DR. SARAFI Rechtsanwälte / HomeFrankfurt am Main · Throughout Germany
AI law

AI in companies: From individual tools to clear rules

Anyone who wants to use AI should look at the use case, data, contracts and responsibility together.

Editor: DR. SARAFI Rechtsanwaltsgesellschaft mbH3 mins

Describe the use in concrete terms

A text assistant for internal drafts, a chatbot for customers and a system for evaluating applications raise various legal issues. Therefore, start with an overview: Which systems are used, by whom, with which inputs and for which decisions? Also include tools that individual teams are already using independently.

The AI Act takes a risk-based approach. The relevant requirements depend, among other things, on the intended use and role of your company. The mere product name doesn't answer these questions. Special obligations or prohibitions must be examined for certain applications. The transitional regulations in force in each case must also match the specific classification.

Understanding data flows and provider conditions

Before approval, check what information is being sent to the provider. If entries contain personal data, their processing must be subject to data protection law. This includes in particular purpose and legal basis, data minimization, security and, where applicable, order processing and transfers to third countries. Whether a data protection impact assessment is required depends on the specific risk.

In addition, the provider conditions are practically important: How are inputs stored, who can access them and are they used for training purposes? What are the contractual commitments? Record the actual agreed product version and its settings. A general advertising notice from the provider does not replace the review of these documents and processes.

Define responsibility in everyday work

A useful internal regulation explains which applications are approved, which information can be entered and who checks results. Based on your work processes, define when a draft must be reviewed and who is responsible for a publication or decision. For employees, these rules should be accessible and explained with understandable examples.

In the case of interactive or generative applications, transparency obligations may need to be taken into account. This includes certain direct interactions with AI and certain artificially created or modified content. Which identification is required depends on the system, role and use case. Internal planning should also include a contact person for errors, complaints and changes to the tool used.

Align the legal audit with a pilot project

A clearly defined use case is suitable for getting started. Describe the intended use, data categories, provider, and departments involved. Provide contract documents and technical information. In this way, advice can identify specific gaps instead of just providing a general catalog of legal topics.

A suitable legal mandate may include classification under the AI Act, the review of data protection and contracts, and an implementable usage policy. The result should set out responsibilities and next steps. If purpose, data, or provider change, the original review also needs to be reconsidered.

Sources & further information

This article provides general guidance. The options available depend on your specific situation.

Explore this practice area AI law

SARAFI.ITRECHT

Your concern: AI law

Briefly describe your case and known deadlines. We clarify the takeover, the scope of services and the remuneration.

Get in touchBook a consultationinfo@sarafi.deAn engagement begins only when we expressly accept it.

English translation of our German website. Statutory references concern German or EU law. The German original remains available through the language selector.