Questions & answersHow can sensitive data be processed with AI?
Not with a ban and not with trust in the provider, but with a rule that comes before the technology.

Sensitive data can be processed with AI if three things are settled: which data belongs to which class, which operating path is permissible for each class, and who may see what in the system. For confidential and personal data that usually means local operation on your own hardware or a European environment with a processing agreement. The ban does not work, the rule does.
When does it make sense?
Whenever the actual benefit of the AI lies in the sensitive data: customer correspondence, contracts, HR cases, engineering data. That is exactly where summarising, classifying and drafting save the most time. And exactly where cloud solutions fail on data protection and trust. So the question is not whether, but how.
When does it not make sense?
When the processing has no clear purpose. GDPR requires purpose limitation, and a system meant to "have a look" at what is in the HR data has no legal basis. It also does not make sense to give sensitive data to a cloud service just because it is convenient, without a processing agreement and without a rule.
Prerequisites
- Data classification. Four classes from public to strictly confidential, with the permissible operating path per class.
- Operating path. Local on your own hardware for the confidential, European environment with a processing agreement for the medium, provider cloud only for the non-critical.
- Permissions concept. Login via the directory, roles, separate knowledge bases. The AI only shows what the user may see.
- Documentation. Record of processing, purpose, legal basis, retention periods. That belongs to the rollout, not to the aftermath.
Options
With a local language model you can summarise customer enquiries, create reply drafts, check contracts for deadlines and clauses, structure HR documents. All in your own network, without transfer to third parties. For analyses without personal reference, anonymisation can open the way into a rented environment. And for processes with approval steps you can define that the AI only prepares and a person decides.
Benefits
- The most valuable use cases become possible instead of failing on data protection.
- Data protection officer and works council support the solution because the rule is documented.
- Shadow AI with private accounts loses its reason.
- Customer audits and evidence become easier because no transfer takes place.
Limits and risks
Local does not automatically mean secure. Without a permissions concept everyone sees everything, including through the AI. A language model can carry content from one knowledge base into answers for other users if the separation is missing. And logs of AI usage are themselves personal data that must be regulated. The EU AI Act also requires that employees know when they are working with AI.
Example
The customer service of a utility wanted replies to customer emails prepared. The emails contained names, addresses and contract data. A cloud service was not an option for the data protection officer. After a data classification, a local model was set up with a knowledge base of text blocks and tariff information. The AI created drafts, employees checked and sent. No data transfer, no processing agreement, one documented rule. The data protection officer approved.
Frequently asked
May personal data go into a language model?
Yes, if legal basis, purpose limitation and operating path are right. Local operation avoids transfers to third parties and with them the hardest questions. With cloud services you need a processing agreement and suitable guarantees.
Does anonymisation help?
For some cases yes, for example analyses. For customer correspondence or HR cases it rarely works because the context is needed. Then local operation is the better route.
What is a data classification?
A division of all information into four classes, from public to strictly confidential, with a rule per class on which operating path is permissible. Worked out in a few hours, with business, IT and data protection at the table.
What does the EU AI Act require for internal AI?
Internal assistant systems usually fall into the lowest risk class. Obligations on transparency and competence still apply. If the system touches HR decisions or safety, that looks different and should be checked beforehand.
Does the works council have to be involved?
If the system could record the behaviour or performance of employees, yes. Early involvement with a clear permissions concept prevents later conflicts.
Conclusion
Sensitive data and AI are not mutually exclusive. They need a rule before the technology: data class, operating path, permissions, documentation. Anyone who settles these four points can implement the most valuable use cases, in a way that data protection and works council support.
Related questions: Cloud AI or local AI: what fits your company?, Can you run ChatGPT locally in a company?, Secure AI environments in Europe, what matters in 2026
Local AI for business
Language models on your own hardware, GDPR-compliant and without vendor lock-in. Options, comparison with the cloud and the path to a pilot.
To the solution: local AI