On June 11, 2026, AIR Artificial Intelligence Regensburg hosted the online webinar “AI in Office & Administration: Using AI in Compliance with Data Protection Regulations.” The webinar focused on how companies and organizations can make effective use of generative AI in their day-to-day office work without losing sight of data protection, data security, and accountability.
Sarah Bamberger and Luis Knarr from Projekt 29 made it clear that data protection should not be viewed as an obstacle, but rather as a prerequisite for the responsible use of AI. The key issue is not whether to impose a blanket ban or grant blanket permission, but rather what framework conditions must be established to ensure that AI can be used safely and in compliance with the law. This includes clear internal rules, a risk-based classification of use cases, and guidance for employees. A traffic-light system and a checklist can help better assess AI uses and reduce uncertainties in day-to-day work.
It was also emphasized that it is not just the specific tool that matters, but also the licensing model, settings, and how data is actually handled. Business licenses come with different requirements than free versions. Sensitive or personal information must be avoided or pseudonymized. In addition, the generated output should always be reviewed by humans in accordance with the “human-in-the-loop” principle and classified responsibly.
The rule of thumb—“The more sensitive the data, the closer it should be to your organization—and when in doubt, store it locally”—served as a natural transition to the second part of the webinar. Dr. Rüdiger Heimgärtner and Christian Eichelhardt from Intercultural User Interface Consulting focused on the technical aspects of data sovereignty. The central question was: Where does the data end up when AI tools are in use? Through illustrative live demos, various approaches were presented using LM Studio, open-source models, AnythingLLM, Nextcloud, and custom solutions. It became clear that powerful AI applications can also be run locally on your own hardware—without the cloud, data sharing, or subscription costs.
The webinar made it clear that data protection should not be viewed as an obstacle to the use of AI. Rather, it is essential to establish the appropriate organizational, legal, and technical frameworks. This will enable AI to be used in everyday office life in a practical, secure, and responsible manner.



