Anyone deploying a digital assistant or a knowledge-based AI system today is not merely deciding on a function. It is a matter of trust, data sovereignty and the question of which legal jurisdiction information is processed in.
Over the past few months, I have spoken with many entrepreneurs and IT managers about the use of Artificial Intelligence. The enthusiasm is great – and for good reason. Digital assistants answer customer inquiries around the clock, knowledge-based systems make corporate knowledge searchable in seconds, and texts and documents are created considerably faster.
Yet in almost every conversation, the same question eventually arises:
“What actually happens to our data?”
This question is justified – and it is often asked too late.
Where the Invisible Risks Lie
When an employee enters an internal document into a widely used American AI service, this information may under certain circumstances leave the protected corporate environment. Many providers are subject to the so-called US Cloud Act. As a result, American authorities can, under certain conditions, demand access to data – even when the servers are located within the European Union.
For many companies, this is problematic. Personal customer data, confidential proposals or strategy papers do not belong in a legal jurisdiction where European data protection standards are only enforceable to a limited extent.
In addition, some providers reserve the right to use inputs to improve their models – unless this is contractually excluded. Internal information can thereby potentially flow into training processes.
What This Means in Practice
Three examples from my consulting practice:
A medium-sized company is planning a digital assistant for customer service that processes order numbers, addresses and complaints. If this data is processed via non-European providers without suitable contractual and technical measures, this can become problematic from a data protection perspective.
A tax firm wishes to deploy a retrieval-augmented AI system (“RAG”) that makes internal client files searchable. With an external non-European provider, highly sensitive client data potentially leaves the firm's protected infrastructure – a critical issue under professional conduct rules.
An online retailer automatically translates product descriptions using a language model. As long as no personal data is processed, this is comparatively uncritical. However, as soon as customer reviews or support data are included, the data protection assessment changes significantly.
What Can Be Secured With American Providers
In many cases, American models are technologically leading and practically unavoidable. Even then, the risk can at least be reduced.
Three measures are common here:
- Data processing agreements including standard contractual clauses
- Business customer plans in which inputs are not used for training
- Technical protective measures such as anonymization, pseudonymization or upstream filtering services
These measures reduce the practical risk considerably. However, they do not fully resolve the problem, because the US Cloud Act continues to apply.
For many applications, this residual risk may be acceptable. For particularly sensitive data, it often is not.
There Are European Alternatives
Europe has caught up considerably in recent years.
The French company Mistral AI is now among the most capable European providers of language models. In many practical use cases, the models are technically fully competitive.
From my perspective, three points are particularly interesting here:
- Development and hosting within Europe
- No access via the US Cloud Act
- Full operation on your own infrastructure possible in some cases
Especially for small and medium-sized companies, this creates a realistic opportunity to build AI systems in a data protection-compliant and long-term independent manner.
In combination with a cleanly designed RAG system, this makes it possible to develop applications that make internal corporate knowledge usable without sensitive documents leaving your own legal jurisdiction.
My Advice
Before you decide on an AI solution, answer three questions:
- What data is processed – and how sensitive is it?
- In which legal jurisdiction is this data processed?
- Is there an alternative with comparable benefit and lower risk?
In many projects I support, the answer to the third question is now: Yes.
If You Would Like to Address This Topic
I support small and medium-sized companies in introducing data protection-compliant AI applications – from the initial assessment through the design phase to the technical implementation of digital assistants and knowledge systems based on European models such as Mistral.
If you are considering how your company can use Artificial Intelligence sensibly and in a legally secure manner, I would be glad to have a conversation with you.