Responsible AI at SAP is based on three pillars—ethics, security, and compliance

Ethics defines our values, security protects your systems and data, and compliance ensures legal alignment.

placeholder

At SAP, we care deeply about the impact of AI and are convinced that AI unlocks boundless potential for businesses, governments, and society. However, AI may also create economic, political, and societal challenges, depending on how it is used and implemented. This makes responsible AI crucial to foster sustainable innovation, create better products, and deepen customer trust.

SAP delivers AI based on the highest ethical and security standards and streamlines compliance organisation-wide, and has achieved the ISO 42001 certification for AI governance and key SAP Business AI products.

AI Ethics

AI Ethics at SAP is guided by a multi-stakeholder approach and a strong governance framework, coordinated by the AI Ethics Office. These efforts are anchored in SAP’s Global AI Ethics Policy and development standards that drive responsible AI innovation.

AI Security

AI security is crucial to helping protect data from potential threats. Advanced security measures let you use AI technology without compromising data integrity.

AI Compliance

AI compliance ensures adherence to global regulations, providing a secure environment for AI deployments and helping to safeguard your information.

SAP earns ISO 42001 certification for AI governance and provisioning

Setting the global standard for responsible AI with certified governance across Joule, SAP AI Core, and key SAP Business AI solutions.

View the certificate

AI Ethics

Human-centred innovation that augments human capabilities and ensures human agency.

Upholding the highest ethical standards, SAP’s AI Ethics policy is based on the 10 guiding principles of the UNESCO Recommendation on the Ethics of Artificial Intelligence as well as other frameworks and development standards. This set of values guides us to create human-centred AI systems that help respect and augment humans, while remaining under human oversight and following the other guiding principles. SAP is proud to have been acknowledged as a leader in responsible AI multiple times by the World Benchmarking Alliance and sustainableIT.org. Building on this foundation, AI Ethics at SAP will continue to evolve – creating more effective, innovative, and ethical outcomes worthy of trust and tailored to our customers’ needs.

placeholder
placeholder

Our principles are:

  • Proportionality and do no harm.

  • Safety and security.

  • Fairness and non-discrimination.

  • Sustainability.

  • Right to privacy and data protection.

  • Human oversight and determination.

  • Transparency and explainability.

  • Responsibility and accountability.

  • Awareness and literacy.

  • Multistakeholder and adaptive governance and collaboration.

Operationalising AI Ethics across our business

Our internal Global AI Ethics Steering Committee and our external Global AI Ethics Advisory Panel are part of our governance bodies.

Our Global AI Ethics Steering Committee comprises senior SAP leaders who review our approach, processes, and product capabilities to ensure operationalisation and alignment with our policies and guidelines.
placeholder
Arin BhowmickChief Design Officer, SAP
placeholder
Jan BungertChief Revenue Officer for SAP Business AI, SAP
placeholder
Mathias CellariusData Protection Officer, Head of Data Protection and Privacy, SAP
placeholder
Wolfgang DierkerHead of Global Government Affairs & CSR, SAP
placeholder
Claus HolzknechtHead of Customer Data Office, SAP
placeholder
Matthias MedertGlobal Head of Sustainability, SAP
placeholder
Rico ModessChief Audit Executive and Chief Risk Officer, SAP
placeholder
Sarah SchmidtHead of Corporate Strategy Group, SAP
placeholder
Freek StaehrHead of Global Legal Commercial and Operations, SAP
placeholder
Walter SunGlobal Head of AI, SAP
placeholder
Wiebke TheloGlobal Head of SAP Quality Management, SAP
SAP Business AI news

Stay informed on the latest business AI trends, best practices, and innovations from SAP.

Sign up for the newsletter

AI Security

placeholder

At SAP, we have a commitment to protect customer data and the customer business when using Artificial Intelligence

The strategic use of business data is integral to the success of AI, and by leveraging business data responsibly, we not only enhance the capabilities of our AI solutions but also improve outcomes for your business. We remain firm in our commitment to prioritise data privacy and security as we release new AI capabilities.

Your data remains safeguarded within our ecosystem

  • We do not share your data with third-party LLM providers for the purpose of training their models.

  • Where permitted, we may use your data to help innovate and improve our products.

  • SAP’s locally hosted AI keeps your data and workflows in-region—fully controlled and safeguarded by SAP, paving the way to sovereign AI.

Our AI solutions are developed responsibly

  • The same rigorous standards that govern all SAP product development extend to our AI offerings.

  • The ISO/IEC42001 certification is a testimonial of our commitment to responsible AI.

We stand by the security of your data

  • We employ advanced data security measures to protect your personal data at all times with encryption, tenant isolation, data masking, filtering, etc.

  • We track the OWASP Top 10 List of security threats when defining our security mechanisms for generative AI

AI Compliance

placeholder

At SAP, we believe that compliance is necessary to enable safe use of AI for our customers.

SAP derives its AI Governance framework based on best practice standards, guidelines, regulations, and frameworks such as the EU AI Act, NIST AI RMF, NIST CSF, ISO 27002, ISO 42001, ISO42005 and the SAP Global Security Policy.

SAP is ISO/IEC 42001 certified

  • SAP achieved ISO/IEC 42001 certification, validating that our AI management systems meet the standards for responsible development and use of SAP Business AI.

  • The certification covers SAP internal AI governance and key solutions such as Joule, SAP AI Core, and SAP AI Launchpad.

SAP is NIST aligned

  • SAP has achieved Tier 3 alignment with the NIST Cybersecurity Framework (CSF v1.1), underscoring strategically managed, enterprise-wide cyber risk practices.

  • For customers, this translates into enhanced protection of critical data, greater transparency into SAP’s security practices, and access to shared insights and a reusable assessment framework.

Resources

placeholder

AI Ethics and the principles contribute to social sustainability

From an environmental perspective, sustainable AI focuses on developing AI technologies in an environmentally friendly way, including optimising energy usage and using greener infrastructure.

placeholder

AI ethics, security, and compliance

Learn how SAP approaches responsible AI—from safeguarding data and enforcing security controls to helping ensure fairness and meeting regulatory expectations.

placeholder

Putting AI Ethics into practice at SAP

Learn how SAP governs AI ethically, addressing opportunities, challenges, and regulatory advancements.

Frequently asked questions

Customer data can be used to improve existing AI features and functionalities of the SAP cloud service to which the customer has subscribed, subject to the terms of the customer agreement, including the general terms and conditions for cloud services and the data processing agreement.

 

Customer data can be used by SAP to develop new AI features and functionalities, subject to the terms of the product development schedule, which is part of the customer contract.

 

Customers who agree to the product development schedule can monitor in which SAP solutions their data might be used and opt out in the SAP for Me interface.

Customer data remains safeguarded in SAP’s ecosystem. Customer data entered in SAP AI technology is treated in the same manner as all customer data that is entered into the cloud service. Therefore, all rights, duties, and obligations around customer data set forth in the cloud agreement with SAP are honored.

 

Specifically for the usage of data to create new features and functionalities, as per the product development schedule, only authorised named persons in SAP can access specific data.

SAP stands by the security of customer data and does not share customer data with other vendors for the purpose of training or improving their large language models (LLMs) or image models.

When customers use an SAP AI technology that leverages a third party–hosted foundation model, their data is sent to the model provider for processing only and is not stored or otherwise retained by the model provider.

At the end of the agreement, SAP deletes the customer data remaining on servers hosting the cloud service, unless applicable law requires retention. Retained data is subject to the confidentiality provisions of the data processing agreement. Customers can export their data before the subscription term expires.

 

The general terms and conditions for SAP cloud services describe the handling of customer data, and the data processing agreement further describes the processing of personal data.

To promote ethical use of AI, SAP requires that all its user interfaces display a short AI notice when the user is using an AI feature or its result has been created by AI. More complex or high-risk AI features show a more detailed acknowledgment. Icons or messages also let customers know when they are triggering an AI-based action.

Customers seeking official responses to AI security inquiries should refer to the SAP Trust Center or get in touch with their SAP account executive.

SAP is dedicated to aligning our operations with the new regulatory standards outlined in the EU AI Act, which will come into effect in phases. Accordingly, the EU AI Act regulation for prohibited practices according to article 5 has already been implemented. We also monitor the regulatory landscape, implementing acts, and national laws of EU member states.

 

Under the supervision of the SAP Executive Board, a dedicated cross-functional team is enhancing SAP’s existing processes to establish a comprehensive classification process that ensures the fulfilment of applicable requirements.

 

As a B2B company, SAP is focused on how responsibilities and tasks are distributed along the AI value chain. SAP may take on multiple different roles within this value chain, such as provider, deployer, purchaser, or integrator of AI systems, as well as developer of our own AI foundation models.

twitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixeltwitter pixel