World Congress 2026 Europe • Jul 10, 2026 • Session details

Your Enterprise RAG Has No Legal Basis

David Klemme , Tilman Mürle

Your general-purpose enterprise RAG chatbot is fundamentally violating GDPR. Discover how architecting purpose-scoped routing layers can rescue your AI tools and enforce legal compliance by design.

Pause
Mute Enter Fullscreen
#1 about 3 min

Introduction to building the enterprise chatbot demo

The hosts introduce the session and prepare to live-code a standard enterprise chat application.

#2 about 3 min

Scaffolding the chatbot application using Vercel AI SDK

The underlying application scaffolding uses a subagent to generate standard components via Vercel AI SDK and Tailwind.

#3 about 3 min

Enforcing quality standards using context and subagents

Knowledge graphs provide context to the agent to enforce production standards and fulfill custom quality gates.

#4 about 4 min

Selecting Anthropic models and anticipating UI styling updates

Claude Sonnet is selected for inference speed over Opus while waiting for the interface styles to compile correctly.

#5 about 2 min

Testing the retrieval application against a vendor proposal

An uploaded vendor proposal demonstrates how the generic application retrieves specific answers from the provided context.

#6 about 3 min

Why general-purpose chatbots violate GDPR purpose limitation

Standard general-purpose RAG architecture fundamentally breaches GDPR guidelines because it lacks a documented, limited legal purpose.

#7 about 3 min

Designing a purpose-scoped architecture for legal compliance

The system needs to map requests through a bot picker and an explicit legal configuration before accessing language models.

#8 about 3 min

Defining usage boundaries and legal basis for auditors

Organizations must proactively govern and document access constraints for specific personal data before execution to satisfy compliance auditors.

#9 about 5 min

Refactoring the chat interface to enforce documented use cases

Developers must integrate a frontend selection layer that enforces organizational limits on data processing and establishes explicit usage guidelines.

#10 about 5 min

Communicating constraints to users and finding compliance resources

Organizations must explicitly collect user consent and communicate limitations within the interface to maintain data accountability.

Matching moments

3:06 min

Handling compliance, logging definitions, and AI agent output

Juraci Paixão Kröhling Juraci Paixão Kröhling · World Congress 2026 Europe

5:50 min

Answering questions on compliance, architecture, and cultural adoption

Agur Jõgi Agur Jõgi · World Congress 2026 Europe

1:40 min

Addressing data sovereignty and compliance blind spots within AI

Sebastian Kister Sebastian Kister · World Congress 2026 Europe

2:43 min

Setting effective guardrails for enterprise agentic AI adoption

Julia Kordick Julia Kordick · Coffee With Developers

4:17 min

Navigating emerging AI legal frameworks and business risks

Kilian Kluge +1 · World Congress 2022

3:10 min

Balancing rapid artificial intelligence development with strict compliance regulations