14 July 2026

Part 31: AI Tools – What about data protection? (2026)

Which AI tools are companies allowed to provide to employees from a data protection and confidentiality perspective? Our popular overview has grown larger and more detailed. Anthropic has been added, while well-known players have unfortunately still not fully done their homework. For part 31 of our AI blog series, we have once again analyzed the most popular offerings.

VISCHER_ai-tools-07-26 reduced.webp

This overview can be found here.

Since our last update 15 months ago, the AI tools offered by the previously featured providers have grown significantly. We have now added Anthropic, the most important new player alongside OpenAI, Microsoft, and Google. Additionally, we have supplemented the overview with offerings from DeepL and several providers from our home market. While this list is not exhaustive, we anticipate inquiries about the omission of European offerings like Mistral. The reason is simple: we simply do not encounter them in the many companies we advise on these matters. Chinese providers of language models are also missing from the list because, although companies use their offerings, they do not use them as a service. Instead, companies deploy these (sometimes very powerful) open-source models on their own infrastructure or that of national providers. From a data protection perspective, this is the most secure option and is also easy to manage with the right hardware; however, many companies still shy away from investing in the necessary infrastructure (typically CHF 20k or more).

The AI tools previously listed surprisingly show no change in the overall assessment of the results: There are solutions that are suitable for corporate use. However, this still does not apply to all AI tools or all company data. As the range of services on offer continues to grow, the relevant contractual terms are constantly changing, and provider-specific – or even AI-tool-specific – issues regularly arise, assessing compliance remains a real challenge from the customer’s perspective. Most companies find this completely overwhelming. At the same time, intense pressure from the business side to deploy specific tools drives companies to use legally deficient solutions.

Microsoft continues to spark intense discussion, as their "Copilot" for Microsoft 365 and Azure OpenAI Services still lack a legally compliant solution for internet search (so-called web grounding). We do not understand why Microsoft cannot offer a truly data protection-compliant solution here, unlike competitors such as Google.

Furthermore, no cloud provider has satisfactorily resolved the issue of concluding agreements that meet professional secrecy requirements while also allowing an opt-out for abuse monitoring. In our view, human abuse monitoring by providers poses a problem in this context, as they monitor data, for example, to verify compliance with agreements or to report incidents to authorities if necessary. A purely automated safeguard that uses solely technical measures to prevent the AI from responding to certain requests or filtering certain outputs does not, in our view, pose a problem with regard to professional secrecy (or data protection). It is part of the service provided by the provider to the customer, including so that the customer does not have to implement its own measures (e.g., filters) to ensure compliant use of AI, and is covered by the provider’s agreement and control. If something "gets caught" in the filter, nothing happens - in both senses of the word. As long as the provider does not access the data in plain text or process it further for other purposes, we believe that abuse monitoring implemented in this manner is acceptable. The situation is different with manual abuse monitoring, where an employee of the provider reviews the content on the provider’s behalf. The customer has no influence over which specific person reviews the data and how, how that person evaluates the data, or what follow-up measures (e.g., account suspension, reporting to authorities) the provider takes. Typically, this does not constitute an auxiliary activity subject to the customer's instructions. If a company cannot opt out of human abuse monitoring with Hyperscalers, local providers offer a viable alternative; although their open-source models cannot match the full functionality and power of major cloud providers, they nevertheless present a competitive offering.

When we subsequently speak about admissibility under data protection law, we do so from the perspective of the EU General Data Protection Regulation (GDPR) and the Swiss Data Protection Act (Swiss DPA) in the case of international cloud providers, and the Swiss DPA in the case of Swiss providers. The remarks on professional and official secrecy refer to the legal situation in Switzerland. Further explanations on this can be found here; these apply to both professional and official secrecy.

In the public sector, however, the legal situation currently plays only a subordinate role. For public administrations, procuring AI services from cloud providers is currently politically taboo, at least for bodies unable to "fly under the radar." This situation is driven primarily by hardliners among the cantonal data protection authorities who, with what we consider to be legally questionable claims regarding the U.S. CLOUD Act, for example, spread the view that cloud use is illegal for official secrecy data and that the risk-based approach does not apply—which is incorrect. Unfortunately, this has caused considerable uncertainty. We assume it will take another year or two before these authorities realize that this blocking attitude actually undermines data protection. In addition to the topic of foreign government access (Foreign Lawful Access), digital sovereignty also shapes the public sector discussion. Conversely, the private sector discusses these issues much more objectively (see here for the whole picture).

OPENAI (GPT)

At OpenAI, nothing has fundamentally changed contractually since the last update of our table. However, we have made our table somewhat more detailed and now point out fur-ther risks that are relevant for companies:

  • Companies must continue to use business-specific offers, as is standard with all providers. Offers for private customers are neither designed nor suitable for corporate use.
  • In the table, we now highlight that OpenAI's data processing addendum (OpenAI DPA) only covers the processing of non-sensitive personal data (the same applies to Anthropic's DPA). In our view, this limitation attempts to evade responsibility for a higher standard of data security. Most customers will not realize this, so it remains questionable whether this "trick" succeeds from a data protection per-spective for OpenAI (and Anthropic).
  • Furthermore, the OpenAI DPA contains a questionable clause regarding notifications about new sub-processors. Specifically, OpenAI states that it notifies customers of changes to its sub-processor list "via blog post, notification within the services or other reasonable means, or via email if customer subscribes to email notifications on the sub-processor list site". Because OpenAI can choose any of these channels alternatively, customers cannot rely on receiving email or direct notifications, as OpenAI may simply post the information in a blog. Consequently, customers must actively monitor all these channels, including OpenAI's blogs, to stay informed. In practice, this mechanism is highly impractical and creates a significant risk that in cases of notification only by blog post, new sub-processors will be engaged without the customer's knowledge, thereby preventing the customer from fulfilling its review obligations.
  • OpenAI also offers a web search option within its services. The standard online contracts linked in our table contain no apparent exceptions, suggesting their pro-visions apply fully to the web search. However, exceptions could exist if an addi-tional service governed by separate terms is used. According to information provided to us by a competitor, OpenAI uses the same Bing web search as Microsoft and is therefore said not to be in a position to fulfill its assurances under the OpenAI DPA (which states that data would be processed only by sub-processors), because Microsoft does not make the Bing search available in the capacity of a data processor. While we cannot verify this claim, we believe a competent supervisory authority should pose critical questions on behalf of OpenAI's numerous users, which OpenAI would then be required to answer.

Of course, we have also contacted OpenAI to explore among other things whether we could use their AI tools in compliance with professional secrecy. However, we received either no response or unhelpful answers from an automated bot. OpenAI therefore appears to have no interest in providing a satisfactory solution for its customers. Consequently, we believe OpenAI is unsuitable for professional and official secrecy holders, and there are also other reservations.

MICROSOFT (COPILOT, AZURE OPENAI SERVICES)

Microsoft has maintained its Copilot naming since our last blog post. Copilot continues to be available in numerous versions. Today, disabling Copilot is more difficult than keeping it active, which partly explains its widespread corporate adoption. For this overview, we have "only" analyzed selected variants within the Office ecosystem—specifically, the Microsoft 365 Copilot Chat integrated into many Microsoft 365 offerings and the paid add-on version, Microsoft 365 Copilot—excluding, and not Copilot in tools like Copilot Studio or GitHub.

While Microsoft's consumer offerings remain not recommended for businesses (see Blog 2), the situation with Microsoft 365 Copilot Chat (automatically included in many Microsoft 365 setups for business customers) and Microsoft 365 Copilot (as an add-on license) has not changed significantly.

  • The same business customer contracts under which a company purchases Microsoft 365 or Azure services generally govern the use of both Copilot variants. From a data protection perspective, these agreements are typically sufficient, provided they include any necessary country-specific, professional, or official secrecy addenda.
  • However, as soon as Copilot, regardless of the version, accesses Bing Search (web search or also called web grounding), standard business contract terms—such as the Microsoft Customer Agreement (MCA) and the Microsoft data processing addendum (Microsoft DPA)—cease to apply. Instead, consumer-grade agreements govern the service, overriding the protections and assurances contained in the business-level contracts. Since the last publication of our overview, in a positive move Microsoft has addressed this issue by adding additional assurances that apply to search queries (so-called "Query Data"). However, these assurances change very little in the legal assessment of the relevant points. Under these contractual supplements, Microsoft promises not to use customer data to improve services, train AI models, or serve advertisements. It also classifies this data as "confidential information". However, the exact meaning of this classification remains unclear. Microsoft has not yet provided a clear assurance that it will indeed treat this confidential information confidentially. Furthermore, contracts define terms for uniform use, capitalizing them in the English versions. In the MCA, a defined term is used: Microsoft undertakes to treat "Confidential Information" (capitalized) confidentially. Even if the MCA applied, its confidentiality clause would likely not cover the web grounding assurances which use the uncapitalized term "confidential information" instead of the defined term. Moreover, the Microsoft DPA does not apply because Microsoft acts as a controller rather than a processor when executing Bing searches. Microsoft appears either unable or unwilling to provide standard processor assurances. Given its persistent refusal to do so despite widespread customer demand, we must conclude that the web search function in Copilot (and similarly in Azure OpenAI Services) fails to meet data protection requirements, as well as professional and official secrecy standards. Consequently, Microsoft may process user data in unauthorized ways. Reservations must also be made regarding business secrets and "Legal Privilege". This privilege requires companies to disclose sensitive data (e.g., legal advice in a dispute) to third parties only under a confidentiality agreement, which is absent here. Although Microsoft repeatedly downplays this issue and now allows certain customers to disable search query logging (Zero Query Logging), this option does not eliminate the security gaps and legal deficiencies. Microsoft must still address these shortcomings, which its competitor Google has already resolved.

What options do companies have? They can disable web search for all users, though this drastically reduces the tool's utility. Alternatively, the paid Microsoft 365 Copilot license allows users to deactivate web search individually. However, Microsoft hides this setting in a context menu, making it user-unfriendly. Furthermore, the distinction between "web" and "work" modes in the paid license confuses users. Many assume "work" mode automat-ically disables the problematic web search, which is incorrect. Based on our current understanding, web search can still occur in "work" mode unless an administrator disables it globally or the user deactivates it on an individual basis.

Many companies prohibit employees from entering personal data or confidential information into Copilot. Legally, this resembles querying an internet search engine, where providers are not data processors and typically do not guarantee confidentiality. However, search engine users control their exact search terms, and they access the service independently rather than through an employer-provided tool. With tools like Copilot, users cannot control—and often do not even know—which parts of their query the tool passes to the search engine, which impairs the level of data protection. While many queries remain unaffected, our tests confirm that web searches can transmit sensitive information to this insufficiently protected environment. We hope that Microsoft will resolve these deficiencies in its widely used tool.

Copilot illustrates how carefully cloud solution users must configure their services. For example, to resolve performance issues and to the annoyance of many data protection officers, Microsoft recently introduced "Flex Routing," a function that processes AI responses in data centers worldwide rather than exclusively in Europe to achieve better load balancing. While not objectionable under data protection law, from our point of view, it would not be acceptable for professional secrets, for example. Crucially, these processing activities outside the "EU Data Boundary" bypass contractual regulations under the label of a "service" and, according to reports, were sometimes activated by default. This reinforces our recommendation to review cloud service configurations regularly.

When using Azure OpenAI Services under a business agreement, the standard business terms generally apply, permitting internal company use. However, Microsoft applies the same exception detailed above when using Bing Search: In this case as well, the Microsoft DPA ceases to apply, and the system no longer treats entered or generated data as customer data under the MCA, leaving it without sufficient confidentiality protection. We refer to our previous explanations on this point. In the case of an API interface, whether web access is routed through the model is controlled by the application using the interface when it calls the language model. While the company can thus restrict web search usage, enabling it allows the model alone to formulate the search query from the user request and the provided context.

With Microsoft, you may use Copilot and Azure OpenAI Services with professional and official secrecy data, provided you conclude the necessary addenda, deactivate abuse monitoring, and do not use Bing Search with data subject to professional or official secrecy. On a positive note, small and medium-sized enterprises can also easily obtain these contract addenda. For further details, please refer to the explanations in the previous blogs (Blog 2, Blog 25). Additionally, when purchasing Microsoft services via a Cloud Solution Provider (CSP), companies must note that the addenda necessary for professional and official secrecy (as well as other contract addenda) are not concluded through a formal process. Therefore, companies should apply our workaround for the missing signature on Microsoft Cloud contracts. Less positive is that Microsoft currently limits the OpenAI Services abuse monitoring opt-out to customers managed directly by Microsoft. However, Microsoft is in the process of testing and hopefully introducing a new process to grant this opt-out to certain professional groups, such as law firms, even if they "only" purchase their Microsoft services via a CSP rather than directly from Microsoft.

It is also worth noting that the Microsoft DPA now applies a 30-day notification period for engaging new AI sub-processors, replacing Microsoft's customary six-month period. However, Microsoft allows customers to deactivate the use of any such sub-processor for at least six months following the announcement.

ANTHROPIC (CLAUDE)

We have added the Anthropic Claude models to this edition of the overview, including vari-ous consumer plans and the three business plans: "Team", "Enterprise", and "API". As with other providers, Anthropic's consumer plans are unsuitable for corporate use. Conversely, the business plans include a data processing addendum (Anthropic DPA), a confidentiali-ty obligation, and an assurance that Anthropic will not use data for training or service im-provement. Consequently, we believe corporate use is generally permissible, subject to the following considerations:

  • The Anthropic DPA only covers the processing of non-sensitive personal data. Con-sequently, the online version of the Anthropic DPA makes the Claude models un-suitable for processing sensitive personal data under the Swiss Data Protection Act, mirroring the situation with OpenAI. Even when employees are clearly instructed, there may still be cases where they (accidentally or intentionally) use Anthropic services with sensitive personal data. Ultimately, each organization must decide for itself whether to accept the associated risks. Like OpenAI, Anthropic seems to lack the intent to offer sufficient data protection for sensitive personal data. In our view, both OpenAI and Anthropic demonstrate the lower data protection and security maturity of "newcomers" compared to hyperscalers like Microsoft, AWS, and Google. We therefore recommend deploying these providers' models only on the systems of established hyperscalers for sensitive applications, as they also host the models of OpenAI and Anthropic (see below).
  • Standard business contracts do not suffice for professional and official secrecy data, and we know of no contract addenda or other solutions that enable use with such data. Although we observe a high demand for Anthropic's models, users should not obtain them from Anthropic for applications in the area of professional or official secrecy, but rather from hyperscalers (see below). Furthermore, Anthrop-ic itself has refused to discuss this subject so far.

DEEPL

We have now included DeepL in our overview, covering both the DeepL Free and DeepL Pro versions. Unsurprisingly, we do not recommend the free version for corporate use, as DeepL may use the entered data for its own purposes. Translating texts that contain personal or confidential data requires a DeepL Pro subscription.

We are unaware of any standard addenda for DeepL regarding professional and official secrecy data. Without a special agreement, it must be assumed that DeepL processes data in US and other non-European data centers. However, our experience shows that clients with sufficient contract volume can negotiate contract adjustments, including provisions for professional and official secrecy data.

VISCHER_ai-tools-07-26 reduced_Page_1.png

The entire overview can be found here.

GOOGLE (GEMINI)

Google has released new offerings, including various versions of Google Gemini Enterprise and renamed some existing offerings. Free versions for business customers (such as the free Google Gemini Enterprise – Business Edition) and for consumers are unsuitable for corporate use since they are either obtained under a consumer contract or Google uses the data for its own purposes. Generally suitable for companies are offerings that are part of the Google Cloud Platform (GCP) and are thus obtained under the "Google Cloud Platform Terms of Service" (GCP Terms). It should be noted in this context that certain offerings for companies are not obtained under the GCP Terms, but under various other contracts, each of which must be examined in detail.

Also for the services purchased under the GCP Terms, not every service is suitable for every use case. Specifically, when using web grounding (web search) via Gemini, certain variations allow Google to store data for debugging. However, unlike Microsoft, Google offers "Web Grounding for Enterprise" when accessing Gemini models via API, whereby no storage for debugging takes place and use with professional and official secrecy data is possible, provided that the further requirements for this are met (see the following explanations on professional and official secrecy). To the best of our knowledge, Google is currently the only provider to do this. This demonstrates once again that the hyperscalers' service-specific terms must be examined in detail in each case.

Google's offerings can be used via the web or as an app (use via the UI) (such as Google Gemini Enterprise) or integrated into Google Workspace. In addition, they are available as an API service, allowing the AI models to be used in one's own systems (such as with "Red Ink"). As explained below, it is important to note that not all offerings are actually suitable for corporate use, even if the name of the service suggests otherwise.

In case of use via the UI as well as with Google Workspace, the following points should be noted:

  • Google Gemini Enterprise – Business Edition: In the free version ("unpaid"), which is not procured under the GCP Terms, Google may use your data for its own purposes. The wording for the paid version has unfortunately deteriorated. Previously, the contract explicitly assured: "For paid services and during the trial period, Google will not use your content to improve our products." Google has unfortunately removed this assurance. While the contract still implies that Google will not use "paid services" data for service improvement, it no longer clearly regulates trial periods. Furthermore, the contract lacks a general confidentiality clause, making the service unsuitable for confidential data and so excluding the offer for corporate use. Although there is a data processing addendum that refers to a list of data categories, this list defines categories for various services but excludes "Google Gemini Enterprise – Business Edition". Consequently, despite its "Business Edition" name, the service is not truly suitable for corporate use in both its free and paid versions.
  • Google Gemini Enterprise Standard, Plus or Frontline: This offer is obtained under the GCP Terms and is generally suitable for corporate use. When using web search (Grounding with Google Search), however, Google may store the data for three days for debugging purposes. Although this use for Google's own purposes is formally declared part of the service via a pre-formulated instruction in the contract and is thus viewed by Google as processing for the customer, under data protection law this will be problematic for some, because they only want to allow the processing of their personal data for their own purposes (i.e., the customer's purposes). This could be resolved by using Web Grounding for Enterprise; however, it is not clear to us whether this service is available with Gemini Enterprise Standard, Plus, or Frontline.
  • As already explained in Blog 25, Google has also integrated its AI Gemini (including Search Grounding) into Workspace. Previously, Google offered this service under specific Google Workspace Terms of Service; now, the GCP Terms also apply to these services, and use within the company is generally possible. For Google Workspace, however, there are separate Service Specific Terms, which interestingly contain no indications of use for Google's own purposes (e.g., debugging, testing) regarding the use of Search Grounding (see also the explanations in Blog 25.

When using API Services, several aspects should be noted:

  • When using the Gemini API in Google AI Studio, there is a free and a paid variant; in both cases, the GCP Terms are not applicable (see also Blog 25). However, for users in the European Economic Area, Switzerland, and the United Kingdom, the paid version's terms apply even to the free tier. While a data processing addendum governs the paid version, the terms lack a general confidentiality clause, making the service unsuitable for confidential data. Furthermore, enabling Google Search grounding in these services allows Google to use data for both debugging and testing. This constitutes a more extensive use of data for Google's own purposes than use via the UI. Consequently, these services are unsuitable for confidential or personal data, particularly when web search is enabled. Companies should therefore transition to alternative offerings that permit unrestricted use.
  • Using the Gemini API via the Gemini Enterprise Agent Platform (formerly Vertex AI)—unlike AI Studio— takes place under the GCP Terms, making it generally suitable for corporate use. The API offers two grounding options: Grounding with Google Search, which retains queries solely for debugging, and Web Grounding for Enterprise, which contractually prohibits both query storage and debugging use. Consequently, the API provides a web grounding option that allows for use in compliance with data protection laws as well as professional and official secrecy requirements.

If special addenda for professional and official secrecy have been concluded, abuse monitoring is deactivated, and web grounding is not used (or, if available, only Web Grounding for Enterprise is used), the processing of professional and official secrecy data is generally possible. As a further measure, data storage within one's own country and, for data processing abroad, Zero Data Retention (no storage of queries to the AI) should be provided. The latter, i.e., Zero Data Retention, requires that caching be deactivated. Furthermore, we recommend setting up "Access Approval", i.e., access by Google employees generally only takes place with the customer's approval (the equivalent of Microsoft’s "Customer Lockbox"). The remaining probability of Foreign Lawful Access must be assessed separately. For both Google and Microsoft, the trend away from nationally defined processing locations continues: while the top models could originally still be obtained in Switzerland, they were subsequently only offered in selected data centers in other EU countries. In the meantime, Google sometimes only offers its models in such a way that they run somewhere in the EU in order to better distribute the load.

Obtaining the special addenda for professional and official secrecy is more difficult with Google than with Microsoft (where any CSP reseller can provide them). Although customers can conclude the "ordinary" Google Cloud Platform agreement online, the secrecy addendum requires an offline billing contract, i.e., a manually brokered agreement that Google typically reserves for larger clients. For smaller institutions like law firms, securing such a contract usually requires specific contacts and can take several months. Fortunately, we have already successfully brokered several of these contracts (see here). We hope that this manual, informal process can be automated or accelerated in the future. Currently, however, it is unfortunately the case that professional and official secrecy holders can only obtain corresponding AI contracts from hyperscalers through arduous workarounds.

AWS - the third major provider, does not yet offer an official solution for smaller institutions, but we are in discussions with them to find a resolution. Unfortunately, such initiatives typically take months or years, which in most cases is due to corporate bureaucracy rather than business or legal issues.

VISCHER_ai-tools-07-26 reduced_Page_2.png

The entire overview can be found here.

ANTHROPIC VIA HYPERSCALER

All three major hyperscalers, Microsoft, AWS and Google allow their customers to use Anthropic's models. These then either run on the hyperscalers' data centers, or Anthropic is engaged by the hyperscaler as a sub-processor (for example, in the case of Microsoft Copilot).

At Microsoft, for example, this approach is currently being used with Copilot, where customers are given the option to use Anthropic models as an alternative to the GPT models for Copilot. At present, the data is processed by Anthropic on systems located in the United States. This does not raise any data protection concerns, as Microsoft is obligated under its Microsoft DPA to ensure the necessary protection of the data and to impose the corresponding obligations on its sub-processors. The fact that Anthropic is not certified under the Data Privacy Framework (DPF) does not change this; Microsoft is contractually obligated—and required under the DPF—to properly integrate Anthropic into its contractual framework. However, this option is out of the question for professional and official secrecy data. That said, we have heard that Anthropic plans to run its models in data centers in Europe by the end of the year.

For certain offerings, hyperscalers host Anthropic models as virtual copies within their own data centers. This setup allows customers to procure these models under the hyperscalers' own contracts, which are better suited for sensitive applications and—with the necessary addenda—legally viable for professional and official secrecy data; in some cases even within Europe (though at relatively high prices). While we have not examined AWS and Microsoft Azure in detail, Google establishes the contractual relationship directly with the customer, even though the customer must agree to "comply" with the Anthropic Terms of Service when activating model access. We assume Anthropic requires this of hyperscalers to ensure that their models are used as specified by Anthropic. According to Anthropic’s statements in its Service Specific Terms, at least in the case of Google, Anthropic has no access to the customer’s Google Cloud Platform environment or to the inputs and outputs processed there. Anthropic therefore does not view or monitor the customer’s data or its processing when its models are obtained through Google—in such cases, this is done solely (but at least) by Google as part of its abuse monitoring. According to our understanding, this exclusion does not apply to so-called Covered Models, where Anthropic retains access to customer data even through a hyperscaler (e.g., for abuse monitoring) and thereby commits to the Anthropic DPA. Furthermore, because certain Anthropic services support specific functions like web search, organizations must verify in each individual case which data protection assurances the providers actually make (and, above all, which they do not).

SWISS PROVIDERS

We have now also included the first Swiss providers in our overview who state that they meet the requirements regarding professional and official secrecy. We analyzed the providers' online contracts as a basis. For professional and official secrecy data, we offer a standardized contract addendum that should be required of Swiss providers. This addendum supplements the data processing addendum and the general terms and conditions, and you can obtain it here free of charge.

VISCHER_ai-tools-07-26 reduced_Page_3.png

The entire overview can be found here.

WHAT DO WE DO?

As a law firm, we have deliberately chosen not to use the commonly available tools—in particular ChatGPT and Copilot—because these products either do not provide the necessary protection for our data (ChatGPT) or fail to meet our standards in terms of functionality and performance (Copilot). We use "Red Ink", a Swiss product we developed ourselves, which enables the use of all common models—including on-premises—and is integrated into Microsoft Office, among other platforms, where it offers significantly more than other products (more information here). We use Google’s Gemini models under a Google contract that includes professional and official secrecy addenda, an abuse monitoring opt-out, and zero data retention, hosted in data centers within the EU—including unrestricted web search. Besides, we have adopted Microsoft Azure OpenAI Services as a "second source" with the latest GPT models, likewise under an agreement compliant with professional and official secrecy requirements and featuring an abuse monitoring opt-out (though without web search in that instance). We also offer our employees access to Perplexity, OpenAI (directly), and Anthropic, though not for sensitive data. By accessing the AI directly via an API on a pay-as-you-go basis, we keep costs significantly lower than other companies and can also better control access. However, we have also tested our solution with powerful open-source models (on systems from the Swiss provider onprem.ai) and were pleasantly surprised by the high speed and quality that can now be achieved when the models are properly configured and deployed on suitable systems.

WHAT ELSE NEEDS TO BE CONSIDERED?

Beyond language model access, organizations must consider the data security and data protection compliance of the software itself (especially in agentic operating mode) and the risks associated with accessing external data sources. We will comment on this separately, as it currently represents a common blind spot in AI integration. This is because the issue mentioned above regarding Copilot’s web search essentially arises with any AI system that accesses third-party data sources (e.g., MCP servers or connectors). Uncontrolled collection of data also raises data protection issues. In other words, it is no longer sufficient to focus solely on the data-protection-compliant use of AI services—the entire ecosystem must be taken into account.


This article is part of a series on the responsible use of AI in companies:

We support you with all legal and ethical issues relating to the use of artificial intelligence. We don't just talk about AI, we also use it ourselves. You can find more of our resources and publications on this topic here.

Share article on:

Service(s) included:

Get in touch with our authors and benefit from their expertise:

partner-David-0

David Rosenthal

david.rosenthal@vischer.com

+41 58 211 36 05

partner-Lucian-1

Lucian Hunger

lucian.hunger@vischer.com

+41 58 211 36 12

partner-Jonas-2

Jonas Baeriswyl

jonas.baeriswyl@vischer.com

+41 58 211 34 57

Our
newsletter

Part 31: AI Tools – What about data protection? (2026)