Skip to main content
“Is AI even possible in a regulated environment? Yes – if you approach it the right way” – BHC GmbH at MedConf Munich
ALM

“Not allowed because of GDPR”? AI and compliance in ALM/PLM

“Can't be done because of GDPR / MDR / TISAX” – and people drop it. Yet most regulations contain no hard ban, just a call to engage seriously with risks.

Automatically translated from German · Read the original

Julian Weyer
Julian Weyer May 18, 2026 · 2 min read
ALM ·ALM ·PLM ·2 min read

“Can’t be done because of GDPR / MDR / TISAX / …” — and then people drop it altogether.

I know that one. I’ve seen it many times. Yet most regulations contain no hard ban, just a call to engage seriously with risks. Yes, that’s hard work, but it’s solvable. Anyone who really reads the standards will usually find room to maneuver.

This applies not just to medical technology. GDPR, ISO standards and industry-specific compliance requirements are rarely real blockers either, but design tasks.

Especially in the ALM/PLM environment — documentation, traceability, review processes — AI support with full compliance is feasible if you approach it the right way. My colleague Benjamin recently put exactly that into a nutshell with this mindset: regulations as a task rather than an excuse.

Takeaway

Regulations such as GDPR, MDR or TISAX are rarely hard bans — they are calls to address risks properly. If you see them as a design task rather than an excuse, you can use AI sensibly and compliantly even in regulated ALM/PLM environments.