Version: 2026-06-05
Note: This recommendation is not legal advice. It describes technical and organisational triggers where privacy, legal, project management, or the customer should be involved.
Summary
- The focus is Germany and EU customer work.
- Do not prompt away legal questions: clarify, document, escalate.
- Except for credentials, almost anything can touch AI: code, documentation, tickets, personal data, production data, contracts, prices, and customer details.
- Credentials and secrets remain taboo.
- The technical lead recognizes the trigger; project management coordinates; privacy, legal, or the customer are involved depending on risk.
- AI as a development tool is internal tool use; AI as a product feature is a compliance topic.
- Confidentiality applies to AI context too.
- License and copyright risks are normal review topics and are escalated when something looks suspicious.
Topic
Technical triggers for legal, privacy, compliance, or customer clarification in AI-assisted development work.
Starting Point
Developers often see the practical situation first: a prompt needs customer data, a tool wants repository access, an AI feature is planned for end users, a generated snippet has unclear origin, or a vendor changes terms.
The developer does not need to solve the legal question alone. The developer needs to recognize the trigger and escalate it early.
Risk
Legal and privacy questions can be hidden inside technical work. If they are treated as prompt-engineering problems, the project may lose traceability and customer trust.
Recommendation
Define trigger points. Personal data, customer-confidential information, production data, contracts, pricing, credentials, AI product features, cross-border processing, unclear licensing, and vendor data processing are not purely technical details.
When a trigger appears, document the situation and involve the right role. That may be the technical lead, project lead, data protection contact, legal contact, or customer contact.
Review Checklist
- Could personal data be involved?
- Could confidential customer information be involved?
- Is AI used only as a development tool or as part of the product?
- Are secrets fully excluded?
- Is vendor data processing understood?
- Is generated content of unclear origin?
- Is the customer contract relevant?
Wall rules
Do not prompt away legal questions: clarify, document, escalate.
Personal data makes AI use a privacy topic.
AI in the product is compliance, not just engineering.
Confidentiality applies in prompts too.
Secrets remain taboo.
Open questions for a project
- Who is responsible for privacy clarification?
- Which customer contracts restrict AI use?
- Which AI use cases are internal tools and which are product features?
- How are legal or privacy decisions documented?