PRACTICE AREAS

Ship smart, own what you build IT, AI & IP Law

We give product and technology companies one team for the full EU legal stack of building, launching, and protecting technology in Europe.

COMMON ISSUES

what catches tech companies off guard in the EU

The EU legal stack for technology is different  and most US teams discover that late.

You don't know which EU regulations apply to your product EU AI Act, GDPR, NIS2, the Product Liability Directive, and the Digital Services Act all potentially apply to US technology products. Each has different thresholds, different timelines, and different obligations. Most US teams don't know where they stand.
We map your product against the EU regulatory stack, identify which regulations apply at what threshold, and give you a prioritized compliance roadmap — starting with what's live now and building toward what comes next.
Your IP is at risk from your own codebase Open source license contamination, undocumented IP assignments from contractors, work done by foreign employees without clear ownership clauses.
We audit your IP and open source position, clean up assignment gaps and license conflicts, and build the IP governance framework that protects your codebase as you grow, hire, and scale in the EU.
Your EU technology contracts don't protect you US-drafted SaaS agreements, vendor contracts, and outsourcing arrangements don't translate cleanly to EU law. Polish courts interpret termination, liability, and SLA obligations differently. EU consumer law overrides standard clauses in B2C contexts.
We rebuild your EU technology contract system - SaaS terms, vendor agreements, outsourcing contracts, SLAs for the EU law jurisdictions where your customers, suppliers, and employees are.

WHO THIS IS FOR

Built for technology companies shipping in the EU

We work best with US product teams, CTOs, and GCs who are past the “does EU law apply to us?” question and into “what specifically do we need to do?” The work pays off fastest when EU revenue, EU enterprise customers, or a US investor’s due diligence is on the line.

You're a US AI company shipping into EU markets

You need to know your AI Act tier, your GPAI status, and your customer-facing obligations before launch, not during a deal.

  • CEO
  • CTO
  • GC

You're a US SaaS company building EU enterprise revenue

Your contracts, terms, and compliance documentation need to hold up under EU law and EU enterprise procurement standards.

  • CEO
  • GC
  • Head of Sales

You're raising a round and your EU IP position is under scrutiny

Open source compliance, contractor IP assignments, and EU IP rights will come up in VC due diligence. You want them clean before they ask.

  • CEO
  • CTO
  • CFO

You're deploying AI in your EU operations or for EU customers

AI features used in HR, compliance, customer support, or financial services trigger EU AI Act obligations. You need the compliance framework before the feature ships.

  • CPO
  • CTO
  • GC

OUTCOMES

what you can expect

What a working EU tech legal stack gives you.

EU enterprise deals close faster

Your contracts, terms, and compliance documentation pass EU enterprise procurement review - no three-week delay in legal review.

Your IP is clean in due diligence

Open source position, contractor assignments, and EU IP rights are documented and defensible before a VC or acquirer asks.

Your AI product ships without regulatory surprises

EU AI Act tier classification, GDPR obligations, and AI governance documentation are in place before launch.

Your technology contracts work in EU courts

SaaS terms, vendor agreements, and outsourcing contracts are built for EU law.

Your team knows what's allowed with AI

An AI governance policy and training program means your engineers and product teams use AI tools with clear rules.

HOW WE WORK TOGETHER

what you can expect

How we build EU tech legal infrastructure.

Assess

We map your product against the EU regulatory stack and identify which rules apply now.

  • AI Compliance Audit
  • EU SaaS Foundations
  • Data Legality

Build

We establish the contracts, compliance documentation, and IP protections your EU operations need.

  • IT & AI Contracts
  • EU SaaS Foundations
  • Open Source
  • AI Governance

Launch

We support the legal dimension of product launches, AI features, and EU market entries.

  • IT & AI Project Counsel
  • AI Governance
  • AI Training

Protect

We maintain the legal infrastructure - IP, contracts, compliance, as your EU footprint scales.

  • Open Source
  • Cybersecurity
  • IT & AI Contracts

BLOG

knowledge base

Practical reads on Polish and EU law, written for the people actually running the business – not studying it.

YOU OFTEN ASK

FAQ

Most questions come down to two things – what applies, and who’s personally liable. Here are the answers we give most often.

Yes. The EU AI Act applies to providers and deployers of AI systems when those systems are placed on the EU market or used in the EU — regardless of where the company is incorporated. A US company that deploys an AI system in its Polish entity, or that provides an AI product to EU customers, can be subject to AI Act obligations. The specific requirements depend on the risk classification of the system. Prohibited practices and AI literacy requirements became applicable in February 2025; most other obligations phase in through 2026 and 2027.

Different frameworks, different questions. An EU AI Act audit assesses your AI systems against the Act’s risk tiers, documentation requirements, and GPAI obligations. A GDPR audit assesses your data processing practices. They overlap – particularly for AI features that process personal data, but each has specific obligations the other doesn’t. We often run them together.

Primarily copyleft licenses — GPL (v2 and v3), AGPL, LGPL — which can require you to publish your own source code under the same license if you distribute or modify covered components. AGPL is particularly problematic for SaaS because it can trigger on network use. Permissive licenses (MIT, Apache 2.0, BSD) are generally low-risk. The issue is often that no one has mapped which licenses are in use.

NIS2 is the EU’s revised Network and Information Security directive, requiring cybersecurity measures and incident reporting for companies in specified sectors and above certain size thresholds. It applies to entities operating in the EU — including subsidiaries of US companies — if they fall within regulated sectors (cloud, digital services, critical infrastructure, and others). We assess whether NIS2 applies to your EU operations.

Not automatically you — which is the problem. Polish law gives individual creators specific rights that require explicit assignment to transfer to the employer or client. Standard US-style work-for-hire language doesn’t work in Polish law. Without proper IP assignment clauses in your contractor agreements, the ownership of what they build is legally ambiguous.