(de-news.net) – Germany is moving to strengthen its legal response to digital violence, with new rules targeting sexualized deepfakes, digital voyeurism, rape videos, identity abuse and cyberstalking. At the same time, child-rights organizations are warning that artificial intelligence is increasingly embedded in young people’s lives while safeguards remain inadequate. German businesses face similar challenges: although AI adoption is growing, only a small share of companies has dedicated procedures for AI-related security incidents, while AI-assisted cyberattacks are already being reported.
The German Cabinet on Wednesday approved a Justice Ministry bill designed to close legal gaps surrounding digital violence, advancing a package of criminal and civil-law changes that would expand protections against several forms of technology-enabled abuse. The proposed rules would address image-based sexual abuse, including the production or dissemination of sexualized deepfakes, digital voyeurism and videos depicting rape. Adult victims of sexualized cyberviolence are predominantly women. The legislation would also establish new offenses covering the creation of sexualized deepfakes, certain deepfakes intended to damage a person’s reputation, identity theft through fake online profiles and cyberstalking using technologies such as GPS trackers. At the same time, victims would receive additional means of identifying alleged offenders through a new information procedure, while online platforms and messaging services would assume greater responsibilities in supporting investigations.
The measures reflect a broader effort to adapt existing criminal law to forms of abuse made possible or easier by digital technologies. Justice Minister Stefanie Hubig (SPD) described digital violence as a rapidly expanding phenomenon that disproportionately affects women. She said the proposed legislation represented an important change in how such offenses are addressed and argued that authorities needed to pursue the different forms of digital violence consistently.
One of the proposed changes to the penal code would prohibit the possession, production and dissemination of videos depicting rape. Private possession is not currently subject to a general prohibition, while the distribution of such material is not automatically criminal in every circumstance. The bill would also prohibit the production of so-called sexualized deepfakes — AI-generated images or videos designed to create the appearance that a particular person is nude or engaged in sexual activity.
The Cabinet’s approval moves the legislation to the Bundestag, where lawmakers will consider the proposed changes. The measure therefore combines changes to criminal law with provisions intended to make it easier for victims to pursue those responsible for digital abuse.
Child protection faces new AI challenges
The debate over digital risks extends beyond criminal law. Child-rights organizations Terre des Hommes and SOS Children’s Villages Worldwide have warned that artificial intelligence offers potential benefits for children and adolescents but also creates significant risks. A joint study by the organizations described AI as already deeply embedded in young people’s everyday lives, including through education, social media, search engines, entertainment and creative applications, often without users consciously recognizing the technology involved.
That growing presence makes the distinction between the opportunities and risks of AI less straightforward, according to the study. The same characteristics that can improve personalization, creativity and accessibility can also increase exposure to misinformation, bias, dependency and commercial exploitation. Experts assessed both children’s exposure to AI and the potential for harm as high, while technical, institutional and regulatory safeguards were considered insufficient.
The organizations argued that protecting children therefore requires more than simply reducing their exposure to potential harms. Young people also need the skills to navigate digital environments critically, safely and confidently. Terre des Hommes called for mandatory safety-by-design standards, effective age verification and systematic participation by children in the development of AI regulation. The groups also pointed to deepfakes, manipulative algorithms and emotional dependency as particular areas of concern. Their position is that safeguards need to be incorporated into AI systems from the outset rather than treated solely as measures to be introduced after problems emerge.
Companies remain poorly prepared for AI-related security incidents
Similar concerns are emerging in the business sector, where German companies are only beginning to establish dedicated procedures for security incidents involving artificial intelligence. A Forsa survey commissioned by the TÜV Association and the Federal Office for Information Security (BSI) found that only 11 percent of the 505 companies surveyed in July had specific procedures for AI-related security incidents.
Another 43 percent said they relied on general IT-security procedures without AI-specific provisions, while 20 percent were developing dedicated processes. One-quarter of the companies reported having no corresponding arrangements. The findings indicate that, despite the growing use of AI, dedicated organizational responses to AI-related security incidents remain limited.
AI adoption itself was considerably more widespread. Forty-nine percent of the companies surveyed said they were already using AI, while another 9 percent planned to introduce it within the following year. Among businesses that were not using AI, 53 percent cited concerns about data protection or security as a reason. For companies already using the technology, generating text, images or code was by far the most common application, reported by 96 percent. Some 31 percent used AI to improve IT security, while 25 percent applied it to automate processes, including customer-service chatbots and invoicing.
BSI Vice President Thomas Caspers said AI should not be viewed merely as another digital tool because it was producing significant operational and strategic changes. He also argued that German businesses had not yet fully exploited its potential. In his view, reducing dependence on Chinese and U.S. AI companies would require Europe to identify the applications that are genuinely important to its interests and develop European models capable of competing with providers in the United States and China.
The security implications are already becoming visible. Seventeen percent of the businesses surveyed reported having experienced attacks involving AI. The actual number could be higher, because determining whether artificial intelligence was used during a cyberattack is not always straightforward.
Dirk Stenkamp, president of the TÜV Association, also pointed to uncertainty over liability when AI causes damage. Questions remain over whether responsibility lies with the AI provider, the company using the technology or another party. Because many businesses cannot build the level of expertise required to assess the security of AI models independently, he argued that regulatory requirements could provide at least a basic level of protection.
AI-enabled attacks extend beyond AI users
The survey also highlights a second dimension of the emerging security challenge: companies do not need to use artificial intelligence themselves to become targets of AI-assisted cybercrime. German businesses remain particularly exposed to attacks in which AI is used to make fraudulent communications more convincing. According to the survey, nine out of 10 attacks involved highly convincing phishing emails designed to obtain login credentials, financial information or other sensitive data. Eleven percent of companies also reported attempted fraud involving deepfakes, including manipulated audio or video.
The documented incidents may represent only part of the problem, according to the TÜV Association, because the use of AI during an attack can be difficult to identify. That uncertainty also complicates efforts to assess the scale of the threat. The findings therefore place AI-related security risks on both sides of the technology divide. Companies that use AI face the challenge of securing their own applications and determining responsibility when systems cause harm, while companies that do not use AI can still be exposed to increasingly sophisticated attacks generated or enhanced by the technology.