Using AI Responsibly: K11 Bridges the Gap Between Law and Implementation

Two Companies, a Coordinated Approach to Your AI Implementation

AI Compliance – How K11 Combines Legal Advice, Governance, and Strategy

Understanding legal requirements and translating them into effective processes

The AI application has been selected, the test was successful, and the business unit is ready to get started. Then the questions arise: What data can be fed into it? What does the contract with the provider stipulate? Who reviews the results? And who decides when the internal assistant suddenly becomes a tool for customer communication?

Such questions cannot be answered from a purely technical or purely legal perspective. AI compliance requires a legal framework and an organization that can translate that framework into effective processes.

This is where K11 Consulting GmbH and K11 Rechtsanwaltsgesellschaft mbH complement each other. This combination brings together management consulting and legal advice. Their shared approach: designing AI initiatives with a solid legal foundation and embedding them within the company.


AI Compliance and AI Governance: K11 Law Firm and K11 Consulting Combine Legal Advice and Implementation

What Does AI Compliance Mean for a Company?

AI compliance refers to adherence to legal and relevant internal requirements when using artificial intelligence. This includes evaluating the specific application, implementing necessary measures, and organizing compliance in a transparent manner.

The EU AI Act provides an important framework for this. Which requirements apply depends, in particular, on the application and the company’s role. In addition, data protection law, copyright law, labor law, and contractual obligations may also be relevant. A general statement along the lines of “This tool complies with the law” is therefore often insufficient.

For a company, what matters most is how it uses a system: with what data, for what tasks, involving whom, and under what controls.

Strategy, Governance, Compliance, and Law: Four Perspectives on the Same Project

The terms overlap, but they address different questions:

  • AI Strategy: What are our goals for AI, which applications are worthwhile, and what resources are we allocating?
  • AI Governance: Who makes the decisions, who bears what responsibilities, and how are applications reviewed, approved, and monitored?
  • AI Compliance: What requirements apply, how are they implemented, and how can compliance be demonstrated?
  • Legal advice: How should specific legal issues be assessed, and how should contracts, internal policies, or individual projects be structured from a legal perspective?

A good strategy takes legal constraints into account early on. A legal assessment, in turn, requires information about actual usage. Governance integrates both of these aspects into day-to-day operations.

This is particularly important in small and medium-sized businesses. In such companies, it’s not feasible to create a new department for every AI project. However, every relevant topic does need a clear place within the existing organization.

Two K11 companies with a clear division of responsibilities

K11 Rechtsanwaltsgesellschaft provides legal expertise. It assesses legal requirements, evaluates specific AI projects, and assists with their legal structuring. This includes, for example, reviewing provider terms and conditions, drafting internal rules of use, and clarifying legal responsibilities.

K11 Consulting supports the organizational implementation. Requirements are translated into an AI inventory, defined roles, assessment and approval processes, and appropriate documentation. Training, audits, and the ongoing development of management systems help ensure that these structures remain functional over the long term.

This connection is particularly valuable at the interfaces: A legal requirement must be understandable to the business department and implementable by IT. Conversely, technical limitations or changes in processes may necessitate a new legal assessment.

The “one-stop shop” approach represents coordinated collaboration between two independent firms. The scope of engagement, responsibilities, and information flows should be clearly defined for each project. Legal counsel and management consulting remain distinct services that build on one another.

Why an AI policy alone does not ensure governance

A policy may stipulate that confidential information may only be processed in approved applications. However, this does not clarify which applications are approved, who makes that decision, or how employees can have a new solution reviewed.

This is precisely what AI governance entails. For example, an up-to-date overview of the systems in use, clear guidelines for use, and a contact person who can be reached are required. It should also be clearly defined when an approval will be reviewed again.

A rule that no one can find or apply in their day-to-day work has, above all, a proper filename.

The collaboration between legal counsel and consulting therefore does not begin with the document as the end product. What matters most is the specific changes this document brings about within the company.

Real-World Example: An In-House AI Assistant for Sales

A medium-sized company wants to implement an AI assistant. The assistant is intended to summarize product information, prepare draft proposals, and answer questions based on internal documents. The following scenario is an example of a project workflow; it is not a description of a specific K11 project.

First, the scope of the project is defined. Is the application intended merely to retrieve information, or should it also generate prices and service commitments? Which tasks will remain the responsibility of the employees? What improvements would the pilot project need to achieve to make its implementation worthwhile?

Next comes the legal assessment. For example, it must be determined whether customer data and confidential contractual documents may be processed. What rights of use exist with respect to the integrated content? What provisions does the provider agreement contain regarding data use, confidentiality, liability, and termination of the contract? Are additional data protection agreements or reviews required?

The results are then translated into workflows. K11 Consulting can assist in structuring authorized data sources, access roles, and approval steps. One possible guideline would be that the assistant prepares drafts, but binding offers are sent only after a technical review.

Legal advice and implementation are intertwined: The legal assessment influences the configuration. The technical features that are actually available, in turn, influence what uses are reasonable.

If the intended use changes later, the assessment should also be reviewed. An assistant that has been tested internally is not automatically approved for unsupervised communication with customers. The original approval applies to a specific use case, not to every subsequent idea.

Combining AI Governance with Data Protection and Information Security

AI projects usually interact with existing structures. Companies often already have data protection processes, information security policies, procurement guidelines, or risk management systems in place. These structures should be taken into account when implementing AI.

For example, a new AI service may require a supplier review, a data protection assessment, and an access rights review all at the same time. If these tasks are organized separately, there is a risk of duplicate queries and conflicting results.

K11 Consulting helps align data protection, information security, and AI governance. The legal assessment provides the legal requirements for the specific case.

To ensure a systematic approach, ISO/IEC 42001 can also serve as a framework for an AI management system. The standard addresses the establishment, implementation, maintenance, and continuous improvement of such a system. However, it does not replace the legal review of individual applications.

Who keeps everything running smoothly during operations?

Even after implementation, challenges remain: new applications are introduced, vendors change features, employees come and go, and legal requirements continue to evolve.

An AI Officer can coordinate these matters. For example, this role helps keep the AI inventory up to date, initiate reviews, and bring together business units, data protection, IT, and legal counsel. It does not replace individual legal advice or the decisions of senior management.

It cannot be inferred from this that there is a blanket legal requirement for every company to appoint an AI Officer. The European Commission also makes it clear that Article 4 of the AI Act does not prescribe any specific governance structure.

In addition, application-specific AI training ensures that employees understand company policies and can appropriately review results.

How does a tailored AI consultation begin?

The first step is to conduct a joint assessment: Which AI systems are already in use? What projects are planned? Where are there unresolved legal issues, unclear responsibilities, or gaps in documentation?

This can be used to develop a prioritized approach. Not every application requires the same level of scrutiny. The key factors are the specific use case, the data and individuals involved, and the potential consequences of errors.

For companies, the first step can therefore be a single project: a planned AI assistant, a contract review, or the revision of existing terms of use. If necessary, this can lead to a longer-term partnership. The scope and tasks should be based on actual needs.

Conclusion: Legally sound and firmly embedded in the company

The combination of K11 Consulting and K11 Law Firm brings together two tasks that go hand in hand when it comes to AI implementation: reliably assessing legal issues and translating the results into workable structures.

AI compliance thus becomes a combination of strategy, clear decisions, appropriate processes, and ongoing monitoring. The goal is not to eliminate every risk, but rather to identify risks, clarify responsibilities, and ensure that AI projects are transparent.

Anyone seeking support in this area can first work with K11 to determine whether legal advice, organizational implementation, or a combination of both is needed.