Why does data sovereignty matter for AI threat simulations?
As generative AI accelerates the volume and realism of social engineering, enterprise security teams are re-evaluating how employee risk data is stored and processed. AI-driven threat platforms process sensitive internal telemetry, including target employee lists, organizational hierarchies, phone numbers, role descriptions, and individual interaction logs. When a corporate threat simulation provider operates under US corporate jurisdiction, European organizations face significant regulatory exposure under cross-border data transfer laws.
The core friction stems from the conflict between US surveillance statutes and European data protection law. Under Section 702 of the Foreign Intelligence Surveillance Act (FISA 702) and the Clarifying Lawful Overseas Use of Data Act (CLOUD Act, 18 U.S.C. § 2713), US federal authorities can compel any company subject to US jurisdiction to disclose data within its possession, custody, or control. Because legal control follows the corporate parent rather than physical server geography, hosting data in European cloud regions does not exempt a US-headquartered vendor from US court orders. This extraterritorial reach directly clashes with Article 48 of the EU General Data Protection Regulation (GDPR), which prohibits disclosures based on foreign judicial orders absent an international agreement.
- Legal control test: US legal process reaches data within a provider's possession, custody, or control regardless of whether that data is stored inside or outside the United States.
- Direct statutory conflict: Complying with a US CLOUD Act order forces a provider into a violation of GDPR Article 48.
- Gag order constraints: US disclosure requests frequently include non-disclosure orders under 18 U.S.C. § 2705(b), preventing notice to European data subjects.
To navigate this legal exposure without sacrificing modern AI capabilities, multinational organizations increasingly adopt a two-vendor strategy. Under this model, US operations rely on domestic platforms tailored to North American regulatory norms, while European entities deploy sovereign platforms hosted on infrastructure like the STACKIT Marketplace to maintain strict compliance with EU standards.
How do sovereign DACH platforms and Adaptive Security approach AI-driven threats?
While legacy awareness tools relied on static template libraries and passive video modules, modern security platforms use artificial intelligence to emulate real-world attack vectors. However, Adaptive Security and sovereign European providers differ significantly in platform architecture, threat focus, and regional localization.
Adaptive Security, based in New York, has established significant scale in the North American market, raising $146.5 million to date, including an $81 million Series B led by Bain Capital Ventures with participation from NVentures, the OpenAI Startup Fund and Andreessen Horowitz. Its offering centers on a library of more than 1,000 training resources with an AI content creator, localized across dozens of languages with jurisdiction-specific compliance tracks. In contrast, specialized European platforms focus heavily on open-source intelligence (OSINT) profiling and continuous multi-channel execution across email, SMS, voice, and video.
| Platform Capability | Adaptive Security | revel8 Platform |
|---|---|---|
| Headquarters & Legal Jurisdiction | United States (New York) | Germany (Munich) |
| Cloud Infrastructure | Hosting regions not publicly documented | Sovereign STACKIT Cloud in Germany |
| Total Capital Raised | $146.5 million | European Venture Capital |
| Simulation Channels | Multi-channel, plus a separate cloud email security product | Continuous Multi-Channel (Email, SMS, Voice, Video) |
| Reporting Granularity | Per-person, team and group risk scores | Default Group Anonymization (min. 5 users) |
| Target Market Alignment | US Enterprise Focus | DACH & EU Enterprise Focus |
For organizations addressing multi-vector social engineering, channel coverage is a critical evaluation criterion. Synthetic voice cloning and vishing require regional voice models and local dialect nuance, which is a different question from how many languages a content library lists. The revel8 Platform natively integrates multi-channel simulations, using OSINT data to mirror real attack surfaces across European business contexts.
What does real EU AI Act compliance look like for deepfakes?
Deploying generative AI to simulate threats inside an enterprise introduces strict regulatory responsibilities under the European Union Artificial Intelligence Act (EU AI Act). Organizations cannot rely on generic vendor assurances or basic website privacy badges; deployers of AI systems face explicit statutory obligations designed to protect worker rights and data integrity.
Article 26 of the EU AI Act sets out the obligations of deployers of high-risk AI systems, from human oversight to log retention and worker information. Organizations using AI to generate simulated interactions must establish verifiable operational safeguards prior to putting systems into workplace service.
- Worker notification: Before putting a high-risk system into service at the workplace, employers must inform workers' representatives and the affected workers that they will be subject to it.
- Automatic log retention: Deployers must keep the logs the system automatically generates for a period appropriate to its purpose and at least six months.
- Human oversight protocols: Natural persons with the necessary competence, training and authority must be assigned to oversee the system, and use must be suspended where a risk is identified.
- Data Protection Impact Assessment (DPIA): Deployers must use the provider transparency information supplied under Article 13 to carry out their DPIA under GDPR Article 35.
Substantive compliance also requires verifiable local governance artifacts. European enterprises must execute a formal Data Processing Agreement (Auftragsverarbeitungsvertrag — AVV) governed by EU law, appoint a dedicated European Data Protection Officer (DPO), and ensure alignment with mandatory NIS2 requirements to satisfy statutory audit scrutiny.
Why is German employee consent (KUG Sec. 22) critical?
Simulating advanced social engineering attacks often involves generating synthetic audio or video representations of company executives and staff. In the DACH region, synthesizing an individual's likeness without robust legal governance introduces significant corporate liability under personality rights legislation.
Section 22 of the German Artistic Copyright Act (Kunsturhebergesetz — KUG § 22) establishes that a person's likeness may only be distributed or publicly displayed with the consent of the person depicted. Creating deepfake avatars using unverified public tools or self-service features therefore creates immediate legal exposure if an employee's voice or likeness is cloned without documented, freely given consent that also satisfies GDPR standards for processing personal data.
To mitigate civil liability and regulatory fines, enterprise threat platforms must enforce strict deepfake governance. This includes role-based access controls for asset generation, clear synthetic watermarking, and mandatory deletion duties that remove personal training assets immediately upon campaign completion. Securing explicit consent ensures that realistic threat exercises build employee resilience without compromising individual privacy rights or triggering legal disputes over spear phishing simulations.
How does platform design impact your works council agreement?
In Germany, Austria, and Switzerland, rolling out any system that monitors employee behavior requires close coordination with worker representatives. Under Section 87 of the German Works Constitution Act (Betriebsverfassungsgesetz — BetrVG), the works council (Betriebsrat) possesses mandatory co-determination rights regarding technical devices intended to monitor employee conduct or performance.
Attempting to negotiate a works council agreement (Betriebsvereinbarung) with a platform designed primarily for US management oversight often leads to friction. Standard US management dashboards frequently aggregate individual failure metrics, exposing specific users to performance monitoring. In contrast, platforms designed for DACH compliance incorporate privacy-by-design safeguards directly into the database architecture.
- Default group-level anonymization: Individual performance tracking is disabled by default, reporting data only in aggregate groups with a mandatory minimum threshold of five employees.
- Pseudonymization by default: user identifiers are pseudonymized at the database layer, so managers see group results rather than named individuals. Pseudonymized data remains personal data under the GDPR and stays inside the customer tenant.
- Strict tenant isolation: All data processing occurs exclusively within the customer's isolated cloud tenant, ensuring employee telemetry is never used to train global AI models.
By embedding default group anonymization into the core platform, security leaders can provide works councils with concrete legal guarantees. This structural approach accelerates Betriebsvereinbarung sign-offs while maintaining measurable risk metrics like the Human Firewall Index across the organization.
Which AI security platform is the right fit for your enterprise?
Selecting between Adaptive Security and sovereign European platforms depends on an organization's corporate structure, primary geographic exposure, and regulatory mandates. Both platforms offer advanced generative AI simulation capabilities, but they serve distinct operational profiles.
- Adaptive Security is best suited to North American enterprises and purely US-headquartered multinationals requiring broad module catalogs, extensive vendor funding scale, and direct integration into US-centric tech stacks.
- The revel8 Platform is best suited to DACH Mittelstand enterprises, DAX organizations, and European entities subject to NIS2, GDPR, and works council co-determination that require sovereign data residency on STACKIT in Germany and localized threat patterns.
For global enterprises managing diverse regional requirements, deploying a dual-vendor model offers a pragmatic solution. Using Adaptive Security across North American business units preserves US vendor alignment, while standardizing on sovereign platforms across European subsidiaries ensures full compliance with local labor laws and sovereign data protection standards during multi-channel security simulations.
If your security team is evaluating how to build measurable employee resilience against deepfakes and multi-channel social engineering without compromising European data sovereignty, we invite you to consult with our specialists to review our architectural benchmarks and works council documentation.

.avif)



