Search
Contact
12.06.2025 | KPMG Law Insights

From AI tool to AI framework – a workshop report

It started with a few questions about Microsoft Copilot – and ended with a company-wide AI framework. We were able to provide the company, a global consulting firm, with legal and strategic support along the way. The example shows why well thought-out AI governance requires far more than just investing in licenses.

The trigger: “We are introducing MS Copilot – can you help us?”

It all began with a phone call that we often encounter in practice. Driven by the promise of generative AI, a leading international consulting firm had decided relatively spontaneously to introduce Microsoft Copilot company-wide. The expectations were clear: to increase efficiency, promote innovation and use the latest technologies in order to stay ahead of the competition. The original request to us was to support this roll-out, particularly from a data protection perspective, and to identify the “biggest pitfalls”.

The realization: A tool is not yet a strategy

Even in the initial discussions and workshops, it became clear what we often experience: There is great enthusiasm for the technological possibilities of AI tools such as Copilot, but awareness of the associated legal and organizational implications is often less pronounced initially. Those responsible on the client side quickly realized in our collaboration that an isolated view of the introduction of Copilot falls short of the mark.

The following questions arose:

  • How do we ensure that the use of Copilot and future AI applications complies with the strict requirements of the GDPR and other relevant laws, such as the AI Act?
  • What data may be fed into the system at all? How do we handle sensitive client information or employees’ personal data?
  • Who is responsible for the results generated by AI?
  • How do we create transparency for our employees and clients regarding the use of AI?
  • How do we establish a process that enables us to evaluate future AI solutions in a structured manner and implement them safely?

It became clear that the desire for Copilot was just the tip of the iceberg. What the company really needed was a solid foundation – a comprehensive AI framework that would regulate and control the use of artificial intelligence throughout the company.

 

A global company needs global standards with local adaptability

The development of such a framework for a global consulting company with various business units and a large number of employees presented a number of challenges:

  • Legal complexity: International data protection standards and AI legislation, which was still developing at the time, had to be taken into account.
  • Organizational integration: AI governance should be seamlessly embedded in existing compliance structures and company processes.
  • Change management: Employees had to be sensitized and trained in order to promote acceptance and responsible use of AI.
  • Practicability: The guidelines and processes to be developed should not only be theoretically sound, but also practicable in day-to-day business.

 

Our solution: a customized AI framework

Together with the client, we have developed a multi-level AI framework based on the following core components:

The AI policy – the basic law for AI in the company

The first component we formulated was the AI policy. It was important that

  • the directive defines clear principles and rules for the responsible and legally compliant use of AI.
  • it addresses ethical aspects, data protection, data security, transparency obligations and responsibilities.
  • the guideline classifies the risks of AI applications and derives protective measures from this.

Information and training materials for the roll-out

To bring the AI policy to life, we developed easy-to-understand guidelines, FAQs and training documents for various target groups within the company.
The aim was not only to impart knowledge, but also to raise awareness of the opportunities and risks of AI and establish a positive error culture when dealing with new technologies.

An agile AI governance process

At the heart of the framework is a clearly defined process that enables the company to evaluate new AI projects in a structured manner, identify risks and make approval decisions on a solid basis. This process includes, among other things

  • A central point of contact for AI initiatives
  • A standardized evaluation procedure (incl. data protection impact assessment where necessary)
  • The involvement of relevant stakeholders (data protection, IT security, legal department, works council)
  • Regular review and adaptation of the AI solutions used

The result: legal certainty, transparency and professional AI management

By implementing this AI framework, our client has not only put the introduction of MS Copilot on a secure footing, but is now generally in a position to manage the potential of AI solutions in a professional, transparent and legally compliant manner.

The advantages of an AI framework are manifold

Minimization of legal risks: The AI framework ensures that the company complies with data protection regulations. It is therefore also well prepared for future AI regulations.

  • Strengthened trust: Transparency towards employees and customers creates trust in the use of AI.
  • Clear responsibilities: Defined roles and processes ensure clarity and traceability.
  • Promoting innovation with guard rails: employees can test and use new AI tools within the framework of clear guidelines.
  • Future viability: The company is well equipped to shape future AI developments proactively and responsibly.

 

Conclusion: AI implementation needs more than technology – it needs governance

The case of this global consulting firm is a good example of how the mere acquisition of AI technology is not enough to leverage its benefits sustainably and securely. It requires strategic anchoring in the company, supported by clear AI governance that combines legal requirements, ethical considerations and practical feasibility. The initial, focused inquiry regarding MS Copilot thus developed into a fundamental project that now enables the client to fully exploit the opportunities offered by artificial intelligence – and to do so with the necessary security and professionalism.

 

We would be happy to discuss with you how your company can also shape the path to customized and future-proof AI governance.

 

Dr. Jyn Schultze-Melling is also part of the League of Lawour new series. You can find out more about him and his work in Episode 2 “Big Data, Big Business”.

Explore #more

04.09.2025 | In the media

Guest article in Unternehmensjurist: Strategically transforming legal departments: A market overview

What are in-house teams at large companies concerned about when it comes to digital transformation? Which topics will be decisive in the coming years? The…

04.09.2025 | In the media

Guest article in the Unternehmensjurist: Successful change management in the HR department

The HR department plays a crucial role in the digital transformation. It is not only affected by change, but also shapes it. Between transformation, co-determination…

03.09.2025 | In the media

Guest article in the insurance industry: Embedded Insurance – More than just a new sales channel

The insurance industry is facing a paradigm shift. Traditional sales models are increasingly being supplemented by innovative approaches aimed at facilitating access to insurance policies…

03.09.2025 | KPMG Law Insights

Supply Chain Act: reporting obligation no longer applies, sanctions reduced

In the coalition agreement, the coalition partners agreed to abolish the Supply Chain Due Diligence Act (LkSG) as part of the implementation of the…

29.08.2025 | In the media

Statement by Ulrich Keunecke on the special infrastructure fund in Politico

KPMG Law financial expert Ulrich Keunecke explains how the infrastructure special fund can be leveraged with capital from private investors. You can find the article…

25.08.2025 | Deal Notifications

KPMG Law is advising APELOS on the refinancing and acquisition of a practice group with around 50 practice locations.

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised APELOS Therapie GmbH, a leading therapy practice group in Germany, on the refinancing…

15.08.2025 | In the media

KPMG Law Statement in Die-Stiftung.de on the topic of foundation registers – The long road to digital order

The entry into force of the foundation law reform on July 1, 2023 marks a turning point in the German foundation system. The list of…

14.08.2025 | KPMG Law Insights

Electromobility in logistics – legal challenges

In order to reduce its CO2 emissions, the logistics industry is increasingly turning to electromobility. This is not only due to ESG regulations such as…

07.08.2025 | KPMG Law Insights

NIS2: How energy suppliers must protect themselves against cyber attacks

In July 2025, the Military Counterintelligence Service reported a significant increase in spying attempts and disruptive measures by the Russian secret service, according to media…

06.08.2025 | KPMG Law Insights

Tax havens: When business relationships trigger criminal proceedings

A German tech company had been paying license fees to a contractual partner in Panama for years without ever having any problems. However, few people

Contact

Dr. Jyn Schultze-Melling, LL.M.

Partner

Heidestraße 58
10557 Berlin

Tel.: +49 30 530199 410
jschultzemelling@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll