KI rechtssicher im Unternehmen nutzen:
Using AI in a legally compliant way in companies: Learnings from the eRecht24 AI Day 2026
Artificial intelligence is no longer a future topic – it’s the present. ChatGPT, Midjourney, GitHub Copilot, and dozens of other tools are used daily in companies. But while the technology is advancing rapidly, the legal understanding often lags behind. The eRecht24 AI Day 2026, held on February 25th in Berlin, addressed precisely this issue.
As a web agency based in Ludwigsburg, we’ve been using AI in projects for quite some time now – from automated chatbots and content generation to code support. Participating in AI Day has broadened our perspective and answered important questions: What is legally permissible? What are the risks? And how can AI be used strategically?

The four pillars: What the AI Day conveyed
The workshop led by lawyer Sören Siebert and his team covered four key areas that are relevant to every entrepreneur.
Legal aspects of AI use
The legal landscape surrounding AI is complex and rapidly evolving. Three sets of regulations currently define the framework.
The EU AI Regulation (AI Act) came into force in 2024 and classifies AI systems according to risk levels. High-risk applications – for example, in medicine, justice, or critical infrastructure – are subject to strict regulations. Most business applications fall into lower risk categories but must still comply with certain transparency obligations.
A key point: Users of AI systems must disclose when content is AI-generated. This applies, for example, to product descriptions, marketing texts, or social media posts. The labeling requirement is not always clear – in many cases, a note in the privacy policy or legal notice is sufficient.
The GDPR remains relevant, especially when personal data is processed. ChatGPT and similar tools transmit input to external servers. If a prompt contains names, email addresses, or other personal information, this poses a data protection problem. The solution: Either conclude Data Processing Agreements (DPAs) with the providers or anonymize data before it is entered into the system.
Das Urheberrecht stellt die dritte große Herausforderung dar. KI-generierte Texte, Bilder oder Code sind nicht automatisch urheberrechtlich geschützt. Das Urheberrecht schützt menschliche Schöpfungen – reine KI-Outputs fallen nicht darunter. Wird KI aber als Werkzeug genutzt und das Ergebnis kreativ überarbeitet, kann ein Schutz entstehen.
Umgekehrt das Problem: Nutzt die KI urheberrechtlich geschützte Werke zum Training, bewegt man sich in einer rechtlichen Grauzone. OpenAI, Google und andere werden bereits verklagt. Als Nutzer haftet man normalerweise nicht für das Training der Modelle – wohl aber, wenn man bewusst geschützte Inhalte reproduziert.
Chancen und Risiken von KI-Systemen
KI bietet enorme Effizienzgewinne – aber nicht ohne Risiken. Der KI Day machte deutlich: Blindes Vertrauen ist gefährlich.
Die Chancen liegen auf der Hand. Automatisierung wiederkehrender Aufgaben spart Zeit und Geld. Content-Erstellung wird beschleunigt – Texte, Bilder, Code entstehen in Sekunden statt Stunden. Datenanalyse und Mustererkennung ermöglichen Einblicke, die manuell unmöglich wären. Personalisierung von Kundenkommunikation skaliert – Chatbots beantworten tausende Anfragen parallel.
Die Risiken sind ebenso real. Halluzinationen – also erfundene Fakten – kommen bei allen großen Sprachmodellen vor. ChatGPT kann mit absoluter Überzeugung Unsinn erzählen. Für rechtliche Dokumente, technische Spezifikationen oder medizinische Inhalte ist das inakzeptabel. Manuelle Prüfung bleibt Pflicht.
Bias und Diskriminierung sind in die Modelle eingebacken. Trainiert auf Internet-Daten, reproduzieren sie gesellschaftliche Vorurteile. Beim Recruiting, bei Kreditvergaben oder automatisierten Entscheidungen kann das rechtliche Konsequenzen haben. Die EU-KI-Verordnung verlangt hier besondere Sorgfalt.
Abhängigkeit von Anbietern ist ein strategisches Risiko. Wer kritische Prozesse auf ChatGPT aufbaut, ist von OpenAI abhängig. API-Preise können steigen, Modelle können abgeschaltet werden, Verfügbarkeit ist nicht garantiert. Für unternehmenskritische Anwendungen sollten Backup-Lösungen existieren.
Datenlecks und Sicherheitslücken bedrohen vertrauliche Informationen. Gibt man Geschäftsgeheimnisse in öffentliche KI-Tools ein, könnten sie in Trainingsdaten landen oder durch Sicherheitslücken abfließen. Sensible Daten gehören nicht in externe KI-Systeme – oder nur in On-Premise-Lösungen mit voller Kontrolle.
KI-Tools, Workflows und Best Practices
Der praktische Teil des KI Days zeigte, welche Tools sich bewährt haben und wie man sie effektiv einsetzt.
Für Textgenerierung dominieren ChatGPT, Claude und Gemini. Jedes hat Stärken: ChatGPT ist am vielseitigsten, Claude besser bei langen Texten und Analysen, Gemini stark bei Google-Workspace-Integration. Die Wahl hängt vom Anwendungsfall ab.
Crucially, prompting makes all the difference. Bad prompts deliver generic results. Good prompts are specific, provide context, and define format and tone. For example, instead of „Write a blog post about AI,“ write „Write an 800-word blog post about the use of AI in medium-sized manufacturing companies. Target audience: CEOs without a technical background. Tone: professional but understandable. Structure: problem, solution, practical example, recommendation.“
Midjourney, DALL-E, and Stable Diffusion are leading image generation tools. The quality is now impressive – but caution is advised for commercial use. The legal situation is unclear, especially for images resembling real people or protected trademarks. It works well for stock photos and illustrations, but human post-processing is recommended for critical marketing campaigns.
Code assistants like GitHub Copilot or Cursor significantly accelerate development. However, the generated code must be understood and reviewed. Security vulnerabilities, inefficient algorithms, or license violations may be present. AI is a tool, not a replacement for developer expertise.
Best practice from the workshop: Iterative use. Start with a rough prompt, check the result, and refine it. AI is a partner, not a one-off generator. Three to five iterations are normal for high-quality outputs.
Second best practice: Human-in-the-loop. AI generates, humans review and refine. This combination delivers the best results – faster than purely manual, and of higher quality than purely automated.
AI use cases in marketing, agencies and SEO
For agencies and marketing teams, AI is already part of everyday life. The AI Day showed where it truly adds value.
Content creation is the most obvious use case. Blog posts, social media texts, product descriptions – AI drastically reduces creation time. Important: The output is rarely directly usable. AI delivers drafts that then need to be refined. Nevertheless, the time savings are between 50 and 70 percent.
SEO optimization benefits from AI-powered keyword research and content analysis. Tools like SurferSEO or Frase use AI to suggest optimal content structures. Meta descriptions, title tags, and alt text can be generated automatically—provided they are reviewed. Google recognizes generic AI-generated texts and ranks them lower.
Personalization of marketing campaigns scales with AI. Email texts can be automatically adapted for different target groups. Landing pages are dynamically generated based on user behavior. A/B testing runs automatically. ROI increases measurably.
Social media management is becoming more efficient. AI tools create post variations, suggest optimal posting times, and analyze engagement. Caption generation for Instagram or LinkedIn saves time daily. However, human oversight is still necessary to ensure brand consistency and quality.
Chatbots and customer service have been discussed extensively. At ip2C, we focus precisely on this – our FAQ chatbot uses OpenAI to automatically answer customer inquiries. The advantages: 24/7 availability, immediate responses, and relief for the support team. The disadvantage: AI often struggles to understand complex or emotionally charged inquiries. The solution: Hybrid approaches where AI handles standard questions and escalates complex cases to human agents.
What does this mean for companies in the region?
Small and medium-sized enterprises (SMEs) in Baden-Württemberg – in Ludwigsburg, Stuttgart and the surrounding area – face the challenge of using AI strategically without incurring legal risks.
Many companies are already using AI tools, often without realizing it. Microsoft 365 Copilot, Google Workspace with Gemini, Canva with Magic Design – AI is integrated everywhere. The question is not whether to use it, but how to use it consciously and legally.
Three recommendations from AI Day:
First: Create transparency. Document which AI tools are used in the company. Review the data protection policies. Conclude data processing agreements. Inform employees about proper usage.
Second: Establish guidelines. Define what is allowed and what is not. Are employees allowed to enter customer data into ChatGPT? No. Are they allowed to use AI for internal brainstorming? Yes. Clear rules prevent violations.
Thirdly: training and further education. Most employees only have a superficial understanding of AI. Workshops on effective prompting, legal boundaries, and best practices quickly pay for themselves. The productivity gains far outweigh the training costs.
Our learnings and practical implementation
What are our agency’s key takeaways from AI Day? Three key insights.
First: Legal certainty is not an obstacle, but a competitive advantage. Customers value service providers who implement AI projects in compliance with the GDPR. Those who are knowledgeable gain trust. Participation in AI Day demonstrates this expertise.
Secondly: AI doesn’t replace expertise, it enhances it. Our chatbots work because we understand the technology and integrate it effectively. AI-generated content works because we refine it editorially. The combination of human know-how and AI efficiency is unbeatable.
Thirdly, on-premise solutions are becoming more important. For customers with high compliance requirements – banks, healthcare providers, public sector clients – the OpenAI API is insufficient. Self-hosted LLMs like Llama 2 or Mistral are becoming more relevant. We are actively evaluating these options for future projects.
AI Regulation and Article 4: What’s in store for us?
An important note on the certificate of participation: The certificate does not constitute proof of AI competence according to Article 4 of the AI Regulation. What does this mean?
Article 4 of the EU AI Regulation requires demonstrable competence of the individuals involved in high-risk AI systems. This primarily concerns developers and operators of such systems – for example, in healthcare, biometric identification, or critical infrastructure.
Article 4 is not relevant for most business applications. A chatbot on a company website is not a high-risk system. Neither is content generation for marketing purposes. Nevertheless, its mention shows that legislators take AI expertise seriously. In the future, proof of competence could be required – similar to how data protection officers are certified today.
Those who pursue further education early on are prepared. The eRecht24 AI Day is a step in this direction – even if it doesn’t yet constitute an official certification.
Conclusion: AI is not a hype, but a tool
AI Day 2026 made one thing clear: AI is here to stay. The technology isn’t perfect, but it’s useful. Used correctly, it saves time and money and opens up new possibilities. Used incorrectly, it poses legal and business risks.
For companies in Ludwigsburg and the surrounding region: Don’t wait, take proactive steps. AI tools are available, often free or inexpensive. Knowledge of how to use them legally is crucial. Those who act now will gain a competitive edge.
At ip2C, we see ourselves as a partner in this process. From strategic consulting and technical implementation to ongoing optimization – we support companies on their journey to intelligent digitalization.
Do you want to use AI in your company?
Whether it’s chatbot integration, automated content creation, or customized AI workflows – we develop solutions that fit your requirements. GDPR-compliant, field-tested, and economically sound.
Contact us for a free initial consultation: kontakt@ip2c.de or by phone at 07141 309 8714.
Further information about our AI services and reference projects can be found on our website: https://ip2c.de

Raphael Ehm
Ich bin Designer und Entwickler für UX & UI, Web, Print, Corporate Design und Touchscreen Anwendungen. Leidenschaft und ein hoher Anspruch sind zentrale Werte meiner Arbeit.
In diesem Blog finden Sie interessante Themen zu Digitalisierung / Firmeninterne News und besonderen technischen Neuheiten von Raphael Ehm und seinen digitalen Partnern.



