- The AI Revolution in numbers
- The EU AI Act: Europe's Regulatory Framework for artificial intelligence
- Data Protection and AI: The GDPR remains the foundation
- Copyright in AI-Generated Works: Who owns the output?
- Beware of Deepfakes and Bias
- Shared Responsibility: What Microsoft covers — and what your company needs to do
- Safety features in Microsoft Copilot
- AI Governance: Strategic and operational
- Microsoft Purview: The tool for AI governance
- Microsoft Fabric: Secure Data as the foundation for AI
- Conclusion: Secure AI requires secure data policies

Artificial intelligence is transforming the world of work at a rapid pace. But as its potential grows, so do the demands for data security, compliance, and responsible use. In our deep-dive webinar (in German), we joined forces with our Compliance Manager, Michael Makowski, to explore the most important aspects — from EU regulations and copyright issues to specific protective measures within the Microsoft ecosystem.
The AI Revolution in numbers
The speed at which artificial intelligence is spreading is unprecedented: While it took 16 years for cell phones to reach 100 million users, ChatGPT achieved this in just two months. According to IDC, 1.3 billion AI agents will be in use worldwide by 2028—fueled by a projected global data volume of 527 zettabytes.
What does this mean for businesses? Microsoft refers to the “Age of Agents”: In the future, every employee will have at least one Copilot at their disposal, and business processes will increasingly be transformed by specialized AI agents. At COSMO CONSULT, we’re experiencing this firsthand: By early 2026, over 600 agents were already in use company-wide—a threefold increase in just a few months.
But this rapid development also brings new challenges in the areas of security, change management, and compliance.
The EU AI Act: Europe's Regulatory Framework for artificial intelligence
With the EU AI Act, the European Union has adopted the world’s first comprehensive AI law. At its core is a risk classification system that can be represented as a pyramid:
Unacceptable risk (ban): Systems such as social scoring or mass biometric surveillance are prohibited. These bans have been in effect since February 2, 2025.
High Risk (Strict Requirements): AI in sensitive areas such as medicine, hiring processes, or critical infrastructure is subject to extensive documentation and audit requirements.
Important: These requirements take effect on August 2, 2026—companies should start preparing now.
Limited Risk (Transparency Requirement): Typical chatbots and AI assistants must be clearly recognizable as AI to the user. The transparency requirements have been in effect since August 2, 2025.
Minimal Risk (Code of Conduct): Applications such as spell-checkers or spam filters are non-critical and can be covered by voluntary codes of conduct.
Practical advice: Before introducing any AI system, companies should determine which risk category the system falls into. Involving data protection and compliance officers early on saves costs and helps avoid penalties down the road.
Current Note (April 2026): The EU AI Act also requires companies to demonstrate their employees’ AI competence (Art. 4). Training and awareness programs are therefore not only recommended but are increasingly becoming mandatory.
Data Protection and AI: The GDPR remains the foundation
Regardless of the EU AI Act, the proven principles of the GDPR continue to apply—including, and especially, when using AI. Four legal bases are particularly relevant for most companies:
1. Consent: Voluntary, informed, and verifiable consent from the data subject.
2. Contractual Necessity: Data processing is necessary for the performance of a contract.
3. Legal Obligation: The processing is necessary to comply with legal obligations.
4. Legitimate Interest: The processing is in the company’s legitimate interest, provided that the data subject’s rights do not override this interest.
Before any processing of personal data by AI systems, three questions should be answered: Does the purpose permit the processing? Is it necessary? And is it appropriate? In case of doubt, it is advisable to consult the data protection officer.
Copyright in AI-Generated Works: Who owns the output?
A frequently asked question: Who owns content generated by AI? The answer is clear—and surprising to many:
- AI itself cannot be an author—it has no legal personality and no rights.
- The creator of the AI did not create the output.
- Nor did the user create the output in the sense of copyright law.
The consequence: AI-generated content is generally not protected intellectual property. At the same time, there is a risk that AI outputs may infringe on the rights of third parties—for example, if training data contains copyrighted material.
Companies should therefore:
- Establish internal guidelines for handling AI-generated content
- Define review and approval processes
- Review contracts with AI providers for relevant provisions
Beware of Deepfakes and Bias
AI systems can reinforce societal biases rather than treating them neutrally. A telling example: If you ask an AI to generate an image of an arrest in the U.S., the result often shows stereotypical depictions—a clear sign of bias in the training data.
Deepfakes also pose a growing threat. They can spread misinformation, enable identity theft, and violate privacy. For ethical and legal reasons, their creation is problematic and can be punished as, among other things, defamation, slander, or a violation of the right to one’s own image.
Shared Responsibility: What Microsoft covers — and what your company needs to do
When using Microsoft Copilot, the principle of shared responsibility applies:
Microsoft is responsible for:
- The secure production environment
- Data encryption (at rest and in transit)
- Access restrictions to the customer environment
Your organization is responsible for:
- Access to AI apps and identity management
- The protection and governance of data in AI interactions
- Employee training and awareness
Safety features in Microsoft Copilot
Microsoft Copilot already comes with extensive security features:
- Security filters prevent biased or discriminatory outputs
- Inputs are not used to further train the models
- Prompt Shields protect against prompt injection attacks
Corporate data remains strictly separated from public models
Especially important: In Work mode, Copilot accesses corporate data (emails, Teams messages, SharePoint documents). In doing so, it inherits the exact permissions of the respective user. This means that permissions and confidentiality labels must be carefully maintained—because whatever a user is allowed to see, Copilot can also find and analyze.
Tip:
Check the confidentiality levels of your documents. A document classified as “General” in a deeply nested folder is not hidden from Copilot.
AI Governance: Strategic and operational
At COSMO CONSULT, we have established an AI Governance Team that works closely with compliance, data protection, and IT security. Our measures include:
- An AI tool strategy that clearly defines which tools may be used within the company—and which may not (e.g., DeepSeek or Grok due to data protection or quality concerns)
- An AI governance checklist that must be completed for every new AI tool or project—with questions regarding compliance, security, transparency, and accountability
- The deliberate avoidance of “Unacceptable Risk” and “High Risk” use cases
As a guide, we recommend the Microsoft Guidelines for Responsible AI, which provide comprehensive frameworks, tools, and best practices.
Microsoft Purview: The tool for AI governance
Microsoft Purview has evolved into the central platform for data protection, data governance, and AI compliance. Particularly relevant for the AI era:
- Monitoring high-risk AI usage — not only for Microsoft’s own tools, but also for third-party providers such as ChatGPT or Gemini
- Preventing oversharing — detecting when agents access too many data sources
- Data Loss Prevention (DLP) — preventing sensitive data from being copied into unauthorized AI applications
- Compliance Manager with EU AI Act templates — directly linking AI applications to the regulatory requirements of the AI Act
In addition, Microsoft Agent 365 was announced—a specialized tool for managing and monitoring AI agents within the Microsoft 365 ecosystem.
Microsoft Fabric: Secure Data as the foundation for AI
The Microsoft Fabric data platform forms the foundation for secure, AI-enabled data architectures. All data flows into OneLake — and is secured end-to-end by Purview:
- Identity and Access Management
- Roles and Permissions
- Data Masking and Pseudonymization
- Data Loss Prevention
- Data Protection and Governance
One component of Microsoft Fabric is the Fabric Data Agent. It enables organizations to develop AI agents that understand the business context and provide informed, reliable answers based on their corporate data. At the same time, Microsoft Purview ensures end-to-end security—from the data source all the way to the interaction with the end user
Conclusion: Secure AI requires secure data policies
Data security in the age of AI is not a one-time project, but an ongoing process. The good news is that the Microsoft ecosystem—comprising Copilot, Purview, and Fabric—provides powerful tools for deploying AI securely and in compliance with regulations. However, it is crucial that companies actively take responsibility—through clear governance structures, training, and a thoughtful tool strategy.
After all, the bottom line is this: Every user is personally responsible for carefully reviewing AI inputs and outputs. Don’t just copy and paste—check, understand, and then use.
How COSMO CONSULT supports you
- AI Governance Workshop: Strategy, Security, and Governance for Implementing AI in Your Company
- AI Readiness Workshop: Analysis of Your Current Maturity Level and Development of Concrete Actions
- AI Solution Assessment: Joint Development of Tailored AI Solutions
- AI Consulting: Strategic, Efficient, and Sustainable Integration of AI into Your Business Processes
Looking for help with your AI strategy?
Book a free consultation with our experts.
More similar blogposts:
Found what you were looking for?
Start your intelligent search now





