The most-used AI tool in Bavarian law firms is not a legal platform. It is DeepL, at 70.7% of AI-using firms, one point ahead of ChatGPT at 69.2%; Microsoft Copilot trails at 21.7%, Gemini at 4.2% and Claude at 2.8% (Bayerischer AnwaltVerband survey, 558 participants, 88% from firms of one to ten). Only 37.9% of those firms use AI at all, and 42% use no cloud software and plan none. Anyone searching for legal AI tools in Germany should start from that picture rather than from a vendor’s customer logos.

The DACH market is not the US market with umlauts. Professional secrecy here is backed by criminal law in Germany (§ 203 StGB) and Switzerland (Art. 321 StGB) and by § 9 RAO and the bar’s own rules in Austria, the bar guidance turns on whether a provider could access mandate data rather than whether it does, and a sovereign lane now exists that has no American equivalent: on 25 March 2026 Noxtua moved into Deutsche Telekom’s AI Factory and named the US CLOUD Act as the reason, six days before Legora opened in Munich.

What German lawyers actually use: DeepL, ChatGPT, and 16% with a dedicated tool

Three surveys, one message. The Bavarian survey found 55% of firms using no cloud software today and 37% using EU-hosted cloud only. The legal-tech.de Umfrage 2025 (about 80 respondents, half of them Einzelanwälte) found only 16% using a dedicated AI tool in the Kanzlei while over half use ChatGPT frequently or sometimes, and 64% planning to invest in a tool within twelve months. Wolters Kluwer’s Future Ready Lawyer 2026 (810 lawyers in the US, China and nine European countries including Germany) puts overall use at 92%, with ethics and data privacy (39%) and inadequate training (39%) as the top barriers.

The uncomfortable reading: the profession adopted AI through the tools it could not be stopped from using, a translator and a consumer chatbot, while the tools built for its secrecy rules sit at 16% penetration. That gap is the market every vendor below is chasing.

The sovereignty stack: Noxtua, Beck-Noxtua, Telekom AI Factory, BSI C5

Noxtua, founded in Berlin in 2017 and formerly Xayn, is the one DACH company built around professional secrecy rather than adapted to it. In April 2025 it raised $92.2m (about EUR 81m) in a Series B led by the publisher C.H.BECK, with CMS and Dentons investing; the model is trained on Beck’s corpus of some 55 million documents (TechCrunch). CEO Leif-Nissen Lundbæk’s pitch: “you cannot just use an American AI model in a German legal context.”

Beck-Noxtua is the product most German lawyers will meet: Noxtua’s model over beck-online’s content. The certification stack is the point: BSI C5, TISAX and ISO 42001, 27001, 27017, 27018 and 9001, with § 203 StGB and § 43e BRAO addressed at the architecture level, according to JuriScout’s comparison.

For Austria, MANZ has distributed Noxtua since June 2026, as reported by anwaltguru.at. The price, per a competitor’s comparison, is EUR 1,050 a month for three licences; Noxtua itself does not publish it.

Legora in Munich: 80+ DACH clients

Legora is Stockholm-born, so EU residency is a default rather than an option, and its Munich office, announced on 31 March 2026, is the most concrete DACH commitment any international platform has made. It reports more than 80 DACH firms and legal teams, naming Linklaters, White & Case, Erste Bank, Dentons, Schönherr, CMS and GÖRG. Max Junestrand: “Munich was a deliberate choice. It places us close to our customers and gives us access to exceptional talent across both disciplines that define our business – engineering and law” (Legora).

What Legora sells is Tabular Review (documents as rows, questions as columns, every cell linked to source), Word and Outlook add-ins and an agentic layer, with ISO 42001, SOC 2 Type 2, bring-your-own-key encryption and EU residency. What it does not sell is a German legal corpus: its grounding is your documents, not beck-online or juris, so the RIS or juris check stays with you. The head-to-head with Harvey and the incumbents is in Harvey vs Legora vs CoCounsel vs Protégé.

Harvey’s EU region and the § 203 question

Harvey has an EU region in Frankfurt, states it never trains on customer data and “requires Zero Data Retention (ZDR) by model providers”, and carries SOC 2 Type II and ISO 27001, 27701 and 42001. Its DACH footprint is real: Hengeler Mueller is a named customer, CMS announced an enterprise roll-out across 50 countries, and GSK Stockmann built a diligence workflow it says saves up to 75% of time on unstructured data rooms.

The open question is not security but Berufsrecht. JuriScout, a German comparison site, assesses Harvey as “not positioned as §203-compliant at architecture level”. That is a third-party view, and Harvey may well sign the § 43e BRAO agreement a German firm needs; but it is the right question, because the BRAK’s test is not whether a provider reads your data but whether it could. Reported pricing is $1,200-$2,000 per seat per month with a 20-seat minimum (JuriScout), which is why the German firms on Harvey’s customer lists are the large ones.

Libra, juris, Lulius, JUPUS and the rest of the market

Germany has roughly 300 legal-tech companies, and legal-tech.de’s roundup of AI tools for Kanzleien runs from Beck-Noxtua and juris KI-Suite to RA-MICRO’s JURA KI Assistent. Four are worth placing:

  • Libra by Wolters Kluwer, built on Wolters Kluwer and Otto Schmidt content, completed a multi-country European rollout; a competitor’s comparison puts it at about EUR 200 a month and cites “12,000+ jurists and 800+ law firms”.
  • juris KI-Suite is the AI layer on juris, the other half of the beck-online duopoly; if your Rechtsprechung lives in juris, this is where the citator check happens.
  • Lulius sells at EUR 99 a month and states the rule this page turns on: “Allgemein-LLM für Sprache, spezialisierte Legal AI für Recht.”
  • JUPUS at EUR 59 per user and, in Austria, AI:ssociate from EUR 39 per user per month with an ÖRAK cooperation, automated pseudonymisation before transfer and EU servers, as marketed.

The incumbents are moving in from outside: RELX agreed on 28 April 2026 to buy Doctrine of Paris, which holds a stake in dejure.org, and Thomson Reuters added German research to CoCounsel Legal in June 2026. The wider map of every tool’s layer is in the legal AI tools map.

The hundredfold price spread

Tool Reported or published price Source
AI:ssociate (Austria) From EUR 39 per user per month Vendor, via anwaltguru.at
JUPUS EUR 59 per user Lulius comparison (competitor)
Lulius EUR 99 per month Lulius (own price)
Libra by Wolters Kluwer About EUR 200 per month Lulius comparison (competitor)
Beck-Noxtua EUR 1,050 per month for three licences Lulius comparison (competitor)
Legora About $3,000 per user per year, 10-seat minimum JuriScout (comparison site)
Harvey $1,200-$2,000 per seat per month, 20-seat minimum; about $14,400 per user per year JuriScout; Lulius

Most of these numbers come from a competitor’s comparison page and none of the platforms publishes a price, but the shape is not in doubt. What you buy at the top is a legal corpus, review tables, a certification stack and a vendor to hold accountable; at the bottom, a frontier model with a German interface and, in the better cases, pseudonymisation before transfer. Who publishes what is in what legal AI really costs.

Do small European models understand German law? LEXam and BenGER

The sovereign pitch has a weak point, and a Swiss benchmark measures it. LEXam, built by ETH Zurich, the University of Zurich and partners including the Swiss Federal Supreme Court, holds 7,537 questions from 340 law exams in English and German (LEXam leaderboard).

Model LEXam open-question score
GPT-5 70.2
Gemini 2.5 Pro 67.4
Claude 3.7 Sonnet 62.9
GPT-4o 56.9
Llama 4 Maverick 47.3
Apertus-70B (Swiss) 34.7
EuroLLM-9B 23.0
Ministral-8B 14.9

Two lessons. “Reasoning models consistently outperform”, in the authors’ words. And the small European open models a “fully sovereign” on-premise stack might run score less than half of GPT-5. A sovereign stack on a small model is a confidentiality gain and a competence loss, unless, as with Beck-Noxtua, a legal corpus supplies what the model lacks.

The good news is BenGER, a German-law benchmark of 596 Gutachtenstil tasks and 531 doctrinal tasks: “human-AI co-creation measurably improves on unaided human work”. Martin Lorentz, a Fachanwalt für Arbeitsrecht in a five-lawyer firm, told the Anwaltsblatt after an appeal brief: “Meine Zeitersparnis lag bei mindestens 50 Prozent.” How to read any of these numbers is in legal AI benchmarks explained.

Normenrecherche und Obersatz, ohne Mandatsbezug
Rolle: Volljurist mit Schwerpunkt [Rechtsgebiet], deutsches Recht, Stand [Datum]. Sachverhalt (vollständig anonymisiert und abstrahiert): [Sachverhalt].
Aufgabe 1: Nenne die einschlägigen Normen als nummerierte Liste; je Norm § mit Gesetz, Wortlaut-Kern (max. zwei Zeilen, wörtlich) und Relevanz. Markiere jede Norm mit [PRÜFEN].
Aufgabe 2: Formuliere den Obersatz nach dem Schema "A könnte gegen B einen Anspruch auf [Rechtsfolge] aus § [Norm] haben."
Aufgabe 3: Liste die Tatbestandsmerkmale in Prüfungsreihenfolge und nenne zu jedem, welche Sachverhaltsangabe fehlt.
Keine Rechtsprechung zitieren, keine Bezugnahme auf US-Recht. Bei Unsicherheit über den Normtext: "WORTLAUT PRÜFEN".

§ 203 StGB, § 43e BRAO and the “possibility of access” test

The rules that decide tool choice in DACH are criminal law, and the bars have read them strictly.

Germany Austria Switzerland
Secrecy norm § 43a Abs. 2 BRAO; § 203 Abs. 1 Nr. 3 StGB; § 43e BRAO for IT providers § 9 Abs 2 RAO; § 40 Abs 3 RL-BA 2015 Art. 13 BGFA; Art. 321 StGB; DSG
Guidance BRAK Hinweise, Stand Dec 2024 (advisory); DAV Stellungnahme 32/2025 ÖRAK Leitfaden, Sept 2025 SAV Wegleitung, 14 June 2024
Public chatbot rule Only “abstrakte” prompts allowing no inference about a mandate; full anonymisation of uploads Mandate data in public or unsecured systems is “standesrechtlich unzulässig”; abstract, anonymous questions only Confidential information not to be entered without one of three set-ups
Route to a provider § 43e BRAO contract in Textform with criminal-law instruction; foreign providers must offer comparable protection; prefer German or European servers Provider must meet the five cumulative § 40 Abs 3 RL-BA conditions, incl. notifying the firm of a search; a signable ten-point vendor checklist On-premise; or a provider under the SAV cloud guidelines; or informed client consent and waiver
Court cases so far AG Köln 312 F 130/25; LG Frankfurt 2-13 S 56/24; KG Berlin 17 WF 144/25 OGH 14 Os 95/25i (appeal rejected unread) BGer 9C_235/2026 (lay appeal not entertained)

The sentence to memorise is the BRAK’s: for the element of access to mandate secrets “es [kommt] … nicht darauf an, ob die KI-Anbieter tatsächlich Kenntnis nehmen. Ausreichend ist wie bei der Offenbarung in § 203 StGB, dass sie die Möglichkeit dazu haben” (BRAK Hinweise). “Nobody at OpenAI reads your prompts” is therefore not a defence; a contract that removes the possibility is. The BRAK adds that removing names and addresses is often not enough “wenn sich Mandatsinformationen aus dem Kontext ergeben können”; the DAV reads § 43e BRAO more permissively and calls anonymisation “nicht zwingend” for contracted providers.

The ÖRAK is blunter (ÖRAK Leitfaden): entering mandate data into public or unsecured AI systems “stellt einen Bruch der Verschwiegenheit dar und ist standesrechtlich unzulässig”, verification must be “ausnahmslos”, and AI use requires staff “KI-Kompetenz”. The Swiss SAV adds the line every verification workflow should quote: “Man kann also zum Beispiel nicht einfach ein KI-System fragen, ob der gelieferte Output der Wahrheit entspricht, da KI-System dazu nicht in der Lage sind” (SAV Wegleitung). The rules clause by clause, with the DAV’s dissent, are in KI in der Kanzlei: BRAK, DAV and ÖRAK.

Make the question abstract before it leaves the Kanzlei
Here is a question I want to put to a public AI tool about a live mandate: <question>...</question>. Rewrite it to comply with the BRAK's rule that prompts must allow no inference about a specific mandate, even from context: remove every name, place, date, amount, industry detail and unusual fact; replace them with neutral placeholders or ranges; keep the legal question intact. Then list every element of the original that could still identify the mandate when combined with public information, and say whether the rewritten question is safe to send or belongs in our § 43e-contracted tool instead.
Anonymise a Schriftsatz on a local model, with a key
Replace every personal name, company name, address, account number, date of birth, Aktenzeichen and unique identifier in the document below with consistent placeholders ([PERSON_1], [FIRMA_A], [ADRESSE_1], [DATUM_1], [AZ_1]) so the document stays internally coherent. Also generalise contextual identifiers that would allow re-identification (unusual job titles, unique events, small towns) to a neutral description. Output the anonymised text and a separate key table. Do not summarise or alter any other content. Document: <dokument>...</dokument>

Run that second prompt on a local model or a § 43e-contracted tool, never on the public chatbot you are anonymising for, and strip metadata first; the workflow is in how to anonymise documents before AI.

Choosing a stack for a mid-size Kanzlei

A 30-lawyer firm in Frankfurt, Vienna or Zurich does not need every tool on this page. It needs one from each of three layers, chosen by where the data sits.

  1. A general model on business terms with EU processing. ChatGPT Enterprise stores new European workspaces at rest in Europe; Claude’s first-party API stores workspaces in the US only, so EU processing runs through AWS Bedrock or Google Vertex; Copilot is an EU Data Boundary service, but “Models provided by Anthropic as a subprocessor are currently excluded from the EU Data Boundary”. The § 43e BRAO or § 40 RL-BA agreement is the document, not the data-centre map; the settings are in EU data residency for ChatGPT, Claude and Copilot.
  2. A grounded legal tool for Recht. Beck-Noxtua or juris KI-Suite if your library is beck-online or juris; Libra if it is Otto Schmidt. This is the layer that answers the Austrian question “Aus welcher Quelle zitiert es, und lässt sich diese Fundstelle im RIS aufrufen?”
  3. A work platform only if diligence or litigation volume justifies it. Legora from Munich if EU residency by default matters and the ten-seat floor fits; Harvey if the firm lives in Microsoft 365 and can get the § 43e agreement signed.

The CCBE’s March 2026 technical guide is the reality check on the fourth option, full on-premise: “the most secure option”, but frontier-class hardware runs to “magnitudes of €6,000,000 as one-off cost, with monthly costs of around €50,000”. For almost every Kanzlei the answer is contracts and anonymisation.

The rule that survives every tool choice is the one the courts in Köln, Frankfurt and Berlin and the OGH in Vienna have written into decisions: the lawyer reads the output, checks every Fundstelle in the primary database, and signs. BRAK’s “abstrakte Anfragen” and ÖRAK’s checklist stop being abstract once you have anonymised a Schriftsatz yourself and checked which tier of ChatGPT, Claude or Copilot you are on; that is a live exercise in the confidentiality session of AI Lab for Lawyers, taught by a Vienna practitioner with browser tools only.

Where to go next: the prompt library has the German-language Gutachten and anonymisation prompts above ready to paste, and the rest of the tools cluster covers the general models every stack here runs on.

Frequently asked questions

Which AI tools do German law firms use?

Translation and general chatbots, not legal platforms. The Bayerischer AnwaltVerband survey of 558 lawyers found 37.9% of firms using AI at all, with DeepL at 70.7% and ChatGPT at 69.2% among users, Microsoft Copilot 21.7%, Gemini 4.2% and Claude 2.8%. The legal-tech.de 2025 survey found only 16% using a dedicated AI tool in the Kanzlei, while over half use ChatGPT at least sometimes. Wolters Kluwer's 2026 survey of US, Chinese and European lawyers puts overall use at 92%.

Is Beck-Noxtua better than ChatGPT for German law?

There is no public benchmark comparing them, so nobody can say honestly. What Beck-Noxtua offers that ChatGPT does not is grounding in beck-online's document corpus, German hosting on Deutsche Telekom's AI Factory with BSI C5 certification, and, per JuriScout's comparison, an architecture built for § 203 StGB and § 43e BRAO. What frontier models offer is raw reasoning: GPT-5 leads the LEXam German-law exam benchmark at 70.2. Run both on five of your own Schriftsätze before deciding.

Does Legora work for German law firms?

Yes, and it is the most visible international platform in DACH. Legora opened a Munich office on 31 March 2026 and reports more than 80 DACH firms and legal teams as clients, including Linklaters, CMS and Schönherr, with EU data residency, ISO 42001 and bring-your-own-key encryption. It is priced by quote, reported at about $3,000 per user per year with a 10-seat minimum, and its grounding is not beck-online or juris, so the RIS or juris check remains your job.

Is Harvey § 203-compliant?

Harvey states it never trains on customer data, requires zero data retention from its model providers and offers an EU region in Frankfurt. JuriScout, a German comparison site, nonetheless assesses Harvey as 'not positioned as §203-compliant at architecture level', a third-party view rather than a finding. Under BRAK's reading of § 203 StGB the mere possibility of provider access counts, so the real question is whether Harvey will sign a § 43e BRAO agreement with the required criminal-law instruction.

Can I use ChatGPT in a German Kanzlei?

For abstract questions, yes; for mandate data, only on terms the bar will accept. BRAK's guidance says language models should receive only 'abstrakte' prompts that allow no inference about a specific mandate, uploads should be fully anonymised, and providers with German or European servers should be preferred. ÖRAK calls entering mandate data into public or unsecured AI systems 'standesrechtlich unzulässig'. ChatGPT Enterprise with EU residency and a § 43e BRAO agreement is the defensible route; consumer ChatGPT is not.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.