← Back to SAP filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Exchange Rates
The sales prices for our ordinary shares traded on German stock exchanges are denominated in euro. Fluctuations in the exchange rate between the euro and the U.S. dollar affect the dollar equivalent of the euro price of the ordinary shares traded on the German stock exchanges and, as a result, may affect the price of the ADRs traded on the New York Stock Exchange (NYSE) in the United States. See “Item 9. The Offer and Listing” for a description of the ADRs. In addition, SAP SE pays cash dividends, if any, in euro. As a result, any exchange rate fluctuations will also affect the dollar amounts received by the holders of ADRs on the conversion into dollars of cash dividends paid in euro on the ordinary shares represented by the ADRs. Deutsche Bank Trust Company Americas is the depositary (the Depositary) for SAP SE’s ADR program. The deposit agreement with respect to the ADRs requires the Depositary to convert any dividend payments from euro into dollars as promptly as practicable upon receipt. For additional information on the Depositary and the fees associated with SAP’s ADR program see “Item 12. Description of Securities Other Than Equity Securities — American Depositary Shares.”
For details on the impact of exchange rate fluctuations see “Item 5. Operating and Financial Review and Prospects — Foreign Currency Exchange Rate Exposure”.
Dividends
Dividend Distribution Policy
Dividends are jointly proposed by SAP SE’s Supervisory Board (Aufsichtsrat) and Executive Board (Vorstand) based on SAP SE’s year-end stand-alone statutory financial statements, subject to approval by the Annual General Meeting of Shareholders. Our dividend policy is to pay a dividend of at least 40% of the SAP Group’s non - IFRS profit after tax from continuing operations. Dividends are officially declared for the prior year at SAP SE’s Annual General Meeting of Shareholders. SAP SE’s Annual General Meeting of Shareholders usually convenes during the second quarter of each year. Following joint market standards in Europe for corporate actions processing, dividends are remitted to the custodian bank on behalf of the shareholders on the third business day following the Annual General Meeting of Shareholders. Record holders of the ADRs on the dividend record date will be entitled to receive payment of the dividend declared in respect of the year for which it is declared. Cash dividends payable to such holders will be paid to the Depositary in euro and, subject to certain exceptions, will be converted by the Depositary into U.S. dollars.
Dividends paid to holders of the ADRs may be subject to German withholding tax. See “Item 10. Additional Information — Taxation,” for further information.
15
Table of Contents
Annual Dividends Paid and Proposed
The following table sets forth in euro the annual dividends paid or proposed to be paid per ordinary share in respect of each of the years indicated. One SAP ADR currently represents one SAP SE ordinary share. Accordingly, the final dividend per ADR is equal to the dividend for one SAP SE ordinary share and is dependent on the euro/U.S. dollar exchange rate. The table does not reflect tax credits that may be available to German taxpayers who receive dividend payments. If you own our ordinary shares or ADRs and if you are a U.S. resident, refer to “Item 10. Additional Information — Taxation,” for further information.
Dividend Paid per Ordinary Share
Year Ended December 31, € US$
2021 2.45 4 2.61 1
2022 2.05 2.23 1
2023 2.20 2.37 1
2024 2.35 2.62 1
2025 (proposed) 2.50 2 2.95 2, 3
1 Translated for the convenience of the reader from euro into U.S. dollars at the Noon Buying Rate for converting euro into U.S. dollars on the dividend payment date. The Depositary is required to convert any dividend payments received from SAP as promptly as practicable upon receipt.
2 Subject to approval at the Annual General Meeting of Shareholders of SAP SE currently scheduled to be held on May 5, 2026.
3 Translated for the convenience of the reader from euro into U.S. dollars at the Noon Buying Rate for converting euro into U.S. dollars on February 5, 2026 of US$1.18 per €1.00. The dividend paid may differ due to changes in the exchange rate.
4 Includes special increase of €0.50 to celebrate SAP’s 50th anniversary.
The amount of dividends paid on the ordinary shares depends on the amount of non - IFRS profits to be distributed by SAP SE, which depends in part upon our financial performance. The Executive Board and the Supervisory Board of SAP SE will recommend to the Annual General Meeting of Shareholders in May 2026 that the total dividend be €2.50 per share. In addition, the amount of dividends received by holders of ADRs may be affected by fluctuations in exchange rates (see “Item 3. Key Information — Exchange Rates”). The timing, declaration, amount and payment of any future dividend will depend upon our future earnings, capital needs and other relevant factors, in each case as proposed by the Executive Board and the Supervisory Board of SAP SE and approved by the Annual General Meeting of Shareholders.
16
Table of Contents
Risk Factors
Our operations and financial results are subject to various risks and uncertainties, including those described below, that could adversely affect our business, financial condition, results of operations, cash flows, and the trading price of our ADRs and ordinary shares.
Economic, Political, Social, and Regulatory Risks
Global Economic and Political Environment: Uncertainty in the global economy and/or financial markets, and social and political instability caused by state-based conflicts, terrorist attacks, civil unrest, war, or international hostilities could lead to disruptions in our business.
As a global company, we are influenced by multiple external factors that are difficult to predict, may develop quickly, and are beyond our influence and control. These include, among others: crises affecting credit or liquidity markets; regional or global recessions; sharp fluctuations in commodity prices, currency exchange rates or interest rates; inflation or deflation; sovereign debt and bank debt rating downgrades; restructurings or defaults; adverse geopolitical events (such as Russia’s invasion of Ukraine and the Israel - Hamas conflict); rising military tensions around the world (such as the China-Taiwan tensions) and in particular within Europe’s borders; global policy including in the United States, the European Union (EU), Russia, and China; and global pandemic diseases such as COVID-19.
Any of these events could have an adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
International Laws and Regulations: Laws, regulatory requirements and standards in Germany, the United States, and elsewhere continue to be very stringent. Our international business activities and processes expose us to numerous and often conflicting laws and regulations, policies, standards, or other requirements, and sometimes even conflicting regulatory requirements.
The SAP Group has a global presence and operates in most countries of the world. As a European company domiciled in Germany with securities listed in Germany and the United States, we are subject to European, German, U.S., and other governance-related regulatory requirements of the countries we operate in.
Our business is subject to numerous risks inherent to international business operations and associated consequences, such as changes in tax laws, changes in external reporting standards, and the interpretation of the complex tax rules in certain countries, including but not limited to conflict and overlap among tax regimes as well as the introduction of new tax concepts that harm digitalized business models; discriminatory, protectionist, or conflicting fiscal policies and tax laws; import and export regulations and trade sanctions; counter or even conflicting sanctions; embargoes, including but not limited to country-specific software certification requirements; and newly emerging cybersecurity and environmental, social, and governance (ESG) compliance and disclosure laws.
As we expand into new countries and markets or extend our business activities in these markets, including emerging and high-risk markets, these risks could intensify. The application of the respective local laws and regulations to our business is sometimes unclear, subject to change over time, and often conflicting among jurisdictions. Additionally, these laws and government approaches to enforcement continue to change and evolve, just as our products and services continually evolve. Compliance with these varying laws and regulations (including, and in particular, global anti-trust regulations) could involve significant costs or require changes in our products or business practices. Non-compliance could result in the imposition of penalties or cessation of orders due to alleged non-compliant activity. Governmental authorities could use considerable discretion in applying these statutes and any imposition of sanctions against us could be material.
Any of these events could have a material adverse effect on our operations globally or in one or more countries or regions, which could have a material adverse effect on our business, financial position, profit, and cash flows.
Legal and IP: Claims and lawsuits against us, such as for IP infringements or breaches of contract, or our inability to obtain or maintain adequate licenses for third-party technology, or if we are unable to protect or enforce our own intellectual property, may result in adverse outcomes.
We have in the past, and believe that we will continue to be, subject to claims and lawsuits, including intellectual property infringement claims, as our solution portfolio grows; as we acquire companies with increased use of third-party code including open source code; as we expand into new industries with our offerings, resulting in greater overlap in the functional scope of offerings; and as non-practicing entities that do not design, manufacture, or distribute products assert intellectual property infringement claims. Also, we have been in the past, and believe that we may continue to be in the future, subject to claims and lawsuits alleging competition and antitrust law violations. Such allegations, for example, often arise from competitors and third parties claiming broad access rights to SAP data.
Moreover, protecting and defending our intellectual property is crucial to our success. The outcome of litigation and other claims or lawsuits is intrinsically uncertain.
17
Table of Contents
We are subject to risks and associated consequences in the following areas, among others: data access and other antitrust-based claims, for example alleged lock-in effects, dependency in the aggregate on third-party technology, including cloud and Web services, that we embed in our products or that we resell to our customers; integration of open source software components from third parties into our software and the implications derived from it; inability to prevent third parties from obtaining, using, or selling without authorization what we regard as our proprietary technology and information; and the possibility that third parties might reverse-engineer or otherwise obtain and use technology and information that we regard as proprietary. Moreover, the laws and courts of certain countries might not offer effective means for us to enforce our legal or intellectual property rights and successfully defend allegations. Finally, SAP might face significant adverse rulings in commercial disputes or might not be able to collect or otherwise enforce all judgments awarded to it in legal proceedings. The outcome of litigation and other claims or lawsuits is intrinsically uncertain. Management’s view of the litigation might also change in the future. Actual outcomes of litigation and other claims or lawsuits could differ from the assessments made by management in prior periods, which are the basis for our accounting for these litigations and claims under IFRS.
Data Protection and Privacy: Non-compliance with increasingly complex and stringent, sometimes even conflicting, applicable data protection and privacy laws, or failure to meet the contractual requirements of SAP’s customers with respect to our products and services, could lead to civil liabilities and fines, as well as loss of customers.
As a global software and service provider, SAP is required to comply with local laws wherever it does business. One of the relevant European data protection laws is the General Data Protection Regulation. International data transfers to third countries that do not provide an adequate level of data protection require additional safeguards, including transfer risk assessments, to justify a transfer from the EU to a third country under the applicable EU Standard Contractual Clauses (SCC). In addition, other countries establish safeguards to justify data transfers to further countries, by implementing their own standard contractual clauses. Examples include Türkiye’s Personal Data Protection Law, China’s Personal Information Protection Law, and Saudi Arabia’s Personal Data Protection Law, which also imposes requirements regarding data localization.
Furthermore, data protection and privacy laws, regulations, and other standards around the world are evolving to better protect individuals’ personal information, particularly in marketing activities and tracking of online behavior. This may impose additional burdens for SAP due to increasing compliance standards that could restrict the use and adoption of SAP’s products and services (particularly cloud services) and make it more challenging and complex to meet customer expectations. These changing criteria also impact the compliant use of new technology, such as machine learning and Artificial Intelligence for product development and deployment of intelligent applications.
Non-compliance with applicable data protection and privacy laws by SAP or any of the subprocessors engaged by SAP while processing personal data could lead to risks. These include, among others: mandatory disclosure of breaches to affected individuals, customers, and data protection supervisory authorities; investigations and administrative measures by data protection supervisory authorities, such as the instruction to alter or stop non-compliant data processing activities, including the instruction to stop using non-compliant subprocessors; or the possibility of damage claims by customers and individuals, contract terminations, and potential fines.
In addition, the German Federal Office for the Protection of the Constitution and security industry experts continue to warn of risks related to a globally growing number of cybersecurity attacks aimed at obtaining or violating company data including personal data.
Any of these events could have a material adverse effect on our reputation, business, financial performance, competitive or financial position, revenue, profit, and cash flows.
Corporate Governance and Compliance Risks
Ethical Behavior: Our global business exposes us to risks related to unethical behavior and non-compliance with policies by employees, other individuals, partners, third parties, or entities associated with SAP.
SAP’s leadership position in the global market is founded on the long-term and sustainable trust of our stakeholders worldwide. Our overarching approach is one of corporate transparency, open communication with financial markets, regulators, and authorities, and adherence to recognized standards of business integrity. This commitment to recognized standards of business integrity is formalized in SAP’s Global Code of Ethical Business Conduct (CoEBC) and supporting policies and guidelines.
Risks and associated consequences to which SAP is subject include: non-compliance with policies; violation of compliance-related rules, regulations, and legal requirements including, but not limited to, antitrust, anticorruption, and antibribery legislation in Germany, the U.S. Foreign Corrupt Practices Act, the UK Bribery Act, and other applicable laws; collusion with external third parties; fraud and corruption; public sector transactions in territories exposed to a high risk of corruption; or increased exposure and impact on business activities in highly regulated industries, all of which may lead to civil or criminal charges, fines, or claims by affected parties as well as reputational damage.
Any of these events could have a material adverse effect on our reputation, business, competitive or financial position, profit, or cash flows. In 2025, SAP continued to strengthen its compliance program and related internal controls in accordance with regulatory expectations and requirements.
Operational Business Risks
Sales and Services: Sales and implementation of SAP software and services, including cloud, are subject to several significant risks sometimes beyond our direct control.
A core element of our business is the successful implementation of software and service solutions. The implementation of SAP software and cloud-based service deliveries is led by SAP, by partners, by customers, or by a combination thereof.
18
Table of Contents
We are subject to risks and associated consequences in the following areas, among others: implementation risks caused by insufficient or incorrect information provided by customers, insufficient customer expectation management, including scope, integration capabilities and aspects, and a lack of purposeful selection, implementation, or utilization of SAP solutions; a lack of customer commitments and respective engagements; challenges to achieve a seamlessly integrated, sufficiently automated and aligned service delivery; unrenderable services committed during the sales stage; inadequate contracting and consumption models based on subscription models for services, support, and application management; deviations from standard terms and conditions; or statements concerning solution developments that might be misperceived by customers as commitments on future software functionalities.
Any of these events could have an adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
Partner Ecosystem: If we are unable to scale, maintain, and enhance an effective partner ecosystem, revenue might not increase as expected.
An open and vibrant partner ecosystem is a fundamental pillar of our success and growth strategy. We have entered into partnership agreements that drive co-innovation on our platforms, profitably expand our routes to market to optimize market coverage, optimize cloud delivery, and provide high-quality services capacity in all market segments. Partners play a key role in driving market adoption of our entire solutions portfolio, by co-innovating on our platforms, embedding our technology, and reselling or implementing our software.
We are subject to risks and associated consequences in the following areas, among others: failure to establish and enable a network of qualified and fully committed partners; failure of partners to develop sufficient innovative solutions and content on our platforms or to provide high-quality products or services to meet customer expectations; failure of partners to embed our solutions sufficiently enough to profitably drive product adoption; failure of partners to adhere to applicable legal and compliance regulations; failure of partners to transform their business model in accordance with the transformation of SAP’s business model in a timely manner; and failure of partners to comply with contract terms in embargoed or high-risk countries.
If any of these risks materialize, this might adversely affect the demand for our products and services as well as the partner’s loyalty and ability to deliver. As a result, we might not be able to scale our business to compete successfully with other vendors, which could have an adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
Cloud Operations: We may not be able to properly protect and safeguard our critical information and assets, business operations, cloud offerings and portfolio presentation, and related infrastructure against cyberattacks, insufficient infrastructure, disruption, or deficient performance.
SAP is highly dependent on the availability, integrity, and reliability of our infrastructure, including infrastructure provided by third-party business partners, and the software used in our cloud portfolio is inherently complex. Customers using our cloud services rely on the security of our infrastructure to protect the availability of our services and the data that they store on our infrastructure. Threat actors are focused on attacking third-party product and service providers, such as SAP, as a means of compromising our and our downstream customers’ systems and data.
We are subject to risks and associated consequences in the following areas, among others: the cloud portfolio or strategic direction of cloud operations may not fully meet customer demands; customers’ cloud service demands may not match our data center capacity or control investments; capacity shortages could affect SAP’s ability to deliver and operate cloud services as expected by or committed to our customers; scalability demands on infrastructure and operation could lead to cost increases and margin impacts; hyperscaler or infrastructure instabilities and the lack of availability or comprehensive contractual agreements could lead to challenges in meeting service level agreement (SLA) commitments; we might lack sufficient “future skills” for delivering and operating hybrid environments; we might lack the automation, standardization, and tools to manage and optimize operations and infrastructure; local legal requirements or changes to data sovereignty may lead to customers relocating their landscapes to a different data center; the loss of the right to use hardware purchased or leased from third parties could affect our ability to provide our cloud applications; disruptions to SAP’s cloud applications portfolio (such as system outages or downtimes, SAP network failure due to human or other errors, security breaches, or variability in user traffic for cloud applications) could affect customer SLAs; hardware failures or system errors might result in data loss or corruption; partner co-location of data centers might not adhere to our quality standards; or we might not comply with applicable certification requirements, such as the Payment Card Industry Data Security Standard (PCI DSS).
Any of these events could have a material adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
19
Table of Contents
Cybersecurity and Security: Cybersecurity attacks or breaches, and security vulnerabilities in our infrastructure or services or those of our third-party partners could materially impact our business operations, products, and service delivery.
SAP delivers a full portfolio of solutions, hosts or manages elements of our customers’ businesses in the cloud, processes large amounts of data, and provides mobile solutions to users either directly or through partners and other third parties. This frequently involves incorporating third-party data, products, and services into SAP products and services. SAP operates complex cloud services across diverse architectures, with services implemented through SAP’s own cloud and data centers as well as through hyperscalers.
Our industry contends with a complex and evolving cybersecurity landscape, facing increasingly sophisticated attacks that can leverage AI and cloud scale or exploit known and unknown “zero-day” security vulnerabilities in our or our customers’ systems or software. These cybersecurity threats can arise from our or our customers’ failure to patch such vulnerabilities in a timely or effective manner. Geopolitical tensions can exacerbate such threats, and hybrid warfare between nation states can include cybersecurity attacks on private companies, targeting IT products, businesses, and the supply chain. Like many companies, SAP and certain of our third-party partners have experienced and expect to continue to experience cyberattacks and other security incidents that could affect our business. However, we are not aware of any such incidents that have had a material impact on our business.
When we become aware of unauthorized access to our systems or those of our third-party partners, we have action plans in place intended to identify and remediate the source and impact of such events.
The scanning tools we deploy across our networks and products regularly identify and track security vulnerabilities, which are prioritized based on known and anticipated risks, and our remediation activities aim to patch vulnerabilities within the designated timeframes.
While we have implemented patch management processes, we may be unable to comprehensively apply patches, or to confirm that mitigating measures address all vulnerabilities or that patches will be applied before exploitation by threat actors. Vulnerabilities may persist if customers do not apply patches, update systems, or authorize the service downtime required for patching by SAP. If attackers can exploit vulnerabilities before patches are installed or mitigating measures are implemented, significant compromises could impact our and our customers’ systems and data.
We could also experience material exposure to our business operations and service delivery due to disruptions in backups, in disaster recovery processes, or in business-continuity management processes, or as the result of malicious or inadvertent actions by employees, contractors, or other parties. Security threats may also exist due to delayed or insufficient responses to identified issues or other interdependencies such as cloud service providers and those threats beyond SAP’s cybersecurity infrastructure and protocols.
SAP and/or its partners may have inadequate security controls or insufficient compliance with existing controls, which could impact SAP’s and/or its partners’ ability to comply with applicable regulations and customer requirements. SAP and/or its partners could unknowingly introduce security threats and vulnerabilities if they have not established relevant security evaluation processes. Failure to integrate or maintain SAP’s cybersecurity framework and protocols with network systems obtained through acquisitions could also introduce cybersecurity vulnerabilities.
Technology and Products: Our technology and products may experience undetected defects, coding or configuration errors, may not integrate as expected, or may not meet customer expectations.
We are subject to risks and associated consequences in the following areas, among others: failure of software products and services to fully meet market needs or customer expectations; failure of software products and services from acquired companies to fully comply with SAP quality standards; failure of new products, services, and cloud offerings, including third-party technologies, to comply with local standards and requirements; the possibility that new products, services, and cloud offerings or subsequent versions and updates to existing products, services, and cloud offerings might contain defects or security vulnerabilities, or might not be mature enough from the customer’s point of view for business-critical solutions, or might not be sufficiently secure after release or shipment despite all the due diligence SAP puts into quality; inability of algorithms to correctly adapt to evolving circumstances, which may lead to adverse decision-making processes in the context of AI-related technologies; and the inability to fulfil expectations of customers regarding time and quality in the defect resolution process.
Any of these events could have a material adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
20
Table of Contents
Strategic Risks
Market Share and Profit: Our market share and profit could decline due to increased competition, market consolidation, technological innovation, and new business models in the software industry.
The market for cloud computing is increasingly competitive and is exhibiting strong growth relative to the market for on-premise solutions. To maintain or improve our operating results in the cloud business, it is important that we not only attract new customers but also that our existing customers renew their agreements with us when the initial contract term expires and purchase additional modules or additional capacity. Additionally, we need to bring innovations to the market in line with the demands of our ecosystem and ahead of our competitors, such as solutions to support new data-driven applications and the extension of our suite of intelligent technologies based on SAP Business Technology Platform (SAP BTP).
We are subject to risks and associated consequences in the following areas, among others: inability to deliver fully suitable solution and transformation services to our customers on the cloud transformation journey, both in cloud-only and hybrid scenarios; inability to successfully execute on our hyperscaler strategy; adverse, near-term revenue effects due to increasing cloud business and conversions from on-premise licenses to cloud subscriptions from existing SAP customers, which could have an adverse effect on related maintenance and services revenue; insufficient solution and service adoption together with increased complexity, as well as failures during the execution of our corporate strategy in the context of our portfolio for solutions and services, which could lead to a loss of SAP’s position as a leading cloud company and subsequently to reduced customer adoption; customers and partners being reluctant or unwilling to migrate and adapt to the cloud; customers considering cloud offerings from our competitors; strategic alliances among competitors; price pressure, cost increases, and loss of market share through traditional, new, and cooperating competitors and hyperscalers; and the inability to achieve the planned margin increase in time as planned.
Any of these events could have a material adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
Mergers and Acquisitions: We might not acquire, integrate, or divest companies or their components effectively or successfully.
To expand and consolidate our business, we acquire and divest businesses, products, and technologies, and we expect to continue doing so in the future. Over time, some of these acquisitions have increased in size and in strategic importance for SAP. Management negotiation of potential acquisitions and divestures and the integration and carve-out of acquired businesses, products, or technologies demands time, focus, and resources of both management and the workforce, and exposes us to unpredictable operational difficulties.
We are subject to risks and associated consequences in the following areas, among others: incorrect information or assumptions during the due diligence process for acquisitions, divestitures, and other transactions; failure to integrate acquired technologies or solutions successfully and profitably into SAP’s solution portfolio and strategy; failure to successfully integrate acquired entities and their operations; failure to fulfill the needs of the acquired company’s customers or partners; failure to implement, restore, or maintain internal controls, disclosure controls, and procedures and policies within acquired companies; debt incurrence or significant unexpected cash expenditures; impairment of goodwill and other intangible assets acquired in business combinations; and failure of acquired companies to comply with regulatory requirements.
We have in the past, and may in the future, choose to divest certain entities, businesses, or product lines. We may have difficulty obtaining terms acceptable to us. Additionally, we may have difficulty carving out portions of or entire businesses, we may incur a loss of revenue or experience a negative impact on margins, or we may not achieve the desired strategic and financial benefits. Such potential transactions may also delay achievement of our strategic objectives, cause us to incur additional expenses, disrupt customer, partner, and employee relationships, and may expose us to unanticipated or ongoing obligations and liabilities, including because of indemnification obligations. Further, during the pendency of a divestiture, we may be subject to risks such as a decline in the business to be divested, a loss of employees, customers, or suppliers, and the risk that the transaction may not close, any of which could have a material adverse effect on the business to be divested as well as our retained business. If a divestiture is not completed for any reason, we may not be able to find another buyer on the same terms, and we may have incurred significant costs without the corresponding benefit.
Any of these events could have a material adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.
Innovation: We might not be able to compete effectively if we strategize our solution portfolio ineffectively or if we are unable to keep up with rapid technological and product innovations, enhancements, new business models, and changing market expectations.
Our future success depends on our ability to keep pace with technological and process innovations and new business models, as well as on our ability to develop new products and services, enhance and expand our existing products and services portfolio, and integrate products and services we obtain through acquisitions. To be successful, we are required to adapt our products and our go-to-market approach to a cloud-based delivery and consumption model so as to satisfy increasing customer demand and to ensure an appropriate level of adoption, customer satisfaction, and retention.
We are subject to risks and associated consequences in the following areas, among others: inability to develop and sell new cloud products spanning various organizations on time and in line with market demands due to complexity in heterogeneous technical environments; inability to anticipate and develop technological improvements or succeed in adapting SAP products, services, processes, and business models to technological change, changing regulatory requirements, or emerging industry standards; a change in requirements of our customers and partners to strengthen the Intelligent Enterprise strategy; the possibility that our product and technology strategy might not be successful, or that our customers and partners might not adopt our technology platforms, applications, or cloud services quickly enough, or that they might consider other competing solutions in the market, or that they may leverage AI to produce their own solutions, or that our strategy might not match customers’ expectations and needs, specifically in the context of expanding the product portfolio into additional markets.
21
Table of Contents
We are integrating AI into several of our products, including our suite of enterprise applications and SAP BTP, and we expect our use of AI across our portfolio to continue to grow. As with many innovations, AI presents risks and challenges that could affect its adoption and therefore our business. AI algorithms or training methodologies may be flawed. Data sets may be overbroad, insufficient, or contain biased information. Content generated by AI systems may be offensive, illegal, or otherwise harmful. Ineffective or inadequate AI development or deployment practices by SAP or our partners could result in incidents that impair the acceptance of AI solutions or cause harm to individuals, customers, or society, or result in our products and services not working as intended. Human review of certain outputs may be required, which could introduce error or inefficiencies to the intended use of our AI-enabled offerings. As a result of these and other challenges associated with innovative technologies, our implementation of AI systems could subject us to competitive harm, regulatory action, legal liability, and brand or reputational harm.
There is significant uncertainty surrounding the applications of intellectual property and privacy laws to AI technology. Intellectual property ownership and license rights, including copyright, surrounding AI technology have not been fully addressed by courts or other laws or regulations of the jurisdictions in which we operate, and our use of AI technology or integration of AI technology into our products and services may result in disputes with respect to ownership or intellectual property, or exposure to claims of copyright or other intellectual property misappropriation. In addition, our AI technology may involve the processing of personal and other sensitive data and may be subject to laws, policies, legal obligations, and contractual requirements related to privacy, data protection, and information security. Various privacy laws extend rights to consumers (such as the right to obtain consent or delete certain personal data) and regulate automated decision making. An alleged or actual failure to meet these obligations may lead to regulatory investigations and fines or penalties; may require us to change our business practices or retrain our algorithms; or may prevent or limit our use of AI technology. It is also possible that we are held liable for intellectual property, privacy, or other legal violations of third-party AI technology that we use, and that we may not have full recourse for any damages that we suffer (for example, our use of third-party AI technology may be subject to limitations of liability or provide no liability coverage).
In addition, some AI scenarios present ethical issues or may have broad impacts on society, and there can be no assurance that our Global AI Ethics Policy or similar policies and procedures will be sufficient to address such issues. If we enable or offer AI solutions that have unintended consequences, unintended usage or customization by our customers and partners, or are controversial because of their impact on human rights, privacy, employment, or other social, economic, or political issues, we may experience reputational harm, adversely affecting our business and consolidated financial statements.
Any of these events could have a material adverse effect on our reputation, business, competitive or financial position, profit, and cash flows.