AI Transformation: Why Haphazard Growth Is Not a Strategy
Management Summary
Who is actually responsible for AI in your company? In many companies, this question first leads to the IT department, because that’s where licenses and software approvals are handled. Then it leads to the data protection department. And eventually, it becomes clear that there isn’t a single central point of responsibility. Every department has found its own applications. This is particularly evident in marketing, where AI has been in use early on and is highly visible. But it’s just one of many areas. In this article, we’ll show why AI transformation is a holistic endeavor: centrally managed, yet understandable to everyone and practical for everyday use. We’ll also discuss what the EU AI Act has to do with it and how companies can get started without slowing their teams down. This article is aimed at everyone who wants to work with AI or has been doing so for some time—from executive management down to the team level. Many want to deploy new tools quickly without burdening IT every time, and realize that a clear framework is missing for this.
Note: This article provides a practical overview and is not a substitute for legal advice. Legal status as of September 29, 2026, including the amendments made by the Digital Omnibus Act on AI (Regulation (EU) 2026/1744).
Why does uncontrolled growth occur so quickly during AI transformation?
It often starts with marketing. The content team needs a tool for text and images, the performance team works with the AI features of advertising platforms, and a chatbot answers inquiries on the website. Sales has quotes pre-drafted; HR seeks support with job postings and the pre-screening of applications; and customer service uses an assistant for standard inquiries.
Each department looks for the tool that best suits its needs. That makes sense. The challenge arises because these decisions are made in a decentralized manner, and rarely does anyone have the full picture. The IT department sees the software ordered through it, but hardly ever the AI features in existing programs or personal accounts. Data protection comes into play when personal data is involved. This leads to uncontrolled growth, usually without any malicious intent.
This is where the real transformation begins. It’s less about the best tool and more about governance: Who decides what AI will be used for? What data is allowed in which systems? Who is held accountable when an AI result is incorrect or content goes online without the necessary labeling? Neither IT nor compliance can answer these questions on their own. They belong within a dedicated structure that specifically oversees this area.
That’s why all the areas critical to a successful transformation need to be brought to the table: from senior management to line departments, IT, data protection, and compliance. This is the only way to achieve an AI transformation that works. If they work in isolation, either the teams will outpace the rules, or the rules will be so strict that employees will resort to using personal accounts. Both scenarios cost time and erode trust.
Marketing is well-suited as a pilot area. Few other fields utilize AI so early on, in so many different ways, and with such high visibility to the outside world. What works here can be applied as a model to other areas.
What framework does the EU AI Act establish for the AI transformation?
The EU AI Act regulates how artificial intelligence is developed and used in the European Union. Many obligations apply to providers of AI systems, but some apply to any company that uses AI. Today, two in particular are relevant for everyday life (Fig. 1):
- AI Competency, effective February 2025. Anyone who uses AI must take steps to ensure that employees understand what they are working with. This applies to all departments, as well as to agencies or freelancers who work with AI on behalf of the company.
- Transparency, effective August 2026. People should be able to tell when they are interacting with AI or viewing certain AI-generated content, such as a chatbot in customer service or AI-generated images and videos that appear real—so-called “deepfakes.” We’ve described what this means for ad creatives and advertising platforms in our article on the EU AI Act in ad campaigns.
From a transformation perspective, both obligations make sense, because proper AI compliance isn’t just about following rules—it also fosters the knowledge within the team and the openness toward customers that any AI implementation requires anyway. Those who document their measures can provide evidence of them to regulators, customers, and partners at any time.
What has the Digital Omnibus changed?
The Digital Omnibus on AI (Regulation (EU) 2026/1744) has been in effect since July 2026. It postpones deadlines but does not eliminate the obligations. When it comes to AI competence, companies must now take measures to promote it rather than simply ensuring a sufficient level. The obligations for high-risk AI—such as in the selection of job applicants—will take effect in December 2027.
Our assessment: The Omnibus buys time; it is not a green light.
EU AI Act – Timeline
Regulation (EU) 2024/1689, in effect since August 1, 2024.
Fig. 1: What the EU AI Act stipulates for companies that use AI: AI competence and transparency requirements are already in effect; high-risk obligations will follow. Status as of the Digital Omnibus.
Source: e-dialog, based on Regulations (EU) 2024/1689 and (EU) 2026/1744
What questions must the AI transformation address before the next tool is introduced?
In practice, an AI transformation is rarely determined by technology, but rather by organizational issues (Fig. 2). These apply to every area of the company. Marketing is simply the area where problems become apparent the fastest.
Fig. 2: Operational building blocks that bring AI transformation and compliance together.
Source: e-dialog
-
01
Who is responsible for the AI transformation?
Responsibility for the AI transformation rests with a centrally appointed leader, while a designated specialist must also be identified within each team for every specific application.
AI requires a clear mandate and a person who structurally leads and oversees the initiative—with dedicated time and support, rather than treating it as an additional task. Each application also requires a designated person in the relevant department. If agencies or freelancers use AI, the responsibility—including for labeling—must be specified in the contract. Who is responsible depends on who makes the decisions regarding AI usage.
-
02
How much AI knowledge does each role require?
The required AI knowledge depends on the actual tasks: Management needs to be able to assess strategic risks, while operational teams need specific knowledge to review and label AI content.
AI competence doesn’t mean that all prompts learn. Management must be able to assess opportunities and risks. A content team must know when AI-generated content needs to be reviewed or flagged. HR needs a particularly critical eye as soon as AI starts reading applications. Good training, therefore, focuses on the actual tasks, not the tool, and is documented.
-
03
Why does every AI transformation begin with an assessment?
Conducting an inventory is crucial for uncovering hidden “shadow AI,” creating a centralized AI inventory, and realistically assessing the risks of existing applications within the company.
Most executives underestimate just how much AI is already in use within their organizations: in officially deployed tools, in AI features of existing software such as CRM systems, in tools developed by individual departments, and as “shadow AI” accessed through personal accounts. An AI inventory reveals what is running, who is responsible for it, and how risky it is.
-
04
What rules do teams need in their day-to-day work?
In their day-to-day work, teams need, above all, clear approval processes, understandable guidelines on data use, and simple rules regarding labeling requirements in order to work with AI safely and in compliance with the law.
Good rules first clarify what is permitted: which tools are approved, which data can go where, when a human reviews it, and what must be labeled. In marketing, this could be an additional step in the content approval process or a fixed set of rules that provides the framework. In HR, the question of where a human retains the final say is more than just best practice: AI that filters or evaluates job applications is generally considered a high-risk application under the AI Act. Practical AI compliance is evident when the rules align with the work—because anything that slows down day-to-day operations will be circumvented.
-
05
How does AI integrate with existing processes?
AI integrates best with existing workflows by embedding verification steps directly into established processes such as content approval, agency briefings, or procurement.
Instead of creating a separate set of rules on top of everything else, it works better to incorporate AI compliance right where decisions are made anyway: in content approval, agency briefings, procurement, data protection, and onboarding. Anyone who has ever set up tracking systems in compliance with data protection regulations is familiar with this principle.
-
06
How Can the AI Transformation Keep Moving Forward?
The AI transformation remains in motion thanks to a clearly defined cycle of regular reviews, ensuring that internal policies are constantly adapted to new tools and legal requirements.
AI tools, use cases, and the legal landscape are constantly changing. A policy that is written once and then set aside will be outdated within a year. Anyone who wants to manage AI over the long term needs a consistent schedule for review and adaptation. This is how we distinguish between a company that is merely experimenting with AI and one that is transforming itself through AI, thereby remaining future-ready and competitive.
Where Do Companies Stand in Their AI Transformation?
The figures confirm what we’re seeing in our projects. According to Bitkom, 57 percent of companies in Germany with 20 or more employees will be using AI for the first time in 2026. A year earlier, that figure was 36 percent. In Austria, according to Statistik Austria, 30 percent of companies with ten or more employees were using AI in 2025; the EU average was 20 percent. While the surveys differ in methodology and company size, the trend is clear. AI was most commonly used in marketing and sales: According to a survey by the Federal Network Agency (conducted at the end of 2024), this was the case for just under seven out of ten companies using AI.
Existing structures cannot keep pace with this rate of change:
- Shadow AI is on the rise. In 2025, 42 percent of companies at least assumed that employees were using personal AI tools for work (Fig. 3). In 8 percent of companies, this practice is already widespread—twice as many as the previous year.
- Guidelines are lacking. Only 23 percent of companies had established guidelines for AI use in 2025; a year earlier, the figure was 15 percent.
- Knowledge is unevenly distributed. According to Bitkom, 70 percent of companies will provide AI training to their employees in 2026, but only 11 percent will train all of them. 66 percent consider their workforce’s AI competence to be low.
Shadow AI is, above all, a sign. Employees want to work with AI. If the company doesn’t provide a framework, they’ll find one on their own.
Fig. 3: More and more companies assume that employees use personal AI tools for work.
Source: Bitkom Research, survey of 604 companies in Germany with 20 or more employees, 2025
How do you get started with AI transformation?
Six questions at once might sound like a major project. In practice, we work with three building blocks that we adapt to the initial situation. Each one offers benefits in its own right, and where you start depends on where the company stands.
-
01
How does the company build up its AI expertise?
Building knowledge is often a good place to start because it requires no prior preparation and establishes a common language. However, basic training will no longer suffice by 2026. AI has long since moved beyond simply generating text: as an assistant or agent, it is integrated into an increasing number of tools and performs tasks independently, from campaign management to responding to customer inquiries. Good prompting alone is therefore not enough. Teams must understand what these systems do, what data they access, where a human must review and intervene, and who is accountable for the outcome. A foundational module for everyone clarifies what AI can do today, what the AI Act requires, and what applies internally. Afterward, the topic is explored in greater depth using real-world tasks from marketing, sales, HR, or IT—including the development of custom assistants and agents that teams build together with us and deploy in their daily work. Participation and course content should be documented to provide proof of completion.
-
02
How do we get an overview of AI usage?
In an AI Readiness Assessment, we work with the business units to identify where AI is currently in use, even beyond the official license lists. The result is a registry of all applications with their risk classifications, a heat map highlighting the areas requiring the most urgent action, and a roadmap with deadlines and assigned responsibilities. This also highlights which content already requires labeling today and which applications must be prepared as high-risk systems by December 2027. For many executive teams, this is the first time the issue becomes visible in a single overview, across all departments.
-
03
How are rules incorporated into everyday life?
The AI policy can build on the overview or serve as the starting point itself when clear rules are needed quickly to specifically govern the use of AI. In a workshop, senior management, the data protection team, and business units make the decisions that best suit the company. This results in a policy, approval workflows, labeling rules, and a communication package to ensure the rules reach everyone, including agencies and partners. After six months, we’ll review together what’s working and what needs to be refined.
Conclusion: Why Does AI Transformation Require Centralized Management?
- Every department needs its own AI tools. Without centralized control, things will get out of hand.
- The real issues are organizational: responsibility, knowledge, oversight, and rules.
- The EU AI Act requires measures to build AI competence starting in 2025 and transparency starting in 2026. Every AI implementation needs both of these anyway.
- The Digital Omnibus has postponed deadlines, not the tasks themselves. Starting in December 2027, high-risk obligations will apply, such as for AI in recruiting.
- Shadow AI shows that teams are ready. What’s missing is the framework.
- Training, assessment, and guidelines help get started, in the order that best suits the company.
Our assessment:
The companies that make the best use of AI rarely have the most tools. They established early on who makes the decisions and how new applications are adopted within the organization. Marketing is a natural starting point for this. The transformation is effective when it is managed centrally and has the support of senior management. Anyone can be the catalyst for this.
Sources:
- Regulation (EU) 2024/1689, Art. 4 AI Competence (as amended by Regulation (EU) 2026/1744)
- Regulation (EU) 2024/1689, Art. 50 Transparency Requirements
- Regulation (EU) 2024/1689, Annex III, No. 4: Employment and Human Resources Management
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since July 27, 2026
- European Commission, AI Literacy: Questions & Answers (as of July 27, 2026)
- European Commission, Transparency Obligations Under Article 50 of the AI Act (FAQ)
- Federal Network Agency, AI Competence (Topic Page, Version Based on the Digital Omnibus)
- Federal Network Agency, AI in Businesses: Adoption, Resources, and Challenges (Survey Oct.–Dec. 2024, published July 2025)
- Bitkom, Employees Are Increasingly Using “Shadow AI” (Oct. 21, 2025)
- Bitkom, For the First Time, a Majority of Companies Are Using AI (September 14, 2026)
- Statistik Austria, Austrian Companies Among the EU Leaders in the Use of Artificial Intelligence, Press Release on “ICT Use in Companies 2025” (June 24, 2026)