Before the supplier set up the first use case, one question blocked everything else. Which of its data may leave the company at all, and which has to stay in the company? As long as that is open, no AI tool can be chosen seriously.
This is the question that blocks everything else. Whoever has answered it can make every further decision, from the choice of tool through operating mode and hardware to timing. Whoever bypasses it builds either something unusable or something impermissible and only notices once budget is committed or burned.
For management
One documented page ends uncontrolled use and keeps budget from flowing into something impermissible.
For IT
A clear line on what may go into which tool, instead of having to block across the board.
For the department
Finally a permitted path for your own documents instead of a grey area.
The clarification needs no technology, no budget and no investment application. It needs an appointment of two to three hours with the right people in the room.
Why the question so often stays open
In most companies there is no written answer to it. Only 23 percent of companies have established fixed rules for the use of generative AI, a further 31 percent are planning guidelines, 16 percent expressly rule out rules.
Source: Bitkom, Artificial Intelligence in Germany, study report 2026.
The consequence is foreseeable. As long as no one says what is allowed, everyone decides for themselves. The department uses what helps. IT blocks what it does not know. Both are right, and the result is an uncontrolled use that management knows nothing about.
A written rule takes away the department's reason to improvise and IT's reason to block across the board. It is thus the smallest measure with the greatest effect.
Four classes are enough
Complicated schemes fail in implementation. Four classes are sufficient and can be filled in a single appointment.
Class 1, stays in the company without exception
Data whose disclosure endangers the competitive advantage or the survival of the company.
Typical. Recipes, alloy compositions, plastics blends, process parameters, costing bases, margins, price floors, design data for ongoing developments.
Consequence. Processing exclusively on your own hardware. And on hardware that is not simultaneously connected to the open internet. A local server alone is not enough if employees use cloud services in parallel on the same machine.
Class 2, stays in the company because of third-party rights
Data in which others have a right.
Typical. Personal data of employees, applications, customer drawings, customer specifications under a confidentiality agreement, contacts and conversation notes from sales, supplier conditions.
Consequence. Processing locally, or in an environment for which a valid data-processing agreement exists and the place of processing is clarified. Also check whether your customer contracts permit processing by third parties at all. Many framework contracts in the supplier industry do not.
Class 3, internal and uncritical
Data that concerns the company, but whose disclosure does no harm.
Typical. Work instructions, internal process descriptions, training materials, general technical documentation, extracts from standards.
Consequence. Local processing is the normal case, cloud use would be justifiable in individual cases. Here the discussion is rarely worthwhile, because the difference in benefit is small.
Class 4, public anyway
Data that is already published or intended for publication.
Typical. Product descriptions from the catalogue, press texts, website content, job advertisements, trade-fair materials.
Consequence. Free choice of tool. Here you can use the most powerful available systems without any risk arising.

The disputed cases that always come up
These four cases cause discussion in almost every appointment. It is worth knowing them in advance.
The quotation history. Contains prices, margin logic and customer names at the same time. It thus falls into class 1 and 2 simultaneously and clearly belongs in the company, even though sales feels the benefit of a cloud solution there most strongly.
Drawings with a customer logo. Technically perhaps uncritical, contractually almost never. Check the framework contract before you decide this.
Test protocols with personnel numbers. The test content is class 3, the personnel number makes it class 2. Often this can be solved by removing a field before the data goes into the system. That is the cheapest way and is often overlooked.
Machine data. Seem harmless and mostly are. They become critical when conclusions about output, utilisation or recipe can be drawn from them. Then they are class 1.
Who has to be in the room
The classification is not purely an IT task. IT knows where the data is, but not necessarily what it is “worth”.
Needed are a person from management with decision-making authority, the head of the affected department, IT and, as soon as employee data is touched, the works council. Whoever involves the works council only later negotiates twice in the end.
A data-protection officer, if there is one, should proofread the result, but does not have to sit in the appointment.
What the result looks like
One page, no more. It contains:
- the four classes with three to five concrete examples each from your company, not from a template
- per class a rule on which tools are permissible
- the name of the person who decides in case of doubt
- a date and a version
This one page replaces most of the discussions that are otherwise held anew in every project. It is also the evidence you need when a customer or an authority asks how you have regulated the use of AI.
What to do if it is already being used in an uncontrolled way?
In most companies that is the case. 8 percent of companies report that employees use generative AI outside the company-side offerings and that this is widespread, twice as many as in the previous year. A further 17 percent see isolated cases, and another 17 percent assume that it happens without knowing for sure. On the employee side, one in ten uses AI without the employer's knowledge.
Source: Bitkom, Artificial Intelligence in Germany, study report 2026.
The obvious reaction is a ban. That is the worst of the available options, because the use does not end as a result, but becomes invisible.
The path that works consists of three movements that have to happen together.
You provide a permissible access that is good enough that no one has to evade any more.
You issue the written rule on which data may go into which tool.
And you explicitly explain that the previous use has no consequences. Without this third point you will not get a reliable inventory, because no one admits what they have done so far.
The connection with the choice of model
Only after this clarification is the technical discussion worthwhile. If a substantial part of your use cases falls into class 1 or 2, local operation is set, and the only question left is which hardware. If the focus lies in class 3 and 4, you have considerably more freedom and can start with a hosted offering.
Both are justifiable. What does not work is to reverse the sequence.
Which models come into question for which class is set out under Models and technology.
An offer for the first appointment
If you want to get this clarification behind you without your own preparation, I moderate the appointment, bring the questions and deliver the result as a documented page. Duration usually half a day, after which you have the basis for everything else.
For the exact procedure, look at the three stages of collaboration.
