Whistleblower protection in 2026: violations of the EU AI Act

The statutory scope of reporting has expanded. Whistleblowing systems should therefore be prepared for possible violations involving the use of artificial intelligence.

What has been added

Section 2(1), no. 10 HinSchG now expressly covers violations of the European AI Act, Regulation (EU) 2024/1689. This extension was introduced by legislation dated July 22, 2026. Whistleblower protection is therefore not limited to traditional corruption or fraud cases.

Inclusion in the HinSchG does not, however, determine whether a particular use of AI is unlawful. It remains necessary to identify the specific obligation and whether it applies at the relevant time. An unexpected or incorrect AI result alone does not establish a legal violation.

What this means for reports

Specific details help: which system is being used? In which workflow? What events have you observed? Why does the use appear problematic? You do not need to prepare a complete technical or legal analysis before making initial contact.

Do not include personal data, confidential documents, or login credentials in a report simply as a precaution. Start by describing the context and agree on arrangements for sending documents with the responsible office.

What organizations should review now

Check whether the description of your whistleblowing system, the allocation of responsibilities, and the training of those handling reports cover the current statutory scope. Where an external ombudsperson is involved, the engagement must also reflect that scope. A technical assessment may additionally be needed; the reporting office should have a clear route to appropriate expertise.