top of page

Login    ·   Newsletter    ·    Contact

Your AI Tools Cannot Legally Touch Your SAP Data

Published by Maya Data Privacy Ā· July 2026


VISCHER, Switzerland's leading AI law firm, published Part 31 of their AI tools data protection seriesĀ this month. It is the most thorough compliance map of enterprise AI tools we have seen, and if you are a CIO, CISO, or DPO trying to get AI deployed on real enterprise data, you should read it.


The finding that runs through every tool they assess is this: for sensitive personal data, the standard contracts from Anthropic, OpenAI, and Microsoft do not make use legal. Not in most enterprise configurations. Not without significant restrictions and workarounds that most companies are not applying.


VISCHER are very good at describing the problem. What the article cannot offer is a technical solution, because VISCHER is a law firm. That gap is what we want to address here.


What the report actually says

The compliance matrix in Part 31 covers ChatGPT, Claude, Copilot, Gemini, DeepL, and a handful of Swiss alternatives. For each tool, three categories are assessed: use with personal data, use with confidential data, and use with professional secrets.

For Anthropic and OpenAI, the pattern is consistent. The DPA covers standard personal data. It does not cover sensitive categories. Health records, salary data, HR files, customer financial profiles — the contract simply does not extend that far. VISCHER note they are aware of no addenda or workarounds that change this for Claude specifically.


Microsoft Copilot has its own issue. A feature called Flex Routing, introduced recently, processes AI responses in data centers around the world rather than exclusively within the EU Data Boundary. In some configurations this was switched on by default. For any organization with data residency obligations under GDPR, Swiss DSG, or sector regulation, that is not a theoretical concern. It is happening now.


The part of the article that deserves the most attention is the section on agentic AI. VISCHER make the point that it is no longer enough to ask whether a specific AI tool is data-protection compliant. When AI agents connect to enterprise systems through MCP servers, connectors, and APIs, they pull live data into AI pipelines whose contractual coverage has often not been considered at all. Copilot for SAP, SAP Business AI, and a growing number of third-party integrations are doing exactly this today.


The problem with the contract-first approach

The instinct most legal and compliance teams have is to find a better contract. Negotiate an addendum. Get a sub-processor agreement. Check the DPA for the new version of the tool. This approach is understandable, but it does not scale.


VISCHER themselves note that the range of services keeps growing, that contractual terms change constantly, and that provider-specific issues keep emerging. Most companies find the whole thing completely overwhelming. And business pressure to deploy AI anyway means many organizations end up using tools that are legally inadequate for the data they are processing.


The contract route is a maintenance problem. It requires continuous legal resource, it never fully closes the exposure, and it restarts from zero every time a new tool is introduced or an existing one changes its terms. Microsoft's Flex Routing is a good example: a product change, enabled by default, that retrospectively created a compliance issue for customers who had done everything right up to that point.


What actually fixes it

The compliance problem VISCHER describes is a data problem, not a contract problem. And data problems have technical solutions.


SAP systems — S/4HANA, SuccessFactors, Ariba — contain employee records, salary information, customer data, health information, financial profiles. All of this falls into categories that AI provider DPAs do not cover for sensitive data. The moment any of this data enters an AI pipeline, in a standard enterprise configuration, the contract is insufficient.


But under GDPR, properly anonymized data is not personal data. It falls outside the regulation's scope entirely. Which means that if the data is anonymized before it reaches the AI tool, the DPA restrictions on sensitive categories do not apply. Not because you negotiated them away. Because there is nothing to restrict.


This is the fix for the Anthropic and OpenAI scenario. Anonymize SAP data at source, before it enters the pipeline, and the gap in the DPA becomes irrelevant.

It is also the fix for Copilot's Flex Routing. If no personal data enters the Copilot pipeline, data being processed outside the EU Data Boundary is a performance question, not a legal one. The data that travels has no weight under GDPR.


And it is the structural fix for the agentic AI problem, which is the one growing fastest. AI agents connecting to SAP via MCP servers are pulling live transactional data into LLM contexts right now, in enterprises across Europe. The contractual framework governing that data is, in most cases, the same inadequate one VISCHER has already reviewed. An anonymization layer at the SAP data layer means every downstream agent, connector, and AI tool operates on data that is already privacy-safe. It does not matter which AI provider is used, which contract tier is in place, or where the data ends up being processed.


Why this matters beyond the legal question

When data is anonymized at source, the compliance question changes. It stops being "does this AI provider's DPA cover what we are doing" and becomes "is our anonymization technically robust." That is a problem with a definite answer. It can be audited, validated, and certified. It does not require a legal team to monitor every AI vendor's terms of service for changes.


This is what we built Maya for. Not as a test data tool, though that is one application. As data privacy infrastructure for enterprise AI: a layer that sits between SAP and every AI system an organization uses, ensuring that what enters the AI pipeline is already legally safe to use with any tool, under any contract, in any environment.


The enterprises feeling the most pressure right now are the ones where the business wants to deploy AI on real SAP data, the CISO knows the contracts do not cover the exposure, and the DPO has read reports like VISCHER's and has no technical answer to give back. All three are in the same company. None of them have a solution yet.


Read the full report

VISCHER's Part 31 is worth reading in full, including the compliance matrix which covers every major tool across multiple data categories. It is available here: vischer.com/insights/part-31-ai-tools-what-about-data-protection-2026


The authors are Lucian Hunger and Jonas Baeriswyl at VISCHER. The status date is 8 July 2026.


Maya is data privacy infrastructure for enterprise AI. We anonymize SAP data at source so it is legally safe to use with any AI tool, in any environment. If this is a problem you are working on, reach out: info@mayadataprivacy.eu

Comments


bottom of page