The image illustrates the data outflow through the Windows 11 recall function, which, according to experts, poses risks to cyber security and digital sovereignty.

Windows 11: Data protection experts recommend switching because of this AI feature

Written By Sebastian Deck
February 24, 2026

Windows 11 and data protection: Why experts say the recall function poses risks for cyber security and digital sovereignty - and what companies should check now.

What is the "recall function"?

The so-called Recall function of Windows 11 is an AI-supported tool that regularly takes screenshots of the screen content and compiles them into a locally searchable "memory". This makes it possible to find activities even days later via an AI search query. However, this approach also generates a comprehensive log of all visible content on the device,including potentially confidential company information.

Recall is initially deactivated in the basic settings and must be activated by users or administrators. Nevertheless, it is part of Windows systems and could be activated automatically during updates.

 

Why security and data protection experts warn

Critics warn of several key risks:

These points of criticism have already led to developers and organizations independently announcing or providing protective measures - such as browsers that actively block recall screenshot recordings.

Data protection vs. productivity - the debate for decision-makers

For decision-makers in highly regulated industries (e.g. financial services, healthcare or critical infrastructure), compliance and security issues are at the forefront alongside convenience aspects of the function:

  1. Control over data flows: Automatically created screen recordings can contain sensitive personal and company information that is critical for compliance requirements (e.g. GDPR).
  2. Attack surface for threats: Local storage of large amounts of information provides an attractive target for potential attackers, especially if there is physical access or endpoint security solutions are inadequate.

  3. Unclear governance: There is a lack of clear guidelines and technical mechanisms that provide fine-grained control over what is actually stored and which data remains excluded.

Recommendations for corporate use

Cybersecurity and data protection experts currently recommend

  • Clear policies for endpoints: IT teams should define which functions may and may not be activated in productive environments. For sensitive or regulated applications, it may be advisable to deactivate recall on all company endpoints.
  • Technical configuration: Functions that are deactivated by default or can only be activated manually should be consciously controlled, including regular checks for updates.

  • Awareness of data protection settings: Employees need to be made aware of potential risks, especially if they are handed devices with features such as Recall.


Conclusion for decision-makers

The AI-based Recall feature of Windows 11 has opened up a new debate about where the line is drawn between operational productivity enhancement and systematic data collection. While Microsoft emphasizes that all data remains local and is not transferred externally, many data protection experts and security analysts consider the risks to be more serious than Microsoft has communicated.

Particularly in highly regulated industries, decision-makers must carefully examine whether and how such functions are acceptable in productive use - or whether the potential damage caused by the compromise of sensitive data outweighs the benefits.


 

Are you interested in the fully sovereign cloud?

Click here for a free trial period

Picture of Sebastian Deck

Sebastian Deck

Sebastian Deck is Chief Marketing Officer (CMO) at SecureCloud and is responsible for brand strategy, communications and marketing. He has many years of experience in building and leading international marketing teams in consulting, fintech and technology companies. At SecureCloud, he drives brand positioning, thought leadership and lead generation. He also manages go-to-market initiatives and campaigns to position SecureCloud as a leading provider of cyber security and secure cloud services.

Related Articles

NIS2 Readiness...
News & Trends

NIS2 Readiness Quick Check: Test how comliant you are

Windows 11 and data protection: According to experts, the Windows 11 recall function harbors risks for cyber security and digital...

News & Trends

Turning point in the cloud: Europe overtakes the US in sovereign cloud investments

According to a study by Gartner, Europe will overtake North America in terms of spending on sovereign cloud infrastructure as early as...

News & Trends

Blackout Day and Kill Switch – the risks of digital dependency

The picture shows a series of companies, servers and computer centers that are all networked with each other and depend on a few US...