An AI can generate a response in seconds. However, it remains to be seen whether that response is correct, suitable for the customer, and actually saves time. This is precisely where the meaningful use of AI in business begins.
For small and medium-sized businesses, artificial intelligence can help make knowledge accessible, simplify routine tasks, and analyze data. However, it can also create additional verification tasks or generate convincing-sounding errors. Therefore, the key is not to implement as many applications as possible, but to select the right tasks.
Four examples illustrate what matters and what companies can learn from them for their own AI implementation.
Those who wish to gain a deeper understanding of the legal and organizational foundations behind AI will find additional guidance in the K11 reference books on AI, compliance, and governance. After all, using AI effectively in a business setting also means understanding its limitations and clearly defining responsibilities.
As of September 14, 2026.
AI in business refers to the use of artificial intelligence to support or automate operational tasks. This includes, for example, analyzing documents, generating suggested responses in customer service, making sales forecasts, or detecting anomalies in production data.
Not every application is a chatbot. While generative AI creates new text, images, or code, other methods can, for example, recognize patterns or classify measurement data. For small and medium-sized businesses, this opens up a variety of applications, ranging from customer communication to predictive maintenance.
Still, the starting point should be a specific problem: Where do delays, recurring errors, or unnecessary search efforts occur?
A study by Erik Brynjolfsson, Danielle Li, and Lindsey Raymond, published in 2025 in the Quarterly Journal of Economics, analyzed the introduction of an AI assistant among 5,172 customer service employees at a large software company.
With AI support, the number of customer issues successfully resolved per hour increased by an average of 15 percent. Less experienced employees benefited in particular. The application made suggestions during customer interactions; employees could modify or reject these suggestions.
It is important to note the limitations of this statement: The study examined a specific system within a company. This does not imply a blanket promise of cost savings, nor does it mean that every service department will achieve the same results.
For SMEs, however, a useful pilot concept can still be derived: An assistant helps employees with recurring questions based on approved information. The system measures not only response speed but also the quality of the solution and the amount of follow-up work required. Automated communication with customers would be a separate step that would need to be evaluated additionally.
The LesswAIste demonstrator, presented by Mittelstand-Digital, shows that AI isn't limited to office work. The application uses image-based AI to identify and analyze surplus bakery products.
This reveals a concrete operational approach: Those who systematically identify which goods remain unsold have a better basis for reviewing their inventory planning.
However, a demonstration alone does not prove that long-term savings can be achieved in every operation. Whether such a solution is economically viable depends, among other things, on the quality of detection, the amount of work involved, and how the results are utilized.
The lesson we can take away: AI doesn't have to make decisions on its own right away. Even just more reliable data collection can be worthwhile if it actually leads to better business decisions.
A study by the research organization METR shows why companies should scrutinize productivity claims. In a randomized trial published in 2025, 16 experienced open-source developers worked on a total of 246 tasks on projects they were familiar with.
Using the AI tools studied, they took an average of 19 percent longer. Nevertheless, even after the experiment, the participants believed they had worked faster thanks to AI.
This is not a general assessment of today's programming assistants. METR published an update in February 2026: While more recent data pointed to improvements, selection biases and difficulties in measuring time made it impossible to reliably determine the current effect.
For companies, there is one practical implication: processing time also includes drafting instructions, reviewing, and making corrections. A quick initial output does not necessarily mean the process is completed quickly.
In 2025, in the case of Al-Haroun v. Qatar National Bank, the British High Court documented significant errors in the documents submitted. Of the 45 references reviewed, 18 cited nonexistent court decisions.
According to his own account, the client had used, among other things, publicly available AI tools for his research. His attorney acknowledged that he had not independently verified the sources cited. The court ordered that the matter be reported to the relevant professional regulatory authority.
This case does not determine the legal situation in Germany. However, it highlights a broader quality issue: a plausibly worded citation is not in itself evidence.
This also applies to market analyses, technical documentation, and decision-making documents. Whenever statements have business implications, relevant facts must be verified using reliable original sources. Asking the AI to confirm its own answer does not constitute an independent verification.
The Mittelstand-Digital guide recommends, among other things, a needs assessment, an interdisciplinary project team, measurable goals, and a phased implementation. From this, five practical steps can be derived for an initial pilot project.
Select a specific bottleneck.
Don’t say, “We need AI,” but rather, for example: “Our service team spends too much time searching for approved product information.” Also consider whether a better search function or simple rule-based automation would suffice.
Define baseline values and success criteria.
Track processing time, error rate, and rework without AI. Before the test, define what improvements are needed and what quality thresholds must not be exceeded.
Clarify data, rights, and responsibilities.
What information is the application allowed to process? Who has access? Who is responsible for the results? Involve the business units, IT, data protection, and, if applicable, employee representatives early on.
Test in a controlled manner and deliberately analyze errors.
In addition to typical cases, use incomplete, contradictory, and unusual inputs. Specify when employees must take over and which outputs should not be automatically reused.
Evaluate the overall benefits.
Take into account licensing, integration, training, monitoring, and ongoing support. Expansion should only follow once the benefits have been proven under realistic conditions. Testing should be repeated after any relevant changes are made to the system.
When it comes to personal data in particular, internal approval alone is not sufficient. Among other things, an appropriate legal basis, suitable safeguards, and an assessment of whether a data protection impact assessment is necessary are required.
These case studies have one thing in common: Employees must be able to assess when AI is helpful and when its results need to be reviewed. Practical AI training for companies should therefore be based on real-world tasks, error patterns, and company policies.
AI literacy also remains relevant from a legal perspective. Article 4 of the AI Act, as amended in 2026, requires measures to promote AI literacy among the affected employees. However, this does not guarantee a specific individual level of proficiency.
An AI Officer can coordinate organizational tasks: tracking applications, consolidating reviews, coordinating training, and ensuring accountability. However, Article 4 does not require either an AI Officer or a specific governance structure for this purpose.
K11 Consulting helps companies integrate these tasks with data protection, information security, and practical workflows. Technical decisions remain the responsibility of the respective decision-makers.
The case studies illustrate how closely technical capabilities, professional review, and operational responsibility are interrelated. Those who wish to systematically understand these relationships can supplement practical testing with professional literature.
The book “AI Regulation—Made Easy” combines technical fundamentals with legal and ethical issues surrounding the use of AI. Among other topics, it covers the EU AI Act, data handling, and management standards such as ISO/IEC 42001. The English-language title “AI Compliance” also offers an introduction to AI and AI governance.
“Simple Governance—Fundamentals, Structures, and Practical Implementation” broadens the perspective on the interplay between compliance, data protection, IT security, and risk management. This is particularly helpful in situations where an AI project involves multiple departments and responsibilities should not end at the door of a particular office.
The three publications, to which Dr. Alexander Deicke contributed, can help prepare for training sessions, support discussions within the project team, and serve as a reference. It remains necessary, however, to examine the specific use case and take new legal developments into account.
AI in business can make work easier, make knowledge accessible, and enable new types of analysis. The examples also clearly show that benefits do not automatically result from access to a powerful system.
A sensible starting point combines a clear use case with appropriate data, trained employees, and verifiable results. Companies don’t have to start everywhere at once to achieve this. A successful pilot is a good start. Ten unsupervised test accounts are, at first, just ten unsupervised test accounts.