netzstrategen

AI Act and GDPR in practice: using AI without the risk

No blockade from legal, no data leaking out. We build the technical and organisational guardrails for running AI in production.

Why this is on the table now

The EU AI Act is in force and applies in stages: first the prohibited practices and the obligation to build AI literacy inside the company, then the requirements for general-purpose AI models. Further stages follow. In parallel the GDPR continues to apply unchanged, now to data flows that did not exist two years ago.

In practice this hits companies in two places. First through shadow usage: people have long been using AI, often through private accounts, and nobody knows which documents leave the building along the way. Second through the counter-reaction: data protection and legal block everything out of uncertainty, and the competitive disadvantage grows quietly alongside.

Both are symptoms of the same problem: there is no safe, official route. That is exactly what we build.

The three guardrails in operation

Legal certainty sits in how the systems are built. These three points are part of ours from the start.

EU hosting and anonymisation

Strategic context and company data are EU-hosted. Personal and sensitive content is masked before it reaches an AI model; compliance warnings take effect inside the workflow, not in hindsight. With the model providers it is ruled out that your data ends up in their training.

Auditability and documentation

Who produced what, with which tool and on what basis? Every run is logged and traceable: which model, which context, which approval. For critical use cases the human decision is a binding part of the process, including disclosure wherever it is required.

Guardrails against hallucinations

Agents work against defined system instructions and filters, not against an empty chat window. They draw on the company knowledge base instead of guessing, and they may only do what they are meant to do. Whatever remains uncertain goes to a person before it goes outside.

How we go about it

01

Take stock

Where is AI already being used, officially and unofficially? Which data leaves the company in the process, which use cases are sensitive, and where is a rule missing?

02

Build the guardrails

Secure access, anonymisation before anything reaches a model, roles and permissions, logging. Built into the systems, not filed as a policy on the intranet.

03

Operation and enablement

Training for the teams, approval paths for critical cases, documentation that keeps up. Governance that makes AI usable instead of slowing it down.

Cost and vendor lock-in

Token consumption, model choice and vendor lock-in are important questions, but they are not legal ones. How we keep costs transparent and models interchangeable is covered in the Admin Layer of the AI platform.

To the Admin Layer of the AI platform →

From blocker to enabler: make your AI projects legally sound.

In a 30-minute AI governance check we name your biggest data protection and compliance risks and show the route to a solution.

Arrange an AI governance check