The image illustrates the data outflow through the Windows 11 recall function, which, according to experts, poses risks to cyber security and digital sovereignty.

Windows 11: Data protection experts recommend switching because of this AI feature

Written By SecureCloud
February 24, 2026

Windows 11 and data protection: Why experts say the recall function poses risks for cyber security and digital sovereignty - and what companies should check now.

What is the "recall function"?

The so-called Recall function of Windows 11 is an AI-supported tool that regularly takes screenshots of the screen content and compiles them into a locally searchable "memory". This makes it possible to find activities even days later via an AI search query. However, this approach also generates a comprehensive log of all visible content on the device,including potentially confidential company information.

Recall is initially deactivated in the basic settings and must be activated by users or administrators. Nevertheless, it is part of Windows systems and could be activated automatically during updates.

 

Why security and data protection experts warn

Critics warn of several key risks:

These points of criticism have already led to developers and organizations independently announcing or providing protective measures - such as browsers that actively block recall screenshot recordings.

Data protection vs. productivity - the debate for decision-makers

For decision-makers in highly regulated industries (e.g. financial services, healthcare or critical infrastructure), compliance and security issues are at the forefront alongside convenience aspects of the function:

  1. Control over data flows: Automatically created screen recordings can contain sensitive personal and company information that is critical for compliance requirements (e.g. GDPR).
  2. Attack surface for threats: Local storage of large amounts of information provides an attractive target for potential attackers, especially if there is physical access or endpoint security solutions are inadequate.

  3. Unclear governance: There is a lack of clear guidelines and technical mechanisms that provide fine-grained control over what is actually stored and which data remains excluded.

Recommendations for corporate use

Cybersecurity and data protection experts currently recommend

  • Clear policies for endpoints: IT teams should define which functions may and may not be activated in productive environments. For sensitive or regulated applications, it may be advisable to deactivate recall on all company endpoints.
  • Technical configuration: Functions that are deactivated by default or can only be activated manually should be consciously controlled, including regular checks for updates.

  • Awareness of data protection settings: Employees need to be made aware of potential risks, especially if they are handed devices with features such as Recall.


Conclusion for decision-makers

The AI-based Recall feature of Windows 11 has opened up a new debate about where the line is drawn between operational productivity enhancement and systematic data collection. While Microsoft emphasizes that all data remains local and is not transferred externally, many data protection experts and security analysts consider the risks to be more serious than Microsoft has communicated.

Particularly in highly regulated industries, decision-makers must carefully examine whether and how such functions are acceptable in productive use - or whether the potential damage caused by the compromise of sensitive data outweighs the benefits.


 

Are you interested in the fully sovereign cloud?

Click here for a free trial period

Picture of SecureCloud

SecureCloud

SecureCloud is a German cloud platform for encrypted data rooms, secure data exchange, and digital signatures. Its headquarters and all data centers are located entirely in Germany. SecureCloud is ISO 27001-certified, holds a BSI C5 attestation, and complies with the requirements of the GDPR. Since 2014, SecureCloud has supported more than 6,000 customers in the private and public sectors, including critical sectors such as healthcare, the legal system, public administration, and the financial sector.

Related Articles

News & Trends

250 million euros for the federal government's AI cloud: The Deutschland-Stack goes live

BSI C5:2026, C3A and the EUCS sovereignty grid make digital sovereignty measurable for the first time in 2026. Which certifications...

News & Trends

The Cyber Resilience Act (CRA) makes no exceptions—security is the key to entering the supply chain

The Cyber Resilience Act applies to all organizations, regardless of size. What the CRA requires, when it takes effect, why it makes...

News & Trends

The EU-US data protection framework following ‘Trump v Slaughter’

On June 29, 2026, the U.S. Supreme Court dealt a structural blow to the EU-U.S. Data Privacy Framework. Safe Harbor, Privacy...

News & Trends

White Paper “Confident in 30 Days”: The Easy Transition to Digital Independence

White Paper “Self-Sufficient in 30 Days”: €660,000 in risk due to dependence on U.S. cloud services, a 3-year cost comparison, and a...