Einblick in die hochmoderne Fertigung der CiS electronic GmbH in Krefeld: KI-gestützte Prozesse steigern Effizienz, Qualität und Innovation in der Kabelkonfektion. © CiS electronic GmbH

Research

AI Agents

Your Data, Your Edge — Why AI requires a new mindset

Article by

neuland AI

·

We need a new awareness of our data and our knowledge. They are the most valuable thing your company owns.

Your corporate data is not really safe with hyperscalers and AI is making the problem dramatically bigger

An objectively grounded wake-up call for decision-makers who want to use AI productively and responsibly.

Imagine you invite a consultant into your company. He is brilliant, fast, always available and costs almost nothing. He helps you write proposals, review contracts, optimize formulas, analyze customer data and formulate strategy papers. What you may overlook: this consultant is not sitting in your office. He is sitting in a data center in Virginia or Oregon. He works for dozens of your competitors at the same time. And he forgets nothing.

Welcome to the reality of AI-supported corporate work in 2026.

The most valuable thing your company owns and how it drains away every day

Karl-Heinz Land, CEO of neuland.ai, sums up the central problem:

"Anyone who builds the AI core of their company on an opaque, global black-box infrastructure will ultimately lose control — over data, over compliance, over their own value creation."¹

And he goes further:

"Sovereign AI is far more than a mere protective mechanism against data outflow or technological dependency. It is the key to keeping value creation, innovation and social participation in one's own country, and thus the foundation for sustainable growth, resilience and our future prosperity."²

These two sentences describe precisely what is at stake. It is not only about protecting individual data sets. It is about whether the knowledge your company produces every day — corrections, clarifications, process logic, experience — remains within your company or drains away as "intelligence exhaust" into the systems of American corporations, where it improves models that are just as available to your competitors as they are to you.

The data security company Cyberhaven analyzed the behavior of more than 1.6 million employees: 4 percent have entered confidential company data into ChatGPT, 11 percent of the data pasted in is confidential — source code, R&D materials, customer data. More recent figures show: 39.7 percent of all AI interactions contain sensitive data.³ This is not the failure of individual employees. This is a structural problem.

Why AI is a different risk than email and cloud storage

AI systems are designed to learn from data. If you enter a formula, a strategy paper or a customer contract into a public AI system, the data can flow into the improvement of the model, be viewed by human reviewers and become part of a training process that improves the model for all users — including your competitors. This is not a worst-case scenario. This is documented standard practice in most consumer plans.

ChatGPT Free/Plus/Pro uses conversations for model improvements by default — opt-out required, data storage primarily in the USA.⁴ Google Gemini Free allows human reviewers to read prompts and use them for training.⁵ Meta AI has even used conversations for advertising personalization since October 2025; external contractors have demonstrably had access to user conversations.⁶ Anthropic Claude stores consumer data for up to two years, and in the case of trust & safety flags for up to seven years.⁷

Enterprise plans offer significantly better guarantees, but most employees do not use the enterprise plan.⁸

Three cases that explain everything

Samsung, April 2023: Less than 20 days after the internal approval of ChatGPT, three separate data leak incidents occurred: engineers uploaded proprietary source code, an employee entered internal meeting notes. At the time of the incidents, OpenAI used user inputs for model training by default. Samsung's response: a complete AI ban on company-owned devices, development of its own internal tool.⁹

Figma, July 2024: The new AI feature "Make Designs" produced near-identical copies of Apple's Weather App on request — reproducible multiple times.¹⁰ ¹¹ At the same time, it became known that Figma intended to train its models on user data by default — on designs that are often under NDA. The training was anchored in the terms and conditions, but not prominently communicated.¹² The case shows: AI models can memorize content so precisely that they reproduce it and one customer's knowledge can benefit the next.

International Criminal Court, February 2025: Trump imposed sanctions on ICC Chief Prosecutor Karim Khan.¹³ His official Microsoft email account was blocked. Khan had to switch to ProtonMail.¹⁴ Microsoft President Brad Smith denied a direct blocking — later reports suggest that the ICC itself deactivated the account, out of fear of compliance measures.¹⁵ The consequence was unambiguous: On 31 October 2025, the ICC switched from Microsoft Office to OpenDesk — developed by ZenDis in Germany.¹⁶

This last case illustrates the deepest risk: it is not about hackers or negligence. It is about a structural dependency that can become a weapon in an emergency. The CLOUD Act (2018) allows US authorities to demand that US companies grant access to data stored on servers worldwide — including in the EU. Microsoft's own legal director admitted before the French parliament that no technical or contractual agreement can override the CLOUD Act.¹⁷ Your data may be located in Frankfurt. It remains subject to US law.

Legal risks: trade secrets lose their protection

The GeschGehG (German Trade Secrets Act) protects trade secrets only in the case of "appropriate confidentiality measures" (§ 2 No. 1). Entering a formula or a strategy paper into an external AI system without contractual protection guarantees can nullify this protected status. Jones Day warns: "These tools pose a potential threat to a company's trade secrets."¹⁸ A US federal court (SDNY) has already ruled: communication with a public AI tool is not protected by attorney-client privilege.¹⁹

Regulators are taking action: the Italian Garante imposed a fine of 15 million euros on OpenAI.²⁰ The EDPS found that the EU Commission itself violated EU data protection law through its use of Microsoft 365.²¹ The BfDI considers a ChatGPT ban in Germany to be possible.²²

The value creation argument: who profits from your data?

In July 2026, Satya Nadella coined the term "Reverse Information Paradox": buyers of AI services pay twice, once with money, once with the proprietary knowledge they reveal through usage. "Models learn from 'exhaust,' the prompts people write, the tools agents use, and especially the corrections people make when the model is wrong."²³

This is exactly what Land means by "intelligence exhaust." And it has an economic policy dimension: European cloud providers hold only 15 percent of the European cloud market.²⁴ 85 percent of the value creation from European data does not remain in Europe. Silicon Valley did not emerge by chance, but because American users bought American products, the value creation stayed in the country and the models got better. Europe can only set this cycle in motion if European companies start buying European solutions. Not out of patriotism, but because it is the only way to finance a competitive European technology industry.

France has understood this: Since 2021, Microsoft 365 has been officially banned in the French state administration.²⁵ 2.5 million civil servants are to switch to sovereign platforms by 2027.²⁶ The ICC is buying OpenDesk from ZenDis.¹⁶ The EU Commission has selected Scaleway for its sovereign cloud.²⁷

The solution: sovereign AI, not less AI

The answer is not to avoid AI. The answer is to use AI sovereignly: with the most powerful models in the world — GPT-5, Gemini, Claude — but in an environment in which your data is not used for training third-party models, no provider employee can view your conversations, data remains in European data centers and a legally binding DPA under the GDPR applies.

The neuland.ai HUB is a German AI management and orchestration platform that delivers exactly that: no training with user data, no employee access, EU data centers, end-to-end encryption, ISO/IEC 27001:2022 (TÜV Rheinland, March 2026), GDPR-compliant DPA, BRAO and DORA compliance.²⁸ ²⁹ And: you are buying from a German company that keeps value creation in Germany.

The decision is due. France has made it. The ICC has made it, after experiencing first-hand what structural dependency means. The question for German and European companies is not whether they should use AI. The question is under what conditions and whether the value creation arising from their data remains in Europe.

All essential statements are substantiated with primary sources. Scenarios and potential risks are identified as such. As of: August 2026.


¹ KI-Plattform - Made in Germany | neuland.ai — "Gartner Top 10 Strategic AI Trends: Warum jetzt die KI-Architektur über Sieg oder Niederlage entscheidet" — KI-Plattform - Made in Germany | neuland.ai

² KI-Plattform - Made in Germany | neuland.ai — "Ökosysteme, Wertschöpfung und die neue KI-Landkarte" — KI-Plattform - Made in Germany | neuland.ai

³ Cyberhaven: "11% of data employees paste into ChatGPT is confidential" (2023) — Data Security For The Agentic Enterprise | Cyberhaven ; Cyberhaven 2025 AI Adoption and Risk Report — Data Security For The Agentic Enterprise | Cyberhaven

⁴ OpenAI: "Data Controls in the OpenAI Platform" — OpenAI Developers ; OpenAI: "How your data is used to improve model performance" — OpenAI Help Center

⁵ Gemini API Additional Terms of Service — ai.google.dev; Google AI Developer Forum: "Are the prompts I submit to Google AI Studio reviewed by a human?" — discuss.ai.google.dev

⁶ Meta: "AI at Meta Terms of Use" — Facebook ; Business Insider: "Meta contractors say they read intimate chats with its AI" (August 2025) — Business Insider - Latest News in Tech, Markets, Economy & Innovation

⁷ Anthropic Privacy Center: "How long do you store my data?" — Home | Anthropic Privacy Center ; Anthropic: "Is my data used for model training?" — Home | Anthropic Privacy Center

⁸ OpenAI: "Business data privacy, security, and compliance" — OpenAI | Research & Deployment

⁹ Bloomberg: "Samsung Bans Generative AI Use by Staff After ChatGPT Leak" (2 May 2023) — Bloomberg - Business News, Stock Markets, Finance, Breaking & World News ; TechCrunch: "Samsung bans use of generative AI tools like ChatGPT after April internal data leak" (2 May 2023) — TechCrunch

¹⁰ TechCrunch: "Figma disables its AI design feature that appeared to be ripping off Apple's Weather app" (2 July 2024) — TechCrunch

¹¹ Figma Blog: "An Update on our Make Designs Feature — A Retrospective" — Figma: The collaborative canvas for design, code, and AI

¹² Hacker News: "Figma defaults to train AI models on personal data" — Hacker News

¹³ White House, Executive Order ICC Sanctions, 6 February 2025 — The White House

¹⁴ Heise, 18 May 2025: "Microsofts E-Mail-Sperre als Weckruf für digitale Souveränität" — heise online - IT-News, Nachrichten und Hintergründe | heise online

¹⁵ Politico EU, 4 June 2025: "Microsoft didn't cut services to ICC" — POLITICO ; The Register, 18 February 2026 — Technology news and analysis | The Register

¹⁶ Handelsblatt, 30 October 2025: "Strafgerichtshof ersetzt Microsoft durch deutsche Lösung" — Handelsblatt - Nachrichten aus Finanzen, Wirtschaft und Politik ; Euractiv, October 2025 — Home | Euractiv

¹⁷ Akave: "The 2026 Data Sovereignty Reckoning" — Akave Cloud: S3-Compatible Object Storage | Zero Egress, Up to 80% Off AWS ; EDPB/EDPS — CLOUD Act Assessment — Home | European Data Protection Board

¹⁸ Jones Day: "Protecting Trade Secrets as Generative AI Evolves" (June 2023) — Home

¹⁹ Akin Gump: "SDNY Rules Communications With a Public Generative AI Platform Are Not Protected by Attorney-Client Privilege or Work Product Doctrine" — Akin, an Elite Global Law Firm

²⁰ Lewis Silkin: "OpenAI faces €15 million fine as the Italian Garante strikes again" (January 2025) — Lewis Silkin - Homepage ; Garante: original decision — garanteprivacy.it

²¹ EDPS press release, 11 March 2024 — edps.europa.eu

²² BfDI: "BfDI launches public consultation on AI models" (2025) — bfdi.bund.de

²³ TechCrunch, 27 July 2026: "Satya Nadella says companies that trust one AI for everything may not survive" — TechCrunch / TechCrunch, 13 July 2026: "Satya Nadella has issued a shocking warning to companies using AI" — TechCrunch ; Satya Nadella: "The Reverse Information Paradox", X, 12 July 2026

²⁴ SRG Research: "European Cloud Providers' Local Market Share Now Holds Steady at 15%" — srgresearch.com

²⁵ DINUM — Cloud au Centre doctrine — numerique.gouv.fr; Legifrance — Circulaire n° 6282-SG, 5 July 2021 — legifrance.gouv.fr

²⁶ AP News, 3 February 2026: "France dumps Zoom and Teams as Europe seeks digital autonomy" — Associated Press News: Breaking News | Latest News Today

²⁷ Scaleway: "Scaleway selected by the European Commission to deliver a sovereign public cloud and AI platform to EU institutions" — European Cloud & AI.

²⁸ KI-Plattform - Made in Germany | neuland.ai HUB User Manual DE 2026-03 (internal document)

²⁹ neuland.ai: "neuland.ai erhält TÜV-Zertifizierungen nach ISO/IEC 27001:2022 und ISO 9001:2015" (25 March 2026) — KI-Plattform - Made in Germany | neuland.ai


Image generated using the neuland.ai HUB.