Analytics Legends The knowledge platform for SAP Analytics
Academy module

SAP AI Ethics and Data Privacy in Delivery

SAP AI Ethics and Data Privacy in Delivery — Analytics Legends section illustration for the SAP Analytics knowledge base (concepts, studies, Academy)

As of 2026-09-25

For SAP AI consultants who already configure orchestration pipelines (M325) and need to know when SAP's own ethics and privacy rules change what they owe a client. Covers SAP's Global AI Ethics Policy (updated September 2024, aligned to the UNESCO Recommendation on the Ethics of AI) and its Handbook's ten principles, split between AI development teams and governance; the red-line / high-risk / standard triage and the two named SAP governance bodies; the generative AI hub's data-privacy defaults (no personal data in prompts, GDPR and ISO 27001 alignment, SOC 1/2 certification); the orchestration masking module's anonymization-vs-pseudonymization choice (irreversible MASKED_ENTITY vs reversible MASKED_ENTITY_ID); input/output content filtering with Azure Content Safety and Llama Guard 3; and the EU AI Act's Article 15 enforcement date (2027-12-02, Digital Omnibus) alongside GDPR's Article 5(2) documentation principle. Three exercises and a self-assessment close the module.

What you will learn

  • Explain SAP's Global AI Ethics Policy and its ten Handbook principles, split between development-team and governance responsibilities
  • Apply SAP's red-line / high-risk / standard triage to a proposed Joule use case and recognise when a routine-looking case reclassifies
  • Name SAP's AI ethics governance bodies and translate their role into a client-side review function
  • Choose anonymization versus pseudonymization in the orchestration service's data-masking module and justify the choice by what must never be reversible
  • Configure input and output content filtering for different risk profiles using Azure Content Safety and Llama Guard 3
  • State the EU AI Act's 2027-12-02 Article 15 enforcement date and GDPR's Article 5(2) documentation requirement, and connect both to a delivery checklist

Module overview

Who this is for. You have used the generative AI hub in M325 and understand grounding, masking and filtering as pipeline steps. This module answers a different question: not how the masking module works, but when you are required to use it, who at SAP already decided your use case needs it, and what you personally sign up for when you configure a Joule agent for a client. It stays inside what SAP has actually published — its own ethics policy, its own privacy statements for the generative AI hub, and the orchestration modules that operationalise both — not a general AI-ethics survey with an SAP label attached.

Prerequisites

  • M325 — SAP Generative AI Hub hands-on (orchestration, grounding, masking, filtering)
  • M333 — AI & LLM Fundamentals for SAP Consultants
  • Basic familiarity with GDPR terminology (personal data, controller/processor, DPA) is helpful but not required

Outcomes

  • Correctly triage a proposed Joule use case as red-line, high-risk or standard and justify the call against SAP's published criteria.
  • Configure an orchestration masking strategy that matches whether a value must be recoverable downstream or never recoverable at all.
  • Design input and output content filtering that reflects the actual risk on each side of a given conversation.
  • Produce a short delivery-checklist entry connecting a use case's classification to its EU AI Act and GDPR documentation obligations.

Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.

Open in the app →