Zweite Schicht DE, Deutsche Fassung Book a call

Test plan

Updated

Introducing AI in a mid-sized company on a sound legal footing: the checklist.

The questions your data protection officer, works council and IT ask before an AI workflow can go live. Six sections, 31 points, each with two sentences of explanation. Tick them off, print the list or have it sent to you.

Sketch of a checklist on a clipboard, the top boxes ticked, a ballpoint pen clipped to the board.

Done0 of 31

Your ticks are stored only in this browser and are not sent to us. When you print, empty boxes appear for ticking off on paper.

Start

1. Before you start

  • Write down which workflow is being rebuilt, from the first input to the finished result. A workflow with clear boundaries can be assessed legally; a general AI project cannot.

  • Decide how you will measure success: hours per week, lead time, error rate. Without a figure beforehand there is no proof afterwards, not even to the works council or management.

  • Name one person who makes the business decisions and one who approves access. This includes who in the business reviews the cases the workflow passes to a human.

  • Record which data the workflow reads and writes and whether personal data or confidential information is involved. This classification determines the legal basis, the operating mode and the scope of all further checks.

Data protection

2. Data protection

  • Any processing of personal data needs a legal basis under Article 6 GDPR, usually contract or legitimate interest. Record the balancing of interests in writing before the workflow starts.

  • You need a contract under Article 28 GDPR with the service provider and with the model provider. Check whether the model provider may use inputs for training, and rule that out.

  • If the model runs outside the EU, the transfer needs a basis such as the EU-US Data Privacy Framework or standard contractual clauses. Where there is no such basis, the workflow runs on your own servers or in an EU data centre.

  • The new workflow belongs in your record of processing activities under Article 30 GDPR, with purpose, data categories, recipients and retention periods. That is an hour of work and the first question in any audit.

  • Decide how long inputs, intermediate results and logs are kept. Logs should contain identifiers, not full texts with personal data.

  • If the workflow assesses people, such as applicants or employees, or processes special categories of data, a data protection impact assessment under Article 35 GDPR may be required. Clarify this with your data protection officer before anything is built.

Works council

3. Works council and employees

  • Technical systems that can monitor behaviour or performance are subject to co-determination under section 87(1) no. 6 BetrVG. The technical possibility is enough; intent is not required.

  • Clarify early whether a formal works agreement is needed or an informal arrangement is enough. A framework agreement for AI saves a new round for every further workflow.

  • Write down what the workflow logs and who sees the logs. Employee data is not used to steer people, and the agreement should say so.

  • Tell the people who work with the workflow what it does and what it does not do, before it starts. The people who do the work today know the exceptions and should be part of the analysis.

  • Plan how your team reviews drafts, adjusts rules and reports errors. The training is also your proof of AI literacy under Article 4 of the EU AI Act.

AI Act

4. EU AI Act

  • Assign each workflow to a risk class of the EU AI Act. Product texts and enquiries are usually low risk; selecting applicants and assessing employee performance count as high risk.

  • Anyone talking to a chatbot must be able to tell that an AI is answering, and AI-generated content must be labelled in certain cases. Decide where and how this happens in the workflow.

  • Decide which cases a person reviews and approves before they take effect. A workflow that passes on unclear cases instead of guessing meets this obligation in everyday operation.

  • Record the purpose, model, rules, checks and changes in writing. Your IT department will need the same documents if it takes over the workflow later.

  • Since February 2025, companies that use AI have been required to ensure sufficient AI literacy among the employees involved. Document who was trained, when and how.

Operation

5. Technology and operation

  • Decide for each workflow whether the model runs on your own servers, in an EU data centre or in the cloud under contract. The yardstick is the type of data from the first section, not habit.

  • The workflow gets only the rights it needs, with its own account instead of a personal one. Every change to data is logged with the time and the reason.

  • Decide which results go through automatically and which a person approves. Move that line after the first weeks based on the figures, not on gut feeling.

  • Every change made by the workflow must be reversible, individually and in bulk. Try this out once before going live.

  • Someone has to notice when the workflow stops or its error rate rises, before a customer notices. Define thresholds and reporting channels.

  • Name who is responsible for the workflow after launch, internally and at the service provider. Without a name, an error on a Friday evening stays where it is.

Contract

6. Contract with the service provider

  • Code, rules, prompts and documentation should belong to you once paid for. Otherwise you are paying for a workflow you cannot take with you.

  • Agree that the workflow is documented well enough for your IT department or another service provider to take it over. Check this with an example at handover.

  • Ongoing operation should be cancellable at short notice. A long minimum term is no substitute for a good result.

  • Settle who is liable for faulty output and which checks the service provider owes. Approval stays with you; diligence in the build lies with the service provider.

  • Have it confirmed in writing that your data is not used for training by either the service provider or the model provider. The sentence belongs in the contract, not in the sales deck.

Limits

Not legal advice

This checklist summarises what we check in projects with data protection officers, works councils and heads of IT. It does not replace legal advice. Whether an obligation applies to your workflow is something to clarify with your data protection officer or your legal advisers. As of: October 2026.

In more depth: The EU AI Act for mid-sized companies, Introducing AI with the works council, On your own servers, in Europe or in the cloud.

Form

Checklist by email

Optional. You receive the complete list with your ticks by email, to forward to your data protection officer, the works council or IT. We send nothing else.

Thank you, the checklist is on its way. You will receive it by email within a few minutes.
That did not work. Please check your name, email and the privacy tick box.

One email, nothing else

Handover

The first step is a 30-minute call.

You tell us about the workflow that costs you the most time. We tell you honestly whether AI pays off there and what the next step would be. Whether a workflow analysis follows is up to you.

Book a callApproach and prices