AI Tools in companies: 7 steps for selection, procurement and implementation
Artificial intelligence promises enormous efficiency gains. But between the first test account and a company-wide rollout, there are numerous legal, organisational and strategic questions to answer. Companies that select AI tools systematically, procure them properly and implement them professionally create not only productivity, but genuine future resilience.
Content
- Why AI projects are more than an IT topic
- 1. The right foundation: strategy before tool selection
- Establish AI governance from the outset
- 2. AI procurement: contracts, licences and risk assessment
- Key questions when procuring AI
- 3. Before rollout: the compliance check
- Correctly classify data protection requirements
- 4. IT security: understanding new risks
- 5. Works council and internal involvement
- 6. Copyright: handling input and output correctly
- 7. Operational use: embedding governance permanently
- Conclusion: successful AI begins with structure
Why AI projects are more than an IT topic
Many companies start with a spontaneous test: one team tries out an AI tool, the results are impressive and suddenly the question arises of how to introduce the whole thing “officially”.
This is precisely where risks arise.
AI projects do not only concern IT. They affect processes, change decision-making structures and may trigger legal obligations. The more deeply a system intervenes in operational workflows or even in decision-making processes, the higher the requirements for governance, documentation and control.
Companies that want to use AI successfully should therefore understand it as a management and compliance project not merely as a software upgrade.
1. The right foundation: strategy before tool selection
Before providers are compared or licences negotiated, there should be clarity about the actual objective.
Helpful guiding questions include:
- Which specific problem is the tool intended to solve?
- Which processes will change as a result of using AI?
- What role will the AI play? Supporting, reviewing or making automated decisions?
- How critical is the affected business process?
- How will we measure success, for example through KPIs, profitability or efficiency?
A common mistake is to start with the tool rather than with the use case.
Establish AI governance from the outset
Clear structures should already be created during the planning phase:
- appointment of responsible persons, or owners
- documentation of the AI strategy
- establishment of an interdisciplinary body, including IT, Legal, the relevant business unit and HR
- creation of an AI inventory
Such an inventory creates transparency: Which AI systems are in use? In which departments? For what purpose? Who is responsible?
This overview is not only useful from an organisational perspective, but is also becoming increasingly relevant from a regulatory perspective.
2. AI procurement: contracts, licences and risk assessment
Once the use case has been defined, structured procurement begins. This involves much more than price.
Key questions when procuring AI
- Which model is actually being used?
- Which licence model is required?
- Where are data processed?
- Are there any special regulatory requirements?
- How is use documented?
Contract review is particularly critical.
Among other things, the following points should be reviewed:
- scope of usage rights
- data protection and IT security standards
- service description and service levels
- liability and warranty
- open-source components
- provisions on termination and data return, or exit
Especially with generative AI systems, it is crucial to determine whether, and in what form, inputs are further processed or used for training purposes.
Professional AI procurement supports business units and IT through clear checklists and defined approval processes.
3. Before rollout: the compliance check
Before an AI tool is used productively, a structured preliminary review should be carried out.
Typical review areas include:
- data protection compliance
- IT security
- protection of trade secrets
- assessment under the EU AI Act
- works council participation rights
- questions relating to fine-tuning and training
Correctly classify data protection requirements
AI systems process data in different phases from input and possible training steps through to the use of the output.
Depending on the constellation, different legal bases may be relevant, such as:
- consent
- legitimate interests
- performance of a contract
Each of these legal bases requires its own assessment, documentation and transparency.
Companies should also ensure that employees clearly understand which data they may enter into AI systems and which they may not.
4. IT security: understanding new risks
AI systems bring their own attack scenarios. These include, for example:
- manipulation of inputs, or prompt injection
- falsification of training data, or poisoning
- attacks aimed at disclosing sensitive information
- circumvention of safeguards through minimal changes
For this reason, both technical and organisational measures are required.
Technical measures may include, for example:
- secure hosting
- monitoring of outputs
- testing for vulnerabilities
Useful organisational measures include:
- adapting internal policies
- vendor risk management
- AI-specific contractual clauses
- training
- business continuity plans
AI security is not a one-off project, but an ongoing process.
5. Works council and internal involvement
As soon as AI systems collect behavioural or performance data, co-determination rights may be triggered.
Early information and involvement of the works council significantly reduces the potential for conflict.
Transparency is also crucial regardless of formal co-determination rights. Employees must understand:
- what the system is used for
- which data are processed
- what impact its use has
Trust is a central success factor for any AI implementation.
6. Copyright: handling input and output correctly
AI systems work with content and that content is often protected by copyright.
Companies should define clear rules.
What may be entered into the AI?
- own content for revision
- public-domain works
- self-created prompts
Caution is required when using third-party protected works.
Who owns AI-generated content?
Pure AI outputs are generally not automatically protected by copyright. Protection may arise where there is substantial human post-editing.
If existing works are reproduced or translated, the rights remain with the original author.
Without clear internal rules, legal uncertainty can quickly arise here.
7. Operational use: embedding governance permanently
The real work begins with go-live.
Before operational use, the following should be clarified:
- Is the use regulated internally?
- Are there defined use cases with an approval process?
- Are AI-generated contents labelled?
- Has a change management process been established?
- Is use monitored and documented?
An AI usage policy creates clarity and binding rules in this respect.
It should contain both general guardrails and tool-specific requirements.
Conclusion: successful AI begins with structure
AI can unlock enormous efficiency and innovation potential. But without clear processes, liability risks, data protection issues and internal conflicts arise.
Successful implementation of AI tools requires:
- a clear strategy
- structured procurement processes
- careful contract review
- compliance checks before rollout
- ongoing governance during operational use
Companies that think about AI strategically, secure it legally and implement it properly at an organisational level give themselves not only technological advantages, but sustainable competitive strength.
Schedule your initial consultation
Describe your situation to us in a no-obligation phone call, and our lawyers will work with you to find the best solution.
Our AI advisory services at a glance
- Regulatory mapping:
Identification of relevant legal requirements through detailed mapping against various national requirements and EU data regulations. - Data & AI governance:
Development and adaptation of governance structures, identification of requirements and preparation for the EU AI Act. - Training:
Workshops on the scope and implementation of the EU AI Act, including AI literacy under Article 4 of the AI Act for executives, product teams and developers. - AI inventory:
Support in creating an overview of all AI systems within the company, including determining whether a system must be classified as an AI system. - Contract drafting:
Contract drafting in connection with AI projects, such as development agreements, AI-as-a-Service agreements, AIaaS, and others. - Advisory on external AI applications:
Advice and guidance on the use of external AI applications and review of third-party applications. - Anonymisation & pseudonymisation:
Design of and advice on anonymisation and pseudonymisation concepts. - Risk assessments:
Advice on risk assessments in the context of data protection impact assessments and fundamental rights impact assessments relating to AI systems. - Copyright advisory:
Advice on copyright implications in connection with generative AI, for example rights in data input, protectability of prompts and output. - Lawful data use:
Advice on the lawful use of data in connection with big data, machine learning and generative AI, including data protection law, trade secrets and database rights. - AI development advisory:
Holistic advice on contract management, compliance and other legal aspects of AI development projects.
Content
- Why AI projects are more than an IT topic
- 1. The right foundation: strategy before tool selection
- Establish AI governance from the outset
- 2. AI procurement: contracts, licences and risk assessment
- Key questions when procuring AI
- 3. Before rollout: the compliance check
- Correctly classify data protection requirements
- 4. IT security: understanding new risks
- 5. Works council and internal involvement
- 6. Copyright: handling input and output correctly
- 7. Operational use: embedding governance permanently
- Conclusion: successful AI begins with structure
Your experts