07/23/2026

AI Between Compliance and Data Protection: "A Ban or Ignoring It Often Just Leads to Shadow AI"

"A Ban or Ignoring It Often Just Leads to Shadow AI" Data protection and compliance

When people talk about compliance and data protection, many lump these terms together. Does data protection actually belong to compliance?

Dr. Matthias Zuchowski: Yes, data protection is fundamentally a subset of compliance. Compliance encompasses all the rules and requirements a company must observe — from legal requirements to internal policies to technical standards. Data protection plays a special role here. It is very heavily regulated, requires specialized expertise, and has an extensive body of rules in the form of the General Data Protection Regulation (GDPR). That is why data protection is often perceived as a distinct topic in its own right, even though it is actually part of compliance.

What role does the new European AI Act play in this?

Dr. Matthias Zuchowski: The AI Act is a classic compliance topic. It defines requirements for the use of AI systems and also touches on data protection. However, it does not regulate all data protection issues. Many aspects continue to be covered by the GDPR. Companies must therefore consider both bodies of regulation together.

AI has by now arrived in almost every company. Where are the biggest challenges currently?

Dr. Matthias Zuchowski: In my view, the biggest challenge is not the technology itself, but its uncontrolled use. Many employees experience in their daily work how helpful AI can be. It analyzes large amounts of data within seconds, creates presentations, or is used when programming software. If companies do not provide official tools for this, or ban AI outright, so-called shadow AI often emerges.

What is meant by shadow AI?

Dr. Matthias Zuchowski: We speak of shadow AI when employees use AI applications that are not officially approved or even known about. This usually does not happen with bad intent. People want to do their work more efficiently. The problem, however, is that confidential information can quickly end up in public AI systems as a result. Anyone who, for example, enters internal balance sheets, strategy papers, or product information into a freely available service may lose control over that data.

Does that mean companies should allow AI as openly as possible?

Dr. Matthias Zuchowski: No, not without limits. As always, the truth lies between two extremes, both of which are problematic. One is: “We allow everything.” The other: “We ban everything.” A complete ban increases the risk of shadow AI. Completely unregulated use, on the other hand, creates new security risks. The right path lies in between. Companies should define clear guardrails and consciously decide which tools may be used and which data may be processed.

Are there examples?

Dr. Matthias Zuchowski: A good example is Microsoft 365 Copilot. The system can access information available within a company. If access rights in SharePoint environments have not been properly maintained, the AI can make documents findable that were previously protected only because nobody had found them. The AI does not create the problem. It makes existing vulnerabilities visible.

What role does risk assessment play in this?

Dr. Matthias Zuchowski: A central role. Not every piece of information is equally sensitive. Marketing materials differ significantly from unpublished business reports or confidential merger plans. Companies should therefore first clarify which data is particularly worth protecting and which risks they are willing to take. Only on this basis can sensible decisions be made about the use of AI. A tool used, for example, to transcribe webinars and publicly accessible information must be assessed differently than an application that supports the creation of business reports.

Data protection is often criticized as an innovation brake. Is this criticism justified?

Dr. Matthias Zuchowski: Partly. Data protection has an important function and protects legitimate interests. At the same time, we see in Europe that some regulations make the use and development of AI significantly more difficult. Especially when it comes to using data for training or further developing AI models, high legal hurdles and elaborate review processes arise. As a result, European companies are in some cases falling behind in international competition.

Does that mean data protection needs to be relaxed?

Dr. Matthias Zuchowski: Not fundamentally. Nobody wants sensitive health data, information about job applicants, or trade secrets to be processed without controls. The decisive question is rather: where is there actually a relevant risk, and where do rules prevent sensible use cases? In my view, we need more risk-based regulations that distinguish between different types of data and usage scenarios.

Many companies rely on European providers to reduce data protection risks. Is that enough?

Dr. Matthias Zuchowski: Unfortunately not automatically. That is still a misconception. European providers often create more transparency and meet higher data protection standards. Nevertheless, it is always worth taking a close look at the technical infrastructure.

Many services, for example, use cloud infrastructures from large American providers. Companies should therefore carefully check where their data is processed, which contracts apply, and which rights providers grant themselves — especially with regard to AI training. Many consumer products, for instance, are not suitable for business purposes precisely because they use data for training by default. Trust is important. Control nevertheless remains necessary.

What should companies do regarding AI?

Dr. Matthias Zuchowski: Companies should actively engage with the topic of AI and create clear rules. Anyone who ignores or bans AI will not stop its development. Anyone who introduces it in an uncontrolled way creates new risks.

Responsible use is based on three factors: transparency, risk assessment, and clear guardrails. Then AI does not become a security problem, but rather a tool that makes companies more productive and competitive.



Stefan Karpenstein

Stefan Karpenstein

Public Relations Manager


Share Article