the use of AI in the judicial systems and their environment has been adopted by the Council of Europe’s European Commission for the Efficiency of Justice (CEPEJ) in December 2018. It lays out five non-binding basic principles relating to the use of AI in judicial systems:

  1. Respect of fundamental rights (‘ensure that the design and implementation of AI tools and services are compatible with fundamental rights’),
  2. Non-discrimination (‘specifically prevent the development or intensification of any discrimination between individuals or groups of individuals’),
  3. Quality and security (‘with regard to the processing of judicial decisions and data, use certified sources and intangible data with models conceived in a multi-disciplinary manner, in a secure technological environment’),
  4. Transparency, impartiality and fairness (‘make data processing methods accessible and understandable, authorise external audit’),
  5. 'Under user control' (‘preclude a prescriptive approach and ensure that users are informed actors and in control of their choices’).

Guidelines for practitioners

Across the criminal justice system, a growing number of guidelines, strategies and policy papers have been released for various actors involved in criminal proceedings, at both the federal and state level. Whilst these documents differ in scope, they share a set of common core principles, including the principle of human responsibility and control.

As at June 2026, there are no guidelines on the use of AI specifically for law enforcement members, but a number of general guidelines for employees of the German public administration have been adopted which also apply to personnel of police authorities.

As at June 2026, there is also no publicly available evidence to suggest Germany has formally adopted the UNESCO Guidelines for the Use of AI Systems in Courts and Tribunals (2025). However, Germany has demonstrated a broader commitment to UNESCO's work on AI governance. Germany supported the UNESCO Recommendation on the Ethics of Artificial Intelligence (2021) and submitted its first national implementation report in 2025, documenting domestic measures to implement the Recommendation. Moreover, several principles reflected in the UNESCO Guidelines, in particular human oversight and the protection of fundamental rights, are also found in Germany's own policy framework, such as the E-Justice Council's Strategy for the Use of AI in the Justice System and the Joint Declaration on the Use of AI in the Judiciary adopted by the federal and state justice ministers in June 2025.

Federal and State Ministers of Justice, ‘Joint Declaration on the Use of Artificial Intelligence in the Justice System’ (2025)

In June 2025, the Federal and State Ministers of Justice (Justizministerinnen und Justizminister des Bundes und der Länder) issued a Joint Declaration on the Use of Artificial Intelligence in the Justice System’. The Declaration does not necessarily constitute a guideline for practitioners, but emphasises that final decision-making in the judiciary must be performed by a human. The declaration stresses that this requirement does not only apply to judges, but that the decision-making competences of prosecutors must likewise be preserved.

German Federal Bar, ‘Information on the Use of Artificial Intelligence (AI)’ (2024)

In December 2024, the German Federal Bar (Bundesrechtsanwaltskammer), the umbrella organisation representing the 28 regional bar associations in which every lawyer in Germany is required to be a member, issued guidelines entitled ‘Information on the Use of Artificial Intelligence (AI)’. The guidelines are conceived as a non-binding orientation aid for legal practitioners on the compliant use of AI applications in law firms.

The guidelines state at the outset that AI tools can offer significant efficiency gains for law firms, for example in document analysis and management, research assistance, and translation. At the same time, it stresses that AI systems do not ‘understand’ legal content in a human sense and remain prone to hallucinations and biases, which may result in outputs that appear plausible but are factually incorrect or misleading.

Against this background, the guidance emphasises that:

  1. AI may only be used as a supporting tool and must never replace the lawyer’s independent legal judgment. Lawyers remain fully and personally responsible for all work products generated with the assistance of AI. Accordingly, they are required to carry out a careful review and control of any AI-generated output, in line with the duty of conscientious professional practice under Section 43 Federal Code for Lawyers (Bundesrechtsanwaltsordnung) (‘BRAO’).
  2. The level of care required increases with both the degree of automation and the proximity to the client relationship. While the use of AI for purely internal purposes may raise fewer concerns, heightened caution is required where AI tools are used in client-facing contexts, such as automated communications or chatbots for client intake.
  3. There is no general obligation to use AI in legal practice, even if its use may – in some cases – lead to faster or more efficient outcomes. However, the guidance notes that, pursuant to Section 5 Rules of Professional Practice (Berufsordnung für Rechtsanwälte), which requires lawyers to maintain the material, personnel, and organisational prerequisites for a professional practice, there may be case-specific obligations to use legal tech or AI tools, for example in the handling of mass proceedings.
  4. A central pillar of the German Federal Bar guidance is the strict protection of confidentiality. The duty of confidentiality under Section 43a (2) BRAO applies without limitation to the use of AI systems and is reinforced by criminal liability under Section 203 (1) No. 3 German Criminal Code (Strafgesetzbuch). Where possible, lawyers should work with abstract or fully anonymised prompts that do not allow any inference to be drawn about a specific case. If the use of external AI providers involves access to confidential information, this is only permissible under the narrow conditions of Section 43e BRAO on IT outsourcing, including careful selection of the provider, contractual confidentiality obligations, purpose limitation, and strict compliance with the ‘need-to-know’ principle (i.e. limiting access to confidential information to the minimum necessary for the performance of the outsourced service). The guidance expressly notes that, given the current state of technology, the transmission of client secrets to public AI systems such as ChatGPT is neither necessary nor acceptable.
  5. Data protection considerations are closely linked to confidentiality. The Federal Bar stresses that the use of AI tools must comply with the GDPR and related German data protection rules (see below). Particular risks arise where AI providers are located outside the EU or where data may be transferred to third countries. In such cases, additional safeguards are required and, where possible, providers with servers located in Germany or the EU should be preferred.
  6. Under current professional rules, lawyers are generally not obliged to inform clients that AI tools are being used in the handling of their matters. However, transparency obligations may arise from other areas of law, such as contract law or unfair competition law, and the guidance therefore recommends a transparent approach to the use of AI in client relationships, including contractual clarification where appropriate.

The guidance also situates the use of AI in German legal practice within the broader European regulatory framework, in particular the EU AI Act (see above). It highlights that lawyers typically qualify as ‘deployers’ of AI systems and will be required, from February 2025 onwards, to ensure an adequate level of AI literacy and competence within their organisations. While most AI tools used in law firms are unlikely to qualify as high-risk systems, compliance with the EU AI Act does not automatically guarantee compliance with German professional conduct rules, and vice versa. Lawyers must therefore navigate both regimes in parallel, ensuring adherence to both regulatory and professional standards.

Presidents of Higher Regional Courts and the Federal Court of Justice, Paper on ‘Use of AI and Algorithmic Systems in the Justice System’ (2022 and 2026)

In May 2022, a paper on ‘Use of AI and Algorithmic Systems in the Justice System’ was prepared for the Conference of the Presidents of the Higher Regional Courts and the Federal Court of Justice (Präsidentinnen und Präsidenten der Oberlandesgerichte, des Kammergerichts, des Bayerischen Obersten Landesgerichts und des Bundesgerichtshofs). The paper sets out guidelines based on the constitutional and ethical boundaries for the use of AI in the judiciary.

Most notably, the Paper sets out the principle that the exercise of judicial power must remain human-centred, in accordance with Article 92 of the German Constitution, which provides that judicial authority is vested exclusively in natural persons acting as judges. Consequently, the use of AI systems for decision-making or drafting judgments is constitutionally impermissible. The Paper therefore distinguishes between permissible assistive functions and impermissible systems influencing the legal evaluation, the weighing of evidence, subsumption, or the exercise of discretion, all of which belong to the constitutionally protected core of judicial decision making.

A central concern identified in the Paper is the risk posed by non-transparent self-learning systems, particularly where their internal decision logic cannot be reconstructed (also known as ‘black box’ systems). Where the decision-making process of an AI system is not transparent, meaningful human responsibility and accountability are undermined. The paper therefore treats explainability and transparency as preconditions for any lawful use of AI in the justice system.

The Paper also suggests that any form of factual or institutional pressure to follow algorithmic recommendations, including indirect pressure through efficiency targets, workload expectations, or personnel planning, would threaten judicial independence and is therefore incompatible with constitutional guarantees.

The Paper further emphasises that the constitutional guarantees of the right to be heard, to a fair trial, effective legal protection, equality, and human dignity impose strict limits on AI deployment. Building on these constitutional guarantees, and in conjunction with ethical requirements, the paper identifies a set of further requirements that apply to judges when using AI-based tools. These include, in particular: technical robustness and security, protection of privacy and data quality management, transparency, diversity, non-discrimination, fairness, social and environmental well-being and accountability.

In April 2026, the Paper was updated to reflect recent technological and regulatory developments, in particular the rapid emergence of large language models and generative AI, as well as the entry into force of the EU AI Act. While the revised version does not alter the constitutional and ethical core principles established in the 2022 Paper, it expands the analysis. In particular, it provides more detailed guidance on the opportunities and risks associated with generative AI, including automation bias, hallucinations and the lack of explainability of AI-generated outputs. It further develops the governance framework for the use of AI in the judiciary by addressing issues such as risk management, data governance, testing and evaluation of AI systems, human oversight, AI literacy and organisational responsibilities. The updated Paper also incorporates the regulatory framework established by the EU AI Act.

E-Justice Council, ‘Strategy for the Use of AI in the Justice System’ (2025)

In E-Justice Council’s (E-Justice-Rat) ‘Strategy for the Use of AI in the Justice System’, the federal government and states jointly commit to a trustworthy and human-centred use of AI in the justice system. The E-Justice Council is a central strategic committee for the digital transformation of the justice system which consists of the heads of the Federal Ministry of Justice and the justice ministries of the 16 German states. Beyond constitutional requirements and statutory law, the strategy addresses additional factors relevant to the development of trustworthy AI, in particular ethical considerations. These include, inter alia, transparency and explainability, traceability of AI-assisted outcomes, fairness, and the avoidance of bias in machine-learning systems.

Federal Ministry of the Interior, ‘Guidelines for the Use of AI in the Federal Administration’ (2025)

The Federal Ministry of the Interior (Bundesministerium des Innern und für Heimat), the supervising authority of the Federal Police, sets out five guiding principles for the responsible use of AI within the German federal administration in its ‘Guidelines for the Use of AI in the Federal Administration’. These guiding principles consist of:

Responsible and ethical use of AI

The guidelines require a responsible and ethical use of AI, ensuring that AI systems are employed strictly in accordance with their intended purpose and within the applicable constitutional, legal, and ethical framework. Discriminatory, misleading, or otherwise inappropriate inputs and outputs must be avoided. The guidelines explicitly stress that unethical prompts or the circulation of harmful or unlawful AI-generated content are impermissible.

Minimal disclosure of data

Users are instructed to minimise the disclosure of data, particularly when using externally hosted or third-party AI systems. Users are encouraged to apply privacy-preserving account settings and to object, where possible, to the reuse of entered data for training purposes.

Assess which types of data are permitted for the system and use case

Before entering or uploading data into an AI system, users must assess which types of data are permitted for the specific system and use case. Authorities are required to make this information easily accessible, but the responsibility for compliance lies with the user. Particular caution is required with regard to personal data or sensitive material.

AI shall serve solely as a support tool

The guideline stresses that AI systems shall serve solely as support tools, and therefore imposes an obligation to critically and professionally review AI-generated output. Users must be particularly cautious regarding hallucinations.

Transparency

The guideline requires a transparent use of AI, including appropriate internal or external disclosure where AI-generated content is used, especially if such content has not been fully reviewed. Where AI outputs have been thoroughly checked and substantially revised, explicit labelling may not be required.

Guidelines for public administration at the state level

Only a limited number of States have so far adopted AI-specific guidelines for employees of the State administration, including law enforcement agencies. As at June 2026, only Bavaria, Berlin and Hamburg have issued such guidelines:

State

Guidelines

Contents

Bavaria

Bavarian State Government (Bayrische Staatsregierung), ‘AI Guidelines for Employees’ (updated April 2025)





The Bavarian State Government’s Guidelines set out core requirements governing the use of AI systems by employees of the public administration in Bavaria.

A central rule is that only AI systems that have been reviewed and expressly approved by the competent authority may be used in an official capacity. Whether the use of freely accessible AI systems requires an explicit approval is not regulated uniformly but depends on the internal regulations of the respective department or authority.

AI systems are explicitly characterised as support tools. All AI-generated outputs must be critically reviewed and professionally assessed prior to use. The guidelines explicitly warn against the risk of hallucinated or misleading content and prohibit the unverified adoption of AI-generated results.

The guidelines emphasise strict data protection and information security obligations. In particular, the input of personal data, confidential information, or internal administrative content is either prohibited or permitted only under narrowly defined conditions, with heightened restrictions applying to freely accessible, externally hosted AI systems.

Transparency obligations apply where AI-generated content is reused without a substantive review. Especially AI-generated images or videos must generally be labelled as such to prevent deception.

Berlin

Governing Mayor of Berlin, Senate Chancellery (Der Regierende Bürgermeister von Berlin – Senatskanzlei), ‘Guidance on Dealing with LLM-based Chatbots in the State of Berlin’ (September 2024)



In September 2024, the Berlin Senate Chancellery issued an orientation paper on the use of LLM-based chatbots by employees of the Berlin administration. The document provides practical guidance for a self-accountable use of freely accessible AI systems. The Guidance reflects the core principles of lawful, human-centred, and responsible AI use in public administration.

In particular, it emphasises human responsibility and control, strict data protection and information security requirements, the prohibition of entering personal or sensitive data into publicly accessible AI systems, and the obligation to critically review all AI-generated outputs. The Guidance also stresses transparency in the use of AI, the avoidance of automated final decisions, and the need to remain aware of risks such as hallucinations, bias, and discrimination.

Hamburg

Hamburg Commissioner for Data Protection and Freedom of Information (Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit), ‘Checklist for Using LLM-Based Chatbots’ (November 2023)



The Checklist reflects largely the same core principles, including human responsibility, data protection and transparency. However, unlike the guidelines addressed directly to individual employees, the Hamburg checklist is primarily directed at the authorities themselves. It calls on authorities to establish clear internal rules governing the use of LLM-based chatbots, to involve data protection officers, to provide appropriate technical and organisational measures (such as functional accounts and secure authentication) and to ensure that staff are adequately sensitised and trained.

Regional guidelines on judiciary’s use of AI

Moreover, there are several European-level guidelines that address the judiciary’s use of AI, most notably the European Ethical Charter on the use of AI in judicial systems and their environment adopted by the European Commission for the Efficiency of Justice (CEPEJ) of the Council of Europe (discussed above).

Other non-binding initiatives have given rise to guidelines for justice system professionals and for lawyers, or may serve as useful benchmarks and standards to be upheld in professional practice:

Sector

Title

Contents

Council of Bars and Law Societies of Europe

Considerations on the Legal Aspects of Artificial Intelligence (2020)

According to the Council of Bars and Law Societies of Europe, for the sake of transparency and in order to enable individuals to defend their rights, it seems appropriate that the persons impacted by the use of an AI system should be duly informed that AI is being used and that data concerning the individual may be considered by an automated system.

Council of Bars and Law Societies of Europe

Guide on the Use of Artificial Intelligence-Based Tools by Lawyers and Law Firms in the EU (2022)

The Guide emphasises that lawyers should have at least a general understanding of how AI tools function. Where such understanding is lacking, this should be clearly communicated to clients and taken into account in the provision of legal services. Ultimately, under existing professional rules, lawyers remain fully responsible for the quality of their services and the outcomes for their clients, even where AI tools are used.

Court of Justice of the EU

Artificial Intelligence Strategy (2023)

While the AI Strategy does not address the disclosure of AI use, it emphasises that once AI solutions, procedures, methods and governance are put in place, staff awareness and knowledge level should ensure that the reasoning behind AI algorithms should be clear and understandable, both for those created in-house and those acquired.

European Bars Federation

Guidelines 2.0 on How Lawyers Should Take Advantage of the Opportunities Offered by Large Language Models and Generative AI (2024)

The Guidelines explain that lawyers should maintain transparent communication with their clients regarding the use of generative AI in their legal practice. Lawyers should clearly explain the fact that they use it, as well as the purpose of such use, benefits, limitations, and guarantees, ensuring that clients understand the role of this technology in legal matters.


The European-level guidelines apply to the German regional bar associations that are members of the European Bars Federation (12 of 28 as at June 2026).

Council of Europe

Use of Generative AI by Judicial Professionals in a Work-Related Context (2024)

The aim of this note is to give some preliminary thought to what judges and other public sector justice professionals can expect from the use of generative AI tools in a judicial context. The Council reiterated that it is essential, in particular in the case of justice, to be transparent about the use of generative AI as the relationship with the litigant is based on trust.

 

Contemplative Gaze with Futuristic Colors

Criminal procedure rules

As at June 2025, the German Code of Criminal Procedure contains no explicit provisions governing the use of AI.

In 2024, a legislative initiative to introduce AI-enhanced digital documentation of first-instance proceedings before the district courts and higher regional courts, by way of an amendment to Sections 271–274 the German Code of Criminal Procedure, failed due to the premature end of the previous legislative term.

With respect to law enforcement, a Draft Bill that would have permitted the use of AI to retrospectively compare biometric data with publicly available online data by introducing Section 98d of the German Code of Criminal Procedure ultimately failed due to the Federal Council’s (Bundesrat) refusal to grant its consent. However, in its coalition agreement, the government has stipulated that, under certain narrowly defined conditions in cases of serious crime, law enforcement agencies should be allowed to use retrograde remote biometric identification to identify perpetrators (p. 89). As at June 2026, no corresponding draft legislation has been published.

As part of its assessment of the evidence (Section 261 of the German Code of Criminal Procedure), the court is under a duty to establish the relevant facts of the case ex officio (Section 244(2) of the German Code of Criminal Procedure). Accordingly, where there are indications that a piece of evidence may be a deepfake, the Court must investigate those indications and verify the authenticity of the evidence.

Data protection legislation

In addition to the EU AI Act, EU data protection regulations must be observed with regard to the use of AI in criminal proceedings. The EU AI Act does not seek to affect existing Union law governing the processing of personal data (according to Article 2 No. 7 AI Act and Recital 10). Data protection law governing the use of personal data may be relevant with regard to various stages of the AI lifecycle. Personal data can be relevant during AI development (e.g., collection and use of data for training) and AI use (e.g., personal data as input data).

On 25 January 2012, the European Commission presented the Data Protection Reform package, proposing a directive (LED) and a regulation (GDPR). On 27 April 2016, the European Parliament and the Council adopted:

  • The Law Enforcement Directive (Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data) (‘LED’)
  • The General Data Protection Regulation (Regulation (EU) 2016/679 of the European Parliament and of the European Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (‘GDPR’).

The GDPR remains the primary regulation for ‘general’ processing of data, but the LED is the lex specialis for criminal matters, since it governs processing ‘for the purposes of the prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties’. These regulations have distinct scopes of application that are intended to be complementary.

In both regulations, ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 3 (1) LED and Article 4 (1) GDPR). As at June 2026, this term also includes pseudonymised data as indicated by Article 4 (5) GDPR. Recital 26 sentence 2 GDPR points out that identifiability should (still) be recognised in view of pseudonymised personal data that could be assigned to a natural person based on additional information.

EU Directive 2016/680, Law Enforcement Directive (LED) (2016)

The directive governs the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection, and prosecution of criminal offences or the execution of criminal penalties.

The rights of data subjects are recognised but may be limited in order to ensure the proper conduct of investigations, prevention, and the prosecution of offenses. These rights include the right to information, the right of access (often exercised indirectly through the supervisory authority), and the right to rectification or erasure. As such, the directive imposes obligations on data controllers that are comparable to those of the GDPR, but creates additional obligations that are specific to the criminal context:

  1. There must be a clear distinction among categories of data subjects: those suspected of committing or planning a criminal offense, those who have been convicted, victims of crimes, and individuals who may be at risk of becoming victims. It also includes third parties connected to a crime, such as potential witnesses, people who can provide information, and contacts or associates of the individuals mentioned above, as set out in Article 6.
  2. The processing of special categories of personal data is strictly regulated under Article 9(2) of the GDPR and requires the data subject's consent, which shall be freely given and well-informed, or for a legitimate purpose. But the LED establishes a specific exception for criminal matters: Article 10 permits the processing of sensitive data without consent when it is strictly necessary, provided that appropriate safeguards are implemented. For example, the German legislator has specified 'appropriate safeguards' as measures such as specific requirements for data security, special time limits, restrictions of access, pseudonymisation or encryption (Section 48 (2) Federal Data Protection Act (Bundesdatenschutzgesetz).
  3. The LED also addresses automated individual decision-making. A decision ‘based solely on automated processing, including profiling, which produces an adverse legal effect concerning the data subject or significantly affects him or her’, is prohibited unless authorised by Union or Member State law to which the controller is subject and which provides appropriate safeguards for the data subject´s rights and freedoms of, at least the right to obtain human intervention on the part of the controller (Article 11 (1)). The EU legislator specifies that this right to intervention comprises the right to express his or her point of view, to obtain an explanation of the decision reached after such assessment or to challenge the decision (Recital 38). Furthermore, such decisions shall not be based on special category data, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union memberships, as well as genetic data, biometric data, data concerning health or a natural person’s sex life or sexual orientation, unless suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place (Article 11 (2)). German Federal Law provides that, in respect of automated processing, controllers or processors must implement special security measures such as storage control, data access control, input control, integrity, and processing control (Article 29 (2) and Section 64 (3) of the German Federal Data Protection Act). The LED further prohibits profiling resulting in discrimination against natural persons on the basis of special category data (Article 11 (3)).
  4. In order to protect individuals’ rights during criminal investigations, Articles 13 and 14 provide for information and access rights, while allowing limitations where their exercise could undermine ongoing investigations or prosecutions.
  5. Article 16 complements these safeguards by providing the right to request the rectification of inaccurate data and the erasure of data, and in the event of refusal, the possibility of lodging a complaint with a supervisory authority or seeking judicial remedy.
  6. Finally, Articles 27 and 29 impose obligations relating to risk assessment and data security, requiring competent authorities to assess the impact of high-risk processing operations and to implement appropriate technical and organisational measures throughout the criminal procedure.

Regulation (EU) 2016/679, General Data Protection Regulation (GDPR)

The GDPR protects fundamental rights in the digital landscape by imposing obligations on data controllers and processors upon all processing of personal data. Hence, in the area of criminal justice, the GDPR is relevant for: (i) the processing of personal data collected by competent authorities for the purposes set out above but intended to be further processed for other purposes, (ii) processing by public bodies for other purposes from the outset (this includes, e.g., archiving conducted by criminal justice authorities), and (iii) any processing by natural persons or private entities (Article 9 (1) and (2) LED, Article 2 (1) GDPR, Recital 19 to GDPR).

Obligations placed on data controllers include: lawful, fair and transparent processing; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability; transparency and information duties; security obligations; data protection impact assessments. The GDPR also grants basic rights to data subjects such as access, rectification and erasure of personal data.

Compared to the LED, the GDPR establishes a higher level of protection regarding the lawfulness of processing. Several aspects of criminal proceedings are subject to the following provisions of the GDPR:

  1. Article 10 requires the processing of personal data relating to criminal convictions and offences to be carried out ‘only under the control of official authority’, and to provide for ‘appropriate safeguards for the rights and freedoms of data subjects.
  2. Paragraph 1 of Article 22 prohibits any decision that produces legal or similar effects based exclusively on automated data processing. This serves as a key safeguard against ‘algorithmic judges’ or fully automated sanctions.
  3. Paragraph 1 of Article 35 provides that the controller must carry out a data protection impact assessment prior to any processing likely to pose a high risk to the rights and freedoms of individuals, particularly when new technologies are involved. A single assessment may cover multiple similar processing operations presenting comparable risks.

On 6 and 25 May 2018 respectively, the GDPR and the LED were implemented across all EU Member States. In Germany, the GDPR is directly applicable. Where the GDPR leaves room for legislative discretion, the Federal Data Protection Act ('Bundesdatenschutzgesetz') lays down additional rules. The LED was also implemented in Germany through a variety of amendments to existing legislation, in particular to the German Code of Criminal Procedure.

EU AI Act (Regulation (EU) 2024/1689)

Acknowledging both existing data privacy regulations and the relevance of personal data in the AI context, the EU AI Act contains several provisions addressing the use of such data in the course of complying with broader obligations under the AI Act:

  1. The EU AI Act provides a (narrow) legal basis for the processing of special category personal data in the context of training or testing a high-risk AI system. Where such processing is strictly necessary for the purpose of ensuring bias detection and correction in relation to a high-risk system, the providers of such systems may exceptionally process special category data, subject to appropriate safeguards for the fundamental rights and freedoms of natural persons. Exceptional circumstances exist where (in addition to the requirements for such processing set out in the LED or the GDPR) certain cumulative conditions are met, including where there are technical limitations and state-of-the-art security measures, including pseudonymisation, as well as strict security safeguards (cf. Article 10 No. 5 sentence 2 AI Act, (6)).
  2. The data sets for training, validation, and testing of AI systems shall be subject to appropriate data governance and management practices that, in the case of personal data, shall also concern the original purpose of the data collection (Article 10 No. 2 (b) AI Act).
  3. Where applicable, deployers of high-risk AI systems shall use the information provided for such systems under their transparency obligation (cf. Article 13 AI Act) for conducting a data protection impact assessment under the LED or the GDPR (Article 26 No. 9 AI Act).

Cybersecurity Laws

EU AI Act (Regulation (EU) 2024/1689)

For high-risk AI systems, the EU AI Act requires resilience against attempts by unauthorised third parties to alter their use, outputs, or performance by exploiting system vulnerabilities (Article 15 (5)), which is confirmed by the underlying Recital 76, emphasising the crucial role of cybersecurity.

EU Cybersecurity Act (2019) and EU Cyber Resilience Act (2024)

As regards the demonstration of compliance with the AI Act’s cybersecurity requirements for high-risk AI systems, two other European regulations may be relevant:

EU Cybersecurity Act (‘CSA’) - Regulation (EU) 2019/881

Aims to achieve a high level of cybersecurity, cyber resilience and trust within the EU and sets forth a framework for the establishment of voluntary European cybersecurity certification schemes for so-called ICT products, i.e., an element or a group of elements of a network or information system (Articles 1 (1) (b), 2 (13) CSA). Where high-risk AI systems are also ICT products, compliance with the cybersecurity requirements laid down in the EU AI Act can be presumed by demonstrating certification under the CSA in so far as such certification covers the AI Act’s respective requirements (Articles 42 No. 2, 15 No. 1, 5 AI Act). Concerning law enforcement and criminal justice, this would be particularly relevant for high-risk AI-enabled software, for instance allowing for biometric identification. In January 2026, the European Commission announced a Proposal for a Regulation for the EU Cybersecurity Act (‘The Cybersecurity Act 2’) aiming at, inter alia, further simplifying the certification process.

Cyber Resilience Act (‘CRA’) - Regulation (EU) 2024/2847

Whereas the CSA establishes a voluntary certification framework, the CRA aims at ensuring that digital products and services are secure by design, resilient against threats, and able to maintain security throughout their life cycle, and sets out mandatory cybersecurity requirements for products with digital elements made available on the market. With most of its provisions applying from December 2027, the CRA will concern a wide range of products placed on the EU market, including AI-enabled software. For high-risk AI systems, compliance with the CRA requirements shall also be deemed to satisfy the AI Act’s cybersecurity requirements in so far as those requirements are covered under the CRA (Recital 51 to the CRA).

EU NIS2 Directive (2016) and Implementing Legislation

At the domestic level, Germany has implemented the EU NIS2 Directive (Directive (EU) 2022/2555) through the NIS2 Implementation and Cyber Security Strengthening Act (NIS2UmsuCG), which entered into force on 6 December 2025. The NIS2 Directive imposes strict risk management, incident notification, and security obligations on critical entities and public bodies.

In particular, the EU NIS2 Directive establishes a high common level of cybersecurity across the EU, requiring entities subject to the framework to implement comprehensive cybersecurity risk management measures, covering access control, supply chain security, physical security of network systems, and human resources security, while management bodies are personally accountable for approving and overseeing such measures. On incident reporting, the Directive introduces a tiered architecture requiring an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and further reports as the situation develops. At governance level, Member States must establish national cybersecurity strategies, designate competent authorities, and set up Computer Security Incident Response Teams.

Human Rights

In Germany, issues of human rights at a national level are primarily governed by the fundamental rights framework of the German Constitution, the European Convention on Human Rights (‘ECHR’), the International Covenant on Civil and Political Rights (‘ICCPR’), Charter of Fundamental Rights of the EU (‘CFR’), and the Treaty on the European Union (‘TEU’). In view of typical autonomy and opacity, deploying AI systems in the judicial sector must respect and realise in particular the fundamental freedom and principles regarding:

  1. Fair trial (Article 6(1) ECHR, Article 14 ICCPR) (the fair trial principle is viewed to have its roots in Article 20 (3) German Constitution);
  2. The explainability of public measures as an expression of the rule of law and due process (Article 20 (3) German Constitution, Article 2 TEU);
  3. Judicial independence (Article 97 (1) German Constitution, Article 47 (2) CFR, Article 14 ICCPR);
  4. The right to express one’s views and have them considered in legal proceedings (audi alteram partem, Article 103 (1) German Constitution, Articles 41 (2) and 4 (1) CFR, Article 14 ICCPR);
  5. The right to adjudication (Article 19 (4) German Constitution, Article 47 (1) CFR);
  6. The right to non-discrimination (Article 3 German Constitution, Articles 6 and 14 ECHR, Articles 20, 21 and 23 CFR, Articles 4 and 14 ICCPR); and
  7. The right to privacy and informational self-determination and data protection (Articles 2 (1) and 1 (1) German Constitution, Articles 7 and 8 CFR, Article 8 ECHR, Article 17 ICCPR).

Moreover, the Council of Europe Framework Convention on AI and Human Rights, Democracy, and the Rule of Law deserves special mention as a multilateral initiative, being the first legally binding international treaty specifically designed to regulate AI. Opened for signature in September 2024, its primary objective is to ensure that as AI technologies evolve, they do not erode the fundamental pillars of modern society: human rights, democratic integrity, and the rule of law. As at June 2026, the Convention has not yet entered into force, as the minimum number of five ratifications has not been reached yet. Thus, the Convention currently has no binding effect in Germany. The Convention focuses on the lifecycle of AI systems, from design to decommissioning, and mandates adherence to seven fundamental principles: human dignity, transparency, accountability, equality, privacy, reliability, and safe innovation. It requires signatories to establish independent oversight bodies and provide clear legal remedies for individuals who suffer harm due to AI systems.

Outlook

Germany´s AI strategy for the justice sector is set out in a number of documents, focusing on responsible, human-centred and trustworthy deployment of AI to support, but not replace, judicial and administrative work.

The E-Justice Council’s Strategy for the Use of Artificial Intelligence in the Justice System, adopted in April 2025 is intended to coordinate the development, procurement and deployment of AI systems throughout the German justice system. Its stated mission is to use responsible, fair, comprehensible and reliable AI to improve access to justice and increase the effectiveness and efficiency of the justice system. In particular, AI is expected to support the structuring of case files, analysis of data and documents, and the handling of mass proceedings, while relieving justice personnel of repetitive tasks.

The strategic direction set out in the AI Strategy was further endorsed by the Joint Declaration on the Use of Artificial Intelligence in the Justice System, adopted by the Federal and State Ministers of Justice in June 2025. The Declaration reaffirms the commitment to a human-centred, trustworthy and transparent use of AI, emphasising that AI should automate repetitive tasks and facilitate document handling. It also highlights the intention to establish a nationwide AI platform for the judiciary for efficiently sharing, managing and further developing AI systems. Further goals are to strengthen data governance, promote innovation, develop a common interpretation of the EU AI Act and enhance AI literacy across all justice personnel.

The Guidelines for the Use of Artificial Intelligence in the Federal Administration issued by the Federal Ministry of the Interior in March 2025 further establish a common framework for the responsible deployment of AI across the federal administration. They are intended to ensure a coordinated, secure and trustworthy use of AI while leaving decisions on whether and which AI systems are deployed to the respective authorities. The guidelines are expressly conceived as the starting point of a longer-term transformation process that will radically transform work in the federal administration. The guidelines envisage AI being deployed primarily to support administrative processes while ensuring a responsible use of AI, a human-centred approach, trustworthy and secure AI, the promotion of AI literacy and sustainable implementation

European Commission’s Proposed Digital Omnibus Regulation (2025)

In November 2025, the European Commission published its Digital Omnibus Regulation Proposal, a reform package to simplify and streamline existing EU regulations concerning the digital space, including the GDPR and EU AI Act. Respective amendments to the LED are to follow.

Notably, the European Commission intends to amend the definition of the term ‘personal data’ in Article 4 (1) GDPR by stating that information is ‘not to be considered personal data for a given entity when it does not have means reasonably likely to be used to identify the natural person to whom the information relates.’ Accordingly, such an entity would not fall within the scope of the GDPR regarding the processing of such data. This approach is generally in line with recent CJEU case law establishing that existing additional information enabling an entity to identify the data subject does not as such mean that pseudonymised data are to be considered personal data in all cases and for every person. In other words, personal data can be pseudonymised for one entity and anonymised (and thus not identifiable) for another (CJEU, 4 September 2025, EDPS v SRB, C‑413/23 P). Such an amendment wording would, if implemented, significantly reshape the legal test to be conducted to assess applicability of the GDPR (i.e., the assessment of the existence of personal data) towards an entity-focussed approach and largely exclude pseudonymised data from the scope of the GDPR.

The European Commission, through its Digital Omnibus Regulation, also intends to clarify that the processing of personal data in the context of AI development may be carried out for purposes of a legitimate interest where appropriate (Article 6 (1) (f) GDPR). Such an amendment would address an issue that has been widely adopted since the emergence of LLMs, and which has also been subject to a dedicated Opinion of the European Data Protection Board (Opinion 28/2024).

CASES

Facial recognition

In its decision of 24 April 2025 (5 Ds 29 Js 1276/25), the District Court Reutlingen held that the accused should be assigned a court-appointed attorney due to the complexity of the factual and legal issues, since the suspicion ('Tatverdacht') against the accused was based primarily on an unspecified police facial recognition software, of which neither the algorithm, underlying reference data nor the quality parameters of the evaluation were disclosed. It further held that in cases such as this one, as a rule, an expert opinion from an anthropologist will be required to resolve the issue of identity.

In a further decision of 11 February 2026 (5 Gs 19/26), the District Court Reutlingen held that an arrest warrant could not be issued, since a strong suspicion ('dringender Tatverdacht') cannot be established using predominantly a facial recognition software, whose functionality, algorithm, reference data, and quality parameters are not documented in a transparent manner.

Data protection

In February 2023, the German Federal Constitutional Court issued ruling 1 BvR 1547/19 and 1 BvR 2634/20, in which it determined that the legal basis for automated data analysis (specifically the HessenDATA system in Hesse and a similar legislative framework in Hamburg) was unconstitutional as it violated the right to informational self-determination. The Court found that the state laws allowed for 'data mining' or automated analysis without a sufficiently high threshold of danger. It ruled that such intrusive software may only be deployed if there is a 'sufficiently concretised danger' to particularly important legal interests, such as life, bodily integrity, or the existence or security of the Federal Republic or one of its states. Consequently, the court declared the Hessian law unconstitutional but granted the State of Hesse a transition period to rewrite its law to meet constitutional standards and continue operating HessenDATA. In contrast, the Court struck down the Hamburg law without an amendment period, as the system was not yet operational in that state.

In a similar line of caselaw, in Order of 17 July 2024, dkt. No. 1 BvR 2133/22, the German Federal Constitutional Court has also found, upon constitutional complaint, certain surveillance powers concerning data collection and transfer vested in the Hessian Office for the Protection of the Constitution (Landesamt für Verfassungsschutz) by the Hessian Protection of the Constitution Act (Hessisches Verfassungsschutzgesetz – HessVSG) to be incompatible with the German Constitution. Specifically, the Court affirmed a violation of the right to informational self-determination based on Articles 2 (1) and 1 (1) German Constitution. This ruling concerned, inter alia, Section 9 (1) No. 2 HessVSG which permitted the use of ‘technological means’ to track the location of mobile devices during their active mode, provided that such measure is necessary to realise the authority’s tasks. Hence, the provision would potentially legitimise long-term near-synchronous tracking and thereby creating movement profiles. In view of severe interference with said fundamental right and absent both a sufficient threshold (‘heightened need for surveillance’) and mandatory ex ante oversight, the Court denied proportionality. Ultimately, the Court held that ‘technological means’ pursuant to Section 9 (1) No. 2 HessVSG may only be used to track movements selectively intermittently, and not on a long-term basis unless, as Section 9 (2) HessVSG stipulates, such measures are necessary in view of high need for surveillance. The latter is specified in Section 3 (2) HessVSG as a potential significant threat to the liberal democratic order or the existence or security of the Federal Republic or one of its states.