In this post
Introduction to this topic
-
Automation does not save unresolved processes
The core contribution lays the process foundation. -
Generative AI first changes the way of working
The historical perspective shows the first practical change in February 2023. -
AI without a knowledge base produces interchangeable results
The contribution explains the role of audited company sources. -
What companies need to clarify before AI automation
The audit model translates the fundamentals into a concrete preliminary decision. -
Why human review remains part of every reliable AI process
The viewpoint classifies release and exception handling. -
AI deployment requires roles, rules, and responsibilities
The current organizational densification leads to a governance model. -
AI Act for Companies: How Regulation Can Become a Competitive Advantage
The current article classifies the transparency obligations applicable since August 2026 as a strategic and organizational management task.
AI enhances the quality of existing structures
Robust AI deployment arises from the interplay of task, process, knowledge, data, technology, testing, and responsibility.
A company is not well-positioned simply because employees use various AI tools or individual processes have been automated. What matters is whether it is clear:
- which task is to be supported,
- which inputs and rules apply,
- which knowledge may be used,
- how exceptions are detected,
- who checks and approves results,
- what risks and limitations exist,
- how impact and errors are documented.
The topic area „AI and Automation“ classifies these prerequisites from classic process automation to operational AI governance.
The central problem
Technical possibilities are often considered before the organizational question.
A tool can draft texts, summarize data, sort requests, retrieve information from documents, or trigger actions in other systems. This quickly creates the impression that the process is already understood.
In practice, however, fundamental questions remain open:
- Which variant of a service is binding?
- Which data may be transferred to the provider?
- How are conflicting sources handled?
- Which request can be answered automatically?
- When does a human need to take over?
- Who is responsible for an incorrect output?
- How is it recognized that the underlying process has changed?
Technology cannot make these decisions on our behalf. It requires a prepared working basis.
The seven levels of robust AI work
1. Task
Every application begins with a clearly defined task. "Automate marketing" or "Use AI in customer service" is too broad.
More suitable questions are:
- Should an incoming request be pre-sorted according to comprehensible criteria?
- Should a technical text be prepared based on approved sources?
- Should an existing dataset be checked for missing mandatory information?
- Should an employee be supported in searching for a binding process rule?
The clearer the task, the better the result, risk, and control requirements can be determined.
2. Process
The task is part of a process. The process has triggers, inputs, rules, handovers, exceptions, and an expected result.
The core contribution “Automation does not save unresolved processes” shows why an unclear process does not improve with technical acceleration. It is only repeated faster.
3. Knowledge and Data
Generative models provide general patterns and formulations. Company-specific quality requires binding sources, terms, examples, and rules.
"AI without a knowledge base produces interchangeable results" explains why a powerful model cannot know which statement is current, permissible, and factually correct in the specific company.
4. Technology
Only after task, process, and knowledge base is it decided which technical solution is appropriate.
Possible components are:
- classic rule-based automation,
- Language model,
- Classification model,
- search or retrieval system,
- Interface,
- Process platform,
- Agent,
- Validation rule.
The simplest viable solution is often better than a technically impressive but difficult-to-control architecture.
5. Verification
Not every result needs the same level of control.
An internal draft can be sufficiently secured through sampling and expert review. A binding customer response, contract information, medical statement, or irreversible system action requires a higher level of control.
“Why human review remains part of every robust AI process” classifies checking as a defined process function.
6. Responsibility
Every productive deployment requires designated responsibility for:
- Business purpose,
- Process,
- Knowledge and data,
- technical configuration,
- technical approval,
- Data protection and security,
- Incidents and escalation.
Responsibility must not end with the individual employee operating a tool.
7. Learning
Models, sources, processes, and providers are changing. Reliable use therefore requires logging, error analysis, updating, and recurring testing.
A functioning application is not a finished state. It is a managed part of the digital system.
The development from 2022 to 2026
Automation before the AI boom
In February 2022, many companies were still focused on connecting existing software, data, and recurring processes.
The crucial insight was already valid back then: automation not only accelerates the desired process. It equally accelerates unclear rules, bad data, and faulty handovers.
Generative AI changes individual work steps
After the release of ChatGPT at the end of 2022, it first became apparent in February 2023 how drafting, summarizing, rephrasing, brainstorming, and checking are changing.
The historical contribution 'Generative AI changes the way we work first' separates this immediate effect from later expectations of fully integrated AI systems.
Knowledge becomes a prerequisite
With more powerful models, it also became clearer that convincing language does not guarantee company-specific truth.
In April 2023, the strategic task was therefore not only about better prompts. Companies had to clarify which sources and rules the application should use at all.
Pre-testing becomes necessary
In autumn 2023, the question shifted from 'What can the model do?' to 'Under what conditions is it permissible and advisable for the process to go live?'
“What companies need to clarify before AI automation” bundles six checking fields for this purpose: task, data, roles, approval, risk, and success criterion.
Governance becomes organizational
By June 2025, AI use in many companies was no longer just an experiment by individuals. The EU AI Act was in force, initial provisions on prohibited practices and AI competence applied since February 2025, further obligations followed in stages.
"AI deployment requires roles, rules, and responsibilities" describes the organizational response. Not as a full legal review, but as a management and operating model.
Transparency obligations are becoming concrete
Since August 2, 2026, the transparency obligations from Article 50 of the AI Act have been in force. This makes it more concrete when people must be informed about direct AI interaction, deepfakes, or certain AI-generated content.
“AI Act for businesses: How regulation can become a competitive advantage” shows why the relevant task goes beyond individual labels: companies must organize use cases, data, testing, and responsibility in a manageable way.
The SDC model for AI orchestration
Typical misconceptions
"A better model will solve our quality problem."
A more powerful model can generate better general outputs. It does not resolve conflicting sources, unexplained technical terms, or missing approval rules.
"Automation automatically saves time."
Automation can save time. It can also create additional control, error handling, and maintenance. The overall process impact must be considered.
„Human review makes every application secure.“
Auditing is only effective if the person auditing is sufficiently informed, qualified, and capable of acting. A formal confirmation at the end is not a robust control mechanism.
"An internal policy is already governance."
A policy can document rules. Governance additionally requires roles, decisions, technical controls, competence, incident management, and regular review.
"RAG prevents hallucinations."
Retrieving external sources can better anchor answers. It can also provide unsuitable, outdated, or incorrectly prioritized sources. Retrieval and generation must be checked.
"Agents can later organize the process themselves."
An agent can perform multi-step tasks. It therefore requires clearer rights, boundaries, states, and fallback paths. More agency increases the need for governance.
Connection to other topics
- Digital Strategy decides which tasks and dependencies have priority.
- Content and Expertise creates the knowledge architecture and verified statements.
- Data and Control defines success criteria, quality measurement, and feedback.
- Websites and digital systems provide controllable access, interfaces, and action paths.
- Organization and Transformation anchored roles, competence, and ability to change.
Framework of action
1. Capture usage scenarios
Companies should document existing and planned AI uses. This also includes informal applications in individual teams.
2. Limit tasks
Each prioritized use is translated into a concrete task with an expected outcome, permissible inputs, and a clear termination condition.
3. Check process and knowledge base
Rules, exceptions, sources, authorizations, and responsibilities are clarified before further technology is added.
4. Define the control level
The required review depends on impact, probability of error, reversibility, and affected individuals.
5. Define roles and escalation
Business, professional, technical, and legal responsibilities are named separately and linked together.
6. Let Impact and Errors Be Learned
Metrics, incidents, corrections, and process changes flow into a documented learning loop.
What companies should not do
Companies should not control AI usage solely through prohibitions or individual tools. Pure blocking logic often shifts usage to unofficial areas. Conversely, pure release logic without rules leads to uncontrolled expansion.
You also shouldn't try to solve every conceivable case centrally right away. A limited, relevant process with clear sources and responsibilities provides more insight than a broad program without a solid foundation.
Consequences for companies
AI and automation become commercially valuable when they are not operated as an additional technology world alongside the company.
They must be embedded in existing responsibility, knowledge, data, processes, and control. This does not result in complete error-free operation. It creates a system that can comprehensibly handle benefits, limitations, and deviations.
Subject-matter connection
Structuring AI use from task to governance
A robust introduction begins with clarifying processes, knowledge, data, roles, and control requirements. SDC-Discovery categorizes existing uses, prioritizes suitable use cases, and identifies prerequisites missing before technical orchestration or automation.
Structurally review AI and automation foundations
Sources and factual basis (6)
- National Institute of Standards and Technology, „Artificial Intelligence Risk Management Framework (AI RMF 1.0)“, 2023. Open source
- ISO, "ISO/IEC 42001:2023. Artificial intelligence management systems", 2023. Open source
- European Commission, "AI Act. Regulatory framework for artificial intelligence". Open source
- European Union, 'Regulation (EU) 2024/1689 on Artificial Intelligence', 2024. Open source
- OECD, "OECD AI Principles". Open source
- Object Management Group, "Business Process Model and Notation 2.0.2". Open source

