30.03.2026.
Legal aspects of blockchain and digital assets – Issues of Technology and Law

Interdisciplinary international conference on technological and legal issues.

The aim of the event organized by Attila Menyhárd, professor at the Department of Economics and Technology Law, is to provide a broad overview of current legal issues that hinder, restrict, or even prevent IT developments in the industrial, financial, and service sectors.

Key topics:

  • Technology: AI, blockchain

  • Law: Law of Technology
  • Assets, Crypto Assets
  • Financial Sector
  • Costumer Protection

Conference venue: Eötvös Loránd Tudományegyetem, 1053 Budapest, Egyetem tér 1-3.
Date of the conference: 2026. 02. 12.

Explore the Conference Sessions

IN MEDIAS RES: ASSETS

Data ownership: where we are, and where we are heading

Tamás Parti

vice president, Hungarian Chamber of Civil Law Notaries, head of its Data Research Unit

This presentation explores what it truly means to treat digital data as property. It examines why today’s legal systems still struggle to distinguish data from information, and how this conceptual gap complicates efforts to build coherent rules for data ownership. Viewers get a clear, accessible overview of why redefining digital data is essential for the future of property law in the digital economy.

Summary

This lecture explores one of the most pressing conceptual challenges of the digital era: how to understand and regulate data as a potential object of property law. It examines why, despite the growing economic value of digital data and database assets, current legal systems still struggle to treat data as property. The speaker highlights that modern regulatory frameworks typically interpret data through the lens of information, a conflation that obscures the physical nature of digital data and prevents the development of coherent property based regulation. This conceptual gap is shown to hinder the creation of clear, enforceable rights in the data economy.

The presentation goes on to clarify the fundamental distinction between digital data—a physical, machine readable phenomenon—and information, which only arises when data is interpreted by the human mind. Building on this distinction, the lecture surveys current European and international regulatory trends, explaining why the EU’s legal instruments remain focused on data access and governance rather than ownership. It also introduces emerging international examples where certain digital assets, such as tokenized or electronic securities, are beginning to receive property like treatment, offering early models for how data itself might eventually enter the realm of property law.

Ultimately, the lecture argues that establishing a genuine property framework for digital data would bring significant benefits: legal clarity, stronger enforceability, greater market stability, and the ability to integrate data assets into financing, insolvency, and inheritance processes. By outlining both the conceptual problems and the potential legal solutions, the presentation invites viewers to reflect on how the future of data governance may depend on rethinking the very foundations of property law in the digital age.

Tokenization of Securities and Real-World Assets: New Clothes for Old Concepts?

António Garcia Rolo

Universidade de Lisboa

This talk offers a fresh perspective on crypto assets by shifting the focus from their technological hype to their legal substance. It explains tokenization as a modern form of representing rights and assets, showing how tokens relate to real world value and where current legal frameworks succeed — or fail — in addressing them. A compelling introduction for anyone seeking clarity on how blockchain based assets fit into traditional civil and commercial law.

Summary

This lecture examines how blockchain based crypto assets fit — or fail to fit — within the traditional structures of civil and commercial law. The speaker reflects on several years of research and practical involvement in the field, noting that once the initial technological hype fades, a more fundamental question emerges: what is actually special about crypto assets from a legal standpoint? The presentation argues that, despite their technological novelty, most crypto assets are best understood as digital representations of rights, obligations, or value, whose distinguishing feature lies primarily in how ownership and transferability are determined through decentralized ledger systems such as blockchain. In this sense, blockchain functions less as a radical departure from legal tradition and more as a new type of registry — a private, technologically decentralized counterpart to state run registries.

The talk then explores tokenization as an increasingly prominent way of understanding crypto assets. Rather than classifying tokens according to their function, tokenization focuses on what real world (off chain) assets, values or legal relationships a token seeks to represent. The speaker outlines different forms of tokenization — from direct or “native” tokenization, where the token itself is the primary legal representation of the asset (as with tokenized securities), to indirect tokenization, where tokens merely reflect rights or values that continue to be governed by traditional legal structures. Through examples involving tokenized securities, stablecoins, real estate structures, and commodity backed tokens, the lecture demonstrates that many widely advertised “tokenized real world assets” are in fact indirect, contractual representations, not true digital embodiments of physical ownership.

Finally, the presentation surveys how different jurisdictions — such as France, Germany, Spain, Liechtenstein, and Dubai — are attempting to regulate tokenization, with varying degrees of ambition and success. While some countries now provide bespoke legal frameworks for tokenized securities, the speaker emphasizes that direct tokenization of physical assets remains legally difficult and politically sensitive, as it would require rethinking property law, public registries, and even core elements of state sovereignty. As a result, real world asset tokenization today tends to function less as a reinvention of property law and more as an evolution of capital market infrastructure, offering new technological “clothes” for long established legal and financial arrangements.

Implementing MiCa in the Hungarian Legal Environment

Diána Mile

attorney at Mile & Partners, Mile Law Office, Blockchain Hungary Association

This presentation dives into Hungary’s unique and controversial implementation of the EU MiCA framework. It highlights how national rules introducing transaction level validation collide with EU level harmonization, raising questions about market access, legal certainty, and regulatory sovereignty. A timely and insightful look at a real world legal conflict shaping the future of European crypto regulation.

Summary

This presentation examines Hungary’s implementation of the EU wide MiCA framework through the lens of asset access, liquidity, and regulatory harmonization. Rather than focusing on how crypto works as a technology, the speaker explores how regulation determines who can hold, trade, and move digital assets — and how national rules can shape market reality just as much as EU level law. The Hungarian case becomes a vivid illustration of this tension. While MiCA was designed as a fully harmonized, single license regime meant to eliminate fragmented national frameworks, Hungary introduced an additional transaction level validation requirement, creating a dual system in which crypto to crypto and crypto to fiat transactions must be screened by a designated validator, with failure to comply carrying even criminal consequences.

The lecture offers a clear walkthrough of how this validator functions, emphasizing that it is not a supervisory authority in the MiCA sense, but a mandatory intermediary performing blockchain based risk analysis before certain transactions can proceed. This system overlays a new layer of compliance on top of existing EU AML rules, narrowing the pathways through which crypto service providers can legally operate. The presentation then situates Hungary’s approach within the wider EU legal landscape, explaining why the European Commission has already launched an infringement procedure: MiCA’s maximum harmonization logic leaves little room for member states to add additional licensing or criminal law regimes. As a result, service providers in Hungary now face a unique and legally uncertain environment in which EU level rights and national obligations may collide.

Finally, the speaker highlights the competitive and structural implications of Hungary’s model, especially as only one validator has so far been authorized — enabling, for example, Bitpanda to become the first fully compliant crypto broker under the new rules. This raises broader questions about proportionality, market access, and whether a single compliance channel risks creating de facto exclusivity. The presentation concludes by noting that Hungary’s situation may become a precedent for how strictly the European Commission enforces MiCA’s harmonization mandate, and underscores the need for continuous legal monitoring as national implementation and EU oversight continue to evolve.

Digitization and Private Law

Attila Menyhárd

Professor, ELTE Law

This talk opens up the broader civil law challenges raised by digital assets, showing how deeply emerging technologies force lawyers to rethink long established legal concepts. It highlights the tension between traditional legal reasoning and a rapidly transforming digital reality — and explains why adapting our legal mindset may be the most urgent task of all.

Summary

In this presentation, the speaker invites the audience to step back from specific regulatory debates and look at the fundamental civil law challenges posed by digital assets, blockchain technology, and the digital transformation more broadly. Rather than focusing on a single legal category or case, the talk maps out the deeper conceptual problems that arise when traditional legal thinking meets phenomena that cannot be easily visualized, localized, or fitted into pre existing frameworks. The speaker argues that much of the difficulty stems from a mismatch between law’s traditional attachment to physical reality and the intangible, often boundary less nature of digital assets. Concepts that once felt self evident — such as property, consent, written form, money, or securities — no longer provide clear guidance when applied to virtual environments, NFTs, or algorithmic decision making.

The presentation also reflects on how disruptive technologies expose long standing cognitive habits within the legal profession. Lawyers, trained to rely on codified rules and tangible references, struggle when those rules fail to capture emerging digital practices. This is evident in areas such as consumer protection, where the classic distinction between “consumer” and “non consumer” becomes increasingly inadequate in a world where everyone — individuals, companies, even banks — may be vulnerable to the power of dominant digital platforms. The speaker suggests that existing frameworks may eventually need to be replaced by broader principles capable of addressing transparency, accountability, and fundamental rights in digital ecosystems.

In the final part of the talk, the speaker highlights one of the most pressing unresolved issues: determining the applicable law for digital assets that have no physical location, no clear jurisdictional link, and no established legal classification. Traditional private international law — built on territoriality and the physical location of assets — offers no satisfactory solution for assets that are “not where.” The lecture outlines the emerging debates among major legal bodies (such as UNIDROIT, the American Law Institute, the European Law Institute, and The Hague Conference) and underscores how far the legal field still is from consensus. Ultimately, the talk emphasizes that the digital era not only challenges existing rules but forces a deep reconsideration of core legal concepts, requiring lawyers to rewire long established ways of thinking to keep pace with technological reality.

ESSENTIA OBLIGATIONIS: FINANCIAL SECTOR

The AI Act and its impact on the financial sector, with a particular focus on the categorization of AI systems and the resulting obligations for financial institutions

Damián Palašta

Masaryk University, Brno

This presentation demystifies the EU AI Act by showing how its regulatory logic applies in practice — especially in the financial sector. It explains why AI challenges traditional legal assumptions, how high risk systems are identified, and what new obligations organizations face when deploying AI tools that many already use every day. A clear and practical guide to understanding what the AI Act really demands.

Summary

In this talk, the speaker introduces the regulatory logic behind the EU Artificial Intelligence Act, focusing particularly on the challenges it raises for financial institutions. The presentation begins by highlighting a central dilemma: AI produces probabilistic outcomes through opaque "black box" models, while traditional legal systems rely on provable, transparent chains of reasoning. Because regulation inevitably lags behind technology, lawmakers must craft rules that accommodate AI’s unique character without fully understanding every technical detail. Against this backdrop, the EU has developed the AI Act — a horizontal, risk based framework designed to govern AI systems across sectors while interfacing with existing legislation such as GDPR and financial services regulations.

The speaker then explains how the Act categorizes AI into unacceptable, high risk, limited risk, and minimal risk systems. High risk categories — a key focus for the financial sector — include credit worthiness assessments, insurance risk scoring, and any system that profiles natural persons in ways that affect their rights or economic opportunities. Because these systems can manipulate behavior, exploit vulnerabilities, or unintentionally reproduce discriminatory patterns, the AI Act imposes extensive obligations on both providers and deployers. The presentation emphasizes that organizations cannot avoid responsibility by relying on third party software: if they fine tune or substantially modify an AI tool such as a large language model, they may legally become its “provider,” inheriting heavy compliance burdens, including documentation, monitoring, and conformity assessments.

A major practical takeaway concerns the newly introduced obligations around AI literacy, human oversight, risk management, and the Fundamental Rights Impact Assessment — a process akin to GDPR’s DPIA but broader in scope. Financial institutions using AI in credit or insurance contexts must assess impacts on equality, autonomy, transparency, and due process, and report their findings to supervisory authorities. The presentation also stresses the difficulty of distinguishing legitimate fraud detection analytics from prohibited profiling or biometric categorization, especially in systems trained on large behavioral datasets. Ultimately, the speaker argues that the Act forces organizations to deeply rethink their internal governance structures: AI cannot simply be “added on,” but must be embedded into risk management, compliance design, and human in the loop oversight. The result is a regulatory landscape that is ambitious, complex, and still evolving — requiring continuous adaptation as AI systems become increasingly integrated into everyday operations.

Artificial Intelligence and Deepfake-Enabled Fraud in the Banking Sector: Identification and Classification of Emerging Threats

Kristýna Mlčáková

researcher, Institute of Law and Technology, Faculty of Law, Masaryk University

This presentation examines how AI and deepfake technologies are transforming financial fraud, turning familiar scams into highly convincing digital attacks and creating entirely new threat categories. It highlights why traditional detection methods are failing — and why both regulators and institutions must rethink how they assess risk, protect customers, and build resilience in an age of synthetic identities, real time deepfakes, and AI driven deception.

Summary

In this talk, the speaker explores how artificial intelligence and deepfake technologies are reshaping the landscape of financial fraud, rapidly pushing institutions from familiar, traditional schemes into a new era of technology augmented attacks. As digital transformation accelerates across financial services, AI is no longer used only to support internal processes — fraudsters now employ voice cloning, face swapping, synthetic identities, and real time deepfakes to impersonate executives, deceive customers, and exploit authentication systems. Because these tools are cheap, accessible, and astonishingly convincing, the scale and sophistication of fraud attempts have surged dramatically. Even simple prompting of generative AI tools can produce realistic fraud scenarios, lowering the barrier of entry for attackers and elevating risk across the entire financial sector.

The presentation distinguishes between enhanced versions of traditional fraud — such as phishing, CEO impersonation, investment scams, or fake customer support — and entirely new types of fraud enabled by synthetic identities and deepfake manipulation. It highlights striking real world examples, including large scale losses caused by deepfake video calls in corporate environments. Fraudsters now use AI to bypass biometric authentication, manipulate onboarding processes, and craft personalized, highly credible phishing attacks that are nearly indistinguishable from legitimate communication. These developments expose significant vulnerabilities in processes that previously relied on human intuition, language cues, or facial recognition.

Finally, the speaker examines the limitations of the existing EBA fraud taxonomy, which primarily classifies fraud by outcome rather than by the technologies enabling it. While this approach has benefits, it fails to capture how AI and deepfakes fundamentally change execution methods, detection challenges, and risk profiles. The talk proposes expanding the taxonomy to explicitly include AI enabled and AI driven fraud categories, as well as new indicators such as attack vector, technical enablers, and the role of synthetic identity. The concluding message is clear: as AI makes fraud increasingly difficult to identify even for trained professionals, financial institutions and regulators must reconsider liability assumptions, redesign decision making frameworks, and acknowledge that the traditional expectation—that consumers should detect fraud themselves—is no longer realistic in an era of hyper convincing digital deception.

Limits to Using AI to Evaluate Credit Risk in Light of the Provisions of the AI Act

János Székely

associate professor, Sapientia EMTE, Law Faculty , Cluj Napoca/Kolozsvár

This presentation examines how the EU AI Act restricts the use of artificial intelligence in credit scoring and creditworthiness assessments. It highlights why such systems are classified as high risk, how the Act draws a sharp line between natural and legal persons, and what practical and conceptual challenges financial institutions face as they prepare for compliance in 2026.

Summary

In this talk, the speaker provides a clear and structured exploration of how the EU AI Act applies to credit scoring and creditworthiness assessments. The presentation begins by situating the AI Act within a broader regulatory trend in which the European Union attempts — unusually — to regulate technological risks before they materialize. This forward looking approach brings with it significant complexity: the Act combines extraterritorial scope, risk based categorization, and dense procedural obligations. Credit scoring and creditworthiness evaluation appear explicitly in the Act’s high risk category, as reflected in Recital 52 and Annex III, because AI based scoring can directly influence a person’s access to essential services and may reinforce discriminatory patterns. The speaker stresses that this logic places natural persons at the center of protection, establishing a regulatory asymmetry that will have lasting consequences.

A major part of the lecture highlights the regulatory divide between natural persons, who benefit from the Act’s fundamental rights based protections, and legal persons, who fall largely outside this framework. The speaker argues that this distinction is difficult to justify in practice. Small businesses may suffer the same vulnerabilities as individuals when evaluated by foreign, non EU AI systems, especially those developed by dominant U.S. providers. Drawing on human rights case law, the talk suggests that excluding legal persons entirely from the Act’s protections risks creating a form of implicit discrimination — something EU law seeks to avoid. The presentation also examines the narrow and somewhat artificial distinction between high risk “credit scoring” and non high risk “fraud detection,” questioning whether such activities can meaningfully be separated in the real world.

In its final section, the talk turns to practical compliance hurdles. Banks and financial institutions must contend with the opacity of AI models, the pervasive problem of algorithmic bias, long and fragmented supply chains that obscure responsibility, and the absence of an AI liability directive to harmonize evidentiary rules. The speaker also identifies a regulatory gap: the AI Act does not address dynamic pricing, a practice already in use in the United States, where AI adjusts prices based on a consumer’s behavior or perceived ability to pay. Such systems could influence interest rates or loan terms, yet remain outside the Act’s current definitions of creditworthiness assessments. The lecture concludes that the AI Act is both ambitious and incomplete — a framework that will require substantial judicial interpretation and likely legislative revision as AI continues to evolve faster than the regulatory mechanisms designed to govern it.

TECHNOLOGIA EX MACHINA: BLOCKCHAIN

“Just sign here” - the challenge of trust for smart contracts on blockchain

Simon Thompson

emeritus professor, University of Kent

This presentation revisits the technological foundations of blockchain to show why “trustless” systems are far less trust free than they claim. By unpacking the gap between the idealized peer to peer vision and the messy reality of modern blockchain interactions, it explains how identity, assurance, and software vulnerabilities create significant risks — and why these technological limits inevitably carry legal consequences.

Summary

In this talk, the speaker takes a technological deep dive into the foundations of blockchain, grounding the discussion in the original Bitcoin white paper and its ambition to eliminate trusted intermediaries. The presentation highlights how early blockchain ideology — built on cryptographic proof, peer to peer autonomy, and decentralized program execution — envisioned a system where individuals transact without relying on institutions. Yet, as the speaker demonstrates, this vision has never fully materialized. Real blockchain ecosystems are complex, layered environments filled with wallets, light clients, cloud services, oracles, and interfaces that mediate nearly every interaction. As a result, users often lack the basic assurances they take for granted in traditional online banking, such as identity verification or reliable confirmation of whom (or what program) they are actually engaging with.

The core problem, the speaker argues, is assurance: knowing that a smart contract behaves as intended, that a transaction is safe, or that the program one interacts with is legitimate. Through concrete examples of multi million dollar exploits — arising from coding mistakes, governance attacks, flash loan vulnerabilities, or outright fraudulent “rug pulls” — the presentation shows how brittle smart contract ecosystems can be. Unlike conventional software, smart contracts are immutable once deployed, meaning that even minor flaws can have catastrophic consequences. Auditors consistently report discovering vulnerabilities, and even well audited contracts can be undermined by small, later optimizations. The result is a technological environment where the absence of trusted intermediaries often shifts all risk onto users, contradicting the early blockchain promise of “trustlessness.”

In its concluding reflections, the presentation proposes a direction for improvement: integrating certification and verification mechanisms directly into blockchain tooling, allowing wallets to display authenticated information about smart contracts before transactions are signed. Emerging industry standards — such as Ethereum ecosystem certification frameworks — offer partial steps toward this goal but remain underdeveloped and inconsistently adopted. Ultimately, the speaker suggests, blockchain’s ideological commitment to decentralization does not remove the need for trust; it merely pushes questions of identity, reliability, and responsibility to higher layers of the ecosystem. Until technological and legal infrastructures evolve to address these gaps, blockchains will continue to operate in a space where users bear disproportionate risk and regulators struggle to keep pace.

The role of blockchain in Digital Transformation in SME and Public Administration

Bálint Molnár

professor, ELTE Faculty of Informatics

This presentation explores how blockchain can serve as a trust‑enhancing infrastructure for businesses and public administration. Moving beyond cryptocurrencies, it highlights the broader organizational, technological, and governance questions that arise when blockchain meets digital transformation — and shows why trust, interoperability, and careful system design matter far more than the technology itself.

Summary

In this talk, the speaker examines blockchain from an interdisciplinary perspective, connecting technology with business information systems and public‑sector digitalization. While blockchain is often associated with financial services, the presentation emphasizes that its potential reach is much wider. As organizations undergo digital transformation, they face fragmented systems, rising administrative burdens, and growing concerns about trust and data integrity. Blockchain promises solutions in the form of distributed ledgers, consensus‑based verification, immutability, and smart contracts, all of which can support real‑time data sharing, reduce reconciliation costs, and enable multi‑party collaboration. Yet these benefits come with significant challenges — from security risks to governance issues — that organizations must fully understand before adopting blockchain‑based solutions.

The speaker explores how blockchain can support small and medium‑sized enterprises by facilitating supply‑chain tracking, automating transactions through smart contracts, and reducing cross‑border payment frictions. Real‑world examples include Italian fashion and food‑industry tracking systems, German pilots in decentralized energy commerce, and the growing use of blockchain for anti‑counterfeiting and provenance verification. The presentation also highlights public‑sector use cases: connecting fragmented government databases, streamlining bureaucratic processes, enhancing transparency in public procurement, and enabling secure digital identity infrastructures. European initiatives such as the European Blockchain Services Infrastructure (EBSI) and Estonia’s blockchain‑enabled registries demonstrate how the technology can support diploma verification, land registries, court systems, and other critical functions.

In its concluding analysis, the presentation underscores that blockchain adoption requires more than technical enthusiasm. It demands robust governance structures, clear compliance frameworks, careful integration with legacy systems, and a realistic assessment of costs, benefits, and regulatory constraints — particularly regarding GDPR and data immutability. The speaker offers practical guidance: identify concrete problems, run pilot projects, consider consortium models, and evaluate return on investment before scaling. Looking ahead, blockchain is expected to converge with AI and digital‑identity ecosystems, forming part of a broader cyber‑economic infrastructure. If implemented thoughtfully, it can become a shared, trusted foundation for both private enterprises and public administration — but only when governance, identity, and legal compatibility are treated as first‑class design principles, not afterthoughts.

The Data Protection Issues of Smart Contracts as Possible Tools for Automated Decision-Making

Dániel Eszteri

head of unit, Hungarian National Authority for Data Protection and Freedom of Information, Data Breach Notification and Forensic Analysis Unit

This presentation examines how smart contracts operate within blockchain systems and what happens when these automated mechanisms meet the EU’s data protection rules. It clarifies when smart contracts remain simple automation — and when they cross the threshold into GDPR regulated automated decision making — providing a clear guide to the legal risks at the intersection of blockchain, AI, and personal data processing.

Summary

In this talk, the speaker introduces the data protection implications of blockchain based smart contracts, framing the discussion within the General Data Protection Regulation (GDPR). After briefly revisiting how distributed ledger technologies function — decentralized networks, consensus based verification, immutable data structures — the presentation focuses on smart contracts as self executing programs deployed on blockchains such as Ethereum. These contracts typically operate through deterministic “if–then” logic, automatically triggering predefined actions based on data inputs and network conditions. The speaker contrasts deterministic smart contracts with non deterministic ones, which rely on external data sources supplied by “oracles.” Using examples ranging from smart city infrastructure to household utility metering, the presentation illustrates how blockchain based automation can streamline processes, coordinate services, and support data driven optimization.

Turning to GDPR, the speaker analyses how smart contract environments map onto existing data protection obligations. According to guidance from EU data protection authorities, blockchain node operators and smart contract designers are often considered data controllers or processors when personal data is involved — making them responsible for legal compliance. A central focus is Article 22 GDPR, which grants individuals the right not to be subject to decisions based solely on automated processing that significantly affect them. Most smart contracts, the speaker notes, do not reach this level of complexity: they automate predefined human decisions rather than making autonomous, data driven judgments. However, when smart contracts are combined with machine learning models — for instance, in adaptive energy management systems — they can become true automated decision systems, triggering Article 22 and the need for explainability, meaningful human oversight, and transparency.

The presentation concludes that smart contracts themselves are generally compatible with the GDPR when used as deterministic tools, but risks escalate sharply when AI driven decision making is embedded into blockchain environments. In such hybrid systems, data controllers must assess whether automated decision making is taking place, ensure transparency about system logic, provide human review mechanisms, and carefully manage the interplay between blockchain immutability and GDPR rights such as erasure. The speaker emphasizes that the legal analysis depends not on the technology alone, but on how it is designed, governed, and integrated — and highlights the importance of rigorous data protection assessment as blockchain and AI systems converge in increasingly complex applications.

Digitalisation and the deployment of AI, with a particular focus on the Digital Justice 2030 strategy

László Ormai

Policy Officer, European Commission, DG Just, Digital transition and judicial training Unit

This presentation introduces the EU’s Digital Justice Strategy 2030, outlining how the Union plans to accelerate the digitalization of national justice systems through shared tools, AI integration, interoperable platforms, and cross border cooperation. It highlights the practical steps the Commission and Member States will take to make justice systems more efficient, transparent, and resilient — while ensuring that technology supports, rather than replaces, human decision making.

Summary

In this talk, the speaker presents the EU’s Digital Justice Strategy 2030 — part of the broader Digital Justice Package — which aims to modernize judicial systems across the Union through digital transformation and responsible use of AI. The strategy’s overarching goal is to enhance efficiency, transparency, accessibility, and resilience while safeguarding the rule of law and fundamental rights. Building on the 2023 Digitalisation Regulation, the Commission and Member States identified significant fragmentation: courts often lack visibility into one another’s digital tools, and there is no central resource tracking which IT or AI applications are used in judicial proceedings. To address this, the strategy introduces two major initiatives: a mapping exercise to gather best practices and national projects, and a “living repository” on the e Justice Portal where Member States can share and access justice related IT and AI tools.

The presentation then outlines the second major pillar: the IT Toolbox, an open source focused platform hosted on the Interoperable Europe Portal. Unlike the living repository, which may include proprietary tools and be access restricted to courts and legal professionals, the IT Toolbox will be openly accessible and support reuse of open source judicial solutions. The third workstream concerns the use of AI in justice, where the Commission emphasizes that AI must support — not replace — judges and court staff. Examples include Brazil’s automated preliminary appeals screening and Slovenia’s AI assisted transcription services, contrasted with U.S. cases where unsupervised AI drafting led to orders containing fictitious legal references. To prevent such risks, the Commission plans new guidelines on when and how AI may be responsibly used in courts, accompanied by structured dialogue with Member States and stakeholders.

Finally, the speaker discusses the strategy’s fourth workstream: video conferencing interoperability for cross border proceedings. Current tools such as Teams, Zoom, and Webex cannot interconnect, making remote hearings impossible when parties are in different Member States. In response, the Commission aims to establish common technical requirements and explore the development of an EU sovereign video conferencing solution. The presentation closes by noting that Member States oppose new legislation in this field, stressing that the priority must be implementing existing legal frameworks — and that the Digital Justice Strategy focuses on practical, administrative actions rather than new regulatory burdens.

TUTELA: CONSUMERS AND LAW

Implementation of the Consumer Credit Directive in Italy

Elena Bargelli

professor, University of Pisa

This presentation examines how Italy has implemented the EU’s new Consumer Credit Directive (CCD3), highlighting the widening gap between harmonized EU level duties and the limited remedies available to consumers under national law. It explores why information duties and creditworthiness assessments matter more than ever — and how Italy’s choice to rely on public enforcement leaves critical private law questions unresolved.

Summary

In this talk, the speaker analyzes Italy’s implementation of the EU Consumer Credit Directive (Directive (EU) 2023/2225), focusing on the extent to which the Italian legislature used the discretion granted by the directive to define remedies and penalties for non compliance. The implementation was carried out through Legislative Decree No. 212/2025, amending the Italian Banking Act. Because the directive follows a full harmonization model, Italy largely transposed its provisions verbatim. Yet, as the presentation stresses, member states still retain discretion in two crucial areas: remedies for contractual infringements and administrative penalties. These are essential in practice, as the directive increases information obligations at every stage of the credit relationship — from advertising to pre contractual disclosures to the newly introduced duty to provide adequate explanations.

The presentation highlights that while CCD3 specifies consequences for failing to provide contractual terms (most notably the postponement of the withdrawal period), it remains silent on the effects of other information failures. Italy did not fill this gap. The Banking Act continues to require consumers to repay capital and accrued interest upon withdrawal, without clarifying whether interest should still apply when the creditor fails to provide mandatory information. The speaker notes that EU case law suggests member states could adopt consumer friendly solutions, such as denying interest when key information was missing, but Italy did not seize this opportunity.

A similar gap appears in the area of creditworthiness assessments, which the new directive treats as a central pillar of responsible lending. CCD3 obliges creditors to carry out a serious and documented assessment and, in cases involving automated processing, to provide consumers with human intervention, explanations, and review rights. Yet the directive does not specify what happens when these obligations are breached. Italy once again opted not to legislate on private law remedies. Instead, the Banking Act now provides for enhanced administrative penalties issued by the Bank of Italy, but no new contractual remedies were introduced. As a result, consumers remain reliant on general damages claims — a burdensome and often ineffective route requiring them to prove not only the breach but also the loss suffered. The presentation concludes that Italy’s implementation favors public enforcement over private enforcement, leaving unresolved key issues regarding the effectiveness of consumer protection in cases of inadequate information or creditworthiness assessments.

Balancing Efficiency and Consumer Protection: The Payment Order Procedure and the Impact of CJEU Case Law

Piia Kalamees

associate professor, University of Tartu, Faculty of Social Sciences, School of Law

This presentation explores how far efficiency driven payment order procedures can go without undermining EU mandated consumer protection. By examining recent CJEU case law, it shows where automated or streamlined systems must pause to ensure fairness — and why even highly efficient national procedures must remain embedded in a framework that genuinely allows consumers to defend their rights.

Summary

In this talk, the speaker analyzes the structural tension between the efficiency oriented design of payment order procedures and the European Court of Justice’s (CJEU) requirements for effective consumer protection. Payment order systems, widely used in mass consumer debt litigation, rely on speed, automation, and minimal judicial involvement: creditors submit simplified applications, courts conduct a largely formal review, and unless the consumer objects, an enforceable order is issued without any substantive merits assessment. While these features make the system attractive for professional creditors, the presentation highlights that they also create a systemic risk: unfair contract terms and failures in creditworthiness assessment may never be reviewed if consumers remain passive — a common scenario given informational and procedural asymmetries.

Drawing on the CJEU’s well developed case law, the speaker explains that EU consumer protection rules require ex officio review of unfair terms whenever the court has the necessary factual and legal material, even in default judgments or payment order procedures. Where the consumer has a genuine, accessible opportunity to object, the Court accepts that full judicial scrutiny may occur only after an objection. But if the design of the procedure makes objections unrealistic — due to short deadlines, fees, complexity, or evidentiary demands — efficiency no longer justifies limiting judicial involvement, and courts must intervene of their own motion. Recent rulings, including those involving the Finanmadrid, Profibanka and Bondora lines of cases, also show that when judges develop serious doubts about fairness, they must be able to request underlying contracts or additional information, even if the consumer has not objected. This reinforces that efficiency cannot override the duty to protect consumers from unfair terms.

The presentation concludes by characterizing the CJEU’s approach as a model of “conditional efficiency.” Payment order procedures may remain streamlined and partially automated, and may even be handled initially by court officials rather than judges, provided that the overall system preserves a realistic path to full judicial scrutiny. Finality (res judicata) remains the rule when consumers had a meaningful chance to object; reopening is required only when unfair terms were never reviewable at any stage. In essence, expedited procedures are permissible — even desirable — but only when embedded within a broader procedural framework capable of delivering effective consumer protection, both in theory and in practice.

Scored by Design: AI-Driven Social Scoring in Consumer Law Contexts

Martin Hamřik

assistant professor, Civil Law Department Law Faculty, Univerzita Komenského v Bratislave

This presentation unpacks the AI Act’s prohibition of social scoring and asks a crucial question: is AI‑based scoring of consumers in B2C relationships actually forbidden? By breaking down the legal test hidden inside Article 5 and exploring where legitimate scoring ends and prohibited profiling begins, the talk shows why social scoring is one of the most sensitive — and least understood — areas of AI regulation.

Summary

In this talk, the speaker examines the concept of AI‑driven social scoring through the lens of Article 5 of the EU AI Act, which lists prohibited AI practices. Beginning with the broader cultural backdrop — including longstanding dystopian fears of surveillance and behavioural control — the presentation explains why the EU chose to explicitly ban certain forms of social scoring. While early debates drew comparisons to China’s alleged social credit system, the speaker notes that the EU’s prohibition is ultimately forward‑looking: it responds to the technological reality that AI systems can integrate vast amounts of behavioural and inferred data to generate highly influential evaluations of individuals. The central research question is whether, and to what extent, social scoring is prohibited specifically in B2C contexts.

The speaker reconstructs Article 5 into a four‑part legal test: (1) an AI system must be deployed; (2) it must evaluate a natural person’s social behaviour or personal characteristics; (3) this evaluation must rely on multiple data sources over a period of time; and (4) the resulting score must produce harmful or unjustified treatment of the consumer. Only when all these elements are present does the AI Act’s prohibition apply. The presentation carefully distinguishes between unlawful social scoring and legitimate forms of evaluation such as creditworthiness assessments, insurance risk calculations, fraud prevention, or platform safety mechanisms — all of which require some form of scoring and are expressly permitted or required by sector‑specific legislation. The talk further highlights the Act’s two “trigger points”: scoring must not be used outside the context in which the underlying data was generated, and the consequences imposed on the individual must not be disproportionate to the underlying behaviour.

The final part of the presentation explores “positive social scoring,” such as rewarding environmentally conscious consumers or providing loyalty‑based discounts. While the AI Act does not prohibit such practices outright, the speaker points out that they may still clash with other legal frameworks — including the Unfair Commercial Practices Directive (UCPD), anti‑discrimination rules, and the GDPR. The talk concludes that AI‑driven social scoring in B2C settings is not categorically banned, but its legality depends on context, purpose, proportionality, and consistency with other areas of EU law. Businesses must therefore proceed cautiously: compliance with Article 5 does not guarantee compliance with broader consumer‑protection or data‑protection obligations.

Back to the future – how would Roman law respond to the technological legal challenges of today's car manufacturing?

Péter Báldy

vice director of Institute for Postgraduate Legal Studies, ELTE Law

Open lecture, aims to share the main themes of our conference with a wider audience beyond the academic community, within the framework of our project supported by the Ministry of Culture and Innovation of Hungary through the National Research, Development and Innovation Fund under the Scientific Mecenatúra Funding Scheme.

This presentation reflects on whether today’s legal challenges posed by AI, digital platforms, and complex technological ecosystems can be understood — or even partially answered — through the lens of Roman law. By mixing historical insight with contemporary regulatory debates, it invites the audience to reconsider what is genuinely “new” about modern technology and what remains, at its core, a timeless legal question of responsibility, fairness, and human judgment.

Summary

In this thought provoking concluding lecture, the speaker challenges the audience to reconsider the relationship between technology and law, asking whether ancient legal concepts — particularly those of Roman law — can illuminate today’s dilemmas surrounding AI, automation, and digital complexity. Rather than proposing a “law of technology,” the talk emphasizes the importance of technological neutrality in legal thinking, echoing the GDPR’s approach. The speaker draws from Frank Easterbrook’s famous “Law of the Horse” critique to argue that lawyers should focus less on regulating technology itself and more on regulating human behaviour, duties, and relationships shaped by technology. Today’s regulatory environment, from the Cyber Resilience Act to platform governance rules, struggles not because technology is unprecedented, but because legal relationships have grown vastly more complex, with multilayered dependencies among manufacturers, suppliers, platforms, and automated systems.

By taking the audience on an intellectual time travel, the presentation highlights how many cornerstones of modern legal doctrine — contractual and delictual liability, duties of care, personality rights, dignity, and even the essence of consent — were already present in Roman private law. The truly disruptive element of contemporary AI is not the existence of autonomy or delegation, but the shift from deterministic software (where identical inputs reliably produce identical outputs) to non deterministic systems capable of unexpected, untraceable behaviour. This unpredictability complicates classical liability models, raising the question of who the modern equivalent of the Roman dominus (master) should be when the “actor” is an AI system. The speaker argues that the fundamental legal question is not what AI is, but whom the law should protect — consumers, vulnerable groups, children, businesses, or innovation itself — and therefore where responsibility and accountability should be placed.

The lecture concludes by examining prohibited AI practices such as subliminal manipulation, questioning whether the law should ban a technology or simply prohibit unfair behaviour regardless of the tool used. The speaker suggests that law’s strength has always been its flexibility and moral grounding, not its ability to pre write technical recipes for future problems. Instead of chasing every new technological form, the law should reaffirm its core principles — fairness, dignity, transparency, and accountability — and allow courts and regulators to adapt them case by case. In a world of “zombified” consumers and persuasive digital environments, the final message is clear: technology does not replace the need for judgment. The law must continue to evolve, but its foundations remain remarkably resilient — and surprisingly familiar, even two thousand years later.

Project no. MEC_SZ 149575 has been implemented with the support provided by the Ministry of Culture and Innovation of Hungary from the National Research, Development and Innovation Fund, financed under the MEC_24 „Tudományos Mecenatúra Pályázat” funding scheme.