The relevance of this study is driven by the necessity to transform modern civil law doctrine toward a post-non-classical stage. Civil law constantly faces challenges from newly emerging relationships. The new decentralized internet, Web3, has shifted the paradigm for perceiving the elements of civil legal relations; as this article demonstrates, a new legal object exists on the blockchain, even though current civil norms state otherwise. In this regard, decentralized autonomous organizations are not merely a technological phenomenon but also a challenge to existing civil law theories and an instrument for protecting human rights amid the identity crisis of the information society and "surveillance capitalism". The purpose of this work is to substantiate a paradigm shift in research on decentralized autonomous organizations and to analyze their legal status by deconstructing the values they defend: privacy, dignity, and autonomy. The methodology is based on the axiological and historical approaches to Roman law and Kantian ethics to comprehend the depth of privacy problems and the relevance of these decentralized entities, alongside the synergetic method, which views a decentralized autonomous organization as a dissipative structure. The results demonstrate that such an organization is an autopoietic system where the protocol acts as a slaving principle (teleonomy of the code), while in bifurcation points preserving teleology of the community. It is argued that applying general corporate laws is dogmatically flawed due to the absence of affectio societatis (mutual trust) and undermines the very causa finalis of these decentralized systems – advocating for a decentralized internet and a shift of power to users, rather than creating just another form of a limited liability company. Prospects for further research include the proposal to treat these decentralized organizations as a sui generis construct. It is concluded that regulators should create "strange attractors" by applying the legal construct of Zweckvermögen (purpose-bound patrimony) to smart contracts, allowing these structures to participate in offline legal relationships without destroying their unique nature.
The relevance of this study is driven by the necessity to transform modern civil law doctrine toward a post-non-classical stage. Civil law constantly faces challenges from newly emerging relationships. The new decentralized internet, Web3, has shifted the paradigm for perceiving the elements of civil legal relations; as this article demonstrates, a new legal object exists on the blockchain, even though current civil norms state otherwise. In this regard, decentralized autonomous organizations are not merely a technological phenomenon but also a challenge to existing civil law theories and an instrument for protecting human rights amid the identity crisis of the information society and "surveillance capitalism". The purpose of this work is to substantiate a paradigm shift in research on decentralized autonomous organizations and to analyze their legal status by deconstructing the values they defend: privacy, dignity, and autonomy. The methodology is based on the axiological and historical approaches to Roman law and Kantian ethics to comprehend the depth of privacy problems and the relevance of these decentralized entities, alongside the synergetic method, which views a decentralized autonomous organization as a dissipative structure. The results demonstrate that such an organization is an autopoietic system where the protocol acts as a slaving principle (teleonomy of the code), while in bifurcation points preserving teleology of the community. It is argued that applying general corporate laws is dogmatically flawed due to the absence of affectio societatis (mutual trust) and undermines the very causa finalis of these decentralized systems – advocating for a decentralized internet and a shift of power to users, rather than creating just another form of a limited liability company. Prospects for further research include the proposal to treat these decentralized organizations as a sui generis construct. It is concluded that regulators should create "strange attractors" by applying the legal construct of Zweckvermögen (purpose-bound patrimony) to smart contracts, allowing these structures to participate in offline legal relationships without destroying their unique nature.
This paper presents the first formally documented implementation of post-quantum cryptographic infrastructure within a production-grade institutional compliance enforcement system. It addresses a structural vulnerability endemic to the entire regulatory technology industry: every compliance record generated today under RSA or ECC encryption is potentially exposed to "Harvest Now, Decrypt Later" (HNDL) attacks — a documented, operationally active collection strategy confirmed by NSA, CISA, ENISA, and BSI — and will remain so until quantum computers capable of running Shor's algorithm at scale become available, currently projected between 2030 and 2035. Given mandatory regulatory retention periods of 5–30 years under DORA Art.10, GDPR Art.5(e), FinCEN BSA 31 CFR §103.33, Swiss OR Art.958f, and Solvency II, compliance records created today under classical cryptography will still exist — and may be decryptable — within their own legally mandated retention window. This paper documents the complete architectural response: the deployment of CRYSTALS-Kyber-1024 (NIST FIPS 203, 2024) as the primary cryptographic primitive for all compliance ledger operations in the immo.quick Core Machine Law Engine, combined with: A hybrid encryption architecture providing quantum security with full backward compatibility A Merkle Tree Batching scheme reducing post-quantum storage overhead by 99.99% (from 4.67 PB/year to 0.35 TB/year at Tier-1 clearing volumes) A multi-region HSM key hierarchy (EU/CH/US/UK) with Shamir Secret Sharing (3-of-5) and zero-downtime rotation A Zero-Knowledge Proof integration (Groth16, PLONK, Cairo zk-STARK) that resolves the structural contradiction between GDPR Art.17 erasure rights and immutable ledger requirements — by placing zero personal data on the ledger A crypto-agility policy engine enabling algorithm migration without application code changes or audit trail disruption Complete regulatory compliance mappings to DORA, GDPR, BSI TR-02102-1, and NIST FIPS 203 The immo.quick Core platform is presented as the first operational implementation of this architecture across fourteen regulatory frameworks and five institutional sectors (Real Estate, Banking, Insurance, Government, Cloud/FinTech). This paper is a standalone technical specification and supplements the immo.quick Core architecture series (DOI: 10.5281/zenodo.19301212 through 10.5281/zenodo.19457223). It provides the first focused, formally structured academic documentation of CRYSTALS-Kyber-1024 deployment within a deterministic gate enforcement environment with hardware TEE attestation and bi-temporal legal state management. The central argument: Post-Quantum cryptography is not a feature request for 2030. It is a structural prerequisite for any compliance system intended to produce legally defensible evidence chains beyond the quantum threat horizon. The architecture to achieve this exists, is formally specified, and is operationally deployed.
About this paper This paper argues that the conflict between online protection and privacy is not inevitable. The real problem is that most current systems wrongly treat compliance and identity as the same thing. The proposed VI + CJT framework separates them. It allows platforms to receive only the minimum lawful compliance result they need — for example, whether a user falls below the relevant legal age threshold — without learning the child’s name, date of birth, address, biometric profile, or broader identity. In that sense, the paper’s central theme is age verification without surveillance through purpose-bound cryptographic enforcement. How AI Makes the Problem Worse AI makes the children’s online safety problem more serious in three distinct ways. First, it changes exposure from passive to active. Harmful material is no longer merely available on a platform; recommendation and optimisation systems can identify vulnerable users, rank harmful content more aggressively for them, and progressively amplify it based on engagement signals. In that environment, a child is not simply finding harmful content — the system is learning from the child and serving more of it. Second, AI makes weak age-verification methods more dangerous. A false self-declared age is no longer just a wrong entry in a sign-up form. Once accepted, it becomes operational input for recommendation, advertising, and behavioural optimisation systems, which then treat the child as an adult user profile. This means the error is not static; it is continuously acted upon by AI systems that optimise for attention and engagement rather than child protection. Third, AI encourages platforms to solve the problem through more surveillance. In practice, this often means AI-based age estimation using faces, voices, or behavioural patterns. But this approach creates a new harm while claiming to solve another one: it turns child protection into biometric and behavioural monitoring, and can generate datasets that may later be reused for additional profiling or model training. In other words, AI can make age assurance both more intrusive and less accountable. A further difficulty is that AI systems are often opaque even to their operators. As your draft correctly notes, policy rules alone may not be enough, because platforms may not reliably know how their own recommendation systems are treating minors in practice. This is why the problem is not only one of age verification, but also one of enforceable control over AI behaviour. That is precisely why the VI + CJT model matters. It does not ask AI systems to infer age or interpret law for themselves. Instead, it provides a minimal, authoritative compliance signal and machine-readable constraints that can limit recommendation, advertising, and profiling behaviour toward minors without exposing identity. Current Solutions Self-declaration is easily bypassed. A child can simply enter a false age, and the platform’s AI systems then treat that false declaration as valid input for recommendation, targeting, and optimisation. Identity-linked verification creates major privacy risks. When age assurance depends on sharing civil identity information with commercial platforms, the result is unnecessary exposure of family and child data to entities with strong incentives to collect, retain, and monetise it. AI-based age estimation introduces biometric surveillance. Estimating age from face, voice, or behaviour may appear convenient, but it creates new harms by collecting sensitive personal and biometric data as a side effect of child protection. Current systems collapse compliance into identity. What platforms usually need is not the full identity of the user, but only the legally relevant compliance fact. Existing approaches fail because they demand far more data than is necessary for that purpose. Policy rules alone are not enough in AI-driven environments. Even where legal obligations exist, platforms may not reliably translate them into enforceable constraints on opaque recommendation and engagement systems. As a result, compliance may remain declaratory rather than technically enforced. Proposed Solution Use VI + CJT as a purpose-bound cryptographic layer. The framework converts verified civil identity held by trusted authorities into a minimal compliance credential that reveals only the relevant age-threshold result for the applicable jurisdiction. Avoid disclosure of identity data. The credential contains no name, no full date of birth, no address, and no biometric data. Each credential uses a fresh random identifier, making it unlinkable across sessions. Keep the credential under user control. The credential is stored on the user’s device in secure hardware rather than on platform servers, reducing centralised exposure and retention risks. Use zero-knowledge proof for age compliance. When access is requested, the platform receives only a yes-or-no compliance result, without learning the underlying identity attributes or credential contents. Encode law into machine-readable CJTs. The Compliance Jurisdiction Token expresses the applicable legal rules, including jurisdiction-specific age thresholds and AI-related restrictions such as limits on engagement optimisation, advertising targeting, or behavioural profiling for minors. Constrain platform AI without making it identity-aware. Recommendation engines and other AI systems receive only the compliance signal necessary to adjust behaviour for minors, allowing them to become jurisdiction-aware and age-aware without becoming identity-aware. Replace probabilistic AI age estimation with authoritative attestation. Instead of guessing age through opaque models, the framework provides deterministic, government-signed, legally relevant compliance proof. Enable auditability and cross-border enforcement. Regulators can test whether platforms respond correctly to compliance signals, and the applicable child-protection rule can follow the user across borders through jurisdiction-bound credentials and tokens. Core Message The paper’s core message is simple: platforms do not need to know who a child is in order to know what protections the law requires. By separating compliance from identity, the VI + CJT model offers a path to child safety that is enforceable, privacy-preserving, and better suited to AI-driven digital environments.
Edge-Cloud-Systeme ermöglichen Anwendungen, die auf Basis von Daten intelligenter Objekte und Infrastrukturen wirtschaftliche Mehrwerte schaffen und gesellschaftliche Herausforderungen adressieren. Dies bedarf häufig eines Teilens von Daten mit Partnern in etablierten Wertschöpfungsnetzwerken oder entlang des Edge-Cloud-Kontinuums. Eine fundamentale Anforderung ist dabei die Sicherstellung des Schutzes sensibler betrieblicher und personenbezogener Informationen. Während die lokale Datenverarbeitung an der Edge ein grundlegendes Maß an Datenschutz und Informationssicherheit ermöglicht, reicht ein ausschließlicher Rückgriff auf diese Maßnahme oftmals nicht aus, um diese Anforderungen bei gleichzeitiger Erzielung der Mehrwerte datengetriebener Anwendungen zu erfüllen. Beispielsweise besteht häufig die Notwendigkeit, schützenswerte Daten an zentraler Stelle, beispielsweise der Cloud, zu aggregieren, um zu reichhaltigen Erkenntnissen zu gelangen oder die Integrität der verwendeten Daten sicherzustellen. An dieser Stelle rücken Privacy-Enhancing-Technologies (PET) in den Fokus, die Mechanismen umfassen, um Datenschutz, Informationssicherheit und Datensouveränität „by-Design“ in Systemarchitekturen zu integrieren. Bei PET handelt es sich um eine Klasse von individuellen Werkzeugen, die jeweils spezifische Informationssicherheitsanforderungen und -risiken in Edge-Cloud-Systemen adressieren können. Für Praktiker ergibt sich die Herausforderung, auf Basis der spezifischen Bedarfe ihrer Anwendungen und der verfügbaren PET-Werkzeuge passende PET-Strategien zu entwickeln, die eine Realisierung der Edge-Cloud-Anwendung unter Berücksichtigung der Anforderungen und Risiken für die Informationssicherheit ermöglichen. Diese Orientierungshilfe unterstützt Praktiker bei der Entwicklung eigener PET-Strategien für Edge-Cloud-Anwendungen. Sie bietet Hilfestellungen bei der Identifikation von Informationssicherheitsanforderungen und -risiken, der Auswahl passender PET-Werkzeuge und deren Integration in das Anwendungsdesign. Zentrales Element der Studie ist hierbei die Analyse von PET-Werkzeugen in Edge-Cloud-Anwendungskontexten. Die Orientierungshilfe zeigt, wie PET-Werkzeuge zur Umsetzung von Informationssicherheit beitragen können, welche Voraussetzungen für ihren Einsatz in spezifischen Szenarien geschaffen werden müssen und welche Implikationen sich aus dem Praxiseinsatz der PET-Werkzeuge ergeben. Dazu beruft sich die Orientierungshilfe auf die Erkenntnisse der Early-Adopter von Edge-Cloud-Systemen und PET aus den Projekten des Technologieprogramms „Edge Datenwirtschaft“ des Bundesministeriums für Forschung, Technologie und Raumfahrt (BMFTR). Die Inhalte dieser Orientierungshilfe adressieren insbesondere Systemarchitektinnen und -architekten und Datenschutzbeauftragte, die Datenverarbeitungsprozesse in Edge-Cloud-Systemen datenschutzkonform gestalten müssen. Ausgehend von der Darstellung möglicher Risiken wie physischen Angriffen und Cyberangriffen, unsicherer Datenhoheit, Insiderbedrohungen und Fehlkonfigurationen sowie Anforderungen wie Datenminimierung, Integrität, Zweckbindung und die Verhinderung von Datenabflüssen „by-Design“ in Edge-Cloud-Anwendungen analysiert diese Orientierungshilfe fünf konkrete PET-Werkzeuge in praxisnahen Anwendungsszenarien: § Hardware-Schlüssel für die sichere Authentifizierung ohne personenbezogene Daten in der Lebensmittelwirtschaft, § Federated-Learning für kollaboratives KI-Training ohne Rohdatenweitergabe in der industriellen Fertigung, § Compute-to-Data zur Ausführung von Analysen in der Umgebung des Dateneigentümers in der industriellen Fertigung, § Zero-Knowledge-Proofs für datenbasierte Nachweise ohne Offenlegung sensibler Daten in der Energiewirtschaft, § Trusted-Execution-Environments für vertrauliche Berechnungen in isolierten Hardware-Umgebungen in der Energiewirtschaft. Zudem präsentiert die Studie vier Handlungsfelder und zugehörige Handlungsempfehlungen für den erfolgreichen Einsatz von PET-Werkzeugen in Edge-Cloud-Anwendungen: 1) Aufbau vertrauenswürdiger Partnerökosysteme und Schaffung notwendiger Anreizmechanismen, 2) Schaffung betrieblicher Voraussetzungen für den PET-Einsatz inklusive Schulung und Akzeptanzförderung, 3) Sicherstellung technischer Validität und Integrationsfähigkeit der PET in den Anwendungskontext, 4) Gewährleistung regulatorischer Konformität der PET-gestützten Edge-Cloud-Anwendung. Im Zuge der steigenden Relevanz von Edge-Cloud-Systemen und dem Teilen von Daten zur Generierung von Datenwertschöpfung bei mindestens gleichbleibenden Anforderungen an Datenschutz und Informationssicherheit wird der Einsatz von PET zu einem entscheidenden Erfolgsfaktor. PET ermöglichen nicht nur die Einhaltung regulatorischer Vorgaben, sondern schaffen die Grundlage für vertrauensbasierte Kooperationen in komplexen Edge-Cloud-Ökosystemen. Unternehmen, die zukünftig gemeinsam datengetriebene Wertschöpfung betreiben wollen, sollten sich aktiv mit PET beschäftigen.
In the digital era, consumers increasingly encounter an illusion of ownership when purchasing copyrighted works such as video games, digital music albums, or e-books. Under dominant licensing models exacerbated by cloud computing and subscription services users acquire mere access rights rather than true property interests, rendering their acquisitions vulnerable to platform shutdowns, account terminations, or service discontinuations. This phenomenon marks the “vanishing ownership” of digital content, eroding the traditional balance struck by the First Sale Doctrine in U.S. copyright law and the Exhaustion Principle in EU law. This article examines the failure of these doctrines to adapt to digital distribution, as evidenced by landmark cases. It further explores emerging challenges and opportunities posed by cloud-based services and Non-Fungible Tokens (NFTs), which promise transferable digital ownership but raise unresolved questions about copyright exhaustion, resale rights, and potential disruptions to rightholders’ licensing revenues. Through comparative legal analysis and doctrinal critique, this study argues for reconstructing the First Sale Doctrine and digital exhaustion to restore consumer property rights. It proposes hybrid legislative and technological solutions, including limited exhaustion for permanently downloaded works, mandatory resale mechanisms, and blockchain-enabled forward-and-delete protocols.
Amy Thomas, Maria-Jose Schmidt-Kessen, Simon Karlin
This chapter explores the role of intellectual property (IP) in the commercialisation and regulation of sports and eSports, focussing on copyright, trade marks, and image rights. It outlines how these rights enable key stakeholders - such as sports organisers, players and fans - to assert control over various aspects of sporting content and performances. Though comparative analysis of legal frameworks in Germany, the EU, and the UK, the chapter highlights significant jurisdictional differences in the protection and interpretation of these rights, particularly in relation to the use of player likenesses and ownership of performance outputs. The chapter also investigates how new technologies, including generative artificial intelligence (AI) and Non-Fungible Token (NFTs), might complicate rights-based relationships in both fields. A central theme is the imbalance of rights and bargaining power among stakeholders, especially players, whose creative contributions are often excluded from IP protection. In doing so, the chapter raises normative questions and critical reflections on fairness, enforcement, and contractual practices in the regulation of sports and eSports content.
Alex Wong, Duncan McFarlane, Charlotte Ellarby, M.B. Lee · 5 authors
Twenty-five years ago, the specification of the Intelligent Product was established, envisaging real-time connectivity that not only enables products to gather accurate data about themselves but also allows them to assess and influence their own destiny. Early work by the Auto-ID project focused on creating a single, open-standard repository for storing and retrieving product information, laying a foundation for scalable connectivity. A decade later, the approach was revisited in light of low-cost RFID systems that promised a low-cost link between physical goods and networked information environments. Since then, advances in blockchain, Web3, and artificial intelligence have introduced unprecedented levels of resilience, consensus, and autonomy. By leveraging decentralised identity, blockchain-based product information and history, and intelligent AI-to-AI collaboration, this paper examines these developments and outlines a new specification for the Intelligent Product 3.0, illustrating how decentralised and AI-driven capabilities facilitate seamless interaction between physical AI and everyday products.
Smart Contracts sind ein Phänomen der Digitalisierung. Sie wurden insbesondere durch die zunehmende Popularität von Ethereum einem breiten Publikum bekannt. Die vorliegende Arbeit untersucht daher die vertragsrechtlichen Implikationen von Smart Contracts und on chain Transaktionen auf der Ethereum Blockchain. Ausgangspunkt ist die verbreitete Annahme, dass Smart Contracts auf der Blockchain rechtsgeschäftliche Vorgänge abbilden oder automatisieren sollen. Dem wird im Rahmen dieser Arbeit eine konträre These entgegengestellt: Smart Contracts sind nur eine spezielle Art von Software und stellen selbst keine Verträge dar. Auch die Interaktion mit ihnen (via on-chain Transaktionen) bildet einen rechtsgeschäftlich neutralen Vorgang.Technisch betrachtet handelt es sich bei Smart Contracts nämlich um schlichte Blockchain Programme, die von speziell ausgebildeten Programmierern entwickelt werden. Diese eignen sich schon konzeptionell nicht zur Modellierung von rechtsgeschäftlichen Vorgängen. Die unpräzise Terminologie der Initiatoren dieser Technologie führt zu zahlreichen Missverständnissen in der Rechtswissenschaft. Nach intensiver Betrachtung der dahinterstehenden Funktionalität und ihrer historischen Entwicklung erkennt man bereits, dass das Substantiv „Contract“ in diesem Zusammenhang genauso wenig Aufschluss über die zivilrechtliche Qualifikation wie das Adjektiv „Smart“ über die Qualität der Software gibt.Ziel dieser Arbeit ist es schließlich, einen Beitrag zur präzisen vertragsrechtlichen Einordnung der technischen Vorgänge auf der Ethereum Blockchain zu leisten. Dafür wird in einem ersten Schritt die Technologie grundlegend erklärt. Danach erfolgt neben einer historischen Analyse eine umfassende Systematisierung zum aktuellen Meinungsstand von Lehre und Rechtsprechung. Den Abschluss bildet eine intensive zivilrechtsdogmatische Analyse dieses neuen Phänomens.
In the case of Federated Learning (FL) there's a problem.Most existing systems require a central coordinator or permissioned ledgers, restricting the transparency of the data and leaving the prevention of Sybil attacks in a grey area.We have addressed these issues by using a permissionless Proof-of-Stake (PoS) blockchain to coordinate FL, and making it difficult for Sybil attacks to be carried out by putting model lists and updates directly onto the blockchain.Large amounts of data are instead stored offchain, using InterPlanetary File System (IPFS) which takes care of the problem of storage space.Our system has a training process that is split into rounds, with clients updating a shared model locally, sending out IPFS content identifiers to the network and a designated 'lister' pooling the updates and publishing the new global model.The idea is that the blockchain would be based on Proof of Stake with longest chain, highest stake finality, but our prototype mimics this with a tiny light-weight proof-of-stake mechanism.