What happened?
Kötter Security hosted a security conference in Berlin under the theme "State of Security 2026" with the motto "Secure Future – Corporate Protection in the Age of AI." At the Allianz Forum near the Brandenburg Gate, representatives from politics, business, academia, security authorities, and companies gathered to discuss the impact of artificial intelligence on corporate security. Speakers included Prof. Dr. Dennis-Kenji Kipker of the Cyberintelligence Institute and Prof. Key Pousttchi of the wi-mobile Institute for Digital Transformation.
The Details
Friedrich P. Kötter, member of the supervisory board of the Kötter Security Group, emphasized in his welcoming address the symbolic significance of the venue: the Brandenburg Gate represents change, societal upheaval, and new perspectives – attributes that also apply to the security industry. AI is rapidly transforming the economy, society, and security architectures, opening up both opportunities and new risks, dependencies, and responsibilities. It is no longer merely a driver of innovation but is increasingly becoming an essential factor in security management – while simultaneously serving as a tool for attacks.
Marvin Schulz, a member of the German Bundestag and of the Committee on Digital Affairs and State Modernization, said policymakers have a duty to create framework conditions that allow companies to leverage the benefits of AI without risking misuse or economic harm. He described the EU AI Act as an important commitment by Europe, but acknowledged that the law is too complicated, too extensive, and too bureaucratic. In response, adjustments have been made, resulting in what is known as the Digital Omnibus.
Prof. Dr. Dennis-Kenji Kipker warned against failing to engage sufficiently with the technology before deploying AI: "AI integration doesn't mean simply activating a Microsoft Copilot license." Instead, companies must build genuine AI expertise using their own data and determine in which projects AI should actually be deployed. It is equally crucial, he said, to bring the workforce along during implementation.
Prof. Key Pousttchi urged caution regarding the interplay between humans and AI: AI is meant to imitate humans, yet in doing so, something is being replicated that we do not fully understand ourselves. He offered participants three recommendations: never compromise on security, view security as a continuous process rather than a reaction to individual incidents, and always coordinate closely with the IT security provider in the event of an emergency.
Dr. Carolin Schilling-Schulz, attorney and partner at Arnecke Sibeth Dabelstein, pointed to additional regulatory requirements such as the NIS2 Directive, which must be observed alongside the EU AI Act. Companies need to integrate transparency, security, and compliance requirements into existing processes at an early stage. Other speakers included Ralf Schneider (Deutsche Telekom Security GmbH), Franziska Weindauer (TÜV AI.Lab), and Matt Kish (Siemens AG Corporate Security).
Analysis
The conference made clear that corporate security is at a turning point: AI is no longer merely a tool for increasing efficiency but is increasingly acting autonomously while simultaneously becoming a weapon for attacks itself. This dual role confronts security officers with the task of more closely integrating physical and digital protection concepts, as the boundaries between the two areas are becoming increasingly blurred, according to Friedrich P. Kötter. For the security industry as a whole, this represents a paradigm shift: away from purely physical and perimeter security, toward holistic resilience strategies that equally encompass technical systems, data security, and legal compliance.
The regulatory framework – the EU AI Act and the NIS2 Directive – further illustrates that corporate security is increasingly becoming a matter of strategic corporate leadership, not merely operational implementation. The criticism of the EU AI Act as overly bureaucratic, combined with the Digital Omnibus as a corrective measure, shows that the political instruments are still being fine-tuned – for companies, this means continued uncertainty in practical implementation.
Practical Tips
- Don't reduce AI integration to merely activating software licenses; instead, build genuine AI competencies within the company using your own data.
- Before deployment, clearly define which projects and processes would actually benefit from AI integration.
- Actively involve employees in the AI rollout to enable meaningful collaboration between humans and AI.
- View security as a continuous process rather than merely reacting to individual incidents – an appropriate, up-to-date security level must be maintained permanently.
- Define clear, well-thought-out processes for coordination with the IT security provider so that a swift and coordinated response is possible in an emergency.
- Treat regulatory requirements such as the EU AI Act and NIS2 Directive as a strategic component of corporate development from the outset, rather than as an afterthought.
Outlook
Marvin Schulz pointed to the new generation in the German Bundestag, which is open to expert input from the business community, and explicitly invited conference participants to engage in dialogue with policymakers. This suggests that the further development of the regulatory framework – for instance, in the course of the Digital Omnibus – will remain a topic of discussion in the coming months and years. For companies and security providers, this means that both adapting technically to AI-driven threats and monitoring legal developments surrounding the EU AI Act and NIS2 Directive must remain on the agenda. The discussions at State of Security 2026 suggest that corporate security will need to be understood increasingly as an interdisciplinary interplay of technology, law, and organization in the future.