In many businesses AI is already in use, just privately: staff have texts drafted, enquiries summarised or spreadsheets analysed, using their own accounts and without any agreement. That is not misconduct. It is a sign that the business has not yet provided a suitable tool. The work is there, the help is missing.
Anyone who wants to introduce AI in an orderly way runs into four questions. This article answers them. It does not replace legal advice, but it shows what matters in practice.
Our data must not go to the cloud. Is AI possible at all?
Yes. Not every AI has to run with one of the large providers. Language models can also run on your own hardware, in your own data centre or on a server in the building. Then the data does not leave your business.
That has pros and cons. A model in-house needs suitable hardware and maintenance. In return it can access data you would not entrust to an external service, such as the network drive or shared mailboxes. A mix often makes sense: sensitive tasks run in-house, uncritical ones with a provider. For each task we agree which data may go where before it is implemented. More on this in the article Running AI in-house.
AI makes mistakes. How can anyone rely on it?
Not blindly, and that is not necessary either. AI models make mistakes. They can assign details wrongly, overlook something or phrase a convincing answer that is not correct. Anyone who ignores that will be disappointed.
That is why we use AI so that it suggests and a person decides. An example: the AI compares an order confirmation with the purchase order and marks differences. A member of staff checks the marked points and approves. The AI takes over the tedious search, the responsibility stays with the team.
It is important to agree before rollout how good the results need to be. We test the application on your real work, including the difficult cases, and measure how often it is right. Only then do you decide whether it goes into daily use. Where AI reaches its limits is described in the article What AI cannot do for your business.
What about data protection and the AI Act?
Both matter, and both can be handled if they are considered from the start. For each task we document which data is processed, where it goes and who checks the results. We involve your data protection officer from the outset.
Part of the AI Act is that staff who work with AI are sufficiently trained. We plan for that during rollout as well. We do not make a legal assessment of your project. The documentation created along the way does, however, give your data protection officer and your legal advisers a good basis.
We have already developed something ourselves. What now?
That is common. With AI tools, first applications come together quickly these days, and many of them work surprisingly well in testing. In daily use something is often missing: a login with permissions, secure handling of data, backups or someone who maintains the application.
We look at what you have and what is still missing for lasting use. Our production readiness check gives a first assessment: twelve questions that show where an application is already fit for daily use and where it is not.
Where do you start?
With a single task that involves a lot of routine and where the benefit is easy to see. We trial it with your team on real work and calculate what it brings. Only when that has paid off is the next task added.
