Dark Mode Light Mode

AI-generated corporate secrets: The internal market’s legal void

How algorithmic autonomy bypasses civil law and threatens the EU single market.
CC BY-SA 4.0© Photo by Bbx118 (European Single Market map, published 3 January 2026.)

As European enterprises rapidly integrate generative AI into their daily operations to optimise logistics, a vulnerability is emerging. While policymakers remain focused on public compliance with the EU AI Act, a systemic threat is developing within the domain of private B2B commerce.

Continental private law frameworks (specifically contract law, tort law, and trade secret regimes) are fundamentally built around human intent and creation. When companies use generative models to produce business strategies or industrial designs, they often move entirely outside these traditional legal protections. While hybrid human-AI workflows still offer some degree of protection where human refinement and oversight are substantial, purely autonomous outputs represent a profound legal gap. This analysis examines two critical dimensions: first, whether European civil law protects business data and industrial designs produced autonomously by AI, and second, who bears responsibility when such systems cause commercial harm. 

The human element 

The legal status of generative artificial intelligence outputs within the European Single Market depends heavily on traditional civil law principles. Across continental legal traditions, including the Italian Codice Civile, the German Bürgerliches Gesetzbuch (BGB), and the Spanish Código Civil, the allocation of property rights and the enforcement of remedies are inextricably connected to human authorship and human personality. For a process or dataset to be recognised as a protected corporate asset, it must result from conscious human intellectual choices.

When an enterprise generative model processes operational data to output an optimised industrial layout or a chemical synthesis process, this human-centric legal framework creates structural market friction across two core fronts: formal intellectual property protection and trade secrecy.

Advertisement

Firstly, under European intellectual property laws, original authorship and inventorship are strictly restricted to natural persons. While a corporation can own an intellectual property title, it cannot claim original copyright or patent ownership over an output that lacks a direct human creator. Because an autonomous algorithm generates the underlying configuration, the output fails to qualify for standard intellectual property registrations. For instance, it cannot be patented under the European Patent Convention (EPC) guidelines, which strictly require that the inventor must be a natural person, a principle upheld by the European Patent Office in the landmark DABUS rulings. This creates an immediate asset vulnerability: machine-generated layouts, codebases, and molecular formulations fall straight into the legal public domain, leaving them highly exposed to replication by competitors.

Consequently, to protect these assets in the absence of patents or copyrights, companies often rely on the EU Trade Secrets Directive (Directive 2016/943), which protects undisclosed know-how and business information. However, to claim trade secret protection in a civil court, a company must satisfy three cumulative criteria under Article 2: the information must be secret and not readily accessible, it must have commercial value because it is secret, and the holder must take reasonable steps under the circumstances to keep it confidential.

Using third-party generative AI models directly conflicts with this third requirement, particularly when companies utilise standard or unmanaged consumer-grade platforms. While enterprise-tier contracts often feature robust Data Processing Agreements (DPAs) and private cloud environments, standard commercial models routinely retain user inputs for model training. Inputting proprietary parameters into these unverified architectures breaks the confidential chain of custody.

If a competitor later intercepts or independently generates the same process, courts may rule that the original firm failed to maintain the required standard of reasonable confidentiality. Furthermore, the legal defence available to competitors under the Directive exacerbates this risk. Article 3 explicitly establishes that independent derivation and reverse engineering are lawful means of acquiring information. If a competitor feeds an unprotected industrial layout into their own AI model and arrives at a near-identical optimisation, they are exercising a protected statutory right rather than committing a trade secret violation.

By processing proprietary data through unverified external networks, a company risks invalidating its trade secret protections long before a commercial dispute ever reaches B2B litigation.

Contractual intent and cross-border liability asymmetry

The private law gap similarly distorts risk allocation when generative AI models commit errors during cross-border B2B transactions within the single market and extended global supply chains. Contract law is historically based on the meeting of minds and the expression of human intent. European private law has long treated software as a mere messenger or passive tool used by a human to express a predetermined will. If an automated system made an error, the deploying company was bound by the output, but the parameters remained predictable because they were set by humans.

Generative AI alters this relationship. Because these models adapt and produce variable, probabilistic outputs, they do not simply execute pre-programmed human commands. Instead, they generate new contractual variables without direct, real-time human oversight.

While the deploying enterprise may argue a lack of specific intent for those exact terms, continental civil courts consistently prioritise protecting a good-faith counterparty who relied on the system’s output. The deployer’s legal intent is constructed as an anticipatory declaration of intent to be bound by the system’s operational boundaries, applying the doctrine of apparent authority.

Because the EU has not harmonised the rules of digital contractual agency, member states evaluate these attribution disputes through fragmented national laws. A German court applying the BGB under the doctrine of Rechtsscheinvollmacht (agency by apparent authority) utilises entirely different reliance and negligence thresholds than an Italian court applying the Codice Civile under the tutela dell’affidamento (protection of legitimate expectations and good-faith reliance). This divergence significantly reduces transactional predictability within the internal market. It introduces friction into bi-regional economic partnerships where clear legal attribution is critical to sustaining foreign direct investment and secure data flows.

Furthermore, while a European company is bound to an unfavourable contract by a civil court, it rarely has a direct legal avenue to seek indemnification from the technology provider that built the AI. Standard End-User Licence Agreements (EULAs) used by major software vendors contain broad, non-negotiable liability waivers. These contracts disclaim all responsibility for damages caused by algorithmic errors or data distortions. Consequently, European companies absorb the operational liability down the supply chain while being contractually barred from passing that liability back to the software developers.

Unfair competition and tort remedies

When proprietary, machine-generated layouts or strategies are copied by competitors, firms often look to tort law and doctrines of unfair competition as a safety net. Under Article 2043 of the Italian civil code or Article 1902 of the Spanish civil code, an act that causes unjust damage obliges the negligent actor to repair it. However, litigating the misappropriation of an AI-generated asset under these provisions presents significant evidentiary hurdles.

Unfair competition claims demand proof of illicit methods—such as deceptive exploitation or a breach of confidence. Because machine-authored configurations lack formal copyright or patent status, a competitor who copies an AI-optimised design can easily argue they are engaging in permissible market imitation of legally unappropriated data. Without a clear paper trail of bad faith, national judges struggle to justify immediate injunctions.

To establish extra-contractual tort liability, a plaintiff must also prove a direct causal link between the defendant’s conduct and the resulting economic harm. In generative AI environments, proving this link is incredibly complex. If a competitor copies a process, they can easily feed it into their own generative model, altering the parameters slightly. In court, the defendant can argue that their configuration was arrived at independently by their own AI, making it virtually impossible to trace the origin of the data or prove derivation.

This commercial liability vacuum is supercharged by the colliding timelines of recent EU legislation. As Member States navigate the transposition deadline for the revised Product Liability Directive (PLD), the law’s expansion of strict liability to software harbours a critical B2B exclusion: data destruction protections apply exclusively to non-professional uses, leaving commercial property damage and pure economic loss entirely unaddressed.

Conclusion

The integration of generative AI into corporate workflows creates real private law challenges that complicate asset protection. While the structural implementation of the EU AI Act establishes a vital baseline for public administrative safety and risk classification, it leaves the foundational engine of the internal market exposed to severe systemic friction. To prevent a deepening legal vacuum that actively disincentivises private sector innovation, European policymakers must expand their focus beyond bureaucratic compliance and address the unharmonised cracks within continental civil law. With the European Commission’s withdrawal of the AI liability directive  (AILD), the single market is left in a regulatory pincer as domestic enterprises face heavy compliance overhead under the AI Act while possessing zero harmonised civil recourse.

To maintain the long-term stability and predictability of the single market, future EU policy initiatives must target these private law dimensions:

  1. Establish digital contractual agency: To resolve the systemic friction between fragmented national doctrines, the EU should establish a technical-legal standard for digital agency.  Under the eIDAS 2.0 (Regulation 2024/1183) framework, the Commission should introduce Certified Algorithmic Representative Credentials (CARCs) as a specific class of Electronic Attestation of Attributes (EAA). Managed through EUDI wallets, these credentials would allow an enterprise to issue a legally binding cryptographic mandate. By using qualified electronic signatures to sign operational parameters like transaction ceilings or approved counterparty lists, enterprises can provide immediate legal clarity, so any transaction executed by an algorithmic agent within these verified bounds would be automatically and legally attributable to the parent enterprise, providing a unified standard that would ensure transactional predictability across the Single Market.
  2. Rebalance upstream/downstream liability: The EU should use the established unfairness control mechanism and transparency mandates within existing digital legislation to dismantle the regulatory pincer without infringing on B2B freedom of contract. As the withdrawal of the AILD last year leaves B2B AI liability primarily to private law, the Commission should clarify that contractual terms in B2B data-sharing arrangements are presumptively unfair (under Article 13) if they exclude liability for algorithmic failures that prevent a business from exercising its right to access data. Thus, by framing algorithmic defences as a breach of data-related obligations, the EU can leverage the EU Data Act’s existing grey list to protect SMEs.  Furthermore, the Commission should use its mandate under Article 41 of the Data Act to draft specialised model contractual terms (MCTs) that provide risk allocation frameworks for AI-related services, such as standardised right of recourse clauses. Even though they are not binding, the MCTs would serve as a benchmark for dispute settlement bodies when determining if there has been an abuse of market position by a provider to shift the regulatory burden to downstream European enterprises. Lastly, the EU should establish that a provider’s failure to comply with the AI Act’s documentation or the GPAI transparency requirements triggers a breach of the duty of care, allowing downstream businesses to use this lack of transparency as a basis to seek damages. 
Author: Luciana Belen Escalante Columbus Reviewer: Fátima Elke García Pérez

Keep Up to Date with European Affairs

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Previous Post

Coerced Diversification – Hungary, EU Financial Leverage, and the Logic of Weaponized Interdependence

Next Post

Protecting children from organised crime: is that possible?

Advertisement