Typical starting point
We often encounter the following picture: initial internal attempts with generic chat assistants remained disappointing – a lack of domain knowledge, no audit trail and unresolved data protection questions. At the same time, growing pressure from ticket volume and the open question of which obligations the AI Act actually triggers for the planned use – the risk classification is usually still pending.
The typical brief we receive: pilot two concrete AI use cases that deliver immediate impact while remaining audit-ready.
How we typically proceed
Ten weeks, five phases – a senior consultant together with an AI specialist from our partner network:
- Use-case workshop (weeks 1–2) – with QA, Compliance, Data Protection and Architecture – prioritisation by impact and risk.
- Tool selection and data-protection concept (weeks 2–3) – hosting model with EU data residency, clear responsibilities under GDPR and the EU AI Act.
- Pilot 1: Defect triage (weeks 3–6) – LLM-assisted classification and routing of incoming tickets, with human-in-the-loop.
- Pilot 2: Test-data generation (weeks 6–8) – synthetic load-test data, anonymised and auditable.
- Audit documentation and scaling plan (weeks 8–10) – record-keeping under the EU AI Act, a concept for extending to further QA use cases.
Typical impact figures
These are the orders of magnitude we typically see a few months after the end of an engagement in comparable mandates:
Range depends on data availability and use-case selection. We establish reliable expected values for your case in the Quick-Check.
Typical engagement framework