Technology Law · Priority Practice

Emerging Technologies & AI.

Legal counsel for companies at the cutting edge — AI corporations, robotics companies and autonomous vehicle developers. EU AI Act compliance and risk classification, AI liability frameworks, governance programme design and novel risk assessment for products ahead of the regulation.

EU Data Regulation
11 yrsIn-House Tech GC Experience
8Jurisdictions Covered
4Languages
Fortune 50 GC experience
In-house experience with a major technology corporation navigating emerging-tech regulatory exposure — national security designations, novel product classifications — across 8 jurisdictions and 4 business divisions.
AI Act and GDPR, handled together
A formal, examined qualification in European data protection law — directly relevant where AI systems process personal data and the AI Act and GDPR both apply at once.
Dual-qualified: Greece & England/Wales
Our Managing Partner is dual-qualified in England & Wales and Greece, so English-law questions are advised on directly in-house. Court appearances remain before the Greek courts and international arbitral tribunals; English proceedings are conducted through instructed English correspondent counsel.
Building something the law hasn't caught up to yet?
Tell us what you're building, what data it touches, and where you plan to deploy it. We'll tell you your risk tier and what actually needs to be in place before launch.
Request Consultation
Overview Scope of Service Process Why Us FAQs

Emerging Technologies & AI

Novel technology
is not a legal vacuum.

The EU AI Act introduces a risk-based classification system that now governs how AI systems can be built, deployed and marketed across the European Union. AI practices are sorted into four tiers — unacceptable risk (prohibited outright), high risk (subject to conformity assessment, technical documentation and human oversight requirements), limited risk (transparency obligations) and minimal risk (largely unregulated) — and which tier a given system falls into is rarely obvious from the outside. Getting the classification wrong at the outset compounds every downstream compliance decision. An EU AI Act lawyer in Greece will classify the system before advising, since obligations follow from the risk tier.

The absence of an AI-specific rule is not the absence of legal risk. Companies building robotics platforms, autonomous vehicles or genuinely novel AI applications sometimes assume that because no regulator has written a bespoke rule for their exact technology, they operate in a legal grey zone with limited exposure. That assumption is wrong. Product liability law, consumer protection law, general tort principles and sector-specific safety regulation all continue to apply to AI and robotics systems regardless of whether AI-specific legislation has caught up — and courts and regulators are already applying existing frameworks to novel technology in ways that create real, present liability.

Novel technology does not mean no legal exposure — it means the exposure has to be reasoned out from first principles instead of read off a statute built for it. Provider and deployer duties differ substantially, so an EU AI Act lawyer in Greece establishes your role in the chain first.

The complexity compounds further when an AI system also processes personal data, which is the case for most commercially deployed AI. The AI Act and the GDPR then apply simultaneously and interact — a high-risk AI system processing personal data carries obligations under both frameworks at once, and satisfying one does not automatically satisfy the other. Companies building technology that is genuinely ahead of the regulatory curve need counsel who can reason from underlying legal principles — liability, safety, jurisdiction, data protection — rather than counsel whose method starts and ends with citing an existing rule that may not yet exist for what they've built. Describe the system and its use and we will classify it.

Not optional
Risk classification isn't optional
Every AI system placed on the EU market falls into one of four AI Act risk tiers whether or not anyone has formally assessed it — an unassessed system is not a compliant one.
A common mistake
Novel tech ≠ no legal exposure
Product liability, consumer protection and tort law apply to AI and robotics systems today, regardless of whether AI-specific legislation exists for the exact use case.
Dual framework
AI Act meets GDPR
AI systems processing personal data must satisfy both frameworks simultaneously — the overlap, not either regime alone, is where most compliance programmes fall short.
Sequencing matters
Governance before enforcement, not after
A governance programme built before a regulator or claimant asks questions is materially cheaper and more defensible than one assembled in response to one.

Scope of Service

From risk classification
to a defensible governance programme.

EU AI Act Compliance & Risk Classification
Determining which of the four AI Act risk tiers your system falls into — unacceptable, high, limited or minimal risk — and building the conformity assessment, technical documentation and oversight measures the classification requires.
AI ActRisk TiersConformity
Core service →
01
AI Governance Programme Design
Designing the internal governance structure — policies, oversight roles, model documentation and review cadence — that lets an organisation demonstrate control over its AI systems before a regulator asks it to.
GovernancePolicyOversight
Core service →
02
AI Liability & Accountability Frameworks
Mapping where liability sits when an AI system causes harm or makes a consequential decision — developer, deployer, integrator — and structuring contracts and internal accountability lines accordingly.
LiabilityAccountabilityContracts
Core service →
03
Algorithmic Decision-Making Legal Review
Reviewing automated and algorithmic decision-making systems — credit, hiring, pricing, content moderation — against transparency, explainability and non-discrimination obligations before they go live.
AlgorithmsTransparencyReview
Core service →
04
Robotics & Autonomous Vehicle Regulation
Advising robotics manufacturers and autonomous vehicle developers on the product safety, type-approval and liability regimes that apply well before any AV-specific legislation is finalised.
RoboticsAutonomous VehiclesProduct Safety
Core service →
05
Novel Risk Assessment for Unregulated Technology
Reasoning from first principles — product liability, tort, sector safety rules, cross-border jurisdiction — to assess legal exposure for technology that has no dedicated regulatory framework yet.
Novel RiskFirst PrinciplesStrategic Advisory
Core service →
06

How We Work

A governance process built to survive regulatory scrutiny.

STEP 01
Technology & Risk-Tier Assessment
Understanding what the system actually does, what data it touches and how it is deployed, then mapping it against the AI Act's risk tiers and any applicable product safety regime.
STEP 02
Governance Framework Design
Designing the governance structure — oversight roles, documentation standards, review cadence — calibrated to the risk tier and the organisation's actual operating model.
STEP 03
Documentation & Compliance Implementation
Drafting the technical documentation, conformity records, data processing assessments and internal policies, and embedding them into how the system is actually built and shipped.
STEP 04
Ongoing Regulatory Monitoring
Tracking AI Act guidance, national implementing measures and case law as they develop, and updating the governance programme before a gap becomes an exposure.

Why Pantazis & Associates

Counsel who reasons from principle
not just from precedent.

In-House · Fortune 50
Emerging-tech regulatory exposure at scale
As general counsel to a Fortune 50 technology group, Dionysios Pantazis navigates emerging-technology regulatory exposure at first hand — national security designations, novel product classifications — across eight countries and seven business lines, at real scale, not in the abstract.
Certified · Data Protection
One methodology for the AI Act and GDPR overlap
A formal, examined qualification in European data protection law, applied directly to the compounding compliance question every AI system that touches personal data eventually faces.
Dual Qualification · International
Greece & England/Wales — cross-border AI deployment covered directly
AI products rarely launch in one jurisdiction alone. Dual qualification means cross-border deployment questions are handled under a single instruction, without a referral to a second firm.

Frequently Asked Questions

Questions about emerging technologies & AI.

Does the EU AI Act apply to my AI product, and which risk tier am I in?+

In almost all cases, yes, if you develop, deploy or distribute an AI system that touches the EU market. The AI Act sorts systems into four tiers — unacceptable risk (banned outright, such as certain manipulative or social-scoring practices), high risk (subject to conformity assessment, technical documentation, human oversight and registration requirements), limited risk (transparency obligations, such as disclosing that content is AI-generated) and minimal risk (largely unregulated). The classification depends on what the system does and who it affects, not on what industry you're in, and it is rarely as obvious as it first appears. We assess the system against the Act's criteria and document the classification to a standard that holds up under scrutiny.

If my AI system doesn't have a specific law written for it yet, does that mean there's no legal risk?+

No, and this is one of the most consequential misconceptions we see. The absence of AI-specific legislation for your exact use case does not mean the absence of legal exposure. Product liability law, consumer protection law, general tort principles and sector-specific safety regulation all continue to apply to AI, robotics and autonomous systems regardless of whether bespoke AI rules exist yet. Courts and regulators are already applying existing frameworks to novel technology, and being first to market with something genuinely new does not delay the point at which liability can attach. We assess exposure by reasoning from the legal principles that do apply, rather than waiting for a rule that names your product specifically.

How does the AI Act interact with GDPR when our AI system processes personal data?+

The two frameworks apply simultaneously and independently — satisfying one does not satisfy the other. A high-risk AI system that processes personal data needs both an AI Act conformity assessment and a GDPR-compliant lawful basis, and in many cases a Data Protection Impact Assessment covering the AI-specific risks the system introduces (profiling, automated decision-making, novel inference from data). The two regimes also use different vocabulary for overlapping concepts, which is where compliance programmes that treat them as separate workstreams tend to develop gaps. We handle both together under a single methodology, so the overlap is addressed once rather than twice.

What legal issues should a robotics or autonomous vehicle company think about before launch?+

Product liability and safety come first — who is responsible when a robot or autonomous system causes harm, and what evidence will demonstrate the system was designed and tested responsibly. Type-approval and sector-specific safety regimes may apply depending on the product category, often well ahead of any AI- or AV-specific legislation catching up. Data governance matters too, since these systems typically collect sensor and environmental data at scale. And cross-border questions arise quickly — a vehicle or robot that operates or is sold across jurisdictions inherits a different liability and regulatory picture in each one. We work through these systematically before launch, not after an incident forces the question.

Do we need an AI governance programme, or is a policy document enough?+

A policy document is a starting point, not a governance programme. A functioning programme includes defined oversight roles, a documented risk classification for each system in use, technical documentation that is actually maintained as systems change, and a review cadence that catches new deployments before they go live unassessed. Regulators and claimants test what an organisation can actually produce and demonstrate, not what a policy states in principle. Building the governance programme before it is tested — rather than after a regulator or an incident forces the question — is materially cheaper and more defensible.

Related Services

Other Technology Law services.

Building something the law hasn't caught up to yet?
Let's get ahead of it.

A first conversation about your technology, your risk tier and the governance gaps that actually create exposure. No obligation.