# Dr. Oliver M. Duschka > Chief Data Officer at Versicherungskammer (Germany's largest public insurer), based in Munich. PhD in Computer Science from Stanford University. Specialises in AI governance, data governance, and EU AI Act compliance. Builds governance frameworks that enable responsible AI adoption rather than blocking it. ## About Dr. Oliver M. Duschka leads AI and Data Governance at Versicherungskammer. His work focuses on practical EU AI Act compliance — including an AI system registry, risk classification frameworks, and embedded governance workflows. He also leads data governance within the company's Data Driven Transformation programme and regulatory preparedness for FiDA (Financial Data Access regulation). He represents Versicherungskammer in industry regulatory working groups and speaks regularly at conferences on proportionate, embedded AI governance. Earlier career: Engagement Manager at McKinsey & Company (financial services focus), SVP at T-Systems (~750 employees), VP & General Manager EMEA at Unisys, Head of Sales and Customer Success at think-cell, and founding engineer at Socratix (bioinformatics startup, Palo Alto). Education: PhD & MS in Computer Science from Stanford University (Fulbright Scholar, Schlumberger Fellowship), General Management Programme at London Business School, Business Technology Programme at MIT Sloan, BS in Business Administration & Computer Science from TU Darmstadt (German National Scholarship Foundation). ## Expertise - AI Governance and EU AI Act compliance - Data Governance and Data Driven Transformation - FiDA (Financial Data Access) regulatory preparedness - GDPR and AI — legal certainty for model training and data rights - Risk-based AI classification frameworks - Insurance industry AI standards ## Writing The writing index lives at https://duschka.com/blog/ (also linked as "Writing" in the top navigation). Individual essays are listed below. ## Blog Posts - [Frontier Today, EU Tomorrow](https://duschka.com/blog/frontier-today-eu-tomorrow-2026.html): What the US Supreme Court's Trump v. Slaughter ruling (29 June 2026, overruling Humphrey's Executor) means for AI architecture in Europe. EU primary law wires lawful transatlantic data flows to independent oversight — exactly the property the Court has now foreclosed. The adequacy decision's pillars (FTC enforcement, the Data Protection Review Court, PCLOB oversight) are hollowed out, and the General Court's Latombe judgment — the framework's only judicial endorsement — rested on removal protections that no longer exist. Unlike 2015 (Safe Harbour) and 2020 (Privacy Shield), the executive-action repair path is constitutionally foreclosed. The adequacy decision remains formally in force; what has shifted is the weight American safeguards carry in any risk assessment. For AI adoption, a two-by-two grid (personal data × frontier model) isolates one critical quadrant — in insurance largely a health-data quadrant where GDPR Article 9, the AI Act's high-risk regime and financial supervision cumulate. Three observations: the critical quadrant is smaller than it looks; much frontier demand sits in the uncritical quadrant, whose by-product is an eval suite; capabilities diffuse (open-weight models roughly four months behind the frontier). The sequence: develop without personal data on the frontier, formalise the bar with evals, go productive with personal data on the model that clears it. Exit-capable is whoever has evals. - [Is a Straight Line "AI"?](https://duschka.com/blog/straight-line-ai-2026.html): Asks whether ordinary linear and logistic regression — the generalised linear models (GLMs) that have run insurance tariffs, risk models and scoring for decades — count as "AI" under the EU AI Act. Because risk assessment and pricing in life and health insurance sit on the Act's high-risk list, and because there is no middle gear (the narrow exemption does not apply where a model drives a decision about a person), the entire weight of the obligations rests on a single definitional question. The Commission's February 2025 guidelines said regression used to improve mathematical optimisation does not go beyond "basic data processing" and falls outside scope, but the carve-out was conditional and is being tested again; civil society warns of a loophole; and the OECD definition the Act tracks already excludes simple statistical techniques. Notes that BaFin's Julia Wiens argued at insureNXT (May 2026) that common statistical methods should not be swept into the high-risk net. Concludes that good governance classifies by function — autonomy, adaptiveness, inference beyond basic processing — not by label, which is exactly what the Act's own definition turns on. - [Who Decides?](https://duschka.com/blog/who-decides-2026.html): Steve Bannon, Bernie Sanders, Dario Amodei and Pope Leo XIV converged on the same grievance about AI — not safety but legitimacy: a small number of unelected private actors are deciding on everyone's behalf. Argues that "who decides" is two questions — who decides what gets built and released (a hard question, belonging to states and international institutions such as the Council of Europe's Framework Convention on AI), and who decides how AI touches an ordinary life (answerable, because an accountable institution already stands at the point of contact). The EU AI Act answers the second by locating and constraining the decision at the deploying institution; simplification (the Digital Omnibus) should cut procedure that protects no one while keeping the architecture that keeps decisions located and answerable. Closes by noting the Commission's June 2026 appointment of a scientific panel of independent experts and a broadly composed advisory forum — independent judgement placed in the loop, not left to the builders alone. - [When the Adviser Is a Chatbot](https://duschka.com/blog/chatbot-insurance-adviser-2026.html): Argues that AI systems producing individualised insurance recommendations need regulation — and that the AI-specific layer belongs in the EU AI Act (sharpened Article 50 transparency, Annex III extension to consumer-facing insurance agents), not in a national § 34d Gewerbeordnung extension. Frames harmonisation as innovation strategy: 27 national answers is not a market, and EU-wide rules are the precondition for AI investment in Europe — including for insurers' own AI-based distribution channels. - [Why AI Governance Must Be a Design Principle](https://duschka.com/blog/ai-governance-design-principle-2026.html): Notes from the V.E.R.S. Leipzig AI Network on the August 2026 transparency deadline of the EU AI Act, the AI register as both compliance artefact and steering instrument, and why effective AI governance defines what must be ensured (governance) and leaves how to do it to IT. - [Why a Math Prize Ceremony Belongs in an Insurance Company](https://duschka.com/blog/math-prize-insurance-2026.html): Versicherungskammer hosted the Bundeswettbewerb Mathematik 2025 award ceremony. Reflects on the mathematical lineage of insurance and argues that the cognitive foundation of AI governance — the ability to think precisely about uncertainty — is something no compliance checklist can substitute for. - [The Strength We Have in Excess](https://duschka.com/blog/bundesverdienstkreuz-2026.html): Personal reflection on the Bundesverdienstkreuz (Federal Cross of Merit) ceremony for Oliver's father, recognising nearly five decades of civic engagement (Ehrenamt) in the Hessian town of Lauterbach — including refugee coordination, the senior citizens' advisory council, and disability advocacy. - [When AI Makes Movies — and Why That's Not the Interesting Part](https://duschka.com/blog/ai-movies-governance-2026.html): An AI-generated film is impressive, but the AI decisions that matter in insurance — pricing, claims, underwriting — are invisible. That's where governance counts. Discusses the EU AI Act's risk categories and why content generation and high-risk decision-making require different governance approaches. - [What Companies Actually Need from AI Regulation: Legal Certainty, Not Deregulation](https://duschka.com/blog/ai-regulation-legal-certainty-2026.html): Argues that the real barrier to AI deployment isn't overregulation but legal uncertainty. Analyses Baden-Wurttemberg's LDSG amendment (§ 9a, § 11a) as a model for clarifying GDPR data rights in the context of AI model training, and calls on Bavaria to extend similar provisions to the private sector. - [From Tech Pilots to Scaled Impact](https://duschka.com/blog/plug-and-play-summit-2026.html): Reflections from the Plug and Play Germany Summit 2026 at BMW Welt on why AI governance is a design principle, not a filter — and what that means for Europe's competitive advantage in building trustworthy AI. - [Regulation vs. Reality in Financial Services](https://duschka.com/blog/cdo-bfsi-exchange-2026.html): Key takeaways from the CDO BFSI Exchange Europe keynote panel on making data and AI work for both compliance and competitiveness. Covers light-touch AI governance, FiDA opportunities and risks, and the three pillars of data-driven transformation. ## Selected Publications - Answering Recursive Queries Using Views (ACM PODS — Best Newcomer Paper Award, Alberto O. Mendelzon Test-of-Time Award) - Recursive Query Plans for Data Integration (Journal of Logic Programming) - Query Planning & Optimization in Information Integration (PhD Thesis, Stanford University) - Complexity of Answering Queries Using Materialized Views (ACM PODS, with S. Abiteboul) - Infomaster: An Information Integration System (ACM SIGMOD) ## Contact - Email: oliver@duschka.com - LinkedIn: https://www.linkedin.com/in/duschka - Location: Munich, Germany