# Ki Einsatz Braucht Rollen Regeln Und Verantwortlichkeiten.Html
**Source:** https://en.goeke.digital/insights/ki-einsatz-braucht-rollen-regeln-und-verantwortlichkeiten.html
**Language:** English

---

AI and automation 

# AI deployment requires roles, rules, and responsibilities

As soon as AI is used regularly in a company, a general recommendation for careful handling is longer sufficient. Usage must be organizationally controlled.

## Regular AI use requires organizational leadership

Operational AI use requires clear responsibility, permissible use, regulated data access, appropriate review, escalation, documentation, and competence.

AI governance is not a single set of rules. It is an operating system of roles, decision-making rights, controls, and learning loops. It connects business purpose, expertise, technology, data protection, security, and corporate governance.

## Starting point

In June 2025, AI usage in many companies was longer limited to individual experiments.

Employees used generative systems for:

- Design and revision,
- Research and summarization,
- Translation,
- Data analysis,
- Software development,
- Customer communication,
- internal knowledge search,
- process support.

At the same time, integrated functions emerged in office software, CRM, marketing platforms, and development systems. Therefore, usage could take place without a company consciously having started its own AI project.

This proliferation changed the leadership question.

It was longer just about approving or blocking a tool. Companies had to clarify:

- What use is desired?
- What data can be processed?
- What results does the audit require?
- Who approves new applications?
- Who monitors providers and changes?
- How are errors and incidents handled?
- What skills do employees need?
- How is it documented that rules are being followed?

## The regulatory context in June 2025

The EU AI Act entered into force on August 1, 2024.

As of February 2, 2025, initial provisions applied, including the rules on prohibited practices and the obligation to take measures for sufficient AI competence of persons dealing with AI.

Further requirements were to be applied in stages. The governance rules and obligations for general-purpose models should only apply from August 2, 2025.

This time limit is important for classification in June 2025.

Companies had to act already, but were not yet allowed to write as if all later obligations were fully applicable.

This contribution is not legal advice. The AI Act, data protection law, labor law, co-determination, copyright law, and sectoral requirements must be examined separately for the specific application. For legally relevant decisions, specialized law firms, data protection officers, and possibly other expert bodies should be involved.

## What AI governance must achieve

### Clarify purpose and benefit

Every application needs a responsible business purpose.

The following must be documented:

- desired support,
- affected users or persons,
- expected benefit,
- permissible scope,
- Demolition and exit criteria.

An application without a clear purpose can neither be adequately reviewed nor prioritized.

### Define permissible use

Employees need understandable rules.

Examples:

- Which tools are approved?
- What data can be entered?
- Which tasks are not permissible?
- When must an output be labeled?
- Which results may not be used without verification?
- Which applications require prior approval?

The rules must fit into everyday work. An abstract guideline that one can apply to concrete situations remains ineffective.

### Control data and system access

AI applications can access documents, emails, customer data, CRM, project management, or other systems.

With every access, the potential impact increases.

To be clarified:

- minimal authorization,
- Purpose limitation,
- Data categories,
- Storage and deletion rules,
- external providers,
- technical interfaces,
- Logging,
- Separation of testing and productive operation.

An agent with write access requires different governance than an internal drafting tool without system access.

### Design review and approval

The depth of control depends on the risk.

Governance defines:

- which results are only drafts,
- when random samples suffice,
- when a technical mandatory review applies,
- when a four-eyes principle is required,
- when automatic processing is excluded,
- who is allowed to approve.

The rules must be technically and organizationally feasible.

### Handle escalations and incidents

An AI process can:

- produce incorrect results,
- access unsuitable sources,
- process sensitive data,
- trigger an impermissible action,
- systematically disadvantage certain cases,
- function differently due to provider change.

For this, the company needs:

- reporting channel,
- Stop right,
- technical shutdown option,
- Person responsible for assessment,
- Documentation,
- Communication to those affected,
- Correction and restart.

An incident must not be dismissed as an individual operating problem if the cause lies in the system or process.

### Ensure documentation and traceability

Not every use requires the same documentation.

For relevant applications, however, at least the following should be traceable:

- Purpose,
- Responsible persons,
- system used and version,
- Data sources,
- Rules and review steps,
- known limits,
- Release,
- Changes,
- Incidents,
- regular review.

Documentation serves not only compliance. It enables maintenance, handover, and learning.

### Build Competence

Article 4 of the EU AI Act made AI competence a concrete organizational task.

Competence does not mean that every person must master technical model details.

It must fit the application and can include:

- Capabilities and limitations of the system,
- permissible data,
- typical errors,
- Audit criteria,
- Security and data protection rules,
- Escalation path,
- Impact on affected individuals.

A one-time general webinar is not sufficient for every role.

![Four guardrails for AI use: purpose, data, roles, and release](/insights/images/visuals/infografik-ki-leitplanken-793.webp)Enlarge graphic 

Robust AI processes require a clarified purpose, permissible data, responsible roles, and approval rules.

## The role model

AI governance does not require a large new department. It requires clearly assigned functions.

### Business owner

Decides on purpose, priority, resources, and acceptable risk.

### Process owner

Is responsible for the process, handovers, and integration into operations.

### Subject matter or knowledge expert

Secures sources, terms, rules, and factual quality.

### Technical Responsible Person

Responsible for configuration, interfaces, permissions, versions, and operation.

### Data protection, security, and compliance

Check the respective relevant requirements and support risk-relevant decisions.

### Reviewing and approving roles

Evaluate results according to defined criteria and have actual stop rights.

### Users

Apply the system within the defined framework, recognize limits, and report deviations.

### Incident and escalation manager

Coordinates reaction, documentation, correction, and, if necessary, external communication.

One person can take on multiple roles. This must not lead to ambiguity.

## The SDC role model for AI governance

## A pragmatic governance model for SMEs

### 1. AI usage inventory

The company records:

- approved systems,
- actually used systems,
- Tasks,
- Data,
- affected processes,
- responsible persons.

This inventory does not have to be complete immediately. It should first make risk-relevant and recurring uses visible.

### 2. Simple risk classes

A practical classification could be:

- **Class A:** internal draft, low impact, easily correctable.
- **Class B:** external communication or operational decision with mandatory review.
- **Class C:** sensitive data, significant impact, system action or low reversibility. Separate approval and review required.
- **Not permitted:** prohibited, not justifiable, or not sufficiently clarified use.

The classification does not replace a legal classification according to the AI Act. It supports internal control.

### 3. Binding usage rules

Rules should answer concrete situations and include examples.

### 4. Approval process for new applications

New applications are not just procured technically. Business purpose, data, risk, provider, testing, and responsibility are assessed jointly.

### 5. Competence by Role

Users, subject matter experts, technical leads, and management require different training content.

### 6. Recurring review

Models, providers, processes, and legal situations change. Applications are therefore reviewed on fixed occasions or at intervals.

## Strategic Classification

ISO/IEC 42001 described an AI management system at the end of 2023. Its value lies not only in possible certification. It structures AI as a recurring management task according to the Plan, Do, Check, Act principle.

The NIST AI RMF assigns similar functions as Govern, Map, Measure, and Manage.

Both approaches show a common logic:

AI governance is not a one-time approval form. It connects planning, context, control, operation, and learning.

## Perspective from practice

The greatest danger for medium-sized companies often lies not in an officially introduced high-risk system.

It lies in the growing number of small uses:

- a team uses an unapproved tool,
- sensitive information is copied into an assistant,
- a plugin receives extensive access,
- an automatically generated response is sent without review,
- a central knowledge source is not updated,
- one notices a model or provider change.

A pragmatic governance system must capture this reality without stifling every use in bureaucracy.

The appropriate standard is proportionality:

- low impact, simple rules,
- higher impact, stronger review,
- sensitive or irreversible impact, formal release, and specialized review.

## Procurement belongs in governance

Even the purchase of an AI service is not purely a technical or price decision.

Contract terms, data usage, subcontractors, storage locations, deletion options, change notifications, model updates, access controls, and the possibility of an orderly exit must be checked, among other things. A technically suitable use case can become untenable if the provider does not meet essential requirements in a comprehensible manner.

Therefore, procurement, the specialist department, and technical responsibility must evaluate the same use case. The approval of a tool does not automatically apply to every possible use within that tool.

## What companies should not do

Companies should not delegate AI governance to a single department.

IT can control technical access but cannot solely assess the business purpose. Business units know the task but not necessarily the data protection and security implications. Compliance can define rules but not operate the process.

Likewise, a policy without technical implementation is insufficient. If unapproved tools remain easily usable, permissions are too broad, and there is reporting mechanism, governance remains theoretical.

Companies should also not treat every application the same way. Excessive approval requirements promote shadow usage. Rules that are too lax leave relevant risks uncontrolled.

## Consequences for companies

AI governance is part of digital maturity.

It is demonstrated by whether a company can translate new technical possibilities into existing responsibilities.

Robust governance enables:

- faster selection of suitable use cases,
- clear boundaries for employees,
- better data and security decisions,
- traceable approvals,
- controlled scaling,
- Learning from mistakes,
- Connection to legal and normative requirements.

It does not slow down sensible use. It prevents speed without direction from arising.

## Subject-matter connection

### Anchor AI governance as an ongoing leadership task

AI governance and orchestration connect usage inventory, roles, rules, data access, audit models, competence, and escalation. In an SDC partnership, these elements can be gradually integrated into real processes and continuously developed.

Systematically classify AI governance and orchestration

Sources and technical foundations (8) 

1. European Union, 'Regulation (EU) 2024/1689 on Artificial Intelligence', 2024. Open source
2. European Commission, "AI Act. Regulatory framework for artificial intelligence". Open source
3. European Commission, “AI Literacy. Questions & Answers”. Open source
4. European Commission, „Guidelines on AI system definition and first rules“, February 6, 2025. Open source
5. ISO, "ISO/IEC 42001:2023. Artificial intelligence management systems". Open source
6. ISO, "ISO/IEC 23894:2023. Artificial intelligence. Guidance on risk management". Open source
7. National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework (AI RMF 1.0)”. Open source
8. OECD, "OECD AI Principles". Open source

![Göke Frerichs, digital strategist and Smart Digital Creative](/images/goeke-frerichs-portrait-400w.webp)

Author 

## About Göke Frerichs

Göke Frerichs has been combining digital strategy, communication, technology, and implementation since 1999. As a digital strategist and Smart Digital Creative, he supports owner-managed B2B companies in developing clear and reliable digital systems from individual measures. His perspective is based on many years of consulting and implementation experience in the DACH region and North America.

More about Göke Frerichs

Reading path 

## Next up

**Back to the introduction** AI and automation 

### Automation does not save unresolved processes

A process that today only works through experience, verbal agreements, and constant exceptional decisions does not automatically become better through automation. It is reproduced faster.

### Further suitable classifications

AI and automation 

### Generative AI first changes the way of working

In February 2023, the most immediate impact of generative AI was not automating entire companies. It changed the order, speed, and distribution...

AI and automation 

### AI without a knowledge base produces interchangeable results

A language model can formulate a convincing text about a service. It does not yet know how the specific company actually provides this service, limited...

AI Governance and Orchestration 

## Clarifying the digital starting point

The right collaboration begins with a clear categorization.

Categorize collaboration